Charging a customer to take their data out stops being legal on 12 January 2027
A customer on your annual plan gives notice. Their ops lead asks for everything before the account closes: the full record export, the file attachments, the event history, in something their new vendor can actually ingest.
Your team has fielded this twice before, so the answer is the usual one. Bulk export was never built, so an engineer has to write a script. That is quoted at 3,500 euros, plus the egress, and it goes in the queue behind whatever is shipping this sprint.
Their counsel replies the next morning, citing Articles 23 to 31 of the EU Data Act. Your contract does not contain the switching terms the Regulation requires it to contain. Of the 3,500 euros, only costs directly linked to the switching process are chargeable at all. And after 12 January 2027, the chargeable amount is zero.
So you are renegotiating your own contract in the middle of a churn event, against someone who has read a law you had filed under connected machinery and industrial sensors.
If you sell software that runs on your servers to businesses in the EU, this is your homework: open your customer agreement and find the nine things Article 25(2) says must be in it, then open your price list and find everything you charge a customer for moving off you. The first list is probably short, and every item missing from it is a term your contract is required to carry today. The second list has to be empty of switching charges by 12 January 2027, and anything still on it after that date puts you in breach.
Does the Data Act apply to a SaaS company?
The Data Act is best known for its connected-products chapter, so most founders I talk to have skipped it. Chapter VI is a different thing: switching between what the Regulation calls data processing services.
A data processing service is defined as a digital service that "enables ubiquitous and on-demand network access to a shared pool of configurable, scalable and elastic computing resources" 1. That reads like infrastructure, and it is easy to stop there. Read it as a list of elements and multi-tenant software walks in: a shared pool, on demand over the network, provisioned when someone signs up, scaling with what the customer uses. Recital 81 then says it outright, naming Infrastructure as a Service, Platform as a Service and Software as a Service as the three delivery models these services fall into 1. Recitals are the numbered explanatory paragraphs at the front of an EU law, where the legislature says what it meant the rules to do. The Commission's FAQ on the Data Act, updated in January 2026, puts it more plainly still: Chapter VI "does not make a distinction between different types of SaaS" 4.
The two escapes founders reach for first are both closed. Size does not help: the Data Act's carve-out for small companies sits in Article 7 and applies only to the connected-products chapter, and the switching chapter has no equivalent, so a four-person company and AWS are under the same rules. Distance does not help either, because Article 1(3)(f) applies the Regulation to providers "irrespective of their place of establishment, providing such services to customers in the Union" 1.
Article 31 holds two exits, and they are for a narrow crowd: services built bespoke for one customer and not sold from your catalogue, and non-production instances handed over for testing. If your product is the same product for everybody, neither is yours.
If one of them is yours, the bespoke exit buys you less than it sounds. It lets you keep charging for a switch. It does not touch the contract terms or the export duties, which still apply in full. And you have to tell the customer, before they sign, exactly which obligations you are claiming an exemption from 1.
Between those exits and a plainly multi-tenant product there is real grey area, and the Regulation does not settle it service by service. Where a customer buys an outcome and the computing is incidental to it, there is an argument to have. My read is that most SaaS will not win that argument, but it is a read rather than settled law, and if the answer is worth real money to you it is worth counsel.
Does your legal documentation match what you ship?
Lawcel watches your product changes and flags the moment your terms or privacy policy fall out of sync, then proposes the edits for your team to approve and publish.
Get startedWhat has to be in the contract?
Article 25(1) catches most people, because it is not about behaviour at all. The customer's switching rights and your obligations must be "clearly set out in a written contract", available to them before signing in a form they can store and reproduce 1. Handling an export well when someone asks does not satisfy it. The words have to be in the document.
Article 25(2) then says what the contract must contain "at least" 1:
- Thirty calendar days to switch, to another provider or to the customer's own infrastructure. During those 30 days the contract stays live and the service keeps running, and you assist the customer and anyone they authorise, flag known continuity risks, and keep the data secure through the transfer.
- Two months' maximum notice to start the switch. You can require less, never more.
- A list of what you will hand over: every category of data and digital asset that can be ported, covering at minimum all exportable data.
- A list of what you will hold back, and why: the categories specific to the internal workings of your service that you are keeping because exporting them would risk your trade secrets. It cannot be a list that delays the switch.
- Help with their exit, including giving them all the relevant information.
- Thirty more days, at least, to retrieve the data after the transitional period ends.
- Erasure afterwards, once that window (or a later one you agree) closes, provided the switch completed successfully.
- A termination clause saying the contract ends when the switch completes, or at the end of the notice period if they only want their data erased and gone.
- Your switching charges, if any, on the terms Article 29 allows.
If 30 days is technically unfeasible, Article 25(4) lets you say so, but on terms: notice within 14 working days of the request, a duly justified explanation, and an alternative period capped at seven months. Assume the burden of proof is yours (recital 87). The customer, meanwhile, can extend the transitional period once for as long as suits them, and that is not a right you can argue with 1.
There is no grace period left to wait out. The Data Act has applied since 12 September 2025 2, and Article 50 hands a transitional period to the chapter on unfair contract terms while handing the switching chapter none 1. Every contract in your book is already in scope, including the ones you signed years ago and have not reopened since.
Which raises the fair objection that you cannot rewrite a signed agreement on your own. You cannot. What is in your gift is the standard agreement every new customer signs from now on, the renewal conversation for everyone else, and behaving as though the terms were already there in the meantime, because the obligations bind you whether or not the paperwork has caught up.
What can you still charge for?
Article 29 sets out a two-stage withdrawal 1. Until 12 January 2027, you may impose reduced switching charges, capped at the costs you actually incur that are directly linked to that switching process. From 12 January 2027, you may impose none. Data egress charges are named as switching charges in the definitions, so the bandwidth you meter on a customer's way out goes to zero on the same date.
The biggest clouds have already moved. Google Cloud dropped its exit egress fees in January 2024, the week the Data Act entered into force, and AWS followed in March, naming the Data Act as the direction it was following. The UK competition authority's evidence review of those free switching programmes found uptake low to moderate, a hint that the fee was never the only barrier: the contract terms and export duties are what decide whether a customer can actually leave.
Three things survive, and they matter commercially:
- Standard service fees. The fees for providing the service are explicitly not switching charges and remain payable until the contract ends, so a customer switching does not stop paying for the months they are still using you (recital 89).
- Early termination penalties. A proportionate penalty on a fixed-term contract is untouched.
- Genuinely additional work. If the customer asks for support beyond what the Regulation obliges you to provide, and agrees the price in advance, you can charge for it (recital 89).
Which leaves the 3,500 euros, and this is where I would expect a customer's lawyer to push. Exporting their data in a machine-readable format is something Article 30(5) obliges you to do, so charging for it is a switching charge rather than the extra-work exception above. The counter-argument sits in the same article: Article 30(6) says providers "shall not be required to develop new technologies or services", and a vendor who never built bulk export will reach for it 1. My read is that it does not carry, because 30(5) asks you to hand over data the customer already generated rather than to build them a product, and a script that reads your own database is not a new technology. That is arguable, and for a big enough sum it will be argued. The date is not. Until 12 January 2027 you can pass on the costs directly linked to that switch; after it the amount is zero however the costs were split. So there is no point re-pricing an export fee. Treat it as revenue you are losing on a date you already know.
Article 29(4) and 29(6) make you disclose your standard fees, any early termination penalties and any switching charges to a prospective customer before signing, and publish them somewhere easily accessible.
Article 30(2) then requires every provider that is not bare infrastructure, which is to say PaaS and SaaS, to make open interfaces available "to an equal extent to all their customers and the concerned destination providers of data processing services free of charge to facilitate the switching process" 1. The closing words bound the duty to the interfaces someone needs in order to get their own data out and into the next tool, so this is not a rule about your product API in general. For those interfaces it is absolute: they cannot be a paid add-on, and they cannot sit behind the enterprise tier.
How we deal with this at Lawcel
Lawcel is a compliance platform: it watches the changes your team ships, in GitHub and in your issue tracker, and works out which of your published legal documents each one puts out of date.
Read Article 25(2) again and notice how much of it is a clock: 30 calendar days to transition, two months as the notice ceiling, 30 calendar days to retrieve, 14 working days to declare something unfeasible. Lawcel builds a structured record of what a company has committed to, drawn from its own legal documents, and promises with a clock attached get their own section of that record, called commitments. Each entry holds the trigger, the obligation, the timing quoted word for word from the document it came from, and who it is owed to.
They earned a section because deadline promises break quietly. A retention job that purges at 14 days, a storage tier that archives after 30, a change to what the export contains: none of it looks like a legal change while it is being written, and all of it can contradict a sentence someone put in the contract two quarters ago. It will not write your Article 25 clauses for you. It is there for the quarter after you write them, when something you ship quietly stops being true.
Who actually enforces this?
Not a regulator with a headline fine, and I think that is why this keeps sliding down everyone's list. Article 40 leaves penalties to each member state, and the GDPR-style administrative fines it does allow attach to other chapters of the Data Act, not to the switching one 1. There is no four-percent-of-turnover number waiting behind a bad exit clause.
So it arrives as a commercial problem first. The people who find the gap are a customer's counsel during an exit, a procurement reviewer working through a security questionnaire, or an enterprise buyer whose contract playbook now has a Data Act section in it. None of them can fine you. They can redline your contract, at the point in a deal where you have the least leverage.
If you would rather not draft the clauses yourself, the Commission published draft standard contractual clauses for cloud contracts on 19 November 2025, covering switching and exit, termination, and security and business continuity during a switch 3. Non-binding, and free.
What should you do before 12 January 2027?
You need none of the above to start, and no lawyer either. Open your customer agreement and look for the nine items listed earlier under Article 25(2). Then open your price list and find every line that charges a customer for moving off you, egress on the way out included. Give each of those lines the date it has to be gone by.
Then two things that take longer, so they are worth starting now: the export has to come out in a format somebody else can read, and the interface that produces it cannot be something a leaving customer has to pay for. Both are cheaper to build in a quiet quarter than in the fortnight after a customer's counsel writes to you.
Tags
FAQ
References
- Regulation (EU) 2023/2854 (Data Act), including Articles 1, 2, 23, 25, 26, 29, 30, 31, 34, 40 and 50, and recitals 81, 82, 86, 87, 88, 89 and 99 - accessed 6 Aug 2026
- European Commission - Data Act policy page, including entry into force and application dates - accessed 6 Aug 2026
- European Commission - Draft Recommendation on non-binding model contractual terms on data access and use and non-binding standard contractual clauses for cloud computing contracts (19 November 2025) - accessed 6 Aug 2026
- European Commission - Frequently Asked Questions on the Data Act, version 1.4 (22 January 2026) - accessed 27 Aug 2026
About the author
Kenneth Graupner
Co-founder, Chief Product Officer
Kenneth is Co-founder and CPO at Lawcel. He focuses on product strategy and on shaping workflows so legal, engineering, and GTM teams can ship continuously without treating compliance as a late-stage gate.
- Product strategy
- Compliance operations
- SaaS delivery
Related articles
A connected device sold in the EU after 12 September 2026 must export its data to the user
For a connected device first sold in the EU after 12 September 2026, and the software it needs to work, the readings it produces have to reach its user by default: free of charge, in a machine-readable format, and directly accessible where feasible. Small companies get an exemption, but lose it if a larger company owns a quarter of them, or if they were paid to build somebody else's product.
NIS2NIS2 is nearly two years late in four countries. It reached your sales cycle on time.
NIS2 had to be in national law by 17 October 2024, and in July 2026 four member states were referred to the EU Court for still not having transposed it. That gap does not shelter a SaaS vendor: Article 21(2)(d) requires every in-scope entity to cover supply chain security, including relationships with its direct suppliers, so NIS2 reaches you as a contract clause from customers, not a letter from a regulator.
AI ActThe EU KIDS Act would regulate general AI chatbots, not customer-support bots
The EU KIDS Act, proposed on 17 September 2026 and not yet law, would regulate AI chatbots that minors can reach and that can help across multiple domains. Chat limited to one task, such as customer service, is excluded. In scope, every user would get child-safe defaults, such as no memory between chats, until an age check that is not a tick box shows they are an adult.
NIS2NIS2 supplier contracts need eight security clauses. A DPA covers five at best.
NIS2's implementing regulation names eight things your supplier contracts have to specify. By my count a GDPR data processing agreement covers five at best, and three have no counterpart in it at all. Suppliers that reach your systems without touching personal data fall outside every DPA you hold, and NIS2 wants contract terms with them regardless.