Charging a customer to take their data out stops being legal on 12 January 2027
A customer on your annual plan gives notice. Their ops lead asks for everything before the account closes: the full record export, the file attachments, the event history, in something their new vendor can actually ingest.
Your team has fielded this twice before, so the answer is the usual one. Bulk export was never built, so an engineer has to write a script. That is quoted at 3,500 euros, plus the egress, and it goes in the queue behind whatever is shipping this sprint.
Their counsel replies the next morning, citing Articles 23 to 31 of the EU Data Act. Your contract does not contain the switching terms the Regulation requires it to contain. Of the 3,500 euros, only costs directly linked to the switching process are chargeable at all. And after 12 January 2027, the chargeable amount is zero.
So you are renegotiating your own contract in the middle of a churn event, against someone who has read a law you had filed under connected machinery and industrial sensors.
If you sell software that runs on your servers to businesses in the EU, this is your homework: open your customer agreement and find the nine things Article 25(2) says must be in it, then open your price list and find everything you charge a customer for moving off you. The first list is probably short, and every item missing from it is a term your contract is required to carry today. The second list has to be empty of switching charges by 12 January 2027, and anything still on it after that date puts you in breach.
Does the Data Act apply to a SaaS company?
The Data Act is best known for its connected-products chapter, which is why most founders I talk to have skipped it. Chapter VI is a different thing: switching between what the Regulation calls data processing services.
A data processing service is defined as a digital service that "enables ubiquitous and on-demand network access to a shared pool of configurable, scalable and elastic computing resources" 1. That reads like infrastructure, and it is easy to stop there. Read it as a list of elements and multi-tenant software walks in: a shared pool, on demand over the network, provisioned when someone signs up, scaling with what the customer uses. Recital 81 then says it outright, naming Infrastructure as a Service, Platform as a Service and Software as a Service as the three delivery models these services fall into 1. Recitals are the numbered explanatory paragraphs at the front of an EU law, where the legislature says what it meant the rules to do.
The two escapes founders reach for first are both closed. Size does not help: the Data Act's carve-out for small companies sits in Article 7 and applies only to the connected-products chapter, and the switching chapter has no equivalent, so a four-person company and AWS are under the same rules. Distance does not help either, because Article 1(3)(f) applies the Regulation to providers "irrespective of their place of establishment, providing such services to customers in the Union" 1.
Article 31 holds two exits, and they are for a narrow crowd: services built bespoke for one customer and not sold from your catalogue, and non-production instances handed over for testing. If your product is the same product for everybody, neither is yours.
If one of them is yours, the bespoke exit buys you less than it sounds. It lets you keep charging for a switch. It does not touch the contract terms or the export duties, which still apply in full. And you have to tell the customer, before they sign, exactly which obligations you are claiming an exemption from 1.
Between those exits and a plainly multi-tenant product there is real grey area, and the Regulation does not settle it service by service. Where a customer buys an outcome and the computing is incidental to it, there is an argument to have. My read is that most SaaS will not win that argument, but it is a read rather than settled law, and if the answer is worth real money to you it is worth counsel.
Does your legal documentation match what you ship?
Lawcel watches your product changes and flags the moment your terms or privacy policy fall out of sync, so your legal pages always match what you actually ship.
Try for freeWhat has to be in the contract?
Article 25(1) catches most people, because it is not about behaviour at all. The customer's switching rights and your obligations must be "clearly set out in a written contract", available to them before signing in a form they can store and reproduce 1. Handling an export well when someone asks does not satisfy it. The words have to be in the document.
Article 25(2) then says what the contract must contain "at least" 1:
- Thirty calendar days to switch, to another provider or to the customer's own infrastructure. During those 30 days the contract stays live and the service keeps running, and you assist the customer and anyone they authorise, flag known continuity risks, and keep the data secure through the transfer.
- Two months' maximum notice to start the switch. You can require less, never more.
- A list of what you will hand over: every category of data and digital asset that can be ported, covering at minimum all exportable data.
- A list of what you will hold back, and why: the categories specific to the internal workings of your service that you are keeping because exporting them would risk your trade secrets. It cannot be a list that delays the switch.
- Help with their exit, including giving them all the relevant information.
- Thirty more days, at least, to retrieve the data after the transitional period ends.
- Erasure afterwards, once that window (or a later one you agree) closes, provided the switch completed successfully.
- A termination clause saying the contract ends when the switch completes, or at the end of the notice period if they only want their data erased and gone.
- Your switching charges, if any, on the terms Article 29 allows.
If 30 days is technically unfeasible, Article 25(4) lets you say so, but on terms: notice within 14 working days of the request, a duly justified explanation, and an alternative period capped at seven months. Assume the burden of proof is yours (recital 87). The customer, meanwhile, can extend the transitional period once for as long as suits them, and that is not a right you can argue with 1.
There is no grace period left to wait out. The Data Act has applied since 12 September 2025 2, and Article 50 hands a transitional period to the chapter on unfair contract terms while handing the switching chapter none 1. Every contract in your book is already in scope, including the ones you signed years ago and have not reopened since.
Which raises the fair objection that you cannot rewrite a signed agreement on your own. You cannot. What is in your gift is the standard agreement every new customer signs from now on, the renewal conversation for everyone else, and behaving as though the terms were already there in the meantime, because the obligations bind you whether or not the paperwork has caught up.
What can you still charge for?
Article 29 sets out a two-stage withdrawal 1. Until 12 January 2027, you may impose reduced switching charges, capped at the costs you actually incur that are directly linked to that switching process. From 12 January 2027, you may impose none. Data egress charges are named as switching charges in the definitions, so the bandwidth you meter on a customer's way out goes to zero on the same date.
Three things survive, and they matter commercially:
- Standard service fees. The fees for providing the service are explicitly not switching charges and remain payable until the contract ends, so a customer switching does not stop paying for the months they are still using you (recital 89).
- Early termination penalties. A proportionate penalty on a fixed-term contract is untouched.
- Genuinely additional work. If the customer asks for support beyond what the Regulation obliges you to provide, and agrees the price in advance, you can charge for it (recital 89).
Which leaves the 3,500 euros, and this is where I would expect a customer's lawyer to push. Exporting their data in a machine-readable format is something Article 30(5) obliges you to do, so charging for it is a switching charge rather than the extra-work exception above. The counter-argument sits in the same article: Article 30(6) says providers "shall not be required to develop new technologies or services", and a vendor who never built bulk export will reach for it 1. My read is that it does not carry, because 30(5) asks you to hand over data the customer already generated rather than to build them a product, and a script that reads your own database is not a new technology. That is arguable, and for a big enough sum it will be argued. The date is not. Until 12 January 2027 you can pass on the costs directly linked to that switch; after it the amount is zero however the costs were split. So there is no point re-pricing an export fee. Treat it as revenue you are losing on a date you already know.
Article 29(4) and 29(6) make you disclose your standard fees, any early termination penalties and any switching charges to a prospective customer before signing, and publish them somewhere easily accessible.
Article 30(2) then requires every provider that is not bare infrastructure, which is to say PaaS and SaaS, to make open interfaces available "to an equal extent to all their customers and the concerned destination providers of data processing services free of charge to facilitate the switching process" 1. The closing words bound the duty to the interfaces someone needs in order to get their own data out and into the next tool, so this is not a rule about your product API in general. For those interfaces it is absolute: they cannot be a paid add-on, and they cannot sit behind the enterprise tier.
How we deal with this at Lawcel
Lawcel is a compliance platform: it watches the changes your team ships, in GitHub and in your issue tracker, and works out which of your published legal documents each one puts out of date.
Read Article 25(2) again and notice how much of it is a clock: 30 calendar days to transition, two months as the notice ceiling, 30 calendar days to retrieve, 14 working days to declare something unfeasible. Lawcel builds a structured record of what a company has committed to, drawn from its own legal documents, and promises with a clock attached get their own section of that record, called commitments. Each entry holds the trigger, the obligation, the timing quoted word for word from the document it came from, and who it is owed to.
They earned a section because deadline promises break quietly. A retention job that purges at 14 days, a storage tier that archives after 30, a change to what the export contains: none of it looks like a legal change while it is being written, and all of it can contradict a sentence someone put in the contract two quarters ago. It will not write your Article 25 clauses for you. It is there for the quarter after you write them, when something you ship quietly stops being true.
Who actually enforces this?
Not a regulator with a headline fine, and I think that is why this keeps sliding down everyone's list. Article 40 leaves penalties to each member state, and the GDPR-style administrative fines it does allow attach to other chapters of the Data Act, not to the switching one 1. There is no four-percent-of-turnover number waiting behind a bad exit clause.
So it arrives as a commercial problem first. The people who find the gap are a customer's counsel during an exit, a procurement reviewer working through a security questionnaire, or an enterprise buyer whose contract playbook now has a Data Act section in it. None of them can fine you. They can redline your contract, at the point in a deal where you have the least leverage.
If you would rather not draft the clauses yourself, the Commission published draft standard contractual clauses for cloud contracts on 19 November 2025, covering switching and exit, termination, and security and business continuity during a switch 3. Non-binding, and free.
What should you do before 12 January 2027?
You need none of the above to start, and no lawyer either. Open your customer agreement and look for the nine items listed earlier under Article 25(2). Then open your price list and find every line that charges a customer for moving off you, egress on the way out included. Give each of those lines the date it has to be gone by.
Then two things that take longer, so they are worth starting now: the export has to come out in a format somebody else can read, and the interface that produces it cannot be something a leaving customer has to pay for. Both are cheaper to build in a quiet quarter than in the fortnight after a customer's counsel writes to you.
FAQ
References
- Regulation (EU) 2023/2854 (Data Act), including Articles 1, 2, 23, 25, 26, 29, 30, 31, 34, 40 and 50, and recitals 81, 82, 86, 87, 88, 89 and 99 - accessed 6 Aug 2026
- European Commission - Data Act policy page, including entry into force and application dates - accessed 6 Aug 2026
- European Commission - Draft Recommendation on non-binding model contractual terms on data access and use and non-binding standard contractual clauses for cloud computing contracts (19 November 2025) - accessed 6 Aug 2026
About the author
Kenneth Graupner
Co-founder, Chief Product Officer
Kenneth is Co-founder and CPO at Lawcel. He focuses on product strategy and on shaping workflows so legal, engineering, and GTM teams can ship continuously without treating compliance as a late-stage gate.
- Product strategy
- Compliance operations
- SaaS delivery
Related articles
Continuous compliance in Lovable. No plugin required.
If someone on your team shipped a customer-facing tool in Lovable, connect the GitHub repository it already syncs to Lawcel the same way you would connect any other repo, no Lovable plugin is needed. We read every commit the way we read any team's pull request and flag what needs to change in your legal documents, or draft a first document if this build needs one of its own.
Drift60% of Product Hunt sites load a foreign vendor their policy never mentions
I scanned 458 products launched on Product Hunt over 30 days, loading each from inside the EU and reading its legal pages. 233 both publish a privacy policy and load a third-party service in the visitor's browser, but 139 of those (59.7%) say nothing at all about international transfers. The transfer starts when somebody pastes a snippet, not when somebody signs a contract.
NIS2NIS2 is nearly two years late in four countries. It reached your sales cycle on time.
NIS2 had to be in national law by 17 October 2024, and in July 2026 four member states were referred to the EU Court for still not having transposed it. That gap does not shelter a SaaS vendor: Article 21(2)(d) requires every in-scope entity to cover supply chain security, including relationships with its direct suppliers, so NIS2 reaches you as a contract clause from customers, not a letter from a regulator.
AI ActArticle 50 applies on 2 August 2026, and your model vendor cannot carry it for you
Article 50 of the EU AI Act applies from 2 August 2026. The delay you read about in June covered high-risk uses such as hiring and credit scoring, not this. If your product has an AI feature that ships under your own name, the law treats you as its provider even though the model belongs to your vendor, so telling users about it and marking what it generates are your duties. You may use whatever marking your vendor builds, but the Commission's guidelines say that demonstrating compliance stays with you.