eu data actcloud switchingdata portabilitycancellation flowcompliance

The EU Data Act Bans Cloud-Switching Fees in January 2027 — And SaaS Is Explicitly in Scope

The EU Data Act's switching rules cover SaaS, not just cloud infrastructure — a 30-day export clock and a fee ban landing January 12, 2027.

XY
21 September 2026 · 8 min read

Most SaaS teams who've heard of the EU Data Act filed it under "someone else's problem" — a rule for AWS, Azure, and Google Cloud to worry about, not for a subscription product built on top of them. That reading is wrong, and it's wrong in a way that matters: the Act's switching obligations name software-as-a-service explicitly, they've applied since September 2025, and the provision that removes switching fees entirely lands on a fixed date that's now under sixteen months away.

Key stat
30 days
The maximum default window a data processing provider gets to complete a customer's switch under the EU Data Act — and SaaS providers are named in scope, not just infrastructure vendors
Source: Regulation (EU) 2023/2854 ("Data Act"), Chapter VI, Articles 23–31

We've written before about the EU's withdrawal button requirement and the growing pile of GDPR and CCPA deletion deadlines that kick in after someone cancels. The Data Act is a different animal from both. It's not a consumer-protection rule, and it's not primarily about personal data. It's a business-to-business switching right, and it exists specifically to stop cloud and SaaS vendors from using data gravity — the sheer cost and hassle of moving — as a substitute for actually being worth staying with.

This is not the data-portability rule you already know

If you've already built a GDPR Article 20 export flow, it's tempting to assume the Data Act is the same obligation wearing a new name. It isn't, and conflating the two is the most common mistake we're seeing teams make right now. Article 20 gives an individual consumer the right to a copy of the personal data they gave you, in a portable format. The Data Act gives a business customer the right to take their entire operational footprint — configuration, workloads, generated data, not just what one named person typed into a form — and move it to a competitor, on a defined clock, without you charging them for the privilege after January 2027.

RequirementEU Data Act, Ch. VI (switching)GDPR Art. 20 (portability)CCPA/CPRA (portability)
Who can invoke itAny business customer of a data processing serviceAn individual data subjectAn individual California consumer
What transfersFull exportable data and digital assets defined in the contractPersonal data the individual providedPersonal information collected about the consumer
Response deadline30 days default, extendable to 7 months if technically infeasible1 month, extendable to 345 days, extendable to 90
Fee statusCost-only until Jan 12, 2027; zero afterMust be free for the first requestMust be free for requests up to twice a year
Applies regardless of provider size?No — narrow legacy-contract relief for SME/small mid-capYesYes, above CCPA's revenue/data-volume thresholds

The practical upshot: a customer who cancels your product in the EU can now invoke two structurally different rights at once, on two different clocks, and satisfying one doesn't satisfy the other. A CSV of their profile data emailed out under Article 20 does nothing for a Data Act switching request, which is a business-level operation and typically needs technical assistance on your side, not just a file download.

The four-phase switching clock

Chapter VI runs on a defined sequence, and each phase has its own cap. First, the customer gives notice — they can do this at any point, and you're not allowed to require more than two months' notice before the switching clock starts. Second, the transition period itself: 30 calendar days by default, during which you're required to actively assist the move, not just leave an export button live and call it done. If the switch is genuinely not technically feasible in 30 days — a legitimately complex migration, not a stalling tactic — that period can extend up to seven months, but the burden is on you to justify the extension, not on the customer to accept it. Third, a minimum 30-day data retrieval window after the transition period closes, during which the customer can still pull anything they missed. Fourth, and only after that window expires, you're required to fully erase the exportable data and digital assets you were holding for them.

Switching clock phases, maximum duration in days
Customer notice period (cap)60 days
Default transition/export period30 days
Minimum data retrieval window30 days
Transition, if extended for technical infeasibility210 days

Source: Regulation (EU) 2023/2854, Articles 25 and 30; law firm implementation guidance (Maples Group, Greenberg Traurig, 2025–2026)

The contract detail that catches teams off guard: you're not allowed to discover new "non-exportable" categories of data mid-switch. The Data Act requires that contracts specify, in advance, exactly which data and digital assets are exportable. If your terms of service are silent on this today, that's not a neutral default — it's a gap you'll be negotiating under pressure the first time an enterprise customer's legal team actually invokes the switching right, instead of on your own schedule now.

The fee ban has a date, and it's not far off

Through January 11, 2027, you can still charge for a switch — but only "cost-covering" charges, meaning the actual expense of performing the migration, disclosed and agreed in advance. Markup, penalty pricing, or anything framed as a deterrent doesn't qualify, even if it's dressed up as an infrastructure or support fee. From January 12, 2027, the Data Act prohibits charging anything at all for a customer-initiated switch, including data egress charges specifically — the fee structure that's functioned as the main practical lock-in mechanism for cloud and SaaS vendors for the better part of two decades.

Enforcement runs through individual member states rather than a single EU body — Ireland's ComReg and Germany's Bundesnetzagentur are among the designated regulators — but the penalty ceiling is GDPR-scale: up to 4% of annual turnover or €5 million, whichever is higher. That's not a rounding-error fine for a company doing real ARR in the EU, and it's the same order of magnitude that's made GDPR enforcement something legal teams actually track rather than dismiss.

One honest caveat: some of the finer print here is still moving. The EU's Digital Omnibus package, under negotiation through mid-2026, proposes clarifying exactly which early-termination penalties survive the fee ban and tightening the legacy-contract exemptions for smaller providers. The January 2027 date and the core switching mechanics aren't in dispute in that process — the ambiguity is around edge cases, not the deadline itself — but it's worth checking the current text before you finalize new contract language rather than working from a static reading of the 2024 regulation.

Does this actually reach your SaaS company

If your product is a hosted subscription and an EU business customer pays you to run their data on your infrastructure, you're a data processing service under the Act's definition — company size doesn't take you out of scope on its own. The relief that does exist is narrower and contract-dated: SME and small mid-cap providers of non-infrastructure services get an exemption specifically for contracts signed before September 12, 2025, and providers of heavily customized services can get a full exemption for the life of a pre-2025 contract. Sign or renew after that date, and none of that relief applies — you're in the same regime as a hyperscaler, just with a smaller customer base asking to exercise the right.

That's the detail worth flagging to whoever owns your EU contracts this quarter: every renewal you paper after September 2025 resets the clock on any exemption you might have been relying on.

Building this into a flow you already have

None of this requires a parallel product. It slots into the same account-lifecycle work most SaaS teams already own — the same systems that handle a cancellation flow or a data-deletion pipeline just get a new trigger and a new clock to track.

  • Get the exportable-data list into your contract now, not during a live switch. Waiting until a customer invokes the right means negotiating scope under a deadline instead of on your own terms.
  • Log the notice date the moment it comes in. The two-month notice cap and the 30-day transition period both start from a specific timestamp — treat it like the webhook-triggered clock we described for GDPR erasure requests, not a ticket that sits in a queue.
  • Separate switching requests from your retention motion entirely. A customer exercising a statutory switching right isn't a save-flow candidate, and routing the request through a discount offer or an exit survey first is the same mistake we flagged with the EU withdrawal button — it can itself become the compliance failure.
  • Build the export as a self-serve action where you can. A support ticket that requires someone on your team to manually assemble an export doesn't scale past a handful of requests a year, and it's a slow way to blow through a 30-day window on a busy quarter.

This kind of switching-cost conversation is exactly the signal we described in our piece on vendor consolidation churn — a procurement or IT contact asking pointed questions about data export and API access is often the first sign a comparison sheet is already being built. It's also the kind of gap that shows up in a security or vendor-risk review well before a customer ever gets near your cancellation flow. Treating the Data Act's switching clock as a compliance checkbox misses that it's also a leading indicator: the accounts asking about it are the ones actively pricing out what it would cost to leave. If you're tracking how those departures move your numbers, it's worth running them through a churn calculator separately from ordinary cancellations — a regulatory switch and a subscriber who just stopped finding value are different problems, even when they both end the same way on your revenue line.

Frequently asked questions

Does the EU Data Act apply to SaaS companies, or only cloud infrastructure providers like AWS?+

It applies to SaaS. The Data Act defines "data processing services" broadly enough to cover infrastructure, platform, and software-as-a-service alike — the European Commission's own implementation guidance specifically says providers of platform and software services have to make open interfaces available for switching. If your product runs as a hosted subscription and a customer can ask to take their data and leave, you're a data processing service under the Act, not just the hyperscalers underneath you.

When did the EU Data Act's cloud-switching rules actually take effect?+

The Data Act itself entered into force on January 11, 2024, but Chapter VI — the switching and interoperability obligations — only became applicable on September 12, 2025. That's the date that matters for compliance purposes, and it's also the cutoff the Act uses to decide which contracts get transitional relief, since contracts signed before that date get treated differently than ones signed after.

When do cloud-switching fees actually go away?+

January 12, 2027. Until then, providers can still charge switching costs, including data egress charges, but only up to the actual cost of performing the switch — no markup, no penalty pricing. From that date on, the Data Act prohibits charging anything at all for a customer-initiated switch to another provider or to on-premises infrastructure. Standard subscription fees and proportionate early-termination charges for ending a fixed term early are a separate matter and aren't banned by this provision.

Is my small SaaS company exempt because of its size?+

Not automatically, and this is the detail that trips people up. There's no blanket small-business exemption from the switching obligations. What exists is narrower: SME and "small mid-cap" providers of non-infrastructure data processing services get relief specifically on contracts signed before September 12, 2025, and providers of heavily customized services can get a full exemption for the life of a pre-2025 contract. Any contract you sign or renew after that date is in scope regardless of your headcount or revenue.

Try CancelFlow

Stop losing subscribers today

One script tag. One function call. A live cancellation flow in under 10 minutes.

Start free trial →
← All postsHome