The EU Data Act applies from 12 September 2025. For SaaS providers, its most important rules are often in Chapter VI: providers of qualifying data processing services must remove obstacles to switching, put detailed exit terms in their contracts, make customer data exportable, and phase out switching charges.

Chapter VI is not limited to infrastructure clouds. It covers IaaS, PaaS and SaaS when the offering meets the Data Act definition of a data processing service. The regulation's separate connected-product chapters address access to data generated by connected products and related services; they are not a general data-sharing regime for every SaaS product.

Key dates

DateWhat changes
11 January 2024The Data Act entered into force; the transitional cap on switching charges began.
12 September 2025Most of the Data Act began to apply, including Chapter VI cloud-switching duties.
12 September 2026The Article 3(1) data-access-by-design duty applies to connected products and related services placed on the market from this date.
12 January 2027Switching charges, including one-off data-egress charges for switching, are prohibited.
12 September 2027Chapter IV's unfair-contract-term rules extend to certain older data-sharing contracts of indefinite or very long duration.

The 2027 transition for older contracts belongs to Chapter IV, which regulates unfair terms in business-to-business data-sharing contracts. It is not a general delay for Chapter VI switching duties. The Commission's January 2026 FAQ says a qualifying provider must bring its service contracts into line with Article 25.

Does Chapter VI apply to SaaS?

Yes, when the SaaS offering meets the definition of a data processing service. The service must:

  1. Be provided to a customer under a contract for the use of one or more data processing services.

  2. Enable ubiquitous, on-demand network access to a shared pool of configurable computing resources, including applications and services.

  3. Provide scalable and elastic resources that can be rapidly provisioned and released with minimal management effort or provider interaction.

The Commission's 2026 FAQ says this definition covers IaaS, PaaS and SaaS and does not distinguish among SaaS categories that satisfy those characteristics.

Not every online application is necessarily being used as a data processing service. The Commission distinguishes a customer using such a service as such from an end user merely consuming a function enabled by cloud infrastructure, such as listening to music or watching video. Providers should document the contractual customer, the service supplied, and how the offering meets each part of the definition instead of relying on the label “SaaS”.

What must a SaaS provider do for switching?

A provider of a qualifying service must remove pre-commercial, commercial, technical, contractual and organisational obstacles that prevent a customer from:

  • Ending the service contract after the permitted notice and switching process

  • Moving to a provider of the same service type

  • Moving exportable data and digital assets to on-premises infrastructure

  • Using several providers in parallel, where relevant

  • Porting data after using a free-tier offering

The source provider must give reasonable assistance, maintain continuity and security during the transition, disclose known continuity risks, and cooperate in good faith with the customer and any destination provider. Its responsibilities are limited to its own services, contracts and commercial practices. The Data Act does not require it to rebuild the customer's service inside the destination provider's environment.

Which contract terms are mandatory?

Article 25 requires switching rights and provider duties to be stated clearly in a written contract that the customer can store and reproduce before signing. The contract must cover at least:

Contract termMinimum rule
Switching or exitThe customer can switch to another provider, move to on-premises infrastructure, or erase its exportable data and digital assets.
Notice periodNo more than two months before the switching process starts.
Transition periodNormally no more than 30 calendar days after the notice period.
Technical extensionIf 30 days is technically unfeasible, the provider must notify and justify this within 14 working days of the request; the alternative period cannot exceed seven months.
Customer extensionThe customer may extend the transition once for a period it considers more appropriate.
Portable materialAn exhaustive specification of portable data and digital assets, including at least all exportable data.
Provider exclusionsAn exhaustive specification of internal data excluded to protect provider trade secrets, without impeding or delaying switching.
RetrievalAt least 30 calendar days after the agreed transition ends.
ErasureFull erasure of covered exportable data and customer-related digital assets after retrieval, or after a later agreed period, once switching succeeds.
ChargesClear switching-charge terms consistent with Article 29.

The provider must also support the customer's exit strategy and publish information about its switching procedures, porting methods, formats, restrictions and known technical limitations. Its contract must point to an up-to-date online register describing available data structures, formats, standards and open interoperability specifications.

The Commission published voluntary standard contractual clauses for cloud contracts in November 2025. They include modules for switching and exit, termination, security and business continuity. They can help with drafting, but they do not replace a provider's responsibility to check the binding regulation and its own service design.

What data must be exportable?

“Exportable data” includes input and output data and metadata directly or indirectly generated or co-generated by the customer's use of the service. It excludes provider or third-party material protected by intellectual property rights or trade secrets.

“Digital assets” are elements the customer has a right to use independently of the service contract and needs to use its data in the destination environment. Depending on the service, these can include configuration metadata, security settings, access-control information, applications, virtual machines or containers.

For SaaS and PaaS, the provider must make open interfaces available. When no relevant standard or common specification is yet listed in the EU repository, the provider must, on request, export all exportable data in a structured, commonly used and machine-readable format when the customer switches between services of the same type. Once applicable standards or specifications are listed, the provider must meet the Data Act's compatibility timetable.

Does SaaS require functional equivalence?

No. Article 30(1)'s duty to facilitate functional equivalence applies to IaaS, not SaaS or PaaS.

SaaS and PaaS providers still have technical duties: open interfaces, export in the required format, and compatibility with applicable harmonised standards or open interoperability specifications once they are published through the EU repository. These obligations do not make a source provider responsible for recreating the service in a destination provider's environment.

When are switching and egress fees banned?

Until 11 January 2027, a provider may impose reduced switching charges only up to the costs directly linked to the switching operation. From 12 January 2027, it may not charge the customer for the switching process, including one-off data egress used for that switch.

There is a specific distinction for in-parallel use, such as an ongoing multi-cloud setup. Article 34 allows providers to pass on continuing data-egress costs for in-parallel use even after 12 January 2027, but not to charge more than the costs incurred. A contract and billing model should distinguish a one-off switch from ongoing parallel operation.

Are custom-built and test services exempt?

Article 31 provides a lighter regime where the majority of a service's main features is custom-built for one customer's specific needs, or all components were developed for that customer, and the service is not offered broadly through the provider's catalogue.

That is not a complete Chapter VI exemption. The current regulation removes only specified duties for these services, including the switching-charge rule and parts of the functional-equivalence and standards regime. Other duties remain, including relevant contract, open-interface and structured-export requirements. The provider must tell the prospective customer before contracting which Chapter VI duties do not apply.

A non-production service supplied only for testing and evaluation for a limited time is outside Chapter VI. An ordinary standardised, multi-tenant SaaS offering cannot use the custom-built regime merely because its configuration was tailored for a customer.

Is there an SME exemption?

Under the Data Act currently in force, Chapter VI has no general exemption for SME providers. Do not import the micro- and small-enterprise relief from the connected-product chapters into the cloud-switching rules.

The Commission's Digital Omnibus proposal of 19 November 2025 would introduce targeted relief for SME and small-mid-cap providers and a lighter regime for certain custom-made services, including some older contracts. As of 15 August 2026, those changes remain in the EU co-legislative process and are not the current rule. Monitor the final adopted text before changing a compliance position.

How do the connected-product rules differ?

Chapters II and III concern data generated through connected products and related services. They give users access to readily available product and related-service data and can require data holders to share it with a third party chosen by the user.

Those chapters do not automatically apply merely because a company sells application SaaS. They become relevant when the business manufactures a connected product, provides a related service that affects the product's behaviour, or acts as a data holder or recipient in the covered data-sharing relationship. Micro and small enterprises receive specified relief in this part of the regulation, subject to the detailed conditions.

The Article 3(1) obligation to design connected products and related services so data are directly accessible where relevant and technically feasible applies to products and services placed on the market from 12 September 2026.

Other duties for data processing services

Chapter VII requires providers to take adequate technical, organisational and legal measures against unlawful third-country governmental access to or transfer of non-personal data held in the EU.

Providers must publish and keep current:

  • The jurisdiction governing the ICT infrastructure used for each service

  • A general description of measures taken to prevent unlawful governmental access or transfer that would conflict with EU or Member State law

The contract for each data processing service must identify the website where that information is published. These rules address governmental access to non-personal data; they do not replace GDPR rules for personal data or ordinary business-to-business international transfers.

A practical applicability check

Ask these questions in order:

  1. What service is the customer contracting to use? Separate a data processing service from a consumer-facing function merely enabled by cloud infrastructure.

  2. Does it meet the Article 2(8) definition? Record the on-demand, shared-pool, scalability, elasticity and rapid-provisioning characteristics.

  3. Which delivery layer is it? Distinguish SaaS or PaaS open-interface duties from IaaS functional equivalence.

  4. What can be exported? Inventory input, output, metadata and customer-controlled digital assets, plus any justified IP or trade-secret exclusions.

  5. Can the customer actually leave? Test notice, transition, retrieval, continuity, erasure and assistance against Article 25.

  6. What is being charged? Separate switching and one-off egress from continuing egress for in-parallel use.

  7. Is a special regime claimed? Prove the custom-built or limited testing conditions rather than relying on bespoke configuration or an SME label.

  8. Does connected-product data exist? Analyse Chapters II and III separately from the cloud-switching assessment.

SaaS readiness checklist

  • Update customer contracts with the Article 25 switching and exit terms.

  • Publish switching procedures, technical limitations, formats and the online data-format register.

  • Build and test a complete export of input, output and customer-use metadata.

  • Expose documented open interfaces for portability.

  • Define the operational workflow for two-month notice, 30-day transition, retrieval and erasure.

  • Preserve security and business continuity throughout a switch.

  • Remove switching and one-off switching-egress charges by 12 January 2027.

  • Distinguish at-cost continuing multi-cloud egress from prohibited switching charges.

  • Publish the infrastructure-jurisdiction and governmental-access safeguards disclosure.

  • Track EU repository standards and the final outcome of the Digital Omnibus proposal.

  • GDPR overview — personal-data access, portability and international transfers continue to apply

  • B2B SaaS SME profile — the provider archetype most likely to need the Chapter VI assessment

  • ICT third-party risk — the buyer-side cloud contract and exit stack


This briefing explains the official sources reviewed on 15 August 2026. It is not legal advice; confirm service-specific conclusions against the current law and guidance.