Back to insights
Cloud 10 September 2026

What is the EU Data Act? Your right to switch cloud providers

EU Data Act cover with a map of Europe and data flows

Since 12 September 2025, the European Data Act has applied in all EU member states. For cloud users, it is the most important legal change in years: the regulation gives you an enforceable right to switch cloud providers, and obliges providers to make that practically possible.

Yet we notice that many organizations mainly know the law as "something about IoT data". For most companies, the cloud chapter is the part they will feel most directly, in their contracts, costs and negotiating position.

What is the EU Data Act?

The Data Act, Regulation (EU) 2023/2854 in full, is a European regulation that defines who has access to data and what they may do with it. It was adopted at the end of 2023, entered into force on 11 January 2024 and has applied since 12 September 2025. Because it is a regulation and not a directive, it applies directly across the EU without transposition into Belgian law.

The law covers more than cloud. It also regulates who may use data from connected devices and under which conditions public authorities may request data in exceptional situations. But the chapter on "data processing services", cloud and edge services, affects almost every organization: it contains the rules for switching between cloud providers.

What changes in your cloud contract?

The Data Act imposes concrete obligations on cloud providers that must be included directly in your contract:

  • Switching clauses are mandatory. Your contract must set out in writing how you can switch to another provider or to your own infrastructure.
  • Maximum two-month notice period. You can announce the switch with a notice period of no more than two months.
  • A thirty-day transition period. During that period, the provider must cooperate with the migration. Only if this is technically not feasible may that period be extended.
  • Data export in a usable format. You have a right to your data and digital assets in a machine-readable format, so you can continue elsewhere.

For anyone who has ever tried to terminate a cloud contract, this is a fundamental shift: what used to be a provider's goodwill is now a customer's right.

Switching charges disappear

Perhaps the most tangible consequence: the cost of leaving is being reduced. Since September 2025, providers may only charge cost-based fees for a switch, with no margin on your departure. From 12 January 2027, they may no longer charge any switching charges at all.

That also affects the notorious egress costs: the fees large cloud platforms charge to get your own data out of their environment. Those costs often made migration prohibitively expensive before anyone had even looked at technical feasibility.

Protection against access from third countries

Less well known, but relevant for anyone working with sensitive data: the Data Act also requires providers to take reasonable technical, organizational and legal measures against unlawful access by authorities outside the EU to non-personal data.

That touches the same question as the US CLOUD Act, which can require US providers to hand over data to US authorities, even when that data is stored in a European data center. Organizations that want to remove that exposure completely end up looking at a sovereign European cloud environment.

Paper versus practice: your architecture determines whether you can really switch

A right on paper does not make a migration feasible. The Data Act requires providers to cooperate, but it does not solve technical vendor lock-in: an application deeply woven into proprietary services from one platform will not move in thirty days.

We see that in practice too. In migration projects from hyperscalers to European cloud environments, the real work is rarely moving servers. It is untangling dependencies that have grown over the years. The more cloud-independent an application is, the more the rights in the Data Act are worth in practice.

What should you do with it today?

Four practical steps turn the Data Act into a stronger position:

  • Review your cloud contracts. Do they contain the required switching clauses? Providers had to adapt their contracts, including existing ones.
  • Map dependencies per workload. Which applications rely on proprietary services, and which are already portable today?
  • Define an exit strategy for critical systems. Not because you necessarily want to leave, but because a credible alternative changes your negotiating position.
  • Include portability in every new architecture choice. Lock-in you do not build today does not have to be bought off later.

For organizations subject to NIS2, there is another layer: that legislation expects demonstrable control over suppliers, including cloud providers. You can read how to approach that on our page about NIS2 and ISO 27001 readiness.

The wind is behind you, but you still have to steer

The Data Act removes contractual and financial barriers that blocked switching for years. What remains is the technical reality of your own architecture. Organizations that have that in order can make cloud choices based on cost, control and compliance, not on what the current provider allows.

Is your cloud environment truly portable?

The Data Act gives you the right to switch. Whether that is practically possible depends on your architecture. We can assess it together.

Explore our European cloud approach