EU Data Act Makes Cloud Portability Mandatory
Cloud portability after the EU Data Act: Which exit clauses contracts need and how IT Ops can realistically calculate switching costs.
On 12 January 2027, switching fees for cloud services in the EU will be abolished-egress costs included. The EU Data Act transforms portability between providers from a voluntary gesture into a legal obligation. For IT operations, this means switching providers becomes a plannable process-if your architecture allows it.
Key Takeaways
- In effect since September 2025: The core rules of the EU Data Act have been applicable since 12 September 2025, including obligations for provider switching in cloud services.
- Switching fees end in 2027: From 12 January 2027, providers may no longer charge switching or egress fees. During the transition phase, only actual direct costs are permitted.
- The contract is the lever: Article 25 specifies which switching rights and provider obligations must be included in writing. Those who don’t review them risk forfeiting their rights.
Related:Lock-in on shaky ground / German hyperscalers
What the EU Data Act has required since September 2025
The EU Data Act has been in effect in its core provisions since 12 September 2025. For cloud services, it includes a dedicated chapter on provider switching. The core idea is simple: customers should be able to switch providers-or use multiple providers in parallel-without technical or contractual barriers effectively locking them in.
The regulation obliges providers to remove switching obstacles, support the transfer of data and digital assets, and aim for functional equivalence in infrastructure services. What was once a marketing argument for providers has now become an enforceable customer right.
Where exit barriers truly lie
Portability rarely fails due to a single issue. In practice, four barriers stack up. First, proprietary data formats that require effort to convert into a neutral format. Second, API dependencies on exclusive managed services that aren’t available with the next provider. Third, egress costs that make bulk exports expensive. Fourth, contractual clauses with long notice periods and unclear cooperation obligations.
The Data Act addresses these barriers from a legal perspective. The technical side remains the responsibility of your own architecture. A regulation can ban egress fees, but it can’t untangle a data landscape that has been locked into proprietary services over years.
Breaking free from data formats and API lock-in
The most effective exit protection is built before switching-during architecture design. Those who store data in open, documented formats and connect managed services via an abstraction layer structurally reduce switching costs. The trade-off is consciously forgoing the last few percentage points of convenience that a deeply integrated proprietary service offers.
For existing environments, an honest inventory is worthwhile. Which components are so deeply embedded with the provider that switching would require rebuilding them? These points are the real lock-in anchors-regardless of what fees the Data Act bans.
What Article 25 in the Contract Requires
Article 25 is the section that IT operations and procurement teams should read together. It specifies what a data processing service contract must include: the customer’s rights when switching providers, the provider’s obligations to cooperate, and the conditions of the transition-all documented and specified in advance.
In practice, this means reviewing existing contracts against these requirements and actively demanding the necessary clauses in new agreements. A switching right that isn’t clearly stated in the contract is difficult to enforce in a dispute, even if the regulation technically grants it.
What Applies from January 2027
January 12, 2027, is the hard deadline. From that day forward, providers may no longer charge switching or egress fees for changing providers. During the transition period before that, fees are permitted but limited to actual direct costs and must be disclosed upfront.
Two exceptions remain. Providers may continue to charge for switching services that go beyond the legal minimum. And egress fees for parallel multi-cloud usage will still apply, as this constitutes ongoing operations rather than a one-time migration. If you’re running a long-term multi-cloud setup, these costs should remain part of your budget.
Frequently Asked Questions
From when can my provider no longer charge switching fees?
Starting January 12, 2027, switching and egress fees for changing providers will be prohibited. Until then, providers may only bill for actual direct costs, which must be specified in advance.
Does the Data Act apply to SaaS or just infrastructure?
The switching rules apply broadly to data processing services, covering IaaS, PaaS, and SaaS. The requirement for functional equivalence is particularly relevant for infrastructure services, as these are most easily replaced with technically comparable alternatives.
Does the Data Act automatically solve my lock-in problem?
No. While the regulation lowers legal and financial barriers, it doesn’t eliminate technical dependencies. Proprietary data formats and deeply integrated managed services remain a challenge for your architecture.
What must be included in the contract under Article 25?
The customer’s switching rights, the provider’s cooperation obligations, and the conditions of the transition-all documented and specified in advance. It’s worth reviewing existing contracts against these requirements and actively demanding them in new agreements.
Do egress costs remain for multi-cloud setups?
Yes. The fee waiver applies only to provider switching as a one-time event. Egress fees for ongoing parallel multi-cloud operations will still apply and should remain part of your multi-cloud cost model.
Editor’s Picks
cloudmagazinAWS and Azure under EU supervision: Vendor lock-in is shakingcloudmagazinFinOps: Cutting cloud costs by 30 percent is realisticcloudmagazinMoving KRITIS to the cloud: What secures the migrationMore from the MBF Media Network
Digital ChiefsSovereign cloud: When the premium really pays offMyBusinessFutureGermany’s AI oversight now has an official addressSecurityTodayPost-quantum cryptography becomes mandatory in cloud certificationImage source: AI-generated (July 2026)

