Adapted from the Polish article, originally published on 06 October 2026. The English version was published on 06 October 2026.
Suppose your company is replacing its customer support platform. Procurement has approved the new tool and the operations team is ready. The existing provider offers an export button. It produces ticket text, but leaves out attachments, links between records and the change history.
You can open the file, but it will not reconstruct your support operation. The team still needs to establish how the missing elements will move.
The Data Act requires providers of qualifying data processing services, which can include SaaS, to remove obstacles to switching. It sets requirements for contracts, timelines, assistance and data portability. It does not promise that your new application will have identical features or that the old provider will build an integration with a competitor.
What you will learn
- which SaaS services fall within the switching rules;
- how to define exportable data and digital assets;
- how notice, transition and retrieval periods fit together;
- what changes for switching charges on 12 January 2027;
- how to handle exceptions and divide migration responsibilities.
In brief
- Chapter VI has applied since 12 September 2025. Assess the service against the statutory definition rather than relying on its SaaS label.
- Contracts must address the data and assets that can move, the procedure, assistance, timing and deletion after the process.
- The notice period before switching starts cannot exceed two months. The transition normally cannot exceed 30 calendar days, subject to exceptions.
- A separate retrieval period must last at least 30 calendar days after the transition ends.
- For services subject to Article 29, switching charges disappear on 12 January 2027. Ordinary service fees and legally permissible early termination charges are separate issues.
Does the Data Act cover every SaaS subscription?
It covers services with the characteristics of a data processing service, not every website sold on subscription. The definition concerns network access on demand to a shared pool of configurable, scalable and elastic computing resources that can be rapidly provisioned and released with minimal provider interaction. Those resources can include applications.
For the support platform, examine what the customer actually purchases and controls: an application environment, access and scalable use of the service. Watching videos through a streaming platform does not automatically make the viewer a customer of a data processing service for these purposes. The Commission’s FAQ, particularly questions 52 and 58a, explains this distinction.
The rules cover providers serving customers in the EU irrespective of where the provider is established. A US headquarters does not by itself remove the obligation. The relevant starting points are Article 1(3)(f) and Article 2(8) of the Data Act.
Do not import small-manufacturer exceptions from the connected-product provisions into the cloud switching chapter. Proposed additional exemptions for smaller cloud providers in the Digital Omnibus are also separate from current law. On 6 October 2026, the relevant legislative procedure still awaits a committee decision.
What should the customer be able to export?
Exportable data includes input and output data, including metadata generated directly or indirectly through the customer’s use of the service, subject to statutory exclusions. Metadata describes other data: the link between an attachment and a ticket, for example, or when a record was created. Losing it can make a dataset much less useful.
For the support platform, review ticket content, attachments, identifiers, relationships, status and change history. That is a product-specific assessment list, not a statutory checklist requiring identical fields in every SaaS export.
The contract must exhaustively identify the categories of data and digital assets that can move. Digital assets are elements needed to use the data in the new environment where the customer has a right to use them independently of its contract with the source provider. They may include configuration or applications, but the actual rights and service architecture matter.
There are exclusions protecting intellectual property and trade secrets of providers and third parties. A customer does not automatically obtain the SaaS platform’s source code. The contract must also identify internal-operation data categories excluded where disclosure risks breaching the provider’s trade secrets; those exclusions must not impede or delay switching. These limits appear in the definitions and Article 25 of the Data Act.
Is a CSV file enough?
Judge the format together with its contents, documentation and practical usability. CSV can work well for a simple table. A ticket system also needs a way to transfer the relevant attachments, relationships and history.
For SaaS, the Act requires open interfaces to facilitate switching, available without charge. An interface such as an API must include enough information to develop software that communicates with the service. Compatibility obligations for specified interoperability standards depend on their publication in the EU repository and the applicable deadline. Where services of the same type have no such published standards, the Act provides for export of all exportable data on request in a structured, commonly used and machine-readable format. See Articles 26 and 30.
Before signing, ask for an export sample, field documentation, the attachment retrieval method and API limits. Run a trial import. This is a practical recommendation, not a universal statutory requirement to perform a particular test.
How long can a SaaS switch take?
Separate three periods. A promise to retain data for 30 days does not tell you when migration starts or when the service contract ends.
| Stage | Rule | Contract decision |
|---|---|---|
| Notice | No more than two months before the switching process starts | Request channel, receipt date and migration start |
| Transition | Without undue delay, normally no more than 30 calendar days | Assistance, continuity, security and cutover plan |
| Retrieval after transition | At least 30 calendar days | Access, deletion date and confirmation of completion |
If a 30-day transition is technically unfeasible, the provider must notify the customer within 14 working days of the switching request, justify the technical limitation and state an alternative transition period of no more than seven months. A support backlog alone is not that justification. The contract must also give the customer a right to extend the transition once for a period it considers more appropriate for its purposes. These requirements come from Article 25.
The contract must provide for termination after successful switching. If the customer chooses deletion without migration, termination takes place at the end of the maximum notice period.
For the support platform, migrate older tickets and test the import first. Then schedule the final export of new tickets and the integration cutover. Assign someone to validate completion. The later retrieval window is not automatically a promise to keep the entire application running on its previous terms.
Which charges end in January 2027?
For services subject to Article 29, switching charges before 12 January 2027 cannot exceed the provider’s costs directly linked to that switching process. From that date, those charges are prohibited. They include data egress associated with the switch: transferring data out of the provider’s infrastructure.
Ordinary subscription fees and early termination charges fall outside the definition of switching charges. Whether they are permissible, and in what amount, requires a separate assessment under the contract and applicable law. The January deadline therefore does not automatically release a customer from every payment under a multi-year commitment. The provider must disclose the relevant charges before the contract is concluded. See Article 2(36) and Article 29.
Not every transfer between clouds is a switch. Continuous parallel use of services can involve a different treatment of egress charges even after that date. The Commission distinguishes parallel use in FAQ question 54.
Custom-built services and test versions have different rules
A negotiated contract does not itself exempt a SaaS product. The special regime concerns services where most main features were custom-built for an individual customer, or all components were developed for that customer, and the service is not offered at broad commercial scale through the provider’s catalogue.
The exemption covers specified obligations, including Article 29 on switching charges. Other obligations remain, including contract terms, information, open interfaces and export. Customer branding, role configuration or a few integrations added to a standard support tool do not automatically satisfy the exception.
A separate exemption excludes non-production services supplied for testing and evaluation for a limited period from Chapter VI. Before contracting, the provider must explain which obligations do not apply. Article 31 sets these boundaries.
Who rebuilds workflows, and when are old copies deleted?
The Data Act does not generally require a SaaS provider to recreate its product inside a competitor’s environment. The specific duty to facilitate functional equivalence concerns infrastructure services, IaaS. SaaS has different technical obligations, including interfaces and export. The source provider’s responsibilities concern its own services. Articles 24 and 30 and the Commission’s FAQ question 58b explain the distinction.
The company replacing its support platform must therefore assign responsibility for rebuilding automations, permissions and integrations in the new tool. Agree the incoming format, import timetable and responsibilities with the destination provider too.
Schedule deletion after successful switching and the retrieval period, or a later agreed period, under the contract required by the Act. Where the source provider processes personal data on the customer’s behalf, GDPR Article 28(3)(g) adds a separate requirement: the processing agreement must provide for return or deletion at the controller’s choice after the relevant services end, and deletion of copies unless EU or Member State law requires storage. Align the migration timetable with those duties rather than scheduling deletion before anyone has checked the import.
Agree an exit plan while you still want to use the product
For the support platform, a useful contract schedule should let the team plan migration without discovering the product’s basic data structure in its final week. Cover:
- transferable data and asset categories, with justified exclusions;
- formats, documentation, interfaces and attachment handling;
- notice, transition, retrieval and deletion dates;
- responsibility for export, import, validation and cutover;
- assistance, service continuity, security and the different cost categories.
This complements your SaaS SLA and availability measurement. For AI-enabled tools, connect the exit plan with vendor assessment, retention and data flows.
If you sell SaaS or are negotiating a purchase, our technology legal services can help check whether the proposed exit terms work with the product and its data. Contact Lis.Legal.
Sources and legal status
Checked on 6 October 2026.
- Data Act, Regulation 2023/2854: definitions, Chapter VI and Article 50. Official English text from the EU Publications Office.
- Commission FAQ, version 1.4 of 22 January 2026: SaaS scope and limits of migration duties. The FAQ supports interpretation; the legislation controls the requirements.
- GDPR: processor duties when services end.
- Digital Omnibus procedure 2025/0360(COD): proposed changes, distinguished from current obligations.