In a little over three weeks, on 12 September 2025, the cloud-switching provisions of the European Union’s Data Act become applicable. For the first time, EU cloud customers will have enforceable legal rights to move their data and workloads between providers — and cloud providers will carry binding obligations to enable that movement and to dismantle the technical and commercial barriers that have historically made switching difficult. This is one of the more consequential pieces of cloud regulation Europe has produced, and the weeks before the deadline are the right moment for both providers and customers to assess where they stand.
What the Data Act Requires
The Data Act entered into force on 11 January 2024 with a roughly twenty-month implementation runway, which is what brings us to the September 2025 applicability date. We covered the broader scope and intent of the regulation when it took effect in our analysis of the Data Act’s cloud-switching provisions; the focus here is narrower and more immediate — the obligations that crystallize on the deadline and what organizations should do about them now.
The cloud-switching chapter of the Data Act is built around a set of customer rights and corresponding provider duties:
The right to switch. Customers of data-processing services — cloud infrastructure, platform, and software services fall within scope — have the right to switch to a different provider, or to move to on-premises infrastructure, and providers must facilitate that switch. The right is structural: it cannot be contracted away.
Removal of barriers. Providers are required to remove pre-commercial, commercial, technical, contractual, and organizational obstacles that prevent customers from terminating a service, concluding a contract with a different provider, and porting their data and digital assets. This is the provision with the broadest practical reach, because it targets the accumulated friction — not any single barrier — that keeps customers in place.
Contractual terms. Contracts must include clear terms covering the switching process, the assistance the provider will give, the maximum notice and transition periods, and the formats in which data will be made available. Vague or hostile exit terms are no longer permissible.
Phasing out switching charges. The Data Act requires the progressive reduction and eventual elimination of the egress and switching fees that have been a primary economic barrier to leaving a provider. The regulation sets out a transition under which such charges are reduced and then withdrawn, so that the cost of moving data out ceases to function as a lock-in mechanism.
Interoperability and portability. Providers must support functional equivalence and make reasonable efforts to enable interoperability, providing data and assets in structured, commonly used, machine-readable formats so that a customer can actually use them with a different provider rather than receiving an unusable export.
The Market Has Already Moved
One reason the deadline arrives with less drama than it might have is that parts of the industry anticipated it. The egress-fee question, in particular, saw movement well before the applicability date. In early 2024, Google announced it would waive egress charges for customers leaving its platform, explicitly citing the Data Act, and the other major providers followed with comparable free-exit-migration arrangements within weeks. The most economically significant barrier — the prohibitive bill for moving large volumes of data out — has therefore been substantially eroded at the major providers in advance of the legal requirement.
This is a recurring pattern in regulation of this kind: the credible prospect of binding rules shifts behavior before the rules bite. But anticipatory compliance on one provision does not equal full compliance across all of them. The egress-fee waivers address the most visible barrier; the obligations around contractual terms, format portability, interoperability efforts, and the removal of the subtler organizational and technical obstacles are broader and harder to satisfy with a single announcement.
What Customers Should Do Before the Deadline
For organizations consuming cloud services in the EU, the deadline is an opportunity to convert new rights into actual optionality. Rights that are never exercised provide little leverage. The practical preparation:
- Review existing contracts against the new requirements. Identify where current agreements fall short of the Data Act’s switching, notice-period, and format obligations. Providers should be updating terms to comply; customers should verify that the updated terms are present and adequate, and raise the gaps where they are not.
- Map your actual switching cost. The legal removal of barriers does not by itself make a given workload portable. Application coupling to provider-specific managed services remains a technical reality the Data Act does not erase. Use this moment to assess, workload by workload, how portable your estate actually is — the regulation lowers the externally imposed barriers, but the architectural ones are still yours to manage.
- Exercise the data-export rights as a test. The surest way to know whether a provider’s portability is real is to try it. Requesting a structured, machine-readable export of a representative dataset — and confirming it is usable elsewhere — turns an abstract right into verified capability.
- Treat the new leverage as negotiating capital. Enterprise cloud contracts are renegotiated periodically. The Data Act strengthens the customer’s position by making the threat of switching more credible. Organizations should factor this into renewal discussions rather than letting the new rights sit unused.
What the Deadline Does Not Solve
It is worth being clear-eyed about the limits. The Data Act lowers the legal and commercial barriers to switching; it does not make proprietary platforms interoperable by fiat. An application built deeply on one provider’s serverless functions, proprietary database, and managed services will still require substantial re-engineering to run elsewhere — the regulation cannot legislate away architectural lock-in that the customer chose to incur. The deepest form of portability still comes from architectural decisions: using open, portable abstractions where switching optionality matters, rather than relying on regulation to rescue a fully coupled estate.
There is also the question of enforcement, which lies on the other side of the deadline and is therefore not something this analysis can assess. How vigorously the obligations are enforced, how providers’ compliance is judged in practice, and how the subtler barrier-removal requirements are interpreted will all be matters for the period after applicability begins. Those are stories to be written after 12 September, not before.
The Broader Significance
Set against the longer history of cloud computing, the Data Act represents a notable shift. For most of the cloud era, lock-in was treated as a fact of life — a cost of the convenience that hyperscaler platforms provide, and a source of leverage that providers were under no obligation to surrender. The Data Act reframes switchability as a customer right and a provider duty. Combined with the maturation of open, portable infrastructure that gives organizations a technical path to independence, the regulatory shift moves the European cloud market toward a structure in which customers retain genuine choice rather than being captured by their initial provider selection.
For infrastructure teams, the message in the weeks before the deadline is to prepare actively. The rights are arriving; their value depends on organizations being ready to use them. Review the contracts, map the real switching costs, test the export paths, and carry the strengthened position into the next round of negotiations. The barriers are coming down — the optionality is there for those who prepare to exercise it.
Further Reading
- European Commission — Data Act — the Commission’s official Data Act page, including the regulation text, timeline, and guidance on the cloud-switching provisions.
- European Commission Digital Strategy — Cloud Computing — broader EU cloud policy context surrounding the Data Act’s switching and interoperability requirements.