Since September 2025, the EU Data Act has been fully applicable across the European Union.
For international SaaS and cloud providers offering services to European customers, this is not a marginal regulatory development. The Data Act directly regulates switching, data access, interoperability and certain third-country government access requests.
These requirements can affect core provisions of SaaS agreements — and, if not properly addressed, the economics of the subscription model itself.
Until recently, many aspects of SaaS exit arrangements were primarily a matter of contract negotiation, subject to general contract and data protection law.
The Data Act changes this approach.
Mechanisms such as switching, migration, access to data and interoperability are now subject to specific regulatory requirements.
Depending on the service concerned, providers may notably be required to:
For international providers using global SaaS or cloud agreements, these requirements therefore need to be assessed against existing contractual documentation and operating processes.
The Data Act significantly strengthens customers’ ability to move from one data processing service to another.
Providers may no longer rely on unjustified contractual, commercial or technical barriers to prevent or discourage switching.
This has practical consequences for:
For providers operating across multiple jurisdictions, EU switching requirements may therefore require specific adaptations to global contractual and operational processes.
But switching should not be confused with an unrestricted right to terminate any fixed-term subscription without contractual consequences.
A SaaS provider may still need to protect the economics of a committed subscription term while ensuring that its exit and migration arrangements comply with the Data Act.
See SaaS Switching under the EU Data Act: Protecting Contractual Commitments and the Subscription Model.
Historically, migration and reversibility services could form part of the provider’s commercial model.
The Data Act substantially restricts this approach.
Providers need to distinguish between switching activities covered by the regulation and additional services that may legitimately remain separately chargeable.
This distinction needs to be reflected consistently in:
For international providers, particular care is required where a global pricing model includes standard exit, migration or professional-services charges that may not operate in the same way for EU customers.
The Data Act also introduces interoperability requirements for certain data processing services.
These obligations are not purely technical.
Information concerning interfaces, standards, portability and switching capabilities may need to be reflected in the contractual framework offered to customers.
Legal, product and technical teams therefore need to ensure that the commitments contained in the agreement correspond to the provider’s actual architecture and capabilities.
For global providers, this is particularly important where EU contractual documentation is derived from technical standards developed for a wider international customer base.
The Data Act also strengthens rights relating to access to and use of data.
This goes beyond GDPR data portability.
The relevant data may include non-personal data generated or co-generated through use of a connected product or related service, depending on the circumstances and the applicable provisions of the Data Act.
Providers therefore need to determine:
The contractual framework needs to remain consistent with the provider’s technical ability to identify, extract and transfer the relevant data.
The Data Act contains safeguards concerning certain requests by third-country public authorities for access to non-personal data held in the European Union.
This issue deserves particular attention from international providers.
A SaaS or cloud provider may itself be subject to legislation outside the European Union, or may rely on infrastructure providers or other subcontractors that are.
The provider therefore needs an internal framework for assessing relevant requests, applicable international agreements and potential conflicts of law, while maintaining appropriate documentation and safeguards.
This is not simply a contractual issue.
It may require coordination between EU legal requirements, the provider’s global policies and the laws applicable to its corporate group or infrastructure providers.
Although the Data Act is an EU regulation, enforcement is organised through competent authorities designated at national level.
International providers should therefore avoid treating EU compliance as a purely centralised exercise.
Their global contractual framework needs to comply with the Data Act, while local requirements and enforcement arrangements may also need to be considered in the Member States in which they operate.
In France, this can notably involve the French regulatory framework applicable to switching and data processing services.
For providers entering the French market, these issues form part of the broader legal assessment described in Dowing Business in France: A Legal Guide for International SaaS and Technology Providers.
A Data Act review should not be limited to adding a new reversibility clause to a SaaS agreement.
Effective compliance requires consistency between:
For global providers, the key question is also how to implement the necessary EU adaptations without unnecessarily fragmenting the global contractual model.
The objective should be to identify what genuinely needs to change for EU customers and to integrate those changes into the existing framework as efficiently as possible.
The Data Act does not undermine the SaaS model.
It does, however, restrict certain practices that may previously have been used to manage customer exit or switching.
Providers therefore need to distinguish carefully between regulatory switching obligations and the commercial mechanisms used to structure a subscription.
A well-designed contractual framework can comply with customers’ switching rights while continuing to protect legitimate fixed-term commitments, pricing structures and the overall economics of the service.
Withlaw assists international SaaS and cloud providers in assessing and implementing EU Data Act requirements, including:
The objective is to achieve EU compliance while preserving, as far as possible, the consistency and economics of the provider’s global contractual model.