In brief
- Regulation: Data Act.
- Publishers offering data processing services (cloud, SaaS) are directly targeted by obligations relating to provider switching and data portability.
- Facilitating provider switching.
- Removing exit fees.
- Ensure portability.
- Penalties are set by each Member State; they must be effective, proportionate and dissuasive, with the possibility of alignment with GDPR ceilings for breaches involving personal data.
Regulatory deadlines
The key dates of this regulation.
January 2024
Entry into force
In forceSeptember 2025
Application
In forceWhat is the Data Act about?
The Data Act pursues two objectives: giving users access to the data they generate and streamlining the data services market by removing proprietary barriers. It complements the GDPR without replacing it: the GDPR targets personal data, while the Data Act governs access to and sharing of data, whether personal or not.
It targets both manufacturers of connected products and providers of data processing services.
Is the 'Software Publishers' sector concerned?
Publishers offering data processing services (cloud, SaaS) are directly subject to the obligations on provider switching and portability. Publishers of connected products are covered under the provisions on user access to generated data.
A standard SaaS vendor is therefore in scope as soon as it stores and processes data on behalf of its customers, regardless of its sector.
Detailed obligations
Facilitate vendor switching.
Enable a client to migrate to another provider or to their own infrastructure, with reasonable assistance and timelines.
Remove egress fees
Progressively reduce and then eliminate switching costs, in accordance with the timeline set out in the regulation.
Ensure portability
Provide export mechanisms in usable formats and promote interoperability.
Ban abusive clauses
Revise contractual terms to remove data-sharing clauses deemed abusive, particularly with respect to SMEs.
Informing users
Document the data generated, the access modalities and the associated rights.
Sanctions & risks
Penalties are set by each Member State; they must be effective, proportionate and dissuasive, with the possibility of alignment with GDPR ceilings for breaches involving personal data.
Beyond sanctions, non-compliance becomes a commercial handicap: portability is now a purchasing criterion, and proprietary lock-in a grounds for exclusion.
Application timeline
- 1Entry into force. The regulation entered into force in early 2024.
- 2Application. The majority of obligations apply from 12 September 2025; the removal of switching fees follows a phased timeline.
Common mistakes in the sector
- 1Prohibitive exit fees. Maintaining high fees that run counter to the objective of switching.
- 2Proprietary formats. Making export impossible or unusable due to the absence of an open format.
- 3Abusive clauses. Retaining unbalanced data-sharing clauses.
- 4Confusion with GDPR. Assuming GDPR compliance is sufficient, when the Data Act adds its own distinct obligations.
Practical case
A SaaS vendor was charging high fees and only offering a partial export in a proprietary format. An SME client invoked the Data Act to migrate. The vendor implemented a full export in a standard format, revised its terms and conditions to remove exit fees, and documented a switching procedure — turning a regulatory constraint into a commercial argument for transparency.
Compliance roadmap
- 1
Inventorying data. Map the data generated and stored by the service.
- 2
Tooling the export. Implementing portability and interoperability mechanisms.
- 3
Revising contracts. Adapting the T&Cs and exit clauses, removing unfair clauses.
- 4
Document switching. Formalise supplier-switching procedures.
- 5
Inform. Informing customers of their new rights and the methods of access.
Frequently asked questions
No, it complements it: GDPR targets personal data, the Data Act governs access to and sharing of data, whether personal or not.
Take action on Data Act
Free assessment or a chat with an expert dedicated to software publishers.
They already trust us
See how organisations in the software publishers sector secured their compliance with DCO.