Software publishers · Data Act

Software publishers & Data Act: what changes for the cloud

The Data Act (EU Regulation 2023/2854) governs access to and sharing of data generated by connected products and services, and requires data processing services — cloud, SaaS, PaaS, IaaS — to facilitate switching between providers. It is a foundational text for any vendor offering cloud services. This guide details portability obligations, the elimination of switching fees, and the prohibition of abusive contractual clauses.

DPO / CISO team — Data Comply One Updated on 15 June 2026

In brief

  • Regulation: Data Act.
  • Publishers offering data processing services (cloud, SaaS) are directly targeted by obligations relating to provider switching and data portability.
  • Facilitating provider switching.
  • Removing exit fees.
  • Ensure portability.
  • Penalties are set by each Member State; they must be effective, proportionate and dissuasive, with the possibility of alignment with GDPR ceilings for breaches involving personal data.

Regulatory deadlines

The key dates of this regulation.

January 2024

Entry into force

In force

September 2025

Application

In force

What is the Data Act about?

The Data Act pursues two objectives: giving users access to the data they generate and streamlining the data services market by removing proprietary barriers. It complements the GDPR without replacing it: the GDPR targets personal data, while the Data Act governs access to and sharing of data, whether personal or not.

It targets both manufacturers of connected products and providers of data processing services.

Is the 'Software Publishers' sector concerned?

Publishers offering data processing services (cloud, SaaS) are directly subject to the obligations on provider switching and portability. Publishers of connected products are covered under the provisions on user access to generated data.

A standard SaaS vendor is therefore in scope as soon as it stores and processes data on behalf of its customers, regardless of its sector.

Detailed obligations

Facilitate vendor switching.

Enable a client to migrate to another provider or to their own infrastructure, with reasonable assistance and timelines.

Remove egress fees

Progressively reduce and then eliminate switching costs, in accordance with the timeline set out in the regulation.

Ensure portability

Provide export mechanisms in usable formats and promote interoperability.

Ban abusive clauses

Revise contractual terms to remove data-sharing clauses deemed abusive, particularly with respect to SMEs.

Informing users

Document the data generated, the access modalities and the associated rights.

Sanctions & risks

Penalties are set by each Member State; they must be effective, proportionate and dissuasive, with the possibility of alignment with GDPR ceilings for breaches involving personal data.

Beyond sanctions, non-compliance becomes a commercial handicap: portability is now a purchasing criterion, and proprietary lock-in a grounds for exclusion.

Application timeline

  • 1Entry into force. The regulation entered into force in early 2024.
  • 2Application. The majority of obligations apply from 12 September 2025; the removal of switching fees follows a phased timeline.

Common mistakes in the sector

  • 1Prohibitive exit fees. Maintaining high fees that run counter to the objective of switching.
  • 2Proprietary formats. Making export impossible or unusable due to the absence of an open format.
  • 3Abusive clauses. Retaining unbalanced data-sharing clauses.
  • 4Confusion with GDPR. Assuming GDPR compliance is sufficient, when the Data Act adds its own distinct obligations.

Practical case

A SaaS vendor was charging high fees and only offering a partial export in a proprietary format. An SME client invoked the Data Act to migrate. The vendor implemented a full export in a standard format, revised its terms and conditions to remove exit fees, and documented a switching procedure — turning a regulatory constraint into a commercial argument for transparency.

Compliance roadmap

  1. 1

    Inventorying data. Map the data generated and stored by the service.

  2. 2

    Tooling the export. Implementing portability and interoperability mechanisms.

  3. 3

    Revising contracts. Adapting the T&Cs and exit clauses, removing unfair clauses.

  4. 4

    Document switching. Formalise supplier-switching procedures.

  5. 5

    Inform. Informing customers of their new rights and the methods of access.

Frequently asked questions

No, it complements it: GDPR targets personal data, the Data Act governs access to and sharing of data, whether personal or not.

Take action on Data Act

Free assessment or a chat with an expert dedicated to software publishers.

They already trust us

See how organisations in the software publishers sector secured their compliance with DCO.

See testimonials