
Starting January 12, 2027, cloud service providers in the EU will no longer be allowed to charge switching or data egress fees. The door is opening, but only those with the right architecture, data, and contracts in place will be able to walk through it. With less than 100 days to go until the deadline, we’ll show you what’s worth auditing now and how we can help.
The EU Data Act (Regulation (EU) 2023/2854, or simply the Data Act) is a key piece of European Union legislation for the data economy. While the GDPR focuses on the protection of personal data, the Data Act regulates who can access business and industrial data, who can use it, and under what conditions. As a regulation, it does not need to be transposed into national law: it is directly applicable in every member state.
The regulation entered into force in January 2024, and most of its provisions have been applicable since September 12, 2025 . Its main areas include:
One of the primary goals of the Data Act is to reduce vendor lock-in , ensuring that a company can freely switch cloud providers, migrate back to its own on-premise infrastructure, or use multiple providers simultaneously. To this end, the regulation mandatesthat cloud contracts may include a notice period of no more than two months , and that the transition must be supported by a 30-day transition period during which the provider must offer active support.
The phase-out of fees is gradual. Since September 2025, providers have only been allowed to charge their actual, direct costs for switching and egress fees. According to cloudmagazin.com's analysis , from January 12, 2027, cloud providers serving EU customers—whether IaaS, PaaS, or SaaS—will be prohibited from charging such fees altogether. This rule applies equally to American hyperscalers and European providers. An important exception: penalties for the early termination of fixed-term contracts remain enforceable.
Egress fees were the most visible element of vendor lock-in, but not the most powerful. Free migration is of little value if an application is tightly integrated with a provider's proprietary services and the exported data can only be read by the original tool. The real constraints lie in three areas:
Article 20 of the GDPR regulates who receives the data; the Data Act regulates how much switching costs. However, how technically feasiblethe switch is, neither regulation solves for us—that is an architectural issue.
Our Big Data & Cloud team for over 20 years we have been designing, building, and operating enterprise data platforms in on-premises, cloud, and hybrid environments. As a Microsoft Azure Data & AI Solutions partner, as well as a Cloudera and Databricks partner we don't commit to a single provider; instead, we look for what is best for the client in the long run—and what will remain portable tomorrow. Through the lens of the Data Act, this means five steps in practice:
Cloud migration with zero downtime. For a multinational oil and gas client, we had to migrate an end-of-life application from on-premises OpenShift to Azure Kubernetes Service, following the SAFe methodology with teams working across three continents. Thanks to the containerized microservices layer, the application was migrated in 5 months and over 350 man-days, with zero downtime and with its functionality intact—and today it runs more stably, securely, and with faster scaling.
The lesson in both cases is the same: migration is seamless when the architecture is portable by design. The Data Act doesn't do this work for us, but for the first time, it makes it economically rational.