Back to Blog

Data Act: in January 2027 leaving the cloud becomes free; moving does not

An empty industrial hall with a concrete floor, a pallet in the foreground and an open door at the back

On 12 January 2027 your cloud provider loses the right to charge you for leaving. That is good news and it is real: it sits in Article 29 of the European Data Act. It is also the smallest piece of good news in the whole affair, because the exit invoice was never the expensive part of leaving.

We manage customer infrastructure every day that lives spread across our own datacentres and third-party platforms, and in any platform move the budget does not go on getting the data out: it goes on rebuilding what was sitting on top of it. The regulation that completes in January does not touch that part. It does not even try to.

What Article 29 actually says

Regulation (EU) 2023/2854 — the Data Act — has applied since 12 September 2025, per its own Article 50. Withdrawing switching charges runs on its own staged clock. Paragraph 2 allows providers to bill reduced switching charges between 11 January 2024 and 12 January 2027, which paragraph 3 caps at the costs the provider incurs that are directly linked to the process. And paragraph 1 puts an expiry date on all of it: "From 12 January 2027, providers of data processing services shall not impose any switching charges on the customer for the switching process."

It pays to read the definition too, because that is where the first trim happens. Article 2(36) defines switching charges as fees "other than standard service fees or early termination penalties." Translated into invoice terms: what disappears is the exit toll. The ordinary service fee keeps running for as long as the handover takes, and the early termination penalty, if you signed a minimum term, is still yours to pay. Free does not mean "no invoice": it means they cannot invent a new invoice out of the fact that you are leaving.

This already happened in 2024, which is why the headline misleads

This has to be said early, otherwise the whole piece reads like two-year-old news. If your cloud is one of the big three, they already stopped charging you to leave: Google opened the door in January 2024 and AWS announced it on 5 March that year, with Microsoft following on Azure a few days later. The trade press reported at the time, without much coyness, that it was a response to the European regulation already on its way — and our five-year colocation versus public cloud maths already took it as given.

What changes in January, then, is not the amount: it is the nature of that free pass. The 2024 moves are credit programmes with conditions and an application in the middle: you have to ask, you have to fit the case and, with Google and Azure, you have to close the account — Azure also requiring the move to be finished within sixty days. It is a commercial policy, and a commercial policy changes whenever whoever wrote it feels like it. From 12 January 2027 it becomes an unconditional legal obligation, and above all it stops being about three companies: it reaches the hundreds of mid-sized and small providers that never announced anything, which are exactly the ones a great many smaller firms actually work with.

The word that decides everything is "minimum"

The concept holding up the whole chapter is functional equivalence: the idea that after you switch, the thing still does what it did. The definition in Article 2(37) is worth reading in full rather than in whichever fragment suits you, because each half pulls in a different direction: functional equivalence means "re-establishing, on the basis of the customer's exportable data and digital assets, a minimum level of functionality in the environment of a new data processing service of the same service type after the switching process, where the destination data processing service delivers a materially comparable outcome in response to the same input for shared features supplied to the customer under the contract."

That "materially comparable outcome" is demanding, and rightly so. The trim sits in the two words that bound it: shared features. Recital 86 spells it out: a provider can only be expected to facilitate functional equivalence "for the features that both the source and destination data processing services offer independently." Translated: whatever the source does and the destination does not is out of scope by definition. And that, as it happens, is the exact list of what holds you in place.

And not even that bounded minimum applies to everyone. Read in practice — this reading is ours, the article is not structured this way — Article 30 works as two tiers and a floor, and the distance between the first and the last is the distance between a house move and having your boxes returned:

  • 1Infrastructure (IaaS). Functional equivalence appears here and nowhere else, and paragraph 1 writes it as an effort: the provider must take "all reasonable measures in their power" to help you get there, supplying capabilities, information, documentation and technical support. Recital 86 confirms it from the other side: the regulation "does not constitute an obligation to facilitate functional equivalence for providers of data processing services other than those offering services of the IaaS delivery model." We read that as an obligation of effort, not of result.
  • 2Everything else (PaaS and SaaS). Paragraph 2 asks them for open interfaces, free of charge and available equally to all customers, with enough information to build software against them. No functional equivalence. What they owe you is a door, not a removal van.
  • 3And where no standard has been published, paragraph 5 lowers the bar to solid ground: export all exportable data in a "structured, commonly used and machine-readable" format. A dump. Correct, enforceable, and a long way from a running system.

One trim is left, in paragraph 6, and most summaries stop halfway through it: the provider need not disclose or transfer digital assets protected by intellectual property rights or constituting a trade secret, nor compromise security to do so, nor develop new technologies or services. The trade secret is the genuinely wide door, because invoking it requires registering nothing. And it is also precisely where the thing that ties you down lives: the rules engine, the proprietary data model, the connector somebody wrote against an API that exists only there.

That a paper right to export and an actual exit are not the same thing we already covered with a concrete case in the Project Online shutdown: there, what was missing was not the law but the live licence you needed in order to press "export". The Data Act fixes the price of that door. It does not guarantee there is a house built on the other side.

Multicloud keeps paying the toll, and it is written down

Here is a nuance that goes missing from almost every summary and that will hurt somebody's invoice. The regulation's recitals distinguish between the one-off egress that forms part of a switch and the ongoing egress that happens when you run two services at once. And they say, in so many words, that providers "should therefore continue to be able to impose data egress charges, not exceeding the costs incurred, for the purposes of in-parallel use."

Now think about how a migration that cannot stop the business actually happens: replicate, run in parallel, cut over in slices, over months. Seen from the invoice, that is not a switch: it is in-parallel use. The clean exit described in Chapter VI is an operation almost nobody can afford to run in one go. The careful way of working is precisely the one that is not covered.

The deadlines you can already enforce today

This, for us, is the useful part of the regulation, and it is not the part that makes headlines. Article 25 requires the contract to carry specific deadlines, and they are deadlines you can put on the table before January:

  • →Maximum notice period: two months. The contract cannot demand more before you start the switch.
  • →Transitional period: 30 calendar days, starting after the notice period. And the customer may extend it once, for whatever length they consider appropriate. You are the one who decides on that extension.
  • →If 30 days is technically unfeasible, the provider must tell you within 14 working days and may propose an alternative period of up to seven months. Knowing that ceiling exists changes an entire negotiation.
  • →Data retrieval: at least 30 more calendar days, counted from the end of the transitional period. After that, full erasure of exportable data and digital assets.
  • →The service keeps running throughout, maintaining "a high level of security". Mind the wording: the regulation says "a high level", not "the same level". Not parity, but it does rule out a degraded "exit mode".

Add them up and you get the number that is actually useful for planning: between notice and transition, changing provider is a three-to-nine-month project, and that is counting only the deadlines the law sets. Nine is not a ceiling either: the extension of the transitional period is yours to decide and carries no written cap. If renewal falls in June, the conversation starts now, not in May. The other article worth reading before you relax is 31, which carves two categories out of several of these obligations: services custom-built for one specific customer and not offered at broad commercial scale, and non-production versions for testing and evaluation. If your critical platform is a bespoke build, do not assume it is covered.

The exit drill: stopwatch in hand

With backups we learned years ago that a copy you never restore does not exist. The same holds for the cloud and almost nobody applies it: an exit you never rehearse is not an exit, it is a clause. This is what we do, and it can be done without us:

  • 1Separate data from assets. The regulation already does it for you: "exportable data" means input and output data, including metadata, generated by your use; "digital assets" means elements in digital form, applications included, that you have the right to use. And read the small print of the first definition, which is where plenty of people trip: Article 2(38) itself excludes from exportable data "any assets or data protected by intellectual property rights, or constituting a trade secret." Not even "the data" comes out whole by default.
  • 2Ask in writing for what they already owe you. Article 29 itself requires the provider to disclose service fees, termination penalties and applicable switching charges, and to publish that information accessibly. Ask for it together with the exhaustive list of categories of data and assets that can be ported. A provider that takes three weeks to answer has already told you what switching day will look like.
  • 3Time a real export of your largest workload. Not the test one: the large one. How long a volume takes to come out through the official route is an architectural fact, and it appears in no contract and no law changes it.
  • 4Bring the export up somewhere else and see what does NOT start. There, and only there, you get the real list of what was never portable: the identifier that does not exist outside, the managed queue with no equivalent, the function somebody wrote against a proprietary service. That list is your cost of leaving.

The exercise looks a lot like the one we propose when somebody tells us their cloud is resilient because it spans several zones: we wrote it up in your cloud can lose one zone, not a region. The question is the same in both cases, and it is uncomfortable for the same reason: you do not answer it by reading the contract, you answer it by testing.

And no, this is not an invitation to leave

It would be very convenient to end this piece by saying the cage opens in January and everyone should run for their own hardware. We are not going to say that, not least because it is not true. If your workload is genuinely elastic — seasonal peaks, campaigns, things that exist three weeks a year — public cloud is still the right answer and we will keep recommending it. If your systems team is two people already stretched thin, bringing hardware in-house without an operations contract behind it swaps an invoice for an on-call rota.

What changes in January is not the answer: it is that you can finally ask the question without a price list answering it for you. When we ran the five-year numbers between colocation and public cloud, what tipped the balance was almost never the hourly price: it was how stable the workload was and who was going to run it. That calculation is unchanged on 12 January 2027, except that one variable — the exit toll — drops to zero, and that makes the others easier to see.

Free is not the same as easy

In January 2027 one invoice line disappears that the big three had already removed on their own. What you gain is not money: it is that leaving stops depending on anybody's goodwill, and that it also reaches the mid-sized provider half the smaller firms in this country actually work with. What you do not gain is time. The connector still has to be rewritten, the month of running both platforms side by side still gets billed because it is in-parallel use, and the inventory of what breaks when things move still has not been done. If you could leave for free tomorrow, how long would it take you? The day you can answer that with a number, you are the one running the conversation with your provider.

Sources (verified on 2026-09-25 against the articles of Regulation (EU) 2023/2854, the Data Act): gradual withdrawal and prohibition of switching charges, plus pre-contractual information — Article 29; functional equivalence for infrastructure only, open interfaces for everyone else, structured-format export and the intellectual-property limit — Article 30; notice period, transitional period, extension, seven months, 14 working days and data retrieval — Article 25; definitions of switching charges (2(36)), functional equivalence (2(37)), exportable data (2(38)) and digital assets (2(32)) — Article 2; exemptions for custom-built services and non-production versions — Article 31; date of application — Article 50; functional equivalence limited to the IaaS model and to shared features — recital 86; egress charges for in-parallel use, "Providers of data processing services should therefore continue to be able to impose data egress charges, not exceeding the costs incurred, for the purposes of in-parallel use after three years from the date of entry into force of this Regulation" — recital 99. The 2024 exit-fee waivers and their conditions, per the trade press at the time: SiliconANGLE (AWS, 2024-03-05) and CIO Dive (Azure). Quoted passages are reproduced in the English of the published text so as not to shift their meaning. The "three to nine months" range is our own sum of the Article 25 deadlines (two months' notice plus 30 days of transition, or up to seven months where the provider claims technical unfeasibility), not a figure that appears in the regulation. This post explains how the regulation affects us in technical practice: it is not legal advice.

How long would it take you to leave your cloud? Let us run the drill

At everyWAN we are not resellers of any particular platform: we recommend on the merits of the case, not on the commission. We inventory your data and your applications, time a real export, and tell you what comes out, what does not, and what moving it actually costs. If the answer is your own hardware, we run it in colocation; if the answer is to stay put, we will tell you that too, in writing.

Talk to everyWAN

Tags:

Share:

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN