Most SaaS founders file the EU Data Act under “IoT regulation” and move on. That is a mistake. Chapter VI of the Act covers switching between data processing services, and EU guidance makes clear that Software as a Service is in scope. The switching rules have applied since September 12, 2025, and the next milestone is close: from January 12, 2027, providers may not impose any switching charges on customers for the switching process, including data egress charges. Until then, only reduced charges that do not exceed costs directly linked to switching are allowed. If you sell to EU businesses, switching is no longer a negotiation point in a big contract. It is a product capability with legal minimums, and it should be designed like one.
What the contract must say
Article 25 requires switching rights to be set out in a written contract made available before signing. The minimums are concrete: a maximum notice period of two months to initiate switching; a transitional period of up to 30 calendar days during which you keep providing the service, give reasonable assistance, and maintain security; an exhaustive list of the data and digital assets that can be ported, including at least all exportable data; a data retrieval period of at least 30 days after the transition; and guaranteed erasure afterward. If 30 days is technically unfeasible, you must say so within 14 working days of the request and propose an alternative of no more than seven months.
Open interfaces are part of the obligation
For SaaS and PaaS providers, Germany's Bundesnetzagentur summarizes the requirement plainly: make open interfaces available free of charge to customers and to the destination provider, along with the documentation needed to use them. At a minimum, exportable data should come out in a commonly used, machine-readable format. A CSV of one table and a support email will not survive a serious switching request. Your public API, bulk export endpoints, and their documentation are now compliance artifacts, so give them the same care as your product docs.
Define exportable data before a customer does
The contract must exhaustively list what can be ported and, where trade secrets are at risk, what internal data is exempt, without delaying the switch. Do this work deliberately: customer-created records, files, configuration, users and roles, audit logs, and metadata such as timestamps and relationships. Decide how you handle derived data, such as computed scores or embeddings, and say so. Founders who leave this vague end up negotiating it under pressure with a departing customer's lawyer.
Switching request workflow (sketch)
1. Customer submits switching or erasure notice (in-app + email)
2. Notice period clock starts (max 2 months)
3. Transition: full service continues (default 30 days)
- bulk export jobs + API access for destination provider
- known continuity risks documented to the customer
4. Retrieval window: >= 30 days after transition
5. Erasure job runs, certificate issued, contract terminatedRethink pricing that depends on exit friction
From January 12, 2027, fees for executing a switch or for data egress are gone. Standard service fees and proportionate early-termination compensation remain permissible, according to legal analyses of the Act, and Article 29 requires you to tell prospective customers about standard fees, early-termination compensation, and reduced switching charges during the transition period. If any part of your revenue model quietly relies on export fees, professional-services charges for offboarding, or the sheer pain of leaving, plan its replacement now.
Build offboarding as a first-class flow
Most SaaS products have polished onboarding and a neglected exit. Build a switching console for admins: request a switch or erasure, see the timeline, trigger exports, generate scoped credentials for the destination provider, and download an erasure confirmation at the end. Instrument it so support can see where a request stands. A good exit experience also helps sales: procurement teams relax when they can see that leaving is clean, and some will say so in renewal conversations.
Watch the exemptions, but do not count on them
Article 31 offers lighter treatment where most main features are custom-built for a specific customer, and services provided for testing for a limited period fall outside Chapter VI. A few highly bespoke deployments may qualify. Most multi-tenant SaaS products will not. Get specific legal advice for your contracts rather than assuming an exemption covers your standard plan.
Prepare sales and support for switching requests
Switching requests will arrive through account managers, support tickets, and legal emails, often with different wording. Give every customer-facing team one intake path and a short script: acknowledge the request, confirm the notice date, explain the timeline, and route it to the owner of the switching workflow. Track each request in a system with dates, because the notice, transition, and retrieval periods are measured in calendar days and missing them is easy when the request sits in a shared inbox.
Test an exit before a customer does
Run a full switching drill against a realistic test tenant once a quarter: request, export, import into a neutral format or a competitor-shaped target, retrieval, and erasure. Time each step and note anything that needed an engineer. The first drill usually reveals missing attachments, broken relationships between records, or exports that time out for large tenants. Fix those before a real customer with a deadline finds them.
Founder takeaway
The EU Data Act makes switching a regulated customer right, and from January 12, 2027 it must be free of switching and egress charges. Update contracts to meet the Article 25 minimums, document exportable data, ship open interfaces and bulk exports, build an offboarding console with clear timelines, and remove any pricing that depends on exit friction. It is a quarter of focused work that also makes enterprise procurement easier.




