Switching providers: portability and exit terms

Switching cloud providers can take more than copying files. An organisation may need to move data, applications or workloads, adapt processes and keep services running during the transition. Whether this is practical depends on technical capabilities as well as contractual terms and associated costs.

Regulation (EU) 2023/2854, known as the Data Act, addresses barriers to switching between certain data processing services. It is not a promise that every system can be migrated without friction, nor a requirement that all providers offer identical services. To assess a particular case, identify the contracted service and consult the obligations that apply in the legal text; do not extrapolate from the general idea of portability. Official text of the Regulation.

This distinction is useful for planning: a contract clause may describe exports, assistance or time limits, but that alone does not show that a transition will be technically straightforward. The law establishes a framework; assessing whether a particular migration is feasible requires reviewing the contract, architecture and data involved. The Commission presents switching between cloud services as one of the Regulation’s objectives, alongside access to and use of data from connected products. Commission explanation.

What the Data Act regulates—and what should not be assumed

The Data Act lays down harmonised rules on fair access to data and its use. Its text includes provisions on switching between data processing services, as well as other matters, including access to data generated by connected products. Switching cloud providers is therefore one part of the framework, not the only subject it regulates. Regulation (EU) 2023/2854, Spanish version.

The expression “data processing service” has a legal meaning and does not automatically cover every product marketed as a cloud service. Analysis must take account of the Regulation’s definitions and scope, as well as its specific switching provisions. The Commission explains that the Act also aims to make it easier for cloud service users to switch providers or use several services. That summary is a useful guide, but it does not replace the legislation. European Commission: explanation of the Regulation.

Do not infer specific obligations from an institutional summary alone. Before turning the general objective into a contractual demand, identify in the Regulation which obligations apply to the provider, which apply to the customer, and what exceptions or conditions are relevant. The Regulation also covers other data relationships and uses, so citing it in general terms is not enough to resolve a commercial dispute.

Who is affected: identify the provider, customer and service

The first practical check is to identify who provides the service and what service is being provided. A company may contract for several components—for example, infrastructure, a platform, storage or software—that do not necessarily fall into the same legal category. The commercial label “cloud” does not settle the legal classification on its own.

The legal text contains definitions and sets the scope of application; a review should therefore begin with those categories, not an informal list of providers. It also matters whether the party requesting the switch is acting as the service customer, which data or assets are to be moved, and which contracting entity is responsible for each component. These questions help distinguish regulatory obligations from migration work agreed by the parties.

As a guide to reviewing a contract, collect the name and scope of the service, the provider entity, dependent services, export formats, exit request conditions and transition documentation. These items do not automatically prove compliance, but they help compare the agreed terms with the relevant rules in the Regulation. The legal conclusion depends on how the specific situation fits its definitions and articles.

Timeline: adoption, entry into force and application

The Regulation was adopted on 13 December 2023 and published in the Official Journal of the European Union on 22 December 2023. The Commission announced that it entered into force on 11 January 2024. Entry into force and application are not synonymous: to determine when a specific obligation applies, check the dates and transitional provisions in the Regulation itself. Official Journal text; European Commission, announcement of entry into force.

The Commission said that the Regulation began to apply in the EU on 12 September 2025. That general date is relevant, but it does not replace checking any special deadlines that may apply to particular articles or categories. Nor does it allow one to conclude automatically that every clause in an earlier contract has changed or that every provider-switching operation is covered in the same way. European Commission, announcement of 12 September 2025.

For a business decision, record three milestones separately: adoption and publication; entry into force; and the application date of the specific provision being relied on. If a transition is still pending, check the operational timetable against the official version of the act and the current contract. Do not use a press release instead of checking the specific legal date.

What to review before starting a migration

A preliminary review can reduce surprises, although it does not replace legal advice. Start by taking inventory of the services and workloads to be moved; determine which data will be exported and in what format; identify dependencies on the provider’s tools; and review costs, notice periods, deadlines and assistance included in the contract. Compare the written terms with the service’s current technical documentation.

An exit may involve several distinct stages: requesting the switch, extracting data, transferring it, rebuilding components and checking service continuity. Clarify which tasks are the customer’s responsibility, what assistance the provider offers and how data will be handled when the transition ends. These checks are matters of practical diligence; they should not be presented as an exhaustive list of statutory obligations without checking the applicable provisions.

A short checklist for procurement and technology teams: (1) request the switching and exit clause; (2) ask for export formats, interfaces and documentation; (3) identify associated charges and conditions; (4) agree responsibilities, a timetable and data validation; (5) compare each point with the Regulation and, where appropriate, obtain legal review. Keep records of contract versions and provider responses so decisions can be documented.

Limits of the evidence and practical conclusion

The evidence reviewed confirms that the Regulation exists, aims to harmonise rules on data access and use, includes switching between cloud services among its objectives, and has a general timetable communicated by the Commission. On its own, however, it is not enough to determine how each obligation applies to a particular contract, service or migration. That requires reviewing the full relevant articles, definitions, possible exceptions and agreement between the parties.

There is also an important difference between a public-policy objective—making switching easier—and a technical outcome. The Regulation does not show that a workload is portable without conversion, interruptions or costs, or that two services are functionally equivalent. The useful conclusion for businesses is to check the legal and contractual fit before budgeting for an exit, rather than treating portability as a uniformly guaranteed feature.

This article is not legal advice and does not assess specific providers. For a decision with financial consequences, use the official text in Spanish, confirm the application date of the relevant provision and document which data and services will be moved. The Commission’s summaries are institutional guidance; where interpretation is uncertain, the Regulation published in the Official Journal prevails.