The verifiable development: voluntary contractual clauses

The specific development is not the launch of a new cloud service or a provider’s migration feature. On 19 November 2025, the European Commission published a recommendation containing non-binding model contractual terms on data access and use, together with standard contractual clauses for cloud computing contracts. The initiative is intended to help parties — particularly SMEs — put provisions of the Data Act into practice. The Commission’s publication describes the documents and their purpose.

The key qualification is their status: the Commission says their use is voluntary and that parties may modify them. It would therefore be inaccurate to present the publication as a new mandatory condition that all cloud customers must accept, or as a reform that automatically changes every existing contract. The news is that reference models are now available, not that all businesses must replace their agreements or that dependence on a provider has already been eliminated.

The Commission’s page was published in November 2025; here, that date is presented as the date stated by the source, not as the date on which an obligation came into force. The clauses are related to a broader legal framework, but should not be confused with the regulation itself. That distinction matters to any organisation receiving a contractual proposal or assessing a migration: the model may be useful in negotiations, but its publication does not show that a provider has adopted it or that leaving is technically and economically straightforward.

How it relates to the Data Act

The EU Data Act is the legal framework to which the Commission links these contractual tools. The regulation’s official page on EUR-Lex summarises rules on fair access to and use of data, while the Commission presents the models as tools to support implementation of the Act’s provisions. The law and the clauses play different roles: one establishes legal rules; the others provide suggested contractual wording that parties may consider.

The Commission’s publication identifies two areas covered by the documents. First, model terms address certain data-sharing relationships covered by Chapters II and III of the Data Act. Second, standard contractual clauses are provided for cloud computing contracts. It is best not to group everything under the idea of “a mandatory European cloud contract”: the material brings together models with different objectives and, according to the Commission, their use is voluntary.

The Commission explains that the models were designed primarily for business-to-business relationships, although they may also be used in business-to-consumer relationships if the relevant consumer-protection rules are incorporated. This is not the same as a legal assessment of a specific contract. Suitability depends on the service, the parties, the applicable law and the negotiated wording. For an actual decision, businesses should review the clauses with legal and technical advice rather than assume that a general model resolves the obligations specific to their activities.

Portability and switching providers: the contract is not enough

Switching cloud providers usually involves more than copying files. It may also involve data formats, application dependencies, configurations, credentials, integrations, transfer costs and periods when services must run side by side. The existence of a model contract for cloud computing therefore does not establish that a particular migration will be quick, inexpensive or complete. Those conditions depend both on the contract and on the systems’ characteristics and how they were built.

In 2018, the European Commission published a study entitled Switching of Cloud Services Providers, available through the EU Publications Office. Its existence documents that switching between cloud providers was already being examined at European level before the 2025 model clauses were published. It does not, by itself, establish the current cost of a migration or justify attributing a general figure to organisations today. Quantifying the impact would require examining comparable data, methods, samples and the date of each study — something the information collected here does not make possible.

An independent legal analysis by Garrigues describes the provider-switching regime under the Data Act and provides context on the new rules. That commentary may help interpret the framework, but it does not replace the legal text or show how a clause will operate in a particular case. The prudent conclusion is narrower: the Commission’s tools may facilitate contractual discussions; effective portability requires checking the service and the exit scenario.

What to check before signing or planning an exit

For a customer organisation, the publication can be a starting point for a contract review, not a checklist of guarantees that have already been met. It is worth comparing the current contract with the relevant models and making each party’s responsibilities explicit. That comparison should cover both which data can be recovered and the format, timing and conditions under which the provider supplies it, as well as what happens to copies or dependent services when the agreement ends.

A practical review can start with these questions:

  • Scope: which services and data the contract covers, and whether this includes metadata, configurations or information needed to rebuild the environment.
  • Format and assistance: which export formats are available, what transition support is included, and which tasks remain the customer’s responsibility.
  • Costs and timetable: what charges may apply during an exit, how long the transition period lasts, and what deadlines apply to data deletion.
  • Dependencies: which applications, interfaces, identity tools or operational processes must change for the alternative to work.
  • Protection and compliance: how the exit is coordinated with the security, continuity, privacy and retention requirements that apply to the organisation.

This list does not claim that the Commission requires each answer to be worded in a particular way. It is a set of due-diligence points that turns the idea of portability into questions that can be checked. If an exit matters to business continuity, an organisation can document responsibilities and test its own processes, while avoiding confusion between an internal test and a general guarantee about the provider.

What we know and what the evidence does not allow us to conclude

The available information supports the statement that, on 19 November 2025, the Commission published non-binding contractual models to support implementation of the Data Act and expressly described their use as voluntary. It also allows us to distinguish those documents from the regulation and to note that the publication is not a provider’s commercial announcement. These are facts supported by the Commission’s institutional page; they are not inferences about widespread adoption or migration outcomes.

The evidence reviewed does not allow us to measure how many providers have incorporated the models, how many contracts have been amended or how much a business will save by switching services. Nor does it establish whether a specific clause is sufficient for a particular sector or contract. These are limits of the documentation reviewed, not grounds for concluding that the tools are useless.

To update this information in response to later news, the evidence should be specific: a dated official document, an identifiable regulatory amendment or a provider announcement describing an available feature and its conditions. Until such evidence is provided, the models should be described for what they are: a voluntary reference for negotiations, not a promise of universal interoperability or proof that switching cloud providers no longer requires planning.