Data Act

The EU Data Act and AI: cloud switching, portability and third-country access

The Data Act has applied since 12 September 2025. For AI teams its most relevant parts are the cloud switching rules, which let customers leave a data processing service on two months' notice and end switching charges on 12 January 2027, and the safeguards against unlawful third-country governmental access to non-personal data. It also gives users access to data from connected products.

sources

Who this applies to

Customers of data processing services
Organisations using cloud, platform or software services that fall within the Data Act definition of a data processing service. Whether a particular AI API or SaaS is in scope is a question to confirm with counsel.
Providers of data processing services
Cloud and related service providers serving customers in the EU, including contract, interface and exit obligations.
Users of connected products
Chapter II gives users access to data generated by connected products they own, rent or lease.

Key dates

See the Commission's Data Act explained and the Regulation text.

DateWhat happened or happens
11 Jan 2024The Data Act entered into force.
12 Sep 2025The Data Act applies, including Chapter VI on switching between data processing services.
12 Sep 2025 to 12 Jan 2027Providers may charge only for costs directly linked to the switching process (reduced switching charges).
12 Jan 2027Switching charges, including egress charges, are removed entirely.

Cloud switching rights

Chapter VI (Articles 23 to 31) requires contract terms that let customers switch provider or move to on-premise. According to a Faegre Drinker summary (secondary source), the main terms are:

  • Notice. A customer can switch with a maximum of two months' notice.
  • Transition. The transition period should last no more than 30 calendar days from the end of the notice period. A provider may extend it only where 30 days is technically unfeasible and must justify that. The customer has a right to extend once.
  • Data retrieval. A retrieval period of at least 30 calendar days.
  • Interfaces and portability. Per the Commission, platform and software providers must offer open interfaces to export data in a commonly used, machine-readable format, and infrastructure providers must facilitate functional equivalence.

Check the primary text for the exact conditions before you build a contract around them.

Third-country governmental access

Chapter VII protects non-personal data held by data processing service providers in the EU against unlawful third-country governmental access or transfer. Without an international agreement, access or transfer is permitted only if the third country's legal system meets specified guarantees, including reasoned decisions and a proportionality assessment. Providers should take reasonable measures, such as encryption, audits and certification schemes, publish those measures and, where possible, inform customers before giving access. The Commission is to issue guidelines through the European Data Innovation Board.

This is non-personal data. Personal data remains under the GDPR transfer rules. For AI, the combined effect is that "where the data is" is only half the question; "who can be compelled to hand it over" is the other half. See GDPR for AI.

What this means for an AI stack

  • Exit planning is now a legal lever. If your model, retrieval index or workflow platform sits on a data processing service, switching rights and the end of egress charges make migration cheaper and more predictable. Pair them with the DORA exit-strategy duties if you are a financial entity (DORA for AI).
  • Keep your AI estate portable. Prompts, evaluations, retrieval content and policies should be exportable in open formats so a switch is a configuration change, not a rebuild.
  • Read the contract. Switching terms, retrieval period, charges until 12 January 2027 and sub-contractor access belong in your AI vendor and cloud agreements.
  • Connected-product data. If your AI uses data from connected products, Chapter II access rights and the data holder's duties may apply.

How the platform supports it

Each row maps a requirement to a platform control, the evidence artifact it produces, and the Trust & Governance Fabric facets involved. Swfte provides the controls and the evidence. You remain responsible for the decisions.

RequirementPlatform controlEvidence artifactFabric facets
Be able to switch models and providers without rebuilding (Chapter VI spirit)A model gateway across 50+ LLMs so models can be swapped behind a stable interface.Documented fallback models and switch-over test records.Policy, Traceability
Export your own data and configurationExportable audit logs, Trust Profiles and policy sets; open interfaces.Export and migration runbook agreed in your contract.Evidence, Data controls
Know who can access data (Chapter VII context)Identity and access scoped per actor; the Trust Profile records data residency and permitted systems.Access records and Trust Profile fields.Identity, Access, Data controls
Reduce lock-in at the application layerGovernance and workflows defined on the platform, not hard-wired to one model vendor.Workflow and policy definitions independent of the model.Policy, Compliance

Compliance-by-design. Swfte provides the technical controls, governance mechanisms and evidence to support deployment within applicable requirements. The exact posture depends on your use case, jurisdiction, deployment and configuration. This is not legal advice.

Hosting today: customer data is stored in AWS eu-west-1 (Ireland), as stated on the trust page. EU region, in-country, dedicated and on-prem options are the platform position: what it is designed to let you do, scoped with you through a dedicated deployment engagement, not self-serve.

What this does not cover

  • Swfte does not decide whether a given AI service is a data processing service under the Data Act.
  • It does not change your cloud provider's contract terms. Switching rights are a matter for your agreements.
  • It does not guarantee that third-country authorities cannot request access to data. Hosting location alone does not settle that question.
  • The Data Act is not primarily an AI law, and this page covers only the parts relevant to AI infrastructure.

Frequently asked questions

When does the Data Act apply?

Since 12 September 2025. The Chapter VI switching rules apply from the same date, and switching charges, including egress charges, end on 12 January 2027.

What is the notice period for switching cloud providers?

A maximum of two months' notice, with a transition period of up to 30 calendar days, per a law firm summary of the Regulation. Confirm against the primary text for your contract.

Are egress fees banned?

Not yet, entirely. Until 12 January 2027 providers may charge only the costs directly linked to switching. From 12 January 2027 switching charges, including egress charges, are removed.

Does the Data Act regulate AI models?

Not directly. It governs data access, cloud switching and safeguards against unlawful third-country governmental access to non-personal data, all of which affect how you host and exit AI services.

Does hosting in the EU stop third-country access?

No. The Data Act requires providers to protect non-personal data against unlawful access, and GDPR transfer rules cover personal data, but location alone does not remove the question of who can be compelled to disclose.

Sources

Last verified 2026-10-06. Primary sources are EUR-Lex and European Commission pages. Items marked as secondary are commentary or trackers; check the primary text before relying on them.

Across the platform

The controls on this page are part of the Trust & Governance Fabric that runs through every layer of the Sovereign Intelligence Platform.

Build EU-first AI with the evidence already running

Start with one entry point. Add governance, in-region options and evidence as your requirements grow.

Ready to build with Swfte?

One platform for the agents, models and workflows your team ships. Free to start, no card required.