The EU Data Act Is a Cloud-Exit Law as Much as an IoT Law

The EU Data Act changes who can use data from connected products, but its most immediate infrastructure impact may be the way it restricts cloud lock-in.

The European Union’s Data Act started to apply on 12 September 2025. It is often introduced as legislation about data generated by connected cars, industrial machinery, medical devices and consumer products. That description is correct, but incomplete.

The regulation also reaches deep into cloud contracts, exit procedures, data portability and interoperability. For infrastructure teams, it turns cloud migration from a commercial negotiation into a regulated capability.

Connected-product data no longer belongs to a black box

Connected products continuously generate operational data. Until now, the manufacturer or service provider often controlled the only practical route to that data. The user might own the machine while lacking usable access to the information produced through its operation.

The Data Act gives users—businesses as well as consumers—rights to access data generated through their use of a connected product and related service. They may also share it with a third party, such as an independent maintenance company or analytics provider.

This creates architectural questions that cannot be answered by adding a download button at the end of a project. Organisations must identify which data is in scope, separate raw and readily available data from derived information, authenticate users and recipients, protect trade secrets, and deliver data in a usable format.

For new connected products placed on the market after 12 September 2026, the design obligation becomes especially important: data should be readily accessible to the user by default where the regulation requires it.

The cloud provisions deserve equal attention

The Data Act requires providers of data-processing services—including cloud and edge services—to remove obstacles to switching. Contracts must explain the switching process, the data and digital assets that can be exported, applicable timeframes, assistance and continuity arrangements.

The technical objective is not to make every cloud service identical. It is to make departure realistic. Providers must support the extraction and transfer of exportable data and digital assets, cooperate in good faith, and use open interfaces or relevant interoperability specifications where required.

Switching charges are being phased out. From 12 January 2027, providers may no longer impose switching charges for the regulated switching process. Standard service fees and legitimate early-termination provisions are a separate matter, but a punitive egress model becomes much harder to defend.

Cloud exit is now an engineering control

Many organisations have a cloud-exit paragraph in a policy but have never tested it. The Data Act exposes the difference between a contractual promise and a recoverable service.

A credible exit plan should answer:

  • Which data, metadata, configurations and customer-controlled digital assets can be exported?
  • Which formats and interfaces are used?
  • Can identity, logging and encryption dependencies be rebuilt elsewhere?
  • How long can source and destination environments operate in parallel?
  • What happens to data remaining with the former provider?
  • Which managed services have no practical equivalent outside the source platform?

The hardest dependencies are often outside the primary workload: identity federation, key management, monitoring, event pipelines, deployment automation and proprietary databases. If these are absent from the exit test, the test is incomplete.

Contracts and architecture must be reviewed together

Legal teams will need to review data-sharing and cloud terms, particularly unilaterally imposed terms that restrict access, remedies or reuse. Technical teams should provide the evidence needed to make those negotiations meaningful.

An organisation preparing for compliance should:

  1. Inventory connected products and related services in the EU.
  2. Map generated data to users, holders, recipients and existing access mechanisms.
  3. Review cloud contracts for exit support, formats, charges and deletion commitments.
  4. Test at least one representative workload migration, including security dependencies.
  5. Record trade-secret and personal-data safeguards without using them as blanket reasons to block access.
  6. Update product roadmaps for the connected-product design requirements applying after 12 September 2026.

The larger change

The Data Act treats access and portability as characteristics of a functioning digital market. A product that hides its operational data and a cloud service that a customer cannot leave are two versions of the same problem: control created through technical dependency.

The practical response is not merely a new privacy notice or contract clause. It is an architecture in which data can be identified, exported, protected and used without the original supplier remaining permanently in the middle.

Official sources

This article provides general information and is not legal advice.

Leave a Reply

Your email address will not be published. Required fields are marked *