Latest posts Visit blog

Computing power, storage and services usually come from the cloud in shop operations - and how tightly the contract sits is something you typically only notice once a switch is on the table. Chapter VI of Regulation (EU) 2023/2854, known in practice as the Data Act, changes that in two stages: the switching rules have applied since 12 September 2025, and the fee exemption takes effect on 12 January 2027 (EUR-Lex). This article sets out what applies from that date, which deadlines a switching contract has to state, which data is exportable at all - and which of those points should already be in your contract for cloud services.

What changes on 12 January 2027

The core of the change sits in Article 29 of the Data Act. From 12 January 2027 providers of data processing services may no longer impose switching charges for the switching process (EUR-Lex). Until then a transitional rule applies: from 11 January 2024 until 12 January 2027 reduced switching charges are permitted (EUR-Lex), and those reduced charges must not exceed the costs incurred by the provider that are directly linked to the switching process concerned (EUR-Lex). The European Commission summarises the date by stating that switching charges, including charges for data egress, disappear entirely from 12 January 2027 (European Commission). For a shop operation that means the price of leaving disappears as a bargaining chip.

The three-year run-up to that date is not accidental. Recital 88 of the Regulation justifies the abolition by stating that switching charges should be abolished three years from the date of entry into force (EUR-Lex); the Regulation entered into force on 11 January 2024 and has applied since 12 September 2025 (European Commission). Chapter VI carries the heading "Switching between data processing services" and covers Articles 23 to 31. The first sentence of Article 23 refers, for the switching measures, to five of those articles: 25, 26, 27, 29 and 30 (EUR-Lex). Anyone reviewing a contract is therefore well advised to work along that list of references rather than along a single provision.

Two chapters, two dates

The frequently quoted date of 12 September 2027 concerns Chapter IV of the Data Act, that is unfair contractual terms between businesses: for contracts concluded on or before 12 September 2025 and of indefinite duration, Chapter IV applies from that day (EUR-Lex). The switching rules in Chapter VI, by contrast, have applied since 12 September 2025, and the fee exemption arrives on 12 January 2027. We covered the device and IoT part of the same Regulation in EU Data Act for IoT shops: design duties since 12 Sep 2026.

Switching charge, standard service fee, data egress

Whether an item on the invoice disappears in 2027 is decided not by its label but by how it fits the definitions in Article 2. The Regulation separates three things there that often appear as a single line in a provider's quote: the fee for the service, the fee for the switch and the fee for the route the data takes out of the house. Only that separation makes a contract review verifiable, because it assigns every item to a provision.

  • Switching charges are, under Article 2 point 36, charges other than standard service fees or early termination penalties imposed by a provider for the switching actions prescribed by the Regulation - data egress charges included (EUR-Lex).
  • Data egress charges are data transfer fees charged for extracting customer data through the network from the infrastructure of one provider to the systems of another provider or to on-premises facilities (EUR-Lex, Article 2 point 35).
  • Standard service fees are unaffected: the running invoice for computing power, storage and services continues. What falls away from the date is the surcharge that makes leaving more expensive.

The second point of principle concerns scope. A switch is of limited use if the transport costs nothing but the object of the transport turns out to be thin. The Regulation therefore describes separately what counts as exportable data and where the boundary runs. In practice this point determines how much work remains after the move: whatever does not come along is rebuilt in the target system, and by hand.

Exportable does not mean complete

For Articles 23 to 31, exportable data means the input and output data, including metadata, directly or indirectly generated by the use of the service, excluding assets and data protected by intellectual property rights or constituting a trade secret of the provider (EUR-Lex, Article 2 point 38). For a shop that means: orders, customer accounts, media and logs are the normal case, whereas the configuration of a provider's own management interface typically is not.

The deadlines of the switching contract

Article 25 requires a written contract that the provider makes available before signature, and it prescribes the deadlines that contract must contain. The order matters more than any individual figure: first the notice period for initiating the switching process runs, then the transitional period for transferring data and digital assets begins, and only after it expires does the minimum period for data retrieval count (EUR-Lex). Lining up the three deadlines produces a window that can be planned into the operating schedule - provided the contract names them at all.

StepDeadlineReference in Article 25
Notice period for initiating the switchtwo months at mostparagraph 2 point (d)
Transitional period for the transfer30 calendar days at mostparagraph 2 point (a)
Retrieval period after the transitional period30 calendar days at leastparagraph 2 point (g)
Notification where technically unfeasible14 working daysparagraph 4
Alternative transitional periodseven months at mostparagraph 4
Extension by the customeronce, duration at the customer's discretionparagraph 5
Technically unfeasible is not a blank cheque

Where the mandatory maximum transitional period is technically unfeasible, the provider notifies the customer within 14 working days of the switching request being made, duly justifies the unfeasibility and indicates an alternative transitional period, which may not exceed seven months (EUR-Lex, Article 25(4)). The exception thereby becomes a statement that requires justification and carries its own upper limit. The contract should say where that notification goes and in what form it is documented.

The extension that belongs to the customer

The contract must also include a clause providing that the customer has the right to extend the transitional period once for a period that the customer deems more appropriate for its own purposes (EUR-Lex, Article 25(5)). The right sits with the customer, not the provider, and it applies without prejudice to the rule on technical unfeasibility. For a shop that is the reserve for the awkward case: a migration that slips into peak season, a target system that becomes available later than planned, a data set that turns out to be larger than the inventory suggested.

Mandatory information before the contract and on the website

Before concluding a contract, the provider informs the prospective customer clearly about three points (EUR-Lex, Article 29(4)). Those items are the lever for the contract negotiation, because they have to be available before signature and therefore become comparable. Anyone lining up several quotes is well advised to request them explicitly in this structure:

  1. The standard service fees that the provider may charge.
  2. The penalties that may be imposed for early termination.
  3. The reduced switching charges that may arise until 12 January 2027 - after which this item falls away (EUR-Lex).

the jurisdiction to which the ICT infrastructure deployed for data processing for its individual services is subject;

Regulation (EU) 2023/2854, Article 28(1) point (a)

Under Article 28 that information belongs on the provider's website, and for each individual service (EUR-Lex). For selecting a hosting or cloud partner this is a solid checkpoint: where the infrastructure is legally located co-determines which external access is conceivable and how a data processing arrangement has to be drafted. What supervising processors looks like in day-to-day operation is covered in our article on data processing agreements and vendor audits; the contractual side of a provider switch also leads into our data protection consulting.

There is one exception, and it is narrower than its name suggests. For data processing services the majority of main features of which have been custom-built to the specific needs of an individual customer and which are not offered at broad commercial scale, Article 23 point (d), Article 29 and Article 30(1) and (3) do not apply (EUR-Lex, Article 31(1)). Everything else remains in force: the switching contract under Article 25 with its deadlines, the information obligations and the duty to inform the customer. A purpose-built environment is therefore no reason to do without the contractual clauses.

On interoperability it pays to look closely at the direction of the deadline. Providers outside the infrastructure scope described in Article 30(1) ensure compatibility with common specifications at least 12 months after the references to them have been published in the central Union standards repository (EUR-Lex, Article 30(3)). That is a minimum lead time for providers and not a deadline by which something has to be done. In addition, the Commission was to develop and recommend non-binding standard contractual clauses for cloud computing contracts before 12 September 2025 (EUR-Lex, Article 41); they serve as a negotiating basis, they are not binding.

Who enforces the rules

In Germany the Bundesnetzagentur is, under Section 2(1) of the Data Act Application and Enforcement Act, the competent authority for the application and enforcement of the Data Act (Federal Office of Justice). With that act entering into force it has been the competent German authority for implementation since 30 May 2026 (Bundesnetzagentur). Its tasks expressly include monitoring compliance with the new rules on making switching between cloud providers easier (Bundesnetzagentur). Shop operators therefore have a named body to which a complaint can be addressed if a provider fails to deliver the switching clauses.

The enforcement act lists the infringements in a catalogue of its own. In the cases of Section 15(2) numbers 16 to 19 the fine range reaches up to one hundred thousand euros; number 19 covers imposing an obstacle to switching contrary to the second sentence of Article 23 of the Data Act (Federal Office of Justice). Where a provider fails to make available the contract prescribed by Article 25, or does so incorrectly, incompletely or late, that is an administrative offence under Section 15(2) number 20 (Federal Office of Justice); for the cases of that catalogue not listed separately in subsection 4, the range reaches up to fifty thousand euros (Federal Office of Justice).

Article 29 is not in the fines catalogue

The catalogue in Section 15 of the German enforcement act lists Articles 23, 25, 26 and 30 of the Data Act among others, but not Article 29 (Federal Office of Justice). A switching charge imposed after 12 January 2027 is therefore not a separate offence; anyone wanting to act against it starts with the contract and the supervisory authority, not with a fine. That distinction belongs in any argument put to a provider, otherwise the case rests on a provision that does not carry it.

How widespread cloud use is in German companies

Slightly more than half of companies in Germany with at least 10 employees used paid cloud services in 2025, namely 54 percent (Destatis). The size classes are far apart: 86 percent of large companies, 65 percent of medium-sized companies with 50 to 249 employees and 51 percent of small companies with 10 to 49 employees (Destatis). All of these shares refer to companies with 10 or more employees; the survey does not cover smaller businesses. For the switching rules the distribution matters because bargaining power rises with company size - and the Regulation levels that difference to some extent.

By economic sector, information and communication leads with 88 percent of companies, while cloud services are comparatively rare in accommodation and food services at 45 percent and in transportation and storage at 43 percent (Destatis, companies with 10 or more employees in each case). Retail sits in between. In practice a shop with a connected merchandise management system and its own media library sits closer to the upper end of that range, because several systems run in third-party infrastructure at the same time and each of them needs its own exit route.

What the services are used for rests on a different base: among companies that use cloud services at all, email leads at 76 percent, data storage at 71 percent and office applications at 68 percent; ERP and CRM follow at 23 percent each (Destatis, base: companies with 10 or more employees that use cloud services, multiple answers possible). Those last two applications in particular are the heavy items in a shop switch: they carry master data, prices and customer history, and their export determines the length of the transitional period. How to keep operations stable throughout is described in our article on managed hosting for online shops.

EU overall

52.74 percent of enterprises in the EU reported buying cloud computing services in 2025, 7.42 percentage points more than in 2023 (Eurostat).

Medium-sized enterprises

66.78 percent of medium-sized enterprises in the EU with 50 to 249 employees bought cloud computing services in 2025, compared with 59.09 percent in 2023 (Eurostat).

Large enterprises

84.67 percent of large enterprises in the EU bought such services in 2025, 6.9 percentage points more than in 2023 (Eurostat); among cloud-using enterprises, 77.53 percent were classed as highly dependent (Eurostat).

Why hardly anyone switches even so

A switch becoming legally easier does not mean it happens. The British competition authority records in its market investigation into infrastructure and platform services that fewer than one percent of customers switch provider each year (Competition and Markets Authority). The investigation describes the UK market, not Germany: there, customers spent ten and a half billion pounds on infrastructure and platform services in 2024, with spending growth of just under 30 percent per year since 2020 (Competition and Markets Authority). Software as a service is not included in that figure.

The same investigation identifies charges for data egress between providers as a significant commercial barrier (Competition and Markets Authority). For a sense of scale the authority illustrates that a price five percent above the competitive level would cost UK customers roughly 500 million pounds a year extra (Competition and Markets Authority). That is exactly where Article 29 applies: once the fee for the route out disappears, the technical barrier remains - and that one can be planned for, unlike an invoice that only becomes visible on the way out.

What to check in the hosting contract now

There is time before the deadline for the unspectacular part: read the contract and name the gaps. The following points can be worked through using the contract text and the provider's website, and every line has a reference in Chapter VI. A question put to the provider can then be phrased as a reference rather than as a wish.

  • Notice period for initiating the switch stated and no longer than two months
  • Transitional period of no more than 30 calendar days expressly promised
  • Retrieval period of at least 30 calendar days after the transitional period agreed
  • Procedure and recipient for the notification in case of technical unfeasibility defined
  • Right to a one-off extension of the transitional period by the customer present in the text
  • Standard service fees, termination penalties and reduced switching charges itemised separately before signature
  • Jurisdiction of the infrastructure used, per service, findable on the provider's website
  • Scope of exportable data including metadata and output format described

Whatever is missing from that list is no longer a pricing matter after 12 January 2027 but a contractual one. We usually review such contracts together with the technical inventory, because only both sides together show how long a move actually takes; day-to-day operations during a migration are covered by hosting and maintenance. To begin with, a plain list per service that brings scope, format and deadlines together in one place is enough - here with sample values and the deadlines from Article 25:

export-scope.json
{
  "service": "shop-production",
  "exportable": {
    "orders": { "format": "csv", "period": "since 2019" },
    "customer_accounts": { "format": "csv", "personal_data": true },
    "media": { "format": "original files", "paths": "per article" },
    "logs": { "format": "jsonl", "retention_days": 90 }
  },
  "not_exportable": [
    "configuration of the provider's management interface",
    "provider-owned templates and rule sets"
  ],
  "deadlines": {
    "notice_months": 2,
    "transition_calendar_days": 30,
    "retrieval_calendar_days": 30
  }
}

The switch in everyday shop operations

In practice a switch rarely fails on the legal position and often on the inventory. Anyone planning with a transitional period of 30 calendar days should know beforehand how many gigabytes travel over which line, which exports the provider offers itself and which have to be pulled through an interface. Measuring in advance is typically cheaper than an extension halfway through, even though that extension is available under Article 25(5) (EUR-Lex). Such an inventory can look like this, with sample values:

Terminal
$ shop-export --inventory --service shop-production
Orders: 418220 records, 11.8 GB, format csv
$ shop-export --inventory --area media
Media: 61003 files, 238.4 GB, original format
$ shop-export --plan --bandwidth 200
285.3 GB total, around 3.5 days of pure transfer at 200 Mbit/s

What does not come along

Three things typically stay behind. First, the configuration of provider-owned tools, in so far as it is protected by the provider's rights and therefore does not count as exportable data (EUR-Lex, Article 2 point 38). Second, the operating history: metrics, alert thresholds and reports that came into being in the previous provider's management interface. Third, the ability to restore - a backup in a foreign format is of little use if it cannot be loaded into the target system. What a robust contingency plan looks like is set out in backup and disaster recovery for shops.

How we approach it

We start with the contract and the provider's website: which of the items from Chapter VI are present, which are missing, which deadlines appear in the text. Then follows the inventory of data per service with scope, format and dependencies; from that comes a schedule that fits inside the transitional period. If you first want to know where your own shop stands technically, a shop check is a sensible starting point; we then discuss the target architecture as part of our cloud services. If a platform change falls into the same window, it belongs in the same plan - as with the TYPO3 14 LTS upgrade.

The schedule does not end on 12 January 2027. By 12 September 2028 the Commission is to carry out an evaluation of the Regulation and submit a report on its main findings to the European Parliament and the Council (EUR-Lex, Article 49(2)); adjustments are therefore anticipated. Until then the version published in the Official Journal applies, and it can be held line by line against your own contract. If you would rather not run that review yourself, discuss your cloud contract with us.

Sources and studies

This article draws on Regulation (EU) 2023/2854 as published on EUR-Lex, on the German Data Act Application and Enforcement Act, on the Bundesnetzagentur press release of 30 May 2026, on press release no. 416 of the Federal Statistical Office of 24 November 2025, on the Eurostat cloud computing statistics and on the market investigation by the British competition authority of 31 July 2025. The Destatis figures describe companies in Germany with 10 or more employees, the Eurostat figures enterprises in the EU; the two surveys are not congruent and are not set against each other here. The figures from the British investigation relate to the United Kingdom. Figures can change with the survey date.

From 12 January 2027 providers of data processing services may no longer impose switching charges for the switching process (EUR-Lex). Until then reduced switching charges are permitted, which must not exceed the costs incurred by the provider that are directly linked to the switching process (EUR-Lex). The running standard service fees for the service itself are unaffected.

The notice period for initiating the switch may not exceed two months, the transitional period for the transfer may not exceed 30 calendar days, and at least 30 calendar days remain afterwards for data retrieval (EUR-Lex, Article 25). Where the transitional period is technically unfeasible, this must be notified within 14 working days and set at no more than seven months (EUR-Lex). The customer may extend the transitional period once.

For services the majority of main features of which have been custom-built for an individual customer and which are not offered at broad commercial scale, Article 23 point (d), Article 29 and Article 30(1) and (3) do not apply (EUR-Lex, Article 31(1)). That is not a full exemption: the switching contract under Article 25 with its deadlines and the information obligations continue to apply.

The Bundesnetzagentur is the competent authority for the application and enforcement of the Data Act under Section 2(1) of the German enforcement act (Federal Office of Justice) and has held that role since 30 May 2026 (Bundesnetzagentur). The fines catalogue in Section 15 covers, among other things, failure to make available the contract under Article 25 (Federal Office of Justice). Article 29 itself is not in that catalogue, so the route there runs via the contract and the supervisory authority.

The provider states on its website which jurisdiction the ICT infrastructure deployed for the respective service is subject to (EUR-Lex, Article 28(1) point (a)). For selecting a partner that is a checkable statement that can be documented. What role data sovereignty plays in choosing a location is explored in our article on the sovereign cloud for online shops.

The decisive concept is exportable data: input and output data, including metadata, directly or indirectly generated by the use of the service, excluding assets and data protected by intellectual property rights or constituting a trade secret of the provider (EUR-Lex, Article 2 point 38). In practice it is advisable to record the scope per service in writing beforehand.