Here is the timeline hosted-cloud customers in the EU are now operating under, whether their vendor has told them or not: since September 12, 2025, a provider can hold a switching request for at most two months before starting the clock, then has a maximum of 30 calendar days to actually move exportable data and digital assets to a new provider or back on-premises. Switching fees are capped at cost-recovery today. On January 12, 2027, they disappear entirely. Miss any of it, and national regulators can fine a provider up to 4% of annual EU turnover.
That's not a proposal or a draft — it's Chapter VI of Regulation (EU) 2023/2854, the Data Act, and the switching regime (Articles 23-31) has already been live for almost a year. What makes it worth a second look now isn't that it's new; it's that the 2027 fee ban is close enough to change vendor behavior today, and the mechanics of what the law actually forces a provider to hand over are narrower — and more specific — than the "no more vendor lock-in" headlines suggest. Below is the full timeline, what counts as portable under the law, who enforces it, and where the guarantee still runs out before a "just leave" migration actually is one.
The Switching Timeline, Start to Finish
The Data Act entered into force on January 11, 2024, but the switching provisions became applicable on September 12, 2025 — that's the date every clause below has been enforceable since. The regime runs in four phases:
| Phase | Deadline | What it requires |
|---|---|---|
| Notice period | Max 2 months | Customer notifies intent to switch; provider can't stall past this before starting the transition clock |
| Transition period | Max 30 calendar days | Provider must actively assist the move — maintain service continuity, keep security intact, and export data/assets to the new provider or on-premises |
| Data retrieval window | Min 30 calendar days after transition ends | Customer can still retrieve exportable data; provider can't delete early |
| Full erasure | After retrieval window closes | Provider must fully erase the customer's exportable data and digital assets |
Contracts have to spell out, in advance, an exhaustive list of exactly which data and digital assets are exportable — a provider can't discover new "non-exportable" categories mid-switch. That's the structural fix for the most common complaint about cloud exits: vague contract language that lets a vendor negotiate the terms of your own departure after you've already announced you're leaving.
The Fee Ban's Real Date Is 2027, Not 2025
This is the part that gets flattened in coverage: switching fees aren't banned yet. From the Data Act's 2024 entry into force through January 12, 2027, providers are allowed to charge switching fees — but only "cost-covering charges," meaning the charge has to map to costs the provider actually incurs facilitating the move, disclosed transparently and agreed in advance. No punitive exit pricing, no undisclosed reformatting surcharges, but also no free lunch during the transition period.
From January 12, 2027, that changes completely: all switching charges are prohibited, full stop. What survives the ban is narrower than "everything is free" — standard subscription fees keep running until a contract ends, proportionate early-termination fees in fixed-term contracts are still allowed, and bespoke work outside the regulatory switching scope (say, a custom export format nobody was contractually promised) can still be billed. But the line item that funds a lot of hosted-cloud stickiness today — the fee for the act of leaving — goes to zero for every customer covered by the Act, not just the ones big enough to negotiate it away.
Who Enforces This, and What It Costs to Get It Wrong
The Data Act leaves enforcement to individual member states rather than a single EU body, and two data points show how seriously that's being taken. Ireland's Commission for Communications Regulation (ComReg) has been designated the competent authority specifically for Articles 23-31 and 34-35 — the switching and international-transfer provisions — giving the switching regime its own dedicated regulator rather than folding it into a generalist data-protection office. Germany has gone further, naming its Federal Network Agency (Bundesnetzagentur) as central enforcer with fines up to 4% of annual EU turnover or €5 million, whichever is higher, mirroring GDPR-scale exposure.
That 4%-of-turnover ceiling is the number that should reframe how a hosted provider prices "sticky" contract terms. A switching-fee structure that looks like a rounding error against a customer's total spend can still be argued as a violation carrying a fine benchmarked against the provider's own global revenue — a very different risk calculation than the one that governed cloud contracts for the past decade.
The Hyperscalers Already Tried to Get Ahead of This — And the Gaps Show the Law's Point
AWS, Google Cloud, and Microsoft Azure didn't wait for enforcement to start moving. Google Cloud announced it would waive egress fees for departing customers in early 2024; AWS followed within weeks, framing it as "customer choice"; Microsoft followed with Azure, citing the same regulatory pressure. On paper, that looks like voluntary compliance arriving ahead of the mandate. In practice, the fine print shows exactly why a legal floor was necessary instead of trusting providers to self-regulate the terms of their own exit.
Azure's version requires the customer to formally terminate the subscription, apply for credits within a 60-day window, and — in the at-cost transfer option — move the data to a destination that is, in Microsoft's own terms, "a service operated by the same customer." That last condition is a meaningful restriction: it's not a free lane to any new provider, it's a free lane back to yourself. Google's and AWS's programs carry their own conditions and caps. None of this is dishonest, exactly — it's a genuinely cheaper exit than existed in 2023. But it's also a preview of what "the vendor decides what counts as a fair switching cost" looks like when there's no statutory floor under it, which is precisely the gap Articles 23-31 are built to close by January 2027.
What the Law Doesn't Reach
The Act's guarantee is narrower than "your whole application becomes portable." It covers two defined categories: exportable data (the input/output data and metadata a customer's use of the service generates, explicitly excluding the provider's own IP, trade secrets, or security-sensitive internals) and digital assets the customer already has an independent right to use — things like configuration of settings, access controls, and rights-management state that exist apart from the switching contract itself.
What that leaves out matters. A running application's full operational state — its build pipeline quirks, provider-specific glue code, bespoke integrations wired against one platform's proprietary APIs — isn't automatically "exportable" just because the underlying data is. The Data Act forces a provider to hand back what you own and generated; it doesn't retroactively make an application architecture that was never designed to be portable actually portable. Reading the law as "the EU solved vendor lock-in" overstates what Chapter VI does. Reading it as "the EU eliminated the parts of lock-in that were pure vendor friction, and left the parts that are genuine architecture decisions" is the accurate version.
What This Means If You Never Signed Up for the Lock-In in the First Place
For a hosted PaaS, the Data Act is a compliance floor arriving on a fixed schedule — every provider covered by it has to build the same notice-period, transition-window, and fee-elimination machinery by January 2027, whether or not it was ever part of their product roadmap. For a team running its own infrastructure — a Cluster API-managed fleet on hardware it owns, with its own git repos, its own container images, its own DNS — none of Articles 23-31 apply, because there's no vendor relationship to switch out of. The data was never someone else's to hold hostage during a 30-day transition window; it was already yours.
That's the honest framing worth taking from this: the Data Act is forcing hosted-cloud vendors to eventually offer, under legal threat of a 4%-of-turnover fine, the baseline that self-hosted infrastructure gives away for free by construction. It's not a new capability question for anyone already running their own machines — it's a regulatory deadline for everyone else to catch up to where owned infrastructure already was.
Bex.co is the open-source, AI-native Render alternative — push a git repo, get a running HTTPS service on machines you own, with a Render-compatible API and no vendor switching clock to watch. Star the repo on GitHub or deploy your first app today.



