To remedy this, the Regulation prohibits providers from imposing any unjustified obstacle on their customers’ switching (whether changing provider or bringing the service in-house), whether pre-commercial, commercial, technical, contractual or organizational, and imposes minimum requirements on them designed to facilitate data reversibility.
Chapter VI of the Data Act has its own specific scope. It applies to contracts concluded by providers of data processing services within the meaning of the Regulation — that is, digital services enabling ubiquitous, on-demand access to a shared pool of computing resources, covering SaaS (Software as a Service), IaaS (Infrastructure as a Service) and PaaS (Platform as a Service) models.
As regards the data concerned, the Regulation applies to both personal data and non-personal data (Art. 1.2).
Two categories of services are expressly excluded from certain obligations arising from this chapter (Art. 31): (i) data processing services that are custom-built and not offered at large commercial scale, and (ii) services provided in test or beta version, for a limited period and for evaluation purposes.
As regards the temporal scope of application:
The Regulation might suggest that it grants the customer a right of early termination as soon as it wishes to change provider, bring the service in-house, or delete its data. Three provisions in particular could be misleading:
But Recital 9 of the Regulation is unambiguous in this respect: the Data Act does not affect (national) contract law. The Regulation contains no express provision creating an autonomous ground for termination in the customer’s favor. It is therefore always the contract, and the contract alone, that determines when and under what conditions the parties may end their relationship.
The Data Act facilitates switching once the contract has come to an end, whatever the reason for that termination.
On the other hand, the Data Act may have an indirect effect on the actual duration of the contractual commitment, insofar as the contract continues throughout the transitional period, during which the provider is required to continue providing the services (Art. 25(2)(a)). This 30-day period may be significantly extended.
A data reversibility process organized into four successive phases:
– Notification: the process begins with the customer notifying its intention to change provider or move to on-premises infrastructure (Art. 25.3). This notification marks the starting point of the notice period;
– Notice period (≤ 2 months): from the notification, the provider must ensure continuity of service. This period may not exceed two months (Art. 25.2.d), and any contractual clause providing for a longer notice period is deemed not written;
– Transitional period (≤ 30 days, or ≤ 7 months): once the notice period expires, the transitional migration period begins. This period may not exceed 30 calendar days (Art. 25.2.a), unless duly justified technical impossibility allows for an extension of up to 7 months (Art. 25.4). The customer may also request a single extension (Art. 25(5));
– End of contract: the contract ends upon completion of the provider-switching process. The provider must maintain access to exportable data for a minimum period of 30 calendar days, and must then completely erase all data.
A mandatory, regulated reversibility clause
The Data Act now requires the provider to include in the contract a reversibility clause meeting a minimum content defined by the Regulation. This clause must in particular specify:
– the scope of exportable data and the format in which data will be returned;
– the notice period, which may not exceed 2 months;
– the duration of the transition period (30 calendar days by default);
– the provider’s obligation to assist with the customer’s exit strategy;
– the applicable migration fees (until 12 January 2027, only actual direct costs incurred may be recharged, subject to prior notice – Art. 29);
– the provider’s obligation to completely erase the exportable data and digital assets at the end of the recovery period.
Any reversibility clause included in a contract covered by the Data Act must also withstand review under the rules on unfair contract terms (Art. 13). Early termination penalties would remain lawful, provided they are proportionate and do not amount to a financial lock-in equivalent to forced continuation of the contract.
Member States are responsible for providing for effective, proportionate and dissuasive penalties in the event of non-compliance with these obligations (Art. 40). In France, ARCEP has been designated as the competent authority responsible for monitoring compliance with the Regulation, in coordination with the CNIL for matters relating to personal data. Financial penalties could reach 3% of worldwide turnover (excluding tax) for the last closed financial year, rising to 5% in the event of repeat infringement. For legal entities that do not have a turnover figure allowing this ceiling to be determined, the penalty could be capped at €150,000, rising to €375,000 in the event of a further violation within five years.
In any event, the competent authority must, when setting the amount of the penalty, take into account the various criteria listed in Article 40(3) (in particular, the duration of the infringement, measures taken to mitigate or remedy the harm suffered, and the financial benefits obtained or losses avoided as a result of the infringement).
Authors :
Hello,
Thank you for your message; we have received it.
We will get back to you as soon as possible.
Yours sincerely,
Altaïr Avocats