Does the EU Data Act Apply to Our SaaS - and What Do Buyers Expect Before January 2027?
An EU customer - or a US buyer with an EU entity - asks for your switching process, export formats, and Data Act contract language. You already have a DPA and a SOC 2 report. The instinct is that privacy readiness covers it. For Regulation (EU) 2023/2854, that instinct is incomplete.
This post is for growth SaaS founders, Heads of Sales or RevOps, and lone compliance/privacy owners selling into the EU who need a clear read on whether they are a data processing service, what Article 25 switching rights look like in deals, and what belongs on a Trust Center before the 12 January 2027 free-switching clock. It is GTM packaging and scope framing - not legal advice, and not a promise that Workstreet rewrites your counsel's MSA.
Short answer: does the EU Data Act apply to our SaaS?
Often yes - if customers store and process their own data in your cloud product. The Data Act has applied since 12 September 2025 to providers of data processing services. That label commonly includes B2B SaaS where the customer's intent is to process their data (CRM, project tools, HR, fintech, and similar). US headquarters does not exempt you if you serve EU customers (Sedlakova Legal, 30 Apr 2026; Maples Group, 17 Apr 2026).
The Data Act is not GDPR. GDPR is about personal data. The Data Act's switching chapter is about limiting vendor lock-in for cloud-style services: notice to start switching, transitional assistance, portable data categories, retrieval then erasure, and a phase-out of switching charges. Treat GDPR readiness as necessary but not sufficient for this ask.
Are we a data processing service? The Art. 2(8) scope test
Not every SaaS is automatically in. Article 2(8) describes a digital service that gives on-demand network access to a shared pool of configurable, scalable, elastic computing resources that can be rapidly provisioned and released with minimal management effort. Sedlakova's practical framing (30 Apr 2026) breaks the test into four features teams can actually check:
1. Access to computing resources (networks, servers, storage, applications - the as-a-service stack).
2. On-demand network access from standard customer devices.
3. Rapid provisioning without heavy provider intervention.
4. Elasticity and scaling with demand.
The Commission's clarifying lens, as summarized in that same guide: customer intent matters. If the customer contracts primarily to store and process their own data, the service tends to fall in. If data processing is a side effect of content delivery (music streaming, many pure e-learning content products), it may fall out. Fully custom one-off builds for a single client can sit outside under Article 31(1)-style custom-made framing; multi-tenant commercial B2B SaaS usually does not.
In practice, most CRM, project management, cloud ERP, and similar B2B tools fall in; streaming/content-only and true bespoke builds are the common outs. Maples (17 Apr 2026) is explicit that complex software services still need careful assessment against the definition - do not invent a bright-line Workstreet legal opinion. Run a service-by-service check and document the conclusion for sales and counsel.
A one-page internal scope note is enough for most growth teams: product name, whether customers primarily process their own data, multi-tenant vs custom-built, EU customer presence, and a yes/no/needs-counsel flag. That note becomes the source for Trust Center language and questionnaire rows so AEs are not improvising scope on a live deal thread.
Digital Omnibus proposals discussed by Maples may lighten some SME/custom-made paths; treat those as secondary context until they are law, not as a reason to skip today's Art. 25 packaging.
What buyers and contracts now expect under Article 25
When a prospect or customer asks for Data Act switching, they are usually asking for the Article 25 parameter set to show up in the contract and in customer-facing docs. Drawing on Sedlakova (30 Apr 2026) and Maples (17 Apr 2026):
| Parameter | Practical expectation |
|---|---|
| Notice to start switching | Maximum 2 months |
| Transitional assistance | Maximum 30 calendar days after notice ends (Maples: if technically unfeasible, notify within 14 working days with a justified alternative not exceeding seven months) |
| Portable data | Exhaustive categories of exportable data and digital assets (plus clear trade-secret exceptions where used) |
| Retrieval then erasure | At least 30 days to retrieve after the transitional period, then full erasure of exportable customer data/assets |
| Switching charges | Direct costs only until 12 January 2027, then zero switching charges |
Providers must also avoid obstacles that block termination for switching, multi-homing, porting to on-prem, or unbundling, and cooperate in good faith with source and destination providers (Maples, 17 Apr 2026). Functional equivalence and interoperability expectations vary by IaaS / PaaS / SaaS delivery model - another reason SaaS teams should not copy-paste an IaaS exit clause blindly.
Export format practice among addenda Sedlakova describes (Asana JSON, Pipedrive XLSX, Talon.One CSV/JSON) is useful as a format pattern, not an endorsement: structured, commonly used, machine-readable. You choose a compliant format; you are not required to build one-off converters for every customer's preferred schema. Premium assisted migration can stay a paid add-on by agreement.
Switching is not free termination-for-convenience
This is the distinction that saves bad AE answers. Article 25 creates a right to switch, not a general right to walk away from a fixed-term deal for any reason. Sedlakova (30 Apr 2026) stresses that the two-month notice is to initiate switching, not a blank termination-for-convenience coupon. Recital 89 framing, as those sources summarize, still allows fixed-term contracts and reasonable early-termination penalties - separate from banned or capped switching charges.
In plain GTM language:
- Switching fees for export/transfer/cooperation - direct costs only until 12 Jan 2027, then prohibited.
- Standard subscription fees during the notice and transitional period - still owed under the contract.
- Reasonable early-exit penalties on a fixed term - still possible if transparent and proportionate (get counsel; do not invent a penalty formula from a blog post).
If your AE says Data Act means customers can cancel anytime for free, correct that before it lands in a negotiation email.
What to publish on a Trust Center (and link from the MSA)
The Data Act expects public, up-to-date information - not only a clause buried in a PDF. Sedlakova's website disclosure list (30 Apr 2026), aligned with Maples' transparency obligations, is a practical Trust Center checklist:
1. Description of the switching process (steps, methods, formats, known technical limits).
2. Online export / data-structure documentation (schemas, formats, interoperability specs).
3. Jurisdiction of the ICT infrastructure holding customer data.
4. Safeguards against unlawful international governmental access to non-personal data held in the Union.
Common vendor pattern in Sedlakova's examples: a separate Data Act addendum (not a full MSA rewrite) plus a public page or Trust Center section linked from ToS / MSA / application terms. That is the same GTM habit as publishing attestation and subprocessors where buyers already look - see building trust with a company trust page.
When the ask arrives as a questionnaire row rather than a contract redline, package the same facts once and reuse them; see security compliance questionnaires.
Minimum GTM pack before January 2027:
1. Public switching page (or Trust Center section) covering the four disclosure items above.
2. Data Act addendum or MSA clause set that mirrors Art. 25 parameters - drafted with counsel, linked from the public page.
3. Export runbook your support/engineering team can execute (who triggers it, which tenant data, which format, how long retrieval lasts, how erasure is confirmed).
4. AE one-pager that separates switching rights from early-termination penalties so pricing conversations stay accurate.
You do not need a novel legal theory for every RFP. You need consistent artifacts that match what Sedlakova and Maples describe buyers and regulators now expect to see in writing.
How this differs from DORA, NIS2, CRA, and GDPR
Same EU-buyer confusion family, four different objects:
| Data Act (this post) | DORA | NIS2 | CRA | |
|---|---|---|---|---|
| Object | Commercial switching / portability for data processing services | EU financial ICT third-party resilience | Essential/important entities + supply-chain cybersecurity | Products with digital elements / Art. 14 reporting |
| Typical SaaS feeling | Exit, export, notice, website disclosure | Financial-entity ICT questionnaires and clauses | Article 21 supplier questionnaires | Product-scope / remote-data-processing questions |
| Sibling | This post | DORA compliance | NIS2 for US SaaS | Cyber Resilience Act for SaaS |
GDPR still owns personal data, DPIAs, and DSARs. A clean DPA does not answer Art. 25. A CRA pure SaaS is usually out memo does not answer switching. A NIS2 Pathway C evidence pack does not replace export documentation. Keep the narratives separate so reviewers do not get a franken-answer.
Clocks worth putting on the wall
Cite-only timeline from Sedlakova and Maples:
| Date | What changes |
|---|---|
| 12 September 2025 | Data Act applicability for Chapter VI on new contracts; switching framework live for those deals |
| 19 November 2025 | Commission draft non-binding SCCs for cloud (Maples) - reference drafting aid, not a Workstreet template CTA |
| February 2026 | Irish Data Bill General Scheme; ComReg framed for Arts. 23-31; Maples notes administrative sanctions framing up to 4% of annual EU turnover for undertakings under that scheme |
| 12 January 2027 | Switching charges must be zero |
| 12 September 2027 | Chapter VI applies to pre-12 Sep 2025 contracts still in force |
Secondary context only: connected-product / IoT expansions around Sep 2026 in Sedlakova's timeline are out of scope for this pure SaaS switching post. Do not invent additional fine schedules beyond what named sources state.
Soft next step
If EU buyers are asking for switching process docs, export formats, and Trust Center jurisdiction language, and your team is assembling answers from scratch each deal, Workstreet can help package a privacy / Trust Center readiness set - public disclosure pages, questionnaire-ready scope language, and privacy / vCPO ownership as EU commercial asks scale. That is packaging and program help, not a claim that Workstreet replaces EU counsel or rewrites your MSA as legal advice.

