BLOG
October 1, 2026
decorative
Travis Good

Does the EU Data Act Apply to Our SaaS - and What Do Buyers Expect Before January 2027?

Most B2B SaaS is a Data Act data processing service. Switching clocks, portability, and Trust Center disclosures buyers expect before January 2027.
Abstract illustration for EU Data Act switching and portability obligations for SaaS

An EU customer - or a US buyer with an EU entity - asks for your switching process, export formats, and Data Act contract language. You already have a DPA and a SOC 2 report. The instinct is that privacy readiness covers it. For Regulation (EU) 2023/2854, that instinct is incomplete.

This post is for growth SaaS founders, Heads of Sales or RevOps, and lone compliance/privacy owners selling into the EU who need a clear read on whether they are a data processing service, what Article 25 switching rights look like in deals, and what belongs on a Trust Center before the 12 January 2027 free-switching clock. It is GTM packaging and scope framing - not legal advice, and not a promise that Workstreet rewrites your counsel's MSA.

Short answer: does the EU Data Act apply to our SaaS?

Often yes - if customers store and process their own data in your cloud product. The Data Act has applied since 12 September 2025 to providers of data processing services. That label commonly includes B2B SaaS where the customer's intent is to process their data (CRM, project tools, HR, fintech, and similar). US headquarters does not exempt you if you serve EU customers (Sedlakova Legal, 30 Apr 2026; Maples Group, 17 Apr 2026).

The Data Act is not GDPR. GDPR is about personal data. The Data Act's switching chapter is about limiting vendor lock-in for cloud-style services: notice to start switching, transitional assistance, portable data categories, retrieval then erasure, and a phase-out of switching charges. Treat GDPR readiness as necessary but not sufficient for this ask.

Are we a data processing service? The Art. 2(8) scope test

Not every SaaS is automatically in. Article 2(8) describes a digital service that gives on-demand network access to a shared pool of configurable, scalable, elastic computing resources that can be rapidly provisioned and released with minimal management effort. Sedlakova's practical framing (30 Apr 2026) breaks the test into four features teams can actually check:

1. Access to computing resources (networks, servers, storage, applications - the as-a-service stack).

2. On-demand network access from standard customer devices.

3. Rapid provisioning without heavy provider intervention.

4. Elasticity and scaling with demand.

The Commission's clarifying lens, as summarized in that same guide: customer intent matters. If the customer contracts primarily to store and process their own data, the service tends to fall in. If data processing is a side effect of content delivery (music streaming, many pure e-learning content products), it may fall out. Fully custom one-off builds for a single client can sit outside under Article 31(1)-style custom-made framing; multi-tenant commercial B2B SaaS usually does not.

In practice, most CRM, project management, cloud ERP, and similar B2B tools fall in; streaming/content-only and true bespoke builds are the common outs. Maples (17 Apr 2026) is explicit that complex software services still need careful assessment against the definition - do not invent a bright-line Workstreet legal opinion. Run a service-by-service check and document the conclusion for sales and counsel.

A one-page internal scope note is enough for most growth teams: product name, whether customers primarily process their own data, multi-tenant vs custom-built, EU customer presence, and a yes/no/needs-counsel flag. That note becomes the source for Trust Center language and questionnaire rows so AEs are not improvising scope on a live deal thread.

Digital Omnibus proposals discussed by Maples may lighten some SME/custom-made paths; treat those as secondary context until they are law, not as a reason to skip today's Art. 25 packaging.

What buyers and contracts now expect under Article 25

When a prospect or customer asks for Data Act switching, they are usually asking for the Article 25 parameter set to show up in the contract and in customer-facing docs. Drawing on Sedlakova (30 Apr 2026) and Maples (17 Apr 2026):

ParameterPractical expectation
Notice to start switchingMaximum 2 months
Transitional assistanceMaximum 30 calendar days after notice ends (Maples: if technically unfeasible, notify within 14 working days with a justified alternative not exceeding seven months)
Portable dataExhaustive categories of exportable data and digital assets (plus clear trade-secret exceptions where used)
Retrieval then erasureAt least 30 days to retrieve after the transitional period, then full erasure of exportable customer data/assets
Switching chargesDirect costs only until 12 January 2027, then zero switching charges

Providers must also avoid obstacles that block termination for switching, multi-homing, porting to on-prem, or unbundling, and cooperate in good faith with source and destination providers (Maples, 17 Apr 2026). Functional equivalence and interoperability expectations vary by IaaS / PaaS / SaaS delivery model - another reason SaaS teams should not copy-paste an IaaS exit clause blindly.

Export format practice among addenda Sedlakova describes (Asana JSON, Pipedrive XLSX, Talon.One CSV/JSON) is useful as a format pattern, not an endorsement: structured, commonly used, machine-readable. You choose a compliant format; you are not required to build one-off converters for every customer's preferred schema. Premium assisted migration can stay a paid add-on by agreement.

Switching is not free termination-for-convenience

This is the distinction that saves bad AE answers. Article 25 creates a right to switch, not a general right to walk away from a fixed-term deal for any reason. Sedlakova (30 Apr 2026) stresses that the two-month notice is to initiate switching, not a blank termination-for-convenience coupon. Recital 89 framing, as those sources summarize, still allows fixed-term contracts and reasonable early-termination penalties - separate from banned or capped switching charges.

In plain GTM language:

  • Switching fees for export/transfer/cooperation - direct costs only until 12 Jan 2027, then prohibited.
  • Standard subscription fees during the notice and transitional period - still owed under the contract.
  • Reasonable early-exit penalties on a fixed term - still possible if transparent and proportionate (get counsel; do not invent a penalty formula from a blog post).

If your AE says Data Act means customers can cancel anytime for free, correct that before it lands in a negotiation email.

What to publish on a Trust Center (and link from the MSA)

The Data Act expects public, up-to-date information - not only a clause buried in a PDF. Sedlakova's website disclosure list (30 Apr 2026), aligned with Maples' transparency obligations, is a practical Trust Center checklist:

1. Description of the switching process (steps, methods, formats, known technical limits).

2. Online export / data-structure documentation (schemas, formats, interoperability specs).

3. Jurisdiction of the ICT infrastructure holding customer data.

4. Safeguards against unlawful international governmental access to non-personal data held in the Union.

Common vendor pattern in Sedlakova's examples: a separate Data Act addendum (not a full MSA rewrite) plus a public page or Trust Center section linked from ToS / MSA / application terms. That is the same GTM habit as publishing attestation and subprocessors where buyers already look - see building trust with a company trust page.

When the ask arrives as a questionnaire row rather than a contract redline, package the same facts once and reuse them; see security compliance questionnaires.

Minimum GTM pack before January 2027:

1. Public switching page (or Trust Center section) covering the four disclosure items above.

2. Data Act addendum or MSA clause set that mirrors Art. 25 parameters - drafted with counsel, linked from the public page.

3. Export runbook your support/engineering team can execute (who triggers it, which tenant data, which format, how long retrieval lasts, how erasure is confirmed).

4. AE one-pager that separates switching rights from early-termination penalties so pricing conversations stay accurate.

You do not need a novel legal theory for every RFP. You need consistent artifacts that match what Sedlakova and Maples describe buyers and regulators now expect to see in writing.

How this differs from DORA, NIS2, CRA, and GDPR

Same EU-buyer confusion family, four different objects:

Data Act (this post)DORANIS2CRA
ObjectCommercial switching / portability for data processing servicesEU financial ICT third-party resilienceEssential/important entities + supply-chain cybersecurityProducts with digital elements / Art. 14 reporting
Typical SaaS feelingExit, export, notice, website disclosureFinancial-entity ICT questionnaires and clausesArticle 21 supplier questionnairesProduct-scope / remote-data-processing questions
SiblingThis postDORA complianceNIS2 for US SaaSCyber Resilience Act for SaaS

GDPR still owns personal data, DPIAs, and DSARs. A clean DPA does not answer Art. 25. A CRA pure SaaS is usually out memo does not answer switching. A NIS2 Pathway C evidence pack does not replace export documentation. Keep the narratives separate so reviewers do not get a franken-answer.

Clocks worth putting on the wall

Cite-only timeline from Sedlakova and Maples:

DateWhat changes
12 September 2025Data Act applicability for Chapter VI on new contracts; switching framework live for those deals
19 November 2025Commission draft non-binding SCCs for cloud (Maples) - reference drafting aid, not a Workstreet template CTA
February 2026Irish Data Bill General Scheme; ComReg framed for Arts. 23-31; Maples notes administrative sanctions framing up to 4% of annual EU turnover for undertakings under that scheme
12 January 2027Switching charges must be zero
12 September 2027Chapter VI applies to pre-12 Sep 2025 contracts still in force

Secondary context only: connected-product / IoT expansions around Sep 2026 in Sedlakova's timeline are out of scope for this pure SaaS switching post. Do not invent additional fine schedules beyond what named sources state.

Soft next step

If EU buyers are asking for switching process docs, export formats, and Trust Center jurisdiction language, and your team is assembling answers from scratch each deal, Workstreet can help package a privacy / Trust Center readiness set - public disclosure pages, questionnaire-ready scope language, and privacy / vCPO ownership as EU commercial asks scale. That is packaging and program help, not a claim that Workstreet replaces EU counsel or rewrites your MSA as legal advice.

Turn compliance into a growth engine: Workstreet delivers full-stack solutions that transform security and compliance into growth accelerators. Talk to an expert →
Build trust, accelerate growth.
Workstreet offers Al-first security solutions that help high growth technology companies get compliant, scale securely, and close bigger deals.
Get started
Ready to Transform Security into a Growth Advantage
Schedule a consultation with our trust solutions experts to see how we can accelerate your security program and compliance journey.
Talk to an engineer
Travis Good

Architect of security and privacy programs for 1,000+ hypergrowth companies. Author of "Complete Cloud Compliance," HITRUST 3rd Party Council member, and recognized speaker on startup security.