What does cloud switching under the Data Act require of providers selling to the public sector?
|
In brief
|
Cloud switching under the Data Act is now a legal requirement for any provider of cloud services to customers in the EU. For providers selling cloud and AI services to central and local government in the Nordic countries, a credible exit route is quickly becoming a competitive factor in its own right. This article explains what Chapter VI of the Data Act requires, how its status differs between the EU and the EEA countries, and what providers should do now to stay competitive in public procurement.
Why is cloud exit becoming a procurement issue across the Nordics?
The switching rules in Regulation (EU) 2023/2854, known as the Data Act, have applied in the EU since 12 September 2025. Public bodies are customers like any other under the regulation. A Swedish agency, a Danish municipality or a Finnish hospital district buying cloud services is therefore already entitled to the switching rights in Chapter VI, and providers serving them must comply.
Political pressure points the same way. Dependence on a small number of large, mostly non-European technology providers is now treated as a question of security and preparedness, and public buyers are expected to show that they can leave a service without losing control of their data or their operations. That expectation translates directly into tender requirements on exit, data portability and transition assistance.
Norway illustrates the trend even though the Data Act does not yet apply there. On 29 September 2026 the Norwegian government announced a white paper on digital sovereignty, citing dependence on a few large providers, mainly from outside Europe, as a risk to security, preparedness and freedom of action. The Storting has already considered proposals for a national exit strategy for large international IT platforms in Innst. 225 S (2025–2026). In its draft budget for 2027 the government also proposes NOK 30 million for more joint purchasing agreements, including through the government marketplace for cloud services, with municipalities able to join voluntarily. The budget has not yet been adopted.
When purchasing volumes are consolidated into fewer and larger framework agreements, the cost of being locked in to a single provider rises. Buyers respond by tightening exit requirements, and providers with a documented exit route gain an advantage.
What does cloud switching under the Data Act cover?
Chapter VI (Articles 23–31) applies to providers of data processing services. Under Article 2(8), a data processing service is a digital service that gives the customer on-demand network access to a shared pool of configurable, scalable and elastic computing resources that can be rapidly provisioned and released. In practice the definition captures infrastructure, platform and software as a service (IaaS, PaaS and SaaS). AI delivered as a cloud service will often fall within it, although the boundary for some AI services has not been settled.
Under Article 1(3)(f), the regulation applies to such providers irrespective of their place of establishment, as long as they provide services to customers in the EU. A Norwegian or Icelandic provider with customers in Sweden, Denmark or Finland is therefore covered in respect of those customers.
Article 23 is the core obligation. Providers must not impose, and must remove, pre-commercial, commercial, technical, contractual and organisational obstacles that prevent customers from terminating the contract after the notice period, concluding a contract with a new provider, porting their exportable data and digital assets, or achieving functional equivalence with a new provider of the same service type. Where technically feasible, infrastructure services must also be capable of being unbundled from other services.
Does the Data Act apply in Norway and Iceland?
Not yet. As of 10 October 2026, the EFTA Secretariat lists the Data Act as under scrutiny for incorporation into the EEA Agreement by Iceland, Liechtenstein and Norway, and no EEA Joint Committee decision has been adopted. According to the Norwegian ministry’s EEA memorandum, implementation in Norway will require new legislation and therefore the consent of the Storting. No date for incorporation has been announced.
This has three practical consequences for providers in the region.
- Contracts with customers in EU member states must already comply with Chapter VI, regardless of where the provider is based.
- Contracts with Norwegian and Icelandic customers are currently governed by the contract and national law alone. Once the regulation is incorporated, it will apply there too, and long-term contracts signed today may still be running at that point.
- Public buyers in Norway can and do set equivalent requirements by contract. The Norwegian government’s standard IT contracts (SSA), including the cloud agreements SSA-sky and SSA-lille sky, were updated in 2026 and contain provisions on termination of cloud services and fees on termination.
Our assessment is that Chapter VI will become the practical benchmark for exit requirements in public tenders throughout the Nordic region, including in Norway before the regulation formally applies there.
What are the deadlines for switching cloud provider?
Article 25 sets mandatory deadlines that must be written into the contract. The table summarises the main rules.
| Element | Requirement | Legal basis |
|---|---|---|
| Notice period before switching starts | No more than two months | Art. 25(2)(d) |
| Transitional period | No more than 30 calendar days, during which the contract continues and the service must be maintained | Art. 25(2)(a) |
| Longer transitional period where technically unfeasible | Up to seven months, notified with reasons within 14 working days of the switching request | Art. 25(4) |
| Customer extension | The customer may extend the transitional period once | Art. 25(5) |
| Data retrieval period | At least 30 calendar days after the transitional period | Art. 25(2)(g) |
| Erasure | Full erasure of exportable data and digital assets after the retrieval period, once switching is complete | Art. 25(2)(h) |
| Switching charges | Cost-based charges only until 12 January 2027, prohibited thereafter | Art. 29 |
Taken together, providers should plan for roughly four months from the customer’s notice to the end of data retrieval, and considerably longer if the transitional period is extended. Service continuity and security must be maintained throughout.
What must a cloud contract contain under the Data Act?
Under Article 25(1), the customer’s rights and the provider’s obligations on switching must be set out in a written contract, made available to the customer before signing in a form the customer can store and reproduce. As a minimum, the contract must provide for the following.
- The customer must be able to switch to another provider, or port all exportable data and digital assets to its own infrastructure, within the deadlines. During the transitional period the provider must give reasonable assistance, maintain business continuity, flag known risks to continuity and ensure a high level of security (point (a)).
- The provider must support the customer’s exit strategy, including by providing all relevant information (point (b)).
- The contract is terminated when switching is successfully completed, or at the end of the notice period where the customer only wishes to erase its data (point (c)).
- The contract must exhaustively specify all categories of data and digital assets that can be ported, and any categories of internal operational data exempted to protect the provider’s trade secrets (points (e) and (f)).
- The contract must regulate the retrieval period, erasure and any switching charges (points (g), (h) and (i)).
Providers also have a separate duty to inform customers about switching procedures, methods and formats (Article 26), and all parties involved, including the destination provider, must cooperate in good faith (Article 27). Under Article 28, providers must publish on their websites the jurisdiction to which the infrastructure for each service is subject, together with a general description of their measures against unlawful access by third-country authorities to non-personal data held in the EU. Those websites must be referenced in the contract. This is precisely the information public buyers will ask for when digital sovereignty is high on the agenda.
Which data must be exported, and what may be withheld?
Under Article 2(38), exportable data means input and output data, including metadata, generated directly, indirectly or jointly through the customer’s use of the service. Assets and data protected by the intellectual property rights of the provider or third parties, or constituting their trade secrets, are excluded. Digital assets are defined in Article 2(32) as elements in digital form, including applications, which the customer has the right to use independently of the contract with the provider.
The trade secret exception is narrow. The exempted categories must be listed exhaustively in the contract, and the exception must not impede or delay switching.
AI services raise particular questions. A customer’s prompts, uploaded documents and generated outputs will normally be input and output data. It is less clear how logs, embeddings and models fine-tuned on customer data should be treated, since they may combine customer data with the provider’s protected technology. The law is unsettled here and we regard the uncertainty as significant. Providers should define these categories precisely in their contracts rather than leave the question to be resolved in a dispute.
Can cloud providers still charge for exit?
From 12 January 2027, providers may not impose any switching charges on customers (Article 29(1)). Until then, they may impose reduced charges that do not exceed the costs directly linked to the switching process concerned (Article 29(2) and (3)). Under Article 2(36), switching charges include data egress charges, meaning fees for transferring data over the network to another provider or to the customer’s own infrastructure.
Standard service fees and early termination penalties fall outside the definition of switching charges. Providers may therefore continue to invoice the ordinary service fee during the transitional period, when the contract remains in force, and may agree proportionate early termination penalties in fixed-term contracts. Before concluding the contract, the provider must give the customer clear information about standard service fees, early termination penalties and any reduced switching charges (Article 29(4)).
The boundary between the reasonable assistance the regulation requires and paid additional services, such as data transformation or migration consultancy, has not yet been tested. Many providers price such services separately. In our view it is defensible to charge for assistance that clearly goes beyond what the regulation requires, but our confidence in that view is moderate, and supervisory authorities may draw the line more strictly. Providers should therefore state in the contract what is included in the mandatory assistance and what is an additional service.
On 19 November 2025 the European Commission proposed a simplification package, the Digital Omnibus (COM(2025) 837), which among other things would clarify the scope for early termination penalties in certain contracts. The proposal was still under negotiation when we last checked, and its content may change.
What technical requirements apply to cloud switching?
Providers of infrastructure as a service must ensure functional equivalence with the destination service (Article 30(1)). Under Article 2(37), this means that the customer, on the basis of its exportable data and digital assets, can re-establish a minimum level of functionality with a service of the same type and obtain a materially comparable outcome from the same input for the features supplied under the contract.
For other services, typically platform and software as a service, Article 30 requires open interfaces and export of data in a structured, commonly used and machine-readable format. For SaaS providers, a documented export interface and well-defined data formats are in practice a precondition for compliance.
Which exemptions apply?
Article 31 contains two exemptions. Services whose main features have mostly been custom-built for a single customer, and which are not offered at broad commercial scale through the provider’s service catalogue, are exempt from the functional equivalence requirement, parts of the technical requirements and the rules on switching charges (Article 31(1)). The remaining obligations, including the contractual requirements in Article 25, apply in full. Non-production versions offered for a limited period for testing and evaluation are fully exempt (Article 31(2)). In both cases the provider must inform the customer before the contract is concluded which obligations do not apply (Article 31(3)).
Chapter VI currently contains no general exemption for small and medium-sized providers. The Digital Omnibus proposal would introduce transitional exemptions for contracts concluded on or before 12 September 2025, both for custom-made services and for small and mid-cap providers of services other than infrastructure. The proposal has not been adopted, and providers should not rely on it until it has.
Enforcement is national. Each member state designates competent authorities and lays down penalties for infringements (Article 40), so the practical risk of sanctions will vary between the Nordic EU countries.
How does cloud switching affect public tenders?
In the EU member states, a public buyer can simply require compliance with Chapter VI, since the regulation already applies to the contract. Many buyers will go further and set requirements on exit plans, data formats and transition assistance in the technical specification or the contract terms. In Norway and Iceland, the contract terms are currently decisive, and buyers can impose equivalent requirements by contract.
Deviations from tender documents carry real risk. Under EEA procurement law, tenders that deviate from mandatory requirements must generally be rejected. In Norway, the contracting authority must reject tenders containing material deviations from the procurement documents under section 24-8(1)(b) of the Public Procurement Regulations, and the Supreme Court held in HR-2025-1098-A that deviations from absolute requirements are material by definition, referring to the CJEU’s judgment in Case C-243/89 Storebælt. A provider that attaches its own terms with longer notice periods, egress fees or restricted data export risks rejection wherever the buyer has made the exit requirements mandatory.
Where the buyer instead uses exit and portability as an award criterion, a strong exit offering becomes a competitive advantage. We expect buyers to do this increasingly, particularly in large joint framework agreements. Providers whose terms already meet Chapter VI can document this directly in the tender.
Where the buyer’s requirements are unclear, providers should use the clarification process during the tender rather than submitting reservations. National procurement rules differ in detail between the Nordic countries, so the specific rejection rules should be checked for each jurisdiction.
What should Nordic cloud and AI providers do now?
- Map which services qualify as data processing services under Article 2(8), and identify which customers are located in the EU. Chapter VI already applies to those relationships.
- Prepare a single standard exit schedule that meets Article 25 and use it for all customers, including Norwegian and Icelandic public bodies. One contract framework is easier to maintain and gives a ready answer when exit is evaluated in a tender.
- Review the pricing model before 12 January 2027. Egress and switching charges must go for EU customers, and any exit costs must either be built into the ongoing service fee or handled through fixed terms with proportionate early termination penalties.
- Define the boundary between mandatory assistance and paid additional services on exit, so that customers know what is included and the provider does not take on open-ended transition obligations.
- Specify exportable data, formats and export interfaces. AI providers should take a clear position on logs, embeddings and fine-tuned models.
- Publish the information on jurisdiction and safeguards against third-country access required by Article 28. Public buyers will ask for it.
- Compare your exit terms with the standard contracts used by public buyers in each market, such as SSA-sky and SSA-lille sky in Norway, and identify where your terms could amount to deviations.
- Run a real exit test and document the result. A completed test is stronger evidence than a contract clause when buyers evaluate tenders.
Sources: Regulation (EU) 2023/2854 (Data Act), EUR-Lex · EFTA, EEA-Lex 32023R2854 · Norwegian Ministry of Digitalisation, EEA memorandum on the Data Act · Norwegian government press release, 29 September 2026 · Norwegian government press release, 7 October 2026 · Innst. 225 S (2025–2026) · Norwegian standard IT contracts (SSA) · Norwegian Public Procurement Regulations, Lovdata · HR-2025-1098-A
Last updated 10 October 2026
|
About the author Kjell Steffner · Advokat (Norwegian lawyer) Partner, Nordia Law Kjell Steffner is a partner at Nordia Law and heads the firm’s technology and IT practice. He advises providers and customers on IT contracts, cloud services, data protection, intellectual property and the legal risks of artificial intelligence. |