top of page

The EU Data Act became applicable on 12 September 2025 and introduced new obligations aimed at making it easier for customers to switch service providers. The objective is to prevent so-called vendor lock-in and require cloud service providers to compete on service quality and pricing, rather than allowing customers to become tied to a service because of technical or contractual barriers.


The Data Act requires cloud service providers to enable customers to switch services with a notice period of no more than two months. The rules apply to services including IaaS, PaaS and SaaS.


However, the reform directly affects the core of many SaaS companies’ business models. Many SaaS services are sold under fixed-term agreements, often for one year or several years, and the business model is based on annual recurring revenue, or ARR. Service providers typically offer a lower monthly price to customers who commit to annual billing. The possibility of switching service providers during the contractual term under the Data Act therefore raises questions about the binding nature of fixed-term agreements.


Does the Data Act allow a fixed-term SaaS agreement to be terminated during the contractual term?


The Data Act does not create a general, entirely unrestricted and consequence-free right of termination in all circumstances. It does, however, give customers the right to switch service providers or move to their own solution with a notice period of no more than two months, and generally a transition period of one month, at limited cost. This applies even during the term of a fixed-term agreement where the cloud service falls within the scope of the Data Act. In practice, the outcome comes very close to a “free right of termination” in the situation that matters most to the customer, namely when the customer wishes to switch providers and take its data with it.


During the switching process, the previous service provider must continue providing the service and assist with the transfer of data. Once the switching process has been completed, the agreement and the customer’s payment obligation come to an end. The agreement will therefore generally end three months after the customer gives notice of its intention to switch, as the notice period is two months and the transition period is usually one month.


Can a SaaS provider charge for early termination or assistance with the switching process?


The Data Act permits two types of charges that a service provider may, to a limited extent, impose in connection with the switching process: switching charges and early termination penalties under fixed-term agreements.


During the transitional period ending on 12 January 2027, the Data Act allows service providers to charge fees for switching services where those fees are based on direct and demonstrable costs. After 12 January 2027, switching charges will be prohibited altogether. Customers may not be charged for transferring their data to another cloud service or to their own environment to the extent that the transfer falls within the minimum obligations imposed by the Data Act. Even after the transitional period, customers may purchase additional services that go beyond the minimum obligations, and the service provider may charge for those services where they are provided at the customer’s request and the customer has accepted the price in advance.


The Data Act also allows a SaaS provider to include a “proportionate” penalty in the agreement for terminating a fixed-term agreement before the end of its contractual term. The customer must be informed of such a penalty before the agreement is concluded.


The Data Act does not define what “proportionate” means. In practice, however, the penalty must be proportionate to the actual costs incurred by the service provider, such as investments made on the basis of the agreed contractual term or expenditure relating to the implementation of the service. The penalty may not be used as a concealed switching charge or as a means of preventing switching by making it financially difficult.


From the provider’s perspective, it is therefore necessary to consider which costs arise specifically because the agreement ends earlier than expected. The provider must also assess whether the penalty has been calculated on the basis of those costs or whether its actual purpose is to keep the customer tied to the service. If the latter is the case, the arrangement is likely to be risky under the Data Act.


What contractual obligations does the Data Act impose on SaaS providers?


The Data Act requires SaaS providers to include contractual terms concerning the switching of services in their service agreements. When updating their agreements, SaaS providers may choose to use the model contractual terms published by the European Commission on 19 November 2025. The use of the model terms is voluntary, and the Commission’s objective is to help parties comply with the Data Act in a consistent manner.


It should also be noted that on 19 November 2025, the Commission published its Digital Omnibus proposal, which would introduce lighter cloud switching obligations for small service providers and customised services. The proposed relief would apply to agreements concluded before 12 September 2025. At this stage, it is only a Commission proposal, and its final content may still change.


What should companies do now?


  • Service agreements should be updated to include the contractual terms concerning switching service providers required by the Data Act.


  • SaaS providers should consider whether their service agreements should include a penalty for the early termination of a fixed-term agreement.


  • In the longer term, providers should reconsider their business models in anticipation of customers being able to switch to competitors more easily and at a lower cost. From the SaaS provider’s perspective, the focus of revenue generation will increasingly shift towards the value of the service, customer experience and continuous customer satisfaction.


We have familiarised ourselves with the requirements of the Data Act and assisted SaaS providers in updating their contractual terms accordingly. Should you require advice or practical assistance in updating your own terms or exercising the right to switch services, our contracts team is ready to help.


Folksin Counsel Lila Kallio seisoo valkoisessa paidassa hymyilee ja seisoo ruskeaa tiiliseinää vasten. Aurinkoinen ja rento tunnelma.


Lila Kallio Counsel lila.kallio@legalfolks.fi

+358 41 465 1365









To receive our articles directly by email, subscribe to the Folks newsletter here.

EU digital regulation has undergone a major transformation in recent years. New legislation has been introduced at a rapid pace in areas ranging from online services and artificial intelligence to data use and cybersecurity. Nor does the pace appear to be slowing, as further obligations will become applicable in the near future.


Below, we have compiled an overview of recent developments in digital regulation and the new obligations on the horizon.


Major online platforms under scrutiny


The EU Digital Services Act, or DSA, entered into application in stages during 2023 and 2024. It imposes extensive obligations on various digital service platforms, including requirements to address illegal content and improve transparency towards users. The European Commission and national supervisory authorities have already initiated their first enforcement actions. X, for example, is being investigated for potential infringements relating to practices that manipulate users and a lack of transparency in advertising.

Very large online platforms acting as so-called gatekeepers have also had to update their practices since May 2023 as a result of the EU Digital Markets Act, or DMA. The DMA aims to improve competition and transparency within the ecosystems of major technology platforms. In April 2025, the European Commission imposed the first fines under the DMA. Apple was fined EUR 500 million for restrictions imposed in its App Store that prevented application developers from making sufficient use of alternative distribution channels. Meta was fined EUR 200 million for its “consent or pay” model, which required Facebook and Instagram users to pay in return for more limited processing of their personal data.


Towards risk-based AI regulation With enthusiasm around artificial intelligence at its peak, the first obligations under the EU AI Act became applicable in February 2025. The development, provision and use of AI systems involving prohibited practices must now be discontinued. Organisations have also had to consider what types of training and other measures are needed to meet their obligation to ensure an adequate level of AI literacy.

To clarify some of the questions left open by the AI Act, the Commission published non-binding guidance in early 2025 on matters including the definition of an AI system, prohibited AI practices and the AI literacy obligation. Further changes are approaching rapidly, as the remaining obligations under the AI Act will become applicable in stages between 2025 and 2027. The requirements concerning high-risk AI systems will have a particularly significant effect on both providers and deployers.


Fairer rules for the data market As data plays an increasingly important role in society, the EU has sought to facilitate its free movement between different operators within the internal market. A key legislative initiative supporting this strategy is the Data Act, most of whose obligations will apply from 12 September 2025. The regulation focuses particularly on connected products and Internet of Things devices. In future, users of these devices must be given access to the data generated by them. The Data Act also prohibits the use of unfair contractual terms relating to data where such terms have been unilaterally imposed on another business.

The Data Act will also affect cloud services, and vendor lock-in situations are expected largely to become a thing of the past. Among other things, switching charges that restrict customers from changing cloud service providers will gradually be abolished. Cloud service providers will be required to assist customers with switching services, and customers will be entitled to terminate a cloud service with two months’ notice. The near future will show how the detailed contractual practices develop and what effects the obligations under the Data Act will have, for example, on the pricing of cloud services.


Preparing for cybersecurity threats through regulation


The obligations under the long-awaited NIS2 Directive entered into force in Finland on 8 April 2025, when the Directive was finally implemented nationally through the Cybersecurity Act. As cybersecurity threats increase, organisations operating in critical sectors now have statutory obligations to manage cybersecurity risks and notify the authorities of significant security incidents. The new cybersecurity regulatory framework does not end with the Cybersecurity Act. Further requirements will follow in the coming years under the Cyber Resilience Act, or CRA. The CRA will apply to hardware and software products with digital elements that can be connected, either directly or indirectly, to another device or network. Operators falling within its scope still have time to prepare. The obligations concerning the reporting of vulnerabilities will apply from 11 September 2026, while the requirements concerning the cybersecurity features of products will apply from 11 December 2027.


Cybersecurity threats have also been addressed through sector-specific regulation. In particular, the Digital Operational Resilience Act, or DORA, which became applicable on 17 January 2025, has had a significant impact both on financial-sector entities and on IT service providers supplying services to the financial sector. The beginning of the year saw an extensive round of contract updates as the requirements of DORA were negotiated into agreements between financial entities and IT service providers. The Commission has also drafted and published several regulatory technical standards specifying the requirements of DORA in greater detail. Supervisory authorities are currently carrying out criticality assessments aimed at identifying the critical IT service providers that will become subject to direct regulatory oversight. The designations are expected to take effect in autumn 2025.


What does the future hold?


Within just a few years, the EU’s digital regulatory framework has developed into an extensive body of legislation with a genuine impact on companies’ day-to-day operations. The breadth of the reforms and the speed at which they have been implemented have prompted many organisations to review their processes, contracts and technical solutions. There is no pause in sight. The Commission and national authorities have also demonstrated their willingness to intervene where shortcomings are identified. Enforcement can therefore be expected gradually to extend beyond the largest operators.


For organisations, this means above all that they must remain alert. New regulation is not merely an administrative obligation. It is often also a strategic question. How can services be designed to be user-oriented and competitive while also complying with regulatory requirements? Although the amount of regulation may feel burdensome, it also offers opportunities for differentiation. Operators that address the new requirements and opportunities at an early stage may be able to turn their regulatory obligations into a competitive advantage.


As regulation becomes more stringent, clear direction and practical interpretation are more important than ever. We support our clients with both.

Legal Folksin Counsel Katri Aarnio. Hymyilevä nainen valkoisessa paidassa seisoo betoniseinän edessä. Hän näyttää iloiselta ja rauhalliselta. Taustalla rosoinen pinta.


Katri Aarnio

Counsel

050 306 2031







To receive our articles directly by email, subscribe to the Folks newsletter here.

bottom of page