The Data Act is read as a regulation about connected products and industrial data, and most of its text is. But one chapter of it is about every company that hosts software for customers, and that chapter applied on 12 September 2025 without a transition, a size threshold or a registration. A company selling SaaS is a provider of a data processing service under Article 2(8), which covers infrastructure, platforms and applications delivered over the network from shared, scalable resources, and Chapter VI makes it remove every obstacle to a customer leaving. This article reads Chapter VI for a SaaS company, term by term, then the charges and the technical duties, and then Chapter II for a company whose product is a connected product or a related service; the 96 rows of the Regulation that bind a data holder, a user, a third party, a provider of data processing services, a manufacturer or a smart-contract vendor are a dataset in six languages, each row with its article.
Who you are under it, and why size does not help
Chapter VI names two parties: the provider of data processing services and its customer. The provider is any company offering a service that gives on-demand network access to a shared pool of computing resources, and the Regulation says the three deployment models by name in its recitals: infrastructure, platform and software. A SaaS company is a provider of a data processing service, and so is the cloud it runs on, each toward its own customers. Chapter II, the connected-product chapter, has the exemption of Article 7(1) for microenterprises and small enterprises; Chapter VI has none, only the carve-out of Article 31 for services custom-built for one customer and not offered at scale, and for non-production versions used for testing, and even there Article 31(3) obliges the provider to tell the prospective customer which duties do not apply. A company that hosts one product for many customers carries Chapter VI in full, whatever its headcount.
The nine contract terms of Article 25(2)
Article 25(1) wants the customer's switching rights and the provider's duties in a written contract, available before signature in a form the customer can store and reproduce. Article 25(2) lists what it must contain, and the list is the checklist. One: a clause allowing the customer to switch to another provider or to port everything to on-premises infrastructure within a transitional period of at most 30 calendar days, during which the provider assists, keeps the service running, names the known risks to continuity and keeps the data secure. Two: an obligation to support the customer's exit strategy with all relevant information. Three: a clause on when the contract counts as terminated, on successful switching or at the end of the notice period where the customer only wants erasure. Four: a maximum notice period to start switching of no more than two months. Five: an exhaustive specification of the categories of data and digital assets that can be ported, at a minimum all exportable data. Six: an exhaustive specification of the data specific to the provider's internal functioning that is exempt where trade secrets are at risk, without impeding the switch. Seven: a retrieval period of at least 30 calendar days after the transitional period. Eight: a guarantee of full erasure of the customer's exportable data and assets after the retrieval period, once switching has succeeded. Nine: the switching charges, within Article 29. Article 25(3) adds the customer's notice of what it will do at the end of the notice period, Article 25(4) the provider's duty to say within 14 working days that the transitional period is technically unfeasible and to offer an alternative of at most seven months, and Article 25(5) the customer's right to extend the transitional period once.
Information, charges and the date the charges end
Article 26 has the provider give the customer the switching and porting procedures, methods, formats and known limits, and a reference to an online register it hosts with the data structures, formats, standards and open specifications in which the exportable data is available; Article 30(4) has that register kept current. Article 28 puts two things on the website: the jurisdiction the infrastructure behind each service is subject to, and a general description of the technical, organisational and contractual measures against governmental access from outside the Union that would conflict with Union or member-state law, with the website named in every contract. Article 27 asks all parties, the destination provider included, to cooperate in good faith. Article 29 is the money: from 11 January 2024 to 12 January 2027 a provider may charge reduced switching charges, no more than the costs directly linked to the switch, and from 12 January 2027 none at all; before the contract the prospective customer is told the standard fees, the early termination penalties and the reduced switching charges, and where switching is highly complex or impossible without significant interference, told that too, on a dedicated section of the website.
The technical duties, by kind of service
Article 30 splits the providers in two. Infrastructure services, the scalable compute, storage and network resources on which the customer runs its own software, owe under Article 30(1) all reasonable measures so that the customer achieves functional equivalence on the destination service, with capabilities, documentation, support and tools. Every other service, SaaS included, owes under Article 30(2) open interfaces available to all customers and destination providers free of charge, with enough information to write software that talks to the service for portability and interoperability, and under Article 30(3) compatibility with the common specifications or harmonised standards for interoperability at least 12 months after their references are published in the Union's central repository; until such references exist, Article 30(5) has the provider export all exportable data in a structured, commonly used and machine-readable format on request. Article 34 applies the same rules where a customer uses two services in parallel, with egress charges limited to the egress costs. Articles 33 and 36 add essential requirements for participants that offer data in data spaces and for the vendors of smart contracts that execute data-sharing agreements, the latter with a conformity assessment and an EU declaration of conformity.
The data holder's side, and what to do with it
A company whose product is a connected product, or a related service that makes such a product do what it does, is also a data holder under Chapter II. Article 3(1) wants the product and the service designed so that their data, with the metadata needed to read it, is accessible to the user by default, easily, securely, free of charge, in a structured and machine-readable format and directly where feasible, for products and services placed on the market after 12 September 2026; Article 4(1) makes the readily available data accessible to the user on request, Article 5(1) makes it available to a third party the user names, and Article 6(2) lists eight things that third party may not do with it, from profiling to building a competing product. Chapter III adds fair, reasonable and non-discriminatory terms under Article 8 and reasonable compensation under Article 9 wherever the data must be made available under Union law. What to do with it: put the nine terms in the contract template, publish the procedures, the register and the Article 28 statement, price the switch at cost with 12 January 2027 in the roadmap, open the interfaces, and, if you build connected products, design the next version to hand its data to the user. The rows sit beside the DORA contract clauses a financial customer will already ask for, the GDPR duties that govern any personal data in the exported set, and the Cyber Resilience Act that reaches the same connected product from the security side; StandardOS holds every row of the catalogue as a position with an owner and evidence, the way it holds the other frameworks.