The EU Data Act applies to any SaaS provider with customers in the Union, wherever it is based. Legal representative, governing law and the 12 January 2027 deadline.
8 min read
The first reaction of most software companies outside Europe, when the EU Data Act comes up, is the one that once greeted the GDPR: we are not in the EU, so it does not apply to us. With the GDPR that assumption lasted until the first complaint. With Regulation (EU) 2023/2854, the Data Act, the test is the one Article 27 of the GDPR already taught the market. What counts is where the customers are (Article 1(3)(f)), and software as a service is a data processing service (Recital 81).
The companies with the most to lose understood that quickly. Google Cloud, Amazon Web Services and Microsoft, none of them established in the EU, dropped their data transfer fees for departing customers within months of the Regulation entering into force. In September 2025, Salesforce added a Data Act addendum to its online terms and extended the switching rights to every customer in the EU and the EEA, including those already under contract. A US, UK, Swiss or Israeli SaaS company with fifty European customers on annual plans is inside the same scope as those four, on the same terms and with the same 12 January 2027 deadline, after which any charge for a customer's exit is prohibited (Article 29(1)).
The Data Act does not ask where a SaaS company is incorporated. It asks where its customers sit, and it gives those customers a right to leave that no governing-law clause takes away.
The practical question comes before the legal one. A provider in Denver with a customer in Lyon may assume that a European regulation is someone else's problem until the customer decides to leave. From that moment the Regulation works through three channels, and none of them requires the customer to travel:
Less than most providers assume. The obligations in Chapter VI are not written as rights the customer may invoke; they are written as terms the provider must include in the contract (Article 25(1) and (2)) and as conduct the provider must not engage in (Article 23). A clause choosing Delaware or English law does not change what the provider was obliged to write into the agreement. Where a dispute reaches a court in the Union, the court will be asked to treat these rules as overriding mandatory provisions and apply them regardless of the chosen law, and the wording of the Regulation makes that an easy request to grant. A judgment obtained in that court will then be enforced under the ordinary rules for foreign judgments.
A governing-law clause protects the provider on everything the Regulation does not touch, which is most of the contract, and on nothing it does. Notice, transition, data format, assistance and switching charges follow the Regulation whatever the contract says.
Providers that have already moved have taken one of two routes, and both are visible in public terms. An EU-specific addendum is the first. Salesforce kept its global master subscription agreement and attached a Data Act addendum that applies to customers in the EU and the EEA. The advantage is containment: the rest of the customer base keeps the existing terms, including minimum terms and export fees where local law allows them. The cost is a two-track contract that sales and support have to operate correctly, and the risk of a European customer being sold on the global terms by mistake.
A global change is the second. Google Cloud's removal of transfer fees for customers leaving its platform applied worldwide from January 2024, while its later removal of fees for moving data between clouds applied in Europe only, and Microsoft's at-cost pricing for transfers to other providers was introduced for EU customers in September 2025. A global change is simpler to administer and easier to explain to investors, and it removes the temptation to route a European customer through the wrong terms. Its cost is commercial: the provider gives up lock-in in markets where nothing obliges it to.
For a mid-sized provider, the choice usually turns on how much of the revenue is European and how the contracts are signed. Where European customers sign a standard order form against online terms, the addendum route means writing one document and making sure it attaches automatically to any customer with an EU billing address. Where enterprise customers negotiate individual agreements, each European contract needs its own review, and the Regulation's specific regime for services built to order for a single customer (Article 31(1)) may apply to some of them.
Whichever route is chosen, the same clauses go:
For a provider whose European contracts are still being built, this is part of the compliance framework we deliver in EU Data Compliance.
Two provisions of the Regulation are aimed squarely at providers whose infrastructure or home jurisdiction sits outside the Union. Article 28(1) requires every provider of data processing services to publish on its website the jurisdiction to which the ICT infrastructure used for each service is subject, together with a general description of the technical, organisational and contractual measures it has adopted to prevent international governmental access to, or transfer of, non-personal data held in the Union where that access would conflict with EU or Member State law. The contract must list that web page (Article 28(2)). Article 32(1) then requires the provider to take all adequate measures to prevent such access.
For a European provider these are formalities. For a US provider they are a question the company has to answer in writing: what happens when a request for data held in the Union arrives from its own authorities under its own law, and what the company has done in advance to keep that request from conflicting with European law. The hyperscalers have answered it with published data residency commitments and formal transparency pages. A smaller provider needs at least a short, accurate statement it can stand behind, because a customer's due diligence questionnaire will ask for the link.
The exposure is economic before it is regulatory, and it arrives by four routes:
A proposal is on the table. On 19 November 2025 the Commission tabled the Digital Omnibus proposal, which would expressly recognise proportionate early termination penalties and lighten the switching obligations for custom-built services and for SMEs and small mid-caps that do not provide infrastructure services, though only for contracts concluded on or before 12 September 2025. As of late July 2026 it was still under negotiation in the Council. Until it is adopted, the text in force governs, and the 12 January 2027 date stands.
Yes, if the company provides data processing services to customers in the Union (Article 1(3)(f)). Establishment is irrelevant. Salesforce, AWS, Google Cloud and Microsoft are all established outside the EU and have all adapted their terms.
Yes, in one Member State of the company's choice (Article 37(11)). That Member State's authority then takes competence. Without a representative the company is under the competence of every Member State (Article 37(13)).
Yes. Article 50 provides transitional periods for other parts of the Regulation, but none for Chapter VI, so the switching rules apply to existing contracts. Salesforce's addendum applies to customers already under contract for the same reason.
Yes. Fixed-term contracts with a proportionate early termination penalty are permitted (Recital 89). What is not permitted is preventing the customer from leaving on two months' notice, or charging for the exit itself.
Not the obligations. It may simplify the choice of Member State for the legal representative, and it makes the authority of that Member State the practical one to watch.
Partly. Where most of the main features were built for a single customer and the service is not offered at commercial scale in the catalogue, the abolition of switching charges does not apply (Article 31(1)). The notice period, the transition and the information duties still do, and the customer must be told before signing which obligations are excluded (Article 31(3)).
If this sounds like your situation, you can book a Virtual Consultation here (€90, deducted from the first invoice if we take on the engagement).
GDPR for non-European companies processing the personal data of EU users.
Legal due diligence on technology companies ahead of a funding round or M&A.
60 minutes on Google Meet with a qualified lawyer specialising in TechLaw, litigation or international law. €90 including VAT, deducted from the first invoice if we take on your matter. You leave with legal judgement and a fixed price for whatever comes next.