TechLaw
11/9/26

Does the EU Data Act apply to a SaaS company with no presence in Europe?

The EU Data Act applies to any SaaS provider with customers in the Union, wherever it is based. Legal representative, governing law and the 12 January 2027 deadline.

Tiempo Estimado de lectura:

8 min read

Guillermo Passas Varo

The first reaction of most software companies outside Europe, when the EU Data Act comes up, is the one that once greeted the GDPR: we are not in the EU, so it does not apply to us. With the GDPR that assumption lasted until the first complaint. With Regulation (EU) 2023/2854, the Data Act, the test is the one Article 27 of the GDPR already taught the market. What counts is where the customers are (Article 1(3)(f)), and software as a service is a data processing service (Recital 81).

The companies with the most to lose understood that quickly. Google Cloud, Amazon Web Services and Microsoft, none of them established in the EU, dropped their data transfer fees for departing customers within months of the Regulation entering into force. In September 2025, Salesforce added a Data Act addendum to its online terms and extended the switching rights to every customer in the EU and the EEA, including those already under contract. A US, UK, Swiss or Israeli SaaS company with fifty European customers on annual plans is inside the same scope as those four, on the same terms and with the same 12 January 2027 deadline, after which any charge for a customer's exit is prohibited (Article 29(1)).

The Data Act does not ask where a SaaS company is incorporated. It asks where its customers sit, and it gives those customers a right to leave that no governing-law clause takes away.

What can a European customer actually do against a provider outside the EU?

The practical question comes before the legal one. A provider in Denver with a customer in Lyon may assume that a European regulation is someone else's problem until the customer decides to leave. From that moment the Regulation works through three channels, and none of them requires the customer to travel:

  • Refusal. The customer has the right to switch on two months' notice at most (Article 25(2)(d)), to a transition of up to thirty days with assistance (Article 25(2)(a)) and to all its exportable data in a machine-readable format (Articles 25(2)(e) and 30(5)). Until 12 January 2027 the provider may charge only its direct migration costs; after that, nothing (Article 29). A customer that knows this declines to pay the export fee or the instalments claimed after its exit. The provider is then the one who has to sue: a European company, in a European court, on a contract that breaches a European regulation.
  • The regulator. Each Member State designates an authority and lays down penalties (Articles 37 and 40). A provider offering services in the Union without being established there must appoint a legal representative in one Member State (Article 37(11)), whose authority takes competence. Until it does, every Member State is competent and any of their authorities may act on a complaint (Article 37(13)). Germany's authority, the Bundesnetzagentur, has been in place since 30 May 2026.
  • Procurement. European buyers have learnt, through the GDPR, NIS2 and DORA, to read their suppliers' contracts against EU law before signing. A SaaS agreement that still carries a 90-day notice window and a data export fee tells them the vendor has not looked at the Regulation.

Does a US or English governing-law clause help?

Less than most providers assume. The obligations in Chapter VI are not written as rights the customer may invoke; they are written as terms the provider must include in the contract (Article 25(1) and (2)) and as conduct the provider must not engage in (Article 23). A clause choosing Delaware or English law does not change what the provider was obliged to write into the agreement. Where a dispute reaches a court in the Union, the court will be asked to treat these rules as overriding mandatory provisions and apply them regardless of the chosen law, and the wording of the Regulation makes that an easy request to grant. A judgment obtained in that court will then be enforced under the ordinary rules for foreign judgments.

A governing-law clause protects the provider on everything the Regulation does not touch, which is most of the contract, and on nothing it does. Notice, transition, data format, assistance and switching charges follow the Regulation whatever the contract says.

Two ways to restructure the contracts, and what each costs

Providers that have already moved have taken one of two routes, and both are visible in public terms. An EU-specific addendum is the first. Salesforce kept its global master subscription agreement and attached a Data Act addendum that applies to customers in the EU and the EEA. The advantage is containment: the rest of the customer base keeps the existing terms, including minimum terms and export fees where local law allows them. The cost is a two-track contract that sales and support have to operate correctly, and the risk of a European customer being sold on the global terms by mistake.

A global change is the second. Google Cloud's removal of transfer fees for customers leaving its platform applied worldwide from January 2024, while its later removal of fees for moving data between clouds applied in Europe only, and Microsoft's at-cost pricing for transfers to other providers was introduced for EU customers in September 2025. A global change is simpler to administer and easier to explain to investors, and it removes the temptation to route a European customer through the wrong terms. Its cost is commercial: the provider gives up lock-in in markets where nothing obliges it to.

For a mid-sized provider, the choice usually turns on how much of the revenue is European and how the contracts are signed. Where European customers sign a standard order form against online terms, the addendum route means writing one document and making sure it attaches automatically to any customer with an EU billing address. Where enterprise customers negotiate individual agreements, each European contract needs its own review, and the Regulation's specific regime for services built to order for a single customer (Article 31(1)) may apply to some of them.

Whichever route is chosen, the same clauses go:

  • Minimum term enforced by charging every remaining instalment → fixed term with a proportionate early termination penalty (Recital 89), which the Regulation leaves outside the definition of switching charges (Article 2(36)).
  • 90-day notice window → two months at most (Article 25(2)(d)).
  • Data export fee → cost-justified until 12 January 2027, deleted after (Article 29).
  • Full export only on the enterprise tier → open interfaces available to all customers equally (Articles 23(c) and 30(2)).
  • Pricing in the small print → given before signature, early termination penalty included, and published on the website (Article 29(4) and (6)).

For a provider whose European contracts are still being built, this is part of the compliance framework we deliver in EU Data Compliance.

The obligation that only foreign providers have to think about

Two provisions of the Regulation are aimed squarely at providers whose infrastructure or home jurisdiction sits outside the Union. Article 28(1) requires every provider of data processing services to publish on its website the jurisdiction to which the ICT infrastructure used for each service is subject, together with a general description of the technical, organisational and contractual measures it has adopted to prevent international governmental access to, or transfer of, non-personal data held in the Union where that access would conflict with EU or Member State law. The contract must list that web page (Article 28(2)). Article 32(1) then requires the provider to take all adequate measures to prevent such access.

For a European provider these are formalities. For a US provider they are a question the company has to answer in writing: what happens when a request for data held in the Union arrives from its own authorities under its own law, and what the company has done in advance to keep that request from conflicting with European law. The hyperscalers have answered it with published data residency commitments and formal transparency pages. A smaller provider needs at least a short, accurate statement it can stand behind, because a customer's due diligence questionnaire will ask for the link.

What a provider risks by waiting

The exposure is economic before it is regulatory, and it arrives by four routes:

  • Unenforceable charges. A European customer that leaves without paying an export fee leaves the provider with a claim it will struggle to enforce and, if it litigates, a judgment against it with costs.
  • Damages. A migration obstructed by an unusable backup format or an absent support team gives the customer a claim for the licences, consultants and delay it had to absorb.
  • Valuation. In a funding round or an acquisition, counsel will read the European contracts, find the clauses, ask for the representative, and convert each finding into a warranty, an indemnity or a price adjustment.
  • Supervision. In any Member State that has designated its authority, a complaint is now a live possibility, and a provider that never appoints a representative is exposed to twenty-seven authorities rather than one.

Could the rules still change?

A proposal is on the table. On 19 November 2025 the Commission tabled the Digital Omnibus proposal, which would expressly recognise proportionate early termination penalties and lighten the switching obligations for custom-built services and for SMEs and small mid-caps that do not provide infrastructure services, though only for contracts concluded on or before 12 September 2025. As of late July 2026 it was still under negotiation in the Council. Until it is adopted, the text in force governs, and the 12 January 2027 date stands.

Frequently asked questions

We have no entity, staff or servers in the EU. Does the Data Act apply?

Yes, if the company provides data processing services to customers in the Union (Article 1(3)(f)). Establishment is irrelevant. Salesforce, AWS, Google Cloud and Microsoft are all established outside the EU and have all adapted their terms.

Do we need to appoint a legal representative, and where?

Yes, in one Member State of the company's choice (Article 37(11)). That Member State's authority then takes competence. Without a representative the company is under the competence of every Member State (Article 37(13)).

Our EU customers signed our standard US terms years ago. Are those contracts affected?

Yes. Article 50 provides transitional periods for other parts of the Regulation, but none for Chapter VI, so the switching rules apply to existing contracts. Salesforce's addendum applies to customers already under contract for the same reason.

Can we keep a minimum term with our European customers?

Yes. Fixed-term contracts with a proportionate early termination penalty are permitted (Recital 89). What is not permitted is preventing the customer from leaving on two months' notice, or charging for the exit itself.

We only have customers in one Member State. Does that change anything?

Not the obligations. It may simplify the choice of Member State for the legal representative, and it makes the authority of that Member State the practical one to watch.

Our enterprise deals are heavily customised. Are they exempt?

Partly. Where most of the main features were built for a single customer and the service is not offered at commercial scale in the catalogue, the abolition of switching charges does not apply (Article 31(1)). The notice period, the transition and the information duties still do, and the customer must be told before signing which obligations are excluded (Article 31(3)).

If this sounds like your situation, you can book a Virtual Consultation here (€90, deducted from the first invoice if we take on the engagement).

did you find this article interesting?

Maybe You Are Interested in Our Tailored Related Services with Open Fees

Non-EU companies

EU Data Compliance

GDPR for non-European companies processing the personal data of EU users.

DESDE
€3,500 + VAT
Investors and startups

Tech Due Diligence

Legal due diligence on technology companies ahead of a funding round or M&A.

DESDE
€5,000 + VAT

Book your Virtual Consultation with a lawyer. Today.

60 minutes on Google Meet with a qualified lawyer specialising in TechLaw, litigation or international law. €90 including VAT, deducted from the first invoice if we take on your matter. You leave with legal judgement and a fixed price for whatever comes next.

Choose your lawyer and a time in the calendar. No forms first, no sales calls.