The real cost of a hosting provider usually isn't the monthly invoice. It's what happens when you want to leave: the egress fees on your own data, the proprietary formats that don't import cleanly anywhere else, the notice periods, and the engineering weeks nobody budgeted for.
None of that was illegal, and none of it was accidental either. Switching friction is a rational business strategy when customers who can't easily leave tend not to, which is precisely why removing it took legislation rather than competitive pressure.
The EU Data Act is the first serious legislative attempt to remove that friction, and it's worth understanding before your next provider decision rather than after you're already locked in.
What is the EU Data Act?
The EU Data Act is a broad regulation covering how data can be accessed and shared across the European economy. Much of it deals with data generated by connected devices, who can access readings from a smart machine, an industrial sensor, or a connected vehicle, and under what terms.
The part that matters for hosting and infrastructure decisions is its chapter on switching between data processing services, which is the regulation's term for cloud, platform, and infrastructure providers. That chapter creates obligations on providers designed to make leaving genuinely practical.
The timeline runs in stages, which matters because it's the source of most of the confusion about what applies today. The regulation entered into force on 11 January 2024 and has applied since 12 September 2025, but its financial provisions phase in further, with switching charges only fully prohibited from 12 January 2027. So "the Data Act applies now" and "every exit fee is already gone" are both true-sounding statements that mean different things.
The problem it's trying to solve: vendor lock-in
Lock-in rarely shows up as one big obstacle. It accumulates from several smaller ones, each individually defensible.
Egress fees are the most visible: providers who charge little to ingest data and meaningfully more to move it out create a growing exit cost that scales with how much you've stored. Proprietary formats are the subtler version, where data technically exports but arrives in a shape that only that provider's tooling reads well, so the migration work is real even when the export is free.
Then there are the contractual and operational layers: long notice periods, minimum commitment terms, and the simple fact that rebuilding an environment elsewhere takes engineering time that always competes with shipping features. Put together, these are usually enough to keep a business on a provider it would otherwise have left, which is exactly the outcome the regulation targets.
What the Data Act actually requires from providers
The core requirement is that providers remove unjustified contractual, technical, commercial, and organizational barriers to switching. That's deliberately broad language, and it covers more than fees alone.
On the financial side, the regulation expressly captures data egress charges levied for the purpose of switching, which is the per-gigabyte transfer-out pricing that has done most of the work of keeping customers in place. The withdrawal happens in two steps: until 12 January 2027 a provider may only impose reduced switching charges that don't exceed the costs it actually incurs and that are directly linked to the switch, and from that date it may not impose any switching charge at all.
What remains chargeable is ordinary consumption. You still pay for the compute and storage you actually use, and genuinely separate costs survive too, so an early termination fee agreed in a fixed-term contract isn't automatically void. The thing being removed is the practice of pricing exit as a deterrent, and it's worth watching for charges reclassified into still-permitted categories like premium migration support.
On the process side, once a customer initiates a switch, the provider has to complete the transition within a mandatory maximum period of 30 days rather than letting it drift. Providers also have to support what the regulation calls functional equivalence when switching between comparable infrastructure services, meaning they must help you get data, configurations, and digital assets into a state that works at the destination, whether that destination is another provider or your own hardware.
There's a transparency layer too, and the European Commission's own guidance is worth reading alongside the text. Providers have to publish their switching terms clearly, including the process, the expected timelines, and any remaining charges, rather than leaving customers to discover the details in a support article at the worst possible moment.
What this means in practice for a business choosing a VPS or hosting provider
The immediate effect is negotiating leverage. Exportability and a workable exit path are now regulatory expectations rather than concessions you have to request, which changes the tone of a pre-sales conversation about migration terms.
The limit is equally important to understand. The regulation addresses contractual and financial barriers and sets process obligations; it doesn't perform your migration for you. Moving a production environment still involves rebuilding configuration, re-testing, cutting over DNS, and validating that everything works, and none of that becomes free because the egress charge did.
It also doesn't flatten the differences between providers. A provider whose platform is built on standard components and documented exports will always be easier to leave than one built around proprietary managed services, regardless of what either one charges for egress. Compliance sets a floor, not a guarantee of equivalence.
Questions worth asking a provider given these new rights
Ask what the contract actually says about fees for exporting your own data, and get the answer in writing rather than as a verbal reassurance. Post-Data Act, a provider that's still vague here is telling you something.
Ask what format your data and configuration export in. Standard database dumps, plain configuration files, and disk images are portable. Proprietary snapshot formats and platform-specific service definitions are not, even when they're free to download.
Ask for the documented switching process and its timeline, including who does what and what the provider's side of the work looks like. And ask how much notice your contract requires, since notice periods sit alongside the switching rules rather than being replaced by them.
Wrapping up
The Data Act's switching provisions genuinely shift the balance for anyone evaluating cloud or hosting services, because the ability to leave is now a legal expectation instead of a favor.
What hasn't changed is that specifics still matter. Read the contract terms, check what format your data comes out in, and confirm the documented process rather than assuming compliance makes every exit smooth. Providers with simple architectures, transparent pricing, and short commitment terms were already easier to leave before the regulation existed, and they still are.
Thanks for reading! QDE runs its unmanaged KVM VPS hosting on monthly billing with no long-term contracts and transparent flat pricing, an approach that was already aligned with avoiding lock-in before the Data Act made switching rights a legal requirement.
Curious whether it's the right fit for your project? Contact our team with any questions.
Frequently asked questions about the EU Data Act
When did the EU Data Act's switching rules take effect?
The regulation entered into force in January 2024, with most obligations, including the switching provisions, applying from September 2025. Some financial elements phase in further after that date, so it's worth checking the current state rather than assuming the full set applied from day one.
Does the Data Act apply to a hosting provider based outside the EU?
Yes, if the provider offers data processing services to customers in the EU. The logic mirrors GDPR's territorial scope: what matters is who you serve rather than where you're incorporated.
Does the Data Act mean cloud switching is now completely free?
Not universally. Charges for the act of switching, including egress fees, are being removed on the regulation's timeline, but separately agreed costs like an early termination fee in a fixed-term contract can still apply. The technical work of migrating also remains yours or your new provider's to do.
Is the EU Data Act the same as GDPR?
No. GDPR governs personal data protection specifically. The Data Act is broader, covering access and portability for both personal and non-personal data, including machine-generated data and cloud switching rights. A business can be subject to both, and they're assessed separately.
Does switching providers under the Data Act guarantee no downtime?
No. The regulation removes barriers and sets timelines for the provider's side of a transition, but cutover planning, testing, and DNS changes are still ordinary migration work with ordinary risks.
Do small businesses get any exceptions under the Data Act?
The regulation includes accommodations for micro and small enterprises in some of its data-sharing obligations, since those provisions were largely written with larger data holders in mind. The switching obligations, though, fall on providers rather than customers, which means a small business is generally the beneficiary of those rules rather than a party with obligations under them.
