Skip to main content
Let's discuss Tech - Join our Community
Let's discuss Tech - Join our Community
Data Residency Rules Now Reach Two-Person SaaS Teams
Where data lives, and which jurisdiction can reach it, are now separate questions for builders of every size.
Technology

Data Residency Rules Now Reach Two-Person SaaS Teams

The EU's cloud switching regime carries no small-provider carve-out, and the last permitted exit fees disappear in January 2027

Will Lisil|Director & Digital Creator
6 min read

In Brief

The EU Data Act's cloud switching rules (Chapter VI) apply to any provider serving EU customers, with no exemption for small or emerging providers. Customers can switch on two months' notice with a 30-day transition, and all switching charges are banned from 12 January 2027.

For most of the past decade, data residency rules were something other people worried about. Banks worried. Hospitals worried. Defence contractors worried. A two-person team shipping a scheduling tool from a laptop picked a region in a dropdown and moved on.

That is no longer where the line sits. The European Union's cloud switching regime applies to any provider offering a data processing service to customers in the EU, and it draws no distinction based on the size of the provider. A solo founder with EU users is inside the same chapter of the same regulation as a hyperscaler.

Truth in Technology, Delivered by MW3.BIZ

Join thousands who trust us for unbiased insights on AI, blockchain, and the future of tech

By subscribing, you agree to our Terms and Privacy Policy.

Residency Answers Geography, Not Jurisdiction

The first thing worth separating is what residency actually buys. Choosing an EU region means the bytes sit on disks in a specific country. It does not settle who can compel access to them.

An analysis published by the Cloud Native Computing Foundation frames the fuller requirement as four properties: jurisdictional containment, so every component runs under a defendable legal jurisdiction; operational autonomy, so the platform can be rebuilt or migrated without depending on one vendor; cryptographic and access control, so keys and credentials are not reachable from outside the chosen jurisdiction; and portability, so a workload can move without a rewrite.

The practical consequence for a small team is that the region dropdown is the easy part. Control-plane location, metadata storage, administrative access, encryption and key ownership all have to be decided explicitly, because each one can quietly relocate the effective jurisdiction of a system whose data is nominally local.

The Switching Rules Carry No Small-Provider Exemption

The EU Data Act, Regulation (EU) 2023/2854, entered into force on 11 January 2024 and became generally applicable on 12 September 2025. Its cloud switching provisions sit in Chapter VI.

Analysis by Latham & Watkins is direct on the point that matters most to small builders: there are no exemptions for small-scale or emerging providers in the service-switching provisions. The narrow exceptions that do exist are for heavily customised services built for a specific customer and for services provided for testing. Size is not a qualifying factor.

That is worth setting against a different part of the same regulation, because the two are often confused. Chapter II, which governs access to data generated by connected products, does exempt micro and small enterprises under conditions. Chapter VI, the switching regime, does not. A small SaaS provider can therefore be out of scope for one chapter and fully inside another.

Scope is defined by activity rather than sector. Infrastructure, platform and software services all qualify, along with newer shapes such as database-as-a-service. Guidance from Greenberg Traurig notes that on-premise and private cloud deployments fall outside, as do services needing highly individualised, labour-intensive setup. The regime also reaches providers established outside the EU when the service is offered to EU customers.

What a Compliant Exit Looks Like in Practice

The obligations are concrete, and most of them are product work rather than legal work.

A customer can trigger a switch on a notice period of no more than two months. Once that notice ends, the transition must complete within 30 days, extendable where the move is genuinely complex. Providers have to remove contractual, technical and commercial barriers to leaving, specify exactly which data and digital assets are portable, and offer reasonable assistance to the customer and to the receiving provider.

Two requirements tend to surprise smaller teams. The first is transparency before the sale: switching procedures must be published online or supplied before contracting. The second is an obligation to maintain an online, up-to-date register of data structures, formats and interoperability specifications. Infrastructure providers additionally owe functional equivalence on migration, while others must expose free, open interfaces.

From 12 January 2027, Article 30 requires full portability in machine-readable formats such as JSON and CSV. For teams that already run a clean export endpoint, much of this is documentation. For teams whose export is a support ticket and a hand-written query, it is a roadmap item.

The Fee Cliff Arrives in January 2027

Exit pricing is on a timetable. Since 11 January 2024, switching charges have been limited to a pass-through basis with no markup. Reduced charges may not exceed the costs directly linked to the switch itself. From 12 January 2027, switching charges are prohibited entirely.

Early termination fees and fixed contract terms remain permissible, which is the detail that keeps annual pricing viable. But the Commission's reading of the termination provision, as Greenberg Traurig describes it, points toward a de facto right to terminate for convenience even on fixed-term agreements. Standard contractual clauses drafted under Article 41 are still in progress and are described as customer-friendly by design.

There is also an unresolved question about whether the rules bite only on contracts signed after September 2025 or on existing agreements too. Teams writing multi-year deals now are effectively pricing that ambiguity.

Penalties Scale With Global Turnover

Enforcement is set at member-state level, and the ceilings are proportionate to revenue rather than to company size. France provides for penalties of up to 3% of annual global turnover, rising to 5% for repeat breaches. Germany allows up to 4% of annual global turnover or five million euros, whichever is higher.

Those are maximums, applied through a framework that also allows warnings, reprimands and compliance orders, and that requires sanctions to be effective, proportionate and dissuasive. The realistic risk for a small provider is not a headline fine. It is an enterprise customer's procurement review asking for the switching register and the exit clause, and the deal stalling because neither exists.

What Small Teams Can Do Now

The work divides cleanly. Map each service you run against the definition of a data processing service, since the assessment is service by service rather than company-wide. Rewrite customer agreements to carry the notice period, the transition window and a described exit path. Build and document a real export, in open formats, that a competitor could actually consume. Publish the switching information where a buyer can find it before signing. Then review pricing, particularly any fixed-term discount that assumed a customer could not leave cheaply.

Some of this is already familiar to anyone who has weighed running their own infrastructure against renting it, a calculation covered in our look at record SaaS inflation pushing builders to move. Portability requirements pull in the same direction: they reward architectures that were never locked to one vendor in the first place.

Sovereignty Is Becoming a Product Decision

The wider direction of travel is visible beyond the Data Act. The UK's Data Use and Access Act 2025 is rolling out through 2026 with its own portability rules. NIS-2 and DORA already shape platform choices in regulated sectors. What the industry now calls geopatriation, described by Mindcore as returning data to a specific jurisdiction and keeping it there, has moved from a defence-sector concern to a line item in ordinary procurement.

From a technology-democratisation perspective, this is a genuinely mixed picture and worth stating plainly. Compliance work is a fixed cost, and fixed costs always land hardest on the smallest teams, which is a real argument for proportionate treatment. At the same time, mandatory portability and free exit are precisely the conditions under which a two-person product can win a customer from an incumbent. Our view is that rules which make switching cheap tend to widen access rather than narrow it, and that the fairest version of this regime is one where the obligations scale with capacity while the portability rights do not.

Either way, the assumption that data residency rules are somebody else's problem has expired. For anyone building for EU users, where the data lives, who can reach it, and how quickly a customer could take it elsewhere are now product decisions with dates attached.

This article was AI-assisted and edited for accuracy.

Tags:#data residency#EU Data Act#cloud computing#SaaS#data sovereignty#regulation
Keywords:data residency rulesEU Data Actcloud switchingdata sovereigntyindie SaaS compliance

Key Takeaways

  • The EU Data Act's switching regime has no small-provider exemption; only heavily customised and testing services are excepted.
  • Data residency fixes geography only. Jurisdiction depends on control-plane location, administrative access and key ownership.
  • Customers can trigger a switch on a maximum two-month notice, with completion due within 30 days of that notice ending.
  • All switching charges are prohibited from 12 January 2027, and Article 30 requires portability in formats such as JSON and CSV.
  • Penalties are national: up to 3% of global turnover in France and up to 4% or five million euros in Germany.

Frequently Asked Questions

Yes. The switching provisions in Chapter VI contain no exemption based on provider size. The only exceptions cover heavily customised services built for a specific customer and services supplied for testing.

Yes, where the service is offered to customers in the EU. The regime applies regardless of where the provider is established, so a US or UK company serving EU users is in scope.

A customer can give notice of up to two months to initiate a switch, and the transition must complete within 30 days after that notice period ends, with an extension available where the migration is genuinely complex.

Only until 12 January 2027, and only on a pass-through basis that does not exceed the costs directly linked to the switch. After that date switching charges are banned outright, though proportionate early termination fees remain permissible.

No. Residency settles where data is stored, not which jurisdiction can compel access. Control-plane location, metadata, administrative access and encryption key ownership all have to be defined separately.

Sources

  1. Latham & Watkins: EU Data Act Significant New Switching Requirements(accessed 2026-08-10)
  2. Atalaya GRC: Data Act dates, obligations and cloud switching(accessed 2026-08-10)
  3. Greenberg Traurig: Cloud Switching Under the EU Data Act(accessed 2026-08-10)
  4. CNCF: From data residency to digital sovereignty(accessed 2026-08-10)
  5. Mindcore: Geopatriation and Sovereign Cloud(accessed 2026-08-10)