The new EU Data Act has been of increasing concern for our clients that are active in the SaaS and connected products industries since it entered into force in mid-September. Notably, the EU Data Act is applicable in parallel to the GDPR, and also applies to non-personal data (so-called ‘machine’ or ‘product’ data).
This new EU regulation brings two major implications for the industry:
- Ban on long-term contracts: Typical contract terms of 12 to 24 months will be prohibited in the future as soon as the contracted service falls under the Data Act. Instead, all customers have a 60-day right of termination for convenience – even for B2B contracts.
- Mandatory migration support: Businesses that fall under the Data Act must actively support a migration to another provider requested by the customer – in other words, they must help their competitors onboard new customers free of charge. When migrating customer product data, additional GDPR compliance requirements may apply where personal data is involved.
Businesses that do not implement these requirements in their contracts may be subject to legal action from competitors and risk extremely heavy fines, comparable to the well-known sanctions under EU data protection law.
In this context, a number of our SaaS clients are currently adapting their contracts and, in some cases, also their business and sales models. Before doing so, however, it is of course necessary to check whether the Data Act applies to any of the products offered: Not all SaaS models fall under the law, even if there are some contradictory statements circulating on this subject.
SMEs are not generally exempt from the provisions of the Data Act, but they are exempt from certain obligations. For example, IoT businesses with less than €10 million in revenue are not required to provide migration support.
In addition to posing new risks, the Data Act also offers opportunities for SaaS providers themselves. For example, it has now become much easier to move one’s own cloud infrastructure to another provider.
Our legal team is happy to support you with any questions you may have, or kick off your EU Data Act implementation project, and to align it with your existing GDPR compliance measures.
To provide you with an initial overview of the new law and to give you an opportunity to address your questions, we will be offering a free EU Data Act webinar on December 4th, 2025 at 2.00 pm. Registration
(Dr Lukas Mezger, UNVERZAGT Rechtsanwälte)