DataAct Ready

EU Data Act guides ·

Does the EU Data Act Apply to SaaS Companies?

Most SaaS founders assume the EU Data Act is an IoT law. In many cases it reaches SaaS too, through cloud switching rules, unfair contract terms and related services.

Short answer: quite possibly yes, and not through the part of the law most people read first.

The EU Data Act (Regulation 2023/2854) is usually described as an Internet-of-Things law about smart devices and their data. That description is accurate but incomplete. The regulation has three big pillars, and two of them reach ordinary software companies with no hardware anywhere in sight.

Pillar 1: connected products and related services

Chapter II covers connected products (physical devices that generate usage data) and related services, digital services that are needed for a device to perform one of its functions. If your SaaS is the companion app or backend for somebody's hardware, even hardware you do not manufacture, you can be a related-service provider with direct data-sharing obligations to users.

Pillar 2: cloud switching (this is the one that catches SaaS)

Chapter VI applies to providers of data processing services, a term that is broadly understood to cover IaaS, PaaS and SaaS offered to customers in the EU. If that is you, the regulation requires, among other things:

  • contractual switching terms: a customer must be able to leave with a maximum notice period of two months and a transition period of 30 days,
  • export of the customer's data and digital assets in a machine-readable format,
  • switching charges limited to your own costs, and from 12 January 2027, switching and egress charges are expected to be withdrawn altogether,
  • information obligations: your contract and documentation must describe how switching works.

None of this depends on you selling hardware. A pure B2B SaaS with EU customers is squarely in the conversation.

Pillar 3: unfair contract terms

Article 13 makes certain unilaterally imposed contract terms about data unenforceable against smaller counterparties. If your standard MSA was written before the Data Act existed, some of its data clauses may simply be void in the EU, see our separate guide on Article 13.

The location test: it follows the customer

Like the GDPR, the Data Act does not care where the vendor is incorporated. It cares where the product is placed on the market and where the customers are. A US or UK SaaS with paying users in the EU should assume the cloud-switching and contract-terms rules are on the table.

What to do this week

  1. Work out which pillars apply to you: connected product, related service, data processing service, or several at once.
  2. Read your own contract for notice periods, exit terms and data-export language.
  3. Check whether you can actually export a customer's data in a structured format today.

The fastest way to do step one is our free readiness assessment, it asks a handful of scoping questions and tells you which obligations are likely to apply and where your gaps are.

Where does your product stand on the Data Act?

Free 3-minute readiness assessment, scoped to your product, with a scored gap report. No signup required to see your score.

Start free assessment

This article is general information about EU Regulation 2023/2854, not legal advice. Consult qualified counsel for your specific situation.