FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
470of470items
Across 39 modules • Updated Jul 25, 2026
Author
Sorena AI
Published
May 6, 2026
Updated
Jul 25, 2026
EU Data Act Application Dates and Transition

How do the Chapter IV unfair-contract-term transition rules work under the Data Act?

Chapter IV applies to contracts concluded after 12 September 2025. For contracts concluded on or before that date, Chapter IV applies from 12 September 2027 only if the contract is of indefinite duration or is due to expire at least 10 years from 11 January 2024.

Legal and procurement teams should split contract inventories into new contracts, older indefinite contracts, older long-duration contracts, and older contracts outside the Article 50 transition rule. The review file should identify the data-access, data-use, liability, remedies, breach, or termination terms being assessed under Chapter IV.

  • Flag contracts concluded after 12 September 2025 for Chapter IV review at negotiation.
  • For pre-application contracts, evidence whether the contract is indefinite or expires at least 10 years from 11 January 2024.
  • Keep redlines, fallback clauses, negotiation notes, and the reason a term is treated as in or out of Chapter IV.
Citations
EU Data Act Application Dates and Transition

What records should teams keep for Data Act application dates, cloud switching, and evidence review?

Use a date-by-date register that shows the legal trigger, exact deadline, affected population, action taken, owner, and source URL so a later reviewer can reproduce the timing decision.

Cloud and product clocks must remain separate: Article 29 states a reduced-switching-charge period from 11 January 2024 through 11 January 2027, but the Data Act generally applied only from 12 September 2025; Article 3(1) applies to products and related services placed on the market after 12 September 2026, and the switching-charge ban starts on 12 January 2027. Record standards-dependent interoperability dates only when the required Official Journal and repository publications occur.

  • Keep a single timeline with the article number, date, action owner, and source URL for each milestone.
  • Track cloud switching separately from product-design and contract-transition deadlines.
  • Add a review trigger when an implementation date depends on a Commission repository publication or a contract change.
Citations
EU Data Act Application Dates and Transition

What source evidence should teams keep for an EU Data Act application-date or transition decision?

Keep the specific legal provision that sets the date, not a general note that the Regulation applies. Record Article 50 for general, product, Chapter III, and Chapter IV timing; Article 29 for switching charges; Article 25 for customer-triggered switching periods; or the relevant implementing act and repository publication for a standards-dependent clock.

The record should also show the decision owner, affected product, contract, service, or request population, factual input such as placement or conclusion date, and the implementation artifact. Official Commission guidance can explain the rule, but it does not replace the binding Regulation.

  • Link each deadline to the exact Data Act article or recital used.
  • Store the owner, affected workflow, evidence artifact, and review trigger.
  • Keep the cited external URL, decision date, reviewer, and unresolved assumptions together.
Citations
EU Data Act Application Dates and Transition

How should teams assign ownership for Data Act application-date and transition work?

Under the Data Act, the right owner for an application-date or transition decision is the team that can actually change the affected process. That is usually legal, product, procurement, cloud operations, security, or compliance, depending on the obligation.

One person should be accountable for the deadline decision, while consulted teams can be listed separately. That keeps the record usable when a contract, release, or cloud migration needs to be updated again.

  • Assign one accountable owner per deadline decision.
  • Map the application date to the team that can change the workflow or contract.
  • Record consulted teams and evidence dependencies separately from the owner.
Citations
EU Data Act Application Dates and Transition

Which evidence makes an EU Data Act transition answer reusable and auditable later?

Under the Data Act, capture the source, the decision, and the implementation proof in one place. Without those three parts, a later reviewer cannot tell whether the deadline was based on Article 50, Article 29, Article 25, or another provision.

The most helpful evidence is a short register entry, a source URL, and the artifact that shows the team actually implemented the change.

  • Keep source URL, decision date, and implementation artifact together.
  • Capture contract clauses, release notes, notices, or control updates.
  • Store the reviewer name and the next review trigger with the record.
Citations
EU Data Act Application Dates and Transition

When should the Data Act application-dates answer be reviewed again?

Under the Data Act, review the answer again when the product, service model, contract wording, or legal source changes. A transition answer can go stale as soon as a new product is launched, a contract is renewed, or the Commission publishes interoperability references.

The safest practice is to pair a calendar review date with an event trigger, such as a release, procurement renewal, cloud migration, or new source publication.

  • Review after product, service, contract, or legal-source changes.
  • Set both a date-based review and an event-based trigger.
  • Update the record when a Commission publication changes the compliance clock.
Citations
EU Data Act Application Dates and Transition

What should teams avoid when applying the Data Act transition FAQ answer?

Teams should avoid using one deadline for every Data Act topic. The Regulation has different clocks for general application, product design, cloud switching, contract transition, and interoperability.

They should also avoid relying on internal notes alone. The answer should always point back to a legal source URL or Commission guidance so the reason for the deadline is clear.

  • Do not copy one date across unrelated obligations.
  • Do not rely on internal notes without a source URL.
  • Do not treat the general application date as overriding specific transition rules.
Citations
EU Data Act Application Dates and Transition

By when must cloud providers remove switching charges under the EU Data Act transition timeline?

Providers of data processing services must stop imposing switching charges from 12 January 2027. Through 11 January 2027, any reduced switching charge could not exceed costs directly linked to the switching process. Standard service fees and early-termination penalties are separate categories and do not become switching charges merely because a customer exits.

Data egress charges for in-parallel use of more than one provider are treated separately. Article 34(2) permits a provider to pass on only the egress costs it incurs, without exceeding those costs. The contract and invoice should identify which route applies rather than calling every egress fee a switching charge.

  • Track 12 January 2027 as the date switching charges must be removed.
  • Cap any interim switching charge at costs directly linked to the switch through 11 January 2027.
  • Classify any egress cost for in-parallel use separately and retain the Article 34(2) cost calculation.
Citations
Regulation (EU) 2023/2854 (Data Act)

Articles 29 and 34 distinguish the switching-charge prohibition, the phase-out cost cap, standard service fees, early-termination penalties, and egress charges for in-parallel use.

EU Data Act Application Dates and Transition

How should teams treat existing contracts under the EU Data Act unfair-term transition rule?

Chapter IV applies to contracts concluded after 12 September 2025. For a contract concluded on or before that date, Chapter IV applies from 12 September 2027 only if the contract is indefinite or is due to expire at least 10 years from 11 January 2024. An older fixed-term contract outside those two categories does not enter Chapter IV through this transition rule.

Record the conclusion date, duration, expiry date, whether a term was unilaterally imposed, the enterprise status of the parties, and each data-access, data-use, liability, remedy, breach, or termination clause reviewed. Flag only the legacy agreements that meet Article 50's exact test for remediation before 12 September 2027.

  • Classify each contract by conclusion date to apply the right Chapter IV transition rule.
  • Flag legacy indefinite contracts and contracts expiring on or after 11 January 2034 for review before 12 September 2027.
  • Preserve the calculation and contract evidence when an older fixed-term agreement falls outside the transition rule.
Citations
EU Data Act Article 32: Foreign Government Access

Who is covered by the Data Act rule on third-country government access?

The Article 32 safeguard is aimed at providers of data processing services, including cloud and edge service contexts covered by the Data Act's data processing services chapter. The protected data is non-personal data held in the Union and falling within the scope of the Regulation.

This is narrower than every foreign authority request a company might receive. Article 32 does not govern ordinary commercial transfers between businesses. A product manufacturer, connected-product data holder, support team, or ordinary business system owner should first ask whether the request is addressed to the provider of a data processing service and whether the requested material is non-personal data held in the Union.

  • Confirm the recipient of the request is the provider of a data processing service.
  • Confirm the requested data is non-personal data held in the Union.
  • Separate this Article 32 analysis from GDPR, criminal-law, customs, taxation, and sector-specific access regimes that may have their own rules.
Citations
EU Data Act Article 32: Foreign Government Access

What must providers do before a foreign government request ever arrives under the Data Act?

Providers must maintain technical, organisational, and legal measures, including contractual measures, to prevent third-country governmental access or transfer where it would conflict with Union law or the national law of the relevant Member State. The Commission's explainer gives examples such as encryption, audits, and adherence to certification schemes.

Article 28 also creates a transparency obligation: providers must publish and keep updated the jurisdictions to which the ICT infrastructure deployed for their individual services is subject, and must describe the technical, organisational, and contractual measures used to prevent conflicting international governmental access or transfer.

  • Publish the jurisdictions to which the ICT infrastructure deployed for each service is subject.
  • Publish a general description of preventive technical, organisational, and contractual measures.
  • Keep the public information current and list the relevant website in contracts for data processing services.
Citations
EU Data Act Article 32: Foreign Government Access

Does a third-country court order or authority decision automatically work in the EU under the Data Act?

No. A third-country court judgment, tribunal decision, or administrative authority decision requiring access to or transfer of covered non-personal data is recognised or enforceable only if it is based on an international agreement in force between the requesting third country and the Union or a Member State, such as a mutual legal assistance treaty.

Identify the exact legal instrument and the international agreement relied on. If no such agreement applies and compliance risks a conflict with EU or Member State law, access or transfer may occur only if all Article 32(3) safeguards are met. The provision does not validate the foreign order as a matter of EU law merely because those fallback conditions are satisfied.

  • Capture the decision, judgment, subpoena, warrant, or administrative order as received.
  • Identify the requesting authority and the third country.
  • Verify whether an in-force international agreement covers the request before recognising or enforcing it.
Citations
EU Data Act Article 32: Foreign Government Access

What happens if there is no international agreement and compliance may conflict with EU or Member State law under the Data Act?

Where there is no applicable international agreement and compliance risks a legal conflict, Article 32 permits access or transfer only if defined safeguards are met. The third-country system must require reasons and proportionality, the decision must be specific, the provider's reasoned objection must be reviewable by a competent third-country court or tribunal, and that court or tribunal must be empowered to take account of relevant legal interests protected by Union or Member State law.

This is the core conflict analysis. A provider should not answer only with a business approval or general law-enforcement cooperation statement; it needs a record showing how each Article 32 condition was checked for the request.

  • Check whether the third-country system requires reasons and proportionality and requires the decision to be specific, for instance through a sufficient link to suspected persons or infringements.
  • Check whether a reasoned objection by the provider can be reviewed by a competent third-country court or tribunal.
  • Check whether that court or tribunal can consider the relevant EU or Member State legal interests.
Citations
EU Data Act Article 32: Foreign Government Access

When should the provider ask a national authority for an opinion under the Data Act?

The provider may ask the relevant national body or authority competent for international cooperation in legal matters for an opinion on whether the Article 32 conditions are met. Article 32 identifies this route where the decision may relate to trade secrets, commercially sensitive data, intellectual property-protected content, or a transfer that may lead to re-identification.

The provider must ask that national body or authority for an opinion if it considers that the decision or judgment may affect national-security or defence interests of the Union or its Member States. If there is no reply within one month, or the opinion says the conditions are not met, the provider may reject the request for access to or transfer of non-personal data on those grounds.

  • Escalate for an opinion when trade secrets, commercially sensitive data, intellectual property, or re-identification risk are part of the request.
  • Request an opinion when national security or defence interests may be affected.
  • Record the date of the opinion request, any response, and whether the one-month no-reply rule became relevant.
Citations
EU Data Act Article 32: Foreign Government Access

If the request can be complied with, how much data may be provided under the Data Act?

Article 32 requires minimisation. If the conditions for access or transfer are met, the provider must provide the minimum amount of data permissible in response, based on its reasonable interpretation of the request or the interpretation of the relevant national body or authority.

The evidence file should therefore include both the requested data and the data actually disclosed. That lets a later reviewer see why excluded fields, logs, metadata, backups, or derived records were outside the minimum permissible response.

  • Translate the foreign request into a specific data inventory before disclosure.
  • Remove data categories not necessary for the permissible response.
  • Keep a disclosure log showing the request, interpretation, data supplied, data withheld, and approver.
Citations
Page 10 of 32