Which exportable data and digital assets must a cloud provider hand over on exit under the EU Data Act?
Under the Data Act, exportable data means input and output data, including metadata, generated or co-generated directly or indirectly by the customer's use of the data processing service. It excludes assets or data protected by the intellectual property rights, or constituting trade secrets, of the provider or third parties. Digital assets are separate elements in digital form that the customer has the right to use independently of the contract with the source provider. Procurement should ask the supplier to define these boundaries in the contract rather than discovering them during a migration.
The checklist should confirm the formats, included metadata, and configuration or schema material needed to make the export usable on the destination service. A raw dump that the customer cannot rebuild from is insufficient.
- Require a written list of exportable data categories, digital assets, and the formats they will be delivered in.
- Clarify which provider-internal data is excluded and why, so the exclusion is not used to gut the export.
Articles 25 and 26 support the procurement checks for assistance, continuity, security, switching procedures, formats, restrictions, and the online register.
Commission FAQ support for treating IaaS, PaaS, and SaaS as data processing services when the Article 2(8) characteristics are present.
Commission explainer describes cloud-switching barriers such as data egress charges, lengthy procedures, and lack of interoperability.
Commission material identifies non-binding SCC modules for switching and exit, termination, security and business continuity, and related fair-contract topics.