A cloud exit must be secured in the contract before it is signed. The contract should give a right to all data in a machine-readable format, assistance from the provider, a transition period and documented deletion. In the EU the Data Act requires at most two months' notice, a 30-day transition and at least 30 days' access to the data. In Norway the regulation does not yet apply.
Most businesses spend months choosing a cloud service and minutes reading the contract’s termination provisions. Exit only becomes a live issue when the price goes up, the provider is acquired or the service fails. At that point it is the contract that decides whether the data comes out in usable condition, at what cost and how quickly.
What does cloud exit mean?
Cloud exit is the process by which the customer terminates the contract and moves data, configurations and users to a new provider or to its own systems. A successful exit requires that the customer gets all its data out in a format that can be used elsewhere, that the service keeps working while the migration is under way, and that the provider deletes its copies afterwards.
The risk lies in what happens when the contract is silent. Without contractual terms the customer has no right to a particular format, no right to assistance and no firm deadline. The provider can then dictate the terms at exactly the moment the customer depends on them most.
What does the Data Act say about cloud exit?
The Data Act, Regulation (EU) 2023/2854, gives customers of cloud services a right to switch provider or move to their own infrastructure in Chapter VI, Articles 23 to 31. The rules have applied in the EU since 12 September 2025 (Data Act Art. 50).
The rules cover “data processing services”, which Data Act Art. 2 defines broadly as digital services providing on-demand network access to a shared pool of scalable computing resources. The definition covers infrastructure and platform services and many SaaS services. Where the line falls for some SaaS services is disputed.
The provider must remove commercial, technical, contractual and organisational obstacles to switching (Data Act Art. 23). Under Data Act Art. 25 the customer’s rights on switching must be set out in a written contract, which the customer must receive before signing. The table shows the key deadlines.
| Requirement | Deadline or content | Provision |
|---|---|---|
| Notice to initiate switching | Two months at most | Art. 25(2)(d) |
| Transition period | 30 calendar days at most, service continues as normal | Art. 25(2)(a) |
| Technically unfeasible transition | Provider must notify within 14 working days, alternative period of seven months at most | Art. 25(4) |
| Customer extension | The customer may extend the transition period once | Art. 25(5) |
| Data retrieval | At least 30 calendar days after the transition period | Art. 25(2)(g) |
| Deletion | Full erasure of exportable data after the retrieval period | Art. 25(2)(h) |
| Switching charges | Reduced and cost-based until 12 January 2027, prohibited thereafter | Art. 29 |
During the transition period the provider must give reasonable assistance, maintain the service, inform the customer of known risks and ensure a high level of security. The contract must also list exhaustively which data and digital assets can be ported, and which internal data the provider excludes in order to protect trade secrets. Under Data Act Art. 26 the provider must give information on the available methods and formats and refer to an up-to-date online register of data structures and data formats.
An exit clause is worthless if the data comes out in a format nobody else can read.
Which exemptions apply?
Under Data Act Art. 31 several of the obligations do not apply to services where most of the main features are custom-built for a single customer and not offered at broad commercial scale. Nor does Chapter VI apply to trial versions offered for a limited period. The provider must tell the customer which obligations do not apply before the contract is concluded.
Switching charges do not include standard service fees or early termination penalties (Data Act Art. 2). A commitment period may therefore still cost money to break. How this is to be reconciled with the right to switch on two months’ notice has not been settled. The regulation contains no specific transitional rule for Chapter VI, and on its wording the rules therefore also apply to contracts concluded before 12 September 2025. In its Digital Omnibus proposal the European Commission has proposed relaxations for, among other things, older contracts with small and medium-sized providers. The proposal had not been adopted when this article was written.
Does the Data Act apply in Norway?
Not yet. The regulation is EEA-relevant, but it has not been incorporated into the EEA Agreement. According to the Norwegian Government’s EEA memo, the assessment of acceptability and the need for adaptations has not been concluded, and implementation in Norwegian law will require legislative amendments. We have found no Norwegian public consultation on implementation. The Norwegian Communications Authority, Nkom, has said it is a likely supervisory authority for the switching rules.
Under Data Act Art. 1(3) the regulation applies to providers offering services to customers in the EU, wherever the provider is established. Norwegian businesses with subsidiaries in the EU may therefore already have rights under the regulation today. Many global providers have also introduced the same terms for all customers. Until the rules apply in Norway, however, Norwegian customers must secure their exit through the contract.
What does the GDPR require on termination?
Where the provider processes personal data on the customer’s behalf, the data processing agreement must stipulate that the provider, at the customer’s choice, deletes or returns all personal data when the service ends, and deletes existing copies unless the law requires storage (GDPR Art. 28(3)(g)). This obligation applies in Norway today.
The customer is the controller and must be able to document that the data has been deleted or returned. Ask for written confirmation of deletion, including from subprocessors. Read more about the data processing agreement when buying SaaS. If the data is held by a provider in the United States, the transfer basis must also be assessed on switching. See the article on the Data Privacy Framework and transfers to the US.
What should the exit clause contain?
The Norwegian government’s standard agreement SSA-L is a good benchmark, for private customers too. Under SSA-L 2026 the service must be fully functional throughout the termination period, whatever the reason for termination (clause 5.3). The provider must facilitate the transfer of data together with backups, data structures and metadata, as well as licences, contracts and user lists. The customer is entitled to follow-up assistance for up to 30 days after the service has been established with the new provider, and may require the contract to be extended for up to six months on the same terms (clause 5.4). The data must be delivered in a generally available and machine-readable format, and the provider has no right under any circumstances to withhold the data (clause 7.2).
Assistance is paid for at the agreed hourly rates, but not where the contract is terminated because of the provider’s material breach. That is a balanced solution which customers should also insist on in commercial contracts.
Where does exit most often go wrong?
Exit most often goes wrong because the customer starts too late. The notice period expires before a new provider has been chosen, and the customer must either renew for another year or move in a hurry. The second most common problem is that the export covers raw data only. Attachments, history, access rights, workflows and links between datasets are left behind, or come out in a format that has to be rebuilt by hand.
A third problem is that nobody in the business owns the process. Exit requires legal, technical and subject-matter expertise, and responsibility should sit with one person who has a mandate to take decisions. Loss of data during the transition is also often poorly covered by the provider’s liability provisions.
What should the business do?
- Prepare an exit plan before the contract is signed. Describe which data, integrations and configurations must be moved, and how long it will take.
- Require a machine-readable and documented format, with data structures and metadata intact.
- Agree a transition period and extension. The service must work fully until the migration is complete, and the customer should be able to extend the contract if needed.
- Agree assistance and price in advance, and that assistance is free of charge if the provider is in breach.
- Exclude any right of retention over the data, including where payment is disputed.
- Require deletion with written confirmation, including from subprocessors, and in line with the data processing agreement.
- Test the export regularly. An annual trial export uncovers problems while there is still time to fix them.
- Check whether the provider complies with the Data Act for its EU customers, and ask for the same terms to apply in Norway.
Cloud exit is closely linked to price and liability. A strong exit clause gives the customer a real option to say no to a price increase from the SaaS provider, and it reduces the consequences if data is lost. See also the article on limitation of liability in SaaS contracts, the topic page on contracts and the topic page on data protection.
Questions and answers
Do the Data Act's switching rules apply to Norwegian businesses?
Not as Norwegian law yet. The regulation has not been incorporated into the EEA Agreement. It applies to providers offering services to customers in the EU, wherever the provider is established. A Norwegian business with subsidiaries in the EU, or with a provider that uses the same terms across the EEA, will therefore often feel the rules in practice.
Can the provider withhold our data if we owe it money?
That depends on the contract and on Norwegian law on rights of retention. A good contract excludes it expressly, as SSA-L does. Where the data includes personal data, the provider as processor has no right of its own to use it in any event, and the duty to delete or return it follows from the data processing agreement.
How long should the provider keep the data after the contract has ended?
Long enough for you to have retrieved and checked the data, but no longer. In the EU the Data Act requires at least 30 days after the transition period. After that the data should be deleted, and the provider should confirm the deletion in writing.
- Data Act, Regulation (EU) 2023/2854 Arts. 1, 2, 23, 25, 26, 29, 31 and 50
- General Data Protection Regulation (EU) 2016/679 Art. 28(3)(g)
- Norwegian Government, EEA memo on the Data Act
- Norwegian Communications Authority (Nkom), Data Act (DA)
- DFØ, SSA-L Norwegian government standard agreement for ongoing services (2026) clauses 5.3, 5.4 and 7.2
Next legal review: 31 January 2027