EU Data Act Romania obligations become a central procurement concern in 2026, as the Regulation’s rules on cloud switching, data access and contract fairness take practical effect for buyers and suppliers operating in the Romanian market. The Data Act (Regulation (EU) 2023/2854) is an EU regulation that applies directly across all Member States, meaning Romanian businesses must comply without waiting for national transposition. For in-house counsel, CTOs and procurement leads, the immediate task is repapering SaaS and cloud agreements to reflect new portability duties, restrictions on switching charges, and mandatory exit assistance. This guide translates the dense legislative text into concrete contract drafting instructions, sample clauses and a 2026 compliance checklist.
Who this guide is for: In-house counsel, procurement leads, CIOs/CTOs and SaaS or cloud providers with operations or customers in Romania. Its purpose is to explain how the EU Data Act affects cloud switching, data access and contract terms in 2026, and to provide sample clauses, a checklist and a negotiation playbook you can use immediately.
Scope & limitations: This guide covers the EU Data Act as it applies to cloud switching, data access and B2B/B2C contracting in Romania. It does not cover Romanian labour law changes, taxation, or sector-specific overlays. The sample clauses below are drafts for discussion and require legal review before use. For background on selecting counsel, see the Choosing a Technology Lawyer in Romania, guide.
2026 is a pivot year for Romanian technology regulation. The EU Data Act introduces a package of rights and obligations designed to rebalance the relationship between data holders, users and cloud service providers. The Regulation entered into application in September 2025, so 2026 is the first full year in which its contracting and switching rules operate in day-to-day procurement. For companies with Romanian operations, the practical consequence is that existing cloud and SaaS contracts, many drafted before these rules existed, may no longer be compliant. Terms that lock customers in, impose excessive exit charges, or fail to guarantee data portability are precisely the terms the Data Act targets.
The commercial stakes are high. Procurement teams running competitive tenders in 2026 need contract language that reflects the new baseline, while suppliers must adapt pricing models, exit processes and technical tooling or risk unenforceable terms. The gap between what legacy agreements say and what the EU Data Act Romania framework now requires is the repapering challenge this guide addresses.
The EU Data Act is a flagship instrument of the European Union’s digital strategy, aimed at ensuring fair access to and use of data across the economy. According to the European Commission, the Act’s objectives are to make more data available for use, to set rules on who can use and access data generated in the EU, and to remove barriers that lock customers into particular cloud and edge services.
The Data Act applies broadly. It reaches manufacturers of connected products, providers of related services, data holders, data recipients, and providers of data processing services, including cloud and edge infrastructure. Its obligations cover both non-personal data and, in certain respects, mixed datasets that combine personal and non-personal information. The Regulation addresses both business-to-business (B2B) and business-to-consumer (B2C) relationships, with the precise obligations varying depending on the Article engaged.
Because the Data Act is a directly applicable EU regulation, Romanian organisations are bound by it on the same terms as businesses elsewhere in the Union. There is no separate Romanian statute to wait for. Each Member State is required to designate competent authorities for enforcement; where personal data is involved, Romania’s data protection authority, the ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal), provides supervisory and enforcement context.
The Data Act’s provisions phase in over time, with the cloud switching and contracting rules among the most consequential for procurement teams. The European Parliament’s legislative record documents the file’s progression and the policy rationale behind the switching and fairness provisions. Organisations planning their 2026 repapering should treat the year as the practical compliance window and build their contract review around it.
Crucially, the Data Act does not replace the GDPR. Where a dataset contains personal data, the GDPR continues to govern lawful basis, data subject rights and processor obligations. The Data Act adds a layer concerned with access, portability and fair contracting, particularly for non-personal and mixed data. Where personal and non-personal data are inextricably linked, the GDPR’s protections are not displaced. Coordinating the two frameworks is essential whenever mixed datasets are in play.
The obligations most likely to affect contract drafting fall into four groups. Each carries direct implications for how SaaS and cloud agreements should be structured.
The Data Act strengthens the rights of users to access data generated through their use of connected products and related services, and in certain circumstances to have that data shared with third parties of their choosing. For contracts, this means data access provisions can no longer be an afterthought. Agreements should specify what data the user is entitled to, in what format, within what timeframe, and through what mechanism, whether an API, a secure export, or a structured file transfer.
Providers of data processing services must support interoperability so that customers can move workloads and data between providers. This translates into contractual commitments around supported formats, documented interfaces and the absence of artificial technical barriers. Technical guidance from ENISA on secure data transfer and migration is a useful reference point when specifying these obligations.
Among the most significant changes for EU Data Act Romania compliance are the cloud switching and portability rules. The Act requires providers to enable customers to switch to another service, to port their exportable data, and to receive reasonable assistance during the transition. Contracts must reflect this as an enforceable customer entitlement, not a discretionary vendor favour.
The Data Act restricts the charges a provider can impose when a customer switches away, and provides for the gradual withdrawal of switching charges. Fees that are designed to deter switching, or that are disproportionate to the actual cost of providing the service, are curtailed, with data-processing-service providers required to phase out switching charges over a transition period set out in the Regulation. The European Parliament’s legislative file confirms that restricting abusive switching charges and requiring exit assistance are core aims of the Regulation. Any contract that currently relies on penal exit pricing should be flagged for immediate revision.
Not this guide: Readers searching for 2026 Romanian labour law changes are in the wrong place, those reforms are outside the scope of this Data Act contracting guide. Consult dedicated labour law resources for that topic.
Cloud switching is where the EU Data Act Romania rules bite hardest in day-to-day procurement. Understanding what the Act requires technically and commercially is the foundation for drafting enforceable clauses.
Under the Data Act, cloud switching refers to a customer’s ability to terminate a contract with one provider of data processing services and move to another provider, or to on-premises infrastructure, while retaining access to and control over their data and, where feasible, functional equivalence. The Regulation is designed to remove the commercial, contractual and technical obstacles that historically made switching costly or impractical.
For Romanian buyers, this means the contract must treat switching as a planned, supported process. For providers, it means building and documenting the capabilities that make switching possible rather than relying on lock-in as a retention strategy.
Portability is meaningless if exported data arrives in a proprietary format the customer cannot use. The Data Act therefore pushes providers toward structured, commonly used and machine-readable formats and documented interfaces. Cloud portability rules should be reflected in the contract through explicit commitments on export formats, schema documentation and interface availability. ENISA’s technical guidance on interoperability and secure migration helps teams define what “good” looks like in practice.
The Act obliges providers to offer reasonable assistance during a switch. In contractual terms, this should be expressed as concrete deliverables: migration support, a named transition team, export tooling, and documentation. Service levels should quantify the obligation, for example, the maximum time to produce a complete data export after a switching request, and acceptance criteria to confirm the export is complete and usable.
Sample technical SLA metrics to negotiate:
The restriction and phasing-out of switching charges is a headline reform. Providers may not impose charges that obstruct switching or that exceed the costs genuinely incurred, and switching charges are to be withdrawn progressively in line with the Regulation’s transition timetable. Reduced, cost-based charges for the mandatory switching process may be permitted during the transition period, but they cannot be structured so as to deter the customer from leaving. Contracts should distinguish clearly between prohibited penal exit charges and any permitted, transparent, cost-based recovery, and should state that charges reduce or taper over the transition period in line with the Regulation’s direction of travel.
This is the operational heart of EU Data Act Romania compliance. The following clauses should be reviewed, added or amended in every SaaS and cloud agreement with a Romanian nexus. The sample language below is drafting material for discussion and requires legal review before use.
These are draft clauses for discussion, legal review required. They are not final legal advice.
1. Switching charges (buyer-facing). “The Supplier shall not impose any charge for, or as a condition of, the Customer switching to another provider of data processing services or to on-premises infrastructure, save for transparent, cost-based charges permitted under the applicable transition provisions of the EU Data Act and directly attributable to the technical switching assistance actually provided, which shall not be structured so as to obstruct or deter switching.”
2. Exit and transition assistance (buyer-facing). “On termination or at the Customer’s request, the Supplier shall provide exit assistance including a named transition contact, reasonable migration support, documented export tooling and interface documentation, so as to enable the Customer to migrate to an alternative provider within the agreed transition period.”
3. Portability and data format (buyer-facing). “The Supplier shall, within [X] business days of a written request, export all of the Customer’s exportable data in a structured, commonly used and machine-readable format, together with sufficient schema documentation to enable the Customer to ingest that data with another provider.”
4. Interoperability / interface access (supplier-facing). “The Supplier shall maintain and document standard interfaces enabling the export of Customer data and, where technically feasible, functional equivalence with alternative services; the Supplier’s obligations are limited to data and configurations within its control and do not extend to third-party components outside the Service.”
5. Third-party data access (supplier-facing). “Where the Customer directs the Supplier to make data available to a nominated third party, the Supplier shall do so in the agreed format and timeframe, subject to verification of the third party’s authorisation and compliance with applicable data protection law.”
6. Verification and evidence (buyer-facing). “The Supplier shall provide integrity evidence, including record counts and checksums, confirming that the exported dataset is complete, and shall support at least one test migration prior to the live cutover against documented acceptance criteria.”
Negotiation friction will concentrate on who bears the risk if a migration fails, is delayed, or results in data loss. Practical negotiation points include:
The EU Data Act Romania framework also reshapes how businesses share data with one another and with nominated third parties. Getting the contractual allocation right prevents disputes and compliance exposure.
In defined circumstances, a user is entitled to direct that data generated through their use of a product or service be shared with a third party of their choosing. The data holder must facilitate this, subject to safeguards. For contracts, this means building a clear route for authorised third-party access: how a request is made, how authorisation is verified, what format is used, and what the recipient may and may not do with the data.
The obligations differ depending on whether the relationship is business-to-business or business-to-consumer. B2B arrangements allow more scope for negotiated terms, but the Data Act’s fairness controls, including the rules on unilaterally imposed unfair contract terms, still constrain what can be imposed, particularly on smaller counterparties. B2C relationships attract stronger protective defaults. Drafting teams should identify which regime applies to each dataset and tailor the clauses accordingly.
Compliance cannot stop at the prime contract. Where a provider relies on sub-processors or subcontractors, the data access, portability and switching obligations must flow down so the provider can actually deliver them. Contracts should require the provider to procure equivalent commitments from its supply chain and to remain responsible to the customer for the whole chain.
| Topic | EU Data Act | GDPR | Romanian national law / regulator notes |
|---|---|---|---|
| Primary focus | Fair access and portability of non-personal and mixed data; cloud switching | Personal data protection and individual rights | Designated competent authorities for enforcement; data protection supervision by ANSPDCP |
| Scope | B2B and B2C data depending on the Article | Personal data only | National enforcement designation and policy |
| Contracting impact | Restricts unfair switching charges; requires exit and transition assistance; interoperability duties | Requires lawful basis, DPIAs, processor obligations | National regulator guidance, sector specifics |
The following checklist assigns ownership and sequences the work across a repapering programme. Treat it as a six-to-nine-month roadmap.
Legal workstream (owner: General Counsel / legal):
Technical workstream (owner: IT / engineering):
Procurement workstream (owner: procurement):
Indicative four-quarter timeline:
Exit plan template checklist: named transition contacts; agreed export format and schema; export and completion timelines; test migration and acceptance criteria; integrity evidence; permitted cost-recovery basis; data deletion confirmation post-migration.
Providers that treat these as competitive differentiators, advertising frictionless switching and transparent exit terms, are likely to fare better in 2026 tenders than those that resist the change. Procurement teams can be expected to score portability and exit assistance explicitly.
Buyers who embed these requirements at the tender stage avoid the far harder task of extracting portability concessions mid-contract. The likely practical effect is that well-drafted RFPs will shift the negotiating balance toward customers in 2026.
EU Data Act Romania compliance in 2026 is fundamentally a contracting exercise: the Regulation’s rules on cloud switching, data access and fair terms must be translated into enforceable clauses, supported by real technical capability. Organisations that act early will convert a compliance obligation into a commercial advantage, while those that delay risk unenforceable terms and stalled migrations. The Data Act compliance Romania roadmap set out above gives legal, technical and procurement teams a shared plan of action.
Three recommended next steps:
For broader context on engaging specialist counsel, see the Choosing a Technology Lawyer in Romania, guide.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Razvan Alexandru Olaru at Olawru, a member of the Global Law Experts network.
posted 8 minutes ago
posted 47 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
posted 4 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message