[codicts-css-switcher id=”346″]

Global Law Experts Logo
eu data act romania

Our Expert in Romania

  • GOLD

EU Data Act Romania 2026: Cloud Switching, Data Access and Contracting Rules Explained

By Global Law Experts
– posted 2 hours ago

EU Data Act Romania obligations become a central procurement concern in 2026, as the Regulation’s rules on cloud switching, data access and contract fairness take practical effect for buyers and suppliers operating in the Romanian market. The Data Act (Regulation (EU) 2023/2854) is an EU regulation that applies directly across all Member States, meaning Romanian businesses must comply without waiting for national transposition. For in-house counsel, CTOs and procurement leads, the immediate task is repapering SaaS and cloud agreements to reflect new portability duties, restrictions on switching charges, and mandatory exit assistance. This guide translates the dense legislative text into concrete contract drafting instructions, sample clauses and a 2026 compliance checklist.

Who this guide is for: In-house counsel, procurement leads, CIOs/CTOs and SaaS or cloud providers with operations or customers in Romania. Its purpose is to explain how the EU Data Act affects cloud switching, data access and contract terms in 2026, and to provide sample clauses, a checklist and a negotiation playbook you can use immediately.

Scope & limitations: This guide covers the EU Data Act as it applies to cloud switching, data access and B2B/B2C contracting in Romania. It does not cover Romanian labour law changes, taxation, or sector-specific overlays. The sample clauses below are drafts for discussion and require legal review before use. For background on selecting counsel, see the Choosing a Technology Lawyer in Romania, guide.

Why 2026 Matters for EU Data Act Romania Compliance

2026 is a pivot year for Romanian technology regulation. The EU Data Act introduces a package of rights and obligations designed to rebalance the relationship between data holders, users and cloud service providers. The Regulation entered into application in September 2025, so 2026 is the first full year in which its contracting and switching rules operate in day-to-day procurement. For companies with Romanian operations, the practical consequence is that existing cloud and SaaS contracts, many drafted before these rules existed, may no longer be compliant. Terms that lock customers in, impose excessive exit charges, or fail to guarantee data portability are precisely the terms the Data Act targets.

The commercial stakes are high. Procurement teams running competitive tenders in 2026 need contract language that reflects the new baseline, while suppliers must adapt pricing models, exit processes and technical tooling or risk unenforceable terms. The gap between what legacy agreements say and what the EU Data Act Romania framework now requires is the repapering challenge this guide addresses.

Quick Overview: What Is the EU Data Act?

The EU Data Act is a flagship instrument of the European Union’s digital strategy, aimed at ensuring fair access to and use of data across the economy. According to the European Commission, the Act’s objectives are to make more data available for use, to set rules on who can use and access data generated in the EU, and to remove barriers that lock customers into particular cloud and edge services.

Objectives and Who It Applies To

The Data Act applies broadly. It reaches manufacturers of connected products, providers of related services, data holders, data recipients, and providers of data processing services, including cloud and edge infrastructure. Its obligations cover both non-personal data and, in certain respects, mixed datasets that combine personal and non-personal information. The Regulation addresses both business-to-business (B2B) and business-to-consumer (B2C) relationships, with the precise obligations varying depending on the Article engaged.

Because the Data Act is a directly applicable EU regulation, Romanian organisations are bound by it on the same terms as businesses elsewhere in the Union. There is no separate Romanian statute to wait for. Each Member State is required to designate competent authorities for enforcement; where personal data is involved, Romania’s data protection authority, the ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal), provides supervisory and enforcement context.

High-Level Timeline and Interplay With GDPR

The Data Act’s provisions phase in over time, with the cloud switching and contracting rules among the most consequential for procurement teams. The European Parliament’s legislative record documents the file’s progression and the policy rationale behind the switching and fairness provisions. Organisations planning their 2026 repapering should treat the year as the practical compliance window and build their contract review around it.

Crucially, the Data Act does not replace the GDPR. Where a dataset contains personal data, the GDPR continues to govern lawful basis, data subject rights and processor obligations. The Data Act adds a layer concerned with access, portability and fair contracting, particularly for non-personal and mixed data. Where personal and non-personal data are inextricably linked, the GDPR’s protections are not displaced. Coordinating the two frameworks is essential whenever mixed datasets are in play.

Key Obligations Relevant in Romania for Contracts

The obligations most likely to affect contract drafting fall into four groups. Each carries direct implications for how SaaS and cloud agreements should be structured.

Data Access and Sharing Duties

The Data Act strengthens the rights of users to access data generated through their use of connected products and related services, and in certain circumstances to have that data shared with third parties of their choosing. For contracts, this means data access provisions can no longer be an afterthought. Agreements should specify what data the user is entitled to, in what format, within what timeframe, and through what mechanism, whether an API, a secure export, or a structured file transfer.

Interoperability and Technical Standards

Providers of data processing services must support interoperability so that customers can move workloads and data between providers. This translates into contractual commitments around supported formats, documented interfaces and the absence of artificial technical barriers. Technical guidance from ENISA on secure data transfer and migration is a useful reference point when specifying these obligations.

Cloud Switching and Portability

Among the most significant changes for EU Data Act Romania compliance are the cloud switching and portability rules. The Act requires providers to enable customers to switch to another service, to port their exportable data, and to receive reasonable assistance during the transition. Contracts must reflect this as an enforceable customer entitlement, not a discretionary vendor favour.

Restrictions on Switching Charges

The Data Act restricts the charges a provider can impose when a customer switches away, and provides for the gradual withdrawal of switching charges. Fees that are designed to deter switching, or that are disproportionate to the actual cost of providing the service, are curtailed, with data-processing-service providers required to phase out switching charges over a transition period set out in the Regulation. The European Parliament’s legislative file confirms that restricting abusive switching charges and requiring exit assistance are core aims of the Regulation. Any contract that currently relies on penal exit pricing should be flagged for immediate revision.

Not this guide: Readers searching for 2026 Romanian labour law changes are in the wrong place, those reforms are outside the scope of this Data Act contracting guide. Consult dedicated labour law resources for that topic.

Cloud Switching and Portability in Romania, Technical and Commercial Implications

Cloud switching is where the EU Data Act Romania rules bite hardest in day-to-day procurement. Understanding what the Act requires technically and commercially is the foundation for drafting enforceable clauses.

What “Cloud Switching” Means Under the Data Act

Under the Data Act, cloud switching refers to a customer’s ability to terminate a contract with one provider of data processing services and move to another provider, or to on-premises infrastructure, while retaining access to and control over their data and, where feasible, functional equivalence. The Regulation is designed to remove the commercial, contractual and technical obstacles that historically made switching costly or impractical.

For Romanian buyers, this means the contract must treat switching as a planned, supported process. For providers, it means building and documenting the capabilities that make switching possible rather than relying on lock-in as a retention strategy.

Data Format and Interoperability Obligations

Portability is meaningless if exported data arrives in a proprietary format the customer cannot use. The Data Act therefore pushes providers toward structured, commonly used and machine-readable formats and documented interfaces. Cloud portability rules should be reflected in the contract through explicit commitments on export formats, schema documentation and interface availability. ENISA’s technical guidance on interoperability and secure migration helps teams define what “good” looks like in practice.

Technical Assistance and Export Tools

The Act obliges providers to offer reasonable assistance during a switch. In contractual terms, this should be expressed as concrete deliverables: migration support, a named transition team, export tooling, and documentation. Service levels should quantify the obligation, for example, the maximum time to produce a complete data export after a switching request, and acceptance criteria to confirm the export is complete and usable.

Sample technical SLA metrics to negotiate:

  • Export initiation. Provider to begin data export within a defined number of business days of a written switching request.
  • Export completion. Full exportable dataset delivered within an agreed window, with status reporting at defined intervals.
  • Format compliance. Export delivered in the agreed structured, machine-readable format with accompanying schema documentation.
  • Test migration. At least one supported test migration before the live cutover, with documented acceptance criteria.
  • Verification. Provider to supply integrity evidence (record counts, checksums) so the buyer can confirm completeness.

Switching Charges and Allowed Costs

The restriction and phasing-out of switching charges is a headline reform. Providers may not impose charges that obstruct switching or that exceed the costs genuinely incurred, and switching charges are to be withdrawn progressively in line with the Regulation’s transition timetable. Reduced, cost-based charges for the mandatory switching process may be permitted during the transition period, but they cannot be structured so as to deter the customer from leaving. Contracts should distinguish clearly between prohibited penal exit charges and any permitted, transparent, cost-based recovery, and should state that charges reduce or taper over the transition period in line with the Regulation’s direction of travel.

Contracting Rules: Clauses You Must Change (Playbook)

This is the operational heart of EU Data Act Romania compliance. The following clauses should be reviewed, added or amended in every SaaS and cloud agreement with a Romanian nexus. The sample language below is drafting material for discussion and requires legal review before use.

Required New or Revised Clauses

  • Data access. Define the data the customer is entitled to access, the format, the delivery mechanism and the response timeframe.
  • Portability. Guarantee the right to export exportable data in a structured, machine-readable format on request and on exit.
  • Interoperability. Commit to documented interfaces and supported formats that enable migration to another provider.
  • Exit and transition assistance. Specify the assistance, resources and timelines the provider will deliver during a switch.
  • Switching charges. Prohibit penal exit charges and limit any cost recovery to transparent, cost-based amounts, reflecting the phase-out required by the Regulation.
  • Audit and evidence. Give the customer the right to verify export completeness and compliance with switching obligations.

Sample Clause Language (Buyer-Facing and Supplier-Facing)

These are draft clauses for discussion, legal review required. They are not final legal advice.

1. Switching charges (buyer-facing). “The Supplier shall not impose any charge for, or as a condition of, the Customer switching to another provider of data processing services or to on-premises infrastructure, save for transparent, cost-based charges permitted under the applicable transition provisions of the EU Data Act and directly attributable to the technical switching assistance actually provided, which shall not be structured so as to obstruct or deter switching.”

2. Exit and transition assistance (buyer-facing). “On termination or at the Customer’s request, the Supplier shall provide exit assistance including a named transition contact, reasonable migration support, documented export tooling and interface documentation, so as to enable the Customer to migrate to an alternative provider within the agreed transition period.”

3. Portability and data format (buyer-facing). “The Supplier shall, within [X] business days of a written request, export all of the Customer’s exportable data in a structured, commonly used and machine-readable format, together with sufficient schema documentation to enable the Customer to ingest that data with another provider.”

4. Interoperability / interface access (supplier-facing). “The Supplier shall maintain and document standard interfaces enabling the export of Customer data and, where technically feasible, functional equivalence with alternative services; the Supplier’s obligations are limited to data and configurations within its control and do not extend to third-party components outside the Service.”

5. Third-party data access (supplier-facing). “Where the Customer directs the Supplier to make data available to a nominated third party, the Supplier shall do so in the agreed format and timeframe, subject to verification of the third party’s authorisation and compliance with applicable data protection law.”

6. Verification and evidence (buyer-facing). “The Supplier shall provide integrity evidence, including record counts and checksums, confirming that the exported dataset is complete, and shall support at least one test migration prior to the live cutover against documented acceptance criteria.”

Allocation of Liability and Indemnities

Negotiation friction will concentrate on who bears the risk if a migration fails, is delayed, or results in data loss. Practical negotiation points include:

  • Service credits. Tie failure to meet export or transition SLAs to meaningful credits, not token amounts.
  • Data loss liability. Carve data integrity failures during a supplier-controlled export out of general liability caps, or set a dedicated super-cap.
  • Indemnity scope. Limit supplier exit-assistance indemnities to its own acts and omissions, excluding third-party platform failures outside its control.
  • Cost recovery transparency. Require an itemised, auditable basis for any permitted switching-related charge so the buyer can test it against the Data Act’s switching-charge rules.

B2B Data Sharing and Third-Party Access, Allocation and Compliance

The EU Data Act Romania framework also reshapes how businesses share data with one another and with nominated third parties. Getting the contractual allocation right prevents disputes and compliance exposure.

When the Data Act Mandates Access for Third Parties

In defined circumstances, a user is entitled to direct that data generated through their use of a product or service be shared with a third party of their choosing. The data holder must facilitate this, subject to safeguards. For contracts, this means building a clear route for authorised third-party access: how a request is made, how authorisation is verified, what format is used, and what the recipient may and may not do with the data.

B2B Versus B2C Differences

The obligations differ depending on whether the relationship is business-to-business or business-to-consumer. B2B arrangements allow more scope for negotiated terms, but the Data Act’s fairness controls, including the rules on unilaterally imposed unfair contract terms, still constrain what can be imposed, particularly on smaller counterparties. B2C relationships attract stronger protective defaults. Drafting teams should identify which regime applies to each dataset and tailor the clauses accordingly.

Contractual Flowdowns to Sub-Processors and Subcontractors

Compliance cannot stop at the prime contract. Where a provider relies on sub-processors or subcontractors, the data access, portability and switching obligations must flow down so the provider can actually deliver them. Contracts should require the provider to procure equivalent commitments from its supply chain and to remain responsible to the customer for the whole chain.

Comparison: Data Act Obligations (B2B) vs GDPR Obligations

Topic EU Data Act GDPR Romanian national law / regulator notes
Primary focus Fair access and portability of non-personal and mixed data; cloud switching Personal data protection and individual rights Designated competent authorities for enforcement; data protection supervision by ANSPDCP
Scope B2B and B2C data depending on the Article Personal data only National enforcement designation and policy
Contracting impact Restricts unfair switching charges; requires exit and transition assistance; interoperability duties Requires lawful basis, DPIAs, processor obligations National regulator guidance, sector specifics

EU Data Act Romania Compliance Checklist and Timeline for 2026

The following checklist assigns ownership and sequences the work across a repapering programme. Treat it as a six-to-nine-month roadmap.

Legal workstream (owner: General Counsel / legal):

  • Audit all cloud and SaaS contracts for switching charges, exit terms and portability gaps.
  • Draft updated standard terms and a Data Act clause pack.
  • Map personal, non-personal and mixed datasets and coordinate GDPR and Data Act compliance.
  • Define liability, indemnity and service-credit positions for exit and migration.

Technical workstream (owner: IT / engineering):

  • Inventory export tooling, interfaces and supported data formats.
  • Build or verify structured, machine-readable export capabilities.
  • Establish test migration procedures and acceptance criteria.
  • Align secure transfer and migration practices with ENISA guidance.

Procurement workstream (owner: procurement):

  • Update RFP and tender templates with Data Act-ready clauses.
  • Add portability, switching and exit criteria to supplier evaluation.
  • Require evidence of export tooling and test migration during selection.
  • Train procurement and IT teams on the new contractual baseline.

Indicative four-quarter timeline:

  1. Q1: Contract audit, dataset mapping and gap analysis.
  2. Q2: Draft clause pack, update standard terms and RFP templates.
  3. Q3: Negotiate priority supplier contracts; build and test export tooling.
  4. Q4: Complete repapering, run test migrations and finalise exit plans.

Exit plan template checklist: named transition contacts; agreed export format and schema; export and completion timelines; test migration and acceptance criteria; integrity evidence; permitted cost-recovery basis; data deletion confirmation post-migration.

What SaaS and Cloud Providers Must Do

Commercial and Technical Steps for Providers

  • Product changes. Build documented export interfaces and structured-format outputs so switching is technically feasible.
  • Pricing and terms updates. Remove penal exit charges; replace them with transparent, cost-based recovery where permitted, and plan for the phase-out of switching charges required by the Regulation.
  • Support and transition teams. Stand up a defined exit-assistance function with named contacts and support capacity.
  • Documentation and certifications. Publish schema documentation, interface specifications and migration guides; align security practices with recognised technical guidance.

Providers that treat these as competitive differentiators, advertising frictionless switching and transparent exit terms, are likely to fare better in 2026 tenders than those that resist the change. Procurement teams can be expected to score portability and exit assistance explicitly.

What Enterprise Buyers Must Do

Procurement and Contract Playbook for Buyers

  • Tender language. Specify Data Act-compliant switching, portability and exit requirements in the RFP.
  • RFP clauses. Include the switching-charge, exit-assistance and portability clauses as mandatory, not negotiable extras.
  • Evaluation checklist. Score suppliers on export format support, interface documentation and demonstrated migration capability.
  • Testing and acceptance. Require a test migration and agreed acceptance criteria before committing to a live cutover.

Buyers who embed these requirements at the tender stage avoid the far harder task of extracting portability concessions mid-contract. The likely practical effect is that well-drafted RFPs will shift the negotiating balance toward customers in 2026.

Conclusion and Recommended Next Steps

EU Data Act Romania compliance in 2026 is fundamentally a contracting exercise: the Regulation’s rules on cloud switching, data access and fair terms must be translated into enforceable clauses, supported by real technical capability. Organisations that act early will convert a compliance obligation into a commercial advantage, while those that delay risk unenforceable terms and stalled migrations. The Data Act compliance Romania roadmap set out above gives legal, technical and procurement teams a shared plan of action.

Three recommended next steps:

  1. Commission a legal review of your cloud and SaaS contracts against the Data Act’s switching, portability and exit requirements.
  2. Update your RFP and tender templates with Data Act-ready clauses before your next procurement cycle.
  3. Run a test migration with a priority supplier to validate export tooling and acceptance criteria.

For broader context on engaging specialist counsel, see the Choosing a Technology Lawyer in Romania, guide.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Razvan Alexandru Olaru at Olawru, a member of the Global Law Experts network.

Sources

  1. European Commission, EU Data Act overview
  2. European Parliament, Legislative Train / Data Act file
  3. EUR-Lex, Regulation (EU) 2023/2854 (Data Act)
  4. European Data Protection Board (EDPB)
  5. ENISA, EU Agency for Cybersecurity
  6. Romanian National Authority for the Supervision of Personal Data Processing (ANSPDCP)
  7. OECD, Digital Economy / Data Governance publications

FAQs

Does the EU Data Act apply in Romania?
Yes. As an EU regulation, the Data Act applies directly across all Member States, including Romania, without separate national transposition. Whether specific obligations apply depends on the data and activities involved and the relevant B2B or B2C distinction. Where personal data is in scope, the ANSPDCP provides supervisory context.
A switching charge is a charge imposed when a customer moves to another provider. The Data Act restricts switching charges and provides for their progressive withdrawal: suppliers cannot impose charges that obstruct or deter switching. Transparent, cost-based recovery for genuine switching assistance may be permitted during the transition period, but it cannot function as a penalty.
Contracts should allocate this expressly. Typically the supplier provides defined exit assistance, and any cost allocation is negotiated, but it cannot be structured as an unfair switching charge. Use an itemised, auditable cost basis so the charge can be tested against the Regulation.
The Data Act governs access to and portability of non-personal and mixed data and fair contracting; the GDPR continues to govern personal data processing, including lawful basis and data subject rights. Both may apply to mixed datasets, so coordinate compliance and consult EDPB and ANSPDCP guidance.
Conduct a contract audit, update standard terms and RFP templates, implement structured export tooling, run test migrations, and train procurement and IT teams. Follow the six-to-nine-month repapering roadmap in this guide and secure legal sign-off on all clause language.
No. Labour law reforms are outside the scope of this Data Act contracting guide. Consult dedicated labour law resources for those updates.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

EU Data Act Romania 2026: Cloud Switching, Data Access and Contracting Rules Explained

Send welcome message

Custom Message