Our Expert in Austria
No results available
The rules governing eu data act austria contracts are shifting decisively in the 2025–2026 window, and Austrian in‑house counsel, procurement leads and CTOs need to act now rather than at renewal. The EU Data Act (Regulation (EU) 2023/2854) introduces mandatory access, portability, cloud‑switching and fairness obligations that cut straight across existing cloud, SaaS, ICT outsourcing and business‑to‑business data‑sharing agreements. Many contracts drafted before these obligations became relevant will contain terms that are now unenforceable or non‑compliant. This guide sets out precisely what to change, offers sample clause language for discussion, and maps the interplay with the GDPR and, for financial institutions, the Digital Operational Resilience Act (DORA).
The goal is practical: give Austrian legal and technical teams a clause‑level playbook they can deploy immediately.
Who this guide is for: Austrian in‑house counsel, procurement teams, CTO/CIOs, SaaS and cloud vendors, and banks. Focus: practical contract changes and sample clause language to meet EU Data Act obligations applying across 2025–2026.
The EU Data Act is a horizontal regulation that reshapes how data generated by connected products and related services is accessed, shared and moved between cloud environments. For contract teams, the headline is straightforward: agreements that lock in data, obstruct switching, or impose one‑sided terms on weaker parties must be rewritten. The reforms affecting eu data act austria contracts touch three broad categories, data access and sharing between businesses, switching between data‑processing (cloud) providers, and controls on unfair contractual terms in business‑to‑business dealings.
Austrian organisations do not need to wait for national implementing measures to begin. Because the Data Act is an EU regulation, its provisions apply directly. The practical effect is that any Austrian entity that holds data, processes it on behalf of others, or supplies cloud infrastructure and platform services will need to audit and amend its contract templates. The clock is set by the regulation’s staggered application dates rather than by domestic legislation.
The Data Act has both a broad material and territorial scope. It applies to manufacturers and suppliers of connected products and related services placed on the EU market, to data holders that make data available, to data recipients, and to providers of data‑processing services, including cloud and edge providers. Crucially, the territorial reach extends to non‑EU providers where they serve users in the Union, so an Austrian buyer contracting with a foreign cloud vendor still benefits from these protections.
The obligations do not all commence simultaneously. The regulation entered into force following its publication in the Official Journal, with the core obligations becoming generally applicable after a transitional period, and certain provisions, such as the data‑access‑by‑design obligations for newly placed connected products and specific switching‑charge rules, phased in on later dates. Contract teams should treat the 2025–2026 window as the operative period for template review and renegotiation, and consult the European Commission’s Data Act policy page and EUR‑Lex for the precise application dates relevant to each obligation.
Three groups feel the sharpest impact. Austrian banks and fintechs must reconcile Data Act switching and access duties with DORA’s ICT third‑party requirements. SaaS and cloud vendors face new switching, export and interoperability obligations that directly affect their commercial models. OEMs and manufacturers of connected products, significant in Austria’s industrial and automotive supply base, must enable users and third parties to access product‑generated data. The changes to eu data act austria contracts therefore ripple through both service providers and their customers.
Procurement teams launching new tenders should embed Data Act requirements into RFPs and draft contracts immediately, treating compliance as a mandatory selection criterion. For existing agreements, prioritise high‑value and high‑risk suppliers for amendment ahead of natural renewal dates. Waiting until renewal risks operating under non‑compliant terms and leaves migration options unprotected.
Understanding which agreements fall within the reforms is the first drafting decision. In practice, the following contract types are squarely affected:
Legacy agreements frequently grant the provider broad discretion over data formats, impose steep or open‑ended exit fees, and offer little or no migration assistance. Some contain proprietary lock‑in clauses that make switching commercially prohibitive. Under the Data Act these positions must give way. The provider must offer exports in a structured, commonly used and machine‑readable format, provide meaningful switching support, and refrain from imposing charges that exceed what the regulation permits during the phase‑out of switching charges.
The obligations most likely to require redrafting cluster around three themes: B2B data access and portability, cloud switching and exit assistance, and the prohibition of unfair terms. Each carries both technical and contractual consequences, so legal and engineering teams should draft in tandem.
The Data Act gives users of connected products and related services the right to access the data they generate and to direct that data be shared with third parties of their choosing. For data holders, this means contracts must set out the mechanisms, formats and timelines for making data available. Where a data holder is obliged to make data available to a recipient, the terms on which it does so must be fair, reasonable, non‑discriminatory and transparent. Contract drafters should specify the data categories in scope, the access method (for example an API or secure transfer), the format, and any permitted compensation, ensuring that any charge reflects a reasonable and objectively justified basis rather than a lock‑in premium.
Provisions on switching between data‑processing services are among the most consequential for cloud switching austria strategies. Cloud and edge providers must remove pre‑commercial, commercial, technical, contractual and organisational obstacles that prevent customers from terminating a contract and porting their data and digital assets to another provider or to on‑premises systems. Contractually, this translates into a maximum notice or transition period, an obligation to provide export in usable formats, and a duty to offer assistance during the switching process. The regulation also mandates the progressive withdrawal of switching charges, so contracts should not assume the provider can levy exit fees indefinitely.
The Data Act introduces an unfairness test for certain B2B contractual terms concerning data access and use, targeting terms unilaterally imposed on one enterprise by another. A term is non‑binding if it grossly deviates from good commercial practice in data access and use, contrary to good faith and fair dealing. Terms that exclude or limit liability for intentional acts or gross negligence, or that hand the imposing party sole discretion to determine whether supplied data conforms to the contract, are among those presumed or deemed unfair. Austrian contract teams negotiating with dominant suppliers can use these controls as leverage to strike out one‑sided provisions.
As a practical tip, procurement teams should catalogue suspect clauses in existing templates and flag them for renegotiation, because unfair terms data act controls apply regardless of the label the parties gave the clause.
Turning obligations into enforceable clauses is where most compliance projects succeed or fail. The following section provides a clause bank and negotiation points. All sample language below is offered for discussion and should be adapted to the specific transaction, it is not a substitute for tailored legal advice.
Cost is the most contested area in ict outsourcing contracts austria. Draft an explicit cost‑allocation clause identifying who bears the expense of exports, migration testing and switching assistance, and cap any permissible charges. Because the Data Act constrains and progressively removes switching charges, contracts should distinguish between reasonable ongoing data‑retrieval charges and prohibited exit penalties. Adaptation and migration costs incurred by the customer during switching should be addressed rather than left silent, and any provider attempt to shift disproportionate cost to the customer should be challenged as a potentially unfair term.
The comparison table below allocates the core Data Act obligations between provider and client, and pairs each with the clause type most Austrian teams will need to draft. Use it as the backbone of any amendment or new agreement, then tailor the sample language above to the transaction.
| Obligation | Cloud Provider / Data Holder | Client / Data Recipient | Typical contract clause |
|---|---|---|---|
| Provide export in usable format | Deliver data exports, APIs, documentation | Request exports, confirm format | Export / portability clause (sample) |
| Support for cloud switching | Provide assistance and clear timelines | Plan migration, test exports | Exit assistance and testing clause |
| Interoperability / APIs | Maintain APIs and documentation | Use APIs and ensure compatibility | API access and SLA clause |
| Cost allocation | May charge reasonable costs only where permitted | Negotiate cap or free switching | Cost allocation and cap clause |
| Unfair terms | Must not impose disproportionate obligations | Seek balanced warranties | Unfair terms carve‑out |
When negotiating, hold firm on a defined maximum transition period, a no‑lock‑in warranty, and an obligation to deliver exports in an industry‑standard format. Red lines for the customer should include any clause permitting the provider to withhold data pending payment disputes, any open‑ended exit fee, and any provision granting the provider sole discretion over data‑conformity determinations. For data sharing agreements austria, ensure the sharing terms are expressly fair, reasonable and non‑discriminatory, and record the objective justification for any compensation. Providers, in turn, should reserve the right to recover genuinely reasonable, documented costs and to require reasonable security measures during transfers.
The Data Act operates alongside, not in place of, existing data‑protection and financial‑regulatory frameworks. Where data made available under the Data Act includes personal data, the GDPR continues to apply in full, and the Data Act does not create a new legal basis for processing. Austrian teams must therefore identify a valid GDPR legal basis before sharing or porting personal data, and reconcile any conflict in favour of the data‑protection rules. The Austrian Data Protection Authority and the European Data Protection Board remain the reference points for supervisory expectations on personal‑data handling.
| Issue | Under the GDPR | Under the Data Act |
|---|---|---|
| Scope of data | Personal data of identified or identifiable individuals | Data generated by connected products and related services, personal and non‑personal |
| Legal basis to share | Requires a lawful basis under Article 6 (and Article 9 where relevant) | Creates access and sharing rights but no independent lawful basis for personal data |
| Roles | Controller / processor allocation and processing agreements | Data holder / data recipient / data‑processing service provider |
| Portability | Right to data portability for personal data (Article 20) | Broader portability and switching for data and digital assets |
Austrian financial institutions must align Data Act switching and access provisions with DORA’s obligations on ICT third‑party risk. DORA prescribes contractual content for arrangements with ICT service providers, including exit strategies and access rights, which dovetail with the Data Act’s switching duties. In practice this means a single, coherent set of exit and portability clauses that satisfies both regimes, avoids duplication, and preserves the supervisory‑access rights that financial‑sector authorities expect. Where the two frameworks address the same subject, for example transition planning, draft to the higher standard so that one clause serves both compliance objectives.
As a directly applicable EU regulation, the Data Act is enforced through competent authorities designated by each Member State, alongside the coordinating role of EU institutions. Austrian organisations should monitor the Austrian Legal Information System (RIS) for national measures identifying the competent authorities and any procedural rules, and treat data‑protection matters as falling within the remit of the Austrian Data Protection Authority. Non‑compliant contractual terms may be rendered non‑binding, and affected parties may pursue remedies before the competent authorities and courts.
Allocate risk deliberately. Include audit rights allowing verification of a provider’s export and switching capabilities, negotiate liability provisions that do not fall foul of the unfairness controls, and build termination triggers tied to a provider’s failure to deliver compliant exit assistance. Insurance and indemnity provisions should be reviewed to confirm they respond to Data Act non‑compliance scenarios. Because eu data act austria contracts will be scrutinised against the regulation’s fairness standards, avoid drafting protections in a way that itself becomes an unfair term.
A structured programme prevents the review from stalling. Assign clear owners across legal, procurement and technical teams, and sequence the work by risk rather than by renewal date alone.
“With effect from the amendment date, the Agreement is amended to include the Data Act Compliance Schedule, which sets out the Provider’s obligations regarding data export, switching assistance, interoperability and fair contractual terms. In the event of conflict, the Data Act Compliance Schedule prevails over inconsistent terms of the Agreement.”
Sequencing matters: the fastest wins usually come from standardising a reusable compliance annex, which lets teams update many agreements consistently. For data portability austria obligations in particular, verify that the promised export formats are genuinely usable by an alternative provider before signing off.
Different sectors face different pressure points, and negotiation priorities should reflect them.
Compliance with the reforms shaping eu data act austria contracts is now a practical drafting exercise, not a distant regulatory concern. Austrian organisations should inventory their agreements, insert switching, portability and interoperability clauses, strip out unfair terms, and align each contract with the GDPR and, where relevant, DORA. Prioritise high‑risk suppliers, standardise a reusable compliance annex, and test that exports genuinely work. Teams that move during the 2025–2026 window will protect their switching options and negotiating leverage before enforcement matures.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Roman Hager at WMWP – Act Legal Austria, a member of the Global Law Experts network.
posted 25 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
posted 4 hours ago
posted 5 hours ago
posted 6 hours ago
posted 6 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message