From 12 September 2026, the EU Data Act moves into its next enforcement phase, and it applies to more UK businesses than the name suggests. There’s no UK equivalent law yet, but if you sell into the EU, use EU-based cloud or SaaS providers, or make anything with a chip in it, you’re likely in scope already, whether you’ve heard of it or not.
The headline change most SMEs should care about is Article 25. It requires cloud and SaaS contracts to let customers switch provider with a maximum notice period of two months, without exit fees beyond a short wind-down charge, and with your data handed over in a usable, interoperable format. If you’ve ever tried to leave a platform and been quoted a hefty “data export and migration” fee, or been locked into an auto-renewing annual contract with no clean way out, this is the clause written specifically to stop that. Providers have until 12 September 2026 to bring existing contracts into line.
The second change, also live from 12 September, affects connected products rather than software contracts. Any new “connected product” placed on the market from that date, meaning anything that generates data through its use and can transmit it, from smart meters and fleet-tracking hardware to connected manufacturing equipment, has to be designed so users can access the data it generates by default, securely, and free of charge. If you manufacture, import, or resell IoT or smart hardware into the EU, this changes what “ready to ship” means for your next product line.
Why this matters even without EU operations
A lot of UK SMEs assume EU regulation is someone else’s problem post-Brexit. That assumption gets expensive fast here, because scope isn’t about where your business is registered, it’s about where your customers or your suppliers are. If your SaaS stack includes an EU-headquartered vendor, or you sell equipment to a distributor in Germany or France, the Data Act’s switching and data-access rights likely already apply to that relationship, whether or not anyone at your business has read the regulation.
There’s also no grace period built in for “we didn’t know”. Non-compliance can escalate to GDPR-level fines, up to 4% of global turnover for the most serious breaches, which is a disproportionate risk for a small business that simply never checked whether a contract clause it inherited years ago was still enforceable.
What to actually check before September
Pull your current SaaS contracts and look at the exit terms. Notice period, exit fees, and data export format are the three things Article 25 governs. If an EU-based provider’s contract still says 12 months’ notice and a four-figure migration fee, that term may already be unenforceable, and it’s worth a conversation with them rather than assuming it stands.
If you make or sell connected hardware into the EU, check your next product release date against 12 September. Anything launching after that date needs data-access design built in, not bolted on afterwards. Retrofitting this late in a product cycle is far more expensive than specifying it at the design stage, which is exactly the kind of build decision BuildApps gets involved in early when clients are speccing new hardware or connected product lines.
Don’t wait for a UK equivalent to force your hand. There’s no confirmed timeline for UK-specific legislation mirroring this, but “no UK law yet” doesn’t mean “no exposure now” if your contracts or products already touch EU customers or vendors.
The takeaway
This is a rare piece of EU regulation that mostly works in a small business’s favour: cheaper, faster software switching, and clearer data rights on the products you make. The businesses caught out won’t be the ones affected by it, they’ll be the ones who didn’t check whether they were.