Brussels on Oct. 2026 released a draft "SaaS Portability Regulation" that would require cloud software vendors operating in the EU to provide standardized export interfaces for customer data, application configuration, access controls and audit logs. The proposal targets vendor lock‑in, aiming to make it easier for customers — particularly SMEs and public sector buyers — to move between SaaS products or to bring services in‑house.
What the draft requires
The key obligations in the EU draft are narrow and technical, designed to be implementable within typical SaaS development lifecycles. Under the proposal, vendors meeting the applicability thresholds must:
- Expose an authenticated export API that returns customer data in machine‑readable, documented formats (including schema definitions and metadata).
- Provide export of application configuration and tenant‑level settings (roles, permission models, workflows) sufficient to reconstruct business logic in a replacement system.
- Include a standardized export of access controls and identity mappings (SCIM or equivalent formats) to preserve user and role assignments during migration.
- Offer export of at least 90 days of immutable audit logs and operational metadata to support compliance and forensics post‑migration.
- Document costs and network requirements for any required data egress and provide a non‑discriminatory, published pricing policy for bulk exports.
Scope, thresholds and penalties
The draft applies to SaaS providers "established in or actively targeting" EU customers with more than 50,000 EU-based active subscriptions or annual EU revenue above €5 million. Smaller vendors would be encouraged to adopt an implementation guide but would not be bound by the minimum threshold.
Enforcement would mirror recent digital rules in structure: national regulators would carry out compliance checks, and fines for deliberate non‑compliance could reach up to 3% of global annual turnover — lower than GDPR’s top level but designed to be proportionate to operational obligations.
Why this matters for SaaS vendors and buyers
For enterprise buyers, the draft promises to reduce the technical and commercial friction of switching vendors. Standardized export APIs should make migrations faster and cheaper, improve procurement leverage, and reduce long‑term vendor lock‑in risk. For public sector organizations, the change aligns with existing procurement goals around portability and data sovereignty.
For SaaS vendors, the regulation will require engineering and product work across APIs, data‑export pipelines, documentation and legal terms. Vendors with complex multitenant architectures or heavy use of proprietary runtime logic (embedded business rules, workflow engines or machine‑learning models) will face the biggest technical lift: exporting configuration and behavior sufficiently to allow a functional replacement is non‑trivial.
Industry reaction
Trade groups and vendor coalitions responding to the draft flagged both opportunity and risk. Vendor associations welcomed clarity on portability but warned that exposing configuration and audit artifacts could expose intellectual property or raise security risks if not handled carefully. Procurement and SME groups praised the draft as a pragmatic step toward more competitive SaaS markets.
Several major SaaS vendors — while not named in regulatory text — have already said privately they will push for implementation guidance and allowances for legitimate security, privacy and IP protections, such as redaction of sensitive inference models or aggregation of trade‑secret logic prior to export.
Practical steps for SaaS vendors
SaaS product teams should treat the draft as an early compliance alarm and start a focused program now rather than wait for final text. Key actions:
- Inventory exportable assets: map customer data, tenant configurations, access controls, logs and any tied artifacts (ML models, templates).
- Design an export API: decide formats (JSON Schema, OpenAPI for APIs, SCIM for identities), authentication, throttling and bulk export endpoints.
- Assess IP and security risks: identify which artifacts may reveal trade secrets or introduce attack surface, and define redaction or protected export processes.
- Estimate egress and operational costs: implement reporting to show customers expected bandwidth, time and fees for large exports.
- Update contracts and SLAs: add clear migration commitments, timelines and assurances on integrity and non‑discrimination for exports.
Implementation timeline and next steps
The European Commission set a consultation window of 8 weeks and signalled a typical two‑year phase‑in for regulated vendors after final adoption. That schedule would mean technical implementation deadlines for affected vendors in 2028, with staggered milestones for documentation, API availability and auditability.
Regulators also plan to publish a reference implementation and a machine‑readable schema in collaboration with standards bodies to avoid a fragmentation of formats. Vendors and open‑source communities have an opportunity to shape those standards during the consultation.
What buyers should do now
Procurement teams should bake portability into RFPs immediately: require clarity on export formats, timelines, sample schema and test exports as part of procurement acceptance. SMEs should request migration cost estimates and a trial export during onboarding to reduce surprises later.
Bottom line
The draft SaaS Portability Regulation aims to make switching cheaper and to reduce lock‑in in the rapidly growing SaaS market. The proposal balances technical specificity with room for standards development, but it will force vendors to invest in export tooling, documentation and legal updates. For buyers, it signals a forthcoming era where data, configuration and identity portability become a baseline procurement expectation rather than a negotiated concession.