EU Data Act · Regulation (EU) 2023/2854

EU law gave customers a new right to switch providers.

Running the migration securely — with evidence you can stand behind — is still on you.

Transfer General is software you run in your own cloud accounts to move data between clouds, encrypted with keys only you hold, and to produce a signed record of exactly what moved.

01Act I · The Mandate

What the law requires of providers.

The EU Data Act has been operative since September 2025. Here is what it puts on providers — and what it deliberately leaves to you.

  • Right to
    switch
    Providers must remove the obstacles to switching to another provider of the same service type, or to your own on-premises infrastructure. The switch may be performed by you or by “third parties authorised by the customer.”
  • Security
    in flight
    The law requires “a high level of security throughout the switching process”an obligation on the provider, governing the migration while it is in flight. It is not an obligation on you to secure or prove the data afterward.
  • Article 29
    switch egress
    Switching charges, including switching-related egress, are capped at direct cost now and prohibited from 12 January 2027.
  • Article 34(2)
    in parallel
    Running clouds in parallel is a separate case: providers may still charge egress, but only at cost. This one does not go to zero in 2027.
02Act II · The Response

How the providers complied — with the bill, not the work.

Each major provider now has a program. They split along the exact line the law draws: leaving versus running in parallel.

Exit / switching egress

All three waive it — each via its own eligibility-reviewed process.

AWS

Support credit for customers leaving AWS.

Google Cloud

No switching charges under its EU Data Act terms.

Microsoft Azure

Free data-transfer-out when leaving Azure.

In-parallel egress

When you keep running on both, it stays chargeable at cost.

Google Cloud

“Data Transfer Essentials” waives qualifying same-company in-parallel egress.

Microsoft Azure

At-cost credit for qualifying European in-parallel transfers.

Each program lowers the cost of getting your data out. None lands it intact in a cloud you control, keeps it encrypted with your own keys end to end, or gives you proof it arrived unchanged.

03Act III · What's Left to You

The fee is gone. The work isn’t.

The actual work of moving regulated data — and proving you did — still sits with you. It comes in two shapes, and the law treats them differently.

Egress fees end — when you switch

A definitive move to another provider or on-prem. Switching egress becomes free in 2027 (Art 29).

You still have to execute the move and prove it happened cleanly.

Egress fees remain — when you run in parallel

Two providers together, continuously. Egress stays chargeable at cost (Art 34(2)) — no end date.

You still have to move the data securely, repeatedly, and prove each transfer.

The gap a free exit leaves

A free exit settles the bill. It doesn’t do the three things a regulated migration actually requires:

01

Land it where you control it

The data has to arrive intact in the destination cloud and account you control — not merely leave the old one.

02

Keep it encrypted with your keys

It stays encrypted with keys only you hold for the whole journey, decrypted only at the destination you control.

03

Hand you the evidence

Proof each object arrived unchanged — what your auditors and risk teams will ask for.

04Act IV · The Remedy

Your accounts. Your keys. Your proof.

Transfer General fits exactly here — not as a provider you hand your data to, but as software you run to close the gap the law leaves open.

What Transfer General doesSoftware you run · not a service you hand your data to
Runs entirely in your own cloud accounts.
Server General never holds your encryption keys and is never in the object data path. The attestation signing key is separate from your encryption keys.
TG encrypts the object before cross-cloud transfer and decrypts only in the destination you control. Plaintext exists only at your source and destination, inside your environments.
Moves objects across clouds — today between the major providers, including AWS, Google Cloud, and Azure.
Produces a signed attestation record for every object, with verification material you can check independently.
Network-path sovereignty

Keeps traffic on sovereign routes — a different, complementary control.

Data-layer sovereignty — TG

The data is encrypted with keys only you hold. The strongest control you can carry into a switch is the one nobody else holds for you.

You run it, you hold the keys, you keep the proof.

The proof

So when your auditor asks you to prove the switch moved data intact — this is what you hand them.

Not a log entry. One object’s signed attestation record, produced automatically at transfer completion — every value independently verifiable against the cloud provider’s KMS, without contacting Server General.

tg_id
26e0e72027abd4501c4bf5ced83dbb85b1e6b4fc70495b662922fd839b12c391
Verification passed
6 PASS · 0 WARN · 0 FAIL · COMPLETE — ATTESTED
Object
patient001_study002_series05_img010.dcm · 256.0 MB
Route
GCP (us-east5) → AWS (us-east-2)
Integrity — SHA-256 (source = destination)
7756cef737283c3232…2e1fad   ✓ hash_match = true
Object encryption
AES-256-GCM · FIPS 140-2 Level 2
Signature
EC_SIGN_P384_SHA384 · ECDSA P-384 / SHA-384
Immutability anchor
immudb tx_id 1648 · Merkle-chained · WORM-retained
Representative — sample Meridian Health data. See the full attestation record
The honest bridge

We won’t tell you a tool makes you compliant.

Here’s the accurate relationship between the law and what TG does.

What the law sets up
What TG gives you
Providers must remove the obstacles to switching and keep the switching process secure — but you still operate the move.
A way to run the move yourself, encrypted with keys only you hold, with a signed record of what moved.
The switch may be performed by the customer or “third parties authorised by the customer.”
A customer-authorised tool you run in your own accounts.
Since 12 Sep 2025
Switching obligations are live.
From 12 Jan 2027
Switching egress becomes free.
Ongoing
In-parallel egress remains chargeable at cost.

The right is already in force; the economics tilt further in 2027. The work of moving data well doesn’t change on any of those dates — which is why it’s worth solving once. The compliance determination is always yours.

Get started

See what “evidence you can stand behind” actually looks like.

Every engagement starts with a proof-of-concept in your own environment. Deploy TG in your accounts, run real cross-cloud transfers, and verify the signed evidence yourself.

Informational only, not legal advice. References are to Regulation (EU) 2023/2854; readers should consult the official text and their own counsel. TG is a tool that supports the migration process; compliance determinations rest with the customer.