EU law gave customers a new right to switch providers.
Running the migration securely — with evidence you can stand behind — is still on you.
Transfer General is software you run in your own cloud accounts to move data between clouds, encrypted with keys only you hold, and to produce a signed record of exactly what moved.
What the law requires of providers.
The EU Data Act has been operative since September 2025. Here is what it puts on providers — and what it deliberately leaves to you.
- Right to
switchProviders must remove the obstacles to switching to another provider of the same service type, or to your own on-premises infrastructure. The switch may be performed by you or by “third parties authorised by the customer.” - Security
in flightThe law requires “a high level of security throughout the switching process” — an obligation on the provider, governing the migration while it is in flight. It is not an obligation on you to secure or prove the data afterward. - Article 29
switch egressSwitching charges, including switching-related egress, are capped at direct cost now and prohibited from 12 January 2027. - Article 34(2)
in parallelRunning clouds in parallel is a separate case: providers may still charge egress, but only at cost. This one does not go to zero in 2027.
How the providers complied — with the bill, not the work.
Each major provider now has a program. They split along the exact line the law draws: leaving versus running in parallel.
All three waive it — each via its own eligibility-reviewed process.
AWS
Support credit for customers leaving AWS.
Google Cloud
No switching charges under its EU Data Act terms.
Microsoft Azure
Free data-transfer-out when leaving Azure.
When you keep running on both, it stays chargeable at cost.
Google Cloud
“Data Transfer Essentials” waives qualifying same-company in-parallel egress.
Microsoft Azure
At-cost credit for qualifying European in-parallel transfers.
Each program lowers the cost of getting your data out. None lands it intact in a cloud you control, keeps it encrypted with your own keys end to end, or gives you proof it arrived unchanged.
The fee is gone. The work isn’t.
The actual work of moving regulated data — and proving you did — still sits with you. It comes in two shapes, and the law treats them differently.
Egress fees end — when you switch
A definitive move to another provider or on-prem. Switching egress becomes free in 2027 (Art 29).
You still have to execute the move and prove it happened cleanly.
Egress fees remain — when you run in parallel
Two providers together, continuously. Egress stays chargeable at cost (Art 34(2)) — no end date.
You still have to move the data securely, repeatedly, and prove each transfer.
A free exit settles the bill. It doesn’t do the three things a regulated migration actually requires:
Land it where you control it
The data has to arrive intact in the destination cloud and account you control — not merely leave the old one.
Keep it encrypted with your keys
It stays encrypted with keys only you hold for the whole journey, decrypted only at the destination you control.
Hand you the evidence
Proof each object arrived unchanged — what your auditors and risk teams will ask for.
Your accounts. Your keys. Your proof.
Transfer General fits exactly here — not as a provider you hand your data to, but as software you run to close the gap the law leaves open.
Keeps traffic on sovereign routes — a different, complementary control.
The data is encrypted with keys only you hold. The strongest control you can carry into a switch is the one nobody else holds for you.
You run it, you hold the keys, you keep the proof.
So when your auditor asks you to prove the switch moved data intact — this is what you hand them.
Not a log entry. One object’s signed attestation record, produced automatically at transfer completion — every value independently verifiable against the cloud provider’s KMS, without contacting Server General.
Every transfer leaves a trail your auditors can open and verify.
These are real artifacts from the product, not illustrations.
The signed record
The per-object attestation an auditor receives — source and destination hashes, the match result, and the cryptographic signature.
View a sample recordThe chain of custody
The raw, time-ordered event log behind any object — the evidence trail that stands behind the signed record.
Open the audit evidenceOperational visibility
Every object across every pipeline in one view, with exceptions surfaced the moment they occur.
See the consoleWe won’t tell you a tool makes you compliant.
Here’s the accurate relationship between the law and what TG does.
The right is already in force; the economics tilt further in 2027. The work of moving data well doesn’t change on any of those dates — which is why it’s worth solving once. The compliance determination is always yours.
See what “evidence you can stand behind” actually looks like.
Every engagement starts with a proof-of-concept in your own environment. Deploy TG in your accounts, run real cross-cloud transfers, and verify the signed evidence yourself.
Informational only, not legal advice. References are to Regulation (EU) 2023/2854; readers should consult the official text and their own counsel. TG is a tool that supports the migration process; compliance determinations rest with the customer.