Data Act: does your cloud provider declare the jurisdiction of its infrastructure?
7 min read
Open another tab and go to the website of the provider hosting your workloads. Look for a page declaring which jurisdiction the infrastructure processing your service’s data is subject to — not the company in general, that specific service. Then check your signed contract for the address of that page. If ten minutes turn up neither, you already have the answer to a question that Regulation (EU) 2023/2854 — the Data Act — has been asking for almost eleven months, not since tomorrow: the obligation has been in force since 12 September 2025, and almost nobody has checked it yet.
Two clauses, one website, one contract.
Article 28 of the Data Act, “Contractual transparency obligations on international access and transfer”, is short. Paragraph 1 requires providers of data processing services to publish on their website, and keep up to date, two pieces of information: “the jurisdiction to which the ICT infrastructure deployed for data processing of their individual services is subject”, and a general description of the measures adopted to prevent international governmental access to non-personal data held in the Union, or its transfer, where this would create a conflict with Union law or national law. Paragraph 2 adds the part almost no specification checks: those websites “shall be listed in contracts” for all data processing services offered. It isn’t enough for the page to exist somewhere: the contract has to point to it.
The date isn’t in 2027: it has already passed.
Article 50 sets the Regulation’s application date at 12 September 2025, with three named exceptions: Article 3(1) (on connected products, applying from 12 September 2026), Chapter III (obligations to make data available) and Chapter IV (unfair contractual terms, with a transitional regime running to 2027 for existing contracts). Article 28 sits in Chapter VI, “Switching between data processing services”: it isn’t among the exceptions, so the general rule applies, from 12 September 2025. It isn’t the only deadline this summer that looks like it lies ahead and doesn’t: the data centre sustainability reporting obligation also covers a calendar year already under way.
“Jurisdiction of the infrastructure” is not “where the server sits”.
It’s the distinction a specification has to be able to state. The Regulation doesn’t ask for the data centre’s address: it asks which law the ICT infrastructure processing the data is subject to. A facility in Italy run by a company subject to a third country’s law is a different configuration — under Article 28 — from a facility in Italy run by a company subject only to Union law: same geography, different jurisdiction. The definition of “data processing service”, in Article 2, point 8, is functional, not nominal: “a digital service that is provided to a customer and that enables ubiquitous and on-demand network access to a shared pool of configurable, scalable and elastic computing resources of a centralised, distributed or highly distributed nature”. It doesn’t say “public cloud”, and it covers distributed set-ups too: the declaration must be made for each individual service, not the company as a whole. Anyone buying connectivity, colocation or compute capacity should demand the same granularity in their specification.
The second half: leaving will cost less, and it has to be declared before you sign up.
Two articles further on, Article 29 gradually dismantles switching charges between providers: from 12 January 2027 they disappear; in the transitional period, from 11 January 2024 to that date, they can only be “reduced”, and must not exceed “the costs incurred by the provider … that are directly linked to the switching process concerned”. Before signing, paragraph 4 requires the provider to inform the customer about standard fees, early termination penalties and reduced switching charges. A customer paying today to extract their own data has, from this article, a tool to ask for that cost itemised.
Article 30(1) concerns precisely the infrastructure layer this site writes about: providers “that concern scalable and elastic computing resources limited to infrastructural elements such as servers, networks and the virtual resources necessary for operating the infrastructure”, which do not give access to applications or software, must take all reasonable measures for the customer to achieve “functional equivalence” after switching; the source provider “shall facilitate the switching process by providing capabilities, adequate information, documentation, technical support and, where appropriate, the necessary tools”. Documentation and tools for switching aren’t a commercial courtesy: they’re a written obligation.
The other side of it, which has to be said.
Article 28 asks for “a general description” of the measures against international governmental access, not an itemised list: a vague page can remain fully compliant. Transparency doesn’t solve the problem, it makes it checkable — which is already something, but not a guarantee.
And Article 32, two articles after Article 28, does not shield European data from every foreign authority. I checked paragraph 2: a decision of a third-country court or authority requiring the transfer of non-personal data is recognised or enforceable “only if based on an international agreement … in force” between the third country and the Union — a mutual legal assistance treaty, or a similar agreement with the Member State. Without such an agreement, paragraph 3 doesn’t automatically forbid the transfer: it allows it under three conditions — reasons and proportionality for the decision, with a specific link to suspected persons or particular infringements; a reasoned objection reviewable by a court in the third country; a court with the power, under its own law, to take into account the interests protected by Union law. It isn’t an outright ban: it’s a procedure with checkable conditions. Anyone who writes that the Data Act “puts European data out of reach of foreign authorities” is oversimplifying what the text says.
What to put in the specification.
- Jurisdiction declared service by service, with reference to Article 28(1)(a) — not a single blanket statement for the whole provider.
- The Article 28 web addresses referenced in the contract, as paragraph 2 requires, not just published on a page no clause points to.
- The Article 32 measures attached, not merely linked: the text of the technical and organisational measures, not a pointer to a page that can change without notice.
- Switching costs quantified in advance, as Article 29(4) requires, before signing — not discovered on the way out.
- Functional-equivalence obligations under Article 30 written as a clause, with an itemised list of what the source provider must hand over: capabilities, information, documentation, support, tools.
How to check.
The ten-minute check should happen today: open the provider’s website, find the Article 28 page, confirm it declares the jurisdiction for the specific service you use — not the company in the abstract — and check the last-updated date. Then the contract: is that page’s address referenced, as paragraph 2 requires? If not, that’s a non-conformity on the provider’s part, and a missing clause in your specification. On acceptance, the same logic applies to Article 32: the measures must appear, attached in full, in the contractual documentation — not merely mentioned on a sales call.
The point.
The Data Act doesn’t ask for an act of faith: it asks for an up-to-date page, a contract that references it, an attachment describing the measures — checkable in an afternoon, not a matter of opinion. It’s the work we bring to a compliance specification: jurisdiction declared service by service, Article 28 addresses referenced in writing, Article 32 measures attached, Article 29 switching costs quantified before signing — checkable clauses, with testing done on acceptance and the record to produce. The file of cloud, colocation and connectivity providers for a data centre, together with traces, measures and as-built records of the network that connects them, stops being scattered pages and becomes a single map of the site and the network: an AI flags the inconsistency — a declared jurisdiction that no longer matches the contract, a provider that has changed its page without notice — and a team steps in, together with CSIDIA, the group’s other company. Wherever AI is needed on network data, it runs within the client’s perimeter: on autonomous on-premise machines, with no deep integration into the existing network, or on dedicated cloud with a data centre in Italy, with shared management between the two teams.
Do you need to check whether your cloud, colocation and connectivity providers comply with Article 28, or write the clause that references it into your next specification? Talk to an engineer: the site visit is free, and the provider’s page can be checked today, not at the next contract renewal.