The Data Act
The EU Data Act1 on harmonised rules on fair access to and use of data came into effect on 12 September 2025.
The Data Act has been implemented in Malta through Legal Notice 222 of 2025 on the Fair Access to and Use of Data Regulations, which was published and brought into force on 10 October 20252.
The Malta Communications Authority (MCA) is designated as the responsible authority for the application and enforcement of Articles 23 to 31 (Switching Between Data Processing Services) and Articles 34 to 35 (Interoperability of data processing services) of the Data Act.
‘Data Processing Service’ is a digital service that is provided to a customer and that enables ubiquitous and on-demand network access to a shared pool of configurable, scalable and elastic computing resources of a centralised, distributed or highly distributed nature that can be rapidly provisioned and released with minimal management effort or service provider interaction. Data processing services are primarily cloud services3.
‘Switching’ means the process involving a source provider of data processing services, a customer of a data processing service and, where relevant, a destination provider of data processing services, whereby the customer of a data processing service changes from using one data processing service to using another data processing service of the same service type, or other service, offered by a different provider of data processing services, or to an on-premises information and communication technology (‘ICT’) infrastructure, including through extracting, transforming and uploading the data.
‘Customer’ means a natural or legal person that has entered into a contractual relationship with a provider of data processing services with the objective of using one or more data processing services.
‘Interoperability’ means the ability of two or more data spaces or communication networks, systems, connected products, applications, data processing services or components to exchange and use data to perform their functions.
Switch to another cloud service
If a user of cloud services wants to switch to another provider, providers of data processing services must arrange this easily and without problems. They must also ensure that users can take their data with them when switching.
The Data Act includes measures to ensure that customers can switch from one provider of data processing services (‘source provider’) to another (‘destination’) provider quickly and smoothly, and without losing any data or the functionality of applications.
For example, providers of Platform and Software as a Service must make open interfaces available and, at a minimum, export data in a commonly used and machine-readable format. Providers of Infrastructure as a Service must take measures to facilitate that, where a customer switches to a service of the same type, the customer gets materially comparable outcomes in response to the same input for features that both services share (‘functional equivalence’).
As of 12 January 2027, providers may no longer charge fees for a switch. Until that time, they are still permitted to do so, but only if the costs are directly related to the switching process itself.
Providers are obliged to provide technical support to users during a switch. Furthermore, providers must ensure that the switch and the transfer of data take place securely.
Using different cloud services simultaneously
Users must be able to use cloud services from different providers simultaneously and without problems. They must also be able to allow those different services to exchange data with each other. Providers are required to cooperate in relation to the provision of such services.
Accessible information and clear contract terms
Providers must ensure that users are informed in a clear and accessible manner of all relevant information on available procedures for switching and porting to the data processing service. This information must also be clearly stated in the contract terms, as well as information regarding the maximum notice period and the duration of a transition period in the event of a switch.
It must be clear to users under which jurisdiction the cloud service falls and where the provider's servers are located. If this is in a country outside the European Union, different standards regarding digital security and privacy may apply.
The European Commission (EC) has drawn up sample contracts. These can help providers and users of cloud services draft clear and fair contract terms. Although they were mainly drafted for business-to-business contracts, they can also be used in relations between businesses and consumers, if relevant consumer protection rules are added.
To support the implementation of the Data Act, the EC has also published Frequently Asked Questions (FAQs) offering practical guidance on its application. In addition, the EC’s Data Act Legal Helpdesk helps organisations navigate compliance requirements, make informed decisions, and maximise the opportunities created by the Data Act.
Complaints and Supervision
Persons who have their habitual residence, place of work or establishment in Malta have the right to submit a complaint directly with the MCA individually or, where relevant collectively, if their rights under Articles 23 to 31 and Article 34 and 35 of the Data Act have been infringed.
Customers and providers of data processing services shall also have access to a dispute settlement body, certified in accordance with Article 5 of the Data Act4, to settle disputes relating to breaches of the rights of customers and the obligations of providers of such services.
The right to lodge a complaint with the MCA is without prejudice to the right of an aggrieved person to seek a remedy by filing an action before the courts.
The parties in a dispute are not denied their right to seek a remedy by filing an action before the courts, even when they submit a dispute to a dispute settlement body.
Part VI of the Malta Communications Authority Act, Cap. 418 of the Laws of Malta shall apply in relation to any infringement of Articles 23 to 31 and Articles 34 to 35. Before initiating formal proceedings in relation to an infringement, the MCA may consult with the Malta Digital Innovation Authority (MDIA) or other relevant public bodies where appropriate.
Resources and Further Reading
Disclaimer
The information provided above serves only as general guidance and does not in any way constitute legal advice. If you are seeking legal advice about the interpretation of the law and your rights thereunder, you should consider consulting your lawyer.
1The Data Act is the short title of Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data and amending Regulation (EU) 2017/2394 and Directive (EU) 2020/1828 (Data Act).
2See also Subsidiary Legislation titled Fair Access to and Use of Data Regulations 418.06 and 591.04.
3See Recital 81 of the Data Act which lists Infrastructure as a Service (IaaS), Platform as a Service PaaS), Software as a Service (SaaS) as data processing service delivery models.
4The MDIA certifies dispute settlement bodies established in Malta, at the request of such a body, where the conditions prescribed under Regulation 3 of LN 222 of 2025 have been duly satisfied.