In brief
- Lock-in is a governance risk, not a technical footnote. It sets your price at renewal, your pace, and whether the business keeps running when the vendor drops out.
- The EU Data Act (Regulation (EU) 2023/2854) has required cloud providers since 12 September 2025 to remove switching barriers: a notice period of no more than two months, a switch completed within thirty days, and egress fees that are phased out.
- A law sets a floor, not a ceiling. Being able to switch is not the same as being the owner.
- Real ownership is the way it is built, not an exit clause: code in your own repository from day 1, standard open source, escrow, transferable to any integrator, and a go/no-go at each wave.
Your contract ends, you want to switch, and only then does the real price show. The data sits in a format that only the vendor reads easily. The export is charged per gigabyte. The notice period is longer than you thought. At that moment you are no longer paying for software, you are paying for the right to leave.
Lock-in is not an IT detail, it is a governance risk
Whoever signs for a core system also signs for the way out. That second part rarely appears in the quote, and yet it sets your position for the whole term. With systems that carry daily operations, this is not about months but about years. Dependence then costs you in places that never appear on the invoice.
Start with the price. A vendor who knows that switching costs months of work and a substantial budget has little reason to stay sharp at renewal. The increase arrives neatly at the renewal, precisely when going back is no longer a real alternative. You are then not negotiating the value of the product, but what the exit is allowed to cost. A weak position, and the other side knows it.
Then there is your pace. You follow the vendor's roadmap instead of your own market's, and an integration your operation needs quietly slips to a later quarter or off the list. It becomes sharpest around continuity. If the product is phased out, the vendor acquired, or the licensing model revised, that risk moves straight to your front desk, your warehouse, and your accounting. A board that files lock-in away as a technical choice has put it with the wrong department.
What the Data Act now requires
You are no longer on your own in this. The Data Act, Regulation (EU) 2023/2854, has been in force since 11 January 2024 and applies from 12 September 2025. It addresses switching between cloud services directly and pushes a measure of power back to the customer. In concrete terms, it requires the following:
- Providers must remove commercial, technical, and contractual obstacles to switching.
- Functional equivalence and interoperability must be supported, so that your processes keep running after the switch.
- The notice period is capped at two months.
- The actual switch must be able to complete within thirty days.
- Switching and egress fees are phased out gradually.
For whoever signs, that means the end of 'you are simply locked in' as a valid answer. And for the people who later have to carry out the migration it matters just as much: a readable export format and a working migration path are now contractually enforceable, not something you have to fight for after the fact. That is a real shift, and it falls in your favour.
Being able to switch is not the same as being the owner
The difference comes down to one simple question: where does the source code live? In the classic model you rent access to software that someone else owns, and at best a regulation arranges a clean departure. With real ownership, leaving is not a project in itself, because there is nothing to leave behind. You build from the outset on what is already yours.
With us it looks like this, and it explains why 'how do we get out of here again' is almost never a question among our clients:
- The code sits in your own repository from day 1, not in ours.
- The stack is standard open source: Kubernetes, PostgreSQL, ClickHouse, and Metabase, with no closed format for anyone to decipher later.
- An escrow arrangement gives you access to the source in every scenario.
- The platform is transferable to any integrator, including one that is not called YK.
- Each wave closes with a go/no-go, so stopping is possible without losing the whole.
Open source here is not ideology, but a practical guarantee. If your platform runs on PostgreSQL, then any developer who knows PostgreSQL reads your data, today and in ten years. No closed format to reverse-engineer, no export button to wait for. The interoperability that the Data Act frames as a right is simply the way it is built here.
What you are best off asking now
Before you sign a next contract, put two questions on the table. To the vendor: where do our code and our data sit, in what format do we take everything with us in full, and what does leaving cost on day one of the contract? To yourself: if this party disappears tomorrow, does the business keep running? The answer to that second question is your real risk profile.
The Data Act has opened the market's door, and that is a gain for everyone who once found it shut. The next step is not to wait until you are allowed to invoke the right, but to choose systems where that door was never locked in the first place. Ownership is not an exit clause at the back of the contract. It is the starting point at the front.
Want to apply this to your own situation?
Belgian, founder-led and built to hand over. One email is enough.
More reading
