France – Tech Law Insights #1: France’s Data Act regime takes shape
France is moving to bring national legislation in line with the EU Data Act, which became applicable from 12 September 2025 (with certain exceptions where individual provisions or chapters have a deviating application date). A cornerstone of this legislative effort in France is the draft DDADUE bill adapting national law to EU regulations (Draft DDADUE bill).
The Draft DDADUE bill was passed in the French Senate on 18 February 2026 and is currently being reviewed by the French National Assembly.
A key feature of the Draft DDADUE bill is the proposal to appoint Arcep, the French independent administrative body responsible for regulating electronic communications, postal services and press distribution, as the authority responsible for enforcing the Data Act, as Article 37 of the Data Act requires each Member State to do. The proposal also amends a number of existing national laws, including Law No. 2024-449 of 21 May 2024 (SREN law), which had already anticipated several aspects of the Data Act’s framework before it became applicable with respect to cloud computing services.
This blog post, part of our France - Tech Law Insights series, takes a closer look at the currently applicable framework in France, the key proposed changes included in the Draft DDADUE bill as well as Arcep’s own contribution to this framework, in particular its 2 July 2026 guidelines on switching fees other than data transfer fees, and data transfer fees charged where a customer simultaneously uses several cloud service providers.
Applicable framework: The Data Act, the SREN law and the Arcep’s guidelines and recommendations
Since 12 September 2025, the main provisions of the Data Act have been directly applicable in France and have coexisted with France’s own SREN law. Article 27 of the SREN law anticipated the Data Act’s switching-fee regime – capping data transfer fees on a change of provider (II) and other switching fees (III) at the provider’s directly related costs, as Article 29 of the Data Act does, and capping data transfer fees where a client uses several providers simultaneously (IV), as Article 34 does – while Articles 28 and 29 of the SREN law anticipated the Data Act’s interoperability and portability regime.
Arcep has begun to implement this framework through soft law. In September 2025, Arcep published recommendations on interoperability and portability in the cloud sector, grounded on Articles 28(II) and 29(I) of the SREN law, which task Arcep with implementing the interoperability, portability and API-related transparency obligations of the Data Act (in particular Articles 25, 26, 28 and 30). On 2 July 2026, it published two sets of guidelines: one on the costs relevant to data transfer fees where a customer uses several cloud providers simultaneously (multi-cloud), giving effect to Article 34 of the Data Act, and another on switching fees other than data transfer fees, giving effect to Article 29 of the Data Act.
What could change with the Draft DDADUE bill?
The Draft DDADUE bill essentially removes redundancies with the Data Act, notably by repealing the pricing, transparency, interoperability and portability obligations that the SREN law had introduced for data processing services. These repeals concern, in particular:
The caps on data transfer and switching charges (Article 27, II and III of the SREN law) – which the SREN law had set at the provider’s directly related costs. This repeal should be deferred to 12 January 2027, so as to align with the end of the Data Act’s own transition period. The SREN caps remain necessary only until switching charges, including data transfer charges, are fully prohibited under the Data Act on that same date.
It should be noted that the French minister for Digital Affairs, attached to the minister for the Economy, has set a maximum charge for data transfer fees incurred when changing provider: the Order (arrêté) of 17 November 2025 sets that maximum charge at €0 with effect until 12 January 2027 (aligning with the total ban of the Data Act starting as of this date). Whereas the Data Act permits reduced, cost-based switching charges during the transition period.
France has thus opted for an immediate and total ban on “data transfer” fees charged in connection with a change of provider. In doing so, the government followed Arcep’s position that the incremental cost of such a transfer “may be considered to be nil.” Arcep’s reasoning is therefore evidential rather than normative: the cap is presented not as a price ceiling set below cost, but as a finding that, for a standard transfer (non-recurring, involving a defined volume of data, and not requiring the deployment of additional equipment), there is no cost to recover. Other “switching” fees associated with changing supplier however remain subject to the general cost-based cap mentioned above as well as to Arcep’s guidelines on costs used to determine switching fees for cloud computing services (see below).
Indeed, as a structural difference, the SREN law separates the regime applicable to “data transfer fees” from that of other “switching fees” (other costs associated with changing supplier). On the contrary, in the Data Act, “data transfer fees” and “switching fees” are governed as a single regime: data transfer fees are expressly treated as a component of switching fees, both of which are subject to the same gradual phase-out and total prohibition on 12 January 2027 (Articles 2(36) and 29). The only situation in which data transfer fees are dealt with separately is where a customer uses several services simultaneously (also named “data egress charges”).
- The cap on data transfer fees where a client uses several providers simultaneously (Article 27, IV of the SREN law), which mirrors the equivalent cost-based cap that Article 34 of the Data Act imposes in the same scenario. Unlike the repeal of Article 27, II, this repeal should take effect immediately upon the DDADUE bill’s entry into force, since Article 34 – unlike Article 29 – does not phase down to a total prohibition.
- The pre-contractual transparency obligations on switching fees (Article 27, VII), and the interoperability and portability requirements for cloud providers (Articles 28 and 29), which mirror Articles 25 and 30 of the Data Act respectively (and, more broadly for interoperability, Article 35).
Similarly, references to “cloud computing services” in the SREN law and other applicable legislation (e.g. the French Commercial Code, the Postal and Electronic Communications Code and the Intellectual Property Code) should be replaced by “data processing services”, in line with the Data Act’s terminology.
Arcep’s 2 July 2026 guidelines
Arcep has the power to adopt guidelines, following a public consultation, on the costs that may be taken into account in determining (i) switching fees other than data transfer fees, and (ii) data transfer fees charged where a customer simultaneously uses several cloud service providers, pursuant to Article 27 of the SREN law. Both sets of guidelines were the subject of a single public consultation held from 16 February to 27 March 2026, and were published on 2 July 2026.
Guidelines on switching fees other than data transfer fees
These guidelines operationalize Article 29 of the Data Act, under which switching fees may only reflect the costs directly incurred by the provider in the switching process, without exceeding them, and must be abolished entirely from 12 January 2027. They give providers and customers predictability as to which cost items may still be recovered during the transitional period.
In particular, the guidelines draw a line between core switching-facilitation services – which fall within the price cap and must disappear entirely from 12 January 2027 – and supplementary migration-support services (such as IT audits, tailored migration advice, bespoke reversibility plans, migration project management, code adaptation or staff training to new tools/the new environment), which fall outside the regulated switching fee and may continue to be freely priced.
For the core services, the guidelines set out an incremental-cost methodology – only the share of costs directly attributable to the switching process may be recovered until 12 January 2027 – and provide a cost-by-cost grid across the two following types of assistance that should a priori be covered:
- Reasonable assistance during the switching process (Article 25 of the Data Act), but only for the costs directly attributable to the customer’s own switching process. This covers for instance the technical experts and staff made available to the customer. However, development costs for communication channels, or for documentation covering the cloud service more broadly, that were already incurred for the ordinary operation of the service cannot be recovered.
- Tools and resources provided for the switching process (Article 30 of the Data Act), but only for the share attributable to the switching itself. This covers development, adaptation or acquisition costs for switching tools, to the extent such tools are necessary to comply with its obligations under the Data Act. However, costs of adapting a tool to features specific to the destination environment are excluded. Temporary storage of a copy of the data during the switching process may also be chargeable, including the underlying computing resources and their operating costs (e.g. energy).
On the contrary, the Arcep excludes security costs: since the origin provider must in principle maintain, throughout the switching process, the same level of security it already committed to for the ordinary service, Arcep does not identify any additional cost specifically caused by maintaining that commitment during switching that could be charged on top of the fees already paid for the service.
Arcep also recalls that any switching fee charged on this basis, as well as the price of any supplementary migration-support service, must in any event be specified in the contract, in accordance with Article 25(2)(i) and Recital 89 of the Data Act.
Guidelines on data transfer fees in multi-cloud scenarios
These guidelines operationalize Article 34 of the Data Act, under which data transfer fees charged in a multi-cloud scenario may only reflect the actual “exit costs” incurred by the provider, without exceeding them. They give providers and customers much-needed predictability as to what qualifies as a legitimate “exit cost” in a multi-cloud environment.
The guidelines set out an incremental-cost methodology – only costs genuinely caused by the multi-cloud data transfer may be recovered - and provide a cost-by-cost grid:
- Data transport infrastructure costs are, in principle, not attributable. These include, for example, “dark fibre,” or leased broadband capacity on a third party’s network. Arcep considers that network transport infrastructure is inherent to a cloud provider’s overall activity and serves a wide range of services, of which multi-cloud transfer is only one among many. Moreover, multi-cloud transfers do not, in principle, generate congestion or volume/peak-load issues that would require the provider to expand its network capacity.
- Interconnection costs may be admissible. These cover, for instance, the purchase, hosting, maintenance and supervision of routers dedicated to a specific direct interconnection link, any optical card upgrade needed for a port, and the link between the two ports – as well as paid peering fees. Because these costs can genuinely be caused by facilitating a specific multi-cloud transfer, Arcep considers them potentially chargeable, but only for their strictly incremental, objectifiable share that is specifically attributable to that transfer. Costs of interconnection over the public internet are, by contrast, generally not attributable, save for the incremental share of any capacity upgrade driven by multi-cloud transfers.
- Central-function costs are excluded. Several contributions to the public consultation flagged cost items tied to central functions – marketing, sales, customer support, accounting and similar labor costs – as potentially relevant. Arcep found these to be inherent overheads of operating a cloud business generally, and its review did not identify any incremental cost among them that is specifically induced by multi-cloud data transfers.
The residual French specificity is therefore not a broader scope, but the retention of a national soft-law instrument layered on top of a directly applicable EU regulation.
Competence of Arcep and powers
Building on its existing role under the SREN law - where it already supervises cloud services and data intermediation providers under national law - Arcep should now be designated as the competent authority responsible for the application and enforcement of the Data Act itself in France, except for unlawful international governmental access and transfers of non-personal data (Chapter VII).
Indeed, as a directly applicable EU regulation, the Data Act requires a designated national authority endowed with enforcement powers. The Draft DDADUE bill accordingly equips Arcep with investigation powers, a dedicated sanctioning power, exercised by its restricted committee (formation restreinte) under Article L. 36-11 of the French Postal and Electronic Communications Code and by reference to the criteria in Article 40(3) of the Data Act (fines of up to 3% of worldwide turnover, or 5% for repeat breaches, or up to €150,000 – and €375,000 for repeat offenses – when turnover cannot be determined), complaint-handling and dispute-resolution functions, responsibility for certifying dispute-resolution bodies under Article 10 of the Data Act, and cooperation with other EU authorities.
Arcep’s remit is nonetheless subject to two key limitations. First, the CNIL remains the competent authority for all matters involving the processing of personal data. The CNIL has already confirmed that it will cooperate closely with Arcep on the joint enforcement of the Data Act and the GDPR. Second, sectoral regulators continue to exercise exclusive authority over specific categories of data, such as digital health authorities.
Next steps
The Draft DDADUE bill is not yet final: having passed the Senate on 18 February 2026, it must still clear the French National Assembly before adoption, and its content may still change, not least because the Data Act is part of an omnibus text spanning a wide range of unrelated EU instruments. Several changes should only take effect on 12 January 2027, in order to align with the Data Act’s own timeline. The bill’s progress through the National Assembly should therefore continue to be closely monitored in the coming months.
One point to watch in particular is the identity of the authority that will oversee Chapter VII of the Data Act (cross-border access to, and transfer of, non-personal data by public authorities), which the draft bill carves out of Arcep’s competence without naming a substitute. If a second authority is ultimately designated, France will also have to appoint a data coordinator under Article 37(2) of the Data Act.
Until now, the French regime has in fact been stricter than the Data Act – in particular the zero-euro cap on transfer fees charged when switching providers, already imposed by the 17 November 2025 Order ahead of the Data Act’s own transitional timetable – but it should soon converge with the EU regime once the corresponding SREN provisions are repealed on 12 January 2027. In the meantime, and even after that date, businesses operating in France should keep a close watch on Arcep’s guidelines: although not legally binding, they will be the reference Arcep relies on when exercising its investigation and sanction powers under the Data Act.
