Most of the obligations landing in 2027 will be judged on records the company never planned to keep. Procurement picked the cloud provider. Engineering shipped a connected product. A dataset stayed because deleting it felt like the riskier call, and nobody wrote down why.
That is what turns EU data compliance into an operating issue, not only a legal one. The duties arriving next year cross procurement, IT, security, engineering, product and the board. Legal is the function asked to describe them coherently when someone else sets the deadline.
1. Cloud exit and data portability become a legal test
In short, an exit clause is about to be measured against what can actually be exported. The Data Act has applied since September 12, 2025, and the Commission’s framing is blunt: technical, commercial and contractual barriers to switching have to go. Most teams can find the clause. Fewer can say what format the data leaves in, or who holds the dependencies underneath it.
The EU Data Act’s switching rules
From January 12, 2027, Article 29 of Regulation (EU) 2023/2854 bars providers of data-processing services from charging customers for switching, including data-egress charges. From September 12, 2027, the unfair-term provisions can reach certain pre-existing contracts of indefinite or very long duration, subject to narrow conditions in Article 50. Teams are expected to review the agreements concerned, which means targeting specific contracts rather than reopening everything signed before 2025.
Expert advice
Separate genuine data-processing services from ordinary SaaS in your contract inventory, because the switching duties only bite on the former. Then test one relationship the way a migration would: request an export and record the format, the dependencies and the fee.
2. Product security becomes part of the legal record
Legal’s role now reaches into product. The requirements are not entirely new, but some of them change in 2027. If the company manufactures, imports or distributes products with digital elements on the EU market, security stops being an engineering question and becomes a documentation question. Classification, conformity records, support periods, vulnerability decisions and customer notifications all have to be traceable, and they have to travel with the product through the value chain There are sectoral exclusions, of course.
New in the Cyber Resilience Act
Regulation (EU) 2024/2847 will apply in full from December 11, 2027, but parts of it are already live. Conformity-assessment body provisions applied from June 11, 2026, and manufacturer reporting duties from September 11, 2026: early warning on an actively exploited vulnerability or severe incident within 24 hours, full notification within 72 hours. In this context, a 24-hour clock is not something legal can improvise.
Expert advice
Decide now who classifies a product, who declares an incident reportable and who signs the notification. Then push vulnerability disclosure, support-period and component obligations into supplier contracts, because the duty follows your role in the chain.
3. AI compliance arrives on several clocks
The EU AI Act does not create a single compliance deadline. Some obligations already apply, while others will come into force over the next two years. Prohibited practices and AI literacy requirements have applied since February 2, 2025, and governance and enforcement powers have applied since August 2, 2026. High-risk obligations under Annex III begin on December 2, 2027, while certain Annex I systems have until August 2, 2028.
For legal teams, the challenge is keeping track of which obligations apply to which systems, who owns each requirement and what evidence needs to be available at each stage. A static AI inventory will quickly become outdated.
Example: the EU AI Act timeline
The European Commission’s AI Act guidance and Regulation (EU) 2024/1689 set out the relevant dates. Internal plans should also reflect the AI-focused Digital Omnibus, which has been adopted and moved some high-risk deadlines.
That instrument should not be confused with the separate Digital Omnibus proposal that would amend the GDPR. That proposal remains under negotiation, so it should not yet be treated as settled law when planning for 2027.
Expert advice
Keep the AI inventory dated and update it as systems, use cases and legal requirements change. Separate obligations that already apply from those arriving in December 2027, since they may involve different teams and evidence requirements. Legal should also agree in advance what technical documentation and activity logs need to be retained, rather than deciding after a regulator or business stakeholder asks for them.
4. Purpose limitation and minimization must be defensible at record level
A regulation does not need to change for the expectations around compliance to become more demanding. Article 5 of the GDPR remains in place, but companies using existing data for new AI and analytics projects face new risks.
That creates a basic legal question: what were people told when the data was collected, and does that original purpose support the new use? A privacy policy updated in 2027 cannot explain what the company intended, or what individuals were told, when the data was collected in 2021.
GDPR Article 5 and the proposed GDPR Omnibus
Regulation (EU) 2016/679 requires organizations to respect purpose limitation and data minimization. It also requires a Data Protection Impact Assessment, or DPIA, where processing is likely to create a high risk to individuals.
The Commission has proposed changes to the GDPR through the Digital Omnibus package. Some of those changes could reduce certain documentation requirements, but the proposal remains under negotiation. Planning on the assumption that those amendments will be adopted would leave a significant gap if the final text changes.
Expert advice
Before approving a new AI or analytics use case, review the notice that applied when the data was collected. Record the original purpose, explain why the amount of data remains proportionate and complete a DPIA where the legal threshold is met. The same review should identify how long the data needs to be kept and what event will trigger its deletion.
5. Legal teams have to govern the AI they use
AI governance is becoming familiar territory for legal teams and expectations on their role are changing quickly. The department advising the business on AI is also using AI in contract review, legal research, knowledge management and other internal workflows.
That creates a second responsibility. Legal must know whether the business is using AI appropriately, and whether the tools inside the department can produce records that explain how their outputs were created and reviewed. Board members and regulators may scrutinize enterprise AI while paying less attention to the systems legal uses every day.
Example: the EU AI Act’s evidence standard
The EU AI Act establishes requirements for covered high-risk systems, including logging, technical documentation, human oversight and post-market monitoring. Most contract-review and drafting tools will not fall directly into those high-risk categories.
The standard still provides a useful benchmark. If a regulator, customer or internal reviewer asks how a conclusion was reached, the answer should not depend entirely on which category the tool falls into. Legal technology often logs that a tool was used more clearly than it logs how a specific conclusion was reached.
Expert advice
Begin by identifying the AI tools already used within the legal department. Each vendor, including DiliTrust, should be able to answer four questions: Is customer data used to train the model? Where does processing take place? What activity is logged for each event? How long are those records retained?
Those answers should inform the department’s internal controls. Any clause generated by AI should enter the evidence record only after a person has reviewed and confirmed it.
Stay compliant, work with the right tools
All five pressures end in the same request: produce the contract, the entity behind it, the supplier dependency, the product decision, the data use and the owner. In most legal departments, those records sit in different systems, so a two-question inquiry becomes a two-week project.
Running those records as one connected legal operating system does not remove any of these obligations. What it supports is coordination across the functions involved and faster retrieval of the evidence, which is usually what the deadline is really testing.
Frequently asked questions about data compliance in 2027
What changes for data compliance in 2027?
Four EU instruments reach new milestones in 2027: the Data Act’s ban on switching charges from January 12, the Cyber Resilience Act’s full application on December 11, the AI Act’s high-risk obligations for Annex III systems on December 2, and the Data Act’s unfair-term provisions reaching certain pre-existing contracts from September 12.
Can cloud providers still charge for switching after January 2027?
No. From January 12, 2027, Article 29 of Regulation (EU) 2023/2854 bars providers of data-processing services from charging customers for switching, including data-egress charges. The duty applies to data-processing services specifically, so ordinary SaaS agreements need to be separated from in-scope services in the contract inventory first.
Does the EU Data Act apply to contracts signed before 2025?
In some cases, yes. From September 12, 2027, the unfair-term provisions can reach certain pre-existing contracts of indefinite or very long duration, subject to narrow conditions in Article 50. This means reviewing the specific agreements concerned rather than reopening everything signed before 2025.
When does the Cyber Resilience Act apply in full?
Regulation (EU) 2024/2847 applies in full from December 11, 2027, but parts are already live. Conformity-assessment body provisions applied from June 11, 2026, and manufacturer reporting duties from September 11, 2026: early warning on an actively exploited vulnerability or severe incident within 24 hours, full notification within 72 hours.
Have the EU AI Act high-risk deadlines been delayed?
Yes. High-risk obligations under Annex III now begin on December 2, 2027, and certain Annex I systems have until August 2, 2028. Other obligations already apply: prohibited practices and AI literacy since February 2, 2025, and governance and enforcement powers since August 2, 2026.
Can a company use existing customer data for a new AI project under the GDPR?
Only if the original purpose supports the new use. Article 5 of Regulation (EU) 2016/679 requires purpose limitation and data minimization, so the test is what individuals were told when the data was collected, not what a privacy policy says today. A DPIA is required where processing is likely to create a high risk to individuals.



