The Lock-In Is Over: Dr. Naveen Singh on Why the EU Data Act Rewrites the Rules of Cloud Architecture
For twenty years, switching cloud or database
providers was the corporate equivalent of getting out of a bad lease early
technically possible, prohibitively expensive, and designed that way on
purpose. Brussels just changed the terms. We sat down with Dr. Naveen Singh,
founder of decentralized database company Inery, to unpack what the EU Data Act
actually demands.
“Switching
costs were a feature, not a bug at least for the vendor,” says Dr. Naveen
Singh, founder of Inery. “Proprietary storage formats, closed query engines,
non-standard APIs none of that was accidental. It was retention by design.” Put
plainly, he says, it’s the enterprise version of a familiar annoyance. “Think
of it like being stuck with a phone charger that only works with one brand. It
works fine, right up until the day you want to switch and suddenly the
accessory nobody thought twice about is the whole reason you can’t leave.”
That
era, Dr. Singh argues, is ending not because cloud providers had a change of
heart, but because regulators forced their hand. The EU Data Act, fully
applicable since September 12, 2025, has quietly become one of the most
consequential pieces of infrastructure regulation in recent memory. Its
switching and interoperability provisions Chapter VI, Articles
23–31 have moved lock-in out of procurement meetings and into
the architecture review.
What
the Act Demands
the Act Demands
“This
goes further than portability as a courtesy,” Dr. Singh says. “It makes
portability a baseline obligation, with teeth.” Providers must strip out the contractual,
technical, and financial barriers to switching, with structured exit support
required.
|
KEY DEADLINES September 12, 2025 Data Act fully applicable; notice periods Through 2026Interoperability requirements phase in January 12, 2027 Switching charges banned outright September 2027 Even pre-existing contracts must comply Source: Regulation (EU) 2023/2854, Official |
Several
member states have floated fines reaching 3–4% of global turnover for
non-compliance. “Portability isn’t goodwill anymore,” Dr. Singh says. “It’s a
floor, not a ceiling.”
The Second-Order Effect
The Second-Order Effect
“The
Act removes the economic rationale for architecting around a single vendor,” Dr.
Singhsays. “The businesses in the strongest position aren’t bolting on export
interfaces to hit a deadline they’re the ones whose infrastructure was
interoperable from day one.”
He
reaches for an Indian comparison. “Before mobile number
portability, switching operators in India meant losing
your number and telling everyone you’d changed it so people didn’t switch, even
when unhappy. The day porting arrived, that friction disappeared. That’s
exactly what’s happening to enterprise data. The data was always the ‘number.’
Once it moves with you by default, vendors compete on service, not on exit
cost.”
Where
Decentralized Infrastructure Fits
Decentralized Infrastructure Fits
This
is the terrain Dr. Singh built Inery around. “There’s no lock to pick if there
was never a single point of custody to begin with.” He’s careful not to
overstate it: “The Data Act doesn’t ban centralized providers the hyperscalers
will adapt. What it removes is the structural advantage that made lock-in
profitable. It’s no longer about who makes leaving hardest. It’s about whose
infrastructure was never designed to trap you.”
Where
India’s DPDP Act Stands
India’s DPDP Act Stands
India’s
DPDP Act, passed in
2023, finally had its rules notified in
November 2025, phasing in to full compliance by May 2027.
But Dr. Singh cautions against reading it as India’s Data Act equivalent. “GDPR
was about consent. The Data Act is about switching a layer above that. The DPDP
Act is still solving GDPR’s problem, not handing anyone a right to take their
data elsewhere.” His bet: “India ends up in a similar place eventually.
Organizations building for DPDP compliance now would be smart to build the
switching piece in early, rather than doing it twice.”
What
Leaders Should Do Now
Leaders Should Do Now
Audit
before January 2027. Switching charges are banned outright from
January 12, 2027. “Know today which contracts would survive a
functional-equivalence test don’t find out during the audit.”
Treat
portability as architecture, not a clause. Retrofitting export
APIs later is expensive and brittle; open formats meet the Act’s bar by
default.
Watch
the EU as a bellwether. “GDPR’s fingerprints are already in the DPDP
Act. Infrastructure built for Data Act-style portability today won’t need
rebuilding when equivalent rules land elsewhere.”
Dr.
Singh doesn’t call the Data Act radical. “Nobody needed convincing lock-in was
bad for customers. What changed is it’s now enforceable, on a timeline, with
real penalties. It’s a redirection of the whole incentive structure toward
infrastructure that’s open by default which is where it probably should have
started.”
Dr. Naveen Singh is the
founder of Inery, a decentralized database company focused on data sovereignty
and interoperable infrastructure.