GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

DAT-027 Switching Interfaces and Functional Equivalence Support

Tier 2+ProviderManaged Service Providerdeployment model

Description

The interfaces a customer or a service it is moving to uses to retrieve its data and digital assets are documented, are reachable by every customer on the same terms whatever its plan, carry no charge of their own and carry enough information for a third party to build against them without the organisation's involvement. A route exists by which a customer authorises a third party to call them on its behalf. Alongside them the organisation publishes what a customer needs to stand an equivalent service up elsewhere: the configuration, the documentation of the service's behaviour beyond the data model, the technical support supplied and, where tooling is supplied, what that tooling does. The same interfaces serve a customer running the service alongside another rather than leaving. Where a published interoperability specification applies to the service, the documented formats state which specification each conforms to and the date compatibility was reached.

Rationale

An export API behind an enterprise plan, a support ticket or a partner agreement is the obstacle this control exists to catch, and APP-011 does not catch it: an interface can be inventoried, authenticated and rate-limited to the standard APP-011 requires while being unreachable by the customers who need it. The functional equivalence limb is the harder half and the one the library had nothing like. A complete export that cannot be turned back into a working service is a file rather than a migration, and what closes that gap is configuration, documentation and support rather than more data. The rate-limit distinction matters when testing: a limit applied equally to every plan is not a gate, while a limit that differs by plan is. Boundaries. DAT-023 holds whether an export exists, what it contains, whether it is complete against its documented scope and the register that documentation takes; this control adds who may reach it, on what terms and with what information, and adds the interoperability conformance statement and its date to the formats DAT-023 documents rather than standing up a second register. APP-011 holds the security of the interface: authentication, authorisation, rate limiting and input validation. INF-015 holds tenant isolation, which constrains what an interface may return. VND-013 holds the contractual commitment to the interface and the charge basis. DAT-026 holds the switch that uses it.

Applicability (9 profiles)

SaaS AI Providerstablerequireddeployment duty

Retrieval interfaces and the information needed to stand the service up elsewhere are commitments of a hosted service to its tenants, on the same footing as the export capability in DAT-023.

Enterprise AI Deployerstablenot-applicableout of scope

The deployer calls the retrieval interfaces rather than publishing them. Whether the provider's interfaces reach it on equal terms is a question it asks under VND-001 and VND-004.

GPAI Model Providerstableconditionaldeployment duty

Condition: deployment_model in cloud-saas, cloud-single-tenant

Retrieval interfaces and the information needed to stand the service up elsewhere are commitments of a hosted service to its tenants, on the same footing as the export capability in DAT-023. Conditional since 1.1: the profile lists every deployment model and this row is a commitment of a hosted service, so a provider that publishes weights or runs on infrastructure the customer controls has no hosted service to carry it (ADR-046 amendment, 2026-09-16).

High-Risk Provider (EU)stablerequireddeployment duty

Retrieval interfaces and the information needed to stand the service up elsewhere are commitments of a hosted service to its tenants, on the same footing as the export capability in DAT-023.

Public Body Deployer (EU)stablenot-applicableout of scope

The deployer calls the retrieval interfaces rather than publishing them. Whether the provider's interfaces reach it on equal terms is a question it asks under VND-001 and VND-004.

Data Act Cloud Provider (EU)stablerequiredrole duty

Art. 30(2) makes the open interfaces free of charge and available to an equal extent to every customer and to the destination provider, which rules out an export API behind an enterprise tier, a support ticket or a partner agreement. Art. 30(3) adds a dormant duty with a 12-month fuse: compatibility with a common specification or harmonised standard is owed 12 months after its reference lands in the central Union standards repository, so watching the repository is the compliance action while the list is empty. Art. 34(1) applies the same interfaces to parallel use.

DORA ICT Provider (EU)stablerequireddeployment duty

Retrieval interfaces and the information needed to stand the service up elsewhere are commitments of a hosted service to its tenants, on the same footing as the export capability in DAT-023.

HIPAA Business Associate (US)stablerequireddeployment duty

Retrieval interfaces and the information needed to stand the service up elsewhere are commitments of a hosted service to its tenants, on the same footing as the export capability in DAT-023.

NIS2 Cloud Provider (EU)stablerequireddeployment duty

Retrieval interfaces and the information needed to stand the service up elsewhere are commitments of a hosted service to its tenants, on the same footing as the export capability in DAT-023.

Framework Mappings (5)

EU-DA-Art.23.dFunctional Equivalence in the Destination Servicepartial
EU-DA-Art.30.1Functional Equivalence Support by Infrastructure Providersfull
EU-DA-Art.30.2Open Interfaces Free of Chargefull
EU-DA-Art.30.3Compatibility with Common Specifications and Harmonised Standardspartial
EU-DA-Art.34.1Switching Requirements Applied to In-Parallel Usepartial

Evidence (3)

configurationtechnicalautomated

Entitlement and charging configuration of every interface used for data and digital asset retrieval, read from the system or its infrastructure code.

Example: API entitlement policy export portability-api-entitlements-2026-06.yaml and the metering rule set for the export endpoints, both dated 12 June 2026.

Test: Verify: (1) no interface used for retrieval is gated on a plan, tier, add-on or contract flag, (2) no metered or per-call charge applies to those interfaces, (3) a rate limit applied to them is the same for every plan, (4) a credential issued to a customer on the lowest self-service plan can invoke each of them, (5) the authorisation model admits a third-party principal the customer has authorised, (6) the interfaces admit a caller acting for a customer running the service alongside another rather than leaving.

observationobservationmanual

Walkthrough in which a caller authenticates, enumerates and retrieves through the retrieval interfaces using the published documentation alone, and a customer authorises a third party to do the same.

Example: Retrieval walkthrough record of 18 June 2026, performed by an engineer outside the portability team from the public developer documentation, with the delegated-access run for the Vestad Group migration partner.

Test: Verify: (1) the walkthrough was performed from the published documentation alone, with no support ticket, no private specification and no help from the team that built the interface, (2) it authenticated, enumerated the available data and digital assets and retrieved a sample, (3) the documented behaviour matched what the interface did, and any discrepancy found carries a documentation fix with a date, (4) a customer authorised a third party through the published route and that third party completed the same retrieval, (5) the walkthrough covered the digital assets as well as the data.

recorddocumentmanual

Published functional equivalence pack: the configuration, the documentation of the service's behaviour beyond the data model, the support offered and the description of any tooling supplied, with the interoperability conformance statement against each documented format.

Example: Migration pack v4 published 1 May 2026, with the format conformance table listing three formats and their compatibility dates.

Test: Verify: (1) the pack states the configuration a customer needs to reconstruct the service elsewhere and matches the service as it currently runs, (2) it documents behaviour beyond the data model, such as defaults, limits, scheduling and the effect of each setting, rather than restating the schema, (3) it states the technical support available during a move and, where tooling is supplied, what that tooling does and what it leaves to the customer, (4) where a published interoperability specification applies to the service, each documented format names the specification it conforms to and the date compatibility was reached, (5) the pack carries a version and a date and was updated at the last change to a format or a compatibility claim.

Questions (3)

boolean

Can a customer on the lowest paid or self-service plan retrieve its data through the same interface as a customer on the highest plan?

The question is about entitlement, not about rate limits applied equally to every plan. An interface reachable only after a support request, a partner agreement or an upgrade is a no.

multi

Which of the following does the organisation supply to a customer moving to another service?

Documented retrieval interfaces reachable without contacting supportA route for the customer to authorise a third party to call themThe configuration needed to reconstruct the service elsewhereDocumentation of the service's behaviour beyond the data modelTechnical support during the moveTooling that performs part of the moveNone of the above

Tick an item only where a customer can obtain it without a negotiation. Documentation of behaviour beyond the data model means defaults, limits, scheduling and what each setting does, not the schema.

select

What do the documented export formats state about interoperability specifications?

The specification each format conforms to and the date compatibility was reachedThe specification each format conforms toThe format names onlyThe formats are not documentedNo interoperability specification has been published for this service type

Options run from the most complete statement to the least, with the last reserved for a service type no specification covers yet. Where no specification exists, the last option is the accurate answer rather than the third.