In short. A reversibility plan describes, before the contract starts, how to take the service back: scope, formats, schema, deadlines, owners, cost, proof of deletion and rehearsal. Since 12 September 2025, the EU Data Act has imposed a notice of at most two months and a transition of at most thirty days. The plan is annexed to the contract.
A reversibility plan is the document that describes, before anything starts, how you will leave. It answers a single question: the day this supplier stops — because you leave, because it shuts down, because the contract is re-awarded — what must be done, in what order, within what deadlines, and what do you walk away with?
It is the clause almost everyone signs and almost nobody has ever executed. This page sets out what it must contain to be worth anything.
What it is, and what it is not
Reversibility is the return: the service comes back to you, or to someone you appoint. The reversibility plan is the instruction manual for that return, written and annexed to the contract while the relationship is good — the only moment when both parties will still discuss it calmly.
A backup is not reversibility. A backup returns bytes; reversibility returns a working service somewhere else. Between the two sit the formats, the description of the data, the usage rights, the credentials, the settings, and somebody's time to help. That is exactly what the plan describes.
Reversibility, transferability, portability
- Reversibility — the service comes back to you, or to your own team. You take the controls again.
- Transferability — the service passes to another supplier. That is the re-awarded contract, and it is more demanding: the successor must be able to work without ever having seen the system.
- Portability — your data comes out in a format readable elsewhere. It is one brick of the plan; it is not the plan.
Confusing the three is expensive. Many contracts promise portability — a data export — and call it reversibility. On the day, you collect a file nobody knows how to rebuild from.
What the law has required since 2025
For any data processing service — cloud, hosting, online software — the European data regulation (Data Act, Regulation (EU) 2023/2854) has applied since 12 September 2025. It does not use the word reversibility; it imposes the substance of it. The deadlines it sets are now the minimum you can demand:
- a switching notice that cannot exceed two months;
- a transition period of at most thirty days, during which the outgoing provider must assist its customer;
- a retrieval window of at least thirty days after the transition, before any permanent deletion;
- and, from 12 January 2027, a ban on charging anything at all for switching provider.
The provider must also publish what can be exported: structures, formats, standards. A provider who cannot state in one page what comes out and in what shape has just answered the question.
In French public procurement, article 42 of the 2021 CCAG-TIC covers reversibility and transferability, and the plan itself is annexed to the contract's administrative clauses. The expected deliverables are named there: executable software, source code where applicable, technical and functional documentation, configuration files, operating scripts, data in one or more documented and usable formats, and the technical interfaces that give access to it.
The eight points of a plan that holds
- The scope. What comes back, exactly: data, documents, accounts, settings, history, logs, content produced during the contract. Write down what does not come back too, and why.
- The formats. Not "a standard format": the name of the format, its version, and a sample attached. An encrypted export whose key you do not hold, or a proprietary format with no reader, is not an export.
- The schema. The description of what the files contain: the tables, the fields, what each one means. Without it, the data is a heap.
- The deadlines. Who notifies whom, how far in advance; when the export is handed over; how long it stays available. Three dates, not an intention.
- Who does what. A named person on each side, the time budgeted for each, and what happens if one of them fails to show up.
- The cost. Priced at signature, or zero. A cost "to be agreed at the time" is a lock: it gets negotiated at the worst possible moment, once the decision to leave is taken and known.
- The proof of deletion. What is erased at the provider's end, within what time, and how it is proven — backups included.
- The rehearsal. The date of the next real rehearsal. It is the point almost every plan omits, and the one that makes the other seven true.
How to write it into the contract
The plan is not a paragraph of the contract: it is an annex, called up by a short article. The article creates the obligation, the annex describes it — and the annex can be updated without reopening the contract.
- a "Reversibility" article referring to the annex and requiring it to be updated at least once a year;
- the annex itself, with the eight points above;
- a survival clause: reversibility obligations outlive the contract, whatever ends it — including termination for breach;
- a penalty triggered by a missed deadline, an observable fact, not by a judgement about quality.
The commonest trap fits in one line: making reversibility conditional on payment of all sums due. A single disputed invoice is then enough to hold your data hostage. If that sentence is in your contract, it is the first one to strike out.
A plan never executed does not exist
A reversibility plan that has never run is a guess. The only way to know whether it holds is to do it: ask for the export, take it, and try to rebuild something usable elsewhere. Once a year, half a day.
You almost always find the same three things: a bulky set everyone had forgotten, a field nobody can define any more, and a step that requires an access nobody still has. All three take an hour to fix while the relationship is good. None of them can be fixed on the day you leave.
What that looks like here

KnowledgeCapital serves one space per organisation, in its own database. The full export of that space — the database, the media attached to it, the identity and the settings — is triggered from a screen, by the space's owner, without going through us. Import goes the other way, including onto your own servers. Every export and every import is written to the audit log: who, when, which space.
What the archive contains is detailed on the Reversibility page, and installation on your own servers on the Run it on your own servers page.
A question worth asking today. Ask every one of your suppliers for this plan, us included. The answer — how precise it is, and how long it takes to arrive — will tell you more about them than any demonstration.
See also: Reversibility: export all your data · On-premise installation: the sovereign edition · Security and data confinement · Verified backups and business continuity · Sovereign knowledge management with local AI · Knowledge management system: a 12-point evaluation grid
Frequently asked questions
What is a reversibility plan?
The document, annexed to the contract, that describes how the service comes back to you or passes to another supplier: what, in which formats, within what deadlines, by whom, at what cost, and with what proof of deletion.
What does the Data Act change for reversibility?
Since 12 September 2025, it sets a switching notice of at most two months, a transition of at most thirty days, at least thirty days to retrieve the data and, from 12 January 2027, a ban on charging for switching provider.
Are reversibility and portability the same thing?
No. Portability gets your data out in a format readable elsewhere; reversibility gives you back a working service, with the formats, the schema, the settings and the help needed.
Which clause should be struck out first?
The one that makes reversibility conditional on payment of all sums due: a single disputed invoice is then enough to hold your data hostage.