A software licence is the permission the copyright holder gives you to use a program; you do not buy the software, you acquire a right to use a copy on the terms of the licence. Under Dutch law, however, a one-off purchase of standard software for an indefinite period is treated as a sale, and some statutory rights, such as the right to correct errors and to make a back-up copy, cannot be taken away by the licence.
Under Article 10(1)(12) of the Dutch Copyright Act (Auteurswet, Aw), a computer program is a protected work. Loading, copying or adapting it therefore requires permission or a statutory exception. The licence is that permission, and it sets the scope, duration and conditions of use. Many organisations treat a licence as a receipt rather than a contract, assume rights it never granted, and discover the gap during a vendor audit or a migration. Below we explain what Dutch and EU law give you, what the licence adds or takes away, and which clauses decide your risk.
What do you acquire when you license software?
You acquire a right to use a copy, while the copyright stays with the rights holder. You may only do what the licence allows, such as installing on a second server or letting a group company use it.
That distinction has practical consequences. You cannot assume that you may install the program on a second server, run it for a group company, let a contractor use your account, or keep using it after the agreement ends, unless the licence says so.
When is software acquisition a sale?
Dutch law does not treat every acquisition of software as a pure licence. In De Beeldbrigade (27 April 2012, ECLI:NL:HR:2012:BV1301), the Dutch Supreme Court (Hoge Raad) held that the rules on sale in Book 7 of the Dutch Civil Code (Burgerlijk Wetboek, BW) apply to standard software supplied for an indefinite period against a one-off payment, even though software is not a tangible object.
As a result, the conformity requirement of the law of sale applies: the software must have the qualities you were entitled to expect. That is a stronger position than a bare contractual warranty. It is one reason vendors prefer subscription and cloud models, which are services rather than sales.
What if you are a consumer?
Consumers have extra protection. Since 1 January 2022, Book 7 BW has contained separate rules on contracts for the supply of digital content and digital services, implementing the EU Digital Content Directive. These rules impose conformity requirements, an obligation to provide updates for as long as the consumer may reasonably expect them, and remedies that cannot be excluded to the consumer’s disadvantage. Licences between businesses are largely left to freedom of contract, which is why negotiation matters more there.
Who owns software written for you?
Ownership of software developed for you is a separate question that catches many organisations out. Under Article 7 Aw, copyright in a program written by an employee in the course of his or her duties belongs to the employer. Copyright in a program written by a freelancer or a development agency stays with that party, unless it is transferred by a written deed of assignment under Article 2 Aw.
A client without a written assignment ends up with an implied licence of uncertain scope. That usually surfaces when the client wants to sell the business or change supplier. Our article on proprietary software licensing looks at that relationship in more detail.
Which rights do you have whatever the licence says?
EU software law reserves a few rights for the lawful acquirer, and a clause that excludes them is void. You may load and run the program, correct errors, make a back-up copy and, under strict conditions, decompile for interoperability.
Article 45j Aw allows the lawful acquirer of a copy to make the reproductions needed for the intended use of the program. The parties may vary this in the contract, with one exception: reproduction in the course of loading, displaying or correcting errors in the program may not be prohibited by agreement. A licence that forbids you from fixing a fault that stops the software from working as intended is, to that extent, unenforceable.
Article 45k Aw allows the lawful user to make a back-up copy where that is necessary for the intended use, and this right also cannot be contracted away. Article 45m Aw permits decompilation, but only under strict conditions. It must be indispensable to obtain the information needed for interoperability with an independently created program, it must be done by a lawful user, the information must not already be readily available, and it must be limited to the parts of the program needed for that purpose. Decompiling to build a competing product falls outside the exception.
In Top System (6 October 2021, C-13/20), the Court of Justice of the EU confirmed that a lawful acquirer may also decompile a program to correct errors that affect its functioning.
What does copyright not protect?
In SAS Institute (2 May 2012, C-406/10), the Court of Justice held that neither the functionality of a program, nor the programming language, nor the format of its data files is protected by copyright. What is protected is the expression: the source code and object code. A competitor who studies what your software does and writes its own implementation does not infringe your copyright, however unwelcome that may be. Our guide to intellectual property law in the Netherlands places software copyright alongside the other rights a technology business relies on.
What is the difference between proprietary, open source and copyleft licences?
A proprietary licence keeps the source code closed and restricts use. Open source licences allow broad use but attach conditions, and copyleft licences require you to share your own source code when you distribute the software.
The difference is operational, not ideological: it determines what you must disclose and what you may charge for.
Proprietary licences
A proprietary licence grants a defined right of use, usually non-exclusive and non-transferable. The restrictions are the heart of the agreement: a maximum number of named users or devices, a permitted environment, a ban on sublicensing, and a ban on reverse engineering that only has effect insofar as it does not conflict with the statutory rights described above.
The vendor controls updates, support and pricing, and you bear the migration costs if the product is discontinued or the terms change. You manage that dependency by negotiating notice periods, caps on price increases, continuity arrangements and, for business-critical systems, a source code escrow.
Permissive open source licences
Open source licences are copyright licences, not a waiver of copyright. They are enforceable like any other licence: if you breach the conditions, you lose the permission and infringe the copyright.
Permissive licences such as MIT, BSD and Apache 2.0 impose few obligations. You may include the code in a commercial product, even one you distribute only in binary form, provided you reproduce the copyright notice, the licence text and the disclaimers. Apache 2.0 adds an express patent licence and requires you to state which files you changed. These obligations are easy to meet and easy to overlook. A missing notice file is the most common open source compliance failure in practice.
Copyleft licences
Copyleft licences, of which the GNU General Public License (GPL) is the best known, attach a condition to distribution: anyone who receives the binary must also be able to obtain the corresponding source code, under the same licence. If you modify GPL code and distribute the result, the obligation extends to the work as a whole, which can mean disclosing code you intended to keep proprietary.
Using GPL software internally, without distributing it, does not trigger the obligation. The Affero GPL (AGPL), however, treats making software available over a network as equivalent to distribution, which is exactly the situation of a SaaS provider. The Lesser GPL (LGPL) is a middle ground: you may link your own code to an LGPL library without opening that code, provided the user can replace the library with a modified version. Whether static linking meets that condition is a question to settle before release, not after.
If your company ships software, the practical answer is a written open source policy, an inventory of every component and its licence, and an automated check in the build pipeline. That inventory is also what a buyer will ask for in due diligence, and its absence usually lowers the purchase price.
Which licensing model applies, and what does it mean legally?
The licensing model determines how you pay and how use is measured, and therefore where your compliance risk lies. The main distinctions are per user or per device, perpetual or subscription, and on-premises or cloud.
A named-user or per-seat licence is tied to an identified person. Sharing a named account between two employees is a breach, even if they never work at the same time, and it is the violation vendors detect most easily. A concurrent licence limits the number of simultaneous users and is enforced by a licence server; the risk there is exceeding the peak. A per-device or per-core licence is measured against hardware, and virtualisation is where it goes wrong. Under some vendors’ metrics, running a licensed instance on a cluster means licensing every physical core in that cluster. Read the metric definition, not the price list.
Perpetual licence or subscription?
A perpetual licence gives an indefinite right to use a specific version. Support and new versions come under a separate maintenance agreement, and ending that agreement does not remove your right to keep using what you have. A subscription gives you use only for as long as you pay, so the end of the contract is the end of your access. Agree in advance what happens to your data, in which format it is returned and how long the vendor will help with the exit.
Cloud or on-premises?
With software running on the vendor’s infrastructure, you are buying a service. The agreement should cover availability, support response times, subcontractors, the location of your data and the consequences of termination. If personal data is processed, you also need a data processing agreement that meets Article 28 of the GDPR; a licence agreement does not do that job. Our article on the cloud contract in the Netherlands sets out what that contract must cover.
Can you resell or transfer a software licence?
Sometimes. A perpetual licence bought for a one-off fee can be resold even if the licence prohibits it, but a subscription or cloud service cannot.
In UsedSoft (3 July 2012, C-128/11), the Court of Justice held that a rights holder who makes a copy available for download and grants, for a fee, a right to use it for an unlimited period has sold that copy. The distribution right in that copy is then exhausted, and the rights holder cannot oppose its resale, even though the copy was never on a disc. The first buyer must make its own copy unusable at the time of resale, and a licence for a number of users may not be split and sold in parts.
The limits matter as much as the rule. Exhaustion applies to a perpetual licence sold for a lump sum, not to a subscription or a service. In Tom Kabinet (19 December 2019, C-263/18), the Court held that supplying an e-book by download for permanent use is a communication to the public, not a distribution, so no exhaustion arises. The software ruling rests on the specific provisions of the Software Directive and does not extend to other digital works. Maintenance and support contracts do not transfer with the licence unless the vendor agrees.
A licence sold on this basis can therefore be transferred despite a contractual ban, but everything around it is open to negotiation. Before you buy second-hand licences, ask for the chain of title, the original invoice and written confirmation from the seller that its copies have been deleted.
What must you accept in a vendor audit?
You must accept what the audit clause in your contract provides, and no more. If the clause is silent on a point, reasonableness and fairness under Article 6:248 BW apply, and they do not give a vendor unlimited access to your systems.
Most enterprise agreements contain an audit clause, and vendors use them. A typical audit starts with a letter announcing the audit and asking for deployment data, purchase records and system reports within a set period. A well-drafted clause limits audits to once a year, requires reasonable notice, restricts the audit to normal business hours, obliges the auditor to sign a confidentiality undertaking, lets the vendor bear the costs unless a material shortfall is found, and confines the scope to the licensed products.
Three practical rules help. Do not hand over raw data before you have run the measurement yourself; the discussion is almost always about how use is counted rather than what is installed. Route all communication through one person and confirm every agreement in writing. And keep the audit within the contract: an auditor who asks for access to systems outside the licensed products, or for employees’ personal data, is asking for something the clause does not give, and the GDPR applies to that request.
What if the audit finds a shortfall?
If the shortfall is real, the vendor’s claim is a contractual claim for the licences that should have been bought. There is usually room to negotiate: a forward-looking purchase instead of retroactive fees, a waiver of penalties in exchange for a longer term, or a switch to a different metric.
If the vendor threatens copyright proceedings, it must prove infringement of specific rights. In intellectual property proceedings, the court can order the losing party to pay the full reasonable legal costs under Article 1019h of the Dutch Code of Civil Procedure (Rv). Our article on enforcing intellectual property rights in the Netherlands describes that route, and such a dispute often starts with a cease and desist letter.
The violations found in audits are consistent: installations that grew without matching purchases, accounts of former employees left active, named-user licences shared between people, upgrades installed without upgrade rights, production use of a test licence, and virtual environments counted differently from what the customer assumed. An accurate register of entitlements and deployments, reconciled at least once a year, prevents each of them. Keeping that register is also part of your organisation’s general legal compliance.
Which clauses decide your risk?
For software your business depends on, five clauses deserve real attention: the scope of the grant, the limitation of liability, the intellectual property indemnity, continuity and the change clause.
Most software licences are presented as non-negotiable. For an off-the-shelf tool that is usually true and usually acceptable. For business-critical systems, it is worth negotiating.
Scope of the grant
The grant should state who may use the software, including group companies, contractors and outsourcing providers; on which environments, including test, disaster recovery and back-up; and in which countries. A grant narrower than the way you actually work is a shortfall waiting to be discovered.
Limitation of liability
Under Dutch law, a limitation of liability is generally valid between businesses. The court can set it aside if relying on it would be unacceptable by the standards of reasonableness and fairness, and it does not protect a party whose own intent or deliberate recklessness caused the damage. What matters is the fit: a cap at the annual fee is defensible for a low-value tool, but not for a system whose failure stops production. Check separately whether indirect and consequential loss is excluded, because that exclusion often removes the loss that would actually hurt.
Intellectual property indemnity
If a third party claims that the software infringes its rights, you are the one sued for using it. A proper indemnity obliges the vendor to defend the claim and pay the damages and costs, and lets the vendor choose to obtain a licence, modify the software or refund part of the fee. Be wary of indemnities capped at the same low amount as the general liability clause, which makes them close to worthless.
Continuity
What happens if the vendor stops supporting the product, is taken over or goes bankrupt? A source code escrow with a clear release trigger is the usual answer for on-premises software. For cloud services, the equivalents are an exit plan, agreed data formats and a defined transition period. Bankruptcy deserves attention because a licensee’s position in a Dutch bankruptcy is not straightforward. The trustee (curator) is not obliged to keep performing, and the more the service depends on the vendor actively doing something, the more exposed you are.
Change clause
Vendors often reserve the right to change product terms, metrics or documentation unilaterally. Accepting that without limits means accepting a price and scope you have not yet seen. A workable compromise ties changes to a notice period and gives you the right to terminate without penalty if the change is materially adverse. General guidance on negotiating these documents is in our article on contracts and agreements.
What should you do before you sign, and every year after?
Before signing, compare how you will actually use the software with the wording of the grant. After signing, keep a register of your licences and reconcile it with actual use at least once a year.
Settle any difference between use and grant in the contract, not in an e-mail from a sales representative. Establish in writing which metric applies and how it is measured, with a worked example for your own environment. Confirm whether you have a perpetual licence or a subscription, and what you keep at the end. Check the audit clause, the liability cap, the indemnity and the change clause against the value of the system to your business.

After signing, the work is administrative, and it is what prevents disputes. Keep one register of entitlements: contracts, order forms, invoices, licence keys, metrics and renewal dates. Reconcile it with actual deployments at least once a year, and always after a reorganisation, an acquisition or a move to virtual or cloud infrastructure, because those events create shortfalls. Remove the accounts of people who have left, and keep the open source inventory up to date alongside it.
In summary
- A software licence is permission to use a copy; the copyright stays with the rights holder.
- A one-off purchase of standard software for an indefinite period is treated as a sale under Dutch law, with the conformity protection that comes with it.
- You always keep the right to load the program, correct errors, make a back-up and, under strict conditions, decompile (Articles 45j to 45m Aw).
- Open source licences are enforceable; copyleft licences can require you to disclose your own source code on distribution.
- Audit clauses, liability caps, indemnities, continuity and change clauses decide your risk, and a licence register prevents most audit claims.
Frequently asked questions
Can I resell software I no longer use?
Yes, if you bought a perpetual licence for a one-off fee. The rights holder’s distribution right is then exhausted, even if the licence prohibits transfer. You must make your own copy unusable. Subscriptions and cloud services cannot be resold.
Who owns software a freelancer developed for my company?
The freelancer, unless the copyright was transferred to you by a written deed. Without a deed you only have a licence of uncertain scope. For employees, the employer owns the copyright in software written in the course of their duties.
Does using GPL software oblige me to publish my source code?
Only if you distribute the software or a modified version. Internal use does not trigger the obligation. Under the AGPL, however, offering the software to users over a network counts as distribution.
Law & More advises businesses in the Netherlands on software licences, development and SaaS agreements, open source compliance and disputes with software vendors, including audits and infringement claims. The Dutch Copyright Act contains the statutory rights discussed above. Unsure where you stand? Tell us about your situation. We will let you know your options within one working day.


