Proprietary software licensing under Dutch law: rights, audits and exit

Data analysis on a computer screen

Proprietary software licensing is the model in which the supplier keeps the copyright and the source code and grants the customer only a limited right of use, set out in a licence agreement. Under Dutch and EU law a computer program is a protected work, so without a licence the customer has no right to use it at all. The licence therefore defines everything: how many people may use the program, on which systems, in which territory, for how long, and what happens when the relationship ends.
This article looks at the closed-source model specifically: what a proprietary licence grants, which rights the Copyright Act gives a lawful acquirer whatever the end-user licence agreement says, whether click-through terms bind you in the Netherlands, and how to handle audits, resale and exit. For the mechanics of licensing in general, see our article on how software licensing works, and for the mirror image of this model, our guide to the open source software licence.

What a proprietary licence actually grants

A proprietary licence is a contract, not a sale. The customer receives a right of use that is usually non-exclusive, non-transferable and limited in scope; the supplier keeps ownership of the intellectual property and ships only the object code. Everything not expressly granted stays with the supplier, which is why proprietary terms are read narrowly against the customer rather than generously in its favour.
That has a practical consequence worth stating plainly: using the software outside the licence and using it without a licence are different problems. Exceeding an agreed number of users is a breach of contract, remedied by additional fees, damages or termination. Using the program with no licence at all, or continuing after termination, is copyright infringement, which opens up injunctions, surrender of profits and, in serious and deliberate cases, criminal liability. Our article on copyright and public content explains where those boundaries sit.
The licence rarely stands alone. A maintenance and support agreement, a service level agreement, a cloud terms of service, a data processing agreement under the GDPR and, in resale chains, an OEM or reseller addendum all attach to the same relationship, and they frequently contradict each other. Establish which document prevails before signing, because in a dispute the order of precedence clause decides more than the substantive clauses do.

The Dutch and EU legal basis

Computer programs are protected as literary works. The Dutch Copyright Act (Auteurswet) names them expressly in its list of protected works, and the substantive rules come from the Software Directive 2009/24/EC, which is implemented in Articles 45h to 45n of the Act. Protection arises automatically on creation; there is no registration and no formality.
The rightsholder holds the exclusive right to reproduce the program, to adapt or translate it, and to distribute copies. Loading, running and displaying a program involve reproduction in the copyright sense, which is precisely why a licence is needed to do something as ordinary as installing it.
Who owns the copyright is a separate question from who paid for the development. Where a program is written by an employee within the scope of their duties, the employer is regarded as the author under the Copyright Act. Where it is written by a contractor or an agency, the rights stay with the developer unless they are assigned in writing and signed. Commissioning software and paying the invoice does not transfer copyright, and this is the single most common gap we find in the files of companies that believe they own their own systems.

Rights you keep whatever the licence says

European software law gives the lawful acquirer a small set of rights that cannot be contracted away, and proprietary licences routinely purport to exclude them anyway. Four matter.
The first is normal use. A lawful acquirer may reproduce and adapt the program to the extent necessary to use it for its intended purpose, including correcting errors, unless the contract validly provides otherwise on that last point.
The second is the back-up copy. A person entitled to use the program may make a back-up copy where that is necessary for the use, and a clause forbidding it altogether is void.
The third is observation and testing. Someone entitled to use the program may observe, study and test its functioning in order to determine the underlying ideas and principles, provided they do so while performing acts they are entitled to perform. This right cannot be excluded by contract, and it is the legal basis on which interoperable products are built.
The fourth is decompilation for interoperability. Reverse engineering is permitted where it is indispensable to obtain the information needed to make an independently created program interoperate, where that information is not otherwise readily available, and where the decompilation is confined to the parts that are necessary. The information obtained may not be used for other purposes or handed to third parties. In 2021 the Court of Justice of the European Union added that a lawful acquirer may also decompile in order to correct errors that impair the functioning of the program, even where the licence forbids reverse engineering.
The point is not that these rights make proprietary terms unenforceable. It is that a blanket prohibition on reverse engineering or on making copies is broader than the law allows, and a supplier that relies on it in a dispute is on weaker ground than the clause suggests.

Is a click-through licence binding in the Netherlands

Yes, in principle, and the reasoning matters. A Dutch court will normally treat an end-user licence agreement as general terms and conditions. Under Article 6:233 of the Civil Code a set of general terms can be annulled if the user was not given a reasonable opportunity to take note of them, and Article 6:234 specifies how that opportunity must be offered. In an online environment, terms presented in a way that allows them to be stored and reproduced, with acceptance before conclusion of the contract, generally satisfies the requirement; a link buried in a footer after installation does not.
Two refinements are worth knowing. Consumers benefit from the statutory lists of unreasonable terms, and clauses that strip away statutory rights or impose unreasonably long notice periods are vulnerable. Business customers of a certain size cannot invoke those lists at all, which is why negotiated amendments matter more in a business-to-business setting than the hope that a court will strike a clause down.
Shrink-wrap terms enclosed in a package, only visible after purchase, are the weakest form. If the customer could not read them before the contract was concluded, the supplier faces an obvious argument about the opportunity to take note of them. Our article on the licence agreement looks at how these agreements are structured.
Since 2022 Dutch law also contains a regime for the supply of digital content and digital services to consumers, implementing the EU directive on that subject. It imposes a conformity requirement and a duty to supply updates for a period the consumer may reasonably expect, and it applies whether the software is paid for in money or in personal data.

Licence models and where the money leaks out

Proprietary licensing comes in a handful of models, and the legal risk sits in the metric rather than in the label.
A perpetual licence grants an indefinite right to use a particular version, usually on defined hardware, with support and upgrades sold separately. The exposure here is version drift: the right to run version six does not include version seven, and a supplier that ends support for the licensed version leaves the customer legally compliant but practically stranded.
A subscription or software-as-a-service model grants access for as long as the fees are paid. Access ends when payment stops, which makes the termination and data return clauses more important than the price. For consumers, Dutch law limits automatic renewal: after an initial year, a subscription that renews must be cancellable at any time with a notice period of no more than one month. Business customers have no such protection and are bound by what they signed.
Seat-based and device-based licences meter by named user, concurrent user, device or processor. Almost every audit dispute we see starts here, because the metric in the contract and the way the software is actually deployed have drifted apart: test environments, disaster recovery copies, virtual machines, contractors and departed employees whose accounts were never removed.
Tiered and freemium models sell the same program at different functional levels. Moving between tiers usually means accepting new terms, and terms accepted by an administrator clicking through an upgrade screen bind the company just as firmly as a signed agreement.

The clauses to negotiate before signing

Scope of use is the first. Establish who may use the software: the contracting entity only, or also group companies, contractors and outsourcing partners. A licence for internal business use does not cover a customer-facing portal, and a licence granted to one legal entity does not automatically survive a reorganisation.
Transfer and change of control come next. Non-transferability clauses can block an intra-group restructuring or an acquisition, and a change of control clause can allow the supplier to terminate or to reprice at exactly the moment the customer has least leverage. Negotiate an assignment right for group reorganisations at the outset.
Audit rights deserve attention. Agree the notice period, the frequency, the scope of data to be provided, the confidentiality regime, whether an external auditor may enter the premises, and who bears the cost. A reasonable clause caps audits at once a year, excludes competitors as auditors, and provides that the supplier pays unless a material shortfall is found.
Liability and warranties are usually presented as non-negotiable and usually are not. As-is disclaimers and caps at twelve months of fees are standard, but Dutch law will not allow a supplier to rely on an exclusion where the loss was caused by intent or deliberate recklessness, and a cap that leaves no meaningful remedy at all for a critical system invites an argument that reliance on it is unacceptable. Where the software is business-critical, tie liability to the consequences that matter rather than to the licence fee.
Updates, end of support and exit close the list. Fix how long the supplier will support the version you are buying, what notice applies to a discontinuation, and what happens to your data and your ability to keep operating when the contract ends. A software escrow arrangement is the classic answer for on-premise systems, and a documented exit plan with data export formats is the answer for cloud services; our article on the cloud contract sets out what that requires.

Reselling a licence: what exhaustion does and does not allow

The received wisdom that a software licence can never be resold is too absolute. In its UsedSoft judgment (case C-128/11, 2012) the Court of Justice of the European Union held that where a copyright holder makes a copy available for download in the European Union against payment of a fee, for an unlimited period, the distribution right in that copy is exhausted. The first acquirer may then resell it, provided the original copy is made unusable at the time of transfer, and the resale cannot be blocked by a contractual non-transferability clause.
The limits are just as important. Exhaustion applies to a copy licensed for an unlimited period, not to a subscription or a service. It does not permit splitting a volume licence into separate seats. It requires the seller to stop using the copy, which has to be demonstrable. And in its Tom Kabinet judgment (case C-263/18, 2019) the Court declined to extend the same reasoning to e-books, treating their supply as a communication to the public rather than a distribution, which narrows how far the software reasoning travels to other digital goods.
For a customer, the practical value of this is in negotiation: unused perpetual licences may have residual value, and a supplier’s refusal to permit any transfer at all is not necessarily the last word.

Software audits and true-ups

Most proprietary agreements give the supplier the right to verify usage. In practice an audit starts with a letter, is followed by a request for deployment data or a self-assessment questionnaire, and ends with a report comparing entitlements against installations. Where a shortfall is found, the supplier will claim additional licence fees, often at list price and backdated, plus maintenance and sometimes audit costs.
Three things reduce the exposure. Keep the licence position documented: contracts, order forms, keys, entitlement records and a current view of deployments, held centrally rather than in the inbox of whoever bought the software. Read the audit clause before responding, because the scope of what you owe is defined by the contract rather than by the auditor’s template. And treat the audit report as a claim to be tested rather than an invoice to be paid: the metrics are often applied to environments the contract does not clearly cover, such as virtualised or standby systems, and that is a legal question rather than a technical one.
Where a supplier alleges use beyond the licence, it may frame the claim as copyright infringement rather than breach of contract, because the remedies are stronger. Whether that framing is correct depends on whether the use fell outside the licence or merely breached a term within it, which is exactly the distinction to argue about. Our article on software with a non-commercial licence used in a business shows how quickly this arises in practice, and our overview of intellectual property enforcement in the Netherlands sets out the remedies available.

Lock-in and the right to leave

The strategic risk of proprietary licensing is not the fee; it is dependency. Data in a proprietary format, processes built around one vendor’s workflow and integrations written against one vendor’s interfaces all raise the cost of leaving, and a supplier that knows this prices accordingly at renewal.
European law has started to address that for cloud services. The Data Act, which has applied since 12 September 2025, obliges providers of data processing services to enable customers to switch to another provider or to an on-premise environment, to remove contractual and technical obstacles to switching, and to provide the necessary information and assistance; charges for switching are being phased out under a timetable running into 2027. It does not apply to on-premise software licences, so for those the protection still has to be contractual: escrow, documented interfaces, data export in a usable format, and a defined transition period after termination.
Choosing between proprietary and open source is a business decision with legal consequences on both sides. Proprietary terms buy a single accountable counterparty, contractual service levels and an indemnity against third-party claims, at the price of control. Open source removes the fee and the lock-in but imposes licence compliance obligations of its own, and copyleft conditions can reach further into your own code than expected. Mixed estates are normal; what is not normal, and causes trouble, is an estate nobody has mapped.

When to involve a lawyer

Bring in advice before signing where the software is business-critical, where the contract crosses borders, where personal data are processed by the supplier, or where the licence metric does not match how you actually work. Bring it in immediately when an audit notice or a cease-and-desist letter arrives, because the first response frames the rest of the dispute; our article on handling intellectual property disputes explains the sequence.
Law and More advises suppliers and customers on software licensing, service level and maintenance agreements, cloud and escrow arrangements, audits and licence disputes, and on the intellectual property questions that sit underneath them. If a licence looks one-sided or an audit has been announced, our intellectual property lawyers and our IT law practice will review the position with you.

Need Legal Assistance?

Contact Law & More for expert guidance on your legal matters. Our multilingual team is ready to help.

Related articles

Under Dutch and EU law nobody owns data as such, so the data clause in

There is no separate metaverse law in the Netherlands. Immersive virtual worlds are governed by

AI liability in the Netherlands is not governed by a separate statute. When an AI

Data breaches happen every day in the Netherlands. When they do, someone must take responsibility.

Software licensing is the contractual mechanism by which the holder of the copyright in a

A community service order (taakstraf) is unpaid work imposed as a principal sentence in Dutch

Stay Updated on Dutch Law

Subscribe to our newsletter for the latest legal insights, regulatory updates, and practical advice.