Let’s talk about your firm · A free 15-minute discovery call. No commitment.Prepare for my call

Intellectual Property and Data6 min read

Software license agreements: SaaS, open source and proprietary software

2026 guide to negotiating and securing software license agreements (proprietary, SaaS, open source), with key clauses, Data Act, CRA and litigation strategies.

In 2026, negotiating a software license agreement requires bringing together copyright, cybersecurity compliance and data governance. This practical guide covers the three main models — proprietary software, SaaS and open source — with essential clauses and the new European legislation (Data Act, Cyber Resilience Act) to incorporate.

- Software copyright: in France, the author’s software rights and statutory exceptions (backup copies, observation/decompilation for interoperability) are governed by the Code de la propriété intellectuelle, particularly Article L122‑6‑1 CPI.

- European Union: Directive 2009/24/EC protects computer programs and has enabled recognition, subject to conditions, of exhaustion of the distribution right for certain perpetual licenses, including software downloaded online (note: this reasoning applies neither to subscriptions nor to temporary licenses).

- Enforcement of IP rights: Directive 2004/48/EC strengthens enforcement measures for infringements. The CJEU (case C‑666/18) ruled that breach of software license terms defining the scope of the rights granted may constitute copyright infringement, allowing these enhanced safeguards to be invoked.

- Data and portability: the Data Act (EU) 2023/2854 imposes portability and provider-switching obligations on cloud/SaaS services, regulates exit charges and requires contractual transparency over access to generated data. These rules complement the GDPR right to portability (see CNIL and the EDPB).

- Cybersecurity: the Cyber Resilience Act introduces CE requirements for the security of software integrated into products. Open source developed outside commercial activity is generally excluded, but once incorporated into a marketed product or service, the obligations fall on the economic operator.

- French digital law: the SREN law strengthens the digital regulatory framework. For cloud/SaaS businesses, focus especially on its interaction with the Data Act and, more broadly, fairness and security requirements (references on Legifrance).

2) Proprietary software: essential clauses to negotiate

Scope of use and restrictions

  • Subject matter: define precisely what is granted (rights to install, run, reproduce for backup purposes, adapt), recalling the statutory exceptions in L122‑6‑1 CPI.
  • Scope: type of use (internal/external), user numbers (named/concurrent), CPUs/cores, instances, sites, subsidiaries, environment (production/development/test), territory.
  • Duration: perpetual vs fixed-term; maintenance renewal conditions.
  • Prohibitions: decompilation beyond interoperability, unauthorized reverse engineering, public benchmarking without agreement, sublicensing without consent.

Maintenance, updates and compliance

  • SLAs and operational maintenance: service levels, correction times by severity, development roadmap, system compatibility.
  • Updates: distinguish “patches” from “major versions” (and their cost).
  • License audit: reasonable audit arrangements, frequency, confidentiality, graduated remedies for usage overruns.

To manage financial exposure, combine a liability cap with appropriate exclusions. See our dedicated guide to the limitation of liability clause.

Transfer and resale

Resale of perpetual licenses may be possible (exhaustion of the distribution right within the EEA) if the conditions set by case law are met. Include a controlled assignment clause and representations on deletion of copies by the transferor. Avoid treating a subscription or temporary license as a sale.

Practical tip: document the origin of the code and rights assigned by founders/service providers. Review your chain of title with our focus on “assignment of intellectual property by founders” and secure the code with “protecting a startup’s source code”.

3) SaaS: subscriptions, portability and preventing lock-in

Nature of the right granted

SaaS generally grants a right of remote access/use without a right to reproduce the software locally. State this clearly to avoid ambiguity.

Portability and switching providers (Data Act)

  • Exit/portability: exit assistance, timetable, open format (API/export), restoration tests, temporary data retention.
  • Data access: who may access which data (raw/derived/metadata), permitted purposes, logging, security.
  • Exit charges: transparency and a reduction pathway in accordance with the Data Act.
  • Interoperability: technical documentation, schemas, compatibility with substitute services; obligations for providers to cooperate during switching.

For a complete framework for SaaS relationships (SLAs, availability, backups, support, penalties), consult our guides “SaaS contract: essential clauses” and “SaaS terms of sale: essential clauses”.

Data protection and security

  • GDPR: data processing agreement (DPA), subprocessors, technical/organizational measures, DPIA if necessary; see CNIL.
  • International transfers: post-Schrems II mechanisms (SCCs, TIAs); our guide “data transfers outside the EU” details implementation.
  • Cybersecurity by design: vulnerability management, SBOM, patches; anticipate Cyber Resilience Act requirements if your SaaS integrates with products with digital elements.

4) Open source: compliance, copyleft and product strategy

Identify obligations by license

  • Permissive (MIT, BSD, Apache‑2.0): attribution, rights notice, sometimes a change notice and patent clause (Apache‑2.0).
  • Copyleft (GPL, LGPL, AGPL): make the source code of derivative works available on distribution; AGPL extends the obligation to network access (SaaS).

Establish an OSS compliance process: component inventory (SBOM), license compatibility checks, notices in documentation/product, retention of license texts, internal policy and team training. Open source remains protected by copyright: useful guidance from INPI.

Dual licensing and business model

You may offer an open-source edition and a commercial edition with additional features/professional services. Clearly define the scope of rights and community contributions (Contributor License Agreement).

Cybersecurity and CRA

If an open-source component is incorporated into a commercial product, the party responsible for placing it on the market must ensure security compliance (vulnerability management, traceability, notices) under the Cyber Resilience Act.

5) Litigation: choosing the right route

  • License breach: if it affects the scope of rights (e.g. exceeding user limits, unauthorized modification), it may constitute copyright infringement (CJEU C‑666/18), allowing access to the safeguards of Directive 2004/48/EC.
  • Evidence strategy: log usage, exercise contractual audit rights, record discrepancies and formal demands. In practice, a well-structured formal demand often speeds up amicable resolution; see our guide “effective formal demand”.
  • Financial clauses: provide graduated, calculable contractual penalties; see “penalty clause vs withdrawal-fee clause”.

6) Contractual checklist (ready to use)

A. Proprietary software

  • Scope of use (users, sites, environments, license metrics) and reminder of statutory exceptions (L122‑6‑1 CPI).
  • Clear restrictions (reverse engineering, sublicensing, benchmarking, cloud/VDI).
  • Maintenance/SLA, severity matrix, roadmaps and compatibility.
  • Reasonable license audit, cure period, capped surcharges.
  • Controlled transfer/assignment, uninstallation/deletion guarantees.
  • Liability, caps, specific exclusions, professional indemnity/cyber insurance.

B. SaaS

  • Nature of access (service, no reproduction), service levels and penalties.
  • Data: ownership/use, exit/portability, export formats, APIs, timelines.
  • Portability and switching (Data Act): fee transparency, cooperation when changing provider.
  • GDPR: DPA, subprocessors, international transfers, security.
  • Cybersecurity by design, vulnerability management, SBOM.

C. Open source

  • Component and license inventory (SBOM), license compatibility.
  • Compliance with obligations (attribution, notices, code availability for copyleft/AGPL).
  • Internal approval process, legal review, team training.
  • OSS clauses in the customer contract (third-party notices, exclusions, liability).
  • Preparing for CRA requirements for commercial products incorporating OSS.

To scale these practices, rely on a properly equipped Legal Ops function; our “startup legal audit” and “automating contract management” guides offer ready-to-use frameworks and no-code tools.

Further reading

Related resources

Frequently asked questions

FAQ

What is the difference between a proprietary license and SaaS?

A proprietary license grants rights of use and local reproduction. SaaS grants remote access without reproduction. Clauses, warranties and risks differ.

How can I incorporate the Data Act into my cloud contracts?

Add exit/portability clauses (open formats, APIs, assistance), transparency on exit charges, portability timelines and cooperation when changing provider.

What should I provide for open source in my offerings?

An SBOM inventory, compliance with obligations (attribution, notices, copyleft), an internal policy and customer clauses governing third-party OSS and security.

Can infringement proceedings be brought against a licensee in breach?

Yes, if the breach exceeds the granted scope, in accordance with CJEU C‑666/18 and Directive 2004/48/EC, opening access to enhanced remedies.

References

Sources used

Training · Audit · Support

Put what you read into practice

Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.

Explore the auditBook an introductory call
← Back to all articles