3/20
  • Pages
01 Cover
02 Foreword
03 Technology
04 Is the proposed European AI Act innovation friendly
05 How is EU cybersecurity law affecting IoT product design?
06 Will mid-market tech M&A buck the trend in a downturn?
07 The rise of IP disputes in relation to NFTs
08 The new era for data regulation and what it means for the tech sector
09 Can combining digital twins and the Internet of Things unlock value?
10 Media
11 European regulators set to clamp down on 'dark patterns'
12 The streaming war intensifies with the rise of FAST
13 Building the metaverse: what can we expect in 2023?
14 How performance data is transforming the business of sport
15 How advertisers need to get ahead of the Web3 evolution and its legal ramifications
16 Communications
17 The role of the Internet of Things in the TMC race to net zero
18 Will 2023 be the year 5G private infrastructure and networks finally arrive?
19 Is consolidation in the telecoms industry in the interests of consumers?
20 Disclaimer

Technology

Technology
The importance of software compliance in digital transformation
Is the proposed European AI Act innovation friendly?
How is EU cybersecurity law affecting IoT product design?
Will mid-market tech M&A buck the trend in a downturn?
The rise of IP disputes in relation to NFTs
The new era for data regulation and what it means for the tech sector
Can combining digital twins and the Internet of Things unlock value?
Back to Foreword

The importance of software compliance in digital transformation

Snapshot

  • Harmonising a software portfolio is the first step for businesses going through digital transformation
  • Companies need to structure their software licence agreements and implementation agreements to gain maximum flexibility and futureproof their businesses
  • Software compliance can be challenging for businesses as, in addition to the licensing regime, the regulatory framework is rapidly developing

Digital transformation is much more than a buzzword: it is a prime focus for businesses across all sectors – and will continue to be so in an economic downturn, to create efficiency and unlock value.

Although business change is often unpredictable – as the recent global supply chain crisis and Covid-19 pandemic have shown – those that successfully deliver digital transformation can enjoy competitive advantage. However, with this transformation comes rapidly developing digital regulation and legislation that has particular implications for software compliance in terms of both software licensing and wider regulatory obligations.

Further Osborne Clarke Insights

> Digital Transformation Projects | The Legal Angles
> Data-driven business models: the role of legal teams in delivering success

Harmonising software portfolios from a compliance perspective

To carry out successful digital transformation projects at the pace required in today’s world, the first step for companies is to harmonise their software portfolio, which brings significant advantages from a compliance perspective. Disparate software architecture and legacy systems can make these projects extremely challenging to complete from both a technical and legal perspective, let alone at an acceptable pace. Software portfolios that are streamlined lead to more single sourcing (that is, one-provider strategies) and, therefore, dependencies. However, the risk of relying on a single provider must be acknowledged and managed; it is a trade-off for an otherwise harmonised software portfolio.

Although a company with a harmonised portfolio will use fewer software components, it will still face the challenge of managing its compliance with a range of international licensing requirements and regulatory obligations in a globalised economy. This is particularly so in the EU which is legislating to make compliance with certain software-related laws part of a company's core regulatory obligations, including the integrity of datasets, software updates and cybersecurity risk assessments.

Although these issues are on the horizon at EU level, as with many areas of digital regulation, individual jurisdictions are moving faster than larger regulatory blocs can.

For example, German law requires companies to have a clean software portfolio with clear rules and regulations on companies’ licence rights and restrictions. The Urheberrechtsgesetz (Copyright Act) stipulates that the copyright owner holds all rights to the software. It is therefore important that companies undertaking a digital transformation, and using third-party software to do so, ensure that they can use that software for the purposes that their digitalised business model will require.

Companies need to structure their software licence agreements and implementation agreements to gain maximum flexibility and futureproof their business against changes which might be required.

Open-source software licensing

Compliance concerns apply not only to “standard” software but also to more modern ways of software programming, such as the licensing of open-source software (OSS). The most important features of OSS are that it is open access to the source code and there is the possibility for anyone to change or improve the code, in each case with no consideration owed to the code's originator. The originator essentially grants a non-exclusive right of use to everyone.

However, free software licensing does not imply unfettered use. OSS usually contains a variety of licence provisions; for example, the requirement to cite the originator’s credentials within software using the code or the “copyleft” principle (the method of granting permission for anyone to use copyrighted property freely, with the same rights being preserved in derivative works).

Failure to comply with these provisions may not only give grounds for cease-and-desist orders or other injunctive relief but also be a fundamental breach of the conventions of the "open source" community and the code of conduct at the heart of the development industry.

The current hype around OSS compliance is driven partly by environmental, social and governance requirements, and also by a general trend towards open infrastructures and specific EU-wide and national level projects supporting OSS.

The EU is particularly focused on supporting interoperability between different technologies, including OSS. A harmonised approach has not yet been formally proposed, but, as is often the case, Member States are introducing their own requirements. For example, in Germany, there are discussions on making the use of OSS mandatory for public administration, which should remove barriers to integration and continued software development in the governance sector.

Risk of OSS non-compliance

Apart from the potential to paralyse a huge number of products (more than 50% of the software in today’s cars is OSS and each car has more software on board than the space shuttles), the risks associated with non-compliance with OSS licence requirements must not be underestimated. OSS noncompliance may lead to a breach of copyright law and in some jurisdictions could potentially lead to personal liability for directors if there is no process in place to ensure compliance.

So, while software compliance sounds dull, it is not to be underestimated both to avoid substantial risk and also to simplify and speed up digital transformation. It should therefore be at the forefront of any digital transformation strategy.

Authors

Ulrich Bäumer Partner, Germany ulrich.baumer@osborneclarke.com +49 221 5108 4168

Dawn Troman Associate Director, UK dawn.troman@osborneclarke.com +44 118 925 2046

Lina Böcker Partner, Germany

lina.boecker@osborneclarke.com +49 221 5108 4434

Thomas Stables Associate, UK thomas.stables@osborneclarke.com +44 207 105 7928

Further Osborne Clarke Insights

> Digital Transformation Projects | The Legal Angles
> Data-driven business models: the role of legal teams in delivering success
Technology
The importance of software compliance in digital transformation
Is the proposed European AI Act innovation friendly?
How is EU cybersecurity law affecting IoT product design?
Will mid-market tech M&A buck the trend in a downturn?
The rise of IP disputes in relation to NFTs
The new era for data regulation and what it means for the tech sector
Back to Foreword
Back to top