Forscope

When law outpaces practice: The pre-owned software in public procurement in the EU

Public procurement often excludes used software licenses despite clear EU law and court rulings confirming their legality and economic benefits. This conservative practice leads to unnecessary overspending of public funds, even though secondary-market licenses are widely used, fully supported, and legally secure when properly documented.

As digital transformation accelerates across various sectors, organizations are increasingly caught in the trap of rising software costs. Public institutions, in particular, find themselves in a peculiar bind, driven by the urgent need for digitalization while simultaneously facing pressure to continuously reduce expenses. In the legal framework, it has become common to include the option of purchasing pre-owned software as an effective way to reconcile these constraints. However, public procurement practices often lag behind the possibilities afforded by current regulations.

There remain many misconceptions, misunderstandings, and questions surrounding the use of the secondary software market. A particularly sensitive area is the role of “used” software in public procurement. The caution displayed by decision-makers is striking, given that there have already been rulings indicating that contracting authorities have, without justification, excluded used software from procurement procedures.

Law vs. practice

The legality of purchasing software from the secondary market is confirmed by the European Parliament Directive of 23 April 2009 and a ruling by the Court of Justice of the European Union (CJEU) issued three years later. The conditions for transferring software ownership include: acquiring a perpetual license, ensuring that the software is no longer used by the previous owner, and limiting the transaction to the territory of the European Economic Area (EEA).

Since 1991, within the European Economic Community (EEC) and later the European Union, regulations have allowed for the legal trade of used software across the entire community. However, the secondary market only saw significant growth after 2012, following the CJEU ruling in case C‑128/11, which fully confirmed what had long been implied by the European directive.

Today, the very possibility of trading used software is no longer questioned, and leading software vendors have accepted it. Many commercial entities and individual consumers widely take advantage of this legally compliant form of cost savings when acquiring software licenses. Yet, the public sector often remains highly conservative: those managing public funds frequently have no qualms about purchasing software at several times the cost necessary. One reason for this is a persistent lack of knowledge – officials often assume that “used” means “old,” unsupported, or inferior. In practice, however, approximately 80% of the secondary software market consists of the latest Microsoft programs, which are still fully supported by the vendor. This trend has been reinforced by the migration to cloud-based solutions: large clients resell tens of thousands of perpetual licenses, which are then replaced with subscription-based models.

At the same time, the public sector is already a significant user of second-hand software. Many entities – including those subject to NIS2 cybersecurity management requirements, such as energy infrastructure, hospitals, emergency services, police, and intelligence agencies – utilize it. These institutions typically have dedicated cybersecurity risk management specialists who can easily recognize that the savings from lower license costs can be redirected to improve security in other areas, making the purchase a rational choice.

A conservative approach is more common in smaller organizations lacking sufficient IT, legal, or cybersecurity expertise. In extreme cases, these processes are outsourced to external agencies paid on a flat-fee basis for managing public procurement. Such agencies are often not incentivized to spend time analyzing potential savings or verifying whether alternative solutions are equally secure.

Established practices within the EU

Good practices already exist within the legal frameworks of several European countries, including Germany and the Czech Republic. In both cases, supervisory authorities have issued decisions requiring contracting authorities to accept bids that include secondary software. This approach has enabled more efficient management of public funds – easing pressure on public budgets and taxpayers, while freeing up resources that can be redirected to other essential public needs across Europe.

Public officials in these countries are now well aware that offers including licenses from the secondary market must be permitted. Procurement procedures should therefore be conducted in a way that avoids excuses or artificial restrictions, such as requiring identical – but more expensive – software purchased directly from the manufacturer, for example through mandatory registration in a specific licensing portal. At the same time, contracting authorities have had to learn how to formulate appropriate documentation requirements for used licenses, in order to avoid potential fraud. Just as it is standard practice to assign a new license to the contracting authority’s account in the vendor’s portal, it is now widely understood that this may not always be possible in the case of used licenses. Instead, authorities require copies of documents confirming the legal origin of the licenses and verify their internal consistency.

Nevertheless, in many EU countries public procurers still remain on the sidelines of this market and often – irrationally – prefer new licenses, even if they are up to five times more expensive than previously owned ones. In doing so, they unjustifiably “waste” limited public funds derived from taxpayers.

Such an approach is, of course, beneficial to the largest software vendors. It is precisely in relation to their products that the secondary market for perpetual licenses functions most effectively within the EU. However, many entities still fail to recognize that the so-called residual value of a perpetual license is a legitimate element of the purchase economics. Buyers can take this value into account from the outset, and it may even justify choosing a more expensive product in exchange for a potentially higher resale value in the future.

Public contracting authorities and the principle of equal treatment

Although public contracting authorities operate within predefined budgets, they typically lack in-depth expertise in software law and – unlike commercial entities – are bound by strict procurement regulations, including the principle of equal treatment.

Private entities can relatively easily manage the risk of purchasing improperly licensed new or used software: they select trusted suppliers and reject suspiciously low prices. The public sector faces greater challenges in this regard.

Instead of requiring documentation that confirms the legal origin of the software and the contractor’s qualifications, a common outcome is the outright rejection of bids that include used licenses. This, in turn, unnecessarily multiplies the cost of public procurement. Importantly, this issue usually remains outside the interest of public opinion, the media, and auditors.

A similar pattern can be observed in insolvency proceedings, where the value of software – statistically representing around 1% of companies’ assets – is often overlooked and typically not monetized, resulting in financial losses for creditors.

Germany: Vergabekammer Münster (1 March 2016, VK 1-02/16)

The previously mentioned German example refers specifically to a first-instance ruling of the Westphalian Public Procurement Chamber (Vergabekammer Westfalen) at the District Government of Münster (Bezirksregierung Münster), dated 1 March 2016, case no. VK 1-02/16. The supervisory authority unequivocally rejected the practice of requiring exclusively “new licenses,” specifying a particular licensing program, and restricting economic competition to a narrow group of Licensed Solution Partners (LSPs).

According to the ruling:

When purchasing volume software licenses, a contracting authority may not limit itself exclusively to new licenses, thereby excluding the supply of used licenses solely in order to avoid the risk that the software manufacturer might assert claims for injunctive relief or damages in connection with the use of software based on used licenses. This risk can be mitigated by requiring bidders to provide appropriate evidence of the exhaustion of the right of distribution or by including an indemnification clause in the contract.

The ruling generally criticized the lack of transparency, in particular the combination of requirements relating to new licenses and a specific licensing program, which led to a significant restriction of economic competition.

At the same time, the Chamber found the advantages of new licenses invoked by the contracting authority to be insufficient to justify their exclusive requirement. These included, in particular, features such as access to an online portal, comprehensive license management, a single installation key for software purchased both currently and in the future, and the ability to order smaller quantities of software without renegotiating the contract. The ruling concluded that these are not characteristics of the subject matter of the public contract, but rather conditions governing how the product to be acquired is made available.

Czech Republic: ÚOHS decision (21 July 2021, 25008/2021/500/AIv)

In the Czech Republic, on 21 July 2021, the Office for the Protection of Competition (Úřad pro ochranu hospodářské soutěže, ÚOHS) – which also oversees public procurement – issued decision no. 25008/2021/500/AIv. The decision explicitly refers to the German ruling discussed above.

The central thesis is that, since software does not “wear out,” excluding a contractor solely because of one distinguishing factor – the absence of registration of used software in the manufacturer’s tool or portal – constitutes unjustified and, in fact, disproportionate discrimination. This is even more evident where the contractor offers an alternative management tool.

It is worth noting that public contracting authorities typically use software asset management tools from various vendors whose solutions they operate. Moreover, even within a single tool, they rarely have all licenses from one manufacturer registered – because for many licensing programs, manufacturers themselves do not allow licenses to be entered into such portals.

For example, in the case of Microsoft, licenses acquired outside volume licensing – such as OEM or retail licenses – remain outside the official Microsoft 365 administrative portal.

The authority therefore concluded that it is disproportionate to exclude a contractor offering an identical, legally sourced software product solely because the manufacturer does not provide support for registering those licenses in its own portal.

This approach significantly limits the manufacturer’s control over market conditions and price levels. At the same time, it exerts real pressure on manufacturers to reduce overall pricing – especially since manufacturers (unlike brokers operating on the secondary market) enjoy greater flexibility in shaping final prices. They do not incur costs related to sourcing opportunities, acquiring, processing, and verifying documentation, or purchasing licenses themselves. Their primary expense is product development, which in practice is distributed unevenly across global markets.

A small but telling detail: the German ruling spans 18 pages, while the Czech decision runs to 61 pages.

The case of the city of Most: A procurement limited to the secondary market

A particularly noteworthy example is the public procurement launched by the Czech city of Most, which was explicitly limited to software from the secondary market – because the funds allocated in the municipal budget did not match the prices of new licenses.

Although, in theory, one might question whether such an approach constitutes discrimination against new licenses, in practice this should not pose a problem. New licenses can easily be “turned into” used licenses by first assigning them to the seller and only then reselling them. Similar mechanisms are common, for example, in car dealerships that must meet sales quotas imposed by manufacturers. Toward the end of a reporting period, dealers often register new vehicles in their own name and subsequently resell them in order to meet targets and secure higher discounts.

From a strictly legal perspective, however, it would likely have been “cleaner” to announce a procurement for the required type of software without imposing a specific licensing model – including the exclusive requirement to source licenses from the secondary market.

What comes next?

The key question is which direction public procurement policies will take: whether authorities will gradually follow approaches already adopted in countries such as Germany and the Czech Republic, or whether, in practice, procurement decisions will continue to prioritize the protection of software vendors’ profit models – resulting in higher expenditures for public administrations.

It is worth noting that many public authorities across Europe already purchase software from the secondary market. Others formally reject such solutions; however, this does not necessarily mean that used licenses are absent within their organizations. In many cases, they are acquired indirectly – for example, as part of hardware purchases, a practice that has become common even among the largest hardware distributors.

At the same time, public entities may also encounter issues with software acquired as “new” that is, in fact, improperly licensed, or where an incorrect type or number of licenses has been purchased.

Caution – yes; exclusion of used-license offers – no

Given the varying quality of services and products on the market, public contracting authorities should exercise caution, as the software market – unfortunately, both for used and new software – does include dishonest sellers.

When purchasing new software, contracting authorities should always insist that licenses be assigned directly to their account with the manufacturer. In the case of used software, they should instead require documentation that transparently confirms the software’s lawful origin.

At the same time, such documentation requirements must remain proportionate: sufficient to establish a coherent chain of provenance, but without abusing formal requirements as a means of eliminating bids involving used software. It should be borne in mind that many licenses have long histories – spanning 10 or even 20 years -–and that complete documentation of successive upgrades may amount to hundreds of pages.

All submitted information should be internally consistent. However, there are legitimate doubts as to the proportionality of requiring all documents in original form, notarized deeds, or the repeated proof of the same facts by multiple types of evidence. A standard of evidentiary quality sufficient, for example, to support a criminal conviction should also be sufficient in this context.