Two files closed twenty-one days apart

On 30 July the Bundeskartellamt published the answer to a question it had spent months putting to SAP customers and to the wider market: can you get your data out. Its finding was that you can. Celonis SE, the process mining company whose complaint opened the file, said that answers a narrower question than the one it had asked.

Twenty-one days earlier the European Commission had also finished with SAP, and arrived at the opposite kind of outcome. On 9 July it accepted a set of commitments from the company under Article 9 of Regulation 1/2003 and made them legally binding for ten years, worldwide. Two European competition authorities closed on the same vendor inside three weeks, and only one of them required SAP to change anything at all.

The decision that required nothing

The German authority found no case to bring today, which is not the same as a guarantee for tomorrow. The Bundeskartellamt concluded its preliminary investigation into SAP SE of Walldorf on 30 July and stated that it does not currently intend to initiate abuse proceedings. SAP welcomed the decision the same day.

The complaint had come from Celonis SE and other software providers, and alleged that SAP restricted access to data held in its ERP systems, to the disadvantage of customers and third parties and to the benefit of SAP Signavio, its own process mining product. The authority found that various permissible and practical ways to extract data from SAP systems remain available, and that SAP's new API Policy, published in spring 2026, does not remove methods that were previously permitted. On the pricing complaint it found no proof that Signavio is offered at artificially low prices to drive out rivals, noting that SAP offers a range of licensing models including options without Signavio at a lower price.

The words that matter most to you are the ones about time. Andreas Mundt, the authority's president, said it will continue to monitor the market closely and reserved the right to intervene later. Celonis remains unconvinced on exactly that point, arguing that SAP has not confirmed extraction will stay viable under its new policies. Separately, the suit Celonis filed in San Francisco in March 2025 and SAP's patent counterclaim are both still unresolved.

The decision that required ten years of it

The older decision is the one that reaches into your contract. On 9 July the Commission accepted and made binding a set of commitments addressing its preliminary concerns that SAP had abused a dominant position in the aftermarket for maintenance and support of its on-premises ERP software. Four practices were at issue.

Customers found it difficult to terminate maintenance and support on software licences they were not using. Those who stopped support and later resumed it faced significant reinstatement fees. Minimum contract periods, during which termination was not possible, were systematically extended. And customers were obliged to buy maintenance from SAP for all of their on-premises ERP software and to apply the same type of support across the entire landscape, which ruled out mixed arrangements.

Against each of those, SAP committed to clarify how a customer may separate its SAP landscape and choose different maintenance options for different parts of it, to permit licence termination in defined circumstances, to widen access to simplified single-metric contracts, to clarify the minimum term rules so that adding licences does not trigger a new one, to eliminate reinstatement fees and lower back-maintenance charges, and to run an internal mechanism for handling complaints about compliance. The package was market-tested between November and December 2025, after which SAP adjusted its first offer. It runs for ten years, applies worldwide to current and future customers, and is overseen by an independent monitoring trustee. It covers on-premises maintenance policies only and does not concern SAP's cloud offerings. An Article 9 decision closes a case without any finding that the law was broken, and the obligations bind regardless.

Contract risk is reachable, product risk is not

Set the two outcomes side by side and a line appears that is worth carrying to every other vendor you depend on. Where the objection was to contract terms, meaning fees, notice periods and bundling, the regulator moved, and moved hard enough to bind SAP for a decade. Where the objection was to the product, meaning APIs and what the software will let you take out of it, the regulator looked closely and left it alone.

That asymmetry is not a quirk of these two files. Contract terms are written down, they are comparable between customers, and they can be repaired by ordering different words. Technical access is a design question, and an authority that ordered a different API would be specifying the product rather than policing the market. The working rule this leaves you with is blunt: lock-in that lives in your contract may eventually be fixed for you, and lock-in that lives in the product will not be.

It also reframes what was decided on 30 July. The finding was measured against SAP's spring 2026 API Policy, a document SAP wrote and can rewrite, and it says that the new policy did not withdraw what the old one allowed. That is a comparison against a baseline. It is not a floor placed underneath one.

The window is open and nobody will write to you

The commitments cover current and future SAP customers and a trustee monitors them, but none of that edits your agreement on your behalf. Before your next renewal, put the six commitment areas in a letter and ask which ones your contract already reflects, naming reinstatement fees and split maintenance explicitly. If you are paying full support on licences nobody has logged into for a year, that is now a conversation with a legal basis rather than a favour to request. Ten years sounds long enough to postpone, and it is the same ten years in which every renewal you sign will be drafted.

Then treat the data question as a priced risk rather than a closed one. Run an extraction test against the systems you would actually need to leave from, record what it cost and what it returned, and put a re-test in the calendar against the next revision of the API Policy rather than the next headline. An authority monitoring a market is not the same thing as a contract protecting you, and only one of those two is yours to write.