Single Blog Title

This is a single blog caption

License Overruns and Corporate Liability in ERP Systems

License Overruns and Corporate Liability in ERP Systems

What is license overrunning in ERP systems, and what legal risks do companies and managers face? A comprehensive legal guide examining ERP license violations from the perspectives of the Turkish Copyright Law, Turkish Code of Obligations, Turkish Commercial Code, Personal Data Protection Law, and criminal law.

ERP, or Enterprise Resource Planning, refers to a software infrastructure that integrates a company's core business processes—such as accounting, finance, purchasing, project management, risk and regulatory compliance, supply chain, production, and human resources—on a single platform. ERP systems centralize data flow between different departments and help the company operate with a "single data source" logic. Therefore, an ERP license dispute has far more serious consequences than a simple desktop software dispute, because the issue directly affects the company's financial records, inventory movements, production planning, payroll flow, and management reporting.

In Turkish law, computer programs are explicitly protected as works. According to the Law on Intellectual and Artistic Works, computer programs are considered scientific and literary works; furthermore, the installation, viewing, execution, transmission, and storage of the program are also considered within the scope of the copyright holder's right of reproduction. Therefore, exceeding an ERP license is not merely a narrow technical issue such as "too many users were created"; depending on the nature of the specific case, it can be a form of infringement falling under copyright law as unauthorized reproduction, unauthorized use, or exceeding the license limit.

Legally, the concept of ERP license overrun refers to exceeding the usage limits defined in the ERP contract. These limits are sometimes determined by the number of users, sometimes by module scope, sometimes by company/branch-based usage area, sometimes by the distinction between test and production environments, and sometimes by the integration and access model. In other words, a license overrun problem arises when a company exceeds the economic and technical scope defined in the contract for its ERP license. Because ERP systems integrate numerous business processes into a single platform, this overrun often falls under the responsibility not only of the IT department but also of finance, accounting, purchasing, and senior management.

Why is exceeding an ERP license more serious than a traditional software breach?

The most important reason for this is that the ERP is embedded in the company's core operations. Since daily business activities such as accounting, finance, purchasing, project management, supply chain, and production are conducted through the ERP, any licensing issue with this software becomes not just a copyright matter, but also a problem of business record keeping and corporate governance. Because the company's ability to plan, report, and audit its financial results often depends on the ERP, exceeding the ERP license makes not only the company's software compliance but also its internal control architecture questionable.

Article 64 of the Turkish Commercial Code mandates that every merchant maintain commercial books and records that clearly reflect the economic and financial status of the business, and keep copies of documents related to the business. When ERP systems become the de facto carriers of this record-keeping system, unlicensed or license-overuse practices raise additional questions about how the discipline of bookkeeping, documentation, data flow, and reporting is established. The problem here is not only directed at the software manufacturer but also grows in terms of the company's own accountability. Therefore, ERP license overuse, unlike a classic single computer license breach, makes the discussion of corporate responsibility central.

Consequences of ERP license overuse from the FSEK (Intellectual Property Rights Law) perspective

According to Article 68 of the Copyright Law, the copyright holder may demand a fee, up to three times the amount they would have demanded if a contract had been made or the current market value, from those who process, reproduce, distribute, represent, or publicly transmit a work without obtaining written permission from the copyright holder in accordance with the law. This provision is crucial in the context of ERP license overruns. This is because ERP contracts are often high-cost, enterprise-oriented, modular, and user-based. Therefore, the hypothetical license fee or current market value demanded in case of exceeding the license limit can be much higher compared to ordinary office software.

Article 66 of the FSEK (Law on Intellectual and Artistic Works) is also important in terms of corporate responsibility. The law stipulates that a person whose moral and financial rights have been violated can sue for the cessation of the infringement; and if the infringement was committed by representatives or employees of a business during the performance of the service, a lawsuit can also be filed against the business owner, and no fault is required in this case. Since ERP license overruns often occur through the actions of company employees, the IT department, ERP consultants, or management instructions, the first party to face liability to the outside world is usually the legal entity itself. The defense of "the consultant committed this overrun" or "IT didn't notice it" does not automatically eliminate the company's risk to the rights holder.

Contractual liability and the Turkish Code of Obligations aspect

ERP license overuse is often seen not only as copyright infringement but also as a breach of the license agreement. According to Article 112 of the Turkish Code of Obligations, if a debt is not performed at all or properly, the debtor is obligated to compensate the creditor for the resulting damages unless they can prove their innocence. If the ERP contract specifies a number of users, company-based usage, module limits, location, integration, or maintenance/support regime, exceeding these limits strengthens the argument of breach of contract under private law. In this case, the rights holder can rely not only on the Copyright Law but also on the logic of contractual damage compensation.

Article 49 of the Turkish Code of Obligations stipulates that whoever causes harm to another through a negligent and unlawful act is obligated to compensate for that harm. If the ERP license overrun is carried out intentionally, knowingly, or with gross negligence; for example, if license warnings are knowingly ignored, if users contrary to the contract are allowed access to the system, or if the company establishes a technical structure that misleads the rights holder, a claim for compensation based on tort may arise. Especially due to the intensive commercial use of ERP, the items of damage are sometimes not limited only to the license fee; audit expenses, system conversion costs, and loss of business continuity may also be part of the dispute.

According to Article 116 of the Turkish Code of Obligations, even if the debtor has entrusted the performance of the obligation to auxiliary personnel, they are still liable for any damages caused to the other party by these auxiliary personnel during the execution of the work. In ERP projects, the use of external consultants, implementation firms, integrators, or outsourced IT teams is very common. Therefore, the fact that the license breach technically occurred through a consultant does not always protect the company. While the original license relationship between the company and the rights holder continues, a breach through an external consultant often does not absolve the company of external liability; it only creates internal disputes regarding recourse and sharing of fault.

Will the employee, the IT department, and the ERP consultant be held responsible?

On an internal company level, yes, it's possible. According to Article 396 of the Turkish Code of Obligations, an employee is obligated to perform their assigned work diligently and to act faithfully in protecting the employer's legitimate interests; they must also use the employer's technical systems properly. If an ERP manager, system administrator, finance department official, or consultant knows that the license limit has been exceeded, conceals it, fails to report it, or knowingly allows it to continue, this could lead to internal liability and, if necessary, disciplinary action/termination for the employer. However, the distribution of fault is determined by the specific circumstances of the case; simply working in the IT department does not automatically create personal responsibility.

Article 66 of the Turkish Code of Obligations regulates the employer's liability. As a rule, a company is liable for damages caused to third parties by its employees in the performance of assigned tasks; however, it can be absolved if it proves that it exercised due diligence in selection, instruction, supervision, and control. This provision is crucial in ERP license overrun cases because in most instances, the company has left license management to its employees, ERP administrator, or IT department. The company's ground for absolvation is not the "I didn't know" defense, but rather demonstrating that it has established a license inventory, user control, internal audit, warning mechanism, and contract management system.

Responsibility of managers and company bodies

ERP license overuse is not solely a problem for operations units. Article 369 of the Turkish Commercial Code (TTK) mandates that board members and third parties responsible for management perform their duties with the diligence of a prudent manager and protect the company's interests in accordance with the rules of honesty. Article 553 of the TTK stipulates that in cases of negligent breach of obligations arising from the law and the articles of association, founders, board members, managers, and liquidators may be held liable to the company, shareholders, and creditors. Since ERP is at the heart of financial record-keeping and management reporting, if ongoing license overuse is known to senior management or ignored when it should have been known through reasonable oversight, the matter can escalate to managerial liability.

Therefore, in ERP license overrun cases, the primary legal question is not simply "how many users were excess?" The more important question is, "how did the company manage this risk, who reported it, who turned a blind eye, and which internal control mechanisms failed?" When the record-keeping requirement in Article 64 of the Turkish Commercial Code and the duty of care in Article 369 are considered together, it becomes clear that license management should be linked to corporate procedures within the company. Where ERP affects finance, accounting, and purchasing functions, leaving license compliance to random or purely technical initiative is not a defensible model from a managerial perspective.

Personal Data Protection Law (KVKK) and data security aspect

ERP systems almost always process personal data. Employee data, payrolls, customer records, supplier information, current account transactions, and sometimes health or sensitive data can be found in the ERP infrastructure. Article 10 of the KVKK (Turkish Personal Data Protection Law) imposes an obligation on the data controller to inform the public, while Article 12 imposes an obligation to take necessary technical and administrative measures to prevent the unlawful processing and access of personal data. Exceeding a license does not directly constitute a violation of the KVKK; however, unlicensed or unauthorized extended ERP use can disrupt authorization management, weaken logging discipline, make update and support processes unclear, or create data security vulnerabilities, thus exposing the company to data protection risks.

Practices such as creating extra users in ERP systems, not deleting existing users, transferring test data to production, or group companies sharing the same license and accessing the same database can create problems not only in terms of the license agreement but also in terms of access rights and personal data security. The law expects the data controller to conduct or have conducted the necessary audits. Therefore, exceeding the ERP license sometimes starts as a "copyright claim" for the company, but it can also turn into a "vulnerability to internal audit and the Personal Data Protection Law". This is a conclusion drawn from evaluating the technical-administrative measures obligation in the Personal Data Protection Law together with the functional reality of the ERP system.

Evidence, internal audit, and proof

In ERP license overrun disputes, electronic data often forms the backbone of proof. According to Article 199 of the Turkish Code of Civil Procedure, electronic data and similar information carriers suitable for proving the facts in dispute are considered documents. Therefore, ERP user logs, license server records, usage reports based on company code/customer number, activation history, consultant emails, maintenance contracts, and authorization tables are important evidence in legal proceedings. In ERP disputes, the question of "how the system was actually used" is as important as "it was written in the contract.".

Therefore, the first thing a company should do when a problem arises is not to destroy the data, but to preserve the evidence. Deleting logs, subsequently correcting user records, or restructuring the system in a way that does not reflect the truth before an audit, when suspicion of ERP license overrun arises, can weaken rather than strengthen the defense. The legally correct approach is to present the license inventory, user list, contract scope, external consultant instructions, and actual usage of the ERP infrastructure together. Article 199 of the Turkish Code of Civil Procedure, which considers electronic data as a document, clearly shows why such internal reviews must be conducted carefully.

Is there a criminal law aspect?

Yes, depending on the specific case. Article 71 of the Copyright Law stipulates penalties for those who process, reproduce, distribute, publish, possess for commercial purposes, or store a work without the written permission of the copyright holder. Article 72 of the Copyright Law also imposes a separate penalty for software or hardware designed to disable protective programs created to prevent the unlawful reproduction of computer programs. Not every ERP license overrun automatically means a criminal case; however, the risk of penalties becomes more apparent when the license limit is deliberately exceeded, protection mechanisms are disabled, or fraudulent activation methods are used.

The critical principle here is Article 20 of the Turkish Penal Code: criminal liability is personal; as a rule, no criminal sanctions are applied to legal entities, but security measures are reserved. This means that in an ERP license overrun case, the threat of punishment is often directed not at the company as a legal entity, but at the individuals who knowingly participated in the act, i.e., the responsible manager, ERP manager, IT decision-maker, or those who gave explicit instructions. Nevertheless, it should not be assumed that the investigation will not affect the company; because evidence gathering, device inspection, and record audit are often carried out on the company's infrastructure.

What should companies do?

The way to reduce the risk of ERP license overruns is not to create defenses after a problem arises, but to establish a corporate license management system before problems occur. The company should have an up-to-date license inventory, user matrix, module-based rights list, group company usage policy, testing/production separation, external consultant access protocol, and internal audit schedule. Considering that ERP is central to financial records and reporting, managing this area with a "IT will handle it anyway" approach creates a legally weak foundation. When Articles 64, 369, and 553 of the Turkish Commercial Code are read together, it is clear that ERP license management should be made a part of corporate governance.

Secondly, companies should not leave license verification solely to the notice from the software manufacturer. If external consultants, integrators, and application support teams are used in ERP projects, clear responsibility sharing should be established in the contracts; risks arising from the actions of assisting parties should be taken into account in accordance with Article 116 of the Turkish Code of Obligations. Including explicit provisions in the contract with the external consultant stating that "the usage model will be established in accordance with the license agreement," "the risk of exceeding the limit will be reported," and "the system design will not be expanded in violation of the contract" creates a significant advantage for the company in any subsequent recourse and fault disputes.

Thirdly, in ERP license disputes, the goal is not only to clear the past but also to shape the future. When a dispute arises with the rights holder, the company must consider a plan for transitioning to a licensed version, reducing users, narrowing modules, separating group companies, and scheduling data migration all together. This is because, from the perspective of the Turkish Copyright Law (FSEK), not only past compensation but also stopping the ongoing infringement is important. Since "let's shut it down tomorrow" is often not possible with core software like ERP, the most appropriate strategy is to establish both a legal and technical transition plan in the same file. This is a practical result of evaluating the cost and reference logic of the FSEK together with the operational reality of the ERP.

Conclusion

In ERP systems, license overruns are a more serious and multifaceted legal problem than a classic software license dispute. This is because ERP systems integrate accounting, finance, procurement, production, human resources, and reporting into a single system. Therefore, license overruns can create a risk of copyright infringement and high damages/compensation under the Turkish Copyright Law; breach of contract and tort under the Turkish Code of Obligations; record-keeping and managerial duty under the Turkish Commercial Code; data security and access control under the Turkish Personal Data Protection Law; and, depending on the specific circumstances, personal liability under criminal law.

Therefore, the right question for companies is not "how many users have been overused?" The real question is: what is the limit in the ERP license agreement, how did the actual usage exceed this limit, who knew about this overuse, who reported it, and what organizational structure did the company establish to prevent it? If the answers are strong, the license overuse remains a manageable legal risk. If the answers are weak, the ERP license overuse ceases to be merely a dispute with the software provider; it becomes a larger case that questions the company's internal control, governance, and compliance capacity.

Frequently Asked Questions

Is exceeding an ERP license simply about opening too many users?
No. Legally, exceeding a license means exceeding the scope of use defined in the contract. This scope can be established through user, module, company-based usage, access model, or system environment. Because ERP systems bring together core business processes like finance, accounting, purchasing, and production on a single platform, the impact of this exceeding the license is broader.

Is the company directly liable for exceeding the ERP license limit?
In terms of external relations, the answer is often yes. Article 66 of the Turkish Copyright Law states that if the violation is committed by company representatives or employees during the service, the business owner may also be sued. In internal relations, however, a separate assessment of fault and recourse may be made regarding employees, the IT department, consultants, and managers.

Can exceeding an ERP license lead to a criminal case?
Not always. However, criminal risk may arise, especially in cases of deliberate, systematic use or use that exceeds protective measures, falling under Articles 71 and 72 of the Turkish Copyright Law. Since criminal liability is personal, assessment is often made based on the individuals involved in the act.

Can ERP logs and user records be used as evidence in court?
Yes. Article 199 of the Turkish Code of Civil Procedure recognizes data in electronic form as valid documents. Therefore, ERP user logs, license reports, activation records, and email correspondence can constitute significant evidence in legal proceedings.

Leave a Reply

Call Now Button