The German Federal Cartel Office has declined to open formal abuse proceedings against SAP after finding no evidence the software giant unfairly blocks customers from extracting their data for use with competing applications. The Bundeskartellamt announced Thursday it won't initiate antitrust action following a preliminary investigation, though it will continue watching what it calls a dynamic market. The inquiry began after software companies, including process mining developer Celonis, complained that SAP makes it hard for customers and third parties to access data from its ERP systems while favoring its own Signavio process mining tool.
The German regulator found that sufficient data extraction options remain available despite SAP's controversial API policy changes in April 2025, which triggered customer backlash. Bundeskartellamt President Andreas Mundt said the investigation turned up no signs of exclusionary practices that would violate competition law, noting that data extraction methods that were previously allowed are still accessible. SAP welcomed the decision, confirming that customers and partners have adequate technical options to pull data from SAP systems and use it with other vendors' solutions. Celonis issued a statement warning that the ruling rests on the assumption that data extraction for software from providers like Celonis will remain possible under SAP's new API policy, something SAP hasn't explicitly confirmed.
"Companies must generally also be able to use their own data in third-party applications," Mundt said, adding that with large software platforms, non-discriminatory data access is essential to effective competition. Celonis stated it remains convinced that company data belongs entirely to the customers who create it, and no provider should limit a company's ability to extract its own information or block users from working with third-party vendors. The German authority's decision doesn't settle the matter globally. Celonis is challenging SAP's data extraction policies in a California court, where it filed a complaint in March 2025 alleging SAP uses its software to prevent customers from sharing their own data with third-party providers without paying prohibitively expensive fees. A judge dismissed some claims but left three for trial, originally scheduled for December 2026. Celonis has since expanded its complaint to 10 claims, pushing the trial to 2027, and says its litigation continues to uncover evidence of anticompetitive conduct and intellectual property theft.
Industry analysts warn the regulator's narrow legal decision shouldn't be mistaken for validation of SAP's data access model. Scott Bickley, an advisory fellow at Info-Tech Research, said CIOs may technically retain vendor choice but face expensive replication architectures, API rate and volume restrictions, additional platform costs, performance lags, and data migration expenses, all dependent on an SAP-approved technical pattern that can shift. Kaan Dincer, CEO of data migration vendor Settle, emphasized that the regulator answered a narrow legal question, not the operational one—declining to open proceedings means the friction wasn't proven anticompetitive, but doesn't mean the friction isn't real. Justin Greis, CEO of consulting firm Acceligence, urged enterprises to keep asking hard questions of ERP vendors about how easy it is to access their own operational data, integrate third-party applications, and migrate workloads if business priorities change.
The bigger lesson extends beyond SAP to the entire ERP landscape. Dincer recommended CIOs negotiate export rights, API access on reasonable terms, and data model documentation before signing contracts, and test real extraction while the vendor still wants renewal. He noted that ERP data now feeds analytics and automation outside the system of record, so access friction that used to be an IT annoyance is becoming a strategy constraint. Srinivasulu Reddy Battu, a senior software engineer with ZT Systems, pointed out that Oracle, Microsoft, and every major ERP vendor sits on massive amounts of business data, and if any of them tightened API policies tomorrow, most companies would be scrambling. The cost of your eventual exit is set the day you implement, not the day you leave.

