What the regulators actually decided
On July 30, SAP said it welcomed the German Federal Cartel Office's decision to conclude its preliminary inquiries and not to initiate abuse proceedings. The complaint had been lodged by rival Celonis and centered on whether SAP made it too hard for customers to pull their own data out of SAP systems for use in competing tools. The Bundeskartellamt found the opposite. In its assessment, "SAP customers and partners have sufficient and permissible technical options to extract data from SAP systems and use it in solutions from other providers," and "the SAP API Policy does not restrict these capabilities."
The authority also addressed process mining directly, the market where Celonis competes most sharply with SAP's Signavio. It concluded that SAP offers a range of competition-compliant licensing models, including options that do not require customers to buy SAP Signavio. Taken together, the regulator found no basis to treat SAP's data-access and licensing practices as an abuse of market power. For SAP the outcome removes a cloud that had hung over its data strategy at the exact moment it is positioning Business Data Cloud as the governed layer beneath enterprise AI.
The second reprieve in a month
This decision did not arrive in isolation. It followed the European Commission's conclusion, earlier in July, of a separate investigation into SAP's maintenance and support policies for on-premise software. Two regulatory bodies examining two different theories of harm, data access and aftermarket maintenance, both stepped back from action against SAP inside a single month. For a company navigating the largest platform transition in its history, clearing both reviews at once removes a meaningful source of legal and reputational uncertainty as it pushes customers toward cloud contracts.
We would read the double clearance as a green light for SAP's commercial model rather than a settlement of the underlying tension. The Commission's process, according to coverage of the case, involved SAP-related commitments on aftermarket conduct, while the German decision was a clean close of a preliminary probe. The through-line is that regulators looked at SAP's grip on the ERP estate and its adjacent data and process-mining markets and decided the current practices sit inside the law. That is a real win for SAP. It is also a signal to buyers that they cannot outsource the lock-in problem to competition authorities.
Why Celonis pushed, and why it matters to you
Celonis built a large business on process mining, the discipline of reconstructing how work actually flows through an enterprise by reading the event logs that systems like SAP generate. Its complaint reflected a genuine commercial fear: if SAP can steer customers toward Signavio and shape how easily data leaves the core, the independent process-mining market narrows. The German regulator's finding that permissible extraction paths and non-Signavio licensing exist undercuts that argument in law. It does not eliminate the friction that any customer feels when a strategic vendor also sells the analytics layer that sits on top of its own data.
This is the part CIOs should internalize. The dispute was fought between two vendors, but the stakes belong to the buyer. Every enterprise running SAP faces the same structural question Celonis raised in regulatory language: how independently can you read, extract, and act on your own operational data when the system of record and a leading analytics tool come from the same supplier. A regulator saying the options are sufficient is useful. Proving those options work at your scale, under your contract, is a separate exercise that no antitrust decision performs on your behalf.
Clearance is not portability
The temptation after a clearance like this is to conclude the lock-in worry was overblown. That would be the wrong lesson. The Bundeskartellamt evaluated whether SAP's practices constitute an abuse of market power, a high legal bar that turns on market definition and demonstrable harm. It did not certify that any given customer's data is easily and cheaply portable to a competing stack. Those are different questions. A vendor can operate entirely within competition law and still leave a customer whose integration logic, master data governance, and process definitions are so entangled with the platform that leaving is prohibitively expensive.
The practical gap sits between what is technically permissible and what is operationally feasible. SAP's API Policy may grant extraction rights, and the licensing may allow non-Signavio process mining, but exercising those rights at production scale requires engineering effort, data modeling discipline, and contract terms that most enterprises have not secured. The regulators closed the legal question. They left the engineering and commercial question open, and that is the one that determines your actual leverage when the next renewal arrives and the platform owner knows exactly how hard it would be for you to walk.
What to put in the contract now
The governance response is to convert the regulator's abstract finding into concrete contractual and architectural guarantees. If SAP's own API Policy permits data extraction, document those extraction paths in your agreement, test them against your real data volumes, and confirm the formats are usable by third-party tools without a bespoke integration project each time. Where process mining or analytics matter, use the German decision as negotiating support to secure licensing that does not force you onto Signavio, and keep at least one independent path validated so the option is real rather than theoretical.
Architecturally, the clean-core discipline that SAP itself promotes is also the practice that preserves your independence. Keep custom logic and integration outside proprietary layers where you can, maintain a governed copy of critical operational data in a store you control, and treat portability as an engineering requirement rather than a hypothetical right. The regulators have told you SAP is playing within the rules. That is precisely why the responsibility for keeping your data and processes movable now rests with you, and why the buyers who treat this clearance as a prompt to harden their exit options will be the ones who negotiate from strength.
The broader signal for platform strategy
Beyond SAP, this episode is a template for the concentration debates coming across the enterprise stack. As dominant platforms extend from systems of record into data clouds, process mining, and agentic AI, competitors will keep testing whether that expansion crosses into abuse, and regulators will keep drawing the line at demonstrable harm rather than mere advantage. The pattern suggests that antitrust enforcement will rarely be the tool that protects a customer's day-to-day flexibility. It moves slowly, it targets clear abuses, and it leaves the ordinary friction of lock-in untouched.
For CxOs setting platform strategy, the durable conclusion is to assume clearance is the norm and design accordingly. Bet on strategic platforms where the integration and governance benefits are real, and price the concentration risk into every decision by insisting on documented portability, benchmarked exit costs, and independent data access. SAP earned two regulatory wins this month, and its customers should take those wins as confirmation that the vendor is strong and here to stay. The work of staying free to choose, at the next renewal and the one after that, remains firmly on the buyer's side of the table.


