qui-possede-le-code-de-votre-site
Juridique · PME · Propriété du code

Who owns your website's code? The vendor lock-in trap

5 minutes read · 12 September 2026

You paid for your website. The invoice was settled long ago. So you own it, just as you own a van or a machine you bought. That is the logical conclusion, and in Belgium it is wrong.

The day people discover the problem is almost always the same: you want to change provider, or yours has stopped answering. And you realise you cannot take anything with you.

Paying for work transfers no copyright. Only a written agreement does.

What Belgian law actually says

A website and a piece of software are protected by copyright, just like a text or a photograph. Belgian economic law sets out a simple principle: the rights arise with the person who created the work, meaning the developer. And for those rights to change hands, a written agreement is required.

There is one exception, and this is where many business owners get it wrong: when an employee writes software as part of their job, the law presumes the rights belong to the employer, with no specific document needed. That exception covers employees only.

So it applies neither to freelancers, nor to agencies, nor even to the director of your own company. The Belgian Court of Cassation confirmed this in 2010: outside an employment contract, there is no presumed transfer. Without a written clause, the provider remains the holder of the rights to what you paid for.

In practice, that means they can object to you having the code modified by someone else, or reused elsewhere. This isn't a theoretical threat: it is the most effective bargaining lever there is when a relationship ends badly.

The five locks that have nothing to do with code

Copyright is only half the story. In most cases I come across, the blockage is far more mundane.

  • The domain name is registered in the provider's name rather than yours. That is your commercial address, your email, your search ranking: without it, you start from scratch.
  • The hosting is a sub-account of theirs. You cannot retrieve the files or the database without going through them.
  • The site is built on a proprietary tool, in-house or licensed, that only works at that provider. Nobody else can take it over, however willing they are.
  • Third-party accounts — analytics, online payments, email sending, advertising — were created with their email address. Your data history effectively belongs to them.
  • The original design files and source content were never handed over. All you have is the finished display.

None of those five points comes from bad faith in most cases. They come from habit. But the effect is identical: you cannot leave.

What changed in 2025

A European regulation, the Data Act, has applied since 12 September 2025. It doesn't deal with copyright but with technical and commercial lock-in, and it works in your favour.

Providers of online services must now remove the obstacles that prevent you from changing provider or bringing your data back in-house. The transfer has to be completed within thirty days. And from 12 January 2027, fees charged for that switch will be banned outright.

On top of that sits a right you have had since 2018: European data protection rules let you retrieve your customers' data in a readable, reusable format. A provider telling you "that isn't technically possible" is not answering the question.

The seven questions to ask before signing

Ask them in writing, before the quote. The answers will tell you more about a provider than their portfolio will.

  • "Will the domain name be registered in my name, with my own access?"
  • "Does the contract state in writing that the rights to the code are transferred to me on delivery?"
  • "Where does the code live, and can I have access to it today?"
  • "Is the site built on a proprietary tool, or on technologies another provider could take over?"
  • "Will the hosting, analytics and payment accounts be created in my name?"
  • "If we stop working together, what exactly do you hand over, and within what timeframe?"
  • "What is documented so that someone else could pick up the work?"

A serious provider answers all seven without tensing up, because those are the same answers they would want in your position. Discomfort at question four or six is, in itself, valuable information.

My position, to be clear

I work with open, widely used technologies precisely so that another professional can take the work over without me. The code belongs to you on delivery, it lives in a repository you have access to, and the accounts are created in your name. No proprietary tool, no licence that depends on my being around.

That isn't generosity, it is commercial common sense: a client who stays because they can't leave isn't a satisfied client, they are a dispute in the making.

If you have any doubt about your current situation, start with one simple check, tonight, for free: go to the .be domain registry website and look up your domain name. If the registered holder isn't your company, you have just identified your first lock.

Sources

Share this article
Contact

Let's take the time to talk

Loading...