Orange S.A. Pays €900,000+ for GPL Violation: The License Compliance Warning Every Company Needs to Hear

On February 21, 2024, the Paris Court of Appeals upheld an order requiring Orange S.A. — one of Europe's largest telecommunications companies, with revenues exceeding €44 billion — to pay over €900,000 in damages to Entr'ouvert, a small French company that maintains the Lasso library. The violation: Orange had incorporated Lasso, a GPL-licensed SAML and XML security library, into its products without complying with the GPL's terms.

The Facts of the Case

Entr'ouvert's Lasso library is an implementation of SAML (Security Assertion Markup Language) and Liberty Alliance protocols used for authentication and identity federation. Orange began incorporating Lasso into its products around 2006. The library was licensed under the GNU General Public License version 2. Orange did not provide source code for its modifications as GPL requires, did not include required license notices, and did not make its GPL-derived code available to users as the license mandates.

Entr'ouvert filed suit. The case worked its way through the French courts over nearly a decade. The Court of Appeal's February 2024 ruling affirmed liability and the significant damages award, which covered lost license fees (what Orange would have paid for a commercial license), damages for violation of the moral rights of the software's authors, and legal costs.

Why This Case Is a Landmark

The Orange case is significant for several reasons. First, it demonstrates that GPL enforcement in European courts is real, effective, and produces substantial financial consequences. Second, the damages calculation included not just a reasonable royalty but also damages for the violation itself — establishing that deliberateness is not required for significant liability. Third, the decade-long nature of the violation demonstrates how license compliance failures can accumulate silently over years before triggering legal action.

The Root Cause: A Visibility Failure

The Lasso violation was almost certainly not a deliberate decision by Orange's leadership to violate the GPL. It was a software engineering team making technical decisions without adequate visibility into license obligations. The library solved a technical problem. It was incorporated. No automated system flagged the license. No legal review caught the issue. The violation accumulated for years until it became a court case.

This root cause — a visibility and process failure, not intentional misconduct — is exactly what SCA tooling and automated license compliance programs are designed to prevent. With a license scanner integrated into their development pipeline, the GPL-licensed Lasso library would have been flagged at the moment it was first incorporated. The compliance failure would have been a development conversation, not a decade-long legal proceeding.

The €900K Question: What Would Automated Compliance Have Cost?

An automated license compliance program — running license scanning on every build, enforcing a license policy in CI/CD, generating attribution reports — costs a fraction of what Orange paid in damages, legal fees, and reputational cost. The Orange case should be the business case for license compliance investment at any company that uses open source software in commercial products. The question is not whether to invest in compliance tooling. The question is whether you want to pay for it now or pay for it later at a significantly higher price.

// Recommended Tool

Prevent License Violations Like Orange S.A.'s — Use Fossity

Fossity — Fossity automatically scans every dependency in your codebase, flags GPL and other copyleft licenses before they create legal exposure, and generates the attribution documentation required for compliant open source use. The cost of prevention is a small fraction of the cost of enforcement.

Visit Fossity.com →
// Author: Esteban C.