Under British, American, Bulgarian and German law alike, copyright in commissioned code starts with whoever wrote it, and a client who wants more than the right to use the site has to get it in the contract. So when the contract says nothing, the answer to who owns the code of your website is the studio, however much you paid. One paragraph fixes that. It is the easy half: the domain, the accounts and the licences each have owners of their own, and a handover that leaves those with the studio gives you a folder you cannot run.
Who owns the code of my website if the contract says nothing?
If the contract is silent, the code belongs to the studio or freelancer who wrote it. You get a right to use the site for the purpose you ordered it for, and little more. Code your own employees write is the exception: in the UK, the US and across the EU, it belongs to the employer from the start.
| Country | Who owns commissioned code by default | What moves it to you | Where it is written |
|---|---|---|---|
| United Kingdom | The studio | A written assignment the studio signs | CDPA 1988, s. 11 and s. 90(3) |
| United States | The studio; software is not a “made for hire” category | A written transfer signed by the studio | 17 U.S.C. § 101 and § 204(a) |
| Bulgaria | The studio; you may use it for the purpose ordered | A contract clause; exclusivity only if granted expressly and in writing | Copyright and Neighbouring Rights Act, arts 42 and 36(4) |
| Germany | The studio, and German copyright itself cannot be assigned | An exclusive licence of rights of use, naming each use | UrhG § 29 and § 31 |
| Any of these, code by your own employee | You, the employer | Nothing | CDPA s. 11(2); 17 U.S.C. § 101; Directive 2009/24/EC, art. 2(3) |
The American row is the surprise. Software is missing from the nine kinds of commissioned work that can be made for hire, a list with room for translations, tests and atlases (Circular 30). So careful US contracts say both: the work is made for hire, and where it is not, the developer assigns it.
Bulgaria, where we work, adds a trap for contracts that do say something: a licence that names no term is presumed to last three years (art. 36(5)). In Germany, where no contract can assign copyright itself, the deal is an exclusive grant of rights of use that lists every use, because § 31(5) limits any use left unnamed to what the contract's purpose needs.
English courts sometimes read a transfer into a contract that never mentioned one. In Griggs v Evans (2005) the Court of Appeal held that the client owned the copyright in the Dr Martens logo in equity, since a logo is worthless to a client who cannot stop others using it. Code went the other way that same year. In Clearsprings v Businesslinx the High Court gave the client of a web-based database system a perpetual, royalty-free licence to use, repair and upgrade it in its own business, with no right to license it to anyone else, because both sides knew the developer would reuse and keep developing its own routines. Where I am unsure is the design. A homepage built around a brand sits closer to the Dr Martens logo than to a database, so a court could split one site in two, the look to the client and the code to the studio, and I would want a judgment on a real website before telling you which way it goes. Until then, assume you may run and repair the site and nothing more.
For five static pages the domain is worth more than the code, which can be rebuilt in days. On a platform with user accounts and paid subscriptions, the kind we built from nothing for Riomera, the code is most of what the client paid for, and owning it is the main argument for custom software over a subscription.
What should a website contract say about ownership?
A website contract should assign you all copyright in everything made for the project, exclusively and for every use, with the right to change it and to let other developers change it, from the day you pay the final invoice. Four short sentences beside it settle the source code, the third-party licences, the domain and the accounts.
On receipt of the final payment, the Studio assigns to the Client, exclusively and without limit of time, territory or manner of use, all copyright in the work created under this contract, including the source code, build configuration, database structure and design files, with the right to modify them and to authorise others to modify them. Until that payment, the Client holds a non-exclusive licence to use the delivered work.
The shape of the clause; a lawyer fits the wording to your country's law
Tying the assignment to the final payment protects the studio if a client walks away at 90 per cent, and the licence until then lets the site go live first, which is why studios sign it without a fight.
Now the four sentences. One requires the source code as a repository transferred to an account you control, with instructions a new developer can build from; a zip of the live site is not source code. One lists every third-party item in the build, from fonts to paid plugins, with the name each licence is in. One registers the domain to your company, with your email as the registrant contact. The last opens every account the site depends on in your name, with the studio as your user rather than you as its guest.
A studio will want two things back, both fair: components it wrote before your project and reuses elsewhere stay its own, under a perpetual licence for you to use and change them with any developer, and it may show the work in its portfolio unless you strike that out. Exclusive rights to shared components cost extra, a line to look for when you compare quotes.
Code an AI assistant wrote can leave that clause with less to hand over. On 29 January 2025 the US Copyright Office concluded that AI output is protected only where a human author has determined sufficient expressive elements (Copyright Office). So add a promise that nothing delivered infringes anybody's rights. It still bites when the copyright is thin.
Every font, photo and plugin has a licence holder
Fonts, stock photographs and paid plugins are licensed, each in somebody's name. If the name is the studio's, the piece can stop loading, updating or being yours to use when the studio stops paying, so have each one bought in your name or transferred to you in writing.
Adobe is the clearest case. A client's site must load Adobe Fonts through the client's own Creative Cloud subscription, and once that subscription is cancelled the site falls back to the next font in its stylesheet (Adobe). Fonts under the SIL Open Font License have no such tie, which is why I would choose them for any site that might change hands.
Paid WordPress plugins come with licence keys. ACF PRO, the premium edition of Advanced Custom Fields, costs $49 a year for one site and $249 for unlimited sites, about €42 and €214 at the ECB rate of 9 September 2026. One agency key can cover dozens of client sites, and when it lapses, your existing fields keep working but updates stop and no new PRO fields can be made (ACF). Ask for your own $49 key.
Adobe Stock's standard licence can be transferred to one client (Adobe Stock), so put that transfer in the handover too.
Is a Wix, Shopify or WordPress site any different?
Yes. A Wix site leaves little code to own, so get the platform account and the domain in your name. A Shopify theme written for you is code, and the assignment should name it. WordPress core is licensed under GPLv2 or later, so nobody can take it from you; the contract covers the theme and plugins written for you.
Nothing built on Wix runs anywhere else (Wix Help Center). Wix's Transfer Site option makes you the owner and can bring the premium plan, the domain and its mailboxes along (Wix). Ask for all three. A password to the studio's account is a loan. Shopify will email you the theme as a zip file, without the products, pages or images (Shopify), and that zip is the copy of the code to keep.
What should a website handover include?
A website handover moves the domain, the code repository, the hosting and every account the site runs on into your name, and an item counts as moved once someone on your side has logged in and seen it. Most of it is logins.
I plan an afternoon for a brochure site and up to a week for one with payments, ads or an app, because some moves go through a vendor's support team.
- The domain and its DNS: the registrar account in your company's name, your email as the registrant contact, and a login wherever the DNS records are edited.
- The repository, transferred rather than shared. On GitHub a transfer keeps the history, and one sent to a personal account lapses if it is not accepted within a day (GitHub Docs).
- Hosting, with your own administrator login.
- Search Console, with you as owner. A removed owner can verify again unless their verification token is deleted too (Google).
- Google Analytics, with you as Administrator, the only role that manages users (Google).
- Ad accounts: Admin access in Google Ads (Google). A Meta ad account created inside a business portfolio stays there permanently (Meta), so have it created in yours and give the agency access.
- The payment provider, opened in your company's name before the first payment; moving a Stripe account to another legal entity starts with a request to Stripe support (Stripe).
- App store and code-signing accounts. An app changes hands only when both account holders act, at Apple and at Google Play alike, and Google then replies within two business days. For a Windows program, add the private key that signs its updates.
- Admin logins inside the site, ending with the studio's own account deleted while you watch.
On the websites we build, the code, the content and the domain are the client's from the start, so a move to other hosting means working through this list together, with our help at the far end.
My developer has gone quiet. What do I send?
Send one short, dated email that names every item, sets a deadline two weeks away and offers to pay anything outstanding. Naming items one by one rules out the reply that you already have everything, and the offer to pay removes money as a reason to wait. Copy this:
Hello [name]. I would like to complete the handover of [domain] by [date]. Please move the domain to our registrar account or send the transfer code, transfer the code repository to [account], give [email] an administrator login for the hosting, and make [email] an owner in Search Console and an Administrator in Google Analytics. Please also sign and return the attached one-page assignment of the copyright in the work we commissioned. If an invoice is outstanding, send it and it will be paid. If any item cannot be done, tell me which one and why.
The first email, before anything formal
If the deadline passes in silence, start with the domain: it is the one item you may recover alone. ICANN's lookup tool shows which registrar holds the name. If your company is the registrant, the registrar answers to you, so ask it for the transfer code. For a .com or any other generic ending, ICANN's Transfer Policy gives the registrar five calendar days to hand over the code when its control panel cannot produce one, lets it refuse a transfer within 60 days of registration or of a previous transfer, and locks transfers for 60 days after any change to the registrant's name, organisation or email unless the registrar let you opt out. So move the domain first and fix the details afterwards. A .uk name moves by a tag change at Nominet until 9 February 2027, when transfer codes valid for up to 14 days replace the tags (Nominet). If the studio is the registrant, only the studio can authorise the move.
The code is harder. Without the studio, a repository you never had access to is gone, and the realistic route is a rebuild from the live site and your own copies of the text and photographs.
Is source-code escrow worth it?
For a website I would skip escrow, the arrangement under which a third party holds a copy of the code and releases it to you if the supplier folds, because a repository in your own account from day one does the same job every day rather than on a trigger.
Escrow earns its fee on licensed software you run but will never own, and a single-client agreement costs from $950 for the first year and $750 a year after that at National Software Escrow to $1,595 a year plus a $995 setup fee at EscrowTech: yearly fees of roughly €640 to €1,370 at the same ECB rate.
Can we sign the assignment after the site is live?
Yes. A one-page assignment of the rights in the delivered work, citing the original contract by its date, does the job. The studio's signature is the one that counts, since the studio is giving the rights away.
What about the text and the photographs?
Text you wrote is yours, and text the studio wrote follows the assignment. Photographs belong to the photographer until assigned to you in writing, so if the studio hired the photographer, ask for that assignment as well.
Does the studio keep a copy after the handover?
Code survives in backups and repository history, so ask for written confirmation if you want it deleted. Personal data from forms and customer accounts has a rule of its own: Article 28(3)(g) of the GDPR, kept in the UK GDPR, requires your contract with a studio that processes it for you to make the studio delete it or return it, at your choice, when the service ends.