Back to all blogs
EU Product Liability Directive 2024/2853: What It Means for Businesses

Blog Post

EU Product Liability Directive 2024/2853: What It Means for Businesses

Imagine a smart home security system that fails due to a software glitch, allowing a burglary. Or consider an AI-driven medical diagnostic tool that misreads patient data, leading to improper trea…

Imagine a smart home security system that fails due to a software glitch, allowing a burglary. Or consider an AI-driven medical diagnostic tool that misreads patient data, leading to improper treatment. Ten years ago, determining who was legally responsible for these failures was a complex, grey area of the law.

In the 1980s, product liability was straightforward. It dealt with tangible, physical goods a faulty toaster, a defective car brake, or a poorly manufactured toy. But today, products are alive with code, constant data streams, and continuous wireless updates.

To bridge the gap between 20th-century laws and 21st-century technology, the European Union has finalized a massive legal overhaul: the new EU Product Liability Directive (Directive (EU) 2024/2853) [1.1.1]. Entering into force in late 2024, this landmark legislation completely rewrites the rules of the game for anyone manufacturing, importing, selling, or modifying products in the European market [1.1.1].

With EU Member States required to transpose these rules into national law by December 9, 2026, the clock is officially ticking [1.1.1].

At Complico Consulting GmbH, we know that regulatory jargon can be overwhelming. In this comprehensive guide, we will break down exactly what the new EU Product Liability Directive means for your business, what risks are hiding in your supply chain, and the actionable steps you need to take before the 2026 deadline.

Why Was the Old Directive Replaced ?

Before diving into the changes, it helps to understand why the EU felt the need to rewrite a law that had functioned for nearly four decades. The original 1985 directive was a cornerstone of consumer protection, establishing the principle of "strict liability"—meaning a consumer didn't have to prove a manufacturer was negligent; they only had to prove the product was defective and caused harm.

However, the 1985 rules were fundamentally incompatible with the modern economy in three major ways:

The Digital Economy: Is a software update a "product" ? The old law didn't know.

The Circular Economy: When a company refurbishes a laptop or repurposes an electric vehicle battery, who is liable if it explodes ?

Globalized Supply Chains: If a consumer buys a defective drone from an untraceable overseas seller via an online marketplace, who compensates the victim ?

The new EU Product Liability Directive was drafted specifically to close these loopholes, creating a safety net for consumers and a strict new compliance reality for businesses [1.1.2, 1.2.1, 1.2.4].

1. A Radically Expanded Definition of a "Product"

Perhaps the most disruptive change in the EU Product Liability Directive is how it redefines what a product actually is.

Under the new regime, the definition of a product stretches far beyond physical, tangible items. It now explicitly includes:

Software and AI Systems

Software is now unequivocally classified as a product [1.1.4]. This applies to embedded software (like the firmware in a smart fridge) and standalone software (like a smartphone app or an AI system) [1.1.3, 1.1.4]. If a buggy software update causes a device to malfunction and cause harm, the developer or manufacturer can be held strictly liable. Furthermore, manufacturers can now be held liable if a product becomes unsafe because they failed to provide necessary cybersecurity updates [1.2.4].

Digital Manufacturing Files

In a groundbreaking move, the directive now covers digital manufacturing files, such as CAD files used for 3D printing [1.1.3, 1.2.3]. If you sell a digital blueprint for a bicycle part, and a consumer prints it perfectly but the part breaks due to a design flaw in your file, you are liable for the resulting injuries [1.2.3].

Related Digital Services

The law introduces the concept of "related services." These are digital services integrated into a product in such a way that their absence prevents the product from functioning [1.1.4]. For example, the cloud-based navigation data that a self-driving car relies on is now considered part of the product [1.1.4].

The Business Impact: If you are a software developer, a SaaS provider integrating with physical hardware, or a company utilizing AI, you can no longer hide behind traditional "software licensing agreements" to dodge liability. You are now a product manufacturer in the eyes of EU law.

2. The Widening Net: Who Can Be Held Liable ?

Historically, if a defective product injured someone, the consumer sued the manufacturer. But what happens if the manufacturer is based outside the EU and has no European assets ?

The new EU Product Liability Directive aggressively expands the circle of economic operators who can be held responsible [1.2.2]. The goal is simple: ensure that European consumers always have an EU-based entity to sue [1.2.1].

Depending on your role in the supply chain, you could now be in the crosshairs:

Importers and Authorized Representatives: If the original manufacturer is outside the EU, the EU-based importer or the manufacturer's authorized representative steps into their shoes for liability purposes [1.1.3, 1.2.2].

Fulfillment Service Providers: In a major shift targeting modern e-commerce, if no manufacturer or importer is present in the EU, the fulfillment center (the company storing, packaging, and shipping the product) can be held strictly liable [1.1.3, 1.2.4]. This makes clarity around your Importer of Record status essential.

Online Marketplaces: Platforms can no longer claim to be just "digital noticeboards." If a platform presents a product in a way that makes a consumer believe the platform (or a trader acting under its authority) is supplying it, the platform itself can be held liable [1.2.2].

Modifiers and Refurbishers: In a nod to the circular economy, any company that "substantially modifies" a product outside the original manufacturer's control is legally treated as the new manufacturer [1.1.3, 1.2.1]. If you upgrade, refurbish, or fundamentally alter a product before reselling it, you own the liability.

The Business Impact: Businesses must meticulously map their supply chains. If you are importing goods from non-EU countries, or if you run a fulfillment warehouse, your risk profile just skyrocketed. Contractual indemnification agreements with your overseas partners are now a critical necessity.

3. New Categories of Compensable Damage

What happens when a defective product harms someone ? Previously, compensation was largely limited to physical injury, death, or severe property damage. The 2024 EU Product Liability Directive brings the concept of "damage" into the digital age [1.2.2].

Medically Recognized Psychological Harm

For the first time, victims can claim compensation for psychological harm caused by a defective product, provided it is medically recognized [1.1.2].

Data Loss and Corruption

This is a massive shift for tech companies. The directive allows consumers to seek compensation for the destruction or corruption of personal data (data not used for professional purposes) [1.1.3]. If a defective smart hard drive wipes a family's digitized home videos, or a flawed cloud update permanently corrupts personal files, the consumer can sue for damages [1.2.2].

Abolition of Minimum Thresholds

Under the old rules, property damage claims had to exceed €500 to be valid [1.1.3]. This threshold deterred consumers from pursuing smaller claims. The new directive abolishes this €500 minimum, paving the way for a potential avalanche of low-value claims, which could easily be bundled into massive class-action lawsuits by consumer rights organizations [1.1.3, 1.2.2].

4. A Dangerously Claimant-Friendly Legal Landscape

Perhaps the most concerning aspect of the EU Product Liability Directive for businesses is how heavily the legal scales have been tipped in favor of the consumer [1.1.1]. The new rules make it drastically easier for claimants to win in court [1.2.4].

Rebuttable Presumptions (Guilty Until Proven Innocent)

In highly complex cases—such as those involving black-box AI algorithms or intricate pharmaceutical products—it can be nearly impossible for an average consumer to scientifically prove why a product failed [1.1.1, 1.1.3].

To fix this, the directive introduces "rebuttable presumptions." If a claimant can show that a product malfunction was obvious, or that the product failed to meet mandatory safety requirements, the court will automatically presume the product was defective and caused the damage [1.1.3]. The burden of proof then shifts to you, the business, to prove your product was safe [1.1.3, 1.2.3].

Forced Evidence Disclosure

This is a procedural nightmare for unprepared companies. Under the new directive, if a claimant presents a "plausible" case, national courts can order your company to disclose relevant technical evidence—such as internal testing data, source code documentation, or risk assessments [1.1.3]. If you refuse to hand over the evidence, the court will automatically presume your product is defective [1.1.3, 1.2.2].

Extended Liability Periods

The standard liability period remains 10 years from the date a product is placed on the market [1.1.3]. However, the directive extends this "long-stop" period to 25 years in cases of latent injuries—health issues that take a long time to manifest, which is highly relevant for the pharmaceutical and chemical sectors [1.1.3, 1.2.4].

Furthermore, for software and digital products, the 10-year clock resets every time you push a substantial software update that alters the product's safety profile [1.1.2, 1.1.4].

What It Means for Businesses: The Strategic Fallout

The implementation of the EU Product Liability Directive is not just a legal headache; it is a fundamental shift in how products must be designed, documented, and monitored.

Here is what the C-suite and compliance teams need to understand:

The End of "Ship It and Forget It": Because manufacturers are liable for the software updates they push, liability is now an ongoing, continuous lifecycle. You are responsible for the product as long as you maintain control over its digital ecosystem [1.1.3, 1.1.4].

Rise of Collective Redress (Class Actions): With the removal of the €500 property damage threshold and the inclusion of data loss, consumer protection groups are highly likely to weaponize the EU's Representative Actions Directive to launch massive, bundled lawsuits against tech and consumer goods companies [1.1.3, 1.2.2].

Internal Documentation is Your Only Shield: Because courts can now force you to disclose evidence, and because the burden of proof can easily flip to you, your internal paperwork must be flawless. If you cannot produce rigorous, structured risk analyses and safety testing data, you will lose in court [1.1.2].

Your 2026 Action Plan: How to Prepare Today

December 2026 might seem distant, but adapting supply chains, software development lifecycles, and legal contracts takes years [1.1.1]. Companies that wait until late 2026 to react will find themselves exposed to devastating financial and reputational risks.

At Complico Consulting GmbH, we recommend initiating a four-step action plan immediately:

Step 1: Conduct a Comprehensive Supply Chain Audit

Map out exactly where your products—and their digital components—originate. Are you relying on third-party software developers outside the EU ? Are you utilizing global fulfillment centers ? Identify whether your current operations automatically classify you as a "manufacturer" or "importer" under the new directive [1.1.3, 1.2.2]. Once identified, renegotiate contracts to ensure proper indemnification and liability sharing.

Step 2: Revamp Product Lifecycle Documentation

Your defense in a future lawsuit relies entirely on the data you generate today. Implement robust traceability requirements. Create a "digital paper trail" that tracks component sources, software versions, risk assessments, and compliance decisions [1.1.2, 1.2.3]. Ensure that when a court demands disclosure, you can confidently hand over documentation that proves your product meets all EU safety standards.

Step 3: Upgrade Cybersecurity and Software Protocols

Since a lack of cybersecurity updates can render a product "defective," your IT and product development teams must align [1.2.4]. Establish clear protocols for monitoring digital products post-launch, rapidly deploying security patches, and documenting every software update pushed to consumers.

Step 4: Reassess Your Insurance Coverage

Traditional product liability insurance policies were written for the physical world. They may not cover medically recognized psychological harm, the loss of non-professional data, or liabilities stemming from software updates [1.2.4]. Sit down with your brokers to ensure your policies reflect the broadened scope of compensable damages introduced by the EU Product Liability Directive [1.2.3].

Navigating the Future with Complico Consulting GmbH

The EU Product Liability Directive represents the most drastic evolution in European consumer protection in our lifetimes [1.1.1]. It is designed to be highly protective of the consumer, leaving businesses with a much narrower margin for error [1.1.1, 1.2.4].

While the new rules bring undeniable challenges, they also present an opportunity. Companies that proactively adapt their compliance, safety, and documentation processes will not only mitigate their legal risks but will also build deeper trust with the modern European consumer.

You do not have to navigate this complex regulatory transition alone. At Complico Consulting GmbH, our experts specialize in decoding EU regulations and transforming them into actionable, secure business strategies. Whether you need a deep-dive audit of your digital supply chain, assistance with risk documentation and recall preparedness, or a comprehensive compliance roadmap for 2026, we are here to help protect your business. Contact our team today to schedule your consultation.

Book a 30-Minutes
Consultation

Speak directly with a compliance specialist. In this one-on-one call