Table of Contents
EU Product Liability Directive (2024)
As of 1 October 2026. Information only, not legal advice – see the disclaimer.
| Full title | Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products and repealing Council Directive 85/374/EEC |
|---|---|
| Type | EU directive |
| Adopted by | European Parliament and Council of the European Union |
| Adopted | 23 October 2024 |
| Legal status | In force since 8 December 2024; transposition deadline 9 December 2026; applies to products placed on the market or put into service after 9 December 2026. Directive 85/374/EEC is repealed with effect from that date but continues to apply to products placed on the market before it |
| Official text | EUR-Lex |
| Subject area | Private actors, liability and insurance; Cybersecurity, cybercrime and critical infrastructure |
Overview
The directive replaces the Product Liability Directive of 1985. It establishes no-fault liability of economic operators for damage caused to natural persons by defective products. It expressly includes software in the notion of “product”, regardless of how it is supplied, and takes into account that products may be changed after they are placed on the market through software updates or connected services. It is referred to in debates on how civil liability can create incentives for the security of digital products, including against cyber-attacks.
Provisions relevant to the cyber and information sphere
- Art. 4(1) – “Product” includes software and digital manufacturing files; free and open-source software developed or supplied outside a commercial activity is excluded (Art. 2(2)).
- Art. 6(1)© – Compensable damage includes the destruction or corruption of data that are not used for professional purposes.
- Art. 7(2) – In assessing defectiveness, account is taken, among other things, of the effect of the ability to continue to learn after deployment, of relevant product safety requirements “including safety-relevant cybersecurity requirements”, and of the moment in which the product left the manufacturer's control.
- Art. 9 and Art. 10 – Disclosure of evidence and presumptions of defectiveness and causation, in particular where technical or scientific complexity makes proof excessively difficult.
- Art. 11(2) – The exemption for defects that came into being after the product was placed on the market does not apply where the defect is due to a related service, software including updates or upgrades, or the lack of software updates or upgrades necessary to maintain safety, within the manufacturer's control.
Application to cyber and information operations
The directive does not address State conduct. It allocates the consequences of insecure products among private parties: where a vulnerability in a product is exploited and damage results, the question whether the product was defective, including with regard to cybersecurity requirements and security updates, is assessed under its terms. It is complemented by the security requirements of the EU Cyber Resilience Act.
Germany. The Federal Government introduced a bill to modernise product liability law transposing the directive (Bundestag printed paper 21/4297 of 25 February 2026). The Bundestag held the first reading on 4 March 2026 and its Committee on Legal Affairs a public hearing on 13 April 2026. Final adoption and promulgation were not confirmed in the sources consulted as of 1 October 2026.
Recent developments
- 2024-11-18: Publication in the Official Journal; entry into force on 8 December 2024.
- 2026-03-04: First reading of the German transposition bill in the Bundestag.
- 2026-12-09: Transposition deadline and date of application (scheduled).
Related entries
Sources
- Directive (EU) 2024/2853 (EUR-Lex), accessed 2026-10-01
- Bundestag printed paper 21/4297 (government bill), accessed 2026-10-01
- Bundestag: first reading on the modernisation of product liability law, accessed 2026-10-01
Change log
- 2026-10-01: Entry created.
