AnyLearn
All lessons

Who Pays, and For What Damage

The Directive builds a chain of liable operators so an injured person in the EU always has someone to sue. This lesson covers the manufacturer and component manufacturer, the importer and fulfilment service provider route, the distributor's one-month rule, online platforms, how a modification makes you a manufacturer, the heads of damage including data loss, and the exemptions.

Updated · AI-authored, review-gated · how lessons are made

Not signed in: your progress and quiz score won't be saved.
Progress1 / 10

The design goal: always a defendant inside the EU

Article 8 does not simply name the manufacturer. It builds a chain, and the chain exists to solve one problem: an injured person in the Union should never be left with a valid claim and nobody reachable to bring it against.

That problem got worse as supply chains lengthened and as products began arriving from manufacturers with no European presence, sold through platforms, fulfilled from warehouses operated by third parties. Under the 1985 regime a claimant could end up chasing an entity in another jurisdiction with no assets nearby.

So the Directive works down a priority order, each rung catching what the one above it missed, and ends with a default that makes somebody liable if nobody else can be identified.

Where two or more operators are liable for the same damage, they are liable jointly and severally. The claimant may recover in full from any of them, and the operators sort out contribution between themselves afterwards.

Full lesson text

All 10 steps on one page, for reading, reference, and search.

Show

1. The design goal: always a defendant inside the EU

Article 8 does not simply name the manufacturer. It builds a chain, and the chain exists to solve one problem: an injured person in the Union should never be left with a valid claim and nobody reachable to bring it against.

That problem got worse as supply chains lengthened and as products began arriving from manufacturers with no European presence, sold through platforms, fulfilled from warehouses operated by third parties. Under the 1985 regime a claimant could end up chasing an entity in another jurisdiction with no assets nearby.

So the Directive works down a priority order, each rung catching what the one above it missed, and ends with a default that makes somebody liable if nobody else can be identified.

Where two or more operators are liable for the same damage, they are liable jointly and severally. The claimant may recover in full from any of them, and the operators sort out contribution between themselves afterwards.

2. Manufacturer and component manufacturer

The first rung is the manufacturer of the defective product. For software, that is the developer or provider, and for an AI system, the provider.

The second rung is new in emphasis. Where a defective component is integrated into a product within the manufacturer's control, the manufacturer of that component is also liable, alongside the product manufacturer.

Because components include intangibles and related services, that reaches deep into a software supply chain. The supplier of a commercially licensed library, a model, or an API on which a device depends for a safety-relevant function can be a defendant in its own right.

Two qualifications keep this from being unlimited. Liability attaches to a component manufacturer only where the component was integrated within the product manufacturer's control, and a component manufacturer can exempt itself by showing that the defectiveness is attributable to the design of the product into which it was integrated, or to the instructions given by that product's manufacturer.

3. When the manufacturer sits outside the Union

Where the manufacturer is established outside the Union, the Directive substitutes operators who are inside it, in order.

The importer of the defective product is liable. So is the authorised representative of the manufacturer, where one has been appointed.

Where neither an importer nor an authorised representative is established in the Union, the fulfilment service provider is liable. That is the operator handling warehousing, packaging, addressing and dispatch without owning the goods, and its inclusion closes the gap that direct-to-consumer cross-border selling had opened.

The practical consequence for European businesses is that acting as importer or as an authorised representative is not an administrative convenience. It is an assumption of strict liability for a product someone else designed and built.

That makes supplier due diligence, contractual indemnities and insurance the operative controls. The indemnity does not affect the injured person's claim against you, but it determines whether you can recover afterwards.

4. The distributor's one month

Below those rungs sits a default that turns traceability into a legal duty.

Where no liable operator can be identified, a distributor becomes liable if, on a request from the injured person, it fails to identify a relevant economic operator within one month. Identifying the manufacturer, importer, authorised representative, or the distributor that supplied it, discharges the exposure.

The design is elegant. The Directive does not impose record-keeping as an obligation with a penalty. It simply makes the party who cannot answer the question the one who pays.

Online platforms are drawn in on a related basis. A provider of an online platform allowing consumers to conclude distance contracts with traders can be liable like a distributor where it presents the product, or otherwise enables the transaction, in a way that leads an average consumer to believe the product is provided by the platform itself or by a trader acting under its authority, subject to the conditions in Regulation (EU) 2022/2065.

5. Modify it and you become the manufacturer

One provision can move an integrator, reseller or system builder to the top of the chain without warning.

Any natural or legal person that substantially modifies a product outside the manufacturer's control, and thereafter makes it available on the market or puts it into service, is considered a manufacturer of that product.

For software this deserves careful thought, because modification is ordinary practice. A systems integrator that takes a vendor platform, extends it, and deploys it for a client. A device builder that flashes custom firmware onto a purchased controller. A company that fine-tunes a model and ships it inside its own product.

In each case the question is whether the change is substantial and whether it occurred outside the original manufacturer's control.

The exposure is not total. A person liable as a modifier can exempt themselves where the defectiveness relates to a part of the product not affected by the modification. Which makes the boundary of your change a fact worth documenting at the time, not reconstructing years later.

6. Working down the chain

The claimant starts at the top and stops at the first rung that yields a reachable defendant.

If the manufacturer is established in the Union, the search usually ends immediately, with the component manufacturer joined where a defective component was integrated within the manufacturer's control.

If the manufacturer sits outside the Union, the importer or authorised representative takes its place, and the fulfilment service provider catches the case where neither exists.

Only when none of those can be identified does the distributor default engage, with its one-month window to name someone upstream, and the platform rule alongside it.

Running in parallel, not below, is the modifier route. Someone who substantially modified the product outside the original manufacturer's control is a manufacturer, which puts them on the top rung rather than the bottom.

Wherever two or more operators are caught, liability is joint and several, so the claimant chooses whom to pursue and recovery in full is available from any of them.

flowchart TD
A["Injured person with a defective product"] --> B["Manufacturer, plus component manufacturer where integrated under its control"]
B --> C["Manufacturer outside the Union?"]
C --> D["Importer or authorised representative"]
D --> E["Neither in the Union: fulfilment service provider"]
E --> F["Still nobody identified?"]
F --> G["Distributor, unless it names an operator within one month"]
F --> H["Online platform presenting the product as its own"]
A --> I["Substantial modifier outside the manufacturer's control: also a manufacturer"]
G --> J["Two or more liable: joint and several"]
B --> J

7. Death, injury, and psychological harm

Article 6 sets out what can be recovered, and the first head has been widened.

Death or personal injury is compensable, and the Directive states expressly that this includes medically recognised damage to psychological health. The qualifiers matter: the harm must be medically recognised, must affect general health, and must require therapy or medical treatment. Distress alone does not qualify.

That extension is significant for software. A defective product that causes no physical contact whatsoever can now produce a compensable personal injury claim, where the resulting psychological harm meets the medical threshold.

Compensation covers all material losses resulting from the damage. Non-material losses, such as pain and suffering, are recoverable insofar as national law provides for them, which is one of the points where the fully harmonising rule leaves room for national variation.

There is no financial cap on personal injury, and Member States can no longer introduce one.

8. Property, and the new head: data

Property damage is compensable with three exclusions. Not the defective product itself. Not a product damaged by a defective component integrated into it within the manufacturer's control. And not property used exclusively for professional purposes.

Then the genuinely new head. The destruction or corruption of data that is not used for professional purposes is compensable damage, including the costs of recovering or restoring that data.

Read the two carve-outs side by side, because the wording differs deliberately. Property is excluded when used exclusively for professional purposes, so mixed personal and business use stays in. Data is excluded when used for professional purposes, even if not exclusively so, so any professional use takes it out.

Data is therefore protected more narrowly than property. A consumer whose photo library is destroyed by a defective backup tool has a claim. A freelancer whose mixed-use drive held client files alongside family photos likely does not, on the data head.

9. The exemptions

Article 11 lists the ways an economic operator escapes liability, and each must be proved by the operator.

That it did not place the product on the market or put it into service. That it is probable the defectiveness did not exist when the product was placed on the market, or came into being afterwards. That the defectiveness is due to compliance with mandatory legal requirements. For a component manufacturer, that the defect is attributable to the design of the product it was integrated into or to that manufacturer's instructions. For a modifier, that the defect relates to a part not affected by the modification.

And the development risk defence: that the objective state of scientific and technical knowledge, at the time the product was placed on the market or during the period in which it remained within the manufacturer's control, was not such that the defectiveness could be discovered.

Note the extension in that last clause. For a product you keep controlling, the state of knowledge is measured across the whole period, not at launch.

10. The carve-back that closes the software escape

The most useful exemption for a software manufacturer would be the second one: the defect came into being after the product was placed on the market. Software is exposed to a threat landscape that moves for decades after release, so the argument writes itself.

Article 11 removes it. That exemption does not apply where the defectiveness is due to any of the following, provided it is within the manufacturer's control: a related service; software, including software updates or upgrades; the lack of software updates or upgrades necessary to maintain safety; or a substantial modification of the product.

The third limb is the one to sit with. Liability can arise from an omission. Not shipping an update that safety required is itself a route to a defective product, even though the product left the factory in good order.

This is where the Cyber Resilience Act and the Directive lock together. One imposes the duty to maintain security through the support period. The other prices the failure to do it.

Check your understanding

The lesson ends with a 5-question quiz. Take it in the player above to see your score.

  1. A defective product is manufactured outside the EU, with no importer or authorised representative established in the Union. Who is liable?
    • Nobody, since the Directive cannot reach a non-EU manufacturer
    • The fulfilment service provider
    • The end customer's insurer
    • The national market surveillance authority
  2. An injured person cannot identify any liable operator and asks a distributor. What happens?
    • The distributor is liable outright, with no way to avoid it
    • The claim fails for want of a defendant
    • The distributor becomes liable unless it identifies a relevant economic operator within one month
    • The distributor must indemnify the manufacturer
  3. A defective backup tool destroys a consumer's personal photo library. Is the data loss compensable?
    • Yes, destruction or corruption of data not used for professional purposes is compensable, including recovery costs
    • No, data is never property and falls outside the Directive
    • Only if the loss also caused personal injury
    • Only where the loss exceeds 500 euro
  4. A manufacturer argues the defect did not exist when the product shipped but arose later as attack techniques evolved. When does that exemption fail?
    • It never fails, since defects arising later are always outside the regime
    • Only where the product carried a CE marking
    • Only where the claimant is a consumer
    • Where the defectiveness is due to a related service, software or updates, the lack of updates needed to maintain safety, or a substantial modification within the manufacturer's control
  5. A systems integrator substantially modifies a vendor platform outside the vendor's control and deploys it for a client. What is its position?
    • It remains a distributor with only traceability duties
    • It is considered a manufacturer of that product, though it can exempt itself for parts the modification did not affect
    • It has no liability, since the original vendor designed the platform
    • It becomes an authorised representative of the vendor

Related lessons

Law & Compliance
advanced

Proof: Disclosure, Presumptions, and the Complexity Rule

Strict liability is worthless if the claimant cannot prove a defect they never saw. Articles 9 and 10 answer that with a disclosure order, three presumptions of defectiveness, a presumption of causation, and a rule turning complexity into the claimant's ally. This lesson works through the cascade, the three-year and ten-year clocks, and what a defendant should be able to produce.

10 steps·~15 min
Law & Compliance
advanced

Defectiveness: The Safety a Person Is Entitled to Expect

A product is defective when it lacks the safety a person is entitled to expect. Article 7 turns that into circumstances a court weighs, several written for software: the ability to learn after release, interconnection, cybersecurity requirements, and recalls. This lesson works through the list, the rule that a later improvement is not an admission, and why compliance is not a defence.

10 steps·~15 min
Law & Compliance
advanced

Software as a Product: What the New Liability Directive Changed

Directive (EU) 2024/2853 replaces the 1985 regime and settles a forty-year argument by naming software a product. This lesson covers the new definition and why delivery method is irrelevant, why information is not a product, how components and related services extend the net, where open source sits, and why liability cannot be disclaimed by contract.

10 steps·~15 min
Law & Compliance
advanced

The Cyber Resilience Act: What It Covers and Who It Binds

Regulation (EU) 2024/2847 puts software and connected hardware under product safety law, with a CE mark for cybersecurity. This lesson sets the scope: what counts as a product with digital elements, why a cloud backend can be part of one, what sector law carves out, where open source and stewards sit, the four risk tiers from Annex III and IV, and how a reseller becomes a manufacturer.

11 steps·~17 min