This chapter is part of the mini-guide on Directive (EU) 2024/2853 on liability for defective products. The focus is on the definition of digital product introduced by the directive: software, SaaS, files for digital manufacturing, connected services, and the role of marketplaces. For the specific treatment of software as a product, see the dedicated chapter EU Directive 2024/2853 and software liability.
Directive (EU) 2024/2853, adopted on October 23, 2024, replaces Directive 85/374/EEC and updates European rules on liability for defective products. The most significant innovation for the digital sector is the extension of the definition of “product” to categories previously excluded, with direct effects on software developers, SaaS providers, marketplace operators, and anyone distributing functional digital content.
What is meant by a digital product
Article 4, point 1, defines “product” as any movable good, explicitly including:
- Software — regardless of the delivery method: locally installed, cloud-distributed, or provided as SaaS.
- Files for digital manufacturing — digital models intended for automated production, such as 3D printing files.
- Connected digital services — services whose absence prevents the proper functioning of the physical or digital product to which they are paired.
- Electricity and raw materials — explicitly included in the definition.
The critical point for SaaS and cloud providers is that the distribution method is irrelevant: an application provided as a service falls under the definition of a product and can generate strict liability in the event of a defect that causes damage.
Scope of application and main exclusions
The directive applies to products placed on the market or put into service after December 9, 2026 (Art. 2). The most relevant exclusions for the digital sector are:
- Free and open-source software developed or distributed outside of commercial activities.
- Mere source code, which does not fall under strict liability.
- Nuclear damage already regulated by international conventions.
Who is liable: economic operators and marketplaces
Article 8 identifies the liable parties, ensuring there is always a point of contact within the European Union:
- Manufacturer of the product or a defective component.
- Importer for products coming from outside the EU.
- Authorized representative of the non-EU manufacturer.
- Logistics service provider, on a subsidiary basis when importers or EU representatives cannot be identified.
- Online platforms (marketplaces) — liable when they present the product in a way that makes it appear as if it were provided directly by the platform itself.
For marketplaces, the rule introduces a criterion based on the end-user’s perception: if the platform creates the impression of being the direct supplier, it is liable as such. This has significant implications for business models that aggregate third-party products.
Compensable damages
Article 6 limits compensation for natural persons to:
- Death or personal injury, including certified psychological damage.
- Damage to property, excluding the defective product itself and goods used exclusively for professional purposes.
- Destruction or corruption of data not used for professional purposes, including restoration costs.
Evidence and presumption of defectiveness
To reduce the information gap between the parties, the directive introduces specific procedural measures:
- Disclosure of evidence (Art. 9): the court may order the defendant to produce relevant evidence, while respecting proportionality and the protection of trade secrets.
- Presumption of defectiveness (Art. 10): a defect is presumed if the operator fails to present the requested evidence, if the product does not meet mandatory safety requirements (such as those of the Cyber Resilience Act), or in the event of an obvious malfunction.
- Technical complexity: when proving the defect is excessively difficult for scientific reasons, the court may presume the defect if the damage was likely caused by it.
Exemptions from liability
Article 11 allows the operator to exclude their liability if they demonstrate, among other things, that:
- They did not place the product on the market.
- The defect manifested after commercialization, unless it depends on software updates or modifications under their control.
- The state of technical knowledge at the time of commercialization did not allow the defect to be identified (development risk), without prejudice to the possibility for Member States to derogate for specific products.
Transposition in Italy
Italy has initiated transposition through the 2025 European Delegation Law. Directive 2024/2853 is mentioned in Annex A, point 4, of Law no. 36 of March 17, 2026. The Government is delegated to adopt the necessary legislative decrees by December 9, 2026, which is also the deadline for the entry into force of the new national rules.
Related mini-guide
This article is part of a multi-chapter mini-guide on Directive (EU) 2024/2853:
- General overview of the directive — structure, objectives, and main innovations compared to Directive 85/374/EEC.
- Software liability — how the legal position of software manufacturers changes, including cases of updates and patches.
- Vulnerability assessment and continuous control — how to document monitoring, updates, and vulnerability management.
- Penetration testing and manufacturer liability — when offensive technical evidence is needed before release or after substantial modifications.
Frequently Asked Questions
- Does a SaaS application fall under the directive’s definition of a product?
- Yes. The directive explicitly includes software regardless of the delivery method. An application provided as SaaS is considered a product and can generate strict liability if a defect causes damage to a natural person.
- Is open-source software excluded from the directive?
- Only if it is developed or distributed outside of commercial activities. Open-source software integrated into a commercial product or distributed as part of a business activity falls within the scope.
- When is a marketplace liable as a manufacturer?
- When it presents the product in a way that makes the end-user perceive that the platform itself is providing it directly. In that case, the platform is treated as the manufacturer for liability purposes.
- Is data corruption compensable damage?
- Yes, for natural persons and limited to data not used for professional purposes. Compensation also covers the costs of restoring destroyed or corrupted data.
- By when must companies comply?
- The directive applies to products placed on the market after December 9, 2026. Companies distributing software, SaaS, or products with digital components must review contracts, update processes, and technical documentation before that date.
Protect your organisation with Virtual CISO.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
