Product Liability Directive (PLD)
Table of Contents
Chapter I – GENERAL PROVISIONS
Chapter II – SPECIFIC PROVISIONS ON LIABILITY FOR DEFECTIVE PRODUCTS
Chapter III – GENERAL PROVISIONS ON LIABILITY
Chapter IV – FINAL PROVISIONS
Recitals (64)
Annexes
Recital 51
(51) The possibility for economic operators to avoid liability by proving that the defectiveness came into being after they placed the product on the market or put it into service should be restricted when a product’s defectiveness consists in the lack of software updates or upgrades necessary to address cybersecurity vulnerabilities and maintain the safety of the product. Such vulnerabilities can affect the product in such a way that it causes damage within the meaning of this Directive. In recognition of manufacturers’ responsibilities under Union law for the safety of products throughout their lifecycle, such as under Medical Devices Regulation (MDR) of the European Parliament and of the Council ( 16 ) , manufacturers should also not be exempted from liability for damage caused by their defective products when the defectiveness results from their failure to supply the software security updates or upgrades that are necessary to address those products’ vulnerabilities in response to evolving cybersecurity risks. Such liability should not apply where the supply or installation of such software is beyond the manufacturer’s control, for example where the owner of the product does not install an update or upgrade supplied for the purpose of ensuring or maintaining the level of safety of the product. This Directive does not impose any obligation to provide updates or upgrades for a product.