EU Product Liability Directive (Directive (EU) 2024/2853)
Evidence request list. 18 controls, 18 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
PLD: Damages, Defectiveness and Substantial Modification
The 2024 PLD introduces a substantive 'substantial modification' rule that transfers liability to the modifier. Article 4(18) defines substantial modification: a modification of a product after it has been placed on the market or put into service that is not foreseen or planned in the initial risk assessment of the manufacturer + changes the product's original performance + purpose + type in a way that affects the conformity with the relevant safety requirements. Article 7(1) where an economic operator (typically a distributor or any subsequent operator) substantially modifies a product, that operator becomes the 'manufacturer' for PLD purposes for the modified product. Article 16(3) the modifier triggers a NEW 10-year long-stop from the date of the modification + the original manufacturer remains liable only for the unmodified aspects. The substantial-modification rule is significantly
- Substantial-modification governance process flagging when a change crosses the Article 4(18) threshold
- Internal-record of refurbishment / integration steps
- Modifier-side PLD insurance + indemnity
- Refurbisher / integrator unaware that substantial modifications make them a PLD manufacturer
- Substantial-modification log absent making the Article 16(3) long-stop unprovable
- AI fine-tuning / model retraining without Article 4(18) substantial-modification analysis
Article 6(1) sets the recoverable damage categories: (a) death or personal injury, including medically recognised damage to PSYCHOLOGICAL health; (b) damage to or destruction of any property other than the defective product itself; (c) damage to or destruction of data, where the data is not used exclusively for professional purposes. Article 6(2): in cases of property damage where the property is used by the injured person both for personal AND non-professional purposes, the property damage is recoverable. Article 6(3): pure economic loss is not recoverable. The Article 6(1)(a) inclusion of psychological harm + Article 6(1)(c) data destruction / corruption is one of the most significant modernisations of the 2024 PLD over the 1985 Directive (which covered only death + personal injury + property damage other than the defective product itself in a B2C context, EUR 500 threshold removed). T
- Claims-process documentation covering Article 6(1)(a) medically recognised psychological harm + Article 6(1)(c) data destruction
- Personal vs professional data classification methodology
- Insurance policy review for the expanded damage categories
- Product liability insurance written under the old EUR 500 threshold + property-only damage scope
- Failing to recognise data destruction as recoverable damage
- Excluding psychological injury without medical recognition
PLD: Final Provisions, Repeal and Transposition
Article 19 transparency: Member States shall make public + accessible in user-friendly + electronic formats summary information on final court decisions concerning compensation under this Directive. Article 20 reporting: by 9 December 2030 + every five years thereafter, Member States shall communicate to the Commission information on PLD claims + decisions including aggregated statistical data on number + nature of claims + outcome. Article 21 review: by 9 December 2030 the Commission shall present a report to the European Parliament + Council reviewing the application of this Directive + considering whether to amend it in light of technological + market developments (with particular attention to AI + self-learning systems + software-as-a-service + circular economy / refurbishment + claims pertaining to digital products + the 25-year latent-injury long-stop).
- Internal participation in Article 19 transparency where local court orders publication
- Tracking of Article 20 + 21 Commission review developments + potential PLD 2.0
- No internal awareness of Article 19 transparency obligations affecting reputation
- No transition planning for potential PLD revision post-Article 21 review
Article 22 transitional provisions: Member States shall ensure that the laws + regulations + administrative provisions necessary to comply with this Directive apply only to products placed on the market or put into service AFTER 9 December 2026. Products placed on the market or put into service BEFORE 9 December 2026 remain subject to Council Directive 85/374/EEC (which continues to apply to those products until 10-year long-stop expiry). Article 23 repeal: Council Directive 85/374/EEC is REPEALED with effect from 9 December 2026 (but continues to apply to products placed on the market before that date per Article 22). References to 85/374/EEC are construed as references to this Directive. Article 24 transposition: Member States shall adopt + publish the laws + regulations + administrative provisions necessary to comply with this Directive by 9 December 2026 + apply those measures from t
- Mapping of which products + claims fall under 85/374/EEC versus 2024/2853
- Compliance program implementation deadline 9 Dec 2026
- Coordination with sectoral regulators on co-application of GPSR + MR + EU AI Act + CRA
- Treating 85/374/EEC as fully repealed at sunset (it continues for legacy products until their 10-year long-stop expiry)
- Compliance program not ready by 9 Dec 2026
- No two-track claims handling distinguishing legacy vs new PLD regimes
PLD: Liability and Economic Operators
Article 5(1): Member States shall ensure that any natural person who suffers damage caused by a defective product (the 'injured person') is entitled to compensation in accordance with this Directive. The right to compensation is for natural persons only (Article 5(1)); legal persons + commercial undertakings are NOT covered by PLD and must rely on contract law or other national tort regimes. Article 5(2): only damage falling within Article 6 is recoverable. The right under Article 5 is a NO-FAULT civil liability right - the injured person does not need to prove negligence; they need to prove (a) defect, (b) damage, and (c) causal link between the two (Article 10 and presumptions in Article 11). Article 5(3) the right cannot be excluded or limited by contractual provisions or by waiver in respect of the injured person.
- Internal claims-management procedure separating PLD-eligible (natural persons) from non-PLD-eligible (legal persons / commercial users) claims
- Mandatory non-waiver clause in product documentation
- Attempting to exclude / limit PLD liability via contract terms (Article 5(3) makes this impermissible)
- Commercial users mistakenly treated as PLD-eligible claimants
Article 7 enumerates the economic operators that can be held liable: (1) the manufacturer of the defective product (including its components); (2) where the manufacturer is not established in the Union: (a) the importer of the product; (b) the manufacturer's authorised representative + (c) where neither importer nor AR can be identified - the fulfilment service provider; (3) economic operators that substantially modify the product (Article 4(18)) including distributors that perform substantial modifications; also platforms within the meaning of Article 6(3) DSA where the platform plays a 'predominant' role in the contractual relationship with the consumer. Article 7(2) Member States may limit Article 7(2)(c) FSP liability for products placed on the market before transposition. Article 7(2)(d) a person providing a related service which causes the product to be defective; Article 7(2)(e) w
- Economic-operator identification register per Article 7
- Substantial-modification log + liable-operator reassignment
- DSA Article 6(3) predominant-role analysis for marketplaces facing PLD claims
- Article 7(2)(e) supplier identification trail (within 1 month of injured-person request)
- Distributor unable to identify upstream economic operator within 1 month making it the PLD defendant
- Substantial-modifier ignoring liability transfer under Article 7
- Authorised representative + fulfilment service provider roles overlapping without clear allocation
PLD: Limitation Periods, Reduction and Contribution
Article 15: Member States shall ensure that proceedings for recovery of damages are subject to a limitation period of 3 YEARS from the day the injured person becomes aware OR could reasonably be aware of (a) the damage; (b) the defect; (c) the identity of the relevant economic operator that can be held liable for the damage. The 3-year clock starts running from the latest of these three points. Member States shall ensure that the rules applicable to the suspension or interruption of the limitation period laid down in this Directive do not prevent the injured person from claiming compensation. Article 15 codifies the 'reasonably aware' / 'should have known' standard which is more protective than a strict actual-knowledge standard.
- Internal logging of when a complaint / incident becomes aware-triggering for PLD purposes
- Periodic review of pending claims against the 3-year limit
- Treating the 3-year clock as starting at damage event regardless of knowledge of defect / operator
- No internal tracking of when the injured person became 'reasonably aware'
Article 16(1): the right of an injured person to claim compensation shall extinguish on the expiry of 10 YEARS from the date the actual defective product / its substantially modified version that caused the damage was placed on the market or put into service. Article 16(2): in the case of damage caused by a defect that took LATENT FORM AND THAT MANIFESTED ITSELF MORE THAN 10 YEARS AFTER the product was placed on the market or put into service, the long-stop period is 25 YEARS for personal injury claims (Article 16(2)). Article 16(3): substantial-modifier liability triggers a fresh 10-year long-stop running from the date of the substantial modification (Article 4(18) - so the modifier is liable for 10 years from the date of modification + the original manufacturer remains liable for 10 years from the original placing-on-the-market). The 25-year long-stop for latent personal injury is a 20
- Product placement-on-market + substantial-modification timestamp register (25-year retention required for latent-injury claims)
- Document-retention policy aligned with the 25-year window for safety + technical files
- Modification-control process tagging substantial-modification dates
- Document-retention shorter than 25 years for products that can cause latent personal injury
- Substantial-modification dates not recorded leading to inability to demonstrate / disprove the modifier-liability clock
- Long-stop dropped at 10 years without latent-injury analysis
Article 17 codifies the manufacturer / economic-operator defences: (1) the defendant is not liable if it proves: (a) the product was not placed on the market or put into service by the defendant; (b) the defect did not exist when the product was placed on the market or put into service; or (c) the defect arose from compliance with mandatory Union or national regulations. Article 17(2) the state-of-the-art defence: where a manufacturer can prove that the state of scientific + technical knowledge at the time the product was placed on the market / put into service or during the subsequent period in which the product was under the manufacturer's control was not such as to enable the existence of the defect to be discovered, the manufacturer is not liable. The state-of-the-art defence is NARROWED in the 2024 PLD: it does not apply where the defect arose after the product was placed on the mar
- State-of-the-art evidence file by product / batch
- Post-market software-update obligation tracked with patch + EOL dates
- Article 17(1)(c) regulatory-compliance file documenting which mandatory requirements were followed
- Asserting state-of-the-art defence without contemporaneous evidence at time of placement
- Failing software updates leading to loss of state-of-the-art defence + new liability exposure
- Treating Article 17 defences as automatic without documenting the specific defence basis
Article 18 governs internal contribution among jointly liable economic operators + the right of recourse: this Directive shall be without prejudice to provisions of national law concerning the right of contribution + recourse among liable economic operators. The Article 18 framework + Article 14 joint-and-several liability creates a two-step regime: (1) injured person sues any one liable operator under Article 14; (2) defendants resolve the relative shares among themselves under national contribution + recourse rules. The Article 8 chain-of-recourse rules supplement Article 18 by mandating that each economic operator has a right to be indemnified by the upstream operator for the relevant portion of liability.
- Internal contribution playbook with upstream + downstream operators
- Indemnity clauses in supplier + distributor contracts aligned with Article 18 + 8 + 14
- Insurance coverage for shared-and-several scenarios
- Supplier / distributor contracts lacking indemnity clauses sized to PLD joint-and-several exposure
- No internal contribution playbook leaving recourse to ad-hoc litigation
PLD: Proof, Evidence Disclosure and Presumptions
Article 10 sets the factor-based 'defectiveness' test. A product is defective if it does not provide the safety which the public at large is entitled to expect, considering all the circumstances + in particular: (a) presentation of the product including instructions for use + warnings, including for vulnerable consumers + accessibility (Article 10(1)(a)); (b) reasonably foreseeable use + misuse (Article 10(1)(b)); (c) effects of any ability of the product to continue to learn after deployment - particularly relevant to AI + machine-learning products that change their behaviour over their lifecycle; (d) effects of OTHER products that can reasonably be expected to be used together with the product; (e) the moment the product was placed on the market / put into service / substantially modified; (f) product safety requirements including safety-relevant cybersecurity requirements (a cybersecu
- Product safety risk-assessment file capturing the Article 10 factors
- Reasonably-foreseeable-misuse analysis
- Cybersecurity-as-safety analysis per Recital 38 + Article 10(f)
- Self-learning behaviour monitoring + drift-control evidence for AI-integrating products
- Safety assessment not capturing cybersecurity-as-safety
- Defectiveness test treated as a single-factor (manufacturer warning) instead of multi-factor
- No monitoring of self-learning behaviour drift in deployed AI products
Article 11(1): the injured person must prove (a) defect, (b) damage, and (c) the causal link between the defect + the damage. Article 11(2): defectiveness shall be PRESUMED where any of the following applies: (a) the defendant fails to comply with an obligation to disclose evidence at its disposal pursuant to Article 9; (b) the claimant establishes that the product does not comply with a mandatory product-safety requirement (e.g. GPSR EHSR + MR Annex III + EU AI Act Article 9 + CRA Annex I); (c) the claimant establishes that the damage was caused by an obvious malfunction during reasonably foreseeable use. Article 11(3): the causal link between the defect + damage shall be PRESUMED where it has been established that the product is defective + the damage is of a kind typically consistent with the defect. Article 11(4): where a court finds that, due to technical or scientific complexity, t
- Internal mapping of product safety requirements to PLD Article 11(2)(b) presumption triggers
- Article 9 disclosure-readiness file (to avoid Article 11(2)(a) presumption)
- Technical-explainability documentation for AI / complex software products
- Non-compliance with a mandatory safety requirement that would automatically trigger Article 11(2)(b) presumption
- Article 9 disclosure refused leading to Article 11(2)(a) presumption
- No internal mapping of which obvious-malfunction patterns would trigger Article 11(2)(c)
Article 12 caps and procedural rules: the injured person bears the burden under Article 11 but the procedural rules in Articles 9 + 11 reduce the practical burden through disclosure + presumptions; reduces the bar to bringing claims for highly technical / opaque products. Article 13 sets out reduction of liability: liability may be reduced + extinguished if the damage is caused by both a defect AND the fault of the injured person or any person for whom the injured person is responsible. Article 14 multiple-defendant joint + several liability: where more than one economic operator is liable for the same damage, they shall be jointly + severally liable - the injured person may claim the full damage from any one of them; the choice of defendant is the claimant's; recourse among defendants is governed by Article 18 (national contribution rules).
- Internal evidence-handling playbook for the reduced plaintiff burden
- Comparative-negligence assessment process for Article 13
- Recourse-strategy procedure for joint-and-several Article 14 cases
- Treating Article 13 fault-of-injured-person reduction as a complete defence (it can extinguish but more commonly reduces)
- Single-defendant strategy that ignores Article 14 joint-and-several option
Article 9(1): Member States shall ensure that national courts may order, on the request of an injured person claiming compensation for damage caused by a defective product who has presented FACTS + EVIDENCE SUFFICIENT TO SUPPORT THE PLAUSIBILITY OF THE CLAIM, the disclosure of RELEVANT EVIDENCE that is at the disposal of the defendant. Article 9(2): courts may also, on the defendant's request, order injured person disclosure where the defendant has presented sufficient facts + evidence to support a defence. Article 9(3): the disclosure shall be limited to what is necessary + proportionate, considering the costs + burdens + commercial interests of the parties. Article 9(4): protection of trade secrets per Directive (EU) 2016/943 + confidential information must be preserved through procedural safeguards (in camera review + redaction + protective orders). This is one of the most consequenti
- Internal litigation-readiness file with categorised technical / safety evidence
- Trade-secret tagging + Article 9(4) protective-order playbook
- Document-retention policy aligned with the 10-year (and 25-year) long-stop
- Refusing court-ordered disclosure (triggers Article 11(2)(a) defectiveness presumption)
- No internal litigation-evidence inventory
- Trade secrets not tagged + redactable for in camera review
PLD: Software, AI and Cybersecurity Defect Coordination
Article 4(1) explicitly includes software (whether embedded or supplied separately) + Article 4(21) cross-references the AI system definition from the EU AI Act. The 2024 PLD therefore covers AI systems as 'products' and AI-system defects as 'product defects'. Article 10(c) singles out the 'effect of any ability of the product to continue to learn after deployment' as a factor in the defectiveness assessment - directly addressing self-learning AI systems whose behaviour changes over their lifecycle. Article 17(2)(c) failure-to-update rule additionally applies: an AI provider that fails to deliver necessary security / safety updates loses the state-of-the-art defence. The European Commission WITHDREW its proposed AI Liability Directive (COM(2022) 496) in February 2025; the 2024 PLD is therefore now the operative civil-liability regime for AI-product damage, supplemented by sectoral produc
- AI-product PLD exposure analysis
- Self-learning drift monitoring + intervention thresholds
- Article 11(4) explainability documentation
- Coordination with EU AI Act + MR + MDR safety obligations
- AI provider treating EU AI Act compliance as sufficient (it does not extinguish PLD civil liability)
- No explainability documentation - Article 11(4) presumption may otherwise apply against the AI provider
- No drift monitoring for self-learning AI products in field
Recital 38 + Article 10(f) make clear that a cybersecurity defect that compromises the safety of a product is a 'defect' for PLD purposes. A product with digital elements that fails to receive necessary security updates - where the manufacturer is required to provide such updates under EU law (notably the CRA Annex I Part 2 essential vulnerability handling requirements) - and the failure causes safety damage, is a defective product. This creates a direct civil-liability hook for cybersecurity-as-safety: the absence of patches that the manufacturer ought to have supplied is a PLD defect even though the cyber-physical failure occurred years post-market. The 10-year long-stop runs from initial placement-on-market but cybersecurity-related substantial modifications or software updates that introduce defects can trigger a fresh modifier-liability long-stop under Article 16(3) + Article 4(18).
- Cybersecurity-as-defect impact assessment for products with digital elements
- Patch-availability + security-update SLA tracked to PLD Article 17(2)(c) defence
- CRA Annex I Part 2 vulnerability handling compliance file
- Cybersecurity defect treated solely as CRA compliance issue without PLD exposure analysis
- Patch obligations not delivered making the state-of-the-art Article 17(2) defence unavailable
- No coordination between CRA + GPSR + PLD compliance programs
PLD: Subject Matter, Scope and Definitions
Article 1 establishes the subject matter: this Directive lays down common rules on liability of economic operators for damage suffered by natural persons caused by defective products. Article 2 sets the personal + material scope: applies to liability for damage caused by defective products placed on the market or put into service after 9 December 2026 (Article 22 transitional preserves Directive 85/374/EEC for products placed before that date). Article 3 sets the relationship to other Union law and to national law: this Directive shall not affect rights of injured persons under other Union or national law, in particular consumer protection law, contract law, environmental law, anti-discrimination law, product safety + market surveillance law including GPSR (Regulation (EU) 2023/988); also without prejudice to specific liability rules under Regulation (EU) 2018/1139 (civil aviation), Coun
- Internal scoping memo for products placed on the market / put into service after 9 Dec 2026
- Mapping of which products + claims fall under 85/374/EEC (legacy) versus 2024/2853 (new)
- Coordination matrix with GPSR market surveillance + medical devices + machinery + AI Act regimes
- Treating PLD as a market-surveillance instrument (it is a no-fault civil liability regime, not a regulatory product-safety regime)
- Claims against products placed on the market before 9 Dec 2026 incorrectly framed under the new PLD
Article 4 sets out 22 definitions including: (1) 'product' = all movables, even if integrated into another movable or into an immovable; product includes electricity, digital manufacturing files, and SOFTWARE (whether embedded in a tangible product or supplied as a standalone product / SaaS); (4) 'related service' = a digital service that is integrated into or inter-connected with a product in such a way that its absence would prevent the product from performing its functions; (5) 'component' = a tangible OR intangible item, including software OR related service, integrated into or inter-connected with a product by or under the control of the manufacturer; (6) 'manufacturer' = a natural or legal person who develops + produces + manufactures the product or has it designed / manufactured AND markets it under its own name + trademark, and where the manufacturer is not established in the Uni
- Internal classification matrix for which company offerings qualify as a 'product' or 'related service' under PLD 2024/2853 Article 4(1)/(4)
- AI integration documentation per Article 4(21) cross-reference to EU AI Act Article 3
- Substantial-modification triggers per Article 4(18)
- Treating SaaS / standalone software as outside PLD scope (it is now squarely in scope)
- Substantial-modification rule not internalised into the product change-management process
- AI-component liability misattributed solely to the AI provider when it integrates into a wider product
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.