Uncategorized

EU Product Liability Directive for Dropshippers: Risk After December 9, 2026

The new EU Product Liability Directive covers post-December 9 products, software and supply chains. Map importer, fulfilment, distributor and platform risk.

Quick answer: Directive (EU) 2024/2853 applies to products placed on the EU market or put into service after December 9, 2026. It modernises no-fault liability for defective products, expressly covers software and digital manufacturing files, recognises cybersecurity and connected services in the defect analysis, and makes it easier to find an EU-based defendant when a manufacturer is outside the Union. A dropshipper is not automatically liable for every defective product, but private labelling, importing, fulfilment arrangements, distribution and failure to identify the responsible operator can place a business in the liability chain.

Updated: September 2, 2026

EU Product Liability Directive: key takeaways

  • Member States must transpose Directive (EU) 2024/2853 by December 9, 2026.
  • The new regime applies to products placed on the market or put into service after that date.
  • Products include software, digital manufacturing files, raw materials and electricity.
  • Related digital services can matter when they are integrated or interconnected so the product cannot perform a function without them.
  • Private-label sellers can be treated as manufacturers.
  • When the manufacturer is outside the EU, an importer, authorised representative or—if neither exists—a fulfilment service provider can be liable.
  • A distributor can become liable if it does not identify the relevant EU operator or its own supplier within one month of a request.
  • Certain online platforms can enter the same identification route.
  • Labels, instructions, foreseeable use, software learning, connected products, recalls and cybersecurity can all affect whether a product is defective.
  • Supplier contracts and insurance allocate commercial risk but do not erase a victim’s statutory rights.

What changes after December 9, 2026?

The new Product Liability Directive replaces Directive 85/374/EEC for products placed on the market or put into service after December 9, 2026. The old regime continues for earlier products. The relevant date is therefore the placement of the product on the market or putting it into service, not simply the date a claim is filed.

The official text of Directive (EU) 2024/2853 requires Member States to adopt the necessary national laws by the same date. Ecommerce businesses selling across the EU must monitor implementation in the countries connected to their products, customers and operations.

The Directive remains a no-fault product-liability system. An injured person does not need to prove negligence in product design or manufacturing, but must establish the elements required by the regime: a defective product, compensable damage and a causal link, subject to the Directive’s evidence and presumption rules.

Why December inventory needs a boundary

Create a reliable record of when each unit or batch was first placed on the EU market. A purchase-order date, warehouse arrival, marketplace listing and consumer delivery are not automatically the same legal event. Ask counsel how the rule applies to your exact supply chain, especially for stock held in fulfilment centres before December 9 and sold later.

Which products and services are covered?

The definition of product now reflects digital commerce. It includes all movables, even when integrated into or interconnected with another movable or an immovable. It expressly includes:

  • software, whether stored on a device or supplied through cloud access;
  • digital manufacturing files containing functional information needed to produce a tangible item, including files for automated control of tools or 3D printers;
  • raw materials;
  • electricity.

Free and open-source software developed or supplied outside a commercial activity is excluded, but a commercial manufacturer integrating such software into a product can still face responsibility for the finished product.

Related services

A related service is a digital service integrated into or interconnected with a product so that the product could not perform one or more functions without it. Examples can include a companion application, cloud control service or navigation data that is necessary for an advertised function.

This matters to dropshippers selling connected devices. The physical item, firmware, app, cloud service and later security updates should be assessed as one operational system where the product depends on them.

Our Cyber Resilience Act guide explains the separate incident-reporting and cybersecurity supply-chain work for products with digital elements.

Who can be liable in a dropshipping chain?

The Directive creates a hierarchy designed to leave an injured person with an EU-based operator to pursue.

Operator When the role can arise Dropshipping example
Manufacturer Develops, manufactures or produces a product, has it made, or markets it under its name or trademark. A store sells a supplier’s appliance under the store’s own brand.
Component manufacturer Makes a physical or digital component integrated into the defective product. A battery, control board or companion-app provider contributes to the defect.
Importer Places a product from a third country on the EU market. An EU merchant or wholesaler brings a non-EU product into the Union.
Authorised representative Has a written mandate from the manufacturer for specified tasks and can enter the hierarchy defined by the Directive. A non-EU manufacturer appoints an EU representative.
Fulfilment service provider Can be reached when the manufacturer is outside the EU and no importer or authorised representative in the Union can be held liable. An EU warehouse performs at least two covered fulfilment functions for a non-EU product.
Distributor Makes a product available in the supply chain other than as manufacturer or importer and can face liability under the identification rule. An online retailer resells an already imported branded product.
Online platform Can enter the distributor-style rule when it allows distance contracts and the Digital Services Act conditions are met. A marketplace presents the transaction so an average consumer believes the product is supplied by the platform or under its authority or control.

Private label is a legal decision

A merchant that puts its name, trademark or own brand on a product can be treated as a manufacturer. Changing the logo, packaging or listing identity can therefore change more than search visibility. Before launching private-label inventory, obtain technical documentation, traceability, safety testing, change-control information, insurance and a recall plan appropriate to a manufacturer role.

This expands on our general guide, Can You Be Sued for a Dropshipping Product?, which discusses broader business structures and insurance. The present guide focuses specifically on the EU Directive and its operator hierarchy.

Importer and fulfilment-service-provider risk

The importer is not simply the courier

An importer is a person established in the EU who places a product from a third country on the Union market. Do not assign this role from the shipping term, tax setting or parcel label alone. Map who contracts for the product, who brings the exact unit into the EU supply chain and which entity appears in compliance information.

When fulfilment can enter the chain

If the manufacturer of the defective product or component is established outside the EU, the Directive first looks to the importer or the manufacturer’s authorised representative. Where neither can be held liable, a fulfilment service provider can be liable.

The Directive defines a fulfilment service provider as a person offering at least two of warehousing, packaging, addressing and dispatching without owning the product, excluding the specified postal, parcel-delivery and freight services. A standard carrier is therefore not automatically a fulfilment service provider.

Questions for a 3PL

  • Which legal entity contracts for the service?
  • Which functions does it perform for each SKU?
  • Who is the importer and how is that documented?
  • Does the product show the EU manufacturer, importer or authorised representative?
  • Can the 3PL trace affected units by batch, serial number and customer?
  • How quickly can it stop dispatch, quarantine stock and support a recall?
  • What insurance applies and what exclusions cover customer products?

Moving from direct shipping to an EU warehouse can improve delivery times, but it does not automatically solve product-liability mapping. Review the role before scaling, using the commercial triggers in our guide on leaving AliExpress for a private supplier or 3PL.

The one-month identification rule

Where an injured person cannot identify an EU-established economic operator in the primary hierarchy, a distributor can be liable if two conditions are met:

  1. the injured person asks the distributor to identify the relevant EU operator or the distributor that supplied it; and
  2. the distributor fails to provide that identification within one month.

This turns supplier identity into a live claims process, not a document to search for after a complaint. A support ticket requesting the manufacturer or importer must be escalated immediately. Do not leave it in a normal returns queue until day 29.

Online platforms

The same rule can apply to a platform that enables consumers to conclude distance contracts when it is not already an economic operator and the conditions in Article 6(3) of the Digital Services Act are fulfilled. Those conditions concern presentation that would lead an average consumer to believe the product or service is provided by the platform itself or by a trader acting under its authority or control.

A seller using a marketplace should still maintain its own operator data. Platform participation does not transfer every legal role to the marketplace.

A one-business-day internal target

The legal period is one month, but an internal response target should be much shorter. Keep verified operator data attached to the SKU and prepare a review path for formal claims. Early identification also helps safety investigations and insurance notifications.

How the Directive assesses a defect

A product is defective when it does not provide the safety a person is entitled to expect or that EU or national law requires. Article 7 instructs courts to consider all circumstances, including:

  • presentation, labelling, design, technical features, composition and packaging;
  • assembly, installation, use and maintenance instructions;
  • reasonably foreseeable use;
  • the product’s ability to continue learning or acquiring features;
  • the foreseeable effect of other interconnected products;
  • the time it was placed on the market or, where the manufacturer retains control, when it left that control;
  • relevant product-safety and cybersecurity requirements;
  • product recalls or interventions by authorities or economic operators;
  • the specific needs of the group of users for whom the product is intended;
  • for a life-extending product, the characteristics of the product whose life it extends.

The product page can become evidence

A listing that overstates load capacity, age suitability, waterproofing, compatibility or security can shape the safety a customer is entitled to expect. Supplier copy is not independent evidence. Verify material claims and preserve the version shown when each batch was sold.

Cybersecurity and updates

For connected products, missing security updates can matter where the manufacturer retains control of software or related services. A supplier’s promise of “free lifetime updates” should state who supplies them, for which exact model, until what date and how customers receive critical notices.

Build fact-based pages using our high-converting product-page guide, but remove urgency or performance claims that cannot be substantiated.

Damage, evidence and presumptions

The Directive covers death or personal injury, including medically recognised damage to psychological health; damage to or destruction of property other than the defective product itself, subject to the Directive’s conditions; and destruction or corruption of data not used for professional purposes.

The injured person must prove defectiveness, damage and causation. The new rules also allow courts to order a defendant to disclose relevant evidence, limited to what is necessary and proportionate, while protecting confidential information and trade secrets.

When defectiveness can be presumed

The Directive contains presumptions in specified situations, including where a defendant fails to disclose evidence, where the product does not comply with mandatory safety requirements intended to protect against the risk that occurred, or where damage was caused by an obvious malfunction during reasonably foreseeable use or ordinary circumstances.

Where excessive technical or scientific complexity makes proof excessively difficult, courts can also use rebuttable presumptions under the conditions set by the Directive. This is important for AI-enabled and connected products whose design, logs and updates are controlled by several companies.

Preserve records before the claim

  • supplier identity and contracts;
  • test reports and declarations;
  • batch, model and serial numbers;
  • product-page versions and advertisements;
  • instructions and warnings supplied to the customer;
  • software and firmware versions;
  • support and security-update dates;
  • complaints, failure patterns and corrective actions;
  • import, warehouse and fulfilment records;
  • recall and customer-contact capability.

Supplier contracts, records and insurance

A supplier contract cannot remove rights that the Directive gives an injured person. It can determine how businesses allocate costs, evidence and cooperation between themselves.

Contract clauses to review

  • exact legal manufacturer and EU operator;
  • notification before design, component, factory or software changes;
  • compliance with applicable safety and cybersecurity rules;
  • delivery of test reports, declarations, instructions and warnings;
  • batch and serial traceability;
  • incident reporting and escalation times;
  • stop-sale, recall and customer-notification cooperation;
  • preservation and disclosure of technical evidence;
  • indemnity, defence, jurisdiction and recovery costs;
  • minimum product-liability and cyber-insurance limits;
  • tail coverage after the supply relationship ends;
  • audit and termination rights for missing evidence.

Insurance questions

Ask a broker to confirm territories, product types, private-label activity, imports, online sales, recall costs, connected-product or software exclusions, aggregate limits and retroactive dates. A general business policy or LLC structure is not proof that a specific product claim is covered.

A pre-December catalogue audit

1. Segment by risk

Prioritise children’s products, batteries, electrical goods, load-bearing items, protective equipment, cosmetics, connected devices and products making health or safety claims.

2. Map each operator

Record manufacturer, component supplier, importer, authorised representative, fulfilment provider, distributor and marketplace for the exact SKU.

3. Verify product evidence

Collect documents from issuing sources. Match model numbers, factories and standards instead of accepting a generic PDF.

4. Audit presentation

Compare labels, instructions, warnings, product pages, ads and support scripts. Remove unsupported safety or compatibility claims.

5. Test traceability

Select a batch and identify every affected order. Then select an order and trace it back to the batch and supplier.

6. Test the one-month request

Ask support to identify the EU operator for three products. Measure whether it can produce accurate information within one business day.

7. Test stop-sale and recall

Confirm who can disable ads, marketplaces and checkout, quarantine warehouse stock and contact customers across languages.

8. Review contracts and insurance

Resolve exclusions, missing limits and suppliers that will not provide evidence before increasing spend.

Frequently asked questions

Does the new Directive apply to products sold before December 9, 2026?

The new Directive applies to products placed on the market or put into service after December 9, 2026. The previous Directive continues for earlier products.

Is a dropshipping store automatically liable as manufacturer?

No. Liability depends on the store’s role and conduct. A private-label seller can be treated as manufacturer; an importer or distributor can enter the chain through other rules.

Does software count as a product?

Yes. Software is expressly included, whether stored on a device or accessed through a communication network. The non-commercial free and open-source exclusion is limited.

Can a 3PL be liable?

Potentially. When a non-EU manufacturer is involved and no importer or authorised representative can be held liable, a fulfilment service provider meeting the definition can enter the hierarchy.

Is a courier a fulfilment service provider?

Not merely because it delivers a parcel. The Directive’s definition requires at least two specified services and excludes the named postal, parcel-delivery and freight services.

What is the distributor’s one-month rule?

If requested by an injured person, a distributor must identify the relevant EU economic operator or its own supplier. Failure to do so within one month can make the distributor liable.

Can a marketplace be liable?

In specified circumstances, a platform enabling distance contracts can enter the distributor-style identification rule when the Digital Services Act presentation conditions are met.

Do supplier terms remove liability?

No. Contracts can allocate costs between businesses but cannot remove a victim’s statutory rights under applicable law.

Does CE marking prove a product cannot be defective?

No. Compliance evidence matters, but defectiveness is assessed across all circumstances, including presentation, foreseeable use, instructions, connected products, recalls and cybersecurity.

Should I stop selling every non-EU product?

No. Build a risk-based process. Stop or pause products when the responsible operators, safety evidence, traceability, recall route or insurance cannot be verified.

Practical next step: Choose the five highest-risk products you expect to place on the EU market after December 9, 2026. For each one, write down the legal manufacturer, importer or authorised representative, fulfilment provider, batch identifier, applicable test evidence and insurer. Ask support to identify the EU operator from the SKU alone. If any row is blank or takes days to answer, fix the supply chain before scaling that product.

Editorial disclaimer: Dropshipper Lab is an independent educational website and is not affiliated with or endorsed by the European Commission, any national court or market-surveillance authority, Shopify, WooCommerce, any marketplace, supplier or insurer. This article summarizes Directive (EU) 2024/2853 and public EU materials reviewed on September 2, 2026. It is general educational information, not legal or insurance advice. National transposition, applicable law, operator classification, evidence, limitation periods and coverage should be assessed for the exact product and claim.

Disclosure: This article may contain affiliate links. If you make a purchase through one of these links, the author may earn a commission at no additional cost to you. This does not influence the content or our evaluation of the products and services discussed.

Disclosure: This article may contain affiliate links. If you make a purchase through one of these links, the author may earn a commission at no additional cost to you. This does not influence the content or our evaluation of the products and services discussed.

admin

Author of practical guides to dropshipping, ecommerce, automation, and growing an online business.