Civil Law And Connected Consumer Product Litigation In Europe .

Civil Law And Connected Consumer Product Litigation In Europe

1. Introduction

Connected consumer products are physical products that communicate with networks, cloud platforms, applications, sensors or other devices. Examples include:

smart televisions;

smart watches;

connected cars;

smart refrigerators;

connected medical devices;

smart speakers;

home-security systems;

connected toys;

smart thermostats;

IoT appliances;

fitness trackers; and

products controlled through mobile applications.

Litigation involving these products is more complicated than ordinary defective-product litigation because the "product" may consist of several interconnected elements:

physical hardware + software + app + cloud service + connectivity + updates + third-party components.

European private law therefore has to determine who is liable when the physical product works properly but the software, cybersecurity, cloud service or digital component causes the harm.

Direct reported European case law specifically concerning IoT products remains relatively limited. Consequently, the most useful authorities include CJEU and national cases concerning defective products, consumer conformity, software-related functionality, manufacturers, sellers and remedies. The newer EU Product Liability Directive 2024/2853 is especially important because it expressly brings software, interconnected products, related digital services and certain software updates into the product-liability framework. (EUR-Lex)

2. Meaning of a Connected Consumer Product

A connected product generally contains:

physical hardware;

embedded software/firmware;

network connectivity;

mobile or web application;

cloud infrastructure;

data-processing functions;

security mechanisms; and

sometimes AI or machine-learning functions.

For example:

A connected car may contain mechanical components manufactured by Company A, software supplied by Company B, a navigation service operated by Company C and a mobile application supplied by Company D.

If the vehicle suddenly brakes because of defective software, the legal question becomes:

Who is the legally responsible economic operator?

3. European Legal Framework

The principal legal regimes include:

A. Product liability

Historically, the central EU instrument was Directive 85/374/EEC.

It established a system of no-fault liability for defective products.

B. Consumer sales law

Consumer conformity rules govern whether the product supplied to the consumer conforms to:

contractual specifications;

description;

quality;

functionality;

durability; and

reasonable consumer expectations.

C. Product safety law

Connected products may also be subject to European product-safety legislation.

D. Data protection

Connected products collect enormous quantities of:

personal data;

location data;

behavioural data;

biometric information;

usage information.

Consequently, GDPR and other digital regulations can operate alongside civil liability.

E. Cybersecurity

A connected product may become unsafe because its software contains an exploitable vulnerability.

F. New Product Liability Directive

Directive (EU) 2024/2853 substantially modernises EU product liability for the digital age.

It expressly treats software as a product, including software supplied through cloud technologies or software-as-a-service arrangements. It also recognises interconnected products, related services and software updates. (EUR-Lex)

4. The New EU Product Liability Regime

This is particularly important for connected-product litigation.

The new Directive defines "product" broadly to include:

movable products;

electricity;

software;

digital manufacturing files;

raw materials; and

products integrated into or interconnected with other products.

A "related service" can also form part of an interconnected product where its absence would prevent the product from performing one or more of its functions. (EUR-Lex)

The Directive also expressly addresses:

software updates;

upgrades;

cybersecurity vulnerabilities;

AI systems;

cloud-based software;

interconnected components.

It provides that a manufacturer may remain liable where a defect arises later through software or related services that remain under the manufacturer's control. (EUR-Lex)

Important date

Following the 2026 corrigendum, the Directive applies to products placed on the market or put into service after 8 December 2026. Member States must transpose it by 9 December 2026. Products already placed on the market before the relevant date remain governed by the transitional regime under the older Directive. (EUR-Lex)

5. Case Law

Case 1 — Boston Scientific Medizintechnik, Joined Cases C-503/13 and C-504/13

CJEU, 5 March 2015

This is one of the most important European product-liability decisions.

The litigation concerned:

pacemakers; and

implantable cardioverter-defibrillators.

A potential defect was identified in products belonging to a particular group or production series.

The CJEU held that where products belonging to the same group or production series have a potential defect, an individual product may be classified as defective without proving that the particular individual device actually manifested the defect.

The Court also held that costs of surgery required to replace a defective medical device could constitute compensable personal injury under the Product Liability Directive. (EUR-Lex)

Importance for connected products

The principle is highly relevant to:

connected medical devices;

smart wearables;

connected vehicles; and

IoT products produced in a defective batch.

If a manufacturer discovers a systemic safety defect affecting a connected-device series, litigation may not always require proof that every individual unit has already failed.

6. Case 2 — Faber, C-497/13

CJEU, 4 June 2015

Ms Faber purchased a second-hand car from a garage. The vehicle caught fire approximately four months after purchase.

The dispute concerned the consumer's burden of proving that the defect existed when the vehicle was delivered.

The CJEU interpreted the EU consumer-sales regime in favour of effective consumer protection.

The Court held that where a lack of conformity becomes apparent within the relevant presumptive period, the consumer does not necessarily have to establish the precise technical cause or origin of the defect in the same manner as a sophisticated expert would.

The CJEU's consumer-rights materials summarise the decision as establishing that when the defect becomes apparent within six months, the consumer does not have to prove its cause or origin, although the consumer must establish the lack of conformity and its appearance within the relevant period. (curia)

Connected-product relevance

The reasoning is useful where a consumer's:

smart car;

connected appliance;

smart device; or

electronic product

fails shortly after delivery, but the manufacturer argues that the consumer cannot identify the precise software or hardware cause.

7. Case 3 — Gebr. Weber GmbH v Wittmer and Putz v Medianess Electronics, Joined Cases C-65/09 and C-87/09

CJEU, 16 June 2011

These cases involved defective consumer goods.

In one case, defective tiles had already been installed. In the other, a defective dishwasher had been installed.

The Court considered whether the seller had to bear the cost of:

removing the defective product; and

installing the replacement product.

The CJEU held that consumer remedies could require the seller to bear those costs, subject to the applicable proportionality limitations. (InfoCuria)

Importance for connected products

The principle can become significant where a connected product is integrated into a larger system.

Examples:

defective smart heating system;

defective connected solar equipment;

defective smart-home controller;

defective charging equipment;

connected appliance installed in a building.

The dispute may involve not merely replacement of the device but the cost of disconnecting, reinstalling and reconfiguring the connected system.

8. Case 4 — Quelle AG v Bundesverband der Verbraucherzentralen, C-404/06

CJEU, 17 April 2008

A consumer purchased a defective household appliance.

The seller replaced the defective product but sought compensation for the consumer's prior use of the defective product.

The CJEU held that the consumer was not required to pay compensation to the seller for the use of the defective product before replacement.

The Court emphasised the effectiveness of the consumer's statutory remedies. (curia)

Connected-product relevance

Consider a smart refrigerator that becomes defective after several months.

A seller should not automatically be able to say:

"You used the defective product for six months, so you must pay us for those six months of use before receiving a replacement."

The Quelle principle is therefore important when determining the financial consequences of defective connected goods.

9. Case 5 — Ford Italia, C-157/23

CJEU, 19 December 2024

This is a particularly significant modern product-liability authority.

The underlying dispute concerned a Ford vehicle manufactured by one company and distributed through the Ford group in Italy. The vehicle was involved in an accident because its airbag failed to operate.

The CJEU examined when a supplier may be treated as a producer for purposes of product liability.

The Court held that a supplier may fall within the producer-liability framework where its name or trademark corresponds to the distinguishing mark placed on the product, even though another company actually manufactured the vehicle. (curia)

Connected-product significance

Connected products frequently involve complicated corporate structures:

manufacturer → brand owner → distributor → software supplier → dealer → consumer.

The Ford Italia decision is important because liability cannot always be resolved simply by asking:

"Which company physically manufactured the object?"

Branding and the role of the economic operator can also become legally significant.

10. Case 6 — Boston Scientific and the Concept of Systemic Product Risk

The second Boston Scientific ruling concerning the same litigation is particularly useful when considering connected-device risk management.

The Court recognised that a product may be defective because of an abnormal potential for damage associated with products belonging to a particular group or series.

The underlying reasoning is important for connected products because manufacturers increasingly discover vulnerabilities through:

fleet-wide data;

telemetry;

cybersecurity testing;

software monitoring;

recall databases;

connected-device diagnostics.

The European product-liability system therefore increasingly focuses on reasonable safety expectations rather than simply whether the individual physical object has visibly broken. (EUR-Lex)

11. Case 7 — Gebr. Weber and Putz: Integrated Products

The Weber/Putz litigation deserves separate attention because it illustrates the legal difficulty created when a product is physically integrated into another object.

A connected product may similarly be:

device → building → network → cloud → application.

For example, suppose a smart-home security system is defective and has been permanently installed.

The consumer's loss might include:

purchase price;

removal costs;

installation costs;

reconfiguration;

professional technician fees;

consequential property damage.

The CJEU's approach in Weber/Putz demonstrates that consumer remedies cannot necessarily be reduced to the simple exchange of a defective physical object. (InfoCuria)

12. Case 8 — Faber: Evidentiary Problems

Connected-product litigation creates unusually difficult evidentiary questions.

A consumer may say:

"My smart car suddenly accelerated."

The manufacturer may respond:

"There is no evidence of a hardware defect."

But the actual cause might involve:

firmware;

sensor calibration;

an application;

an update;

network communication;

cloud processing;

cybersecurity intrusion.

Faber is important because it demonstrates the broader European concern that consumer remedies should not become practically impossible merely because the technical cause of a defect is difficult for the consumer to establish. (curia)

13. Is Software a Product?

This is one of the most important questions in modern connected-product law.

Under the older product-liability regime, there were significant conceptual difficulties surrounding software.

The new Product Liability Directive changes the position substantially.

Software is expressly treated as a product, including software:

embedded in hardware;

supplied independently;

accessed through networks;

supplied through cloud technologies;

supplied through software-as-a-service models.

AI systems are also expressly contemplated within the new framework. (EUR-Lex)

Therefore:

Defective software can become a product-liability issue even where the software is not contained inside a traditional physical object.

14. Connected Product and Cybersecurity Defects

A connected product can become dangerous because its manufacturer fails to address a cybersecurity vulnerability.

Examples:

Smart car

Hackers manipulate steering or braking.

Smart lock

A vulnerability permits unauthorised entry.

Medical device

A security weakness interferes with operation.

Smart toy

A vulnerability exposes children to dangerous third-party access.

Industrial consumer appliance

A compromised control system causes overheating or fire.

The new Product Liability Directive specifically addresses the relationship between software updates, cybersecurity vulnerabilities and product defectiveness.

It restricts the ability of economic operators to escape liability merely because the defect arose after the product was placed on the market where the defect involves failure to supply necessary security updates that were within the manufacturer's control. (EUR-Lex)

15. Failure to Update

Suppose:

2027 — Consumer buys smart car.

2028 — Manufacturer discovers critical security vulnerability.

2028 — Manufacturer fails to provide necessary security update.

2029 — Vulnerability is exploited and causes physical injury.

The litigation may involve:

original product defect;

subsequent defect;

software update;

cybersecurity;

manufacturer's control;

causation;

foreseeability;

damage.

The new EU framework is designed to deal with precisely this type of lifecycle problem.

16. Manufacturer's Continuing Control

The new Directive recognises that modern manufacturers may continue exercising control over a product long after the original sale.

Control may involve:

software updates;

upgrades;

connected services;

AI algorithms;

third-party applications;

authorised components.

A manufacturer can therefore potentially remain responsible for a defect that arises later through software or related services under its control. (EUR-Lex)

17. Third-Party Applications

Consider a smart television:

TV manufacturer → TV operating system → third-party streaming application → cloud service

If the application causes the television to become unsafe, the allocation of liability becomes complicated.

The new Directive specifically contemplates situations in which a manufacturer presents a third-party digital component as part of the product or authorises its integration.

This is important because the consumer normally does not negotiate separate contracts with every software supplier.

18. Internet Connectivity

A connected product may depend upon an internet connection.

However, the new Directive distinguishes between:

the product itself;

related services;

internet-access services.

Internet-access services themselves are generally not treated as related services within the manufacturer's control.

Nevertheless, a product that relies on connectivity but fails to maintain safety when connectivity is lost may potentially be considered defective. (EUR-Lex)

19. Cloud Services

Cloud infrastructure presents another difficulty.

Example:

A smart medical device works correctly when connected to its manufacturer's cloud platform. A cloud software error causes incorrect instructions to be sent to the device.

Possible defendants include:

hardware manufacturer;

software developer;

cloud-service provider;

distributor;

importer.

The new EU product-liability framework's inclusion of software and related services is designed to address these digital supply chains more effectively than the traditional physical-product model. (EUR-Lex)

20. Product Defect and Contractual Non-Conformity

Two different claims must be distinguished.

Product-liability claim

Consumer suffers legally recognised damage because a defective product caused harm.

Consumer-sales claim

The product does not conform to the sales contract.

For example:

Smart refrigerator does not connect to Wi-Fi.

This might initially be a conformity/consumer-sales problem.

But:

Smart refrigerator has a software defect causing electrical overheating and a house fire.

This may become a product-liability claim.

Both regimes may potentially operate alongside one another.

21. Types of Defects

Connected-product litigation can involve three principal categories.

A. Manufacturing defect

One particular batch is defective.

Example:

A sensor is incorrectly installed.

B. Design defect

The product is inherently unsafe.

Example:

A smart lock can be remotely opened without authentication.

C. Software/digital defect

The physical product is sound but the software is unsafe.

Example:

A connected car's software incorrectly processes sensor information.

The third category is becoming increasingly important.

22. Causation

Causation is often the most difficult issue.

Suppose:

Connected car → software bug → incorrect braking → collision → injury.

The claimant must establish a sufficiently strong connection between:

defect → accident → damage.

But multiple factors may exist:

driver behaviour;

road conditions;

software;

hardware;

cybersecurity attack;

maintenance;

network failure.

The court may therefore require expert technical evidence.

23. Damage

Under the new EU product-liability regime, compensable damage includes, among other things:

death;

personal injury;

medically recognised psychological injury;

property damage;

certain destruction or corruption of data not used for professional purposes.

The Directive therefore adapts the traditional product-liability concept to digital products and data-related harms. (EUR-Lex)

24. Evidence and Technical Complexity

Connected-product cases often involve information controlled by the defendant.

Relevant evidence can include:

source-code information;

system logs;

telemetry;

error reports;

update history;

cybersecurity records;

internal safety assessments;

recall data;

communications between manufacturer and software supplier.

The new Directive expressly introduces mechanisms concerning access to evidence, recognising that injured persons may otherwise have difficulty proving a technically complex product defect. (EUR-Lex)

25. Data as Damage

Connected devices continuously create data.

Examples:

health data;

location information;

photographs;

home-security recordings;

fitness information;

financial information.

A defective product may destroy or corrupt such data.

The new EU product-liability regime specifically recognises certain destruction or corruption of data not used exclusively for professional purposes as compensable damage. (EUR-Lex)

This represents a significant development from traditional product-liability law.

26. Consumer Expectations

The concept of safety that consumers are entitled to expect remains central.

For a traditional kettle, consumers expect:

electrical safety;

thermal safety;

structural integrity.

For a connected kettle, reasonable expectations may additionally include:

secure software;

safe remote operation;

reliable firmware;

safe integration with the manufacturer's application;

appropriate security updates.

Consequently, "product safety" increasingly encompasses both physical and digital safety.

27. Distributor and Supplier Liability

Connected products often move through complicated supply chains.

Possible participants include:

manufacturer → importer → distributor → retailer → consumer

The Ford Italia decision is especially relevant to determining when a supplier may be treated as a producer for EU product-liability purposes. (curia)

This becomes particularly significant where the consumer cannot realistically identify the company responsible for the underlying technical defect.

28. Marketplace Platforms

Online marketplaces create another layer.

A consumer may purchase:

Smart device → online marketplace → third-party seller → manufacturer outside EU.

Litigation may concern whether the platform is:

merely an intermediary;

a seller;

an importer;

an economic operator;

a producer-like entity.

The precise answer depends on the contractual structure and applicable EU and national legislation.

The new EU product-liability regime is designed around economic operators and digital supply chains, rather than only traditional factory manufacturers.

29. Recall of Connected Products

Connected technology makes recalls different.

Traditional recall:

"Return the physical product."

Connected-product recall may instead involve:

software update;

disabling a dangerous function;

remote diagnosis;

firmware replacement;

physical replacement;

account notification;

cybersecurity remediation.

This creates an important question:

Can a software update cure an otherwise defective product?

The answer will depend on:

the nature of the defect;

the safety risk;

whether the update is effective;

whether physical damage has already occurred;

whether the manufacturer controls the update process.

30. Contractual Exclusion Clauses

Manufacturers may attempt to rely on clauses such as:

"The manufacturer is not responsible for software failures."

Such clauses cannot automatically eliminate mandatory statutory product-liability or consumer-protection rights.

A distinction must be made between:

contractual allocation of commercial risk; and

mandatory liability rules protecting consumers.

This is particularly important where the product causes death, personal injury or property damage.

31. Remedies

Possible remedies include:

Consumer-sales remedies

repair;

replacement;

price reduction;

termination;

refund.

Product-liability remedies

compensation for personal injury;

property damage;

qualifying data loss;

consequential losses recognised under applicable law.

Other remedies

Depending on national law:

injunction;

declaratory relief;

recall;

corrective measures;

restitution;

damages.

32. Limitation Periods

Limitation rules depend on the legal basis of the claim and national implementation.

The new Product Liability Directive provides a three-year period for compensation claims, together with a general 10-year liability period and a 25-year period for certain latent personal injuries. (EUR-Lex)

This is important for connected products because some defects may not become apparent immediately.

33. Civil-Law Classification

Connected-product disputes may simultaneously involve:

Contract law

Was the product as promised?

Tort/delict law

Did the product unlawfully cause damage?

Product liability

Was the product defective?

Consumer law

Were statutory consumer rights respected?

Data protection

Was personal data unlawfully processed?

Cybersecurity law

Was an appropriate level of security maintained?

Intellectual property

Was software or digital content unlawfully used?

Thus, one connected-product accident can generate multiple legal claims simultaneously.

34. Comparative European Position

IssueTraditional productConnected product
DefectPhysical defectPhysical + software + digital
ManufacturerUsually identifiableMultiple economic operators
Product lifetimeRelatively fixedContinues through updates
SafetyPhysicalPhysical + cybersecurity
EvidencePhysical inspectionLogs, code, telemetry
RecallPhysical replacementUpdate + replacement
DamageInjury/propertyInjury/property/data
Supply chainManufacturer/distributorHardware/software/cloud/platform
CausationUsually physicalMay involve algorithms/networks
Consumer expectationProduct safetyProduct + digital safety

35. Key Case-Law Principles

CaseCourtMain principle
Boston Scientific, C-503/13 & C-504/13CJEUSystemic potential defect can establish defectiveness
Faber, C-497/13CJEUConsumer evidentiary protection concerning lack of conformity
Gebr. Weber & Putz, C-65/09 & C-87/09CJEUReplacement/removal and installation costs
Quelle, C-404/06CJEUNo compensation for consumer's use of defective goods before replacement
Ford Italia, C-157/23CJEUSupplier may fall within producer-liability framework
Boston ScientificCJEUSafety expectations particularly important for high-risk products
Weber/PutzCJEUConsumer remedies can extend beyond simple physical replacement
FaberCJEUTechnical uncertainty should not make consumer remedies practically impossible

The first five are particularly important primary authorities; the repeated Boston Scientific, Weber/Putz and Faber principles are useful for applying those authorities to the newer connected-product context.

36. Practical Example

Suppose a consumer purchases a connected electric vehicle.

The vehicle contains:

physical braking system;

sensors;

embedded software;

mobile application;

cloud platform;

automatic software updates.

A software vulnerability causes incorrect braking and an accident.

The litigation may proceed as follows:

Step 1 — Identify the product

Is the vehicle itself defective?

Step 2 — Identify the digital component

Was the software defective?

Step 3 — Identify control

Who controlled the relevant software?

Step 4 — Identify the economic operator

Manufacturer? Software developer? Supplier? Distributor?

Step 5 — Establish causation

Did the defect cause the accident?

Step 6 — Establish damage

Personal injury? Property damage? Data loss?

Step 7 — Examine evidence

Logs, updates, telemetry and technical records.

Step 8 — Apply the relevant regime

Product liability + consumer conformity + applicable national civil law.

Step 9 — Consider limitation

Was the claim brought within the applicable period?

37. Major Legal Issues for Future Litigation

The most important emerging issues are:

AI-controlled consumer products

autonomous vehicles

smart medical devices

cybersecurity defects

failure to provide security updates

cloud-dependent products

third-party applications

algorithmic product defects

data destruction

software-as-a-service

digital manufacturing files

interoperability failures

connected-home systems

product recalls through software

cross-border online marketplaces

manufacturer versus platform liability

proof of algorithmic causation

access to technical evidence

The new Directive expressly recognises many of these technological realities, including software, AI systems, cloud delivery, interconnected products, related services and software updates. (EUR-Lex)

38. Conclusion

Connected consumer product litigation represents the transition of European civil liability from a purely physical-product model to a combined physical-digital model.

The traditional questions were:

Was the product physically defective?
Who manufactured it?
What physical damage occurred?

The connected-product model requires additional questions:

Was the software defective?
Was the product safely designed to operate when disconnected?
Who controlled the update?
Was a cybersecurity vulnerability left unresolved?
Which company supplied the related digital service?
Who has access to the technical evidence?

The cases of Boston Scientific, Faber, Weber/Putz, Quelle and Ford Italia provide important foundations, while the 2024 Product Liability Directive represents the major legislative transition toward expressly recognising software, interconnected products, related services, cybersecurity vulnerabilities and digital damage. (EUR-Lex)

Exam Revision Keywords

Connected product – IoT – smart device – product liability – defective product – software defect – cybersecurity – firmware – software update – cloud service – AI product – related service – manufacturer – supplier – distributor – consumer conformity – reasonable safety expectations – causation – technical evidence – data loss – recall – replacement – restitution – damages – Product Liability Directive 2024/2853 – digital consumer protection.

LEAVE A COMMENT