Your Rights

CRAPLDDSAConsumer RightsEU Compliance
Comply.Land Team
CRAPLDDSAConsumer RightsEU Compliance

When you buy something that connects to the internet, the law is on your side.

Three European laws protect you. The Cyber Resilience Act (CRA) keeps connected products secure. The Product Liability Directive (PLD) pays you back when a defective product causes harm. The Digital Services Act (DSA) protects you on the apps and platforms where you shop, order, and scroll. You do not need to be a lawyer or an engineer to use any of them.

Your rights under the Cyber Resilience Act

The CRA applies to most products with digital elements sold in the EU, from card readers and tablets, to smart cameras, baby monitors, routers, and fitness watches, along with the software inside them. A few categories, such as medical devices and cars, are covered by their own EU rules instead.

Secure from the start. Manufacturers must build security into the product before it reaches the shelf, which rules out shipping with a default password like “admin” or with known exploitable weaknesses already in it.

Free security updates. When a weakness is found, the manufacturer must fix it and send you the update at no cost. This lasts for the product’s support period. That period must reflect how long the product is expected to be in use, and it must be at least five years, unless the product is meant to be used for less time than that.

A clear support period. You will be able to see how long a product will receive security updates before you buy it. Like an expiry date, but for digital safety.

No silence when things go wrong. If attackers are actively exploiting a weakness, the manufacturer must send an early warning within 24 hours, a fuller report within 72 hours, and a final report within 14 days, to the national cyber incident team (CSIRT) and the EU cybersecurity agency (ENISA). Severe incidents follow the same 24 and 72 hour steps, with a final report within one month.

You hear about it too. Where a vulnerability is being actively exploited, or an incident affects the security of your product, the manufacturer must inform the people using it and explain what they should do about it.

A way to reach the maker. Every product must carry a contact point where anyone, including you, can report a security problem.

Some protections are already here

Many wireless products (routers, cameras, baby monitors, some wearables) already had to meet EU cybersecurity rules from 1 August 2025 under separate radio equipment rules. The CRA builds on and extends that.

When the rest arrives

  • From 11 September 2026: manufacturers must report actively exploited weaknesses and severe incidents.
  • From 11 December 2027: all CRA rules apply in full to every connected product sold in the EU, including Malta.

Your rights under the Product Liability Directive

The new PLD covers what happens when a defective product hurts you. For the first time, it clearly covers software and digital products.

Compensation without proving fault. If a defective product causes damage, you can claim compensation from the manufacturer. You do not need to prove the company was careless. You need to show the product was defective and caused the harm.

Software counts. Apps, operating systems, and AI systems are products under this law. A missing security update can make a product defective.

Your data counts. Damage now includes destruction or corruption of data that you do not use for work or business, not only physical injury or damage to property.

Help with the hard parts. Courts can order the manufacturer to disclose evidence. Where proving a technical defect is too difficult for an ordinary person, courts can presume the defect in your favour.

Someone in the EU to claim against. If the manufacturer is outside Europe, you can usually claim against the importer or the manufacturer’s EU representative, so you are rarely left with no one to claim against.

When these rights arrive

The new rules cover products placed on the EU market, including in Malta, from 9 December 2026. Products sold before then stay under the older rules.

Your rights under the Digital Services Act

The gadgets are one half of the story. The apps and platforms you use them through are the other. The DSA applies to online marketplaces, app stores, social networks, and delivery platforms operating in the EU. Think of the app that brought the order to the pastizzi counter.

A button to report illegal content and products. Every platform must give you an easy way to flag illegal goods, scams, and illegal content. The platform must act on your report and tell you what it decided.

Known sellers. Platforms that let you buy from other sellers must find out and display who the trader behind a listing really is. If you buy a gadget online, you should be able to see who is actually selling it.

An explanation when content is removed. If a platform removes your post, review, or listing, or restricts your account, it must tell you why. You get the right to complain and have the decision reviewed.

No dark patterns. Platforms may not design their interfaces to trick you, pressure you, or make cancelling harder than subscribing.

Honest advertising. You must be able to see that an ad is an ad, who paid for it, and why you were targeted. Ads may not target you based on sensitive data such as health or religion. Platforms may not show you profiling-based ads if they know with reasonable certainty that you are a minor.

A choice over your feed. Every platform must explain in its terms how it decides what you see. The largest platforms must also offer you at least one version of your feed that is not based on profiling.

A route to dispute resolution. If a platform’s internal complaint process fails you, you can take the dispute to a certified out-of-court settlement body.

When these rights arrive

They are already here. The DSA has applied in full across the EU since 17 February 2024.

How to report a problem

Something feels insecure?

A weak default password, no security updates, or a flaw the maker will not fix.

  1. Contact the manufacturer. Use the contact point on the product, its packaging, or its documentation.
  2. Contact the Maltese authority. The Malta Digital Innovation Authority (MDIA) is the prospective Market Surveillance Authority for connected products. Submit a regulatory complaint at mdia.gov.mt/services/regulatory-complaints, or email cyber.mdia [at] mdia.gov.mt.

Is the product physically dangerous?

Overheating, electrical risk, fire, choking hazard, or anything that could injure someone.

Safety Gate is the EU alert system for unsafe non-food products. Consumer reports feed alerts that national authorities across Europe act on, including recalls and withdrawals. Report at webgate.ec.europa.eu/consumer-safety-gateway.

Suffered actual damage from a defective product?

Keep the product, receipts, and any evidence of the harm. Speak to a lawyer or your local consumer protection office about a claim under the Product Liability rules. The Office for Consumer Affairs within the Malta Competition and Consumer Affairs Authority (MCCAA) can guide you on consumer remedies. If you bought from a trader in another EU country, the European Consumer Centre (ECC) Malta handles cross-border complaints.

Problem with an app, platform, or online marketplace?

  1. Use the platform’s own reporting tool. The DSA obliges every platform to provide one and to respond.
  2. Escalate to the Digital Services Coordinator. In Malta, the Malta Communications Authority (MCA) is the Digital Services Coordinator. You can complain to the MCA about any platform’s failure to meet its DSA duties, using the complaint form at mca.org.mt/content/dsa-complaint-form.
  3. Illegal or unsafe product sold online? Flag it through the platform, and report it through the Consumer Safety Gateway as well.

Quick answers

Do I have to do anything to get these protections? No. The duties sit with the manufacturer. The protection flows to you automatically.

Do these rules cost me anything? No. Security updates must be free. Reporting a concern is free.

Does this apply to products I already own? The CRA applies to products placed on the market from December 2027. Products already on sale before then are mostly exempt, except that makers must still report actively exploited security flaws found in them. The new PLD applies to products placed on the market from December 2026. Older products stay under existing consumer protection law. DSA rights apply now, on every covered platform you already use.

What about free or open source software? Software supplied in the course of a commercial activity is covered. Hobbyist and non-commercial open source projects are generally outside the CRA’s obligations. Organisations that support open source projects used in commercial products (known as stewards) have a lighter set of duties: a security policy, cooperation with authorities, and reporting of serious problems.

Who checks that manufacturers comply? Market surveillance authorities in each EU country. In Malta, that role is expected to sit with the MDIA. Most products are checked by the maker itself. Higher-risk products need an independent body to check them, and the most critical ones may need a formal EU cybersecurity certificate.

This page is general information, not legal advice. For advice on a specific claim, please consult a qualified lawyer.

References: Regulation (EU) 2024/2847 (Cyber Resilience Act). Directive (EU) 2024/2853 (Product Liability Directive). Regulation (EU) 2022/2065 (Digital Services Act). Commission Delegated Regulation (EU) 2022/30 (Radio Equipment Directive cybersecurity requirements).