NEWSLETTER REGULATORY UPDATE

Product Liability for Medical Devices: An Overview of the New Law

The new Product Liability Act tightens product liability requirements for software used in medical devices. The more digital systems continue to learn or receive updates after they are placed on the market, the more important the question becomes: development risk or manufacturer control? It is precisely this distinction that will determine liability for medical devices in the future.

Waage und Medizinprodukt als Symbol für Produkthaftung und Medizinproduktehaftung unter dem neuen Produkthaftungsgesetz
Waage und Medizinprodukt als Symbol für Produkthaftung und Medizinproduktehaftung unter dem neuen Produkthaftungsgesetz

Product Liability for Medical Devices: An Overview of the New Law

The new Product Liability Act tightens product liability requirements for software used in medical devices. The more digital systems continue to learn or receive updates after they are placed on the market, the more important the question becomes: development risk or manufacturer control? It is precisely this distinction that will determine liability for medical devices in the future.

Teilen Sie diesen Beitrag:

Teilen Sie diesen Beitrag:

An Overview of the New EU Product Liability Directive

The new Product Liability Directive replaces Directive 85/374/EEC and, with it, a liability regime that essentially dates back to a time before software, cloud services, and self-learning algorithms. The basic principle remains unchanged: product liability remains strict liability. An injured party does not have to prove wrongdoing on the part of the manufacturer, but rather the defectiveness of the product, the damage, and the causal link. The framework surrounding these principles has been modernized, and this has a particularly significant impact on medical devices.

Expanded Definition of “Product”: According to Article 4 of the EU Product Liability Directive, software, digital manufacturing files, and raw materials are also expressly considered products. For medical devices, this means that standalone software, embedded software, apps, and AI systems fall directly within the scope of the directive—regardless of whether they are provided on a data carrier, as a download, or as a service.

Expanded Scope of Parties Subject to Liability: In addition to the manufacturer, Article 8 lists, among others, component manufacturers, importers, authorized representatives, fulfillment service providers, and—on a subsidiary basis—distributors and online platforms. Anyone who substantially modifies a medical device and subsequently makes it available may also be held liable as a manufacturer.

Expanded Definition of Damages: Pursuant to Article 6, the following are eligible for compensation : death and bodily injury, including medically recognized mental health impairments; property damage; and the destruction or damage of data that is not used exclusively for professional purposes. The previous deductible of 500 euros for property damage no longer applies, nor does the possibility of a national liability cap.

The New Product Liability Act: Germany’s Implementation

In Germany, the directive is being implemented through the Act on the Modernization of Product Liability Law. This is the first comprehensive reform of the Product Liability Act since 1989 and thus the most significant change to German product liability law that medical device manufacturers have experienced in the past three decades. The government’s draft bill has been available since February 2026 (BT-Drs. 21/4297); following the first reading in March 2026 and the hearing in the Legal Affairs Committee, the parliamentary process is still ongoing. It must be completed by December 9, 2026.

In practice, this means that the new Product Liability Act incorporates the provisions of the EU Product Liability Directive but, in several areas, makes use of national discretion—for example, regarding procedural matters, the protection of trade secrets in the context of disclosure, and the determination of compensation for non-pecuniary damages. Manufacturers should therefore closely monitor the final version of the Product Liability Act and not base their processes solely on the text of the directive. However, those who are already planning based on the Directive are not working in a vacuum: the substantive core—the definition of a defect, relaxed standards of proof, disclosure obligations, and time limits—is prescribed by European law and will be reflected in national law.

Medical Device Liability: MDR-Compliant, Yet Still Liable?

Those who have successfully guided their medical device through the conformity assessment process conducted by a Notified Body often believe they are in the clear. This is precisely where the most common misconception regarding medical device liability lies.

Civil courts determine independently whether a product is defective for purposes of liability law. According to Article 7 of the Directive, the criterion is whether the product provided the level of safety that the general public could reasonably expect, assessed on the basis of a number of circumstances, which expressly include relevant product safety requirements and interventions by competent authorities. MDR compliance and a positive assessment by the Notified Body thus serve as significant evidence in favor of the manufacturer in this evaluation. However, they do not have a binding effect or preclude liability.

In short, this means that a medical device may have been legally on the market for years but could still be retroactively classified as defective—for example, because the state of science and technology has advanced, because comparable products now offer a higher level of safety, or because a known risk was not consistently minimized. Conformity assessment is a regulatory snapshot in time, not a liability shield.

Liability Risks Throughout the Entire Product Life Cycle

A key shift in perspective concerns the point in time that matters. Safety is no longer viewed merely as a snapshot at the time of market release, but as an ongoing responsibility throughout the entire product life cycle.

This is made clear by the liability exemptions in Article 11. The classic defense based on development risk—that the defect was not detectable given the state of science and technology at the time the product was placed on the market—remains in effect in principle. However, it does not apply if the defect is due to a circumstance that remains under the manufacturer’s control: for example, a software update or upgrade, a related service, or an update that was necessary but not provided.

As a result, inadequate product monitoring, failure to provide safety updates, or risk mitigation measures taken too late can directly give rise to liability. Risk management, post-market surveillance, PMCF, and vigilance—already core obligations under the MDR—are thus coming even more into focus because they now indirectly influence civil liability. Anyone who collects PMS data but fails to analyze it, or identifies trends without taking appropriate action, creates not only a regulatory finding but also a documented liability risk.

Documentation Becomes a Liability Factor

This situation is exacerbated by two procedural changes that, in practice, carry at least as much weight as the substantive changes. Disclosure of Evidence (Art. 9): If an injured party presents facts that make their claim plausible, the court may require the defendant to disclose relevant evidence in a comprehensible and accessible form. This may include technical documentation, risk management files, clinical evaluations, and PMS and vigilance data. This does not imply an obligation to disclose all documentation; the order must be proportionate, and trade secrets must be protected. In practice, however, the negotiating position shifts significantly. Presumptions Regarding Defectiveness and Causation (Art. 10): If the manufacturer fails to comply with a disclosure order, or if the injured party faces excessive difficulty in proving defectiveness or causation due to technical or scientific complexity, the court may presume these facts. These relaxations of the burden of proof amount to a partial reversal of the burden of proof: The presumptions are rebuttable, but the burden of rebuttal then lies with the manufacturer. For manufacturers, this means a shift in focus: Documentation is no longer prepared solely for Notified Bodies and regulatory authorities, but potentially for a court. A traceable, complete, and consistent chain of evidence—from risk analysis through clinical evaluation to PSURs and vigilance reports—thus becomes a central component of the defense strategy. Anyone with gaps in this area risks not only regulatory trouble but also a significantly increased risk of litigation.

Product Liability for Software and AI in Medical Devices

The situation is becoming even more challenging for software- and AI-based medical devices. Product liability for software was controversial under the old law; now it is explicitly regulated. Adaptive algorithms, continuous updates, and a high degree of dependence on data quality simultaneously create sources of error that did not exist under traditional product liability law. Article 7 explicitly lists circumstances characteristic of this product category: the effects of a product’s learning capabilities, the effects of other products on which the product reasonably depends, and relevant cybersecurity requirements.

In practical terms, this makes the following, among other things, relevant:

  • inadequately validated or non-representative training data;
  • algorithmic drift and performance degradation in real-world operation;
  • missing or delayed security and functional updates;
  • Inadequate monitoring of field behavior and model quality;
  • Interfaces to third-party systems, cloud services, and data sources.

Cybersecurity as a Liability Factor

Under the new liability regime, cybersecurity is no longer purely an IT issue, but rather an element of the definition of a defect: A vulnerability that impairs the intended use or safety of a medical device may constitute a defect within the meaning of product liability. For manufacturers, this means documenting cybersecurity processes—vulnerability management, patch and update cycles, coordinated vulnerability disclosure, and monitoring—in such a way that they serve as evidence of due diligence in the event of a dispute. Anyone who fails to patch a known vulnerability thereby potentially forfeits the defense based on development risk.

In addition, several regulatory frameworks overlap when it comes to AI systems: the MDR, the AI Regulation (EU) 2024/1689, and the Product Liability Directive take different approaches but rely on the same supporting documentation. It is worthwhile to structure post-market performance monitoring, update management, and cybersecurity documentation in such a way that they can be used in all three contexts.

Deadlines, Transition Periods, and Grace Periods

The time frame is clearly defined, and it has significant economic consequences:

  • The new rules apply to products placed on the market or put into service after December 9, 2026.
  • For medical devices that were made available prior to that date, the existing Product Liability Act based on Directive 85/374/EEC remains applicable.
  • Pursuant to Article 16, claims generally become time-barred three years after the claimant becomes aware of the damage, the defect, and the liable economic operator.
  • Under Article 17, claims expire ten years after the product is placed on the market. In the case of personal injury that manifests itself only later (delayed effects), the maximum period is extended to 25 years.

For medical devices with long market cycles and implants that remain in the body for extended periods, the 25-year period means that documentation and traceability must remain available well beyond the product’s life cycle. Archiving strategies, data formats, and responsibilities should be designed with this in mind, even in the event that product lines are sold, suppliers are changed, or systems are migrated.

Conclusion

The key message of the new Product Liability Directive is this: Formal compliance alone is no longer sufficient. Manufacturers would be well advised to integrate regulatory compliance, risk management, post-market surveillance, and liability-proof documentation more closely in the future, rather than treating them as separate areas of responsibility. Specifically, it is advisable to consider the following six points:

  • Gap Analysis: Which medical devices will be placed on the market for the first time or re-marketed after December 9, 2026—and will therefore be subject to the new Product Liability Act?
  • Update and Lifecycle Management: Have responsibilities, deadlines, and trigger criteria for security and functional updates been defined and documented?
  • PMS and Vigilance Effectiveness: Do identified trends demonstrably lead to corrective actions—and is this causal chain evident in the records?
  • Quality of Documentation: Is the chain of evidence structured in such a way that it would withstand judicial disclosure—consistent, versioned, and supported by traceable rationale?
  • Software and Cybersecurity: Are vulnerability management, update deployment, and post-market performance monitoring regulated for every software-based product?
  • Insurance and Archiving: Do coverage limits, extended liability periods, and retention periods align with the maximum periods of 10 and 25 years, respectively?

It is no longer enough for a medical device to meet all requirements at the time of market launch; rather, its safety must be transparently monitored, evaluated, and documented throughout the entire product lifecycle. Those who establish these processes properly at an early stage are significantly better positioned in the event of an emergency—not only from a regulatory standpoint but also in terms of liability.

FAQ: Frequently Asked Questions About the Product Liability Act

Directive (EU) 2024/2853 entered into force on December 8, 2024, and must be transposed into national law by December 9, 2026. It applies to products placed on the market or put into service after December 9, 2026. For medical devices made available earlier, the previous law remains applicable.

The Product Liability Act is undergoing its first comprehensive reform since 1989. Key changes include an expanded definition of “product” to include software, a broader range of liable economic actors, new disclosure requirements and simplified burden of proof, the elimination of the 500-euro deductible for property damage, and maximum limitation periods of 10 and 25 years, respectively. The government’s draft bill is available (BT-Drs. 21/4297); implementation must be completed by December 9, 2026.

Medical device liability refers to liability for damages caused by a defective medical device. It encompasses strict liability under the Product Liability Act, tort-based manufacturer liability under Section 823 of the German Civil Code (BGB), and contractual claims. The new Product Liability Directive primarily affects the strict liability component—and integrates it much more closely with the regulatory obligations of the MDR.

No. MDR compliance and a positive opinion from a Notified Body are strong indicators of a product’s safety, but they do not preclude civil liability. Civil courts independently determine whether a medical device provided the level of safety that could reasonably be expected.

Yes. According to Article 4 of the Directive, software is explicitly considered a product—whether embedded, provided as a stand-alone application, or delivered as a service. For AI-based medical devices, the ability to learn, dependencies on other products, and cybersecurity requirements must also be taken into account when assessing errors.

That is possible. The defense based on development risk does not apply if the defect stems from a circumstance that remains under the manufacturer’s control—this includes software updates and upgrades, as well as updates that were necessary but not provided. This explicitly applies to cybersecurity patches as well.

Not generally, but in specific cases. Under Article 10, a court may presume that a product is defective or that there is a causal link if proving the claim would pose undue difficulty for the injured party due to technical or scientific complexity, or if the manufacturer fails to comply with a disclosure order. These presumptions are rebuttable—the burden of proof then effectively lies with the manufacturer.

Under Article 9, a court may order the disclosure of relevant evidence if the claim is plausibly stated. The order must be proportionate and take trade secrets into account; it does not entail blanket disclosure of all technical documentation. In practice, however, the quality of the documentation becomes a central focus of the defense.

The statute of limitations is three years from the date of becoming aware of the damage, the defect, and the liable economic operator. Regardless of this, claims expire ten years after the product is placed on the market; in the case of latent damage that becomes apparent only later, the maximum limitation period is extended to 25 years.

Contact Us

Are you planning to bring a medical device to market and looking for an experienced contract manufacturer? Contact us for a no-obligation consultation. Together, we’ll develop the right strategy for your medical device.

More exciting news for you

  • 24. August 2026

    Health Data and the GDPR in Workplace Chats: When a Diagnosis Becomes “Information for Everyone”

  • 20. August 2026

    Product Liability for Medical Devices: An Overview of the New Law

  • 24. June 2026

    Clinical Evaluation in Practice – More Than Just a Clinical Evaluation Report