EUREP

Does the GPSR apply to software and digital products?

Stefan Hülsiggensen

9 min read

Does the GPSR apply to digital products? When apps and software count as products, when a firmware update is a substantial modification, and who answers.

Bare green circuit board with two microchips on a dark grey surface

Your product runs on firmware, comes with a companion app or is itself an app, and your team ships regular updates. Does the GPSR apply to digital products like these? The General Product Safety Regulation (EU) 2023/988, the EU's safety law for consumer products, reaches software as a product in the Commission's reading, as part of a device's safety and through updates.

Is software a product under the GPSR?

Article 3(1) GPSR (opens in a new tab) defines a product as “any item, whether or not it is interconnected to other items”, paid for or free, that is intended for consumers or likely to be used by them. The definition does not mention software.

The Commission reads it broadly. Its guidelines on the GPSR (opens in a new tab) (Commission Notice C/2025/6233 of 21 November 2025) say the definition covers any item “whether tangible or non-tangible or of a mixed nature” and “includes apps and software products, including for example chatbots” (point 2.1).

The guidelines are not binding; binding interpretation lies with the Court of Justice of the EU (what the guidelines are). As the Commission's published reading, they make it prudent to treat a consumer app as a product.

Standalone app, companion app, firmware: three situations

How the GPSR reaches software
SituationExampleWhat the GPSR does
Standalone consumer appA fitness app, a chatbotProduct in the Commission's reading (guidelines, point 2.1)
App or cloud service controlling a deviceA heater's control appA non-embedded item in the device's safety assessment (Art. 6(1)(c))
Firmware inside a deviceA bottle warmer's heating controlPart of the product's design and technical features (Art. 6(1)(a))
How the GPSR reaches software

Devices with electronics are as a rule CE-marked, for example under the RoHS Directive 2011/65/EU on hazardous substances, the Electromagnetic Compatibility (EMC) Directive 2014/30/EU or the Radio Equipment Directive. For them, the GPSR's safety requirement covers only risks those acts leave open, such as self-learning features of low voltage devices (guidelines, point 2.2). Articles 9 to 18 GPSR do not apply (Article 2(1)); the EU operator follows from Article 4 of Regulation (EU) 2019/1020. Listing information, accident reporting and the recall rules apply either way.

What software adds to your GPSR risk assessment

Where the GPSR applies fully, the internal risk analysis comes before placing on the market (Article 9(2); our method). For software, four aspects matter most, on CE-marked devices only where sector acts leave the risk open:

  • Interconnection, both ways, including “non-embedded items” such as apps that change how the product works (points (b) and (c)). The guidelines' example: an update overworks the processor and the device overheats (point 3.1.1).
  • Cybersecurity where the nature of the product requires it, against influences that could affect safety, “including the possible loss of interconnection” (point (g)).
  • Evolving, learning and predictive functions where the nature of the product requires it (point (h)): behavior that changes after the sale.
  • Lifespan and children: safety over the actual duration of use (Article 3(2)); for connected products likely to affect children, “the highest standards of safety, security and privacy by design” (recital 23).

When a software update is a substantial modification

Recital 25 GPSR names software updates as a way to “substantially modify the original product”, which should then get a new risk assessment if safety is affected. Article 13(3) (opens in a new tab) sets the test, but not for CE-marked devices (Article 2(1)). A modification “by physical or digital means” is substantial where it has an impact on safety and:

  1. it changes the product in a way the initial risk assessment did not foresee;
  2. it changes the nature of the hazard, creates a new hazard or increases the risk; and
  3. consumers did not make it themselves, or have it made, for their own use.

A bug fix that leaves the risk unchanged fails the second criterion. The consequences depend on who ships the change:

  • Your own update: you remain the manufacturer. Assess it before release and keep the technical documentation up to date (recital 25, Article 9(3)).
  • A third party's firmware: a reseller or refurbisher that substantially modifies the product is deemed its manufacturer, for the part affected or, where safety is impacted, the entire product (Article 13(2)); to stay limited to the part, it must show the whole is unaffected (guidelines, point 3.4.4).

Software updates as a recall remedy

In a recall, consumers get a choice of at least two remedies among repair, replacement and refund, unless the others are impossible or disproportionate (Article 37(2)). Repair by consumers counts where it is easy, safe and set out in the recall notice; the operator then provides “free replacement parts or software updates” (Article 37(3); guidelines, point 3.4.2). An update can be the repair, but as a rule not the only option. These rules apply to CE-marked products too.

Example: a U.S. maker of a portable bottle warmer

A U.S. company sells a battery-powered bottle warmer to EU parents online. It runs on 5 volts, below the Low Voltage Directive's range from 75 volts DC (Article 1 of Directive 2014/35/EU (opens in a new tab)), and has no radio. It needs CE marking under the EMC and RoHS Directives; neither covers heating, so the GPSR does (Article 2(1)). Firmware controls the heating; updates install over the USB-C cable.

The bottle warmer's firmware under the GPSR
EventWhat appliesBasis
Before launchAssess temperature limits and cut-off for infants; the file names firmware 1.0Art. 5, 6(1)(a) and (e)
Version 2.0 heats fasterHigher scalding risk: assess before release, update the fileArt. 5, recital 25
An EU reseller installs its own “fast mode”No Article 13 for a CE product; the reseller may still only make available safe productsArt. 2(1), 5
Version 2.1 makes units overheatEU operator informs authorities; accidents notified through the Safety Business Gateway; recall: free fixed update plus a second remedyArt. 4(3)(c) Regulation (EU) 2019/1020; Art. 20, 37(2) and (3)
The bottle warmer's firmware under the GPSR

Where the GPSR stops: liability and cybersecurity law

Software in two other EU acts
ActSoftware coveredApplies
Product Liability Directive (EU) 2024/2853Software and digital manufacturing files (Art. 4(1))Through national law, to products placed on the market or put into service after 9 December 2026 (Art. 2(1), 22(1))
Cyber Resilience Act (EU) 2024/2847Software and hardware products with a data connection (Art. 2(1), 3(1))From 11 December 2027; reporting since 11 September 2026 (Art. 71(2))
Software in two other EU acts

The Product Liability Directive (opens in a new tab) links “substantial modification” to product safety rules (Article 4(18)): whoever substantially modifies a product outside the manufacturer's control and then makes it available becomes its manufacturer for liability (Article 8(2)); for your Authorized Representative's liability, see our article on the directive.

Once the Cyber Resilience Act (opens in a new tab) (CRA) applies, the GPSR, including Article 9, still covers the risks the CRA leaves out for products with digital elements not subject to specific safety requirements in other harmonization legislation (Article 11 CRA). Products placed on the market before 11 December 2027 fall under the CRA only after a substantial modification, but its reporting duties already apply (Article 69(2) and (3); see CRA reporting and, for radio devices, RED cybersecurity).

Common mistakes with software under the GPSR

  • Leaving the companion app out of the file. It is a non-embedded item that changes how the device works (Article 6(1)(c)).
  • Freezing the assessment at launch. Keep the documentation up to date (Article 9(3)).
  • Citing GPSR Article 9 for a CE-marked device. The sector acts set its technical documentation (Article 2(1)).
  • Waiting for the CRA. Cybersecurity that affects safety is already a GPSR aspect where needed (Article 6(1)(g)).

Conclusion: treat software as part of the product

The risk analysis and each update decision stay with you as manufacturer. As your GPSR Responsible Person or, for CE-marked devices, your EU Authorized Representative, Representa keeps your compliance files ready for inspections and handles communication with authorities, within the agreed scope and mandate. Our compliance verification audits your documentation, checks labels and packaging and coordinates missing tests.

Frequently asked questions

Does the GPSR apply to apps?

According to the Commission's guidelines (C/2025/6233, point 2.1), the product definition in Article 3(1) GPSR covers non-tangible items, including apps and software products such as chatbots, when consumers are likely to use them. The guidelines are not binding; only the Court of Justice of the EU can interpret the GPSR bindingly.

Is a firmware update a substantial modification under the GPSR?

Only if it affects safety and meets all three criteria of Article 13(3) GPSR: it changes the product in a way the initial risk assessment did not foresee, it changes the hazard or increases the risk, and it was not made by consumers for their own use. A bug fix that leaves the risk unchanged is not one. Article 13 does not apply to CE-marked devices (Article 2(1) GPSR).

Do I need an EU Responsible Person for a consumer app?

Neither the GPSR nor the guidelines say so directly. Article 16(1) GPSR makes no exception for software: if an app is a product covered by the GPSR, as the guidelines read it, it may only be placed on the market if an economic operator established in the EU is responsible for the tasks of Article 4(3) of Regulation (EU) 2019/1020. How the labeling duties apply to apps is open.

Does the GPSR cover digital downloads such as e-books or 3D print files?

Neither the GPSR nor the Commission's guidelines address them; the guidelines name apps, software products and chatbots. For liability, the Product Liability Directive treats digital manufacturing files as products when placed on the market after 9 December 2026 (Articles 2(1) and 4(1), (2)), but not the content of files such as e-books (recital 13).

Does the Cyber Resilience Act replace the GPSR for connected products?

No. From 11 December 2027 the CRA sets cybersecurity requirements. The GPSR still covers the risks the CRA leaves out, including its manufacturer duties where no other harmonization act sets specific safety requirements (Article 11 of Regulation (EU) 2024/2847). CRA reporting duties apply since 11 September 2026.

More insights

Apply this to your product

Talk to our team: we identify which of these requirements apply to you.

Stefan HülsiggensenFounder and Managing Director