On 9 December, Somebody in Europe Becomes Liable for Your Frames

VisioncarePro by

Verified on 14 September 2026 against the text of Directive (EU) 2024/2853 as published in the Official Journal. This article is general information about a law that is still being written into twenty-seven national statute books. It is not legal advice.

European product liability law has been essentially unchanged since 1985, which is to say it was written for a world of tangible objects made by identifiable factories and sold through identifiable shops. That framework is being replaced. Under Article 22, Member States must transpose Directive (EU) 2024/2853 by 9 December 2026. Under Article 21, the old Directive 85/374/EEC is repealed with effect from that date but continues to apply to products placed on the market or put into service before it.

Almost all of the commentary about this concerns AI systems and industrial manufacturers. There are provisions in it that concern a Shopify eyewear merchant a good deal more directly, and they are mostly about who gets sued rather than about what counts as defective.

The deadline is real. The uniformity is not.

Start here, because most coverage skips it. This is a directive, not a regulation. It does not apply to you on 9 December; twenty-seven national laws implementing it do, to the extent they exist.

According to a practitioner survey of national progress published in September 2026, the scoreboard roughly twelve weeks out looks like this:

  • Three Member States have actually transposed it. Hungary’s implementing law was adopted on 16 December 2025. Croatia amended its Civil Obligations Act and notified the Commission on 7 July 2026. Lithuania adopted Act XV-1080 on 25 June 2026, taking effect on 9 December 2026.
  • Twelve have published draft bills — Belgium, Cyprus, Czechia, Denmark, Finland, Germany, Italy, the Netherlands, Poland, Slovakia, Slovenia and Sweden — with Germany, Slovakia and the Netherlands furthest through their parliaments.
  • Seven are at an early stage with nothing published: Austria, Bulgaria, Estonia, France, Ireland, Latvia and Romania.
  • Five show no known public progress at all: Greece, Luxembourg, Malta, Portugal and Spain.

That is secondary reporting, it is a snapshot, and it moves week by week — check it again in November. But the shape of it is not going to change: a large majority of the EU will not have this in force on the day it is due, and for a period the law that applies to your frames will depend on which country your customer was standing in.

There is one divergence the directive invites on purpose. Article 18 lets Member States derogate from the development risk defence — the defence in Article 11 that an operator escapes liability if the objective state of scientific and technical knowledge when the product was placed on the market was not such that the defectiveness could be discovered. Member States may keep existing measures that impose liability anyway, or introduce new ones for specific product categories where justified by public interest and proportionate. Most drafts retain the defence. Finland is reported to be continuing to exclude it, Hungary limits it for medicinal products used as directed, and Germany keeps its existing carve-out for genetic engineering products. The defence you have in one market may not exist in the next.

The cascade: Europe will always have a defendant

The old regime had an obvious gap. If a consumer in Lisbon was injured by a product made in Shenzhen and bought from a website in Ohio, the theory of liability was fine and the practice was hopeless.

Article 8 closes it with a deliberate cascade:

  • The manufacturer of the defective product; and the manufacturer of a defective component, where the component was integrated into a product within that manufacturer’s control.
  • Anyone who substantially modifies a product outside the manufacturer’s control and thereafter makes it available on the market or puts it into service — that person “shall be considered to be a manufacturer” (Article 8(2)). More on this below, because it is the limb that touches an optical business daily.
  • Where the manufacturer is established outside the EU: the importer of the defective product or component, and the manufacturer’s authorised representative.
  • Where there is no importer established in the Union and no authorised representative: the fulfilment service provider.
  • Each distributor, where the injured person asks it to identify an economic operator further up the chain and it fails to do so within one month.
  • Online platforms, on the same basis as a distributor, but only where the conditions in Article 6(3) of the Digital Services Act (Regulation (EU) 2022/2065) are met — broadly, where the platform presents the product in a way that would lead an average consumer to believe it is supplied by the platform itself. It is a defined test, not a general marketplace liability.

Read that as a merchant shipping frames into Europe and the arithmetic is uncomfortable. If your frames are made outside the EU and you bring them in, you are the importer, and you answer as though you had made them. If a third-party logistics provider in the Netherlands is the only EU-established operator, that provider is exposed — and it has read Article 8 and will push the exposure back to you by contract. If you are a European stockist of somebody else’s brand, your protection is your ability to name your supplier within a month of being asked, which makes your purchase records a legal defence rather than an accounting artefact.

Three of the European posts on this blog end on the same structural point: EU rules attach to the imported object and its parcel. This is the consequence. The other regimes tell you what to do. This one says what happens when somebody is hurt.

Software is a product, and a missing patch can be the defect

Article 4(1) defines a product as “all movables, even if integrated into, or inter-connected with, another movable or an immovable”, and says it “includes electricity, digital manufacturing files, raw materials and software”. Article 4(4) makes a related service or intangible item that is integrated into or inter-connected with a product a component. Firmware, a companion app, an embedded AI feature: components, and capable of being defective.

Eyewear walked into this category during 2026. Prescription-first AI glasses launched through optical retail this spring; audio and camera frames sit in ordinary catalogues now. A store that added three connected SKUs to four hundred passive ones has acquired a product with digital components without any change in self-perception.

Article 7 puts cybersecurity in the text, not in a footnote. Among the circumstances for assessing defectiveness it lists “relevant product safety requirements, including safety-relevant cybersecurity requirements”, the product’s ability to learn or acquire new features after being placed on the market, and — critically — the moment the product was placed on the market or, where the manufacturer retains control after that moment, the moment the product left the manufacturer’s control. If you can still push an update, the clock on what the product was supposed to be does not stop at the sale.

Article 11 then closes the exit. A manufacturer generally cannot rely on the exemptions — including “the defect arose after I placed it on the market” — where the defectiveness is due to a related service, a software update or upgrade, or the absence of a software update or upgrade needed to maintain safety, or a substantial modification within its own control.

Set that beside the Cyber Resilience Act reporting obligations that started on 11 September 2026 and the shape is clear: the CRA tells you to report the vulnerability, and this directive is what happens if nobody fixed it. If you private-label connected frames — your logo on somebody else’s hardware, some control over the app — you should work out, on paper, who patches.

Does glazing a lens make you the manufacturer?

This is the question an optical business should actually ask, and nobody writing about this directive is asking it.

Article 8(2) makes a substantial modifier a manufacturer. Glazing is, in plain English, modification: you take a frame and you put lenses in it. Reglazing a customer’s own frame is modification of a product that was unquestionably already placed on the market, done outside the original manufacturer’s control, after which you put it into service. On a naive reading, every optician in Europe becomes a manufacturer of spectacles in December.

The answer is in the definition, and it is a good one. Article 4(18) defines a substantial modification as a modification after placing on the market or putting into service that either “is considered substantial under relevant Union or national rules on product safety”, or — only where those rules set no threshold — changes the product’s original performance, purpose or type in a way not foreseen in the manufacturer’s initial risk assessment and changes the nature of the hazard, creates a new one or increases the level of risk.

The first limb governs, because eyewear does have relevant Union product safety rules. As we set out in detail elsewhere, corrective spectacle frames and corrective ophthalmic lenses are Class I medical devices under Regulation (EU) 2017/745, and the Medical Device Coordination Group’s guidance on adaptable devices (MDCG 2021-3) says that a person who adapts, adjusts, assembles or shapes such a device is not regarded as a manufacturer but as a distributor — provided every component is CE-marked and the assembly follows the manufacturer’s instructions.

So ordinary glazing, done with certified components the way the lens maker specifies, is the thing the device rules have already decided is not manufacturing. Depart from either condition and you were already the manufacturer of a custom-made device under the MDR — and now you are a manufacturer under Article 8(1) of this directive too. The line that decides your product liability exposure is the same line that decides your device obligations, and it is crossed the same way: by sourcing an uncertified frame from a supplier who was cheap and vague.

Two honest caveats. MDCG guidance is guidance, not legislation, and Article 4(18) asks what is considered substantial under the rules. And how national courts treat the professional judgement in specifying a lens — product or service — is exactly the sort of question twenty-seven transpositions will answer differently. This is a strong argument, not a settled one. It is also the argument worth putting to your own counsel rather than assuming the naive reading.

One consequence to note either way: under Article 17, a substantial modification restarts the long-stop clock.

What counts as damage, and who can claim

Article 5(1) gives the right to compensation to “any natural person” who suffers damage caused by a defective product. Businesses do not claim under this directive.

Article 6 lists the heads of damage:

  • Death or personal injury, including medically recognised damage to psychological health.
  • Damage to, or destruction of, any property — excluding the defective product itself, products damaged by a defective component the manufacturer integrated, and property used exclusively for professional purposes.
  • Destruction or corruption of data that are not used for professional purposes.

Two things follow. A companion app that wipes a customer’s photo library is a damages claim rather than a support ticket. And there is no monetary lower threshold anywhere in Article 6 — the old regime’s €500 floor for property damage is simply gone, which makes small claims viable in a way they were not.

Evidence and presumptions: the part your insurer will notice

Two procedural shifts do more practical work than anything above.

Disclosure (Article 9). Where a claimant presents facts and evidence sufficient to support the plausibility of the claim, a court may order a defendant to disclose relevant evidence at its disposal. It is bounded: the order must be necessary and proportionate, and the court must weigh the legitimate interests of all parties, including the protection of confidential information and trade secrets, and may take specific measures to preserve them. It is not an American discovery process. It is still a mechanism that can reach into your supplier file.

Presumptions (Article 10). Defectiveness is presumed where the defendant fails to disclose evidence it was ordered to disclose; where the claimant demonstrates that “the product does not comply with mandatory product safety requirements laid down in Union or national law that are intended to protect against the risk of the damage suffered by the injured person”; or where the damage was caused by an obvious malfunction during reasonably foreseeable use. Causation is presumed where the product is defective and the damage is of a kind typically consistent with that defect. And where technical or scientific complexity makes proof excessively difficult, a court may presume defectiveness or causation on a showing of likelihood.

That second presumption is the one that matters to an eyewear catalogue, and the qualifier in it matters as much as the rule. It does not say that any compliance failure presumes defectiveness. The requirement you breached must have been intended to protect against the risk that actually caused this damage. A missing Responsible Person on a listing will not, by itself, presume a defect in a lens.

But plenty of eyewear requirements are squarely risk-protective. Plano sunglasses are personal protective equipment under Regulation (EU) 2016/425, category I, with UV filtration and filter category marking under EN ISO 12312-1. (That paragraph is about plano sunglasses only and does not extend to prescription lenses.) A sunglass lens that does not filter as its marked category claims is a failure of a requirement aimed precisely at the risk of eye damage. Non-compliance there is no longer just a listing-takedown risk — it feeds a presumption in a damages claim, and the technical file you never obtained from your supplier is the document a court will order you to produce, whose absence feeds a second one.

You cannot contract out of this

The draft advice everyone gives is “put indemnities in your supply contracts.” That advice is right, but incomplete in a way that matters.

Article 15 provides that an economic operator’s liability under the directive is not, in relation to the injured person, limited or excluded by a contractual provision or by national law. Nothing you sign with a supplier, and nothing in your terms of sale, reduces what an injured consumer can recover from you.

What a contract does is give you the route back. Article 14 preserves rights of recourse under national law, and Article 12 makes multiple liable operators jointly and severally liable. So the indemnity and the evidence-cooperation clause are worth having — they are how you get your money back after you have paid. They are not a shield at the front door.

How long the shadow runs

Article 16: a three-year limitation period, running from when the injured person became aware, or reasonably should have become aware, of the damage, the defectiveness, and the identity of the liable economic operator. All three.

Article 17: a ten-year expiry period from when the product was placed on the market or put into service, extended to twenty-five years where personal injury symptoms emerge slowly — and restarted for a substantially modified product.

Ten years is longer than most supplier relationships and longer than most companies keep purchase records.

What an eyewear seller should do before December

Establish, per supplier, who the EU-facing economic operator is. Manufacturer, importer, authorised representative. Write it down. If the honest answer for any line is “us”, that line has changed status.

Get the technical documentation into your own possession. Not a promise that the supplier holds it — the file. Under a disclosure order, “our supplier has it” is not an answer, and the missing file now supports a presumption.

Audit your frames for CE marking, and keep the evidence. This is the single action that does the most work, because it is what keeps you a distributor rather than a manufacturer under both the device rules and Article 8(2).

Put indemnity and evidence-cooperation clauses into supply contracts — knowing they buy you recourse, not immunity.

Separate the connected SKUs from the passive ones. Everything in the software section applies to a handful of products. Do not let it colonise a catalogue of ordinary frames.

For connected products, find out who patches and who owns the app. If you push or badge software updates, you may be a manufacturer. If nobody patches at all, you have a defect waiting to mature.

Extend your record retention to match Article 17. Ten years of purchase records, per SKU, per supplier.

Talk to your insurer before December, not after. Cover written against the 1985 regime does not contemplate software defects, data corruption, or a twenty-five-year tail.

Where the exposure sits, and where it does not

The pattern this blog has traced through tariffs, customs reform, environmental claims and product safety holds here too, and it is worth being precise about why, because the honest version is more useful than the tidy one.

You are not liability-free on lens work. A lens you specify and have made to order is a product, and you are close to its manufacturer. But that is exposure you can see: you chose the lab, you hold the spec, you have the records, you know the standard, and you can inspect what you sold. It is ordinary business risk of a kind opticians have carried forever. And as set out above, the device rules have already decided that doing that work properly, with certified components, keeps you a distributor rather than a manufacturer.

What the directive adds is different in character. It is inherited liability: the strict liability of a manufacturer, for hardware someone else designed, containing firmware you cannot read and cannot patch, evidenced by a technical file you were never given, with a ten-to-twenty-five year tail — acquired not by any decision to take on risk but by the fact that you were the one who brought the box into Europe.

A business whose growth comes from importing more units accumulates that inherited exposure with every SKU. A business whose growth comes from configuring higher-value orders around lens work it controls and can evidence does not. Fewer, better-configured, higher-value orders was already the answer to per-tariff-line customs duty, to packaging registration and to Section 301. It is now also the answer to a liability regime that follows the imported object.

Frequently asked questions

When exactly does this bite?
Member States must transpose by 9 December 2026 and the new rules apply to products placed on the market or put into service after that date. Products already on the market stay under Directive 85/374/EEC. But only three Member States had transposed as of September 2026, so in practice the answer for any given customer is “when their country gets round to it.”

We are a UK or US company with no EU entity. Does it reach us?
The framework attaches to products placed on the EU market, and its whole design is to ensure an EU-based defendant exists — importer, authorised representative, fulfilment provider or, in the DSA-defined circumstances, a platform. If that is a partner of yours, expect the contractual consequences to reach you.

Does glazing lenses into frames make us a manufacturer?
Probably not, if every component is CE-marked and you follow the manufacturer’s instructions — because the medical device rules already characterise that as distribution, and Article 4(18) defers to product safety rules on what counts as a substantial modification. Source off-spec or uncertified and the analysis changes completely. See the section above, and take advice on your own process.

Is a defective prescription lens covered?
A lens is a product, so in principle yes. How national law treats the professional judgement involved in specifying it is exactly the sort of question that will vary between twenty-seven transpositions.

Does this apply to our virtual try-on or lens-recommendation software?
Software is a product under Article 4(1), so the question is not whether it is in scope but whether a defect in it could cause one of the harms listed in Article 6. That is genuinely unsettled. Watch it; do not panic about it. (Your try-on tool has a more immediate problem in the United States.)

Can we cap this in our terms and conditions?
No. Article 15 says liability under the directive is not limited or excluded, as against the injured person, by contract or by national law.

Does this replace GPSR, the MDR and the CRA?
No. Those set the rules. This sets what happens when someone is injured — and non-compliance with a rule intended to protect against the risk that caused the injury now feeds a presumption of defectiveness in the claim.


VisioncarePro adds structured prescription capture and lens selection to any Shopify product page. The lens configuration is the part of an eyewear order you specify, control and can evidence — and the part that raises order value. Free to install.

Install VisioncarePro free on the Shopify App Store →


Sources: Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products and repealing Council Directive 85/374/EEC, Official Journal — Articles 4, 5, 6, 7, 8, 9, 10, 11, 12, 14, 15, 16, 17, 18, 21 and 22 read against the EUR-Lex text · Regulation (EU) 2022/2065 (Digital Services Act), Article 6(3) · Regulation (EU) 2017/745 (Medical Device Regulation) · MDCG 2021-3, guidance on adaptable medical devices · ECOO sector guidance on the Medical Device Regulation · Regulation (EU) 2016/425 and EN ISO 12312-1 · practitioner survey of Member State transposition progress published September 2026.

This article is general information, not legal advice. Product classification, economic operator status and liability position depend on your specific supply chain, the countries you sell into and the national law that ends up applying. Nothing here asserts a compliance or liability position for VisioncarePro or for any merchant. Take your own advice.

RuffRuff Apps RuffRuff Apps by Tsun