Save products you love by clicking the heart icon.
The code you shipped last month can make you personally liable for damages in 2036. That is not an exaggeration — it is the arithmetic of a law most developers have never read, set to change on 9 December 2026.
On that date, Germany's Product Liability Act (Produkthaftungsgesetz) gets its first comprehensive reform since 1989, transposing the EU's new Product Liability Directive 2024/2853. The headline change is deceptively simple: software is now legally a "product". Freelance developers are not exempt. The person who developed the software is, by definition, its "Hersteller" (producer).
I have read the German government draft (RegE, 17 December 2025) so you don't have to. Here is what actually changes, which European and German specifics matter, and the ten consequences that matter for freelance programmers. This is an informed summary, not legal advice — but it points to the exact provisions you should copy into a law-yer's inbox.
The EU adopted Directive (EU) 2024/2853 on 23 October 2024, replacing the 1985 Product Liability Directive. Member states must transpose it by 9 December 2026. The German implementation — officially "Gesetz zur Modernisierung des Produkthaftungsrechts" — passed cabinet in December 2025 (BR-Drs. 775/25) and is working its way through the Bundestag as the deadline approaches.
Three new features separate this from the 1985 regime:
The transition rule matters enormously: products placed on the market or put into service up to and including 8 December 2026 stay under the old law. Everything you ship from 9 December 2026 onwards is judged by the new rules.
The new §2 of the draft defines products as movable things, electricity, digital manufacturing files — and software, with one carve-out:
Software, with the exception of free and open-source software that is developed or made available outside a commercial activity.
So: your commercial client work, your SaaS, your plugins, your embedded frontends — all products. Hobby OSS with no commercial activity is outside the scope. If you are paid to maintain an OSS project, the carve-out may cease to apply — a nuance worth checking with counsel.
§3 is where freelancers should get uncomfortable:
A producer is anyone who develops a product or has it developed. Anyone who presents themselves as producer through name, brand or mark also counts.
There is no "it's the client's product" escape hatch. If you wrote the software, you developed it — you are a producer, strict liability without any fault requirement. The end user does not need a contract with you to sue you directly.
Two related provisions widen the net:
| Damage | Old law | New §1 |
|---|---|---|
| Death / physical injury | Yes | Yes, incl. medically recognised psychological harm |
| Property damage | Yes (private property) | Yes, property used exclusively for professional purposes excluded |
| Destroyed/corrupted data | No | Yes, if not used exclusively professionally |
The data category is new and, for software, the practical risk: a bug that wipes user data now directly triggers liability under §1(1)(3), with data defined via the EU Data Governance Act (Reg. 2022/868). Note the draft's property wording is broader than the directive: only property used exclusively for professional purposes is out — mixed-use and even mostly-business property may be in. The Directive's "normally intended for private use" test does not appear in the German draft.
The claimant side also limits the blast radius: only natural persons claim, and damage to business-only property/data of a company is excluded. A pure B2B internal tool where only the company's data is affected largely escapes this strict regime — but the moment consumers or their private data are in play, the whole law applies.
§7 keeps the classic test — a product is defective if it does not provide the safety one is entitled to expect — but the assessment now explicitly includes:
The decisive clock question is answered in §8: the defect is assessed at the moment the product was placed on the market or, if the producer kept control, when it left his control. Control exists if you can provide software updates yourself. And §9(2) removes the state-of-the-art/development-risk defence where the defect stems from a connected service, software updates, the lack of security updates needed to maintain safety, or a substantial modification.
Translated for a developer: if you still hold the keys — you operate the SaaS, you ship updates — you are judged on the current security state. A known CVE you never patched is a defect, and the "nobody knew better at the time" defence is gone for update-related failures.
Two sections introduce what is effectively US-style discovery into German product liability:
Keep records as if a court might order them produced — because, with plausibility shown, it can.
A project you stopped maintaining in 2027 can hit your insurance in 2037.
The reform does not criminalise shipping software — it makes the economics explicit: someone has to bear the risk of a defective product, and by default that someone is whoever developed it. For a freelancer the honest response is not a panic, but a config file: clarify producer roles in every contract, treat security patching as a contractual obligation with a paper trail, and fix the insurance gap before a claim finds it. The moving part is now — because everything you place on the market after 9 December 2026 runs on the new rules for the next ten years.
This article summarises the German government draft (RegE, 17 Dec 2025, BR-Drs. 775/25) and Directive (EU) 2024/2853. It is general information, not legal advice — the final enacted statute takes precedence.