The Entry into Force of the Cyber Resilience Act (CRA) Strengthens the Security of Digital Products and Data Protection
The Polish data protection authority (UODO) has detailed the implications of the Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, and its interactions with the GDPR.
Article 14 of this regulation will apply from 11 September 2026 and will concern products with digital elements, such as mobile applications or connected objects. It imposes on manufacturers an obligation to notify actively exploited vulnerabilities and serious incidents affecting the security of their products. This notification must include an early warning within 24 hours, followed by a full report within 72 hours from becoming aware of the event. Other provisions of the law will come into force on 11 December 2027.
The president of the UODO emphasized that, although distinct from the GDPR, the Cyber Resilience Act strengthens system security and promotes the consideration of data protection by design. The notification obligations arising from the CRA and the GDPR are parallel and cumulative; a report under the CRA does not replace data breach notifications provided for in Article 33 and Article 34 of the GDPR, as confirmed by recital 32 of the CRA. This new regulation fills a gap by informing data controllers of security flaws in the products they use, even when the manufacturer is not their processor. Reports will be made via a single notification platform managed by the European Union Agency for Cybersecurity (ENISA), through the competent national CSIRT.
Article 14 of this regulation will apply from 11 September 2026 and will concern products with digital elements, such as mobile applications or connected objects. It imposes on manufacturers an obligation to notify actively exploited vulnerabilities and serious incidents affecting the security of their products. This notification must include an early warning within 24 hours, followed by a full report within 72 hours from becoming aware of the event. Other provisions of the law will come into force on 11 December 2027.
The president of the UODO emphasized that, although distinct from the GDPR, the Cyber Resilience Act strengthens system security and promotes the consideration of data protection by design. The notification obligations arising from the CRA and the GDPR are parallel and cumulative; a report under the CRA does not replace data breach notifications provided for in Article 33 and Article 34 of the GDPR, as confirmed by recital 32 of the CRA. This new regulation fills a gap by informing data controllers of security flaws in the products they use, even when the manufacturer is not their processor. Reports will be made via a single notification platform managed by the European Union Agency for Cybersecurity (ENISA), through the competent national CSIRT.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire