Introduction
Have you ever downloaded an app that lost key features after an update, or cancelled a streaming subscription and wondered whether you were entitled to your money back? In today’s digital world, apps, games, SaaS platforms, and streaming services flow across borders like never before, raising questions about refunds, conformity, and fair contract terms. Enter the Consumer Rights Directive (CRD), Directive 2011/83/EU, a landmark EU consumer law that, together with the Digital Content Directive (Directive 2019/770), governs business-to-consumer contracts for digital products and services. Digital content means data produced and supplied in digital form, such as apps, games, music, videos, and e-books, whether downloaded, streamed, or supplied on a tangible medium like a USB drive or disc. Digital services cover things like cloud storage, social media, and SaaS. The goal is a high level of consumer protection that fuels fair cross-border trade, and your obligation as a trader is to know which rules apply and to comply with them end to end.
One update many providers still miss: the CRD was significantly amended by the Modernisation Directive 2019/2161, applicable since 28 May 2022, which extended its scope to digital content and digital services even where the consumer “pays” only with personal data, under the new Article 3(1a). It has been further amended by Directive 2024/825 on empowering consumers for the green transition, which Member States had to transpose by 27 March 2026 and must apply from 27 September 2026. So if you are working from outdated material or older terms, you are already behind. This article explores which directive applies to your digital product, the conformity and update duties, the pre-contract information obligations, the 14-day withdrawal right, and how these consumer protection rules fit alongside the GDPR. By the end, you will understand the core CRD obligations for app providers, SaaS platforms, and streaming services operating in the EU.
Scope of the CRD: Which Directive Applies to Your Digital Product
Getting scope wrong is a costly mistake, so this is where every compliance review should start. If your digital product is supplied on a tangible medium that serves exclusively as a carrier, for example a disc or USB stick containing only the software, its conformity still falls under Directive 2019/770, the Digital Content Directive, and not under the sale of goods rules. Directive 2019/771 on the sale of goods applies instead to goods with digital elements, such as a smart TV, a smartwatch, or a connected appliance. If your product is intangible, meaning it is downloaded, streamed, or accessed in-browser as SaaS, Directive 2019/770 is your home base.
These are different regimes, with different conformity criteria and different remedy pathways. Knowing which one applies to your product before drafting a single line of your terms is the foundation of Consumer Rights Directive compliance for app stores, subscription platforms, game publishers, and every business selling digital products or digital services to EU consumers.
Conformity and Updates: What Your Digital Product Must Deliver
So what does conformity actually mean for your business? Under Articles 7 and 8 of the Digital Content Directive, your digital product must match its description and possess the functionality and quality you have promised. It must remain compatible and interoperable with the hardware and software specified in the contract. It must also receive all updates, including security updates, that are necessary to keep it in conformity for the period set out in Article 8(2). Under Article 8(6), unless the parties have agreed otherwise, you must supply the most recent version available at the time the contract is concluded. And under Article 8(3), if a consumer fails to install an update you have properly notified within a reasonable time, and a defect results solely from that failure, you are not liable for that specific non-conformity. This shield only works if you informed the consumer about the update and the consequences of not installing it, and if the failure was not caused by shortcomings in your installation instructions.
Practically, this means mapping every product’s functionality, compatibility requirements, and update obligations before launch, specifying in your terms which version is supplied and how updates are delivered, and documenting your update notifications carefully. Article 12 of the Digital Content Directive places the burden of proof on you, the trader. Any non-conformity that becomes apparent within the first year, or at any time during the supply period in the case of continuous supply, is treated as having existed at the time of supply unless you can prove otherwise. Good records are not optional. They are decisive.
Pre-Contract Information Obligations: Transparency That Binds
Next come the transparency rules that prevent disputes before they start. Under Article 5 of the CRD for on-premises contracts, and Article 6 for distance and off-premises contracts, which is what most digital providers deal with, you must clearly disclose specific information before the consumer clicks “buy” or “subscribe”. Where applicable, this includes the functionality of the digital content or digital service, including any technical protection measures and DRM, under Article 6(1)(r). It also includes any relevant compatibility and interoperability with hardware and software that you are aware of or can reasonably be expected to be aware of, under Article 6(1)(s).
Why does this matter commercially? Because under Article 6(5) of the CRD, the information you provide pre-contract becomes an integral part of the contract and cannot be altered unless both parties expressly agree. Combined with the burden of proof rule in Article 12 of the Digital Content Directive, missing or vague disclosures hand the consumer the conformity argument on a silver platter. A quick checklist for your sales page and onboarding:
- List technical requirements, DRM restrictions, and tracking features visibly on the product page, not buried in your terms.
- Publish your update and modification policy before the purchase is made.
- Keep timestamped records of the pre-contract information displayed to each customer.
These simple steps add real legal protection.
The Withdrawal Right: Your Biggest Operational Risk
Now to the cooling-off period, where app stores, SaaS platforms, and streaming services most often slip up. Under Article 9 of the CRD, consumers have 14 days to withdraw from any distance or off-premises contract without giving any reason. For digital content not supplied on a tangible medium, which covers almost every download, stream, or in-app purchase, the right can be extinguished before those 14 days expire, but only if the strict conditions of Article 16(1)(m) are met. The conditions are the following:
- The consumer gives prior express consent to begin performance during the withdrawal period.
- The consumer acknowledges that they thereby lose the right of withdrawal.
- The trader provides confirmation of that consent and acknowledgment on a durable medium, in line with Article 7(2) or Article 8(7) of the CRD.
As amended by the Modernisation Directive, these conditions apply where the contract places the consumer under an obligation to pay. For “free” digital content provided in exchange for personal data, slightly different rules apply. If you fail to meet the conditions, the withdrawal right survives, and under Article 14(4)(b) of the CRD the consumer does not have to pay anything for what they have already used. If you fail to inform the consumer about the withdrawal right at all, the period extends by 12 months under Article 10. Once a consumer validly withdraws, you must reimburse all payments received without undue delay and within 14 days at the latest, under Article 13. Operationally, this means building a compliant consent and acknowledgment flow into your checkout, delivering the confirmation by email or another durable medium, and automating your refund process to comfortably meet the deadline.
Modifications, Remedies, and the Broader Compliance Architecture
Finally, how does all of this fit into your wider compliance setup? The CRD and Directive 2019/770 govern contract law, covering information duties, withdrawal rights, conformity, modifications, and remedies. The GDPR governs personal data processing. They are separate, parallel legal frameworks, both mandatory, and compliance with one does not substitute for the other. Your privacy policy and your contract terms serve different legal functions, so maintain them separately but keep them consistent.
Under Article 19 of the Digital Content Directive, you may modify a digital product supplied over a period of time beyond what is necessary to maintain conformity only if the contract allows it for a valid reason, the modification is made without additional cost, and the consumer is informed in a clear and comprehensible manner. If the modification negatively affects access or use in a more than minor way, the consumer may terminate the contract free of charge within 30 days, unless you enable them to keep the unmodified version at no extra cost and in conformity. On remedies, Article 14 of the Digital Content Directive first entitles the consumer to have the product brought into conformity, typically through fixes, patches, or the supply of a conforming version, free of charge, within a reasonable time, and without significant inconvenience. If that fails, is impossible, or is disproportionate, the consumer can request a proportionate price reduction or terminate the contract for any non-minor defect. Keep in mind that AI-specific obligations come from the EU AI Act, Regulation 2024/1689, and from the revised Product Liability Directive 2024/2853, not from the CRD.
Conclusion
In summary, the CRD and the Digital Content Directive establish a comprehensive contractual framework for digital products and services, fully applicable across the EU since the Modernisation Directive took effect on 28 May 2022 and evolving further with the green transition amendments that Member States must apply from 27 September 2026. Providers who know whether Directive 2019/770 or 2019/771 applies to their product, disclose functionality, compatibility, and DRM upfront, build a compliant withdrawal consent flow, and deliver and document updates correctly reduce dispute rates and build durable customer trust. If you want to ensure your digital product or service is compliant, book a call with our team or another qualified professional for personal guidance and concrete legal advice.
Reflecting on these obligations, the framework clearly rewards transparency and preparation. The information you publish before purchase becomes binding contract content, the records you keep carry your burden of proof, and the consent flows you build determine whether refund claims succeed. By keeping your CRD contractual obligations strictly separate from your GDPR data processing documentation, you turn digital borders into opportunities rather than risks. Stay informed to navigate this landscape effectively, and remember: Compliance with the law – prevents the flaw!