This week we look at:
- Tech law shorts – latest edition
- Consumer law: EU Right to Repair Directive applicable
- Trade and supply chain: UK-EU SPS Agreement
- Guidance on EU Cyber Resilience Act published
Tech law shorts – latest edition
In this edition of Tech law shorts we highlight key developments in EU technological sovereignty, global cyber resilience regulation and the trends affecting data centers, alongside global AI regulatory changes (check out our Middle East deep dive!)
Over the last quarter:
- The European Commission presented its Technological Sovereignty Package, introducing new frameworks for cloud sovereignty, semiconductor supply chains, open source development and energy digitalisation.
- In the wake of increased cyber threats and incident volumes, various jurisdictions are refining their approach to cyber resilience and regulation – we take a look at how the UK, US and EU are approaching this.
- Our data center deep dive highlights some of the challenges and opportunities those in the sector are currently mapping and managing.
- The UAE has brought together its AI and data regulation strategy.
- Globally in AI we’re seeing a shift from high-level AI principles to operational regulation.
For global technology businesses, this means reviewing external technology dependencies and cloud infrastructure against evolving EU sovereignty standards, strengthening cyber resilience and AI governance frameworks to meet heightened expectations and monitoring developing regulation to keep apace.
Read more here: Technology Law Shorts - July 2026.
Consumer law: EU Right to Repair Directive applicable
On 31 July 2026 the EU Right to Repair Directive became applicable. Its purpose is to encourage the repair rather than replacement of defective consumer products, and it is part of a package of EU measures focused on sustainable consumption. It:
- introduces a requirement of “repairability” for all consumer products
- amends the EU Goods Directive to incentivise consumers to choose repair rather than replacement of defective products, as if the consumer chooses repair the seller’s mandatory guarantee for the product is extended by at least 12 months
- introduces a standardised European Repair Information Form to improve transparency around repair costs and timing and an EU online repair platform, which will be available in 2027, to help consumers find suitable repairers
- requires manufacturers of certain types of products to repair defects in those products, once sellers’ liability under the Goods Directive has come to an end. Repairs must be carried out for free or at a reasonable price, and within a reasonable time. In-scope products are listed in an annex to the Directive and include washing machines, tumble dryers, dishwashers, fridges, vacuum cleaners, electronic displays, servers and data storage products, phones and tablets, with the Commission having the right to bring additional products within scope. Manufacturers must not impede third party repairs where the consumer chooses to have products repaired by a third party rather than the manufacturer. They must also provide consumers with easily accessible information about their rights regarding repair
Suppliers of consumer products to the EU market will need to comply with the new rules and non-EU manufacturers will need to have an EU authorised representative to perform repairs.
Businesses supplying consumer products to the EU should review product design, spare parts availability, repair networks, warranty processes, customer communications and restrictions on repairs in order to support compliance with the Directive.
Trade and supply chain: UK-EU SPS Agreement
On 30 July 2026 the Department for Environment, Food & Rural Affairs (DEFRA) published the findings from its call for information on the proposed UK-EU Sanitary and Phytosanitary Agreement (SPS Agreement).
The SPS Agreement is intended to reduce red tape at the border, making it easier and cheaper for plants, animals and their products (including food and drink) to be imported and exported, and abolishing the vast majority of routine checks on animal and plant products moving between the EU and Great Britain (including between Great Britain and Northern Ireland). The proposed SPS Agreement would be beneficial for UK and EU businesses currently dealing with the costs and delays caused by border checks and formalities.
However, the SPS Agreement will apply not only to exported goods, but also to goods produced for domestic consumption. It will also require dynamic alignment with EU standards. This has caused concern for many in the agri-food sectors, with the Central Association of Agricultural Valuers warning that the SPS Agreement poses a real risk to farming, with the potential for crops grown this autumn to be illegal to sell by the time of harvest 2027.
Responses to the call for information generally supported the potential for the SPS Agreement to reduce trade friction with the EU, with anticipated benefits including lower compliance costs, simplified certification and border procedures, and improved market access. However, businesses also highlighted significant uncertainty regarding the SPS Agreement's final scope, implementation timetable and compliance requirements. Many expect operational changes, particularly in relation to labelling, compliance processes, supply chain structure and contract terms and IT systems, and stressed the need for clear guidance and adequate transition periods. DEFRA states that the findings will be used to inform implementation planning, business readiness support and future communications as negotiations continue.
In late July 2026 the UK Government also updated guidance on preparing for the SPS Agreement, to clarify that while negotiations are ongoing changes to pesticide use do not need to be made.
Farmers and others in the agri-food supply chain should monitor progress on SPS Agreement negotiations, as well as further Government guidance. The Government has previously said that there will be no transition period for implementation of the SPS Agreement requirements, which are expected to be finalised and come into force in 2027.
Guidance on EU Cyber Resilience Act published
On 27 July 2026 the European Commission published non-binding guidance to support businesses and regulators in implementing the EU Cyber Resilience Act (CRA).
The CRA establishes a mandatory cybersecurity framework for products with digital elements, including smart devices, routers, software and connected industrial systems. From 11 September 2026, manufacturers must report serious cyber incidents and actively exploited security flaws to EU authorities. The remaining rules come into force on 11 December 2027, when products must be built to be secure, carry CE marking and come with security updates.
The guidance clarifies key concepts including what constitutes a product with digital elements; treatment of software, remote data processing, and free and open-source software; what substantial modifications are; support periods; conformity assessment requirements and vulnerability reporting obligations. It provides detailed guidance on when software updates trigger a new conformity assessment, how manufacturers should assess cybersecurity risks and manage third-party components and cloud services, and the circumstances in which open-source software will fall within the CRA. The guidance emphasises a risk-based approach to compliance and is intended to promote consistent application of the CRA across the EU.
The guidance will help inform CRA compliance programmes for manufacturers, developers and other stakeholders.