Comparison
CRA vs GDPR: which one applies to your product?
Reviewed August 2026 against Regulation (EU) 2024/2847, OJ L, 12.12.2024.
Short answer: they regulate different things, and both can apply to the same company at the same time. The Cyber Resilience Act (CRA) governs the cybersecurity of the product itself; the GDPR governs how you process personal data. Being in scope of one tells you nothing about the other.
What each one regulates
The CRA applies to a product with digital elements: a software or hardware product and its remote data processing solutions, made available on the market where its intended or reasonably foreseeable use includes a data connection to a device or network. Its duties, such as vulnerability handling, secure defaults, a software bill of materials and a declared support period, attach to the product and to the manufacturer, importer or distributor who supplies it, not to whatever personal data the product happens to process.
“a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately”
“This Regulation applies to products with digital elements made available on the market, the intended purpose or reasonably foreseeable use of which includes a direct or indirect logical or physical data connection to a device or network.”
The General Data Protection Regulation, Regulation (EU) 2016/679, regulates something different: how any organisation collects, stores, shares and otherwise processes the personal data of people in the EU, whether that processing happens through a product with digital elements, a spreadsheet, or a phone call. It sets principles such as having a lawful basis for processing, collecting no more data than needed, and keeping data secure, and it gives national data protection authorities the power to investigate and to fine. Full text: Regulation (EU) 2016/679, OJ L 119, 4.5.2016 (GDPR).
Do they overlap, and which wins
The CRA names a short, closed list of other Union acts whose product rules take precedence over it for specific product categories: medical devices, in-vitro diagnostics, aviation-certified equipment, agricultural and two- or three-wheel vehicle approvals, marine equipment and road vehicle type-approval.
“This Regulation does not apply to products with digital elements to which the following Union legal acts apply:”
The GDPR is not on that list, and nothing in the Regulation subordinates data-protection law to the CRA, or the reverse. Practically: if your product is in scope of the CRA and it also processes personal data, both regimes apply in full, at the same time, to the same product. Cybiq’s own compliance engine does not ask about the GDPR when scoping a product, because the GDPR is not a scope carve-out: it neither excludes a product from the CRA nor is excluded by it.
The CRA’s own security duty sits alongside, not instead of, the GDPR’s: manufacturers must ensure vulnerabilities are handled effectively and in accordance with the essential cybersecurity requirements, which is a product-safety test, not a data-protection one.
“vulnerabilities of a product with digital elements are handled effectively and in accordance with the essential cybersecurity requirements”
The two regimes even set different penalty ceilings: the CRA caps fines for breaches of the essential cybersecurity requirements at up to EUR 15,000,000 or 2.5% of worldwide annual turnover.
“administrative fines of up to EUR 15 000 000 or, if the offender is an undertaking, up to 2,5 % of the its total worldwide annual turnover”
What this means in practice
- If your product collects any personal data (accounts, telemetry, health readings from a wearable), you need a GDPR lawful basis and privacy notice for that processing, on top of and separate from your CRA duties.
- The CRA’s vulnerability-handling duty and the GDPR’s security-of-processing duty ask a related question, is this secure, through two different legal tests enforced by two different regulators; satisfying one is not evidence you satisfy the other.
- A personal-data breach can trigger GDPR notification duties to a data protection authority, and sometimes to the people affected, on a timeline independent of anything the CRA’s Article 14 reporting requires.
- GDPR penalties can reach up to 4% of global annual turnover or EUR 20 million, whichever is higher, a widely reported GDPR ceiling; the CRA’s own ceilings above are unrelated and enforced separately.
- Two different regulators police these: your market surveillance authority for the CRA, your national data protection authority for the GDPR. Clearance from one says nothing about the other.
Cybiq checks the CRA only: it does not assess your product’s compliance with the GDPR or any other regime. Orientation, not legal advice. Quoted spans come from Regulation (EU) 2024/2847 as published in the Official Journal and are re-verified against the live text by automated tests. Verify before relying on any item; for a binding assessment consult a qualified lawyer.