Comparison

CRA vs GDPR: which one applies to your product?

Reviewed August 2026 against Regulation (EU) 2024/2847, OJ L, 12.12.2024.

Short answer: they regulate different things, and both can apply to the same company at the same time. The Cyber Resilience Act (CRA) governs the cybersecurity of the product itself; the GDPR governs how you process personal data. Being in scope of one tells you nothing about the other.

What each one regulates

The CRA applies to a product with digital elements: a software or hardware product and its remote data processing solutions, made available on the market where its intended or reasonably foreseeable use includes a data connection to a device or network. Its duties, such as vulnerability handling, secure defaults, a software bill of materials and a declared support period, attach to the product and to the manufacturer, importer or distributor who supplies it, not to whatever personal data the product happens to process.

“a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately”

“This Regulation applies to products with digital elements made available on the market, the intended purpose or reasonably foreseeable use of which includes a direct or indirect logical or physical data connection to a device or network.”

The General Data Protection Regulation, Regulation (EU) 2016/679, regulates something different: how any organisation collects, stores, shares and otherwise processes the personal data of people in the EU, whether that processing happens through a product with digital elements, a spreadsheet, or a phone call. It sets principles such as having a lawful basis for processing, collecting no more data than needed, and keeping data secure, and it gives national data protection authorities the power to investigate and to fine. Full text: Regulation (EU) 2016/679, OJ L 119, 4.5.2016 (GDPR).

Do they overlap, and which wins

The CRA names a short, closed list of other Union acts whose product rules take precedence over it for specific product categories: medical devices, in-vitro diagnostics, aviation-certified equipment, agricultural and two- or three-wheel vehicle approvals, marine equipment and road vehicle type-approval.

“This Regulation does not apply to products with digital elements to which the following Union legal acts apply:”

The GDPR is not on that list, and nothing in the Regulation subordinates data-protection law to the CRA, or the reverse. Practically: if your product is in scope of the CRA and it also processes personal data, both regimes apply in full, at the same time, to the same product. Cybiq’s own compliance engine does not ask about the GDPR when scoping a product, because the GDPR is not a scope carve-out: it neither excludes a product from the CRA nor is excluded by it.

The CRA’s own security duty sits alongside, not instead of, the GDPR’s: manufacturers must ensure vulnerabilities are handled effectively and in accordance with the essential cybersecurity requirements, which is a product-safety test, not a data-protection one.

“vulnerabilities of a product with digital elements are handled effectively and in accordance with the essential cybersecurity requirements”

The two regimes even set different penalty ceilings: the CRA caps fines for breaches of the essential cybersecurity requirements at up to EUR 15,000,000 or 2.5% of worldwide annual turnover.

“administrative fines of up to EUR 15 000 000 or, if the offender is an undertaking, up to 2,5 % of the its total worldwide annual turnover”

What this means in practice

Check your product. Run the free Cybiq check: six questions, a definitive verdict, and every claim anchored word-for-word in the Official Journal. For the terms used here, see the glossary; for more scope questions, see the FAQ; for the dates that matter, see the CRA timeline.

Cybiq checks the CRA only: it does not assess your product’s compliance with the GDPR or any other regime. Orientation, not legal advice. Quoted spans come from Regulation (EU) 2024/2847 as published in the Official Journal and are re-verified against the live text by automated tests. Verify before relying on any item; for a binding assessment consult a qualified lawyer.