Compare / GDPR vs CRA
Regulation comparison
GDPR vs CRA
GDPR governs the data a device collects; the CRA governs how securely the device is built. A privacy-perfect product can fail the CRA, and a CRA-conformant product can breach GDPR the moment it collects more data than it needs. Health and biometric data trigger GDPR's strictest tier.
| GDPR | EU Cyber Resilience Act | |
|---|---|---|
| Applies when | Any product handling personal data of people in the EU, wherever the maker sits | Any product with digital elements placed on the EU market, consumer or industrial |
| Who demands it | Legal compliance; data-protection authorities | Market access, mandatory (CE marking) |
| What it is | Regulation | Regulation |
| Scope | Data minimisation, lawful basis and consent, right to erasure, data protection by design, stricter rules for health and biometric data (Article 9) | Security by design, SBOMs, 24-hour reporting of actively exploited vulnerabilities to the CSIRT and ENISA, coordinated disclosure, post-market monitoring for the support period |
| In force | Applies since 25 May 2018 | In force 10 Dec 2024; reporting duties from 11 Sep 2026; main obligations from 11 Dec 2027 |
| Penalties | Up to EUR 20M or 4% of global turnover | Up to EUR 15M or 2.5% of global turnover |
| Authoritative text | GDPR text โ | CRA text โ ยท on this site |
What a product team should do
Map data flows once and use the map twice: data minimisation and lawful basis for GDPR, attack surface and secure storage for the CRA.
Check your own product
The IoT security scorecard grades a product against these frameworks in 19 questions, and the requirements generator turns the applicable ones into PRD-ready requirements. Both cite the same provisions this page does. The full map is on the regulatory landscape reference.
Sources: GDPR (official text) and EU Cyber Resilience Act (official text). Educational reference, not legal advice. See Chapter 18 and Chapter 19 of Tangibles.
โ All comparisons