Bottomley: Solving the Looming Developer Liability Problem
Bottomley: Solving the Looming Developer Liability Problem
Posted Dec 14, 2023 14:53 UTC (Thu) by pizza (subscriber, #46)In reply to: Bottomley: Solving the Looming Developer Liability Problem by Wol
Parent article: Bottomley: Solving the Looming Developer Liability Problem
I am not physically located in the EU, but I have some EU clients to whom I provide support and consulting services [1] related to the F/OSS that I freely provide online. The plain text of the CRA [2] explicitly lists this as an example of a commercial activity, and as such, strips me of the blanket exemptions the CRA provides for F/OSS authors.
> At an absolute maximum, you may be asked to certify for the purposes of the CRA that your products are kept up to date and all known security bugs are fixed.
It's more than that -- Individually, each of these requirements probably isn't that big of a deal, but they add up to a substantial increase in overhead [3]. Worse yet, tasks that used to be directly billable were themselves turned into overhead that I will now be expected to provide as a matter of course. Then there's the matter of potential liability; I'm going to need a more substantial insurance policy that reflects the greater risks which further increases my overhead.
(Or I can just stop doing business with EU entities altogether, not because I'm a shady operator, but because the cost/benefit curve is shifting firmly into "just not worth the effort for a part time side gig" territory. Which will result in less F/OSS for everyone, not just the EU)
[1] Which I provide with a profit (as opposed to cost recovery) motive.
[2] Paragraph 10 of the latest marked-up version, which I quoted verbatim earlier in this thread in a reply to you. [4]
[3] I don't have a citation for this, but I read that official estimates were that compliance with the CRA would lead to an approximately 25% increase in overhead.
[4] https://lwn.net/Articles/954874/
