"(14) Free and open-source software, whereby the source code is openly shared and users can freely access, use, modify and redistribute the software or modified versions thereof, can contribute to research and innovation on the market. Such software is subject to licences that allow anyone the freedom to run, copy, distribute, study, change and improve the software. In order not to hamper innovation or research, this Directive should not apply to free and open-source software developed or supplied outside the course of a commercial activity, since products so developed or supplied are by definition not placed on the market. Developing or contributing to such software should not be understood as making it available on the market. Providing such software on open repositories should not be considered as making it available on the market, unless that occurs in the course of a commercial activity. In principle, the supply of free and open-source software by non-profit organisations should not be considered as taking place in a business-related context, unless such supply occurs in the course of a commercial activity. However, where software is supplied in exchange for a price, or for personal data used other than exclusively for improving the security, compatibility or interoperability of the software, and is therefore supplied in the course of a commercial activity, this Directive should apply"
see also the following recitals.
I think this sounds pretty sensible. If you want to build a business you are responsible for defects in your wares. If you are gifting software you not "selling".
Maybe it means the original project will get forked (or perhaps helped) if it doesn't take care of everything itself.
It would raise the cost of open source software a lot if you do this, and the cost of all other software. This seems very unlikely to actually happen. By which I mean, government and commercial users seem to me very, very unlikely to be willing to pay for this when they could just as well just use software from outside the EU, and this will just really suck for EU software developers and companies.
And that isn't really that outlandish as you make it (maybe inadvertently) sound.
If a wheel falls off of your car because the foundry that made the steels of the screws got their recipe wrong, initally the whole liabilty is on the car manufaturer and they got to fixt that.
For you as a customer it stops there.
The manufacturer may (if their contract permits) try to get some money back from screw factory and they in turn from the steel mill etc. If someone goes bankrupt along the supply chain, tough luck for the one up chain.
So car manufacturers (and their suppliers) are really motivated to QA their parts because recalls are expensive and they may not even get back everything or anything.
You can't blame the universe for putting the wrong ore composition into the ground. You can only blame the people who failed to do proper checks on the way.
Software may follow a similar trajectory with Open source being the ore in the ground. You must take reasonable (see directive) steps to prevent that (e.g. good development practices, updates, react to CVEs etc).
It's really nothing fundamentally new.
Almost all mining companies in the EU are government-sponsored or owned (or, more often, owned by politicians or royal families, e.g. Total and (ex-)Frech presidents and ministers or Shell and the Dutch Royal Family, which then "somehow" results in government support for them, often with suspiciously little people supporting the mining effort. You know, suspiciously little support, given that they're democracies).
Needless to say, I've not heard of these sorts of companies being convicted to fix damages they've caused. If anything is done, it's always the government offering to do it from taxes (e.g. a harbor upgrade in Le Havre demanding the contracting company fixes Total refinery pollution). Have you?
Cars are different because while the German and French states have HUGE interests in car manufacturing, none of the others have. So any car defect, depending on if it's Renault or Mercedes/VW turns into the EU siding with the German or French camp in the EU and either demanding the companies fix it, or demanding nothing happens. Italy tried participating in this game, but, well, we all know what happened. So car QA is indeed done, to avoid the year-long EU-wide diplomatic incidents a recall causes.
Or take the example of public works contractors. These tend to be temporary alliances (e.g. need a big bridge? A company is created by 5 contracting companies just for the explicit purpose of building THAT one bridge, THAT specific tunnel, THAT train station, ordering for pre-agreed amounts of dollars from the specific contractors). Sometimes this company keeps existing to provide maintenance afterwards. If shit hits the fan, which is often, the company immediately goes bankrupt and nobody from whatever government approved the bid is held responsible, nor are the 5 contractors, but whatever repair money comes from the government budget anyway.
So, how will it work for software? Because your explanation sounds vaguely reasonable in theory, if you compare it to actual practice it becomes very unclear.
Is this created to make it impossible to have any kind of software company in the EU without government support, like for contractors? Is this made to be a threat or a weapon against American or Chinese companies?
IOW if I got paid for some work on an existing project under a liberal license, what would I be getting myself into? (I assume the answer is 'nothing' if it happened before this directive, but if it happened after?)
However I'd be cautious when it comes to these finer details. It's where business liability insurances and lawyers a wise investment.
This sounds like there might be extra requirements for an unending? unspecified? period, I don't see how anyone can make a living if so.
As a layman it may be similar to the questions of how long a manufacturer can be held responsible for material fatique under regular use?
However, I highly doubt that EU citizens and companies will now suddenly be willing to pay for liability insurance for people they buy software from (and that will be more expensive the smaller the developer and/or company is)
So this seems like a really great way to stop any software from being released into Europe.
I'm a Debian Developer. To me, that carve out is a major comfort. I doubt I'm alone. I expect it is viewed as very useful by everyone who develops open source.
Business who sell open source - well yeah, it probably is useless to them. That's kinda the point.
Two examples come to mind: donations to OSS maintainers, and OSS maintainers who provide consulting services instead of selling software. The former is arguably covered by donations not being "sales," but some projects/groups do provide invoices (with no particular obligations) to make donations fit into the sale-shaped financial slot that most companies understand.
I happen to agree, but the law itself doesn't make that clear. That's what matters.
> However, where software is supplied in exchange for a price, or for personal data used other than exclusively for improving the security, compatibility or interoperability of the software
I'm really glad that the legislation treats the exploitation of private information as a price.