EU Corporate Sustainability Due Diligence Directive
Content
Corporate Sustainability Due Diligence Directive (CSDDD) at a glance
Following its reopening and amendment in the ‘Omnibus I’ process, the CSDDD is currently being transposed into national law, meaning that there will be a law based on the CSDDD in all EU Member States. The deadline for transposition is July 2028. National CSDDD laws will then be applicable from July 2029.
The EU’s Corporate Sustainability Due Diligence Directive (CSDDD) requires large companies that fall within its scope to identify, prevent, bring to an end and remedy negative human rights and environmental impacts related to their own operations, those of their subsidiaries, and those of their business partners in global supply chains ("chain of activities").
This is supported by stakeholder engagement obligations, complaints and notification procedures, official implementation guidance (currently under development), as well as enforcement through national supervisory authorities and potentially courts in the EU.
What companies fall under the CSDDD?
A company falls within the scope of the CSDDD if it meets one of the following (combinations of) thresholds:
- companies established in the EU with more than 5,000 employees and a net worldwide turnover of more than €1.5 billion.
- non-EU companies that generate more than €1.5 billion in turnover within the EU market, even if they are not headquartered or registered in the EU.
Are franchising and licensing companies covered by the CSDDD?
Yes, the CSDDD also applies to companies – both EU and non-EU – that:
- operate through franchising or licensing agreements in the EU (for example, large retail, hotel, or fast-food chains using franchise models);
- earn more than €75 million in royalties in the EU; and
- have a net worldwide turnover of more than €275 million.
This last category is intended to capture companies that may not directly sell products or services themselves but still exercise significant economic influence and control through franchise or licensing business models.
If you know the company that is likely to be connected to the harm you (or the people you support) have experienced, you can check if the company is covered by the CSDDD in SOMO’s CSDDD Datahub. The Datahub lists both EU and non-EU companies within the Directive's scope.
If you are concerned a company possibly covered by the CSDDD may be involved in (local) risks and harms but you need to find out more about potential connections, you can refer to basic guidance here.
If the company is not covered, there might still other (EU) laws or tools under which to engage with the company, raise your concern, or seek remedy. You can also explore alternative remedy pathways here or answer a few questions to receive suggestions what pathways may be most appropriate for your specific situation here.
What are companies expected to do?
Companies that fall within the CSDDD’s scope are required to conduct human rights and environmental due diligence. They must take appropriate measures to
- identify, assess and (if needed) prioritise negative impacts they are connected to through their operations, subsidiaries and direct or indirect business partners in their global "chain of activities";
"Chain of activities" basically means the company's full supply chain (from design to raw materials sourcing, processing, manufacturing etc.) plus distribution, transport, and storage of the company’s products through (direct) business partners.
- prevent, mitigate (reduce), and end impacts that have been, or should have been, identified;
- provide or collaborate in remediation of impacts they have caused or contributed to (“jointly caused”)
- meaningfully and safely engage with affected stakeholders and set up complaint procedures.
Protected human rights and environmental standards
There are specific human and environmental rights and prohibitions that companies must consider in their due diligence. In other words, the purpose of due diligence under the CSDDD is to avoid and tackle infringemements of these rights and prohibitions. They are spelled out and listed in the CSDDD's Annex at the bottom of the legal text.
For human rights, this includes, among others:
- the right to life;
- the prohibition on torture;
- the right to liberty and security;
- rights to privacy and freedom of thought;
- various core labour protections such as the right to just and favourable conditions of work, including adequate living wage and living income, the prohibition of child labour and forced labour, the right to freedom of association and collective bargaining, and the prohibition of unequal treatment in employment; as well as
- land rights, many of which relate to Indigenous Peoples’ rights.
Companies are required to consider (additional) rights enshrined in a number of human rights instruments listed in the Annex, including:
- the International Covenant on Civil and Political Rights (which relates to the rights of Human Rights Defenders, for instance)
- the International Covenant on Economic, Social and Cultural Rights;
- the Convention on the Rights of the Child; and
- the ILO Core Conventions.
Companies also need to respect adverse impacts on the environment resulting from breaches of prohibitions and obligations under environmental conventions listed in the Annex, such as:
- the Stockholm Convention on Persistent Organic Pollutants; and the
- Basel Convention on the Control of Transboundary Movements of Hazardous Wastes and their Disposal.
The CSDDD covers (further) environmental degradation if it affects human rights and livelihoods, such as harmful soil changes, water or air pollution, harmful emissions, and excessive water consumption.
When are due diligence measures "appropriate" under the CSDDD?
"Appropriate measures" under the CSDDD are measures that are "capable of achieving the objectives of due diligence by effectively addressing adverse impacts” in a context-specific, proportionate and reasonable way (Article 3 (1) (o) CSDDD).
When it comes to preventing, mitigating, ending or remediating negative impacts under the CSDDD, what constitutes appropriate action also depends on whether the company causes them directly, jointly with other entities (including in its supply chain), or whether the impact is fully caused by business partners and the company is only linked to it.
This in line with the Involvement Framework established by the international UN and OECD standards.
Companies covered by the CSDDD do not have to guarantee successful prevention and termination of (all) human rights or environmental risks and harms in their supply chains. They are only obliged to take “appropriate measures” to this effect. This is called an obligation of means or effort (versus an obligation of result).
However, due diligence under the CSDDD cannot be a superficial or one-size-fits-all process that merely exists on paper – positive outcomes for people and the environment do matter.
CSDDD: due diligence in detail (incl. remedy, stakeholder engagement)
1. Identifying and assessing risks and harms
Companies must look for risks to people and the environment related to their business activities. This includes harms arising from their own operations, those of their subsidiaries, and those of the company’s direct and indirect suppliers, contractors, and other business partners in the supply chain (“chain of activities”).
This means companies cannot ignore harms simply because they happen further down the supply chain or are caused by business partners. Companies are expected to proactively identify assess these risks instead of waiting until harm has already occurred.
2. Prioritising
If companies cannot address every problem immediately, they must prioritise those risks that are most severe and most likely to happen across their full chain of activities. This so-called ‘risk-based approach’ is largely in line with the international UN and OECD due diligence standards.
In deciding which risks to address first, companies must consider whether these could otherwise become irremediable (unrepairable), how serious the impact is on affected people and communities, and how many people are affected. Companies must also consult affected stakeholders when making these decisions.
Prioritisation means sequencing when to tackle an issue, not postponing action on certain issues endlessly or ignoring them.
3. Taking action to prevent and end harm
Companies must take meaningful steps to reduce risks and address problems. Measures must be appropriate to the situation. For example, companies should:
- change their own business practices, including adjustments to
- purchasing practices (e.g. where price pressure and unrealistic production targets contribute to harms at supplier level);
- distribution and design practices (e.g. harmful product design that negatively affects users);
- engage and work with suppliers to jointly fix problems;
- agree on burden-sharing between buyer and supplier through fair contractual terms;
- develop prevention or corrective action plans;
- use their influence to improve conditions; or
- as a last resort, responsibly (and if needed indefinitely) suspend working with business partners where there is no prospect nor leverage for improvements – in a way that does not simply leave workers or surrounding communities stranded but addresses the potential negative human rights impacts of leaving.
The goal is not only to identify risks, but to prevent harm from happening, or stop and remediate ongoing harm, through effective, collaborative action that avoids cost-shifting to suppliers.
While (third-party) audits are mentioned among the catalogue of possible measures, they are by no means the prime due diligence instrument under the CSDDD.
4. Engaging with affected people and communities
Companies covered by the CSDDD must engage with workers, trade unions, affected communities, and other "affected stakeholders" (such as Indigenous Peoples) and their "legitimate representatives" (such as community and local civil society organisations or their networks) when identifying risks and deciding what actions to take.
Human Rights Defenders (HRDs) may fit under both categories as they are often affected in their own rights while also representing and supporting other rightsholders.
The perspectives of people directly affected by business activities are key to ensuring due diligence measures are fit for purpose. They convey information about harms and risks that companies may otherwise miss.
These consultations must be meaningful, ongoing, safe, and accessible. Companies should ensure that people can participate without fear of intimidation, discrimination, or retaliation, and they should remove barriers that prevent participation. Where it is impossible or unsafe to engage with affected people and their immediate representatives directly, companies can in addition consult "experts" like international NGOs.
5. Providing safe ways to raise complaints
Companies must set up complaints or grievance mechanisms so that affected parties like workers, communities, trade unions, civil society organisations and Human Rights Defenders can report risks or harms. There must also be a notification channel to enable any other concerned individuals or organisations, even if they are not directly affected, to submit information on risks and harms related to the company’s operations and supply chains. These mechanisms must be accessible, safe, and trustworthy.
People who raise concerns must be protected from retaliation, threats, or punishment. Companies must respond to complaints and follow up appropriately, including by taking remediation action.
6. Providing remedy when harm occurs
The CSDDD clearly says that if a company has caused or contributed to harm, it must (help) repair that harm. Where the harm is caused solely by a business partner, the company that directly falls under the CSDDD may still engage in voluntary remediation, or at least use its leverage to influence the business partner to provide remedy.
Remedy should aim to address the impact suffered by affected people or communities and prevent the harm from happening again. It may include:
- compensation;
- rehabilitation;
- restoring land or the environment;
- apologies;
- guarantees that the harm will not happen again; or
- other appropriate corrective measures.
7. Monitoring and evaluating whether measures are working
Companies must regularly (every five years) check whether their overall due diligence system effective and improve it where necessary. This includes long-term monitoring of whether harms are actually being prevented or addressed and whether company actions are making a real difference in practice. It is a monitoring and evaluation exercise that is fundamentally different from ongoing due diligence and engagement, which however also have to undergo constant recalibration.
8. Public due diligence reporting
Among other disclosure, companies must publicly explain:
- what risks they identified;
- what actions they took; and
- whether those actions were effective.
For most companies covered by the CSDDD, this will be part of their reporting under the Corporate Sustainability Reporting Directive (CSRD). It helps increase transparency and allows workers, communities, civil society organisations, investors, and the public to better understand how companies are addressing human rights and environmental risks.
What can I do if a company does not meet the obligations?
If a company covered by the CSDDD does not meet its obligations, there are several possible avenues to hold it accountable.
The CSDDD will only apply from July 2029 and you can only report violations that are ongoing or imminent at that time, or happen thereafter. This is particularly relevant if you are considering formally complaining with a national supervisory authority, or even legal action.
Jump to...
1. Engaging with the company
The CSDDD, even after Omnibus I revisions, places considerable emphasis on mandatory, meaningful engagement with affected stakeholders like workers and communities, as well as their representatives. Even if it is on the company to initiate such dialogue, contacting other NGOs, grassroots organisations or unions who are already in touch with the company, or using its complaint mechanism, can be a way to actively demand engagement by the company and bring up human rights and environmental issues to work towards a solution.
Civil society organisations and their networks may be able to support you when you are preparing for or already engaging in dialogue with companies.
Companies have to ensure that people can participate without fear of intimidation, discrimination, or retaliation, and they should remove barriers that prevent participation. However, it is important that you think about your safety and the safety of others first when engaging.
2. Using the company’s complaints channel(s)
If you think a company has not fulfilled its obligations, and especially you or the people you support have been harmed as a result, you might consider filing a notification or complaint directly with the company.
Companies covered under the CSDDD must establish and maintain a complaints procedure and notifications mechanism that allows people to raise concerns about human rights or environmental harms, whether they are themselves affected or not. These mechanisms should be fair, publicly available, accessible, predictable and transparent. Complaints can relate to actual harms or risks of harm connected to the company’s activities, subsidiaries, suppliers, or (other) business partners.
Click here learn more about company-based complaints mechanisms in general.
Even though the CSDDD is not yet applicable, companies might already have a grievance mechanism in place because of their obligations under national (due diligence) laws and the international UN and OECD standards.
Companies must take measures to prevent any form of retaliation against the person filing the complaint, including by ensuring the confidentiality of the identity of the person or organisation filing the complaint in accordance with national law. Before filing a complaint, it is nevertheless important to consider any possible safety concerns for yourself and others. Again, it might be helpful to reach out to someone for advice if you are unsure.
FAQ on complaints with companies under the CSDDD
How to find the company’s notifications and grievance mechanism(s)?
First, you should find the company’s grievance mechanism to see how it works and how you can file a notification (if you are not directly affected by the issue but still have relevant information/concerns) or complaint (if you or people you support are directly affected).
You can usually find such grievance channel(s) on the company’s website, by searching for it online, or in production sites if announced on posters, for instance.
It might also be that the company does not have its own complaint mechanism but operates it in collaboration with other companies and participates in other joint mechanisms through industry associations, multi-stakeholder initiatives or global framework agreements.
After finding the mechanism, you should look at what information the company wants you to provide to handle your complaint. Be aware that you don’t necessarily need to adhere to (all) these suggestions; you might want to reach out to someone for advice in case you are unsure.
Who can file a complaint?
The CSDDD mentions a range of people and organisations that can submit a complaint or grievance:
- a person or legal person (organisation) that is affected or has reasonable grounds to believe that they might be affected by a negative impact; as well as their legal representatives, such as civil society organisations and Human Rights Defenders
- trade unions and other workers’ representatives representing people working in the company’s supply chain (chain of activities)
- in case of an environmental impact, civil society organisations that are active and experienced in the area
Any other parties can still submit information and concerns, either confidentially or even anonymously. However, these may be treated as notifications, which means companies may have more discretion whether to engage with the person submitting the information.
What are complainants’ procedural rights?
Complainants are legally entitled under the CSDDD to:
- request appropriate follow-up from a company;
- meet with the company’s representatives to discuss actual or potential negative impacts; and
- receive information on whether their complaint has been considered founded or unfounded, and what steps and actions have been or will be taken in response, including possible remedial action.
As there is no legally prescribed outcome of such a complaint, it can still vary depending on the company and situation.
3. Submitting a notification or complaint to a national supervisory authority
Every EU Member State must appoint a supervisory authority responsible for overseeing compliance with the CSDDD. These have not yet been appointed. Any person or legal person will be able to submit “substantiated concerns” to the respective supervisory authority online when they have reasons to believe that a company falls under the national CSDDD law of that country and is not complying with it.
You do not need to live in the EU to raise concerns with a national supervisory authority.
After receiving a concern, the authority may:
- investigate the company;
- request further information either by the company or the person filing the complaint,
- order corrective and remediation measures; or
- impose penalties or fines, which, for the most serious violations, are set at a maximum limit of 3% of the company’s net worldwide turnover.
If the authority finds that the company did not comply with the provisions of national law adopted pursuant to the CSDDD, it can give the company an “appropriate period of time” to take action. This does not exclude the possibility of penalties or an additional civil liability claim in court.
4. Legal action/civil liability before a relevant EU Member State court
Depending on the relevant national CSDDD law, it might be possible for victims of corporate abuse to hold a company liable under the CSDDD in an EU Member State civil court and seek compensation for damages if:
- the company falls under the CSDDD;
- the company failed to comply with an applicable due diligence obligation;
- the failure caused or contributed to harm to a person or persons;
- there is a sufficient connection between the company’s failure and the harm to establish liability under the relevant national law; and
- the claimant can provide sufficient evidence to support the claim.
Since 'Omnibus I' amendments removed the CSDDD's initial, harmonised, EU-wide civil liability regime, we can expect considerable variation in how Member States transpose the amended wording (see below in our FAQ section) into their national tort law. For victims of corporate abuse and their representatives, it may be helpful to seek legal advice. Our legal assistance directory can help you find (initial) contacts that may be relevant in your situation.
While all engagement, complaint and remedy pathways under the CSDDD can be used simultaneously and independently from each other, legal action is typically seen as a last resort if previous engagement and complaints fail, also given the costs, complexity, and time burden likely to be associated with it. Find out more about business and human rights lawsuits in general here.
FAQ on civil liability under the CSDDD
What does the CSDDD's legal text say about civil liability?
According to the latest version of Article 29(2) CSDDD, “where a company is held liable pursuant to national law for damage caused to a natural or legal person by a failure to comply with the due diligence requirements under this Directive, Member States shall ensure that those persons affected have a rights to full compensation.”
While 'Omnibus I' amendments, compared to the initial Directive, place greater emphasis on Member States' discretion and there is some debate, a growing number of legal experts and scholars have clarified that the new wording still implies that:
- Member States have to ensure civil liability for damages resulting from CSDDD compliance failures in their national tort law to put Art. 29 CSDDD into practice; and
- EU Member States' courts should be able to apply CSDDD-specific national tort law even where damages are sought against a CSDDD-regulated company for harms that occured in a non-EU (e.g. a production) country. The best way to ensure this is for CSDDD-specific national tort norms to be designed as so-called overriding mandatory provisions.
This corresponds to how the European Commission itself explains the revised Directive (slide 12).
Who can bring a claim?
A claim may be brought by a natural or legal person who has suffered damage as a result of a company's failure to comply with its applicable due diligence obligations. Depending on national law, this may include affected rightsholders, workers, communities, individuals, or organisations that have suffered legally recognised harm.
Generally, they must be able to show that the company's failure caused, or contributed to, the harm and fulfil the applicable requirements for civil liability under national law.
What can be claimed?
Victims and their representatives in court may:
- claim full compensation for the damage suffered;
- seek an injunction requiring the company to stop or prevent an infringement, including through urgent or provisional proceedings;
- request disclosure of evidence held by the company where the claimant has provided sufficient facts and evidence to make the claim plausible and can show that additional relevant evidence is controlled by the company.
Companies cannot automatically avoid liability by arguing that they used an independent third-party verifier, participated in an industry or multi-stakeholder initiative, or included due diligence clauses in contracts.
Companies cannot be held liable if damage was caused only by business partners in its chain of activities, but where the damage was caused jointly by the company and another entity in its chain of activities, such as a subsidiary or supplier, joint and several liability may apply, depending on national law.
What outcomes are possible?
Where liability is established, the main outcome is full compensation for the harm suffered. Full compensation aims to cover the actual loss or damage.
A court may also order the company to stop or prevent the harmful conduct, including through provisional or urgent measures.
Where the damage was caused jointly by the company and another entity in its chain of activities, such as a subsidiary or business partner, joint and several liability may apply, depending on national law.
The CSDDD does not prevent claimants from relying on other EU or national civil liability rules that provide stronger or additional protection.
Are there any time limits?
The CSDDD requires Member States to ensure that limitation rules do not make it excessively difficult to bring a lawsuit. The limitation period for CSDDD-related damages claims must be at least five years. It cannot be shorter than the limitation period applicable under the Member State's general civil liability rules. The limitation period should not begin before the infringement has ceased and only when the claimant knows, or can reasonably be expected to know, about the infringement and the identity of the infringer.
Since these are minimum standards, the exact limitation periods and procedural rules will need to be checked under the national law of the relevant Member State, or even the law of a non-EU country (e.g. a production country) where the harm may have occurred. This would be the case if an EU Member State failed to ensure that its courts can apply national, CSDDD-specific rules when companies are sued for harm they have caused or contributed to abroad – for example, within their supply chains. Such an omission would risk making the CSDDD’s core procedural rights (including the five-year limitation period and the right to full compensation) practically meaningless.
