The products covered by the obligation to repair currently include:
- washing machines and washer-dryers
- dishwashers
- refrigerators
- electronic displays
- welding equipment
- servers and data storage products
- mobile phones, cordless phones and tablets
- tumble dryers
- e-bikes and e-scooters batteries (from 18 February 2027)
- local space heaters



Also software… I would love to have regulations that make it clear that the root of trust on all devices need to start by the owner of the device, not by the vendor… That would allow the end users to repair the software on their devices… Replacing it with whatever else they want. Next would be to provide hardware documentation to the owners to program their own devices… I don’t expect that to happen, but I can dream.
The root of trust can never be on the owner of the device for anything that requires actual security.
I disagree. For any actual security, the owner of the secrets is the only one that can be trusted. It is their secrets. Their own interest to keep them save.
Any company or government is a shifting entity, maybe now they are trustworthy, but maybe in some years they aren’t.
Owners are the only stabile point, because it is their data. They should be able to transfer the trust to a company or government to handle security, but they also need to be able to take away that trust and access, and either handle it themselves or transfer that trust to some other entity.
It is not okay for companies or government to hold the data of individuals hostage… That is not security, that is a business strategy.
If the only person that can verify the safety of your device is the owner, that device will and should be marked as insecure and not to be trusted in any instance where security matters.
Are you talking about owner safety, or some bussiness security. Yes the device is ‘insecure’ if you are taking the point of view of DRM provider or software vendor who wants to make sure advertisements are displayed, etc. Or if your software actual security depends of taking control away from the user. But actual end user security does not have to depend on that.
You are not giving a reason for your statement. The owner is the one that bought a device. The sole arbiter about what a device should do or shouldn’t do. The person responsible of the device. The owner must trust their device in order for the device to be trusted. It doesn’t matter what if other people do or do not trust that device, they are not the owners. They should take care to protect their own data on their own devices.