The EU’s Shift from Voluntary Ethics to Mandatory Due Diligence
The European Union took a decisive step towards corporate accountability with the adoption of Directive (EU) 2024/1760, commonly known as the Corporate Sustainability Due Diligence Directive (CSDDD). Formally adopted by the European Parliament and Council in April 2024, the Directive establishes a mandatory framework requiring companies to identify, prevent, mitigate and, where necessary, remedy adverse human rights and environmental impacts arising from their own operations, those of their subsidiaries and their chain of activities. Currently being transposed across Member States, the Directive imposes strict obligations on large EU entities with over 1,000 employees and €450 million in net worldwide turnover, as well as foreign firms generating over €450 million in turnover within the EU.
Beyond direct legal compliance, the Directive is expected to reshape contractual relationships throughout global supply chains. Large companies are likely to require suppliers, contractors and other business partners to adhere to equivalent human rights and environmental standards through contractual commitments, monitoring and audits. As a result, businesses falling outside the Directive’s direct scope may nevertheless be indirectly affected by its implementation. With a statutory transposition deadline of 26 July 2026, Member States were required to establish national legislative frameworks integrating these binding due diligence standards into domestic corporate law.
Structural Integration: Embedding Due Diligence in Corporate Operations
Compliance with the CSDDD requires companies to embed due diligence throughout their governance, risk management and day-to-day business operations, shifting it from a periodic checklist to an active operational requirement. In practice, this requires companies to establish ongoing processes to identify, assess, prevent, mitigate and, where necessary, remedy adverse human rights and environmental impacts arising throughout their own operations, those of their subsidiaries and their chain of activities. Companies can no longer rely solely on periodic or superficial third-party audits; instead, they must implement comprehensive supply chain mapping to identify, assess and prioritise adverse human rights and environmental impacts. Where actual or potential risks are identified, businesses have a statutory duty to take concrete action. This includes developing targeted prevention plans, implementing appropriate internal policies and controls, securing binding contractual assurances from direct business partners, adjusting purchasing practices that exacerbate risk, and engaging directly with affected stakeholders throughout the design and execution of mitigation strategies.
Climate Strategy and the Mandatory Remediation Framework
Beyond operational risk management, the CSDDD introduces new obligations relating to climate transition planning and remediation of adverse impacts, which directly shape corporate strategy. Under Article 22, in-scope entities must adopt and implement a climate change mitigation transition plan, aligning their business model and strategy with the Paris Agreement’s objective of limiting global warming to 1.5°C through time-bound targets across Scope 1, 2 and 3 greenhouse gas emissions, covering emissions generated by the company’s own operations as well as those arising throughout its wider value chain. Concurrently, the Directive establishes a statutory remediation mechanism under Article 12, requiring companies to move beyond passive reporting by taking appropriate remedial measures, including remediation or compensation where required. Supported by accessible and transparent grievance mechanisms for affected workers and local communities, these combined provisions transform corporate sustainability from an administrative reporting exercise into a legally enforceable duty of care.
National Oversight and Administrative Enforcement
Under Articles 24 and 25 of Directive (EU) 2024/1760, Member States must designate national supervisory authorities equipped with robust investigative and administrative powers, ranging from ex-officio inquiries and unannounced inspections to binding interim orders to halt non-compliant practices. Under Article 27, Member States must establish effective and proportionate penalties, requiring maximum administrative fines to be set at no less than 5% of a company’s net worldwide turnover. In addition to financial sanctions, enforcement decisions must be published for at least five (5) years to ensure public transparency. Finally, Article 28 establishes the European Network of Supervisory Authorities to ensure consistent oversight and coordinate cross-border enforcement across Member States.
Defending Against Civil Liability under Article 29
Enforcement of the Directive operates through a dual system of administrative oversight and civil liability. Under Article 29, affected parties may bring civil claims for damages where a company intentionally or negligently fails to comply with its obligations under Articles 10 and 11, and that failure causes damage to a person’s legally protected interests. Importantly, Article 29 provides that a company cannot be held liable where the damage was caused exclusively by its business partners in its chain of activities. While implementing effective due diligence measures does not provide absolute immunity from liability, maintaining documented risk assessments, robust prevention protocols and appropriate contractual safeguards may assist in demonstrating that the company exercised the required standard of care and complied with its due diligence obligations, thereby strengthening its position in the event of civil claims.
Balancing the Cost: The Three-Wave Transition Period
Ultimately, implementing such rigorous ethical and legal standards carries significant financial weight, requiring substantial capital investment for supply chain audits, vendor monitoring, and procedural restructuring. Recognizing these financial burdens and the operational adjustments required, European lawmakers structured the Directive to roll out on a phased timeline based on company size. Accordingly, companies falling within the Directive’s scope should begin assessing their governance frameworks, contractual arrangements, supplier relationships and internal compliance procedures well in advance of the applicable implementation date. The application begins on 26 July 2027 for the largest market players with over 5,000 employees and a net turnover exceeding €1.5 billion, expanding on 26 July 2028 to mid-tier corporate entities with over 3,000 employees and a net turnover exceeding €900 million. Finally, it reaches full statutory application on 26 July 2029, covering all remaining in-scope companies with over 1,000 employees and a net turnover exceeding €450 million.
As Cyprus proceeds with the transposition of the Directive into national legislation, businesses operating in or through Cyprus should begin reviewing their governance frameworks, contractual arrangements and supply chain due diligence processes to ensure timely compliance with the forthcoming domestic legal framework. Early preparation will not only assist businesses in meeting future legal obligations but may also strengthen their contractual relationships with customers, investors and other stakeholders increasingly focused on responsible business conduct.
Conclusion: The Resilience Payoff
In conclusion, while the necessary compliance investments and supervisory measures are financially demanding, this new regulatory reality presents both significant compliance challenges and valuable opportunities for companies that proactively strengthen their governance and sustainability practices. Beyond its upfront compliance costs, the CSDDD transforms ethical responsibility into a binding regulatory obligation and marks a significant development in the European Union’s corporate sustainability and governance framework. Ultimately, businesses that integrate effective due diligence into their governance frameworks will be better positioned not only to ensure legal compliance but also to enhance operational resilience, strengthen stakeholder confidence and manage long-term business risk.
For further information or legal assistance regarding compliance with the above requirements, please do not hesitate to contact us at info@kpklegal.com.
Disclaimer: This article is provided for informational purposes only and does not constitute legal advice. Readers are advised to seek professional legal advice in relation to their particular circumstances.
Co-authored by:
Maria Hadjisavva
Senior Advocate, KPK Legal
Antigoni Georgiou
Paralegal | Law Student, National and Kapodistrian University of Athens (NKUA)
