FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
55of55items
Across 13 modules • Updated Jul 25, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
CSDDD chain of activities boundaries: upstream and downstream

What does chain of activities mean under the CSDDD?

For CSDDD due diligence, start with three buckets: the company's own operations, the operations of its subsidiaries, and the operations of business partners where those partner activities are related to the company's chain of activities.

The upstream side is broad. It covers business partner activities related to producing goods or providing services for the company, including design, extraction, sourcing, manufacture, transport, storage, raw material supply, product or part supply, and development of the product or service.

The downstream side is narrower. It covers distribution, transport, and storage of the company's product only where the downstream business partner performs those activities for the company or on the company's behalf.

Member States must transpose the amended CSDDD by 26 July 2028 and apply the due diligence measures from 26 July 2029. Use the current EU definition for readiness and data design, then confirm the enacted national provision before treating a boundary decision as an operative legal conclusion.

  • Map own operations and subsidiary operations separately from partner operations.
  • Classify each partner as upstream, downstream product logistics, or outside the CSDDD chain-of-activities definition.
  • Do not treat downstream customer use, general resale, product disposal, or downstream services as covered merely because they occur after sale.
Citations
Directive (EU) 2026/470

Binding current amendment for CSDDD scope, due diligence, monitoring, enforcement, and status changes discussed on this page.

CSDDD chain of activities boundaries: upstream and downstream

Are subsidiaries inside the chain of activities boundary?

Subsidiaries sit in a separate category from suppliers. The CSDDD treats due diligence as covering a company's own operations, the operations of its subsidiaries, and, where related to the chain of activities, the operations of business partners.

That means a boundary file should identify subsidiaries directly, then identify which business partners sit in each subsidiary's chain of activities. If a parent carries out due diligence obligations on behalf of in-scope subsidiaries, the subsidiary still needs enough local records to show how the parent policy, risk assessment, prevention measures, stakeholder engagement, remediation, and monitoring apply to that subsidiary.

Where a parent uses the CSDDD group-level support route, keep the parent-subsidiary information exchange, adapted policy, local risk-management integration, and any subsidiary-specific partner measures visible in the evidence file.

  • Record each covered subsidiary, legal entity, activity, site, product line, and service line.
  • Show which parent-level due diligence elements apply to the subsidiary and which are handled locally.
  • Keep subsidiary evidence separate enough to respond to supervisory authority questions and civil-liability analysis.
Citations
CSDDD chain of activities boundaries: upstream and downstream

How should direct and indirect business partners be classified?

A direct business partner is an entity with a commercial agreement related to the company's operations, products, or services, or an entity to which the company provides services. An indirect business partner is not the direct contracting party, but performs business operations related to the company's operations, products, or services.

The distinction matters because CSDDD measures often start with direct partners, then extend to indirect partners when their activities are part of the chain of activities and where risk assessment shows adverse impacts are likely or severe. For example, contractual assurances from a direct partner may need corresponding assurances from that partner's relevant partners; in some cases, the company may seek assurances directly from an indirect partner.

Do not stop classification at the procurement system's vendor record. The useful test is whether the partner's activity is related to the company's operations, products, or services and falls inside the upstream or downstream chain-of-activities definition.

  • Use contract records to identify direct business partners.
  • Use bills of material, logistics flows, service delivery maps, supplier disclosures, audit data, and complaints to identify indirect partners.
  • Flag indirect partners in high-risk geographies, sectors, product inputs, or logistics roles for deeper assessment rather than treating them as invisible tiers.
Citations
CSDDD chain of activities boundaries: upstream and downstream

Where do downstream distribution, transport, and storage stop?

Downstream coverage is limited to distribution, transport, and storage of the company's product where a business partner carries out those activities for the company or on the company's behalf. It is not a general downstream customer, reseller, user, or end-of-life obligation.

A contracted warehouse, fulfilment provider, carrier, distributor, or logistics provider can therefore sit inside the downstream boundary when it handles the company's product for the company. A customer that buys and uses the product for its own business normally needs a separate analysis and should not be included merely because it is downstream.

The directive also states that the chain of activities does not include product disposal. It excludes distribution, transport, storage, and disposal of products subject to Member State export controls, including dual-use controls or weapons, munitions, and war material controls, once export is authorised.

  • Include downstream product logistics performed for the company or on its behalf.
  • Exclude downstream activities related to the company's services, and for regulated financial undertakings exclude downstream recipients of services and products.
  • Exclude product disposal from the CSDDD chain-of-activities boundary, while checking whether another product, waste, export-control, or sector law applies.
Citations
CSDDD chain of activities boundaries: upstream and downstream

How does amended Article 8 limit partner information requests?

The boundary map and the in-depth assessment are different steps. Article 8 first requires a scoping exercise based only on reasonably available information to identify general areas where adverse impacts are most likely and most severe. The company then performs an in-depth assessment in those areas.

For that in-depth assessment, a company may request partner information only where it is necessary. If the partner has fewer than 5,000 employees, the company may request the information only when it cannot reasonably obtain it by other means. Where several partners can provide the information, the company should request it, where reasonable, from the partner or partners where impacts are most likely to occur. Direct partners may be prioritised only where areas are equally likely or equally severe.

  • Use reasonably available information for the initial scoping exercise.
  • Record why a requested data item is necessary for the in-depth assessment.
  • For a partner with fewer than 5,000 employees, record why another reasonable source could not supply the information.
  • Do not turn direct-tier convenience into a blanket rule that excludes higher-risk indirect partners.
Citations
CSDDD chain of activities boundaries: upstream and downstream

What evidence should a CSDDD boundary decision retain?

Keep evidence that proves why each activity is in scope, out of scope, or unresolved. A useful boundary record links the legal definition to the company's actual product, service, subsidiary, supplier, logistics, and partner facts.

The record should also show how the boundary decision fed the Article 8 scoping exercise and in-depth assessment, and how it affected prevention or mitigation measures under Article 10 or actual-impact measures under Article 11.

Because business partners are not generally required to disclose trade secrets, preserve the minimum information needed to identify direct and indirect partners and adverse-impact risks without turning the evidence request into an unsupported data grab.

  • Boundary matrix with columns for entity, activity, product or service, upstream or downstream classification, direct or indirect partner status, inclusion decision, source citation, and reviewer.
  • Product and service flow evidence: bills of material, sourcing maps, logistics routes, warehouse contracts, distributor contracts, service delivery diagrams, and subsidiary activity descriptions.
  • Risk evidence: sector, geography, product, service, business-operation, and complaint data used for the reasonably available scoping exercise and the later in-depth assessment.
  • Information-request record: necessity, partner size, alternative sources checked, requested fields, response, and the reason for choosing that partner.
  • Action evidence: prevention action plans, contractual assurances, verification records, SME support decisions, enhanced-plan or suspension reviews, and monitoring updates where the boundary decision triggered CSDDD measures.
Citations
CSDDD chain of activities boundaries: upstream and downstream

What is the most common mistake with CSDDD chain-of-activities boundaries?

The most common mistake is using a broad value-chain diagram as if every actor in it is automatically inside the CSDDD chain of activities. The directive's wording is more specific: upstream is tied to production of goods or provision of services, while downstream is limited to product distribution, transport, and storage performed for the company or on its behalf.

A second mistake is losing the distinction between subsidiaries, direct partners, and indirect partners. Those categories affect who holds information, who can influence the relevant activity, which assurances are realistic, and what evidence can be requested without overreaching.

A defensible answer is a maintained boundary file: it names the entity, activity, product or service, partner tier, inclusion decision, exclusion rationale, risk signals, and follow-up due diligence measure.

  • Do not include product disposal unless another legal regime separately requires disposal controls.
  • Do not include downstream service recipients as if they were downstream product logistics providers.
  • Do not rely only on first-tier supplier lists when indirect partners perform activities tied to high-risk production, sourcing, manufacture, transport, storage, or supply.
Citations
CSDDD complaints and notifications

What does Article 14 require companies to set up?

Article 14 requires a notification mechanism and a complaints procedure. The complaint route is for listed people and organisations that have legitimate concerns about actual or potential adverse impacts connected to the company's own operations, subsidiaries, or business partners in its chain of activities.

The company procedure must be fair, publicly available, accessible, predictable, and transparent. It also needs a path for complaints the company considers unfounded, and relevant workers' representatives and trade unions must be informed about the procedure.

Member States must transpose the amended CSDDD by 26 July 2028 and apply Article 14 through national measures from 26 July 2029. Before then, teams can build the channel and case workflow against the current EU requirements, but must recheck the enacted national procedure, privacy rules, worker-representation rules, and authority routes before launch.

  • Publish the complaint route where affected people, representatives, unions, and experienced civil society organisations can find it.
  • Accept complaints about actual or potential human rights and environmental adverse impacts within the Article 14 scope.
  • Define how the company assesses whether a complaint is founded or unfounded.
  • Treat the impact in a well-founded complaint as identified under Article 8 and route it into the applicable Articles 10, 11, and 12 measures.
Citations
CSDDD complaints and notifications

Who may submit a CSDDD complaint?

Article 14 lists three groups. First, natural or legal persons who are affected, or have reasonable grounds to believe they might be affected, by an adverse impact may complain. Their legitimate representatives, including civil society organisations and human rights defenders, may complain on their behalf.

Second, trade unions and other workers' representatives may complain for people working in the chain of activities concerned. Third, civil society organisations may complain where they are active and experienced in areas related to the environmental adverse impact at issue.

  • Affected people and legal persons, including those with reasonable grounds to believe they might be affected.
  • Legitimate representatives acting on behalf of affected people, such as civil society organisations or human rights defenders.
  • Trade unions and other workers' representatives for people working in the relevant chain of activities.
  • Experienced civil society organisations for complaints about related environmental adverse impacts.
Citations
CSDDD complaints and notifications

What is a legitimate concern, and what evidence helps?

The Directive uses the phrase legitimate concerns for complaints about actual or potential adverse impacts. Article 14 does not state a court-style evidentiary threshold for accepting a complaint. The company may define a fair intake and assessment process, but it should not demand proof that prevents an eligible complainant from raising a concern tied to the company's operations, subsidiaries, or chain-of-activities business partners.

Useful intake evidence is therefore practical: who or what may be affected, the site, supplier, activity, product, or business relationship involved, the type of human rights or environmental harm alleged, dates or time period if known, documents or photographs if available, and whether confidentiality or anonymity is requested.

  • Capture enough facts to test Article 14 scope without demanding unnecessary proof at intake.
  • Separate evidence supplied by the complainant from facts the company later verifies through due diligence.
  • Record the company's reasoning when the complaint is treated as founded or unfounded.
  • If founded, document the link to identified impacts and the measures taken or planned.
Citations
CSDDD complaints and notifications

What follow-up rights do complainants have?

Complainants have explicit Article 14 follow-up rights. They may request appropriate follow-up from the company, meet company representatives at an appropriate level to discuss actual or potential severe adverse impacts and potential remediation, and receive reasons for why the complaint was considered founded or unfounded.

Where the company considers a complaint founded, it must also provide information on steps and actions taken or to be taken. That makes the case record important: it should show the intake date, assessment path, meetings offered or held, reasons given, and follow-up measures.

  • Acknowledge and triage the complaint through a defined procedure.
  • Offer appropriate follow-up and escalation to representatives able to discuss severe impacts and remediation.
  • Give reasons for a founded or unfounded outcome.
  • For founded complaints, provide information on steps already taken or planned.
Citations
CSDDD complaints and notifications

How do confidentiality, anonymity, and non-retaliation work?

For complaints, companies must take reasonably available measures to prevent retaliation by ensuring the confidentiality of the complainant's identity in accordance with national law. If information needs to be shared, it must be shared in a way that does not endanger the complainant's safety, including by not disclosing that identity.

For notifications, Article 14 requires the mechanism to allow anonymous or confidential notifications in accordance with national law. Companies must also take reasonably available anti-retaliation measures by keeping the identity of people or entities submitting notifications confidential.

  • Ask at intake whether the person wants confidentiality or anonymity where available.
  • Restrict identity access to personnel who need it for handling and safety.
  • Do not disclose identity when sharing information if disclosure could endanger the complainant.
  • Keep retaliation controls documented, including access logs, redactions, and safety decisions.
Citations
CSDDD complaints and notifications

How is a complaint different from a notification or substantiated concern?

A complaint is submitted to the company by the Article 14 complainant groups when they have legitimate concerns about actual or potential adverse impacts. A notification is also submitted to the company, but it is framed more broadly for persons and entities that have information or concerns about actual or potential adverse impacts.

A substantiated concern is different: it is submitted to a supervisory authority under Article 26 when a natural or legal person has reasons to believe, based on objective circumstances, that a company is failing to comply with national law implementing the Directive. Article 14 says using the company complaint or notification channel is not a prerequisite for, and does not block, access to substantiated concerns, civil liability procedures, or other non-judicial mechanisms.

  • Complaint: company channel for listed complainants with legitimate concerns about adverse impacts.
  • Notification: company channel for information or concerns, with anonymous or confidential submission where national law allows.
  • Substantiated concern: supervisory-authority route based on objective circumstances suggesting non-compliance.
  • Do not make company-channel use a condition for access to authority, court, or other non-judicial routes.
Citations
CSDDD complaints and notifications

What records should a company keep for Article 14 complaints?

The useful evidence file is a case file, not a generic policy attachment. It should prove that the channel was public and accessible, the correct complainant and impact questions were assessed, confidentiality and safety were handled, follow-up rights were respected, and founded complaints were connected to due diligence measures.

Because Article 14 outcomes can feed identification, prevention, mitigation, bringing impacts to an end, minimisation, remediation, enhanced plans, and suspension decisions, the record should be usable by sustainability, legal, procurement, human rights, environmental, and worker-relations owners. Article 5 requires due diligence compliance documentation to be kept for at least five years, but longer national limitation, employment, whistleblowing, privacy, or litigation-hold rules may affect a case file.

  • Public procedure, intake form, language/accessibility notes, and worker or union communication records.
  • Complaint or notification intake record, including complainant category, alleged impact, affected operations or chain-of-activities link, and confidentiality request.
  • Triage and assessment record explaining whether the matter is founded, unfounded, outside Article 14, or better routed as a notification.
  • Follow-up record covering acknowledgements, meetings, reasons provided, and steps or actions taken or planned.
  • Retaliation-prevention evidence, such as identity controls, redactions, restricted-access logs, and safety decisions.
  • Due diligence linkage showing any identified impact and the related Article 10, 11, or 12 measures.
Citations
CSDDD contractual assurances FAQ for Articles 10 and 11

When should CSDDD teams seek contractual assurances from business partners?

For potential adverse impacts, Article 10 requires companies to take appropriate measures to prevent or adequately mitigate impacts identified through due diligence. One relevant measure is seeking contractual assurances from a direct business partner that it will comply with the company's code of conduct and, where needed, a prevention action plan.

For actual adverse impacts, Article 11 uses the same structure for bringing the impact to an end or minimising its extent: direct partner assurances can support compliance with the code of conduct and, where needed, a corrective action plan. If the impact cannot be adequately addressed through the listed direct measures, Articles 10 and 11 also allow the company to seek assurances from an indirect business partner.

Member States must transpose the amended CSDDD by 26 July 2028 and apply Articles 10 and 11 through national measures from 26 July 2029. Draft clauses and verification controls can be prepared earlier, but they should be reviewed when the Commission issues voluntary model-clause guidance by 26 July 2027 and again when the relevant national law is enacted.

  • Use Article 10 assurances when the issue is a potential adverse impact that must be prevented or mitigated.
  • Use Article 11 assurances when the issue is an actual adverse impact that must be ended, minimised, and, where relevant, remediated.
  • Tie each assurance to the specific code-of-conduct obligation, prevention action plan, or corrective action plan it is meant to support.
  • Do not ask for generic supply-chain promises when the due-diligence finding points to a narrower activity, site, product line, sourcing practice, or business partner.
Citations
Directive (EU) 2026/470

Binding current amendment for CSDDD scope, due diligence, monitoring, enforcement, and status changes discussed on this page.

Page 1 of 4
Previous1234Next