Social & Human Rights

Human Rights Due Diligence under CSDDD

By ESG Training Institute Editorial 12 min read
Share this article
Human Rights Due Diligence under CSDDD
A practical ESG analysis of Human Rights Due Diligence under CSDDD, including reporting implications, implementation steps, common pitfalls, and actions for the next quarter.
Executive summary

The adoption of the Corporate Sustainability Due Diligence Directive (CSDDD) marks a paradigm shift in corporate accountability, moving human rights from voluntary reporting frameworks into the realm of enforceable legal obligations. This directive requires large companies operating within the European Union to identify, prevent, mitigate, and account for adverse human rights and environmental impacts across their global value chains. For sustainability, risk, and legal professionals, the CSDDD necessitates a fundamental restructuring of procurement, legal contracting, and internal governance mechanisms.

  • Mandatory Due Diligence: The directive codifies the requirement for companies to conduct risk-based human rights and environmental due diligence, moving beyond "check-the-box" compliance to substantive impact management.
  • Scope and Thresholds: The regulation applies to EU companies with over 1,000 employees and a net worldwide turnover exceeding €450 million, as well as non-EU companies with significant EU-generated revenue, ensuring a level playing field.
  • Civil Liability: A critical component of the CSDDD is the introduction of civil liability, allowing victims of human rights abuses to seek compensation in EU courts if a company failed to implement adequate preventive measures.
  • Value Chain Responsibility: The scope extends to "chains of activities," encompassing upstream suppliers and certain downstream activities, requiring deep visibility into multi-tier supply networks.
  • Integration with CSRD: The CSDDD acts as the substantive "doing" component that feeds the "reporting" requirements of the Corporate Sustainability Reporting Directive (CSRD) and the European Sustainability Reporting Standards (ESRS).
Building skills in this area? Enroll in CSRP — the leading certification for this topic.
Enroll now

Operationalizing Human Rights Due Diligence Under the CSDDD

Why It Matters

For decades, human rights due diligence (HRDD) was guided by the United Nations Guiding Principles on Business and Human Rights (UNGPs) and the OECD Guidelines for Multinational Enterprises. While these frameworks provided a moral and operational compass, they lacked the "teeth" of legal enforcement. The CSDDD changes this by transforming soft law into hard law.

The financial implications are significant. Beyond the risk of administrative fines—which can reach up to 5% of a company’s net worldwide turnover—organizations face profound reputational risks and the potential for exclusion from public procurement contracts. Investors are increasingly viewing human rights failures as material financial risks, particularly regarding supply chain disruptions and legal costs.

Furthermore, the CSDDD addresses the "governance gap" in globalized trade. By requiring companies to address issues like forced labor, child labor, and inadequate workplace safety in their global operations, the EU is effectively exporting its human rights standards. For the C-suite, this means that human rights are no longer just a CSR issue; they are a core component of fiduciary duty and long-term value preservation.

The Standard / Framework in Detail

The Standard / Framework in Detail — Human Rights Due Diligence under CSDDD
The Standard / Framework in Detail — Human Rights Due Diligence under CSDDD

The CSDDD is built upon a six-step due diligence process derived from the OECD Due Diligence Guidance for Responsible Business Conduct. Understanding these steps is essential for building a compliant framework.

1. Integration into Policies and Management Systems

Companies must develop a due diligence policy, updated annually, that describes the company’s approach to due diligence, a code of conduct for employees and subsidiaries, and the processes put in place to implement due diligence.

2. Identifying and Assessing Adverse Impacts

This involves identifying actual or potential adverse human rights and environmental impacts. The assessment must be based on quantitative and qualitative information and must involve consultation with affected stakeholders.

3. Preventing and Mitigating Potential Impacts

Where potential impacts are identified, companies must take appropriate measures to prevent them. This includes developing a prevention action plan, seeking contractual assurances from business partners, and making necessary investments in management systems or infrastructure.

4. Bringing Adverse Impacts to an End

If an adverse impact has already occurred, the company must take immediate action to neutralize or minimize its extent. This may include the payment of damages to affected communities or individuals.

5. Establishing a Complaints Procedure

Companies must provide a mechanism for persons who have legitimate concerns regarding actual or potential adverse impacts to submit complaints. This must be accessible to workers, trade unions, and civil society organizations.

6. Monitoring Effectiveness

Organizations are required to carry out periodic assessments of the implementation and effectiveness of their due diligence measures. This monitoring must be based on qualitative and quantitative indicators.

Key takeaway

"The CSDDD represents the most significant evolution in corporate law in a generation, shifting the focus from shareholder primacy to a stakeholder-centric model where the 'S' in ESG is backed by the force of law and civil litigation."

Comparison: CSDDD vs. UNGPs vs. German LkSG

FeatureUN Guiding Principles (UNGPs)German Supply Chain Act (LkSG)EU CSDDD
Legal StatusVoluntary / Soft LawNational Law (Germany)EU Directive (Transposed to National Law)
Civil LiabilityNoNoYes (Direct right of action for victims)
Scope of Value ChainFull Value ChainPrimarily Tier 1 (Direct)Upstream & Limited Downstream
Climate MandateNot ExplicitLimitedMandatory Climate Transition Plan (1.5°C)
EnforcementNoneAdministrative FinesFines (up to 5% turnover) + Civil Liability

Practical Applications

Implementing the CSDDD requires a cross-functional approach involving Legal, Procurement, Sustainability, and Risk Management.

Risk Mapping and Prioritization

Given the scale of global supply chains, companies cannot address every risk simultaneously. The CSDDD allows for prioritization based on the severity and likelihood of the impact. Professionals should use geographic risk indices (e.g., ITUC Global Rights Index) and sector-specific data to map their "hotspots."

Contractual Clauses and "Responsible Purchasing"

Simply adding a "Human Rights Clause" to a supplier contract is no longer sufficient. The CSDDD emphasizes "reciprocal obligations." If a company demands higher labor standards, it must also ensure its purchasing practices (e.g., lead times, pricing) do not make those standards impossible to achieve.

Stakeholder Engagement

Meaningful engagement is a cornerstone of the directive. This means moving beyond surveys to active dialogue with workers, local communities, and NGOs. For companies operating in high-risk zones, this might involve third-party monitors or local grievance mediators.

Transition Planning

Article 15 of the CSDDD requires companies to adopt and put into effect a transition plan for climate change mitigation to ensure that the business model and strategy are compatible with the transition to a sustainable economy and the limiting of global warming to 1.5 °C in line with the Paris Agreement.

Industry Examples

Industry Examples — Human Rights Due Diligence under CSDDD
Industry Examples — Human Rights Due Diligence under CSDDD

1. The Electronics Sector: Conflict Minerals and Cobalt

A major European electronics manufacturer has moved beyond annual audits to a "continuous monitoring" model for its cobalt supply chain in the Democratic Republic of Congo. Recognizing that audits often fail to catch child labor, the company partnered with local NGOs to establish "on-the-ground" grievance mechanisms and invested in blockchain-based traceability.

  • Lesson: Transparency is the prerequisite for due diligence. Without knowing the mine of origin, mitigation is impossible.

2. The Apparel Industry: Responsible Purchasing Practices

A large retail group faced criticism when its aggressive pricing led suppliers to subcontract to unauthorized factories with poor safety records. In response to the impending CSDDD, the group restructured its procurement KPIs. Buyers are now incentivized not just on margin, but on the "social compliance score" of their suppliers.

  • Lesson: Internal misalignments (e.g., Procurement vs. Sustainability) are the primary drivers of supply chain human rights risks.

3. The Automotive Sector: Downstream Due Diligence

A German automaker is mapping the "downstream" impact of its products, specifically focusing on the end-of-life disposal of EV batteries. By establishing take-back schemes and ensuring recycling partners in developing markets adhere to EU safety standards, they are addressing the "chain of activities" requirement of the CSDDD.

  • Lesson: Due diligence does not end at the factory gate; it extends to the disposal and recycling of the product.

Regulatory Implications

The CSDDD does not exist in a vacuum; it is part of a dense web of interconnected regulations and standards.

  • CSRD & ESRS: The Corporate Sustainability Reporting Directive (CSRD) provides the reporting framework. Specifically, ESRS S1 (Own Workforce), S2 (Workers in the Value Chain), S3 (Affected Communities), and S4 (Consumers and End-users) are the disclosure vehicles for CSDDD actions. EFRAG ESRS Standards.
  • IFRS & ISSB: While IFRS S1 and S2 focus primarily on climate and general sustainability-related financial disclosures, the ISSB is currently researching human rights disclosures, which will likely align with the CSDDD’s rigorous assessment requirements. IFRS Sustainability Standards.
  • GRI: The Global Reporting Initiative (GRI) updated its Universal Standards (GRI 1, 2, and 3) in 2021 to align closely with the UNGPs, making it a primary tool for companies to document the due diligence process required by CSDDD. GRI Standards.
  • OECD Guidelines: The CSDDD explicitly references the OECD Guidelines for Multinational Enterprises as the gold standard for due diligence methodology. OECD Guidelines.
  • EU Taxonomy: The "Minimum Safeguards" of the EU Taxonomy (Article 18) require companies to align with the UNGPs and OECD Guidelines to be considered "environmentally sustainable." CSDDD compliance will effectively serve as the proof of meeting these safeguards. EU Taxonomy Regulation.
Free download

The 2026 ESG Reporting & Assurance Playbook

A 42-page practical guide covering IFRS S1/S2, CSRD/ESRS and ISSA 5000 — written for finance, audit and sustainability teams.

Get the guide

Implementation Roadmap

Phase 1: Gap Analysis and Governance (Months 1-6)

  1. Board Oversight: Assign formal responsibility for due diligence to the Board of Directors.
  2. Policy Review: Update the Corporate Code of Conduct and Supplier Code of Conduct to reflect CSDDD requirements.
  3. Cross-Functional Taskforce: Establish a committee including Legal, HR, Procurement, and ESG.

Phase 2: Risk Mapping and Prioritization (Months 7-12)

  1. Value Chain Mapping: Identify all entities in the "chain of activities," focusing on high-risk geographies and commodities.
  2. Salience Assessment: Determine which human rights risks are most severe and likely.
  3. Data Integration: Implement software solutions to track supplier data and risk indicators.

Phase 3: Mitigation and Engagement (Months 13-24)

  1. Contractual Updates: Integrate "reciprocal" human rights clauses into all new and renewing supplier contracts.
  2. Grievance Mechanisms: Audit existing whistleblowing channels to ensure they are accessible to external stakeholders (e.g., supply chain workers).
  3. Supplier Training: Provide capacity-building programs for high-risk suppliers rather than simply terminating contracts.

Phase 4: Monitoring and Reporting (Ongoing)

  1. Effectiveness Audits: Move from "compliance audits" to "impact assessments."
  2. CSRD Alignment: Ensure all due diligence actions are documented for ESRS S1-S4 reporting.
  3. Annual Statement: Publish the mandatory annual due diligence statement on the company website.

Common Pitfalls

  • Reliance on "Paper Compliance": Many companies believe that having a signed Supplier Code of Conduct is sufficient. Under CSDDD, this is merely the first step. If a company knows (or should have known) that a supplier is violating the code and takes no action, the signed paper offers no legal protection.
  • Siloed Data: Human rights data often sits in HR or Procurement, while ESG reporting sits in Finance or Sustainability. Without a unified data architecture, identifying systemic risks across the value chain is impossible.
  • Ignoring Downstream Impacts: While the final text of the CSDDD narrowed the downstream scope, companies still must account for the distribution, transport, and storage of their products, especially in sectors like chemicals or heavy machinery.
  • Lack of Stakeholder Voice: Conducting a risk assessment without talking to the people actually affected (e.g., workers in a specific region) is a major weakness that regulators and NGOs will target.
  • Inadequate Remedy: The CSDDD emphasizes "remediation." If a violation is found, the company must show how it helped the victims. Simply firing the supplier does not count as remediation and may actually worsen the situation for the workers.

Case Snapshot

Sector: Renewable Energy (Solar) Region: Southeast Asia / EU Issue: Allegations of forced labor in the production of polysilicon used in solar panels. Action: A European solar developer implemented a "Traceability-to-Source" program. They required suppliers to provide satellite imagery of production sites and independent labor audit reports. When one supplier refused, the developer engaged in a six-month "corrective action plan" before eventually divesting when no progress was made. Outcome: The company was able to demonstrate to investors and regulators that it had followed the "prevent, mitigate, and cease" steps of the CSDDD, protecting it from legal action when the supplier was later sanctioned by other jurisdictions.

Key Takeaways

  1. Legal Liability is Real: The CSDDD introduces civil liability, meaning companies can be sued in EU courts for human rights failures in their global supply chains.
  2. Beyond Tier 1: Due diligence must extend to the entire "chain of activities," requiring visibility into sub-tier suppliers and certain downstream partners.
  3. Reciprocal Responsibility: Companies must examine their own purchasing practices to ensure they do not inadvertently cause human rights abuses at the supplier level.
  4. Mandatory Climate Plans: The directive includes a requirement for a climate transition plan aligned with the 1.5°C goal of the Paris Agreement.
  5. Integration is Key: CSDDD compliance is the substantive foundation for CSRD/ESRS reporting; the two must be developed in tandem.
  6. Remediation Over Termination: The goal of the directive is to improve conditions. Companies should prioritize working with suppliers to fix issues rather than immediately cutting ties, which is seen as a last resort.

Frequently Asked Questions

Q1: Does the CSDDD apply to non-EU companies? Yes. Non-EU companies are in scope if they generate a net turnover of more than €450 million within the European Union. This ensures that foreign companies competing in the EU market are held to the same ethical standards as EU-based firms.

Q2: What are the penalties for non-compliance? Member States will designate supervisory authorities to monitor compliance. Fines can be as high as 5% of the company’s global net turnover. Additionally, the civil liability provision allows victims to sue for damages.

Q3: How does CSDDD differ from the CSRD? The CSRD is a reporting directive; it dictates what you must disclose. The CSDDD is a conduct directive; it dictates how you must behave and what processes you must have in place. The CSDDD provides the "content" that is then reported under the CSRD.

Q4: Can we rely on third-party certifications (e.g., Fairtrade, FSC)? Certifications can be used as supporting evidence, but they do not provide a "safe harbor." The company remains legally responsible for its due diligence and must verify that the certification schemes it relies on are robust and relevant.

Q5: What is the "Chain of Activities"? This term replaced "value chain" in the final negotiations. It includes upstream activities (raw material extraction, manufacturing) and limited downstream activities (distribution, transport, and storage). It generally excludes the disposal of the product by consumers and the activities of most financial service end-users.

Q6: When does this come into effect? The CSDDD will be phased in based on company size. The largest companies (5,000+ employees, €1,500m turnover) must comply by 2027, with smaller in-scope companies following in 2028 and 2029. However, preparation must begin now due to the complexity of mapping global supply chains.

Further Reading

Frequently asked questions

Related ESG standards
Take it further

Become a certified specialist on this topic.

Enroll in Certified Sustainability Reporting Professional (CSRP) or request a corporate training programme for your team.

References & sources

  1. IFRS Sustainability Standards
  2. Global Reporting Initiative
  3. European Sustainability Reporting Standards

Join the conversation

Sign in to comment and discuss this analysis with other ESG professionals.

Sign in to comment