Key takeaways
- GPSR requires every online offer to show the manufacturer, the EU responsible person, product identifiers, and safety warnings. A missing field is a listing defect, even if the product itself is safe.
- The EmpCo rules on green claims have applied since 27 September 2026. Generic environmental claims and uncertified sustainability labels are banned on product pages, packaging and ads, and this includes old stock.
- PPWR has applied since 12 August 2026. Packaging needs an EU declaration of conformity, and food-contact packaging must stay under PFAS limits.
- EUDR applies from 30 December 2026 for large and medium operators. Only the first operator files a due diligence statement, but the next company in the chain must keep its reference number.
- The Cyber Resilience Act has required manufacturers to report actively exploited vulnerabilities since 11 September 2026, including for products sold years ago.
- Compliance data is spread across ERP, PIM, shop, marketplaces and CRM. Each field needs one owner system, and the gaps between systems cause most failures.
Why Product Compliance Turned Into A Product Data Problem
Enforcement numbers keep climbing. According to the Commission's annual Safety Gate report, authorities issued 4,671 alerts on dangerous non-food products in 2025. That is 13% more than in 2024 and the highest figure on record. Cosmetics and toys made up over half of the cases. The same report counts 35% more follow-up actions, including removals of product listings from online marketplaces. More than 1,200 online marketplaces had registered in the Safety Gate portal by the end of 2025.
That last point matters for anyone selling online. A delisting is a data event. An authority sends the marketplace a removal order; the marketplace matches it to an offer and pulls it. If your product identifiers are inconsistent across channels, the marketplace may pull the wrong offer, or miss the one it should have pulled.
Most compliance failures we see happen after testing. The product passed. The certificate exists. But the listing on one marketplace still shows last year's importer address, the Polish shop has no warning text, and the ERP has no idea which packaging version went out with which batch.
The EU Rules That Now Live In Your Product Data
Several regimes landed in 2026 or will land within months. Each one adds fields, documents, or rules to product records.
GPSR: What Every Online Offer Must Show
The General Product Safety Regulation has applied since 13 December 2024. It requires a responsible economic operator in the EU for every consumer product in scope. That can be the EU manufacturer, the importer, an authorised representative or a fulfilment service provider.
Article 19 defines what a distance sales offer must display. That is the manufacturer's name, registered trade name or trademark, with postal and electronic address. If the manufacturer sits outside the EU, the offer also names the EU responsible person and their addresses. Then come product identification data, including a picture, the product type, and any other identifier. And finally, the warnings and safety information, in a language consumers in the target country easily understand.
Manufacturers must also keep technical documentation for 10 years, run internal product safety processes, and handle consumer complaints. In a recall, they must inform affected consumers directly. That pulls customer and order data into the compliance scope, so CRM and shop systems become part of the recall process.
Under GPSR, a listing that lacks the manufacturer's postal and electronic address is non-compliant, even when the product itself is safe.
Online marketplaces have their own duties. They register in the Safety Gate portal, name a single point of contact, act on authority orders within two working days, and design their interfaces so sellers can enter the Article 19 data. In practice, each marketplace maps these fields into its own attribute schema. Your data has to fit every schema you sell through. Also, the European Accessibility Act has applied to e-commerce services since 28 June 2025, so a warning that exists only inside a product image is a problem twice over.
EmpCo: Claims, Labels And Point-Of-Sale Information Since 27 September
The Empowering Consumers for the Green Transition Directive (EmpCo) amends the Unfair Commercial Practices Directive and the Consumer Rights Directive. It started applying on 27 September 2026. Linklaters' EmpCo guide sums up the main changes.
Generic claims such as "eco-friendly" or "climate friendly" are banned unless the trader can show recognised excellent environmental performance, for example through the EU Ecolabel or an EN ISO 14024 Type I ecolabel. Sustainability labels must be based on a qualifying certification scheme or set by a public authority. Product neutrality claims based on carbon offsetting are banned. So is presenting a legal requirement as a selling point, like "contains no banned chemicals" when the chemical is banned for the whole category.
The rules also reach visuals. A leaf icon next to a sustainability statement can count as a label. Your DAM is now part of the compliance review.
EmpCo adds pre-contractual information too. Traders must show the repairability score where an EU score exists. Smartphones and tablets carry one since June 2025. For household tumble dryers, a repairability class on the energy label is optional until the end of 2026 and mandatory from 1 January 2027. For other goods, they must show spare parts availability and repair information if the producer makes it available. Goods with digital elements need the minimum software update period. Online shops must display a harmonised notice on the legal guarantee, and a harmonised label where the producer offers a free commercial durability guarantee longer than two years. That label can sit next to the product image.
There is no grandfathering. Products already on the market are in scope. According to the same Linklaters guide, the CPC Network of national enforcers published a non-binding Common Understanding on old stock in June 2026. EmpCo leaves penalties to member states. In coordinated cross-border enforcement, though, the maximum fine available must be at least 4% of the trader's annual turnover in the member states concerned, or at least €2 million where turnover data is unavailable.
PPWR: Packaging Data Since 12 August
The Packaging and Packaging Waste Regulation (EU) 2025/40 has applied since 12 August 2026. Packaging placed on the market from that date needs an EU declaration of conformity and technical documentation. Food-contact packaging cannot exceed the PFAS limits in Article 5(5). Heavy metal limits and a duty to minimise substances of concern apply to all packaging. Suppliers must give packaging manufacturers the information needed to show conformity.
Packaging placed on the market before 12 August can stay in circulation. That makes the placing-on-market date a field you need, per packaging version. Harmonised sorting labels follow later, through implementing acts.
ESPR, Digital Product Passports And Batteries
The EU Digital Product Passport registry went live in July 2026, with organisation enrolment only. No product-specific ESPR delegated act was in force at that point. The Commission targets iron and steel first, with textiles, tyres and aluminium planned for 2027. Each delegated act will define its own data fields and compliance date, usually with a transition period.
Batteries come earlier. The battery passport under Regulation (EU) 2023/1542 becomes mandatory on 18 February 2027 for EV batteries, LMT batteries and industrial batteries above 2 kWh.
Toys get their own passport. The new Toy Safety Regulation (EU) 2025/2509, published in December 2025, applies from 1 August 2030. Its digital product passport replaces the EU declaration of conformity, and the toy must carry a data carrier linking to it. Customs can check that data carrier and the commodity code against the EU registry before releasing a shipment. A toy with a wrong HS code in the master data could be stuck at the border.
One ESPR rule already bites. Since 19 July 2026, large companies may not destroy unsold apparel and footwear, and they must disclose the unsold products they discard. Medium-sized companies follow in 2030.
EUDR: Deforestation Due Diligence From 30 December
After two postponements, the EU Deforestation Regulation applies from 30 December 2026 for large and medium operators and from 30 June 2027 for micro and small operators. The December 2025 amendment moved the due diligence statement to the operator who first places the product on the market. The first downstream operator keeps the statement's reference number. Scope follows the HS codes in Annex I, and the Commission can amend that list through delegated acts.
For product data, this means two things. Every SKU needs a reliable HS code and an EUDR relevance flag. And every delivery of in-scope goods needs a traceable DDS reference, which usually lives at batch or purchase order level in the ERP.
Cyber Resilience Act: Vulnerability Reporting Since 11 September
The Cyber Resilience Act (EU) 2024/2847 applies in full from 11 December 2027, with CE marking for products with digital elements. Its reporting duty started earlier. Since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe security incidents through ENISA's Single Reporting Platform, with an early warning due within 24 hours. The duty covers every product still available on the EU market, whatever its sale date. Importers and distributors who sell under their own brand count as manufacturers.
A 24-hour deadline is a data question. You need to know which product models, hardware revisions, and firmware versions are on the market, in which countries, and who supports them. Many companies hold that knowledge in engineering tickets and nowhere else. The software update period that EmpCo puts on product pages belongs in the same record.
Customs Data And Liability
Since 1 July 2026, low-value parcels under €150 entering the EU carry a flat €3 customs duty per tariff heading, for non-EU sellers registered in IOSS. It is temporary until the full customs reform takes over. A wrong HS code now costs money on every parcel.
The new Product Liability Directive (EU) 2024/2853 must be transposed by 9 December 2026. It treats software as a product and lets courts order defendants to disclose evidence. Version histories of product data and instructions will matter in court, too.
Where Compliance Breaks Between ERP, PIM, E-Commerce, Marketplaces And CRM
No single system owns product compliance. Each holds one part of it, and the gaps sit at the interfaces.
The ERP holds the commercial master record: article number, supplier, HS code, country of origin, batches, purchase orders and often the packaging bill of materials. It is good at transactions. It is bad at long multilingual texts, document versions, and channel-specific rules. Most ERPs have no clean place for "EU responsible person for brand X in market Y".
The PIM system holds marketing and technical attributes, translations, media links, and channel exports. It is where listings get assembled. If compliance data is missing here, it is missing everywhere downstream.
The e-commerce platform renders what it receives. Templates are the weak spot. A theme update can drop the warning block on mobile, and nobody notices until an authority does.
Marketplaces add their own schemas, length limits, and validation rules. A field that exports fine to your shop may be truncated or rejected on a marketplace.
The CRM and service tools hold complaints, product registrations, and customer contacts. GPSR recall duties need exactly this data. In many companies, it is not linked to SKUs or batches.
Typical breaks we see in practice:
- Manufacturer and responsible person data stored as free text per product, so one address change means thousands of manual edits
- Certificates and declarations stored on a shared drive, with no link to the SKUs they cover and no expiry date
- Warnings translated for the main market only, then copied untranslated into other country stores
- Marketing copy with claims like "sustainable" written in a CMS that never passes through compliance review
Our customers turn to us with a recurring version of the first problem. A manufacturer of household electrical appliances sold through its own shop and several marketplaces. Manufacturer and importer details existed only as vendor records in the ERP. Listings showed them inconsistently, or not at all. The fix was structural. We modelled the manufacturer and the EU responsible person as separate entities linked to brands, and products inherited them. Channel exports were blocked when either link was missing. An address change became one edit instead of a cleanup project.
What PIM Software Brings To Product Compliance Solutions
Product safety comes from design, testing, and production. A PIM handles the proof: it keeps compliance data consistent, complete, and visible in every channel. Regulators and marketplaces check that proof first.
Treat every compliance statement as a product attribute with an owner, a source document and a validity date. If one of the three is missing, the statement is a liability.
In practice, PIM software covers compliance through a few capabilities. A classification-based data model gives toys, cosmetics, electronics, and packaging their own required fields. Related entities hold shared data once: manufacturers, responsible persons, certificates, packaging versions, suppliers. Document management links each declaration or test report to the SKUs it covers, with validity dates. Completeness rules per channel and per country stop exports when mandatory fields are empty. Workflows route claims and warnings through approval. An audit trail shows who changed what and when, which helps both in market surveillance checks and under the new liability rules.
In projects we implemented with AtroPIM, the configurable data model did most of the work. Teams add entities such as "Responsible Person", "Certificate" or "Packaging Version" and their relations in the interface, without custom development. That matters because the rules keep moving. When a delegated act defines new DPP fields, the model has to absorb them quickly. AtroPIM is open source and built on the AtroCore data platform, so the same platform can also hold supplier or packaging data that does not fit a classic PIM.
A PIM has limits, and it helps to be explicit about them. It does not perform conformity assessments, chemical screening, or legal review. Substance-level data for REACH, SCIP, or PFAS screening usually comes from PLM or dedicated chemical compliance tools. The PIM should store the outcome, the evidence, and the status, then distribute them. Trying to rebuild a lab database inside a PIM rarely ends well.
A Practical Setup That Survives An Audit
Start from obligations. For each product category and target market, list which regulations apply and which data points they require. A toy sold in Germany and France through a marketplace has a different checklist than steel components sold B2B.
Then decide a single source of truth per field. HS codes, origin, and batch data belong in the ERP. Claims, warnings, translations, and documents belong in the PIM. Complaint and recall contacts belong in the CRM. Duplicating any of these creates two versions of the truth, and authorities will find the wrong one.
A workable sequence looks like this:
- Map obligations per category and market, including GPSR, EmpCo, PPWR, EUDR, and sector rules such as toys or cosmetics.
- Model shared entities once and link products to them, so a change in one place flows to every SKU.
- Attach evidence documents to products with validity dates and owners, and alert before expiry.
- Set completeness gates per channel and country that block exports with missing mandatory fields.
- Move claims into a controlled list of approved statements linked to their certificates.
- Link SKUs and batches to CRM and order data, so a recall reaches the right customers fast.
- Keep full change history for product data and documents.
Step 5 deserves attention right now. In projects we implemented for consumer goods manufacturers, green claims sat in free-text marketing fields across the shop, marketplace feeds, and printed packaging. Nobody could say which claim appeared where. The solution was a claim library in the PIM. Each claim carried its certificate link and allowed markets, and free-text descriptions were checked against a list of banned generic terms before export. EmpCo turned this from good practice into a legal requirement.
For ESPR, keep the DPP work proportionate. Clean identifiers, material composition, supplier links, and document structure will be needed under almost any delegated act. Building a full passport schema for textiles before the act is adopted means building it twice.
Risks And Trade-Offs Worth Planning For
Timelines remain partly uncertain. The EUDR has moved twice, and there is an open question about what downstream companies collect between 30 December 2026 and 30 June 2027, when micro and small primary operators are not yet filing statements. ESPR field lists exist only as plans until each delegated act lands. Plan for the data you know you need and leave room for the rest.
Translation is an underestimated risk. GPSR warnings must be in a language consumers easily understand in each market. Every new country store multiplies the review effort, and machine translation of safety warnings needs human approval.
Old stock under EmpCo and PPWR runs on different logic. Packaging placed on the market before 12 August 2026 can stay in circulation under PPWR, while EmpCo has no grandfathering for claims. A product can be fine on packaging and still non-compliant on its product page. Track placing-on-market dates and claim versions separately.
Marketplace sync delays create short windows of non-compliance after every change. If an authority asks for removal within two working days, a nightly batch feed is cutting it close. Event-based updates for safety-critical fields reduce that gap.
Ownership is the last trade-off. Central compliance teams want control, and category managers want speed. A workflow that requires approval only for safety and claim fields, and leaves the rest open, usually keeps both sides working.