Operational notes Regulation

GPSR, general product safety: obligations already in force, the file stays scattered across six systems

7 min read

Black-and-white photograph of five sealed cardboard boxes taped shut, stacked on a wooden shelf against a white brick wall
Every box is sealed and ready for market. No visible label says whether, behind it, the file actually exists.

A typical scenario, not our own case. A company near Modena makes small kitchen appliances, in the manufacturing sector, sold both in shops and on an online marketplace. A consumer reports that a component overheated. The same month, a distributor asks, before renewing the order, for proof that the model is covered by an up-to-date risk analysis and that the company knows, batch by batch, how many units are still in circulation. The quality office holds the complaint. Engineering holds the risk analysis, done two years ago. Neither, alone, can say whether the reported component belongs to the batch already corrected or to an earlier one.

The regulation, the May 2026 update, and when it actually started to apply

Regulation (EU) 2023/988 of the European Parliament and of the Council of 10 May 2023, “on general product safety” — the GPSR — was published in the Official Journal L 135/1 of 23 May 2023. Article 52 sets two distinct clocks: entry into force, “the twentieth day following that of its publication” — so 12 June 2023 — and application: “It shall apply from 13 December 2024.” From that date the regulation repeals Directive 2001/95/EC and replaces, for non-food consumer goods generally, the framework Italian industry had worked with for two decades.

The text has not stood still. Regulation (EU) 2024/2748 of 9 October 2024 inserted a Chapter IIa into the GPSR — emergency procedures and an alternative presumption of conformity for “crisis-relevant goods”, triggered only if the Commission declares the emergency mode under Regulation (EU) 2024/2747 — applying “from 29 May 2026”: less than three months ago. As far as we know it has not been triggered, and it does not touch the ordinary obligations this article covers, but it confirms the text remains under active maintenance.

Where the data actually sits

The regulation does not hand safety to a single office. It spreads it across six systems that, in a typical company, do not talk to each other.

The first is engineering: Article 9(2) requires manufacturers to carry out “an internal risk analysis” plus “a general description of the product and its essential characteristics relevant for assessing its safety”, kept available “for a period of 10 years after the product has been placed on the market” (para. 3).

The second is the production line, where the physical identifier lives: paragraph 5 requires the product to bear “a type, batch or serial number or other element” enabling its identification, “easily visible and legible”. This is the data that later says whether a reported unit belongs to the batch already corrected or an earlier one — but it is born on the shop floor, not in quality.

The third is procurement, governing importers and distributors: Article 11 requires the importer to ensure “that the manufacturer has complied with the requirements set out in Article 9”; Article 12 requires the distributor to verify that both “have complied with the requirements” — a cascading check on a file whoever verifies it has, more often than not, never seen in full.

The fourth is customer service, where the complaint lands: Article 9(12) requires manufacturers to keep “an internal register of those complaints as well as of product recalls and any corrective measures taken”; paragraph 13 caps personal data on the complainant at “no longer than five years after the data have been entered” — shorter than the technical file’s ten years, usually on a different system.

The fifth is legal or compliance, pushing the information outward. Where a product already on the market turns out dangerous, the manufacturer must immediately “inform, through the Safety Business Gateway, the market surveillance authorities” (Art. 9(8)); Article 20 imposes the same notification “without undue delay” for any accident resulting in “serious adverse effects on that individual’s health and safety, permanent or temporary”. The Safety Business Gateway is a Commission portal, not an ERP module: whoever fills it in has to go and find the data elsewhere.

The sixth, when the product is also sold online, is the e-commerce channel: Article 22 requires online marketplace providers to designate “a single point of contact” for the authorities, to “register with the Safety Gate Portal”, and to have “internal processes for product safety in place” — a system the manufacturer, often, does not control at all.

The same pattern — a proof the law demands, scattered across offices with no reason to share that data — recurs in the technical documentation under the Machinery Regulation and in the cascading supplier checks under CSDDD.

The data no company system holds in full

What is almost always missing is not a single data point: it is the chain that holds them together. A batch number born in production, a complaint logged by customer service, a corrective measure decided by quality, a notification sent by legal — no system, as a rule, links these events to the same object across its whole life. The ERP knows how many units of a batch shipped, not whether a complaint is pending on it. The CRM knows about the complaint, not whether it has already been notified to the authorities. The Commission’s portal records the notification but talks to neither of the others. It is the same pattern already told for the battery passport and for medicine traceability: the data is not missing outright, what is missing is putting it back together.

If tomorrow morning a surveillance authority, or simply a lead customer before renewing an order, asked you to reconstruct that chain for a single batch — from the risk analysis to any notification sent — how many of these six systems would you have to open, and how long would it take to be certain the numbers match?

See the service · Talk to an engineer

What we do not know

We are not offering legal advice on which products fall outside the GPSR’s scope: Article 2 excludes medicines, food, feed, live plants and animals, genetically modified organisms, animal by-products, plant protection products, aircraft and antiques; for products already covered by sector-specific harmonised legislation (machinery, toys, appliances with their own CE marking regime) the regulation “applies only to those aspects and risks or categories of risks which are not covered by those requirements” — an overlap read case by case. On penalties, Article 44 leaves it to Member States to set “rules on penalties”, “effective, proportionate and dissuasive”, notified to the Commission “by 13 December 2024”: the regulation itself sets no figure. In the EUR-Lex database of national measures we found no Italian measure notified for the GPSR: we have not independently verified whether Italian authorities rely on the existing Consumer Code penalty regime or on a more recent measure we did not find. The scenario at the top is a typical model, stated as such: it does not describe the internal workings of any real company.

The two axes, applied

Compliance. The risk analysis, the complaints register and the notifications to authorities become, in our system, a check that runs on the client’s documents and systems — technical file, quality register, production traceability — with an alert when complaints build up against a flagged batch, or a technical file goes unupdated for years. An exportable, dated file, ready for the surveillance authority or the customer who asks before renewing an order.

Decisions. The same system holds engineering, production, procurement, customer service, legal and e-commerce together in a single operating model, on which AI agents execute decisions with a human operator in command: not just answering when an inspection arrives, but knowing in advance which batch has an open complaint. For large manufacturers, defence, government and healthcare, always in two modes: on-premises, on self-contained machines with no deep integration into the client’s network, or a dedicated cloud with a dedicated VPN and a data centre in Italy — always with shared management.

From the first session, at no cost, comes a dated map of which pieces of the GPSR file are already in place, which system holds them and who keeps them updated — including the boxes still empty. It stays yours even if we do not go on to work together. Talk to one of our engineers.

Sources