Menu

DPP Grid guide

GPSR Ecommerce Requirements for Fashion Brands in the EU

TL;DR: - GPSR requires all non-food fashion products sold in the EU to meet strict safety, traceability, and documentation standards. Online listings must display manufacturer details, product identifiers, and local safety warnings, with marketplaces responsible for swift removal of dangerous items. Digital Product Passports help brands organize evidence, ensure compliance, and communicate safety information…

By DPP Grid Editorial reviewed by DPP Grid editorial review published 2026-07-24 Updated 2026-07-24

Overview

Decorative title card illustration with sewing and fabric elements


TL;DR:

  • GPSR requires all non-food fashion products sold in the EU to meet strict safety, traceability, and documentation standards. Online listings must display manufacturer details, product identifiers, and local safety warnings, with marketplaces responsible for swift removal of dangerous items. Digital Product Passports help brands organize evidence, ensure compliance, and communicate safety information through QR codes and centralized data management.

What GPSR ecommerce requirements mean for your fashion listings

Regulation (EU) 2023/988, the General Product Safety Regulation, became enforceable on 13 December 2024. Every non-food consumer product sold to EU buyers, including every garment, accessory, and textile you list online, must now meet its requirements. This is not a soft transition. The regulation applies regardless of where your business is registered.

The core GPSR ecommerce requirements for fashion sellers break down like this:

  • Only safe products may be listed. Article 5 prohibits placing any unsafe product on the EU market, online or offline.
  • Manufacturer contact details must appear on every listing. Name, postal address, and electronic address are mandatory. If the manufacturer is outside the EU, details of a responsible person based in the EU must appear instead.
  • Product identification is required. Each listing must carry a clear product identifier such as a model, batch, or serial number.
  • Safety warnings must be in a language easily understood by the buyer. Warnings should be localized according to the target market's language requirements.
  • Marketplaces carry enforcement duties. Platforms must remove dangerous product listings within two working days of receiving an order from a market surveillance authority.
  • Physical traceability is mandatory. Manufacturer and contact details must appear on the product or its packaging, not just in the digital listing.

67% of EU Safety Gate notifications in 2022 concerned dangerous products from outside the EU single market. This highlighted the need for strict economic operator requirements in the GPSR.


Table of Contents

The GPSR places the heaviest documentation burden on manufacturers, but importers and distributors carry real liability too.

Woman reviewing product risk assessment documents

Manufacturers must run an internal risk assessment before any product goes on sale, compile a technical file, and retain that documentation for an extended period after the product is placed on the market. The risk assessment must consider the product's characteristics, its effect on other products, labeling, and risks to vulnerable consumers including children.

Importers cannot assume the overseas factory handled compliance. You must verify that the risk assessment exists, that labeling and documentation are in order, and that your own details are added to the product or packaging. If you place a product on the EU market under your own brand or trademark, GPSR treats you as the manufacturer, and the full manufacturer obligations fall on you.

Distributors must check that the product carries the required traceability and contact information before passing it on.

Consumer rights under GPSR are also explicit. Buyers must be able to report safety concerns through a visible contact channel. Recall notices must offer consumers a choice of remedies such as repair, replacement, or refund. Language that minimizes risk, including words like "voluntary" or "precautionary," is prohibited in recall communications.


What online marketplaces are required to do under GPSR

If you sell through a third-party platform, or if you operate a marketplace yourself, GPSR creates specific obligations that go well beyond passive hosting.

Osborne Clarke's analysis of the regulation identifies the key duties:

  • Interface design. Marketplace platforms must be built to enable traders to display full product information. If the interface makes it structurally difficult to show manufacturer details or safety warnings, that is a compliance failure on the platform's part.
  • Single EU contact point. Every marketplace must designate one contact for direct communication with market surveillance authorities and a separate contact for consumers.
  • Trader suspension. Platforms that repeatedly fail to provide compliant listings must have their services suspended by the marketplace.
  • Safety Gate integration. Marketplaces must register with the EU Safety Gate portal and act on notifications of dangerous products.
  • Data access for authorities. Market surveillance authorities can request access to scrape data from a marketplace's interface for product safety purposes.
  • Two-working-day compliance window. Orders from authorities to remove content, disable access, or display warnings must be acted on within two working days.

Liability does not transfer to the platform. If you are the importer or economic operator, your obligations remain even when you sell through a third-party marketplace.


Ongoing compliance is a process, not a one-time task

GPSR compliance does not end at product launch. Legal analysis from Taylor Wessing and Osborne Clarke is consistent on this point: the regulation requires active, documented risk management throughout a product's commercial life.

Your technical file is a living document. Any change to materials, manufacturing location, or product design requires an updated risk assessment. Market surveillance authorities now have expanded powers, including the ability to conduct purchases under a covered identity and to scrape listing data, so gaps in documentation are more likely to be found.

GPSR also intersects with other EU regulations that affect fashion products. REACH (Regulation (EC) No 1907/2006) restricts hazardous chemicals in textiles and accessories. CLP (Regulation (EC) No 1272/2008) governs classification, labeling, and packaging of chemical substances used in production. A product that passes a GPSR risk assessment but contains restricted substances under REACH is still non-compliant. Your documentation should address both.

Pro Tip: Set a calendar review for every active product line at least once per year. Any supplier change, material substitution, or new market entry should trigger an immediate documentation update, not a year-end catch-up.


How Digital Product Passports support GPSR conformity

Digital Product Passports (DPPs) are structured product records that store and publish the information GPSR requires, in a format that is accessible to consumers, authorities, and supply chain partners.

A well-built DPP covers manufacturer identity, economic operator details, material composition, manufacturing locations, safety information, care instructions, and supporting evidence documents. That is precisely the data set GPSR demands, and a DPP makes it retrievable on request rather than buried in a shared drive. For the 10-year documentation requirement, a permanent, versioned digital record is far more defensible than a folder of PDFs.

QR codes on products or packaging give consumers direct access to safety information at the point of use, not just at the point of purchase. That matters for recall situations: if a safety issue emerges after sale, a brand with DPPs can push updated safety notices to every product already in the field.

DDP Grid's platform lets fashion brands import products from Shopify, CSV, or API, collect supplier data, upload evidence documents, and publish product passport pages with QR codes. AI assists with data extraction, but human reviewers approve information before it is published.

Pro Tip: Start building your DPPs before a compliance deadline forces it. Early implementation surfaces supplier data gaps you would rather find now than during a market surveillance audit.


How to report an unsafe product under GPSR

When you discover or suspect a product you have placed on the EU market is unsafe, GPSR sets out a clear sequence of required actions.

First, stop making the product available. Pull the listing and halt any pending shipments. Second, notify the relevant market surveillance authority in each EU member state where the product has been sold. The primary channel for this is the EU Safety Business Gateway, the business-facing side of the Safety Gate system. Third, inform consumers who have already purchased the product, clearly describing the risk and the remedy available to them.

Recall notices must be written in plain language, state the specific risk without minimizing it, and offer a concrete remedy. Avoid vague language about "out of an abundance of caution." The regulation is explicit: consumers are entitled to repair, replacement, or refund, and the communication must make that clear.


Best practices for evidence management and documentation

The 10-year retention requirement is the one most fashion brands underestimate. A technical file that cannot be produced on request is legally equivalent to no file at all.

Treat each product model as its own documentation unit. The file should include the risk assessment, test reports or justification for the level of testing conducted, supplier declarations, labeling samples, and a record of any changes made after launch. Version control matters: if a material supplier changes mid-season, the file needs to show what changed, when, and what assessment was done.

Store documents in a system that is accessible to your compliance team and auditable. Spreadsheets and email threads do not meet that standard in practice. A centralized platform with version history, access logs, and the ability to attach supporting evidence to specific product records is the practical minimum for a brand managing more than a handful of SKUs.


GPSR compliance by product category in fashion ecommerce

GPSR applies to all fashion products, but the risk profile and documentation depth vary by category.

Infographic showing GPSR compliance by fashion product categories

Childrenswear carries the highest scrutiny. Products for children must explicitly address risks to vulnerable consumers in the risk assessment, including choking hazards from buttons or drawstrings and flammability of fabrics.

Accessories with metal components, including jewelry, belts, and hardware on bags, intersect with REACH restrictions on nickel release and other restricted substances. The risk assessment must address chemical as well as physical hazards.

Footwear requires attention to slip resistance, material safety, and, for footwear with functional components, any mechanical risks.

Adult apparel generally carries a lower risk profile, but flammability, chemical treatments, and care labeling accuracy still require documented assessment. Products marketed with functional claims, such as UV protection or antimicrobial properties, require evidence to support those claims as part of the technical file.


Penalties and enforcement for GPSR non-compliance

GPSR requires member states to set penalties that are "effective, proportionate, and dissuasive." Each EU country sets its own fine levels. Germany and France set significant fines per violation, with additional enforcement measures possible. Enforcement has already begun across the bloc since the December 2024 application date.

Beyond fines, market surveillance authorities can order product withdrawals, require public safety notices, and block websites offering dangerous products. For online sellers, a listing takedown order that must be executed within two working days can disrupt sales faster than any fine.

The regulation has no small-business exemption. A brand shipping a few hundred units per season faces the same baseline obligations as a large retailer.


DDP Grid helps you organize the evidence GPSR requires

Fashion brands selling into Central Europe and the broader EU need product data that is structured, retrievable, and current. That is harder than it sounds when supplier information is scattered across emails, spec sheets, and factory portals.

Dppgrid

DDP Grid gives you a single place to collect supplier data, upload compliance documents, and publish permanent product passport pages with QR codes, without requiring consumers to install an app. For Shopify merchants, product import is direct. For brands managing multiple suppliers across Central Europe, the platform's supplier data collection workflows surface missing information before it becomes an audit problem.

DDP Grid does not provide legal certification and does not claim that using the platform automatically makes a product compliant. What it does provide is the data infrastructure and evidence management that makes demonstrating compliance possible. Start with your GPSR readiness review to see where your product records currently stand.


Key Takeaways

GPSR compliance for fashion ecommerce requires documented risk assessments, physical and digital traceability, localized safety information, and a 10-year technical file for every product on the EU market.

Point Details
Enforcement date GPSR became enforceable on 13 December 2024 for all EU non-food consumer products.
Listing requirements Every online listing must show manufacturer contact details, a product identifier, and safety warnings in the buyer's language.
Documentation retention Technical files and risk assessments must be retained for 10 years after a product is placed on the market.
Marketplace duties Platforms must remove dangerous listings within two working days of a market surveillance authority order.
DDP Grid Centralizes supplier data, evidence documents, and product passport publication to support GPSR documentation requirements.

When did GPSR come into force?

GPSR entered into force on 12 June 2023 and became applicable to businesses from 13 December 2024, replacing the earlier General Product Safety Directive.

Does GPSR apply to fashion brands based outside the EU?

Yes. Any brand targeting EU consumers must comply, regardless of where it is incorporated. Non-EU manufacturers must appoint an EU-based economic operator responsible for the product.

How long must technical documentation be kept under GPSR?

Technical files and risk assessments must be retained for 10 years after the product is placed on the EU market and must be available to market surveillance authorities on request.

What information must appear on an online fashion listing under GPSR?

Each listing must clearly show the manufacturer's name, postal address, and electronic contact details; the EU responsible person's details if the manufacturer is outside the EU; a product identifier such as a model or batch number; and any required safety warnings in the language of the member state where the product is sold.

How does DDP Grid support GPSR compliance for fashion brands?

DDP Grid provides product-data infrastructure for collecting supplier information, uploading compliance documents, and publishing permanent product passport pages with QR codes, supporting the evidence management and traceability requirements that GPSR demands.

This article is operational guidance, not legal advice or certification.