GS1 Global Standards - Supply Chain Traceability and Data Security
Evidence request list. 13 controls, 13 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
GS1: Barcode Symbologies (EAN/UPC, GS1-128, DataMatrix, QR, DataBar) and EU 2D Code Mandate Sunrise 2027
GS1 BARCODE SYMBOLOGIES provide standard machine-readable encoding of GS1 identification keys + AIs. (1) EAN/UPC FAMILY (1D linear barcodes, point-of-sale standard since 1973): EAN-13 (13 digits, global retail + GTIN-13); UPC-A (12 digits, US/Canada retail + GTIN-12); EAN-8 (8 digits, small items + GTIN-8); UPC-E (compressed 8 digits, US small items); ~6 BILLION scanned daily globally at point-of-sale. (2) GS1-128 (Code 128 based, supports AIs + concatenation): used for cartons + cases + pallets + logistics; supports up to 48 characters + multiple AIs. (3) GS1 DATABAR (formerly RSS - Reduced Space Symbology, 1D): compact + supports AIs + variable + fresh foods + small items; multiple sub-types (Omnidirectional + Stacked + Expanded). (4) GS1 DATAMATRIX (2D matrix, ISO/IEC 16022): high data density + supports AIs + GS1 standard 2D format; used for healthcare + pharma + small items + serial
- Barcode selection per use case + symbol grade
- 2D code adoption + Sunrise 2027 readiness
- EU FMD/MDR/DSCSA compliance
- Barcode quality issues
- 2D Sunrise not prepared
- Pharma + medical-device serialization gaps
GS1: Digital Link, EU Digital Product Passport (DPP) per ESPR and 2D Code Web-Resolvable Product Data
GS1 STANDARDS CROSSWALK to international + EU + FDA + ISO/IEC standards. (a) ISO/IEC 19987:2015 EPCIS - ISO international standard for EPCIS v1.1 (current ISO version aligns with EPCIS v1.x; v2.0 anticipates ISO update); GS1 + ISO coordinate; (b) ISO/IEC 19988:2017 CBV - ISO international standard for Core Business Vocabulary; (c) ISO/IEC 16022:2006 DATAMATRIX - 2D matrix barcode symbology; (d) ISO/IEC 18004:2015 QR CODE - 2D matrix barcode symbology; (e) ISO/IEC 15420 EAN/UPC - 1D barcode symbology; (f) ISO/IEC 15438 PDF417 - 2D stacked barcode (legacy use); (g) ISO/IEC 24723 GS1 COMPOSITE - composite barcode symbology; (h) ISO/IEC 24727 IDENTIFICATION CARDS - personal ID card standards; (i) ISO 22526-1/2/3 (Carbon Footprint of Products) - coordination with GS1 + GDSN for product-level reporting; (j) ISO 8601 DATE/TIME - used in EPCIS event time; (k) ISO 4217 CURRENCY - used in commerce
- Multi-standard certification + crosswalk
- EU + FDA + ISO regulatory compliance per sector
- Sectoral coordination evidence
- Multi-standard alignment ad-hoc
- EU + FDA readiness gaps
- Sectoral coordination weak
GS1 DATA SECURITY + INTEGRITY in supply chain data exchange. KEY PRINCIPLES: (1) DATA INTEGRITY - master data + EPCIS events + GDSN exchanges must be ACCURATE + COMPLETE + TIMELY + reflect true state of supply chain; validation rules + check digits + cross-references + audit trails; (2) DATA SECURITY in exchange - TLS 1.2+ + certificate-pinning + mTLS for B2B + EPCIS APIs + GDSN data exchanges; OAuth 2.0 + JWT + API keys for authentication; encryption at rest + in transit; (3) ACCESS CONTROL to traceability data - role-based access (publisher + subscriber + viewer + admin); confidentiality preservation (sensitive supply chain + competitive information); GDPR + privacy compliance for traceability data including personal data (operator name + location + role); (4) MASTER DATA CHANGE CONTROL - change management procedures + version control + approval workflows + audit logs + data lineage; d
- Data security policy + technical controls
- Master data change control + audit
- Tamper evidence per sector
- Barcode quality + ISO grade
- Data security gaps
- Master data integrity issues
- Tamper evidence inadequate
- Barcode quality issues
GS1 DIGITAL LINK is the URI-based extension of GS1 identification keys + AIs enabling web-resolvable product data + connected packaging + IoT integration. STRUCTURE: extends GTIN + AIs into HTTPS URLs (e.g. https://id.gs1.org/01/05012345678900/10/Batch123/21/Serial456) where URL path encodes GTIN + AIs + product owner can register canonical resolver redirecting to various information services (consumer engagement + product info + DPP + warranty + customer service + commerce + after-sales support). RESOLVER SERVICE: GS1-defined resolver service routes requests to appropriate destination based on context (consumer + supply chain + regulator + brand + retailer); GS1 Digital Link Specification v1.3+ (current). RESOURCE TYPES: GS1 Digital Link supports linking to multiple resource types (mco - product info; pip - product instance page; epil - EPCIS link; dpp - digital product passport; ais -
- GS1 Digital Link implementation + resolver service
- EU DPP readiness per sectoral delegated act
- Consumer engagement strategy + content
- Digital Link not adopted
- EU DPP readiness gap
- Consumer engagement limited
GS1: EPCIS (Electronic Product Code Information Services), CBV (Core Business Vocabulary) and Event-Based Data Sharing
GS1 EPCIS (Electronic Product Code Information Services) is the event-based supply chain data exchange standard answering 4 KEY QUESTIONS: WHAT (which products), WHEN (date + time), WHERE (location), WHY (business step + disposition). EPCIS HISTORY: developed by EPCglobal (founded 2003, merged into GS1 2005); EPCIS v1.0 (2007) + v1.1 (2014) + v2.0 (2022); EPCIS is also ISO/IEC 19987:2015 (ISO international standard). EPCIS EVENT TYPES: (a) OBJECT EVENT - state-change of an individual object (e.g. commissioned + manifested + shipped + received + sold + recalled); (b) AGGREGATION EVENT - associations of objects (e.g. case-pallet relationships + parent-child); (c) TRANSACTION EVENT - associates objects with business transactions (orders + invoices + ASNs); (d) TRANSFORMATION EVENT - input-output transformations (e.g. raw materials to finished goods + ingredients to recipe); (e) ASSOCIATION
- EPCIS implementation evidence
- CBV vocabulary adoption
- Trading partner + regulator + consumer access
- EPCIS not implemented
- CBV not standardized
- Trading partner exchange ad-hoc
GS1: GDSN (Global Data Synchronization Network), Master Data, EDI and B2B Data Exchange
GS1 GDSN (Global Data Synchronization Network) is the global B2B network for master-data sharing + synchronization between trading partners. GDSN ARCHITECTURE: (a) GS1 Source - GS1-certified data pools where data publishers + suppliers register + maintain product master data; (b) GS1 Sink - data pools where retailers + buyers access subscribed product data; (c) GDSN MESH - global certified network connecting data pools across MOs + countries; (d) GLOBAL REGISTRY - GS1 Global Registry coordinates global GTIN + GLN uniqueness + cross-pool routing. CERTIFIED DATA POOLS (~30+ globally): 1WorldSync + Atrify + ECC AG + GS1 Mexico + GS1 South Korea + GS1 China + Stibo Systems + Brandbank + Tellium + many more; each meets GS1 certification + interoperability standards. MASTER DATA COVERED: ~5,000+ attributes per GTIN organized in categories including identification + classification + dimensions
- GDSN publisher/subscriber subscription
- Master data attribute completeness
- EDI implementation + compliance
- GDSN not used
- Master data fragmented
- EDI compliance gaps
GS1: Identification Keys (GTIN, GLN, SSCC, GRAI, GIAI, GSRN, GDTI, others) and Application Identifiers (AIs)
GS1 IDENTIFICATION KEYS comprise the foundational unique identifiers covering all supply chain entities. (1) GTIN (Global Trade Item Number) - identifies trade items (products); 4 formats: GTIN-8 (8 digits, small items), GTIN-12 (12 digits, formerly UPC-A, US/Canada), GTIN-13 (13 digits, formerly EAN-13, global), GTIN-14 (14 digits, packaging hierarchy + indicator digit 0-9); each GTIN consists of GS1 Company Prefix + Item Reference + Check Digit; ~5 BILLION GTINs allocated globally. (2) GLN (Global Location Number) - identifies physical + functional + legal entity locations (warehouses + stores + corporate office + sub-locations + departments + bill-to + ship-to); 13-digit format; foundational to logistics + invoicing. (3) SSCC (Serial Shipping Container Code) - identifies logistic units (pallets + cases + containers + roll cages + parcels); 18-digit format; serialized + unique-per-pall
- GS1 keys allocation + catalog
- AI usage + data structure
- Check digit verification + duplicate-detection
- GS1 keys misused
- AIs not used
- Check digit + uniqueness violations
GS1: Organizational Scope, Member Organisations, Prefix Governance and Standards Maintenance
GS1 (Global Standards 1) organizational scope + governance. GS1 GLOBAL OFFICE in Brussels Belgium administers global standards development + maintenance; established 1973 (Uniform Code Council UCC + EAN International) + merged 2005 to form GS1. NETWORK: 116 GS1 MEMBER ORGANISATIONS (MOs) in 150+ countries + 1 Global Office; each MO operates as a not-for-profit + administers GS1 standards + prefix allocation + member services within its national territory. KEY MOs include GS1 US + GS1 UK + GS1 Germany + GS1 France + GS1 Netherlands + GS1 Italy + GS1 Spain + GS1 China + GS1 Japan + GS1 Korea + GS1 India + GS1 Australia + GS1 Brazil + GS1 Mexico + GS1 Argentina + GS1 South Africa + many more. GOVERNANCE: GS1 Management Board + GS1 Global Office staff + GS1 General Assembly (MOs) + technical Working Groups. STANDARDS DEVELOPMENT: through GS1 Standards Management Process (GSMP) involving 200+
- GS1 membership + prefix allocation evidence
- GS1 keys catalog + maintenance
- GSMP participation if applicable
- GS1 membership absent
- Prefix governance unclear
- Standards updates not tracked
GS1: Traceability, Healthcare/Food/Pharma Sectors, EU FMD/MDR/IVDR/TPD, FDA DSCSA/UDI Coordination
GS1 SECTORAL ADOPTION. (a) RETAIL + CONSUMER GOODS - GS1 + GTIN ubiquitous at point-of-sale globally; ~6 billion barcodes scanned daily; ~2 million companies; major retailers (Walmart + Amazon + Costco + Target + Kroger + Tesco + Carrefour + Aldi + Lidl + Mercadona + Loblaws + Sobeys + Metro + Edeka + Real + many more) mandate GS1 GTIN + master data + GDSN; Amazon Marketplace requires GTIN for product listing; e-commerce platforms increasingly mandating GS1 codes. (b) HEALTHCARE - GS1 Healthcare Reference Book + ~16,000 hospitals globally using GS1; EU FMD + MDR + IVDR + FDA DSCSA + UDI; pharma serialization + medical device UDI + medication management + patient safety; major hospital systems (Cleveland Clinic + Mayo Clinic + Johns Hopkins + Kaiser + HCA + NHS + many more) using GS1 for clinical operations + supply chain + recall. (c) PHARMACEUTICAL - EU FMD effective Feb 2019 + FDA DSCS
- Sectoral application evidence
- Major-retailer + regulator compliance
- E-commerce platform compliance
- Sectoral application gaps
- Retailer compliance issues
- E-commerce compliance gaps
GS1 implementation roadmap + organizational roles. ROLES: (a) MASTER DATA MANAGER + DATA STEWARD - day-to-day GS1 keys allocation + master data quality + GDSN data publication + maintenance; (b) SUPPLY CHAIN MANAGER - EPCIS event capture + traceability + recall capability + sectoral compliance; (c) COMPLIANCE + REGULATORY - EU FMD + MDR + IVDR + TPD + DSCSA + UDI + DPP + Food Traceability + sectoral mandates; (d) PACKAGING + ARTWORK - 1D + 2D barcode placement + symbol grade + readability + variable data printing; (e) IT + ENTERPRISE ARCHITECTURE - ERP + MDM + WMS + TMS + barcode + EPCIS + GDSN + Digital Link integration; (f) PROCUREMENT + SUPPLIER MANAGEMENT - supplier master data + GTIN/GLN allocation + GDSN data exchange; (g) MARKETING + CONSUMER ENGAGEMENT - Digital Link + connected packaging + QR codes + consumer info; (h) SUSTAINABILITY + ESG - product carbon footprint + DPP + EPR
- Role inventory + RACI
- Tooling adoption + integration
- Metrics + management review
- Annual cycle documentation
- Roles undefined
- Tooling fragmented
- Metrics gaps
- Annual cycle ad-hoc
GS1 status + 2024-2025 priorities. KEY 2024-2025 INITIATIVES: (a) SUNRISE 2027 - global readiness for 2D barcode acceptance at point-of-sale by 2027; transition from 1D EAN/UPC to 2D DataMatrix/QR with Digital Link; retailer + brand + technology readiness; major retailers (Walmart + Tesco + Carrefour + Aldi + Lidl + Coles + Woolworths) testing/deploying 2D scanners; GS1 publishes Sunrise 2027 guidance + readiness assessments. (b) EU 2D CODE TRANSITION - phased EU mandate for 2D codes on consumer products + EU DPP integration; GS1 + EFRAG + European Commission coordination. (c) EU DIGITAL PRODUCT PASSPORT (DPP) per ESPR - GS1 Digital Link as primary identifier; Battery DPP first (Feb 2027 effective) + Textile + Electronics + Construction + Chemicals + ICT sectoral delegated acts 2026-2030. (d) AI + ML INTEGRATION - GS1 + AI for data quality + image recognition (visual product identificati
- Sunrise 2027 implementation plan
- EU DPP readiness assessment
- AI + sustainability program
- Sectoral expansion + IoT readiness
- Sunrise 2027 not prepared
- EU DPP readiness gap
- Sustainability + carbon footprint not addressed
GS1 ADOPTION STATISTICS + status. GLOBAL ADOPTION: ~2 million member companies + ~5 billion GTINs allocated globally + ~6 billion barcodes scanned daily + 116 GS1 Member Organisations in 150+ countries; foundational layer of global commerce + supply chains + e-commerce + healthcare. KEY GROWTH AREAS: (a) E-COMMERCE - Amazon + Alibaba + eBay + global marketplaces driving GTIN adoption; (b) HEALTHCARE - EU FMD + FDA DSCSA + UDI driving pharma + medical device serialization; (c) FOOD TRACEABILITY - FDA Food Traceability Final Rule + EU + global mandates; (d) DIGITAL PRODUCT PASSPORT (EU ESPR) - mandatory DPP for most consumer products 2027-2030; (e) SUSTAINABILITY + ESG - product-level carbon footprint + EPR + CSRD/ESRS; (f) BLOCKCHAIN + DLT - tamper-evident provenance; (g) AI + ML - data quality + visual recognition + supply chain analytics; (h) IoT + SENSORS - cold chain + condition monit
- Adoption tracking + benchmarking
- 2027+ milestone readiness
- SME + sustainability + AI readiness
- Adoption monitoring gaps
- 2027+ readiness lagging
- SME + sustainability + AI gaps
GS1 SUPPLY CHAIN TRACEABILITY + sectoral applications. END-TO-END TRACEABILITY MODEL: GS1 traceability is built on (a) Critical Tracking Events (CTEs) - significant supply chain events (e.g. creation + shipping + receiving + transformation + selling + recall); (b) Key Data Elements (KDEs) - data points captured per CTE (GTIN + lot + serial + date + location + party + quantity); (c) one-up + one-down traceability (each party knows its immediate suppliers + customers) + full chain via EPCIS event sharing; (d) one-step vs full traceability vs lot tracing vs item-level traceability. PHARMA (EU + US): EU FALSIFIED MEDICINES DIRECTIVE (FMD, Directive 2011/62/EU) effective February 2019 - serialised GS1 DataMatrix (GTIN + Serial Number + Batch + Expiry) on pharma packs + verification at point-of-dispense via EU Hub + National Medicines Verification Systems (NMVS); EU eToken + UI (Unique Identif
- Traceability program + CTE/KDE design
- Regulatory compliance per sector
- Mock recall + withdrawal annual tests
- Traceability incomplete
- Regulatory readiness gaps
- Mock recalls not performed
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the GS1 Global Standards - Supply Chain Traceability and Data Security framework page.