KodDeltaGuides

Selling into the EU: the product data your systems now have to produce

~12 min read

Four EU regimes now demand data most manufacturers hold only on paper: CBAM entered its definitive phase on 1 January 2026, GPSR has required an EU-based responsible person since December 2024, digital product passports begin with batteries in February 2027, and ViDA e-invoicing follows in 2030. All four need traceable, product-level records.

Türkiye sends about 42.7% of its exported goods to the EU, with EU imports from Türkiye reaching €103.3 billion in 2025 — a customs union relationship where motor vehicles, machinery and electrical equipment lead in both directions. For any manufacturer in that flow, a set of EU regulations arriving between 2024 and 2030 changes what a shipment has to be accompanied by.

None of them are software regulations. All of them are, in practice, data problems. This guide covers what each one demands and what it means for the systems you run.

The four regimes and their dates

RegimeWhat it demandsKey datesWho is legally on the hook
CBAMVerified embedded emissions per productDefinitive phase from 1 Jan 2026; first declaration 30 Sep 2027EU importer (data comes from you)
GPSREU responsible person + technical file and traceabilityIn force since 13 Dec 2024Manufacturer, via an EU-based representative
Digital product passport (ESPR)Machine-readable lifecycle and material dataBatteries from 18 Feb 2027; other categories by delegated actWhoever places the product on the market
ViDA digital reportingStructured e-invoicing and near-real-time reportingPillar 1 go-live 1 Jul 2030; full alignment 2035EU-established suppliers and customers

CBAM: the one that is live now

The Carbon Border Adjustment Mechanism moved from its transitional reporting phase into its definitive phase on 1 January 2026, which is when financial obligations begin alongside reporting. Reporting became an annual declaration, reported emissions must be verified, and 2026 imports create certificate cost exposure. Certificate sales open 1 February 2027 and the first surrender deadline is 30 September 2027. Importers below 50 tonnes of net annual imports of covered goods are fully exempt.

Covered sectors are cement, iron and steel, aluminium, fertilisers, electricity and hydrogen, plus selected precursors. If you are outside those, you are outside CBAM — for now.

The obligation is legally the importer’s. Commercially it is yours, because an importer facing a certificate bill will ask you for installation-level and product-level emissions data, and will prefer suppliers who can produce it. The practical requirement is that you can attribute energy and process emissions to a production run, and that production run to a shipment. That is a traceability question, and traceability is a systems question.

GPSR: the quiet one that already bites

Under Regulation (EU) 2023/988, from 13 December 2024 a consumer product sold into the EU must have a responsible economic operator established in the EU when the manufacturer is not. That party is the authorities’ contact point and must be able to supply technical documentation and traceability information on request.

The failure mode here is mundane and expensive. A market surveillance authority asks about a specific unit. You need to identify its batch, its materials, its test records and its supplier declarations, quickly. If that chain lives across an ERP, a quality spreadsheet and a folder of supplier PDFs, the answer takes days and looks like it took days.

Digital product passports: the one to design for now

Batteries lead. From 18 February 2027, industrial and EV batteries above 2 kWh placed on the EU market need a battery passport. Other categories follow through delegated acts under the Ecodesign for Sustainable Products Regulation; textiles are currently expected to apply around 2029 following a delegated act late in 2027.

Whatever your category, the shape is already visible: a QR code or similar carrier on the physical product, resolving to verified data about composition, footprint, repairability and end-of-life handling — data that must be attributable to that specific unit or batch, not to the product line in general.

ViDA: distant, but it sets the direction

The VAT in the Digital Age package was formally adopted on 11 March 2025 and entered into force on 14 April 2025, with Pillar 1 digital reporting requirements going live on 1 July 2030 and full harmonisation to the EN 16931 standard by 2035.

2030 is far away. The direction is not: structured, machine-readable invoices exchanged over networks rather than PDFs attached to email. Every system decision you take between now and then should assume that endpoint.

What all four have in common

Read the four together and one requirement appears in all of them: an unbroken, exportable chain from a shipment back to a batch, back to materials and suppliers, back to the documents that evidence each link.

That is one capability, not four. Built once, it answers CBAM’s emissions attribution, GPSR’s traceability request, a product passport’s data feed and, eventually, a structured invoice’s line-level detail.

Which is why the correct response to four regulations is not four compliance tools.

A readiness checklist

Work through this in order. Most of it costs nothing but attention.

  1. Determine which regimes apply. Your CN codes against CBAM’s covered goods. Whether your products are consumer products under GPSR. Whether your category has an ESPR delegated act with a date. Write the answer down with the reasoning.
  2. Map the chain you have. For one representative product, trace an actual shipment back to batch, materials, supplier declarations and test records. Time it. The time is your baseline.
  3. Find the breaks. They are almost always the same places: the point where paper enters the process, the point where a spreadsheet joins two systems, and the point where a supplier document sits in someone’s email.
  4. Fix the identifiers first. One batch identifier, generated once, carried through production, quality, stock and dispatch. Most traceability failures are identifier failures, and this fix is unglamorous and high-value.
  5. Capture supplier declarations at source. A portal where suppliers upload declarations against a purchase order beats chasing PDFs. Missing supplier data is the most common blocker on both CBAM and product passports.
  6. Make emissions attribution possible if CBAM applies. Energy and process data linked to production runs, not to monthly totals.
  7. Build the output, not just the record. The deliverable is a document pack or structured export an importer or authority can consume — not a screen someone screenshots.
  8. Assume the requirements will tighten. Store more granularly than you currently need. Aggregation is easy later; disaggregation is impossible.

What this looks like as a software project

In our experience the work divides into three increments, each independently useful:

  • Traceability chain. One batch identifier carried end to end, with a screen that resolves a shipment to everything behind it. This is the foundation, and on our bands a single focused module of this kind runs $3,000–6,000 over 2–4 weeks with a prototype in the first two weeks.
  • Supplier declaration capture. A portal where suppliers submit documents and data against orders, with expiry tracking so a lapsed certificate is visible before a shipment, not after. Often built as part of a dealer or supplier portal.
  • Export document generation. Pulling from the two above to produce the packs and structured exports each destination requires, so the same data is never re-entered.

A multi-department version covering all three runs $8,000–15,000 over 4–8 weeks on our published bands, with the full table on the pricing page.

Who owns this internally

Compliance data work fails for an organisational reason more often than a technical one: it sits between quality, production, purchasing, logistics and finance, and therefore belongs to nobody.

A workable allocation:

  • One named owner for the overall obligation, senior enough to require data from other departments. Usually quality or operations, rarely IT.
  • Purchasing owns supplier declarations, because they own the supplier relationship and the leverage. Chasing certificates is a procurement activity, not an administrative one.
  • Production owns batch integrity. If the batch identifier breaks anywhere on the floor, no downstream system can repair it.
  • Logistics owns the shipment-to-batch link, which is where traceability chains most often snap.
  • IT owns the plumbing, and only the plumbing.

Write this down before the project starts. The alternative — a system that technically captures everything while nobody is accountable for whether the data is entered — is the most common outcome and the most expensive, because it produces confidence without evidence.

What good evidence actually looks like

Regulators and customers do not ask for a system. They ask a question and expect an answer with documentation behind it. Three tests will tell you where you stand:

The recall test. Pick a shipment from four months ago. Identify every batch in it, every raw material lot in those batches, and the supplier declaration covering each lot. Time it. Under an hour is good. Over a day means you would be answering a market surveillance enquiry under GPSR by hand, at speed, under pressure.

The certificate expiry test. Take ten supplier declarations at random. How many are still valid? How would you have known if one had lapsed? Most companies discover the answer is “when a customer asked”, which is the worst possible moment.

The attribution test. If CBAM applies, take one product and attribute its embedded emissions to a production run rather than to a monthly average. Monthly averages will not survive verification.

Each test costs an afternoon and produces a more honest readiness assessment than any gap analysis document.

One caution

Compliance software has a way of becoming a parallel system that duplicates your ERP badly. The test for any proposal is whether it reads from the systems you already run or asks people to type things twice. If it asks for double entry, it will be abandoned within a year and you will be non-compliant with a licence still running.

More on the export manufacturer scenario is on the export manufacturers page, the integration approach on the integrations page, the manufacturing scope on the manufacturing page, and a specific requirement can be scoped through the quote form.

Frequently asked questions

Does CBAM apply to me as a non-EU manufacturer?

The legal obligation sits with the EU importer, who must report, buy and surrender certificates. In practice it lands on you, because the importer cannot report embedded emissions they do not have. Expect requests for verified installation-level and product-level emissions data — and expect that inability to supply it will start affecting who gets orders.

When are the first CBAM financial obligations due?

The definitive phase began on 1 January 2026, so 2026 imports create certificate exposure. Certificate sales open from 1 February 2027, and the first declaration and surrender deadline for 2026 emissions is 30 September 2027. Importers whose total annual net imports of covered goods stay below 50 tonnes are fully exempt.

What is GPSR and does it affect exporters?

The General Product Safety Regulation (EU) 2023/988. Since 13 December 2024, consumer products placed on the EU market must have a responsible economic operator established in the EU when the manufacturer is outside it. That party is the contact point for authorities and needs access to technical documentation and traceability records on demand — which means your systems have to be able to produce them.

When do digital product passports start?

Batteries first: from 18 February 2027, industrial and EV batteries above 2 kWh sold in the EU require a battery passport. Other categories follow through delegated acts under ESPR, with textiles expected around 2029. The common requirement is a machine-readable link from a physical product to verified lifecycle data.

Do I need new software, or can I extend what I have?

Usually extend. The requirement is a traceable link from order to batch to material to document, and most companies already hold the pieces across an ERP, a quality spreadsheet and a supplier folder. The work is connecting them and making the output exportable, not replacing the systems that hold them.

How long does compliance data work take to build?

On our published bands, a single focused module — a traceability chain or a document pack generator — runs 2–4 weeks with a prototype in the first two weeks. A multi-department system covering production records, supplier declarations and export documentation runs 4–8 weeks.

Related guides

Service page: Integration service

Let's talk about what you need.

The 30-minute discovery call is free and carries no commitment.