How Product Data Moves Through the Supply Chain
Executive Summary
The previous articles in this pillar each explained one piece of the machinery. GS1 provides the global identification system. A GTIN names a trade item. A data carrier delivers that value to a reader. GS1 Digital Link turns the identifier into a web address that can lead to different services for different audiences. EPCIS records what happened to identified objects. Each is coherent on its own.
What none of them explains alone is the thing organisations actually need: how trusted product information travels alongside a physical product from raw material extraction through to recycling, crossing a dozen organisations that share no systems and often no commercial interest.
This article is the capstone of the pillar. It sets out The Trusted Product Data Flow Model, a ten stage picture of the complete product lifecycle, and shows at each stage which standard operates, what information is created, who consumes it, and where the Digital Product Passport fits.
The single most important idea is a separation that most failed programmes collapse. Product identity, product data, business event data, enterprise master data and passports are five different things with five different owners and lifespans. Identity names the thing. Master data describes it. Events record what happened to it. A resolver connects a scan to a service. A passport presents governed information to a defined audience. Enterprise systems remain the systems of record throughout; nothing in this article moves the source of truth out of them.
- Product data does not travel inside the product; it travels by reference, anchored to a persistent identifier. - GTIN identifies products; GS1 Digital Link connects them to digital services; EPCIS records business events; passports expose governed lifecycle information. - Enterprise systems remain the systems of record throughout the flow. - The Trusted Product Data Flow Model describes ten stages from raw materials to recycling, as a loop rather than a line. - Identity is created once and reused; data is created continuously by many parties. - Trading partner exchange works only where identifiers, locations and vocabularies are shared. - Most supply chain data problems are identity problems discovered late. - A passport is a presentation layer over data that already exists, not a new place to store it.
This is the ninth article in the Standards & Technology pillar and the nineteenth in the tieback Knowledge learning path. It assumes the material in What is EPCIS?.
Follows product data from supplier to consumer and identifies where trust is created and where it is lost.
Table of Contents
- Definition
- Why Product Data Must Move With Products
- The Trusted Product Data Flow Model
- Creating Product Identity
- Capturing Business Events
- Sharing Product Information
- Product Data Across Enterprise Systems
- Product Data Across Trading Partners
- Digital Product Passports Within the Supply Chain
- Following One Product End to End
- Benefits for Manufacturers
- Benefits for Logistics Providers
- Benefits for Retailers
- Benefits for Regulators
- Benefits for Consumers
- Common Misconceptions
- Frequently Asked Questions
- Key Takeaways
- Related Articles
- Related Glossary Terms
- References
- About This Article
Definition
Product data flow is the movement of trusted information about a product across organisations and across time, anchored to a persistent product identifier. The information itself stays in the systems that own it; what travels is the identifier, together with agreed means of resolving it to services and of exchanging events about it.
Five categories are used throughout this article and are worth fixing before going further, because almost every disagreement in a supply chain data programme turns out to be a category error.
Identity names it, master data describes it, events record what happened to it, a resolver leads you to it, and a passport presents the part of it that a given audience is entitled to see.
Why Product Data Must Move With Products
A physical product carries almost no information. It carries a mark, and the mark carries a number. Everything else that anyone might want to know about it lives somewhere else, usually in systems belonging to organisations the current holder has never dealt with.
That is not a defect to be engineered away. Copying a product’s full information into a label, a chip or a file that travels with the goods fails for four reasons that recur in every industry.
Information changes after despatch. Safety notices, corrected specifications, revised care instructions and updated conformity documents arrive after the product has left. Anything printed or embedded at manufacture is frozen at the moment it was least complete.
Different audiences are entitled to different things. A customs officer, a recycler, a repairer and a consumer need different subsets, and some of those subsets are commercially confidential. A single travelling payload cannot express entitlement.
Volume is impractical. Full material declarations, test reports and component records are megabytes of structured data. They do not belong on a label.
Trust needs a source. A file that travels with goods can be altered. A reference that resolves to a governed system can be verified against the organisation accountable for it.
So the workable pattern is the opposite of intuition: the product carries a reference, and the information stays with the parties who own and maintain it. This is what makes identification the foundation of everything else rather than a labelling detail.
Programmes routinely begin by designing a spreadsheet or message payload to send downstream. That work is not wasted, but it addresses the smallest part of the problem. The hard parts are agreeing identifiers, agreeing locations, agreeing vocabulary and agreeing who is accountable for each assertion. Formats are the easy last mile.
The Trusted Product Data Flow Model
The model below traces one product through ten stages, from the extraction of its raw materials to the recovery of its materials at end of life. At each stage it names the data created, the standards operating and the systems involved.
Three conventions apply throughout. The identifier is constant wherever the physical object is constant. Data is created by whoever observed it, not by whoever wants it. And the flow is a loop: the last stage feeds the first stage of another product.
Materials are extracted, grown or recovered. Identity here belongs to lots and consignments rather than to trade items. Origin, certification and due diligence evidence are created by suppliers and held in their own systems.
Components and materials are consumed and a finished item comes into being. This is the moment recycled content, composition and origin claims become substantiable, because the link between inputs and outputs exists only if it is recorded here.
The item is allocated its keys: a GTIN for the trade item, a batch or lot where required, a serial number where unit level identity is needed. Every later record in the entire flow refers back to these values.
The identifier is encoded into a data carrier and applied to the item or its packaging. Where the carrier holds a Digital Link web address, the item becomes resolvable. Units are packed into cases and cases onto pallets, and those relationships are recorded.
Goods move between carriers, ports, customs and warehouses. Each handover produces paired shipping and receiving events written independently by two organisations, which is what makes chain of custody evidence rather than assertion.
The item is received, put on sale and eventually sold. The same identifier that ran through production now drives the till, the online listing and, increasingly, the consumer facing information the retailer is obliged to make available.
The holder scans the carrier and is resolved to information appropriate to them: care, safety, composition, warranty, safety notices. This is where the passport does its work, and where the flow first touches someone with no commercial relationship to the chain.
Independent repairers and service networks need spare part references, disassembly guidance and service history. Repairs performed are themselves events, and where they are recorded the product’s history survives its first owner.
Resale, refurbishment and remanufacture depend on being able to establish what an item is and what has happened to it. A verifiable history is what separates a secondhand market from a market in unverifiable claims.
The item is collected, sorted, dismantled or reprocessed. Recyclers need composition, hazardous substance and disassembly information, and the recovery itself is a transformation whose outputs feed stage one of the next product.
The loop closes: the outputs of stage ten are the inputs of stage one for another product. Every stage adds data; none of them replaces the identity assigned at stage three.
Two properties of the model are worth stating explicitly, because they determine how a programme should be scoped.
No single organisation sees the whole flow. A manufacturer sees stages one to five and glimpses of eight. A retailer sees five to seven. A recycler sees ten and almost nothing before it. The model is a map of a shared system, not of anyone’s internal process.
Data density is uneven. Stages two to six are data rich because commerce requires it. Stages seven to ten have historically been near silent, and that silence is precisely what durability, reparability and circularity obligations are designed to end.
Identify the stages where you are accountable, the stages where you are asked for evidence, and the counterparties who sit immediately either side of you. Deliver those first. Programmes that attempt the full loop before securing stages three and four produce elaborate architecture on top of unreliable identity.
Creating Product Identity
Identity is created once and consumed forever, which makes it the highest leverage and least reversible decision in the flow.
The trade item level. A GTIN identifies a product as a commercial offering: this model, this configuration, this pack size. Two units that a buyer would consider interchangeable share a GTIN. Anything that changes what the buyer receives requires a new one.
The batch or lot level. A batch qualifies a GTIN with a production grouping. It is what makes a recall proportionate: withdrawing the affected production run rather than the product line.
The unit level. A serial number qualifies a GTIN down to an individual item. It is required wherever the history of the individual matters: warranty, high value goods, regulated equipment, resale.
The location and party level. Locations and parties need identifiers too. Events that say “received at the warehouse” are useless across organisations unless the warehouse has a globally unambiguous identifier.
A jacket model sold in size M navy has one GTIN. A production run of 4,000 units made in March carries a batch code. Individual units destined for a market requiring unit level passports additionally carry serial numbers. All three levels coexist in the same encoded carrier, and each answers a different question.
Whether to serialise is treated as a technical detail and deferred. It is not: it determines carrier capacity, print infrastructure, event volume, storage and the granularity of every claim the product can support. Retrofitting serialisation after launch means reprinting, re-labelling and a permanent discontinuity in the record.
Capturing Business Events
Identity says which thing. Events say what happened to it. The mechanics belong to EPCIS; what matters here is where events arise in the flow and who writes them.
Three rules make event capture usable rather than merely voluminous.
Capture at the point of observation. An event written by the party who saw it, at the moment it happened, is evidence. The same fact reconstructed later from paperwork is an opinion.
Never edit an event. Corrections are new events. An audit trail that can be rewritten is not an audit trail, and regulators evaluate the posture as much as the content.
Use shared vocabulary. Two organisations exchanging perfectly structured events with private codes have achieved integration without interoperability.
The useful measure is not how many events are captured but how many obligations and operational questions they answer. Most chains need a small number of event types captured reliably far more than they need comprehensive capture done inconsistently.
Sharing Product Information
Once identity exists and events accumulate, the remaining question is how anyone reaches the information. Three distinct mechanisms operate, and they are frequently confused.
Resolution. A carrier encoding a Digital Link web address means that scanning the product leads somewhere without the scanner needing to know anything in advance. The resolver decides, per requester, which service is appropriate: a passport for a consumer, a specification for a repairer, a certificate for an authority. See What is GS1 Digital Link?.
Master data exchange. Structured product attributes flow between trading partners through established data synchronisation channels, so that a retailer’s listing matches the brand owner’s record. This is descriptive data, not history.
Event query. A counterparty with an entitlement asks a repository for events relating to identifiers it has a legitimate interest in. This is governed and bilateral, never public.
GTIN identifies products. GS1 Digital Link connects products to digital services. EPCIS records business events. Digital Product Passports expose trusted lifecycle information to defined audiences. Enterprise systems remain the systems of record for all of it.
Product Data Across Enterprise Systems
Nothing in this model displaces enterprise systems. It gives them a shared language.
PLM holds design, specification, bill of materials and component data. It is the origin of most composition and material information that later appears in a passport.
ERP runs procurement, production orders, inventory and finance. It typically owns the authoritative commercial view of a product and its supply.
MES and shop floor systems observe what actually happened during production, which is where transformation events originate.
WMS and TMS observe handling and movement, which is where most object and aggregation events originate.
QMS and compliance systems hold test results, certificates and declarations of conformity.
MDM or product data platforms reconcile these into a governed product record fit for publication.
The pattern that works is deliberately conservative: systems of record keep their records, a governed layer assembles the subset that must be exposed, and publication happens from that layer. The anti-pattern is a passport or portal that becomes a second place where product attributes are authored, immediately diverging from the systems that run the business.
Because a passport is the visible artefact, it attracts data entry. Within a year the passport contains attributes that exist nowhere else, maintained by whoever happened to be available. The publication layer must read from governed sources and add presentation, versioning and access control, not become an authoring tool of last resort.
Product Data Across Trading Partners
Between organisations, only four things need to be agreed for data to flow. They are also, reliably, the four things nobody agrees early enough.
Identifiers. Both parties must refer to the same product with the same key, at the same level of granularity. Most reconciliation failures are granularity mismatches: one party working at trade item level, the other at unit level.
Locations and parties. Events are only comparable if places and organisations are named with identifiers both sides recognise.
Vocabulary. Business steps and states must come from a shared vocabulary rather than local system codes.
Entitlement. Who may see what, for how long, and for what purpose. Event data reveals volumes, partners and timing, and is commercially sensitive in every industry.
A retailer books in 480 units against a despatch note for 500. With commercial documents alone, this is a dispute between two records. With shared events, the pallet was aggregated with 500 children, shipped intact, disaggregated at a cross dock and reaggregated with 480. The place and time of the loss are in the record, written by the party who was there.
Confirm, per data flow, whether exchange is at trade item, batch or unit level, and what happens when one side has finer granularity than the other. This single agreement prevents the majority of downstream reconciliation work.
Digital Product Passports Within the Supply Chain
A passport sits at the end of the data flow, not at the centre of it. It is a governed presentation of information that already exists, addressed to audiences who are outside the commercial chain.
Four characteristics follow from that position.
It is audience aware. Consumers, repairers, recyclers and authorities receive different views of the same product. A single public dump satisfies nobody and exposes more than any regulation asks.
It is derived. Passport content summarises: a recycled content percentage, a compliance status, a country of origin. It does not publish the underlying event stream that substantiates it.
It is a point in time publication. Where a passport is published as an immutable snapshot, later events do not silently rewrite what a consumer already saw; new evidence justifies a new publication.
It depends on everything upstream. A passport can only present what identity, master data and events have made available. This is why passport programmes so often surface as data programmes within a few weeks of starting.
The obligation itself comes from regulation rather than from the standards. The Ecodesign for Sustainable Products Regulation establishes the passport framework and leaves product specific requirements to delegated acts, while the batteries regulation sets out its own passport requirements on an earlier timetable. See What is the Ecodesign for Sustainable Products Regulation (ESPR)? for the framework and What Are Delegated Acts? for how requirements become binding.
Following One Product End to End
The abstraction becomes concrete when a single item is followed. Consider a domestic appliance manufactured in the European Union, sold in another member state, repaired once and eventually recycled.
Manufacture. Components arrive with their own lot identities and supplier documentation. Assembly consumes them and produces a finished unit. A transformation event links inputs to output, which is what later allows a recycled content statement to be substantiated rather than asserted. PLM holds the bill of materials; MES observes the build.
Identification. The unit is allocated a GTIN for its model and configuration, a batch code for its production run and a serial number because warranty and passport obligations require unit level identity. These values will appear in every subsequent record about this appliance.
Packaging. A carrier encoding a Digital Link web address, together with the batch and serial, is applied. The unit is packed into a carton, cartons onto a pallet, and those aggregations are recorded so that later handling can scan the pallet alone.
Shipping. The manufacturer records a shipping event against the pallet. The freight forwarder records receipt. Two independent records of the same handover now exist.
Customs. Declarations reference the commercial documents and the goods. The identifiers used in the physical record and in the customs record must reconcile; where they do, queries about a consignment can be answered from existing data rather than reconstructed from correspondence.
Warehouse. The pallet is received, broken down, and cartons are reaggregated for onward orders. Disaggregation and reaggregation events keep the containment picture accurate, which is the only reason a later query about one serial number can find the pallet it travelled on.
Retail. The retailer receives, stocks and sells the unit. Its listing draws on master data synchronised from the brand owner. The sale is the boundary event: after it, the chain no longer has custody, and everything downstream depends on the holder and on published information.
Consumer. The buyer scans the carrier. The resolver identifies the request as a consumer request and returns the passport’s public layer: energy performance, care, spare part availability, warranty terms, safety notices. If a notice is issued after purchase, the scan surfaces it, because the information was referenced rather than printed.
Repair. Two years later a component fails. An independent repairer scans the same carrier, is resolved to repairer oriented information, and identifies the correct spare part for this batch rather than for the model in general. The repair is recorded as an event, and the unit’s history now includes evidence that it was maintained rather than replaced.
Recycling. At end of life the appliance reaches a recovery operator, who scans it and is resolved to disassembly guidance, hazardous substance information and material composition. Recovery is recorded as a transformation: the unit’s identity is retired and recovered material identities come into being, carrying provenance into the next product’s stage one.
At no point did a data file accompany the appliance. What travelled was an identifier in a carrier. Everything else was resolved on demand from the parties accountable for it, which is why the information was still correct nine years after it was printed.
Benefits for Manufacturers
- Substantiated claims. Composition, origin and recycled content statements rest on recorded transformations rather than on supplier assertions that cannot be inspected.
- Recall precision. Affected units are identified by batch, serial or aggregation membership, which is the difference between withdrawing a production run and withdrawing a product line.
- Lower integration cost. One standardised identification and event structure replaces a portfolio of bespoke customer specific interfaces.
- Visibility beyond the factory gate. Repair, resale and recovery events reveal how products actually perform in service, which is design intelligence that warranty claims alone never provide.
- Regulatory readiness. Passport obligations become a publication exercise over existing data rather than a data collection emergency.
Benefits for Logistics Providers
- Handling efficiency. Aggregation means one pallet scan stands in for hundreds of unit scans at every handling point.
- Discrepancy resolution. Independently written shipping and receiving events locate losses at the point they occurred rather than at month end.
- Fewer exceptions. Standard identifiers for locations and parties remove a large class of matching failures between systems.
- Customs and border readiness. Consistent identifiers make consignment queries answerable from records that already exist.
- Demonstrable custody. Paired events from separate organisations are materially stronger evidence than any single party’s internal ledger.
Benefits for Retailers
- Listing accuracy. Product attributes synchronised from the brand owner’s governed record reduce returns caused by mismatched descriptions.
- Obligation coverage. Consumer information requirements can be satisfied by resolving to the manufacturer’s governed content rather than by re-keying it.
- Targeted recalls. Affected batches can be removed from specific stores instead of clearing entire ranges.
- One identifier across channels. The same key drives the shelf, the till, the online listing and the consumer scan.
- Supplier accountability. Where evidence is referenced rather than restated, responsibility for accuracy stays with the party that owns the fact.
Benefits for Regulators
- Evidence rather than attestation. Claims can be examined against recorded events instead of accepted on the strength of a declaration.
- Proportionate market surveillance. Investigations start from the units actually implicated. See market surveillance.
- Cross border consistency. Shared identification and event models reduce divergence between national reporting practices.
- Faster incident response. The distribution of an affected batch can be established from existing records.
- Auditable circularity. Recovery and recycling claims can be checked against transformation events rather than aggregate tonnages.
Benefits for Consumers
- Information that stays current. Because content is resolved rather than printed, safety notices and corrections reach the holder years after purchase.
- Repairability in practice. Spare part references and disassembly guidance keep products in use and support independent repair.
- Trustworthy claims. Sustainability statements backed by recorded evidence are comparable in a way that marketing copy is not.
- Confidence in secondhand markets. A verifiable history supports resale value and reduces fraud.
- One consistent way in. A single scan works across brands, categories and borders.
Common Misconceptions
“Product data travels with the product.” It does not. A reference travels; the data stays with the parties who own and maintain it. That is what allows it to remain correct after despatch.
“The passport is the database.” A passport is a governed presentation layer. Enterprise systems remain the systems of record, and a passport that becomes an authoring tool diverges from them within months.
“A GTIN is enough.” A GTIN identifies a trade item. Batch and unit level questions, and every question about history, require additional identity and recorded events.
“EPCIS and a Digital Product Passport are alternatives.” They solve different problems. EPCIS is evidence infrastructure with restricted access; a passport is a presentation obligation with a public layer that may draw on that evidence.
“Digital Link is a QR code.” Digital Link is a web address structure. A QR code is one carrier that can hold it. See QR Codes vs GS1 Digital Link.
“Adopting the standards gives us traceability.” Traceability is a property of the whole chain. Your records plus nothing from your partners produce a history with holes exactly where the interesting questions are.
“This only matters for regulated categories.” The first obligations are category specific, but the underlying data flow is the same for every physical product, and buyers are increasingly asking for it regardless of mandate.
“We can start at the passport and work backwards.” The passport is the last stage. Starting there produces a presentation with nothing defensible behind it.
Frequently Asked Questions
Does product data physically travel with the product?
No. What travels is an identifier encoded in a data carrier. The information itself stays in the systems that own it and is resolved on demand. This is what allows content to be corrected, extended and superseded long after the product has left the factory.
What is the difference between product data and business event data?
Product data describes what a product is: materials, dimensions, care, specifications. Business event data records what happened to specific objects: made, packed, shipped, received, sold, repaired, recycled. Product data is versioned and maintained; event data is append only and never edited.
Do enterprise systems change under this model?
They keep their role. ERP, PLM, MES, WMS and quality systems remain the systems of record. What changes is that they use shared identifiers and a shared event vocabulary at their boundaries, and that a governed layer assembles what must be published externally.
Where does the Digital Product Passport sit in the flow?
At the consumption end. It presents governed lifecycle information to defined audiences, drawing on master data and, where claims depend on history, on evidence derived from events. It is not an event repository and not a system of record.
Is any of this data public?
Only the parts deliberately published. Event data reveals volumes, partners, timing and locations, and is treated as commercially confidential everywhere. A passport’s public layer is derived, curated and intentionally narrow; other layers are gated by audience.
What if our trading partners do not participate?
You capture your own stages and gain internal benefit, but the chain view remains incomplete. In practice adoption spreads through commercial pressure at the boundaries: each party asks its immediate counterparties for the events it needs, rather than waiting for an industry wide programme.
Do we need serial numbers for every product?
No. Serialisation is justified where the history of the individual unit matters: warranty, high value goods, regulated equipment, resale markets and unit level passport requirements. For many categories, trade item plus batch identity answers every question that will be asked.
Where should an organisation start?
Start at stage three. Confirm that identity is correct, consistent and allocated at the right granularity, and that locations and parties have identifiers your counterparties recognise. Everything downstream, including any passport obligation, depends on that foundation being sound.
Key Takeaways
- Product data moves by reference: an identifier travels with the product, the information stays with its owners. - The Trusted Product Data Flow Model describes ten stages from raw materials to recycling, closing as a loop. - GTIN identifies products; GS1 Digital Link connects them to digital services; EPCIS records business events; passports present governed lifecycle information.
- Enterprise systems remain the systems of record; the publication layer reads from them rather than replacing them. - Product identity, product data, business event data, enterprise master data and passports are five distinct categories with distinct owners. - Identity is created once at stage three and referenced by every later record; granularity decided late is expensive to correct. - Events are written by whoever observed them, are never edited, and are only comparable when a shared vocabulary is used. - Trading partner exchange requires agreement on identifiers, locations, vocabulary and entitlement, in that order. - A Digital Product Passport is the last stage of the flow, not the centre of it, and can only present what upstream stages produced. - No organisation sees the whole flow, which is precisely why open standards rather than bilateral integrations are required.
Related Articles
- What is EPCIS?
- QR Codes vs GS1 Digital Link: What’s the Difference?
- What is a Data Carrier?
- What is a GTIN?
- What is GS1 Digital Link?
- What is GS1?
- How Will Digital Product Passports Change Product Compliance?
- How Should Organisations Prepare for Digital Product Passports?
Related Glossary Terms
Definitions of record for the terms used above live in the glossary.
- Product Data
- Product Identifier
- Product Traceability
- Product Lifecycle
- Data Carrier
- GS1
- GS1 Digital Link
- QR Code
- Digital Product Passport
- Economic Operator
- Market Surveillance
- Conformity Assessment
- Circular Economy
- Sustainability Data
- ESPR
- Delegated Act
References
- GS1 traceability standards and guidance: https://www.gs1.org/standards/traceability
- GS1 EPCIS and Core Business Vocabulary standard: https://www.gs1.org/standards/epcis
- GS1 EPCIS and CBV implementation guideline: https://www.gs1.org/standards/epcis/epcis-cbv-implementation-guideline
- GS1 identification keys, including the GTIN and location and container keys: https://www.gs1.org/standards/id-keys
- GS1 General Specifications: https://www.gs1.org/standards/barcodes-epcrfid-id-keys/gs1-general-specifications
- GS1 Digital Link standard: https://www.gs1.org/standards/gs1-digital-link
- GS1 Global Data Synchronisation Network, for trading partner master data exchange: https://www.gs1.org/services/gdsn
- GS1, the global standards organisation: https://www.gs1.org
- International Organization for Standardization, ISO/IEC 19987 on EPC Information Services: https://www.iso.org/standard/66796.html
- International Organization for Standardization: https://www.iso.org
- Regulation (EU) 2024/1781 establishing a framework for the setting of ecodesign requirements for sustainable products, including Digital Product Passport provisions: https://eur-lex.europa.eu/eli/reg/2024/1781/oj
- Regulation (EU) 2023/1542 concerning batteries and waste batteries, including battery passport and supply chain due diligence provisions: https://eur-lex.europa.eu/eli/reg/2023/1542/oj
- European Commission, Ecodesign for Sustainable Products Regulation: https://commission.europa.eu/energy-climate-change-environment/standards-tools-and-labels/products-labelling-rules-and-requirements/ecodesign-sustainable-products-regulation_en
- EUR-Lex, official portal for European Union law: https://eur-lex.europa.eu
About This Article
tieback Knowledge is a continuously maintained reference library covering Digital Product Passports, product traceability, product compliance and related regulations. Articles are reviewed regularly as legislation, standards and implementation guidance evolve.