Post-Market Surveillance: The Ultimate Guide for EU Product Compliance
Last updated: 2026-08-14. This article is for general information and does not constitute legal advice. If you are handling a live safety incident, follow the instructions of the competent authorities and seek qualified advice.
Getting a product onto the EU market is a project with an end date. Keeping it there safely is not. Post-market surveillance (PMS) is the name for everything a business does after the sale: collecting safety signals about products already in consumers' hands, assessing what those signals mean, acting when a product turns out to be dangerous, and being able to prove all of it later.
For years this was treated as an optional maturity exercise for large manufacturers. Under the current EU framework it is a baseline operating requirement — and for most online sellers it is the part of compliance that is least documented and most likely to fail under scrutiny.
This guide covers what post-market surveillance means in EU law, which rules apply to which products, what a working system actually contains, how to run a signal from detection to closure, and what your records need to look like when an authority asks.
What post-market surveillance actually is
Post-market surveillance is a continuous, documented loop with four steps:
- Collect — gather safety-relevant information about products you have placed or made available on the market, from both internal and external sources.
- Assess — decide whether that information indicates a risk, and how serious it is.
- Act — take corrective measures proportionate to the risk: correct, withdraw, warn, or recall.
- Document — record what you knew, when you knew it, what you decided, and why.
Pre-market compliance answers "was this product safe when we launched it?" Post-market surveillance answers a harder question: "is it still safe in light of everything we have learned since, and can we show that we were paying attention?"
That second question is the one regulators ask after something goes wrong. The evidence that answers it has to have been created before you were asked.
The terminology trap: three different things get called "PMS"
Searching for "post-market surveillance requirements" produces contradictory answers because the phrase means three different things depending on which corner of EU product law you are standing in.
| What people call it | Who performs it | Where the duty comes from | What it produces |
|---|---|---|---|
| Market surveillance | National market surveillance authorities | Regulation (EU) 2019/1020, plus the GPSR | Inspections, testing, recall orders, Safety Gate alerts |
| Post-market surveillance (PMS) — formal | Medical device and IVD manufacturers | Regulation (EU) 2017/745 (MDR) and 2017/746 (IVDR) | A documented PMS system, PMS plan, PSURs, post-market clinical follow-up |
| Post-market obligations / ongoing monitoring | Every economic operator selling consumer goods in the EU | Regulation (EU) 2023/988 (GPSR) and sector-specific harmonisation law | Internal safety processes, complaint records, corrective action, notifications |
The distinction matters practically. The GPSR does not use the phrase "post-market surveillance" and does not give you a single article to comply with. It assembles an equivalent duty out of several separate obligations — internal safety processes, complaints handling, corrective measures, notification, and consumer communication. Businesses looking for "the PMS article" in the GPSR find nothing, conclude the duty does not exist, and skip the whole area.
Only medical devices get a formally named PMS system with a prescribed structure. If you sell medical devices or IVDs, MDR Articles 83 and 84 require a documented PMS system and PMS plan per device, with periodic safety update reports and post-market clinical follow-up on top. Everyone else has to build the equivalent themselves from the obligations described below.
Which regime applies to your products
Before designing anything, establish which body of law your catalogue sits under. Most mixed catalogues sit under more than one.
| Product type | Primary regime | What that means post-market |
|---|---|---|
| Non-food consumer goods with no sector-specific EU safety law | GPSR — Regulation (EU) 2023/988 | General safety requirement, corrective action, notification, recall rules |
| Harmonised products (toys, electrical equipment, machinery, PPE, radio equipment …) | Sector legislation + Regulation (EU) 2019/1020 | Sector duties, plus market surveillance machinery; GPSR fills gaps the sector law leaves open |
| Medical devices and in-vitro diagnostics | MDR / IVDR | A formal, documented PMS system with prescribed deliverables |
| Food, feed, medicines, plant protection products | Their own regimes | Outside GPSR scope entirely |
For harmonised products the GPSR acts as a safety net: sector law governs the aspects it covers, and the GPSR applies to risks and obligations the sector rules do not address. In practice, most e-commerce catalogues need one post-market process that satisfies the strictest regime touching any of their products, rather than a separate process per category.
Regulation (EU) 2019/1020 also introduced the requirement — applicable since 16 July 2021 for the harmonised product categories it lists — that certain products may only be placed on the market if an economic operator established in the EU is responsible for them. The GPSR extended the same principle to products outside harmonisation legislation. That EU-established responsible person is the entity authorities contact first when a post-market problem surfaces, which makes them a mandatory participant in whatever process you build.
If you need the underlying regulation explained end to end, see our guide to what GPSR is and what Regulation (EU) 2023/988 requires.
What the GPSR actually requires after the sale
Read together, these are the obligations that constitute post-market surveillance for consumer goods.
1. Internal processes for product safety
Manufacturers, importers, distributors, authorised representatives and fulfilment service providers must have internal processes for product safety that allow them to comply with the general safety requirement (GPSR Article 14). This is the closest thing the GPSR has to "you must have a PMS system." It is deliberately unprescriptive about form — but "we handle it case by case" is not a process, and an undocumented process is indistinguishable from no process during an inspection.
2. Complaints handling and an internal register
Manufacturers must investigate complaints and information received about accidents concerning the safety of products they have made available, and keep an internal register of complaints, product recalls and any corrective measures taken (GPSR Article 9). The register is the single most commonly missing artefact in small and mid-sized businesses, and the easiest to start today.
Two practical points:
- The register must actually be a register — a searchable record with dates, not an email folder.
- Personal data in it is limited to what is necessary to investigate the complaint, and should not be kept longer than needed for the investigation — and in any event no longer than five years after entry.
3. Monitoring external safety signals
The GPSR does not literally say "check the Safety Gate every day." It requires due care and corrective action once you have reason to believe a product is dangerous. Because Safety Gate alerts are public, "we never looked" is a weak position — the information was available to you. This is why continuous monitoring became the practical baseline rather than a nice-to-have; we cover the reasoning in why continuous product safety monitoring is now expected.
4. Corrective measures
An economic operator who considers, or has reason to believe, that a product is dangerous must immediately take the corrective measures necessary — bringing the product into conformity, withdrawing it from the market, or recalling it from consumers, as the risk requires. The trigger is "reason to believe," not "confirmed by testing." Waiting for certainty before containing is the single most expensive mistake in this area.
You must also keep other economic operators, responsible persons and online marketplace providers in the supply chain informed in a timely manner of safety issues you identify. Post-market surveillance is not a private activity.
5. Notification through the Safety Business Gateway
Two distinct notification duties run through the same portal:
- Dangerous product: when you take corrective measures because a product is dangerous, notify the market surveillance authorities of the Member States where the product was made available.
- Accidents: where a product you placed on the market has caused an accident, notify the competent authorities of the Member State where the accident occurred, without undue delay from the moment you know about it. The notification covers the type and identification number of the product and the circumstances of the accident, so far as known.
"Without undue delay" is measured from awareness. If your complaints intake takes three weeks to reach the person who can file the notification, the clock has already been running for three weeks.
6. Consumer communication and remedies
When a recall or safety alert is necessary, the GPSR sets out how to communicate it and what to offer. This is covered in detail below.
7. Traceability
None of the above can be executed without records that link a safety signal to specific stock: which supplier delivery, which batch, which channels sold it, which customers bought it. Traceability is not a separate compliance box — it is the mechanism that makes every other post-market duty performable within a reasonable time.
The three EU systems you will interact with
These are frequently confused, including in vendor marketing. They are three different systems with three different directions of travel.
| System | Direction | Who uses it | What it is for |
|---|---|---|---|
| Safety Gate Rapid Alert System | Authority → authority | National authorities and the Commission | Circulating alerts about dangerous non-food products between Member States |
| Safety Gate Portal | Authority → public | Consumers, businesses, journalists | The public website where alerts are published weekly and can be searched |
| Safety Business Gateway | Business → authority | Economic operators | Notifying authorities of dangerous products, accidents, and corrective measures |
The practical consequence: the Safety Gate Portal is a publication, not a notification service. Nobody emails you when an alert matches your catalogue. Alerts are written from the authority's perspective — the brand on the packaging, a model code printed on the plug, photographs, sometimes an incomplete identifier — which frequently does not match how the same product appears in your product database. We break down where that mismatch happens in how Safety Gate recalls actually reach businesses.
Online marketplace providers have their own layer on top: under GPSR Article 22 they must register on the Safety Gate Portal, designate a single point of contact for authorities, act on authority orders to remove dangerous listings (in principle within two working days), and take Safety Gate notifications into account in their own processes.
The eight inputs of a working PMS system
A system that only watches one source misses most of what it should catch. Mature post-market surveillance draws on both internal and external signals.
Internal signals — you already own this data:
- Customer complaints and support tickets, specifically those mentioning injury, burning smell, overheating, breakage, small parts, skin reactions, or a child.
- Returns and warranty claims, analysed by reason code rather than volume — a rising "stopped working" rate on a charger is a safety signal, not a quality metric.
- Product reviews, where safety complaints are routinely posted and never routed to anyone who can act on them.
- Incoming QC, inspection and supplier non-conformance records, including batch-level test failures.
External signals — you have to go and get these:
- Safety Gate alerts, published weekly and covering all Member States and languages.
- National authority actions and recalls, which may appear locally before or without an EU-level alert.
- Marketplace delistings and platform notices, which are often the first concrete signal a seller receives.
- Supplier and manufacturer notifications, plus standards updates and, for globally sourced goods, recalls published by non-EU regulators covering the same underlying product.
No single feed covers all eight. The internal ones fail through routing — the information exists somewhere in the business but never reaches the person responsible for product safety. The external ones fail through volume and matching.
From signal to decision: a workflow that survives an audit
The goal is a repeatable path from "something arrived" to "closed, with a record." Times below are illustrative defaults for a consumer-goods seller — set your own against your risk profile, and then actually meet them.
| Stage | What happens | Owner | Target |
|---|---|---|---|
| Intake | Signal is logged in one place with source, date and raw content | Whoever receives it | Same day |
| Identify | Map the signal to specific SKUs, variants and batches in your catalogue | Product safety owner | 1 working day |
| Assess | Judge plausibility and severity: hazard type, vulnerable users, likelihood, severity | Product safety owner | 1–2 working days |
| Contain | Pause sales across all channels while verification is pending, if risk is credible | Ops / channel owners | Immediately on credible risk |
| Verify scope | Determine affected batches, stock locations, channels and customers | Ops + supply chain | 3–5 working days |
| Decide | Correct, withdraw, warn, recall — or record "not affected" with the evidence | Named decision-maker | On completion of scope |
| Notify | Safety Business Gateway, supply chain partners, marketplaces | Product safety owner | Without undue delay |
| Execute | Consumer notice, remedy handling, stock disposition | Cross-functional | Per plan |
| Close | Effectiveness check, final record, lessons learned | Product safety owner | Within 30 days of closure |
Three design rules make the difference between a workflow that holds up and one that does not:
- Contain before you conclude. Pausing a listing is cheap and reversible. Continued sales after a credible signal are neither.
- Record the "no" decisions too. A documented "we investigated this alert and our product is not affected, here is why" is a strong compliance artefact. An investigation that leaves no trace looks identical to never having looked.
- Name one accountable person. Not a team, not a shared inbox. Distributed ownership is how signals expire quietly.
Recall execution under the GPSR
If a signal leads to a recall, the GPSR is unusually prescriptive about how you communicate — the rules exist because pre-2024 recall notices were frequently written to minimise response rates.
Reaching consumers (Article 35). You must directly notify all affected consumers you can identify, in writing and in easily understandable language. Where you cannot identify everyone, publish the notice through other channels with the widest possible reach. For an online seller with order records, "we posted it on our website" is not sufficient — you can identify your buyers.
The recall notice itself (Article 36). The notice must identify the product, describe the hazard, state clearly what the consumer should do, and explain the remedies available. The Commission adopted a standardised template through Implementing Regulation (EU) 2024/1435, which is the safest starting point. Language that reduces the consumer's perception of risk is specifically ruled out — terms such as "voluntary," "precautionary," "discretionary," or "in rare/specific situations" have no place in a safety recall notice.
Remedies (Article 37). Consumers must be offered a choice of at least two of: repair, replacement with a safe product of at least the same value and quality, or an adequate refund — unless offering a second option would be impossible or disproportionate. The remedies must be free of charge, effective and timely, the process must be as simple as possible for the consumer, and a refund must be at least the price the consumer paid. Consumer-performed repair is only acceptable where it is genuinely easy and safe to carry out.
Practically, plan the remedy economics before you need them. A refund at price paid, on products sold two years ago through three channels, is a materially different exposure from your original landed cost.
For ready-to-adapt wording, see our EU product recall notice template, and for the wider obligations checklist, GPSR recall obligations for online sellers.
Documentation: what your PMS file should contain
Assume you will one day have to hand someone a folder. It should contain:
- The written procedure — your internal product safety process, with named roles, sources monitored, review frequency, decision criteria and escalation path.
- The complaints and incidents register — every safety-relevant complaint, with dates, product identification, investigation notes and outcome.
- The monitoring log — evidence that external sources were actually reviewed, and what was reviewed when. This is what turns "we monitor the Safety Gate" from a claim into a fact.
- Signal case files — for each investigated signal: the source, the products assessed, the risk assessment, the decision, and the reasoning, including for signals dismissed as not applicable.
- Corrective action records — measures taken, dates, channels affected, stock disposition, notifications filed with confirmation.
- Consumer communications — the notice issued, the distribution channels used, reach achieved, and response rates.
- Traceability records — supplier, batch/lot, inbound and outbound movements, channel mapping.
- Periodic review — a documented management review, at least annually, of what the system caught and what it missed.
On retention: manufacturers keep technical documentation for 10 years after placing a product on the market, so post-market records that inform it should follow the same horizon. Personal data in the complaints register runs on a shorter clock — no longer than necessary to investigate, and in any event not more than five years after entry.
Documentation created contemporaneously is worth far more than documentation reconstructed later, both legally and practically. A timeline assembled from memory six weeks after the fact tends to reveal exactly the gaps you would rather it did not.
Building the system in proportion to your business
The GPSR expects measures proportionate to your scale and risk. That cuts both ways: a spreadsheet is defensible for a small single-channel seller and indefensible for a multi-entity importer.
| Business profile | Proportionate post-market surveillance |
|---|---|
| Under ~500 SKUs, one channel, low-risk categories | Written procedure, complaints register, a named owner, a scheduled weekly Safety Gate review with a dated log, a recall notice template on file |
| 500–5,000 SKUs, multiple channels | The above, plus automated Safety Gate matching against catalogue identifiers, cross-channel containment that stops sales everywhere at once, batch-level traceability |
| 5,000+ SKUs, importer or multi-entity, higher-risk categories | The above, plus per-category risk assessment, supplier safety agreements with notification clauses, defined SLAs with escalation, effectiveness checks and annual management review |
The break point is usually catalogue size against alert volume. Manual review works until the number of alerts multiplied by the number of SKUs to check exceeds the hours available, at which point it silently degrades into skimming — the failure mode is not that people stop, it is that they keep going while catching less. We compare the two approaches in manual vs automated product safety monitoring.
Metrics that show the system works
If you cannot measure the system, you cannot demonstrate due care and you cannot tell whether it is degrading.
| Metric | What it tells you | Reasonable target |
|---|---|---|
| Time to detect | Alert publication date → your first awareness | Under 48 hours |
| Time to contain | Awareness → sales paused on every channel | Under 24 hours from credible signal |
| Open review backlog | Potential matches awaiting a decision | Trending to zero weekly |
| Identifier coverage | % of SKUs with GTIN/EAN, model code and supplier code | Above 90% — this caps matching quality |
| Complaint closure time | Safety complaint logged → investigated and closed | Under 10 working days |
| Recall reach and response | Consumers notified and units returned as % of units sold | Track and improve; there is no universal target |
Identifier coverage deserves particular attention: it silently determines the ceiling on every other number. Matching an alert to a catalogue that stores only a marketing title is guesswork no matter how good the process around it.
Seven ways post-market surveillance fails
These are the recurring patterns, and they are operational rather than legal:
- Brand-only matching. You watch for your own brand name; the alert names the OEM brand printed on the packaging of the identical product.
- Identifiers that live on the packaging, not in the database. The model code that would have matched the alert was never captured at intake.
- The channel gap. A marketplace delists the item; your own webstore keeps selling it because "the marketplace team handled it."
- Complaints that never reach safety. Customer service resolves an overheating report as a refund, closes the ticket, and no safety review is ever triggered.
- No batch traceability. An alert applies to specific production dates; the seller spends two weeks establishing scope while the product stays live.
- Assumed supplier notification. "The manufacturer would tell us" — they may not, may tell only some partners, or may tell you late. The duty is yours regardless.
- No periodic review. The system was set up once, a category was added later, and nobody updated what is monitored.
Realistic worked examples of several of these are in selling a recalled product without knowing it.
A starter post-market surveillance procedure
Adapt this outline into a one- to three-page document, and store the completed version where an auditor can be shown it:
- Scope — which products, which entities, which markets the procedure covers.
- Roles — the named product safety owner, their deputy, and who may authorise containment, a recall and external communications.
- Sources monitored — the internal and external inputs, each with a review frequency.
- Intake — where signals are logged, and the mandatory fields.
- Risk assessment method — how severity and likelihood are judged, and what triggers containment.
- Decision criteria — thresholds for correct / withdraw / warn / recall.
- Notification — who files with the Safety Business Gateway, within what time, and what evidence is retained.
- Consumer communication — the notice template, channels, and remedy handling.
- Records and retention — what is kept, where, and for how long.
- Review — the annual management review, and what evidence it examines.
For an intake record, capture at minimum: date received, source, raw description, reported hazard, whether injury or damage occurred, product SKUs and batches implicated, assessor, risk decision with reasoning, action taken, dates of each step, and closure date.
For a broader pre- and post-market checklist covering listings, responsible person and traceability alongside this, use the GPSR compliance checklist for online sellers.
Frequently asked questions
What is post-market surveillance?
Post-market surveillance is the systematic, ongoing process of collecting and reviewing safety information about products already on the market, assessing whether they present a risk, taking corrective action when they do, and documenting the whole cycle. It runs for as long as the product is in use, not just while it is on sale.
Does the GPSR require post-market surveillance?
The GPSR does not use the phrase, but it requires the components: internal processes for product safety, complaints investigation and an internal register, corrective measures when there is reason to believe a product is dangerous, notification through the Safety Business Gateway, and prescribed consumer communication and remedies. Meeting those obligations in practice requires a post-market surveillance system, whatever you call it internally.
Is post-market surveillance the same as market surveillance?
No. Market surveillance is what national authorities do — inspections, testing, enforcement, and alerts under Regulation (EU) 2019/1020 and the GPSR. Post-market surveillance is what businesses do to monitor their own products after sale. The two meet at the Safety Gate and the Safety Business Gateway.
Who needs a post-market surveillance system in the EU?
Every economic operator making non-food consumer products available on the EU market — manufacturers, importers, distributors, online sellers, fulfilment service providers — needs internal product safety processes. Online marketplace providers have additional obligations. Medical device and IVD manufacturers need a formally documented PMS system under the MDR and IVDR. There is no small-business exemption; the expectation is proportionality, not absence.
How often should we check the Safety Gate?
The law sets no fixed interval; it expects your detection to be fast enough to prevent continued sales of a dangerous product. Alerts are published weekly, so a weekly manual review is the realistic minimum for a small catalogue, and continuous automated matching becomes necessary as catalogue size and channel count grow.
What records prove we did post-market surveillance?
A written procedure, a complaints and incidents register, dated evidence that external sources were reviewed, case files for investigated signals — including those found not to apply — corrective action records with notification confirmations, consumer communications with reach data, traceability records, and a periodic management review.
What is the difference between a withdrawal and a recall?
A withdrawal stops a product moving further through the supply chain and removes it from sale. A recall goes further and seeks the return of products already with consumers. A recall carries the consumer notification and remedy obligations described above; a withdrawal on its own does not, though it is often the immediate first step while scope is being verified.
How SafeCart supports post-market surveillance
The hardest parts of post-market surveillance to sustain manually are the external monitoring loop and the evidence trail. SafeCart continuously matches new EU Safety Gate alerts against your product catalogue, alerts you when something matches, and keeps a dated record of what was checked, what matched, and what you decided.
It does not replace legal advice, your internal procedure, or your obligation to notify authorities through the Safety Business Gateway — those stay with you. What it removes is the part that quietly stops happening when the catalogue grows: reading every alert, in every language, against every SKU, every week, and being able to show that you did.
You can scan your store without an account to see what a first pass against your live catalogue returns, or review plans and pricing for continuous monitoring.
Related resources
- The regulation itself: What is GPSR? The regulation explained
- Why monitoring is continuous: Why continuous product safety monitoring is now mandatory under GPSR
- How alerts reach you: How EU Safety Gate recalls actually reach businesses
- When it goes wrong: Selling a recalled product without knowing it
- Recall communications: EU product recall notice template
- Full compliance checklist: GPSR compliance checklist for online sellers