SafeCart · GPSR Hub

Post-Market Surveillance: The Ultimate Guide for EU Product Compliance

Last updated: 2026-08-14. This article is for general information and does not constitute legal advice. If you are handling a live safety incident, follow the instructions of the competent authorities and seek qualified advice.

Getting a product onto the EU market is a project with an end date. Keeping it there safely is not. Post-market surveillance (PMS) is the name for everything a business does after the sale: collecting safety signals about products already in consumers' hands, assessing what those signals mean, acting when a product turns out to be dangerous, and being able to prove all of it later.

For years this was treated as an optional maturity exercise for large manufacturers. Under the current EU framework it is a baseline operating requirement — and for most online sellers it is the part of compliance that is least documented and most likely to fail under scrutiny.

This guide covers what post-market surveillance means in EU law, which rules apply to which products, what a working system actually contains, how to run a signal from detection to closure, and what your records need to look like when an authority asks.

What post-market surveillance actually is

Post-market surveillance is a continuous, documented loop with four steps:

  1. Collect — gather safety-relevant information about products you have placed or made available on the market, from both internal and external sources.
  2. Assess — decide whether that information indicates a risk, and how serious it is.
  3. Act — take corrective measures proportionate to the risk: correct, withdraw, warn, or recall.
  4. Document — record what you knew, when you knew it, what you decided, and why.

Pre-market compliance answers "was this product safe when we launched it?" Post-market surveillance answers a harder question: "is it still safe in light of everything we have learned since, and can we show that we were paying attention?"

That second question is the one regulators ask after something goes wrong. The evidence that answers it has to have been created before you were asked.

The terminology trap: three different things get called "PMS"

Searching for "post-market surveillance requirements" produces contradictory answers because the phrase means three different things depending on which corner of EU product law you are standing in.

What people call itWho performs itWhere the duty comes fromWhat it produces
Market surveillanceNational market surveillance authoritiesRegulation (EU) 2019/1020, plus the GPSRInspections, testing, recall orders, Safety Gate alerts
Post-market surveillance (PMS) — formalMedical device and IVD manufacturersRegulation (EU) 2017/745 (MDR) and 2017/746 (IVDR)A documented PMS system, PMS plan, PSURs, post-market clinical follow-up
Post-market obligations / ongoing monitoringEvery economic operator selling consumer goods in the EURegulation (EU) 2023/988 (GPSR) and sector-specific harmonisation lawInternal safety processes, complaint records, corrective action, notifications

The distinction matters practically. The GPSR does not use the phrase "post-market surveillance" and does not give you a single article to comply with. It assembles an equivalent duty out of several separate obligations — internal safety processes, complaints handling, corrective measures, notification, and consumer communication. Businesses looking for "the PMS article" in the GPSR find nothing, conclude the duty does not exist, and skip the whole area.

Only medical devices get a formally named PMS system with a prescribed structure. If you sell medical devices or IVDs, MDR Articles 83 and 84 require a documented PMS system and PMS plan per device, with periodic safety update reports and post-market clinical follow-up on top. Everyone else has to build the equivalent themselves from the obligations described below.

Which regime applies to your products

Before designing anything, establish which body of law your catalogue sits under. Most mixed catalogues sit under more than one.

Product typePrimary regimeWhat that means post-market
Non-food consumer goods with no sector-specific EU safety lawGPSR — Regulation (EU) 2023/988General safety requirement, corrective action, notification, recall rules
Harmonised products (toys, electrical equipment, machinery, PPE, radio equipment …)Sector legislation + Regulation (EU) 2019/1020Sector duties, plus market surveillance machinery; GPSR fills gaps the sector law leaves open
Medical devices and in-vitro diagnosticsMDR / IVDRA formal, documented PMS system with prescribed deliverables
Food, feed, medicines, plant protection productsTheir own regimesOutside GPSR scope entirely

For harmonised products the GPSR acts as a safety net: sector law governs the aspects it covers, and the GPSR applies to risks and obligations the sector rules do not address. In practice, most e-commerce catalogues need one post-market process that satisfies the strictest regime touching any of their products, rather than a separate process per category.

Regulation (EU) 2019/1020 also introduced the requirement — applicable since 16 July 2021 for the harmonised product categories it lists — that certain products may only be placed on the market if an economic operator established in the EU is responsible for them. The GPSR extended the same principle to products outside harmonisation legislation. That EU-established responsible person is the entity authorities contact first when a post-market problem surfaces, which makes them a mandatory participant in whatever process you build.

If you need the underlying regulation explained end to end, see our guide to what GPSR is and what Regulation (EU) 2023/988 requires.

What the GPSR actually requires after the sale

Read together, these are the obligations that constitute post-market surveillance for consumer goods.

1. Internal processes for product safety

Manufacturers, importers, distributors, authorised representatives and fulfilment service providers must have internal processes for product safety that allow them to comply with the general safety requirement (GPSR Article 14). This is the closest thing the GPSR has to "you must have a PMS system." It is deliberately unprescriptive about form — but "we handle it case by case" is not a process, and an undocumented process is indistinguishable from no process during an inspection.

2. Complaints handling and an internal register

Manufacturers must investigate complaints and information received about accidents concerning the safety of products they have made available, and keep an internal register of complaints, product recalls and any corrective measures taken (GPSR Article 9). The register is the single most commonly missing artefact in small and mid-sized businesses, and the easiest to start today.

Two practical points:

  • The register must actually be a register — a searchable record with dates, not an email folder.
  • Personal data in it is limited to what is necessary to investigate the complaint, and should not be kept longer than needed for the investigation — and in any event no longer than five years after entry.

3. Monitoring external safety signals

The GPSR does not literally say "check the Safety Gate every day." It requires due care and corrective action once you have reason to believe a product is dangerous. Because Safety Gate alerts are public, "we never looked" is a weak position — the information was available to you. This is why continuous monitoring became the practical baseline rather than a nice-to-have; we cover the reasoning in why continuous product safety monitoring is now expected.

4. Corrective measures

An economic operator who considers, or has reason to believe, that a product is dangerous must immediately take the corrective measures necessary — bringing the product into conformity, withdrawing it from the market, or recalling it from consumers, as the risk requires. The trigger is "reason to believe," not "confirmed by testing." Waiting for certainty before containing is the single most expensive mistake in this area.

You must also keep other economic operators, responsible persons and online marketplace providers in the supply chain informed in a timely manner of safety issues you identify. Post-market surveillance is not a private activity.

5. Notification through the Safety Business Gateway

Two distinct notification duties run through the same portal:

  • Dangerous product: when you take corrective measures because a product is dangerous, notify the market surveillance authorities of the Member States where the product was made available.
  • Accidents: where a product you placed on the market has caused an accident, notify the competent authorities of the Member State where the accident occurred, without undue delay from the moment you know about it. The notification covers the type and identification number of the product and the circumstances of the accident, so far as known.

"Without undue delay" is measured from awareness. If your complaints intake takes three weeks to reach the person who can file the notification, the clock has already been running for three weeks.

6. Consumer communication and remedies

When a recall or safety alert is necessary, the GPSR sets out how to communicate it and what to offer. This is covered in detail below.

7. Traceability

None of the above can be executed without records that link a safety signal to specific stock: which supplier delivery, which batch, which channels sold it, which customers bought it. Traceability is not a separate compliance box — it is the mechanism that makes every other post-market duty performable within a reasonable time.

The three EU systems you will interact with

These are frequently confused, including in vendor marketing. They are three different systems with three different directions of travel.

SystemDirectionWho uses itWhat it is for
Safety Gate Rapid Alert SystemAuthority → authorityNational authorities and the CommissionCirculating alerts about dangerous non-food products between Member States
Safety Gate PortalAuthority → publicConsumers, businesses, journalistsThe public website where alerts are published weekly and can be searched
Safety Business GatewayBusiness → authorityEconomic operatorsNotifying authorities of dangerous products, accidents, and corrective measures

The practical consequence: the Safety Gate Portal is a publication, not a notification service. Nobody emails you when an alert matches your catalogue. Alerts are written from the authority's perspective — the brand on the packaging, a model code printed on the plug, photographs, sometimes an incomplete identifier — which frequently does not match how the same product appears in your product database. We break down where that mismatch happens in how Safety Gate recalls actually reach businesses.

Online marketplace providers have their own layer on top: under GPSR Article 22 they must register on the Safety Gate Portal, designate a single point of contact for authorities, act on authority orders to remove dangerous listings (in principle within two working days), and take Safety Gate notifications into account in their own processes.

The eight inputs of a working PMS system

A system that only watches one source misses most of what it should catch. Mature post-market surveillance draws on both internal and external signals.

Internal signals — you already own this data:

  1. Customer complaints and support tickets, specifically those mentioning injury, burning smell, overheating, breakage, small parts, skin reactions, or a child.
  2. Returns and warranty claims, analysed by reason code rather than volume — a rising "stopped working" rate on a charger is a safety signal, not a quality metric.
  3. Product reviews, where safety complaints are routinely posted and never routed to anyone who can act on them.
  4. Incoming QC, inspection and supplier non-conformance records, including batch-level test failures.

External signals — you have to go and get these:

  1. Safety Gate alerts, published weekly and covering all Member States and languages.
  2. National authority actions and recalls, which may appear locally before or without an EU-level alert.
  3. Marketplace delistings and platform notices, which are often the first concrete signal a seller receives.
  4. Supplier and manufacturer notifications, plus standards updates and, for globally sourced goods, recalls published by non-EU regulators covering the same underlying product.

No single feed covers all eight. The internal ones fail through routing — the information exists somewhere in the business but never reaches the person responsible for product safety. The external ones fail through volume and matching.

From signal to decision: a workflow that survives an audit

The goal is a repeatable path from "something arrived" to "closed, with a record." Times below are illustrative defaults for a consumer-goods seller — set your own against your risk profile, and then actually meet them.

StageWhat happensOwnerTarget
IntakeSignal is logged in one place with source, date and raw contentWhoever receives itSame day
IdentifyMap the signal to specific SKUs, variants and batches in your catalogueProduct safety owner1 working day
AssessJudge plausibility and severity: hazard type, vulnerable users, likelihood, severityProduct safety owner1–2 working days
ContainPause sales across all channels while verification is pending, if risk is credibleOps / channel ownersImmediately on credible risk
Verify scopeDetermine affected batches, stock locations, channels and customersOps + supply chain3–5 working days
DecideCorrect, withdraw, warn, recall — or record "not affected" with the evidenceNamed decision-makerOn completion of scope
NotifySafety Business Gateway, supply chain partners, marketplacesProduct safety ownerWithout undue delay
ExecuteConsumer notice, remedy handling, stock dispositionCross-functionalPer plan
CloseEffectiveness check, final record, lessons learnedProduct safety ownerWithin 30 days of closure

Three design rules make the difference between a workflow that holds up and one that does not:

  • Contain before you conclude. Pausing a listing is cheap and reversible. Continued sales after a credible signal are neither.
  • Record the "no" decisions too. A documented "we investigated this alert and our product is not affected, here is why" is a strong compliance artefact. An investigation that leaves no trace looks identical to never having looked.
  • Name one accountable person. Not a team, not a shared inbox. Distributed ownership is how signals expire quietly.

Recall execution under the GPSR

If a signal leads to a recall, the GPSR is unusually prescriptive about how you communicate — the rules exist because pre-2024 recall notices were frequently written to minimise response rates.

Reaching consumers (Article 35). You must directly notify all affected consumers you can identify, in writing and in easily understandable language. Where you cannot identify everyone, publish the notice through other channels with the widest possible reach. For an online seller with order records, "we posted it on our website" is not sufficient — you can identify your buyers.

The recall notice itself (Article 36). The notice must identify the product, describe the hazard, state clearly what the consumer should do, and explain the remedies available. The Commission adopted a standardised template through Implementing Regulation (EU) 2024/1435, which is the safest starting point. Language that reduces the consumer's perception of risk is specifically ruled out — terms such as "voluntary," "precautionary," "discretionary," or "in rare/specific situations" have no place in a safety recall notice.

Remedies (Article 37). Consumers must be offered a choice of at least two of: repair, replacement with a safe product of at least the same value and quality, or an adequate refund — unless offering a second option would be impossible or disproportionate. The remedies must be free of charge, effective and timely, the process must be as simple as possible for the consumer, and a refund must be at least the price the consumer paid. Consumer-performed repair is only acceptable where it is genuinely easy and safe to carry out.

Practically, plan the remedy economics before you need them. A refund at price paid, on products sold two years ago through three channels, is a materially different exposure from your original landed cost.

For ready-to-adapt wording, see our EU product recall notice template, and for the wider obligations checklist, GPSR recall obligations for online sellers.

Documentation: what your PMS file should contain

Assume you will one day have to hand someone a folder. It should contain:

  • The written procedure — your internal product safety process, with named roles, sources monitored, review frequency, decision criteria and escalation path.
  • The complaints and incidents register — every safety-relevant complaint, with dates, product identification, investigation notes and outcome.
  • The monitoring log — evidence that external sources were actually reviewed, and what was reviewed when. This is what turns "we monitor the Safety Gate" from a claim into a fact.
  • Signal case files — for each investigated signal: the source, the products assessed, the risk assessment, the decision, and the reasoning, including for signals dismissed as not applicable.
  • Corrective action records — measures taken, dates, channels affected, stock disposition, notifications filed with confirmation.
  • Consumer communications — the notice issued, the distribution channels used, reach achieved, and response rates.
  • Traceability records — supplier, batch/lot, inbound and outbound movements, channel mapping.
  • Periodic review — a documented management review, at least annually, of what the system caught and what it missed.

On retention: manufacturers keep technical documentation for 10 years after placing a product on the market, so post-market records that inform it should follow the same horizon. Personal data in the complaints register runs on a shorter clock — no longer than necessary to investigate, and in any event not more than five years after entry.

Documentation created contemporaneously is worth far more than documentation reconstructed later, both legally and practically. A timeline assembled from memory six weeks after the fact tends to reveal exactly the gaps you would rather it did not.

Building the system in proportion to your business

The GPSR expects measures proportionate to your scale and risk. That cuts both ways: a spreadsheet is defensible for a small single-channel seller and indefensible for a multi-entity importer.

Business profileProportionate post-market surveillance
Under ~500 SKUs, one channel, low-risk categoriesWritten procedure, complaints register, a named owner, a scheduled weekly Safety Gate review with a dated log, a recall notice template on file
500–5,000 SKUs, multiple channelsThe above, plus automated Safety Gate matching against catalogue identifiers, cross-channel containment that stops sales everywhere at once, batch-level traceability
5,000+ SKUs, importer or multi-entity, higher-risk categoriesThe above, plus per-category risk assessment, supplier safety agreements with notification clauses, defined SLAs with escalation, effectiveness checks and annual management review

The break point is usually catalogue size against alert volume. Manual review works until the number of alerts multiplied by the number of SKUs to check exceeds the hours available, at which point it silently degrades into skimming — the failure mode is not that people stop, it is that they keep going while catching less. We compare the two approaches in manual vs automated product safety monitoring.

Metrics that show the system works

If you cannot measure the system, you cannot demonstrate due care and you cannot tell whether it is degrading.

MetricWhat it tells youReasonable target
Time to detectAlert publication date → your first awarenessUnder 48 hours
Time to containAwareness → sales paused on every channelUnder 24 hours from credible signal
Open review backlogPotential matches awaiting a decisionTrending to zero weekly
Identifier coverage% of SKUs with GTIN/EAN, model code and supplier codeAbove 90% — this caps matching quality
Complaint closure timeSafety complaint logged → investigated and closedUnder 10 working days
Recall reach and responseConsumers notified and units returned as % of units soldTrack and improve; there is no universal target

Identifier coverage deserves particular attention: it silently determines the ceiling on every other number. Matching an alert to a catalogue that stores only a marketing title is guesswork no matter how good the process around it.

Seven ways post-market surveillance fails

These are the recurring patterns, and they are operational rather than legal:

  1. Brand-only matching. You watch for your own brand name; the alert names the OEM brand printed on the packaging of the identical product.
  2. Identifiers that live on the packaging, not in the database. The model code that would have matched the alert was never captured at intake.
  3. The channel gap. A marketplace delists the item; your own webstore keeps selling it because "the marketplace team handled it."
  4. Complaints that never reach safety. Customer service resolves an overheating report as a refund, closes the ticket, and no safety review is ever triggered.
  5. No batch traceability. An alert applies to specific production dates; the seller spends two weeks establishing scope while the product stays live.
  6. Assumed supplier notification. "The manufacturer would tell us" — they may not, may tell only some partners, or may tell you late. The duty is yours regardless.
  7. No periodic review. The system was set up once, a category was added later, and nobody updated what is monitored.

Realistic worked examples of several of these are in selling a recalled product without knowing it.

A starter post-market surveillance procedure

Adapt this outline into a one- to three-page document, and store the completed version where an auditor can be shown it:

  1. Scope — which products, which entities, which markets the procedure covers.
  2. Roles — the named product safety owner, their deputy, and who may authorise containment, a recall and external communications.
  3. Sources monitored — the internal and external inputs, each with a review frequency.
  4. Intake — where signals are logged, and the mandatory fields.
  5. Risk assessment method — how severity and likelihood are judged, and what triggers containment.
  6. Decision criteria — thresholds for correct / withdraw / warn / recall.
  7. Notification — who files with the Safety Business Gateway, within what time, and what evidence is retained.
  8. Consumer communication — the notice template, channels, and remedy handling.
  9. Records and retention — what is kept, where, and for how long.
  10. Review — the annual management review, and what evidence it examines.

For an intake record, capture at minimum: date received, source, raw description, reported hazard, whether injury or damage occurred, product SKUs and batches implicated, assessor, risk decision with reasoning, action taken, dates of each step, and closure date.

For a broader pre- and post-market checklist covering listings, responsible person and traceability alongside this, use the GPSR compliance checklist for online sellers.

Frequently asked questions

What is post-market surveillance?

Post-market surveillance is the systematic, ongoing process of collecting and reviewing safety information about products already on the market, assessing whether they present a risk, taking corrective action when they do, and documenting the whole cycle. It runs for as long as the product is in use, not just while it is on sale.

Does the GPSR require post-market surveillance?

The GPSR does not use the phrase, but it requires the components: internal processes for product safety, complaints investigation and an internal register, corrective measures when there is reason to believe a product is dangerous, notification through the Safety Business Gateway, and prescribed consumer communication and remedies. Meeting those obligations in practice requires a post-market surveillance system, whatever you call it internally.

Is post-market surveillance the same as market surveillance?

No. Market surveillance is what national authorities do — inspections, testing, enforcement, and alerts under Regulation (EU) 2019/1020 and the GPSR. Post-market surveillance is what businesses do to monitor their own products after sale. The two meet at the Safety Gate and the Safety Business Gateway.

Who needs a post-market surveillance system in the EU?

Every economic operator making non-food consumer products available on the EU market — manufacturers, importers, distributors, online sellers, fulfilment service providers — needs internal product safety processes. Online marketplace providers have additional obligations. Medical device and IVD manufacturers need a formally documented PMS system under the MDR and IVDR. There is no small-business exemption; the expectation is proportionality, not absence.

How often should we check the Safety Gate?

The law sets no fixed interval; it expects your detection to be fast enough to prevent continued sales of a dangerous product. Alerts are published weekly, so a weekly manual review is the realistic minimum for a small catalogue, and continuous automated matching becomes necessary as catalogue size and channel count grow.

What records prove we did post-market surveillance?

A written procedure, a complaints and incidents register, dated evidence that external sources were reviewed, case files for investigated signals — including those found not to apply — corrective action records with notification confirmations, consumer communications with reach data, traceability records, and a periodic management review.

What is the difference between a withdrawal and a recall?

A withdrawal stops a product moving further through the supply chain and removes it from sale. A recall goes further and seeks the return of products already with consumers. A recall carries the consumer notification and remedy obligations described above; a withdrawal on its own does not, though it is often the immediate first step while scope is being verified.

How SafeCart supports post-market surveillance

The hardest parts of post-market surveillance to sustain manually are the external monitoring loop and the evidence trail. SafeCart continuously matches new EU Safety Gate alerts against your product catalogue, alerts you when something matches, and keeps a dated record of what was checked, what matched, and what you decided.

It does not replace legal advice, your internal procedure, or your obligation to notify authorities through the Safety Business Gateway — those stay with you. What it removes is the part that quietly stops happening when the catalogue grows: reading every alert, in every language, against every SKU, every week, and being able to show that you did.

You can scan your store without an account to see what a first pass against your live catalogue returns, or review plans and pricing for continuous monitoring.

Related resources