EUVERIFY

Regulatory Compliance Glossary

Your reference for compliance, identity verification, and regulatory terminology. Clear definitions of key terms.

All Blogs

Tag
  • All
Open Graph image

Brexit Regulatory Divergence

Brexit regulatory divergence refers to the growing differences between EU and UK rules following the UK’s withdrawal from the EU. These differences can affect product marking, registration, representation requirements, and market access obligations for businesses operating in both regions.
Open Graph image

Supply Chain Due Diligence

Supply chain due diligence involves processes used to identify, assess, and manage compliance risks within a product’s supply chain. This may include verifying supplier practices, reviewing documentation, and monitoring regulatory obligations to reduce legal and reputational risks.
Open Graph image

Product Registration

Product registration refers to submitting required product information to official regulatory systems before sale, where mandated by law. Requirements vary by sector and may involve databases such as EUDAMED, CPNP, or national regulatory portals.
Open Graph image

Regulatory Compliance

Regulatory compliance means meeting all applicable legal requirements before placing a product or service on the market and maintaining those obligations afterward. This includes documentation, testing, labelling, reporting, and ongoing monitoring as required by sector-specific laws.
Open Graph image

Third-Party Testing

Third-party testing refers to independent product testing carried out by a laboratory or certification body separate from the manufacturer. It is often required for higher-risk products and supports evidence of safety, performance, or regulatory compliance.
Open Graph image

Accredited Laboratory

An Accredited Laboratory is a testing facility formally recognised as competent to perform specific tests according to defined international or European standards. Accreditation is typically granted by a national accreditation body and provides confidence in the reliability and validity of test results.
Open Graph image

Distributor Obligations

Distributor obligations apply to businesses that make products available within the supply chain without being the manufacturer or importer. Distributors must exercise due care, verify required markings and documentation are present, and cooperate with authorities if safety concerns arise.
Open Graph image

Importer Obligations

Importer obligations refer to the legal duties of businesses placing products from outside the EU or UK onto the respective market. Importers must verify that products comply with applicable legislation, ensure documentation is available, and provide their contact details on the product where required. They share responsibility for compliance alongside manufacturers.
Open Graph image

Competent Authority

A Competent Authority is the national regulator responsible for enforcing specific legislation within a country. Depending on the sector, this may include product safety authorities, data protection regulators, or medical device agencies. Competent Authorities oversee compliance, conduct inspections, and take enforcement action where necessary.
Open Graph image

European Economic Area (EEA)

The European Economic Area (EEA) includes all EU Member States plus Iceland, Liechtenstein, and Norway. It extends many EU internal market rules — including product safety and CE marking requirements — to these additional countries. Products that comply with relevant EU legislation can generally circulate freely within the EEA.
Open Graph image

Single Registration Number (SRN)

A Single Registration Number (SRN) is a unique identifier issued through EUDAMED to manufacturers, authorised representatives, and importers. The SRN confirms registration within the EU system and must be used in regulatory communications and documentation.
Open Graph image

Notified Body

A Notified Body is an EU-designated organisation authorised to assess conformity of certain medical devices before they can be placed on the EU market. Depending on device classification, manufacturers must undergo review and certification by a Notified Body under the EU MDR.
Open Graph image

Serious Undesirable Effects (SUE) Reporting

Serious Undesirable Effects (SUE) reporting refers to the obligation to notify authorities when a cosmetic product causes serious adverse health effects. Responsible Persons must report such cases without delay and cooperate with authorities to assess and mitigate risks.
Open Graph image

Prohibited Substances (Annex II)

Annex II of the EU Cosmetics Regulation contains substances that are strictly prohibited in cosmetic products sold in the EU. Use of any listed ingredient makes a product non-compliant and subject to enforcement action.
Open Graph image

Restricted Substances (Annex III)

Annex III of the EU Cosmetics Regulation lists substances that may only be used under specific conditions, such as concentration limits or product-type restrictions. Manufacturers must ensure these ingredients comply fully with the stated limitations before market placement.
Open Graph image

INCI

INCI (International Nomenclature of Cosmetic Ingredients) is the standardised naming system used to list cosmetic ingredients on product labels. It ensures consistent terminology across the EU and internationally, allowing consumers and regulators to clearly identify ingredients.
Open Graph image

Good Manufacturing Practice (ISO 22716)

ISO 22716 is the recognised Good Manufacturing Practice (GMP) standard for cosmetic production. It sets guidelines for consistent manufacturing, quality control, hygiene, and documentation to ensure product safety and reliability. Compliance with GMP is mandatory under EU cosmetics legislation.
Open Graph image

Product Information File (PIF)

The Product Information File (PIF) is a required compliance file for cosmetic products sold in the EU or UK. It includes the product formula, CPSR, manufacturing details, labelling information, and supporting safety evidence. The Responsible Person must keep the PIF readily accessible for inspection by authorities.
Open Graph image

Cosmetic Product Safety Report (CPSR)

A Cosmetic Product Safety Report (CPSR) is a mandatory safety assessment required before placing a cosmetic product on the EU or UK market. It evaluates ingredients, exposure levels, toxicological data, and overall safety for human use. The CPSR must be prepared by a qualified safety assessor and forms part of the Product Information File.
Open Graph image

Responsible Person

The Responsible Person for cosmetics is the EU- or UK-based entity legally accountable for ensuring a cosmetic product complies with applicable regulations. This includes maintaining the Product Information File (PIF), ensuring the Cosmetic Product Safety Report (CPSR) is completed, and submitting required notifications. Each cosmetic product placed on the market must have a designated Responsible Person.
Open Graph image

EU Cosmetics Regulation

Regulation (EC) 1223/2009 is the main EU framework governing the safety and market placement of cosmetic products. It sets requirements for ingredient restrictions, product safety assessments, labelling, notification, and responsible persons. Before a cosmetic product can be sold in the EU, it must comply with this regulation and meet all documentation and safety obligations.
Open Graph image

EU Declaration of Conformity

The EU Declaration of Conformity is a formal document signed by the manufacturer stating that a product complies with relevant EU legislation. It must reference applicable directives or regulations and harmonised standards where used. The declaration forms part of the product’s compliance documentation.
Open Graph image

Conformity Assessment Procedure

A conformity assessment procedure is the process of demonstrating that a product complies with applicable regulatory requirements. It may include risk assessment, testing, technical documentation, and, where required, certification by a Notified or Approved Body. The required procedure depends on the product category and risk classification.
Open Graph image

UKCA Marking

UKCA (UK Conformity Assessed) marking is the UK’s conformity mark for products placed on the Great Britain market. It replaced CE marking in certain sectors following Brexit. Manufacturers must comply with applicable UK legislation and complete the required conformity assessment before applying the UKCA mark.
Open Graph image

CE Marking

CE marking is a conformity mark showing that a product meets applicable EU safety, health, and environmental protection requirements and can be placed on the European Economic Area (EEA) market. By affixing the CE mark, the manufacturer declares compliance with the relevant EU legislation.
Open Graph image

Data Protection Impact Assessment (DPIA)

A Data Protection Impact Assessment (DPIA) is a documented risk assessment required when processing is likely to result in high risks to individuals’ rights and freedoms. It evaluates potential privacy risks and outlines measures to mitigate them before processing begins.
Open Graph image

Consent (GDPR)

Consent under GDPR must be freely given, specific, informed, and unambiguous. Individuals must take a clear affirmative action to indicate agreement, and they must be able to withdraw consent easily at any time. Pre-ticked boxes or implied consent do not meet GDPR standards.
Open Graph image

Data Protection Officer (DPO)

A Data Protection Officer (DPO) is a designated individual responsible for overseeing an organisation’s data protection strategy and ensuring GDPR compliance. A DPO is mandatory in certain situations, such as large-scale monitoring or processing of sensitive data. The DPO acts independently and serves as a contact point for supervisory authorities.
Open Graph image

Lawful Basis for Processing

Under GDPR, organisations must have a valid legal basis before processing personal data. These include consent, contractual necessity, legal obligation, legitimate interests, vital interests, or public tasks. Identifying and documenting the correct lawful basis is a core compliance requirement.
Open Graph image

Data Processor

A Data Processor is a third party that processes personal data on behalf of a Data Controller. Processors act only under the controller’s instructions and must implement appropriate security measures. Their relationship with the controller must be governed by a compliant Data Processing Agreement (DPA).
Open Graph image

Data Controller

A Data Controller is the organisation or entity that determines the purposes and means of processing personal data. In simple terms, the controller decides why personal data is collected and how it will be used. Controllers carry primary responsibility for GDPR compliance.
Open Graph image

Data Breach Notification

GDPR requires organisations to notify the relevant supervisory authority of certain personal data breaches without undue delay, and where feasible, within 72 hours of becoming aware of the breach. In some cases, affected individuals must also be informed.
Open Graph image

GDPR Article 27 Representative

A GDPR Article 27 Representative is an EU or UK-based contact appointed by certain non-EU organisations that process personal data of EU or UK residents. The representative acts as a point of contact for supervisory authorities and data subjects. This requirement applies where organisations are subject to GDPR but have no establishment within the EU or UK.
Open Graph image

General Data Protection Regulation (GDPR)

The General Data Protection Regulation (GDPR) is EU law governing how organisations collect, use, store, and protect personal data. It applies to businesses established in the EU, as well as non-EU organisations offering goods or services to, or monitoring, EU residents. GDPR sets strict rules on transparency, lawful processing, data subject rights, and accountability.
Open Graph image

Traceability (Supply Chain)

Traceability refers to the ability to identify products and responsible economic operators throughout the supply chain. It supports effective recalls, enforcement actions, and regulatory compliance under the GPSR.
Open Graph image

Product Recall

A product recall is the process of removing unsafe products from consumers after they have been placed on the market. Recalls may be voluntary or authority-mandated and require clear communication and corrective action.
Open Graph image

Risk Assessment

A product safety risk assessment identifies potential hazards, evaluates associated risks, and outlines measures taken to reduce those risks. It forms a key part of compliance documentation under EU product safety legislation.
Open Graph image

Market Surveillance (GPSR)

Market surveillance refers to checks and enforcement actions carried out by EU and UK authorities to ensure products comply with safety and regulatory requirements. Authorities may request documentation, conduct testing, or impose corrective measures if non-compliance is identified.
Open Graph image

Technical Documentation

Technical Documentation is the structured evidence showing that a product meets applicable regulatory requirements. It may include risk assessments, test reports, design information, and declarations of conformity. Authorities can request this documentation at any time.
Open Graph image

Safety Gate (RAPEX)

Safety Gate, formerly RAPEX, is the EU’s rapid alert system for dangerous non-food consumer products. It allows authorities to share information about unsafe products and coordinate corrective actions across Member States.
Open Graph image

Authorised Representative (EU)

An EU Authorised Representative is an EU-established entity formally appointed by a non-EU manufacturer to carry out defined regulatory compliance duties. Depending on the applicable regulation, responsibilities may include holding documentation, responding to authorities, and assisting with corrective actions. The role must be clearly defined in a written mandate.
Open Graph image

Responsible Person (GPSR)

Under the GPSR, the Responsible Person is the EU-based economic operator accountable for ensuring that required product safety obligations are fulfilled. This may be the manufacturer, importer, authorised representative, or another designated operator. The Responsible Person must ensure documentation is available and cooperate with authorities where needed.
Open Graph image

Economic Operator

An Economic Operator includes any manufacturer, importer, authorised representative, distributor, or fulfilment provider involved in placing a product on the EU market. Under the GPSR and other EU laws, at least one economic operator must be established in the EU for certain products.
Open Graph image
Uncategorized

General Product Safety Regulation (GPSR)

The General Product Safety Regulation (EU) 2023/988 sets updated safety requirements for consumer products placed on the EU market from 13 December 2024. It strengthens obligations for manufacturers, importers, authorised representatives, distributors, and online marketplaces. The regulation introduces clearer documentation, traceability, and enforcement requirements, replacing the previous General Product Safety Directive.

Ready to simplify your compliance?

Euverify Helps Businesses Automate Identity Verification And Regulatory
Compliance. Get Started Today.