Food traceability: Regulation 178/2002, the EUDR and how to make it verifiable
Equipo Proovik · Sep 12, 2026 · 10 min read
Food traceability is the ability to trace and follow a food, feed or ingredient through all stages of production, processing and distribution. In the EU, Article 18 of Regulation (EC) 178/2002 requires it of every operator: knowing who supplied each product and whom it was delivered to. The EUDR adds plot geolocation and due diligence for seven commodities. Making it verifiable means a third party can check that each record existed on a date and has not changed.
This guide is the pillar of Proovik's traceability cluster: what the general rule asks for, what the deforestation regulation adds, and the difference between having records and being able to prove them. The technical detail of the event standard is on the EPCIS 2.0 traceability page.
What Regulation (EC) 178/2002 requires
Regulation 178/2002 is the EU's General Food Law: it lays down the principles (risk analysis, precaution, operator responsibility) and creates the European Food Safety Authority. Its Article 18 has been the basis of all European food traceability since 1 January 2005.
One step back, one step forward
The obligation is simple to state and demanding to meet: every operator must be able to identify who supplied a product (one step back) and which businesses received it (one step forward). To do so it must have systems and procedures that make the information available to the competent authorities on demand. The regulation prescribes no format: a well-kept spreadsheet complies; a system that cannot rebuild a lot within hours does not.
What the general rule does not require
- It does not require internal traceability (which ingredients went into which finished lot), although without it a lot withdrawal turns into the withdrawal of a whole day's output.
- It does not require any particular technology, a central register or records verifiable by third parties: they only have to exist and be handed over.
Rules that build on it
Sector rules sit on top of that base: Implementing Regulation (EU) 931/2011 specifies the information that travels with food of animal origin (lot, volume, consignor, consignee, dispatch date); Regulation (EU) 1169/2011 governs consumer information; Regulation (EU) 2017/625 organises official controls. All demand a reliable record per lot.
What the EUDR adds (Regulation (EU) 2023/1115)
Regulation (EU) 2023/1115 on commodities and products associated with deforestation raises the bar: knowing who supplied the product is no longer enough, you must show which plot it came from and that the plot was not deforested after 31 December 2020.
- Commodities in scope (Annex I): cattle, cocoa, coffee, oil palm, rubber, soya and wood, plus a long list of derived products (chocolate, leather, furniture, paper, tyres, palm oil...).
- Three conditions (Article 3): the product must be deforestation-free, produced in accordance with the relevant legislation of the country of production, and covered by a due diligence statement.
- Geolocation (Article 9): the operator must collect the coordinates of all plots where the commodity was produced, with the date or time range of production. Geolocation is defined as latitude and longitude with at least six decimal digits; above four hectares, polygons.
- Due diligence statement: submitted in the Commission's information system before placing on the market or exporting, with a reference number that follows the product downstream.
- Record keeping (Article 31): due diligence documentation is kept for at least five years.
Timeline
The regulation entered into force on 29 June 2023. Its application was postponed by a year through Regulation (EU) 2024/3234 and, after a second postponement adopted at the end of 2025, the expected date is 30 December 2026 for medium and large companies and 30 June 2027 for micro and small enterprises. These dates may change again: check the Commission's official timeline before planning (link in the sources).
For coffee, cocoa or soya, the evidence (coordinates, dates, contracts, analyses) must exist before the first sale in the EU and still be intact five years later. There is a concrete case in coffee traceability with blockchain.
Records that exist versus records you can prove
An inspector, a buyer or a certification auditor does not only ask whether you have the data. They ask when you recorded it and whether it is the same data that was there at the time. An internal ERP can rewrite its history; so can a conventional EPCIS repository if it is run by the same company that feeds it. The difference between the options lies in who can alter the past and whether an outsider can check.
| System | Who can modify the history | Proof of when it was recorded | Third-party verification |
|---|---|---|---|
| Spreadsheet or internal ERP | Any user with permissions | The date the system itself writes | Only by trusting the company |
| Classic EPCIS repository | The repository operator | The repository's recordTime | With access to the repository and trust in it |
| EPCIS events hash-chained and anchored on a public blockchain | Nobody without breaking the hash chain | The block timestamp, covered by proof of work | Anyone, with the proof file, without asking permission |
Anchoring does not replace the record: it seals it. The content stays in your systems; only the hash (32 bytes) goes on chain, and it reveals neither supplier, price nor coordinates.
How to design records that survive an inspection
- Identify with standard keys. GTIN for the product, lot number, GLN for facilities and SSCC for logistic units. With GS1 keys the same data reads the same in your ERP, your customer's and the authority's system.
- Record events, not just states. Every movement answers what (identifiers), when (date, time and time zone), where (read point and business location) and why (business step: receiving, transformation, shipping). That is the EPCIS 2.0 model.
- Keep the time zone. An event without a UTC offset is ambiguous in a chain that crosses continents. EPCIS makes it mandatory; so should you.
- Chain and seal. Each event carries the hash of the previous one; the event hash is anchored on a public blockchain. If someone changes an old event, the chain breaks and it shows.
- Attach documentary evidence by hash. Lab analyses, contracts, plot polygons: no need to upload them anywhere, sealing their fingerprint is enough. You can do it with any file from the certify page.
- Rehearse a recall. Measure how long it takes to identify every destination of a lot. If the answer is days, the system is not fit for purpose.
What the law says
Regulation (EC) 178/2002, Article 3(15): "'traceability' means the ability to trace and follow a food, feed, food-producing animal or substance intended to be, or expected to be incorporated into a food or feed, through all stages of production, processing and distribution".
Regulation (EC) 178/2002, Article 18(1): "The traceability of food, feed, food-producing animals, and any other substance intended to be, or expected to be, incorporated into a food or feed shall be established at all stages of production, processing and distribution". Paragraphs 2 and 3 require operators to identify suppliers and recipients and to have systems that make that information available to the authorities; paragraph 4 requires labelling or identification that facilitates traceability.
Regulation (EU) 2023/1115, Article 9: among the information the operator must collect is the geolocation of all plots of land where the relevant commodities were produced, together with the date or time range of production. Article 2 defines geolocation by latitude and longitude with at least six decimal digits and requires polygons for plots larger than four hectares (except for cattle).
Regulation (EU) 910/2014 (eIDAS), Article 41(1): "An electronic time stamp shall not be denied legal effect and admissibility as evidence in legal proceedings solely on the grounds that it is in an electronic form or that it does not meet the requirements of the qualified electronic time stamp". The stamp Proovik produces is a non-qualified electronic time stamp: admissible, without the presumption of accuracy of paragraph 2, which is reserved for qualified stamps.
How to do it with Proovik
Proovik records EPCIS 2.0 events validated against the GS1 schema, chains them by hash, lets each actor sign its own events and anchors the hashes on the Kaspa network, which produces about ten blocks per second, so a seal is normally confirmed within seconds. Every lot gets a public verification URL and a consumer QR code; the proof package can be checked without Proovik by following the public specification on the verify page. Integration is through the API or the traceability dashboard.
What it proves: that an event with that content existed no later than the block timestamp and has not been modified since. What it does not prove: that the content is true, that it was recorded by whoever claims to have recorded it (that is what per-actor signatures and, where needed, a qualified electronic signature are for), or that you comply with 178/2002 or the EUDR. Compliance depends on the data being what the rule requires and on filing it where and when it is due; Proovik gives you the evidence that it existed and that nobody touched it.
Frequently asked questions
Does Regulation 178/2002 require blockchain or any specific software?
No. It requires you to identify suppliers and recipients and hand that information to the authorities. The format is free. Blockchain adds something different: the date and integrity of the records can be checked without trusting whoever stores them.
Who is affected by the EUDR?
Any company that places on the EU market, makes available or exports cattle, cocoa, coffee, oil palm, rubber, soya or wood and the derived products in Annex I. Obligations are heavier for operators (whoever first places the product) than for traders, and SMEs have a lighter regime and a later deadline.
Can I seal plot coordinates without publishing them?
Yes. Only the hash of the file (for example the GeoJSON of the polygons) is written on chain. The coordinates stay in your systems. When you need to prove the file existed on a date, you show the file and anyone recomputes the hash.
Does a blockchain timestamp count as evidence before an authority?
It is a non-qualified electronic time stamp under the eIDAS Regulation: it cannot be denied legal effect for being one (Article 41(1)), but it does not carry the presumption of accuracy of Article 41(2). Its strength is that the check is arithmetic and the authority itself can repeat it. The final assessment belongs to whoever adjudicates.
Sources
- Regulation (EC) 178/2002, consolidated text on EUR-Lex: eur-lex.europa.eu/eli/reg/2002/178/oj
- Implementing Regulation (EU) 931/2011 (traceability of food of animal origin): eur-lex.europa.eu/eli/reg_impl/2011/931/oj
- Regulation (EU) 2023/1115 (EUDR): eur-lex.europa.eu/eli/reg/2023/1115/oj
- Regulation (EU) 2024/3234 (first postponement of the EUDR): eur-lex.europa.eu/eli/reg/2024/3234/oj
- European Commission page on the EUDR, with the current timeline: environment.ec.europa.eu
- Regulation (EU) 910/2014 (eIDAS): eur-lex.europa.eu/eli/reg/2014/910/oj
- EPCIS 2.0, GS1 standard: ref.gs1.org/standards/epcis
Proovik team. Published 14 September 2026; regulatory references last reviewed on 6 September 2026.