EU Market Surveillance: Duties, Databases, and Enforcement

EU market surveillance is the system the European Union uses to keep unsafe and non-compliant products off its single market, combining customs checks at the border, inspection powers held by national authorities in each member state, rapid digital alert networks, and legal duties placed on manufacturers, importers, distributors, fulfilment providers, and online marketplaces. The framework applies to nearly every non-food product sold in the EU, whether made inside the bloc or imported, and it has expanded sharply since the General Product Safety Regulation took effect on December 13, 2024.

What the System Covers

Regulation (EU) 2019/1020 is the main legal framework for surveillance of non-food products across the European market.1EUR-Lex. Regulation (EU) 2019/1020 on Market Surveillance and Compliance of Products Toys, electronics, personal protective equipment, machinery, construction materials, and radio equipment all fall within its reach, along with dozens of other categories. It applies across every sales channel, from physical retail to online marketplaces and direct-to-consumer websites.

Where no sector-specific EU legislation governs a consumer product, the General Product Safety Regulation (GPSR), Regulation (EU) 2023/988, acts as the default safety net.2EU-OSHA. Regulation 2023/988/EU – General Product Safety Under the GPSR, only safe products may be placed on the market, manufacturers must conduct a risk analysis and prepare technical documentation, and each product must carry information allowing it to be traced through the supply chain.

Medical devices and in vitro diagnostics sit outside this general framework. They are policed under their own vigilance rules, with adverse-incident data shared between regulators through the restricted Eudamed database.3European Commission (Public Health). Market Surveillance and Vigilance If your product is a medical device, the general market surveillance regulation is not the rulebook you work from.

Who Has to Answer for a Product

The system is built so that someone inside the EU is always accountable for every product on the market. For goods covered by EU harmonization legislation, Regulation 2019/1020 requires a “responsible person” established in the EU. That role can be filled by the manufacturer itself (if EU-based), an importer, an authorized representative appointed by a non-EU manufacturer, or, as a fallback, a fulfilment service provider that handles the product.

The responsible person has to keep the EU Declaration of Conformity and technical documentation available to market surveillance authorities for ten years, hand over any information needed to demonstrate compliance on request, cooperate on corrective actions, and inform authorities immediately when a product presents a risk. When no manufacturer, importer, or authorized representative is established in the EU, those duties fall on the fulfilment service provider handling storage and shipping. That closes a gap that once let overseas sellers ship through third-party logistics without any EU-based party legally on the hook.

CE Marking and the Declaration of Conformity

Manufacturers carry out the conformity assessment, build the technical file, issue the EU Declaration of Conformity, and affix the CE marking.4European Commission. CE Marking Applying the CE marking is the manufacturer’s declaration that the product meets all applicable legal requirements and can be sold throughout the European Economic Area. Depending on the product category, the assessment may be done by the manufacturer alone or may require an independent notified body.5Your Europe. CE Marking

The Declaration of Conformity has fixed mandatory content: the manufacturer’s name and full business address, the product’s serial number or model identification, a statement accepting full responsibility, a means of traceability such as a product image, the details of any notified body involved, a list of the specific legislation and harmonized standards the product meets, and the manufacturer’s signature and date.6Your Europe. Signing the Declaration of Conformity It must be updated whenever applicable legislation or standards change.

Importers have their own verification duty. Before placing a product on the market, the importer must confirm that the manufacturer has carried out the conformity assessment, that CE marking is correctly applied, and that the required documentation exists. Skip these checks and bring in something non-compliant, and the importer faces the same enforcement consequences as the manufacturer.

What Online Marketplaces Must Do

The GPSR pulled online marketplaces directly into the enforcement chain. Every marketplace must designate a single point of contact for market surveillance authorities on product safety matters and a separate contact point for consumers, register on the Safety Gate portal, and put internal product safety processes in place.

Deadlines are tight. When authorities order the removal of a dangerous product, the marketplace has two working days to act. Safety-related notices received through the Digital Services Act framework must be processed within three working days. Marketplace interfaces have to force sellers to provide the manufacturer’s name and contact details, the identity of any EU-based responsible person, product identification, and any required safety warnings before a listing can go live. Marketplaces are also required to suspend sellers that repeatedly offer non-compliant products.

What National Authorities Can Do

Each EU member state runs its own market surveillance authorities, and their powers are broad. Inspectors can make unannounced visits to retail outlets, warehouses, and manufacturing sites. They can demand full technical dossiers and test reports from any economic operator in the supply chain, and they routinely pull product samples for independent laboratory testing.

When a product fails, authorities can order an immediate recall from consumers, withdraw the product from distribution, prohibit its sale, or, where the risk is serious, seize and destroy the goods. These actions come with formal notices setting strict deadlines for the business to fix the problem.

Penalties are set by each member state rather than by a single EU-wide fine schedule, so the financial exposure varies with where enforcement happens. Fines are generally scaled to the severity of the infringement and the size of the business, and most member states also allow daily penalty payments to push companies to complete a recall or produce requested documentation.

How Customs Screens Imports

Customs authorities are the first filter before goods enter free circulation. Under Regulation 2019/1020, customs officials can suspend the release of any product that appears to present a risk or that lacks required documentation, markings, or labeling. Suspension triggers a notification to the relevant market surveillance authority, which then decides whether the product complies.

If the surveillance authority finds the product non-compliant or dangerous, it can prohibit market placement, and goods that pose a serious risk may be destroyed. The economic operator pays for storage and destruction. If the surveillance authority does not act within the prescribed timeframe, the product is released, a design feature meant to prevent goods from sitting in limbo indefinitely.

A 2026 EU customs enforcement operation found that most third-country e-commerce goods examined did not comply with EU product safety rules, and refusals at the border increased significantly.7Taxation and Customs Union. Large Scale EU Customs Control Action Shows Most Third-Country E-Commerce Goods Do Not Follow Standards

The Databases That Run the System

Safety Gate

Safety Gate is the EU’s rapid alert system for dangerous non-food products. When a national authority identifies a serious risk, it uploads a notification that is shared immediately with all member states and the European Commission, covering the product, the risk, and the measures taken.8European Commission. Safety Gate: The EU Rapid Alert System for Dangerous Non-Food Products A public-facing version lets consumers search current recalls, updated weekly. In 2024, Safety Gate validated 4,137 alerts, the highest number since the system was created.9Safety Gate. The Safety Gate Rapid Alert System in 2024

ICSMS

The Information and Communication System on Market Surveillance (ICSMS) is a separate platform used for day-to-day coordination between surveillance bodies across the EU and EFTA.10European Commission. Information and Communication System on Market Surveillance (ICSMS) Where Safety Gate handles urgent alerts, ICSMS stores inspection results, test data, and compliance histories, so inspectors in one country can see whether another has already tested a product before duplicating the work. Its internal area is restricted to surveillance, customs, and EU authorities.

The Safety Business Gateway

The Safety Business Gateway is the mandatory reporting portal businesses use to notify authorities of dangerous products and accidents.11EUR-Lex. Commission Notice: Guidelines for the Safety Business Gateway Under Article 27(2) of Regulation (EU) 2023/988 Manufacturers, authorized representatives, importers, distributors, fulfilment service providers, and online marketplace providers all have reporting obligations through it.

Triggers are straightforward. If a business considers or has reason to believe a product is dangerous, it must report. Accidents causing death, serious injury, illness, or chronic health effects must be reported without undue delay from the moment the business learns of them. Importers that place a dangerous product on the market must inform authorities immediately, and distributors must make sure authorities are notified of irregularities if the manufacturer or importer has failed to do so. Waiting to see how a suspected problem plays out is not a legal option; the obligation attaches as soon as there is reason to suspect one.

What Is Coming for Digital Products and AI

The Cyber Resilience Act

The Cyber Resilience Act pulls connected devices and software into the same enforcement logic. From September 11, 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe security incidents through a new Single Reporting Platform.12Shaping Europe’s digital future. Cyber Resilience Act – Reporting Obligations The clocks are short:

  • Early warning within 24 hours of becoming aware of the vulnerability or incident
  • Full notification within 72 hours
  • Final report for vulnerabilities within 14 days after a corrective measure becomes available
  • Final report for severe incidents within one month

Reports go to the CSIRT where the manufacturer is established and are shared with ENISA and any other affected CSIRTs. The full set of product compliance obligations under the Act applies from December 11, 2027.13Shaping Europe’s digital future. Cyber Resilience Act

The AI Act

AI systems classified as high-risk under the EU AI Act face their own conformity assessment requirements, with rules for systems listed in Annex III applying from August 2, 2026.14AI Act Service Desk. Timeline for the Implementation of the EU AI Act The assessment path depends on the category of AI system and whether the provider has applied harmonized standards. Some high-risk systems can be assessed internally; others require a notified body.

Penalties are heavier than those under traditional product safety law. Using a prohibited AI practice can bring fines of up to €35 million or 7% of worldwide annual turnover, whichever is higher. Non-compliance with high-risk system obligations carries fines of up to €15 million or 3% of global turnover. Supplying misleading information to regulators can trigger penalties of up to €7.5 million or 1% of turnover. Smaller enterprises pay the lower of the fixed amount or the turnover percentage.