Many small sellers and new brands that have just entered the EU market often encounter such confusions: My product does not have corresponding CE safety regulations, such as ordinary plastic water cups and household storage racks. Do I still need to do safety compliance? For products that already have the CE mark, do I not need to worry about other safety requirements? Is it necessary to find a third-party institution to do risk assessment at a high cost?
The core of these questions points to the EU general product safety rule system: GPSD (General Product Safety Directive) is the old catch-all rule, and GPSR (General Product Safety Regulation, Regulation (EU) 2023/988) has officially replaced the GPSD as of December 13, 2024, and is applicable throughout the EU. This set of rules is the general safety catch-all rule applicable to consumer products placed on the EU market — for products covered by special EU safety regulations (such as CE-type directives/regulations), special regulations take precedence, and GPSD/GPSR only supplement and cover safety risks, usage scenarios or product categories not involved in special regulations, while risk assessment is the core compliance link of this set of rules.
This article covers basic definitions, practical steps, qualification judgment, responsibility boundaries and key points of new regulation adaptation, to help you independently complete the risk assessment of ordinary products and avoid common invalid pitfalls.
1. Basic Understanding: First Figure Out What It Is, Who Needs to Do It, and How It Applies
Plain Language Explanation of Core Concepts
The EU has special CE-type safety regulations for high-risk products such as toys, electrical appliances, and medical devices, but more ordinary consumer goods that are not fully covered by special regulations are covered by the general product safety rules as a catch-all. The core requirement is that “products must not pose unreasonable safety risks to consumers”.
The positioning of risk assessment differs under the two sets of rules:
- Under the old GPSD framework, it is a compliance demonstration process to prove product safety, with no mandatory unified format, as long as the logic is reasonable and can prove product safety.
- Under the current GPSR regulation, it is a statutory work that manufacturers must complete, and formal technical documents must be formed as the core component of the product safety file.
Before talking about specific requirements, let’s explain several commonly heard terms in plain language:
- Hazard: A specific point on a product that can cause injury, such as sharp burrs on a cup or slippery foot pads on a ladder.
- Risk: Not just the hazard itself, but a combination of “the probability of injury” and “the severity of injury”. For example, for the same burr, a burr on the cup rim that is touched every day has a higher risk than a burr on the cup bottom.
- Reasonably foreseeable use: The situation where ordinary users use the product normally, including unintentional misuse due to accidental wrong use — for example, a user standing on the top rung of a ladder to reach things (although the instruction manual prohibits it, many people do this) counts; but intentionally dismantling the ladder and using it as a trampoline does not count.
- Harmonized standards: Safety standards officially recognized by the EU. As long as the product complies with these standards, regulators will presume that the product meets safety requirements. Of course, if new evidence of danger is found later, this presumption can be rebutted.
- Economic operator established in the EU: Cross-border sellers often collectively refer to them as “EU representatives”. Specifically, they can be undertaken by eligible importers, authorized representatives, fulfillment service providers and other entities. They are the compliance responsible persons of overseas enterprises within the EU, representing overseas enterprises to liaise with EU regulators and fulfill compliance obligations.
Timing and Transition Instructions
The key timeline is clarified here: as of December 13, 2024, the old GPSD has been officially replaced by the GPSR, which is directly applicable as an EU regulation.
This does not mean that the knowledge of the old GPSD is completely useless: the old assessment logic can still be used to understand historical compliance documents, but new products and products continuously sold in the EU need to be reviewed or updated in accordance with GPSR requirements. Old GPSD assessment documents cannot be directly equated with GPSR compliance documents, and the specific adaptation methods will be explained in detail at the end.
Boundary of Applicable and Non-Applicable Products
To judge whether a product needs a GPSR risk assessment, the core rule is very simple: special product safety regulations (such as CE-type directives/regulations) take precedence, and the GPSR only serves as a catch-all, covering safety risks, usage scenarios or product categories not covered by special regulations.
Common applicable products are ordinary consumer goods not fully covered by special EU safety regulations, such as plastic water cups, household storage racks, ordinary outdoor tools, non-professional home decorative ornaments, etc.
Explicitly non-applicable products include: food, pharmaceuticals, antique collectibles, private custom non-commercial products, non-commercial second-hand products, and military products.
A common question is added here: Do products that already have CE certification still need to do a GPSR risk assessment? The answer is no need to repeat the full set, only need to supplement the general risk analysis not covered by the special regulations — for example, an electrical appliance has passed the CE Low Voltage Directive (covering electric shock risk), but if the directive does not cover mechanical injury from sharp corners of the casing, this part of the assessment needs to be supplemented.
Market Subjects Obligated to Fulfill Duties
The obligations of GPSD/GPSR are not only for manufacturers, but subjects in the entire circulation chain have corresponding responsibilities:
- Primary responsible party: Manufacturer or brand owner — that is, the entity that designs, produces, and affixes its own brand, is fully responsible for product safety.
- Circulation responsible parties: Importers, distributors, offline merchants, online merchants and e-commerce platforms, bear corresponding verification and traceability obligations.
Cross-border sellers should pay special attention: as long as they sell products to EU consumers, they fall within the EU’s jurisdiction. In the GPSD era, the responsibility requirements for overseas sellers were relatively loose, but after the GPSR takes effect, merchants outside the EU that sell products to EU consumers must appoint an economic operator established in the EU, otherwise they cannot sell in the EU.
Actual Consequences of Non-Compliance
Don’t think that risk assessment is just a formality. If it is not done well, the actual impact will be very direct:
- Goods are detained by customs after arriving at the port and cannot be cleared; e-commerce platforms directly remove products from shelves, or even freeze stores.
- Punished by the market supervision departments of EU member states. The amount of fines varies according to national regulations, and there is no unified standard. In serious cases, criminal liability may also be involved.
- Triggering product recalls will not only incur the cost of returns and destruction, but also seriously affect brand reputation.
Judging from the EU Safety Gate notifications and the market spot check practices of member states, the lack of traceable safety demonstration or risk assessment materials is one of the common compliance shortcomings of sellers; there is no EU-wide unified value for the specific unqualified rate of spot checks and penalty standards, which shall be subject to the rules of each member state.
2. Statutory Core Requirements: Only When These Are Met Can the Assessment Be Considered Valid
After clarifying the basic concepts, let’s talk about the core requirements that a legal and valid risk assessment must meet — these are clearly stipulated by EU regulations, and you can’t just write a random document to count.
3 Basic Principles That Must Be Followed
These three principles are the underlying logic of risk assessment, and all assessment work must be carried out around them:
- Based on reasonably foreseeable use: The assessment cannot only be based on the “correct usage” in the instruction manual, but also cover common unintentional misuse by ordinary users, such as users overloading storage racks, installing parts backwards, etc.; intentional damage and obvious abuse of the product do not need to be included.
- Cover the entire product life cycle: Not only consider the user’s use stage, but also cover the entire stage from production, transportation, installation, use, maintenance to scrapping. For example, whether the sharp corners of the product packaging will scratch people who unpack express deliveries, and whether there will be safety hazards when scrapping, all need to be considered.
- Prioritize the protection of vulnerable groups: The usage scenarios of groups that are more prone to injury, such as children, the elderly, and people with disabilities, need to be additionally assessed — even if the product is not sold to children, as long as children may come into contact with it (such as an ordinary water cup placed at home), the risk of children accidentally touching or swallowing it must be considered.
Statutory Considerations for Safety Judgment
The regulation clarifies 6 factors that must be considered when judging whether a product is safe, which should be covered correspondingly during the assessment:
- Product’s own characteristics: Such as materials used, structural stability, functions, service life, energy consumption, etc.
- Appearance and display method: Whether packaging, advertisements, and promotions will mislead users to use the product beyond its designed purpose — for example, if an ordinary plastic water cup is promoted as “can be directly heated in a microwave oven”, the assessment must be based on the risk after heating.
- Labels and warning information: Whether they are clear and easy to understand, and must be in a language that EU consumers can understand (for example, German for sales to Germany, French for sales to France), not only English.
- Interaction with other products: Whether there will be risks when used with common supporting products — for example, whether the sold cup lid will leak or fall off when matched with common cups of the same size on the market.
- Target consumer category: Whether it is aimed at vulnerable groups such as children, the elderly, and people with disabilities. Products aimed at such groups have stricter requirements.
- Impact of digital/network functions: If the product has software, can connect to the Internet, or has AI functions, the corresponding safety risks must also be assessed — for example, software updates of smart water cups cause temperature control failure, manipulated network functions cause overheating leakage, or sensor misjudgment causes abnormal functions resulting in physical injury; when cybersecurity and data issues directly affect the physical safety of the product, they must be included in the assessment scope, which is also a content explicitly required by the GPSR.
4 Statutory Essential Core Contents
No matter what format is used for the assessment, these four core parts are indispensable:
The first is hazard identification: Find out all possible injury-causing points of the product, without omission.
The second is likelihood assessment: Judge the probability of actual occurrence of injury, which must be based on evidence, not arbitrary.
The third is severity assessment: Judge the severity of the consequences if injury actually occurs.
The fourth is risk treatment: For unacceptable risks, put forward specific rectification measures to reduce the risk to an acceptable level.
Statutory Judgment Logic of “Safe Product”
Many people think that safety means “absolutely no injury”, but in fact the requirements in the regulations are not like this:
Absolute zero risk is not required; as long as under normal and foreseeable use, there is only a very low and acceptable risk.
The priority of judgment is: if there are EU harmonized standards, compliance with the standards can presume product safety; if there are no harmonized standards, reference can be made to mature industry practices and international general safety standards; if there are none, you must provide sufficient evidence to prove that the risk is acceptable.
Of course, this “presumption of compliance” is not absolute — if new evidence proves that the product is dangerous later, even if it meets the standards, rectification is required.
Statutory Requirements for Assessment Records
Risk assessment is not something to be thrown away after completion. It must form traceable written or electronic documents, which are stored together with other technical documents of the product.
Regarding the retention period, there was no EU-wide unified requirement in the GPSD era. It is generally recommended to retain them in accordance with the enforcement rules of the selling member states plus the product liability traceability period; while the GPSR explicitly requires that technical documents (including risk assessment) must be retained for 10 years, and must be available at any time during regulatory spot checks.
Qualification Requirements for Assessment Subjects
The question that many novices are most concerned about: is it necessary to find a third-party institution to do it for it to be valid?
The answer is: There is no mandatory requirement that it must be done by a third party. A self-completed assessment is valid as long as it is logically reasonable and evidence-based.
However, in several cases, it is recommended to find professionals or third-party institutions to do it, which is more reliable:
- Products with high mechanical, thermal, or chemical risks, such as household ladders, outdoor knives, and heating kitchenware;
- Products intended for children;
- New category products without mature industry standards.
In addition, if some risk points are not supported by public data or industry standards, such as material safety and structural strength, corresponding tests need to be supplemented, and test reports shall be used as the basis for assessment.
3. Practical Steps: Ordinary Low-Risk Products Can Be Completed by Following These Steps
If you are dealing with low-risk ordinary consumer goods such as plastic water cups, storage boxes, and towels, you can completely complete the risk assessment by yourself following the steps below, without spending a lot of money on a third party.
Step 1: Collect Basic Product Information
Before doing the assessment, first clarify the basic information of the product to avoid missing items later:
- Product model, designed use, target user group, main sales channels;
- Materials used in the product, structural characteristics, sources of key components;
- Records of accidents, complaints, and recalls of similar products — you can query on the EU Safety Gate notification platform to see what safety problems have occurred in similar products, and conduct early investigation;
- Product service life, maintenance and cleaning requirements.
Step 2: Clarify the Priority of Assessment Basis
Assessment cannot be based on feeling, it must have a basis. Different bases have different probative force, and can be prioritized from high to low as follows:
| Priority | Type of Basis | Example |
|---|---|---|
| Highest | EU harmonized standards (EN standards), EU RAPEX/Safety Gate official risk assessment guidelines | EN 14350 (Safety standard for children’s drinking utensils) |
| Second | CEN/CENELEC European standards, ISO/IEC general safety standards | ISO 12100 (General approach to mechanical safety design) |
| Third | Member state industry standards, mature industry practices | Household product safety guidelines issued by the German Federal Institute for Occupational Safety and Health |
| Fourth | Accident/recall/complaint data of similar products, third-party test reports | Recall notifications of similar water cups on Safety Gate, material food contact test reports |
| Lowest | Industry expert experience judgment | Expert qualification certificates must be attached, and cannot rely solely on personal experience |
Note the distinction between two types of Safety Gate-related resources: the Safety Gate notification platform is mainly used to query accidents, recalls and risk clues of similar products; the risk rating method can refer to the official risk assessment guidelines issued by EU RAPEX/Safety Gate. Do not confuse the two functions. Try to use high-priority bases, so that the assessment is more persuasive and easier to pass during regulatory spot checks.
Step 3: Identify All Potential Hazards
Next is the core hazard identification link. It is recommended to check one by one from three dimensions to avoid omission:
- Product itself: Whether there are possible injury-causing parts in structure, materials, energy (such as heat, electricity, noise);
- Usage scenarios: Whether there will be risks during installation, use, cleaning, and storage;
- User groups: Whether there will be special risks when used by ordinary users and vulnerable groups (children, the elderly, people with disabilities).
Common hazard types are roughly as follows: mechanical injury (cuts, pinches, falls), thermal injury (scalds, fires), chemical injury (poisoning, allergies), suffocation (swallowing of fallen small parts), electric shock, noise or radiation injury.
Here, be sure to cover reasonably foreseeable misuse, such as children accidentally swallowing small parts, users overloading storage racks, installing parts backwards, etc. Intentional abuse does not need to be included.
Step 4: Assess Risk Level
After identifying all hazards, it is necessary to rate the risk of each hazard. You don’t have to worry about using any complex formula, as long as the logic is self-consistent. Generally, you can follow these steps:
- Sort out the hazard occurrence chain: For example, “there is a burr on the edge of the water cup → the user touches it when holding it → the hand is cut and skinned”, clarify the entire process from hazard to injury to avoid judgment out of thin air.
- Judge exposure frequency: The frequency with which users are exposed to this hazard, whether it is daily, weekly, monthly, or rarely exposed.
- Judge occurrence likelihood: The probability of actual occurrence of injury is divided into several grades: high, medium, low, negligible. Each grade must have a basis — for example, “if the cup rim burr is not polished, the probability of cuts is medium”, you can’t just say “I think the probability is low”.
- Judge injury severity: If injury actually occurs, how serious the consequences are, generally divided into four grades: minor (such as abrasion), moderate (such as mild scald, requiring simple treatment), severe (such as fracture, requiring hospitalization), fatal (may cause death).
- Calculate initial risk level: You can use the simple logic of “exposure frequency × likelihood × severity”, or use the commonly used risk matrix in the industry, and divide it into three grades: high, medium, low.
It should be specially noted here that neither GPSD nor GPSR mandates the use of a unified rating matrix or formula. As long as the logic is reasonable and evidence-based, it is valid, and there is no need to force a 5×5 matrix. If you use the following two-dimensional risk matrix commonly used in the industry, you can first use exposure frequency as an adjustment factor for occurrence likelihood (for example, the higher the exposure frequency, the higher the likelihood rating by one grade); if you choose to use exposure frequency as a separate scoring item, you need to clearly explain the specific rules for combining the three indicators into a risk level in the report, to ensure logical self-consistency.
| Severity \ Occurrence Likelihood | Negligible | Low | Medium | High |
|---|---|---|---|---|
| Minor | Low | Low | Low | Medium |
| Moderate | Low | Low | Medium | Medium |
| Severe | Low | Medium | Medium | High |
| Fatal | Medium | Medium | High | High |
Step 5: Take Corresponding Risk Control Measures
After assessing the risk level, measures must be taken for unacceptable risks. There is a statutory control priority here that must be followed:
Design to eliminate hazards > Install protective devices > Affix warning labels/write instruction manuals
It is absolutely not allowed to use warning labels instead of high-risk design rectification in reverse — for example, if a product has a high risk of pinching hands, you can’t just stick a “beware of pinching” label and be done. You must first modify the design so that it cannot pinch hands. If it really cannot be modified, add protective devices, and finally the remaining low risks can be reminded with warnings.
Treatment requirements for different risk levels are also different:
- High risk: Must be eliminated through design or structural rectification. Products that fail rectification must never be placed on the market.
- Medium risk: Prioritize rectification. If it is really impossible to solve through design or protection, clear and easy-to-understand warnings can be added to cover the remaining risks.
- Low risk: It is within the acceptable range, and no additional measures are needed.
After rectification, verification is also required: confirm that the rectification will not introduce new hazards, and that the original risk has indeed been reduced to an acceptable level. For all remaining risks that cannot be completely eliminated, the basis for acceptability must be clearly written.
Step 6: Organize and Retain the Assessment Report
The process and results of the risk assessment shall be organized into documents for preservation. There is no restriction on the form, which can be tables, checklists, or documents. The core requirement is complete logic and traceability.
A qualified assessment report must at least include the following contents:
- Basic product information: model, batch, version number, product pictures, designed use, target group;
- Basic assessment information: assessment date, assessor/approver, list of applicable regulations and standards;
- Core assessment content: hazard list, rating basis for each risk, control measures taken and verification results, comparison before and after risk control, description of remaining risks;
- Final conclusion: whether the product meets safety requirements, whether it can be placed on the market;
- Version change record: reason for each assessment update, updated content, update date.
In practice, it is recommended to record each hazard row by row, and each row correspondingly includes: hazard occurrence chain, exposure frequency, likelihood basis, severity basis, initial risk level, control measures, verification evidence, remaining risk level, acceptable reason, to ensure that the assessment process of each risk is traceable. After sorting out, put it together with other technical documents of the product for easy retrieval during regulatory spot checks.

Step 7: Post-Marketing Continuous Monitoring
Risk assessment is not a once-and-for-all thing. After the product is launched, continuous monitoring is required:
- Regularly collect consumer complaints and pay attention to recall information of similar products (can query the Safety Gate platform);
- If there are situations such as product modification, replacement of core components, discovery of new safety hazards, update of regulations or harmonized standards, occurrence of accidents or batch complaints, or recall of similar products, the assessment must be re-done and the documents updated.
If the product has not been sold for a long time and is re-launched later, the assessment must also be re-reviewed to ensure compliance with the latest requirements.
4. Qualification Judgment: How to Verify Whether an Assessment Is Sufficient
If you have already done an assessment, or want to check whether the assessment done by others is qualified, you can verify it against the following core checkpoints, which can also help you avoid many pitfalls of invalid assessments.
4 Core Checkpoints for Qualified Assessment
A qualified risk assessment must at least meet these four requirements:
First, full scenario coverage. It includes normal use, reasonably foreseeable misuse, full life cycle, and usage scenarios of vulnerable groups, with no obvious omissions — for example, only assessing normal use without considering children’s accidental contact is unqualified.
Second, rating is evidence-based. The exposure frequency, occurrence probability, and severity of each risk are supported by corresponding evidence, such as test reports, accident data, industry standards, not the subjective “I think it’s okay”.
Third, high risks have substantial rectification. All high risks are eliminated through design or structural rectification, and there is no situation where only warning labels are used to avoid responsibility.
Fourth, records are traceable. There are complete written or electronic documents that can trace the entire process of the assessment: what basis was used, who did it, when it was done, whether it has been updated, and what the reason for the update is.
Differences in Assessment Depth for Different Products
Not all products need to be assessed in the same detail. The higher the risk, the stricter the requirements, and the higher the level of evidence required:
- Low-risk products (such as plastic water cups, towels, storage boxes): Can be simplified, focus on investigating obvious hazards, no need for complex tests, as long as there is a reasonable basis.
- Medium and high-risk products (such as outdoor knives, household ladders, kitchen heating appliances): Detailed assessment is required, and each risk point must be supported by test data or industry cases.
- Children’s products: Must additionally consider various misuse scenarios of children, such as accidental swallowing, climbing, biting, and the requirements are much stricter than adult products.
- Products with software/network connection: Must additionally assess product safety risks brought by cybersecurity and software updates, such as functional abnormalities caused by software updates, dangerous states caused by cyber attacks, which is also explicitly required by the GPSR.
The principle of judgment is very simple: the more serious the injury the product may cause, and the more vulnerable the target group, the more detailed the assessment must be.
Validity Period of Assessment and Update Trigger Conditions
Many people ask how long the validity period of a risk assessment is. The answer is: There is no fixed validity period. As long as the product, regulations, and standards have not changed, it will always be valid.
But if the following situations occur, the assessment must be updated:
- Product modification, replacement of core components;
- Discovery of new safety hazards;
- Relevant regulations or harmonized standards are updated;
- The product has accidents, batch complaints, or similar products are recalled.
In addition, if the product is re-launched after a long-term suspension of sales, the assessment must also be re-reviewed to ensure compliance with the latest requirements.
Core Differences from CE-Type Special Regulation Assessments
Many people can’t figure out the relationship between GPSR assessment and CE certification. In fact, they are two systems, and the core differences are as follows:
| Comparison Dimension | CE-Type Special Regulation Assessment | GPSD/GPSR Risk Assessment |
|---|---|---|
| Scope of application | For products with special safety regulations (such as toys, electrical appliances, medical devices), special regulations take precedence | Catch-all rule, only covering risks, scenarios or product categories not covered by special regulations |
| Clarity of requirements | Usually have clear basic safety requirements, conformity assessment paths, and technical document requirements | No unified test or assessment requirements, as long as the logic is reasonable and evidence-based |
| Third-party requirements | Some high-risk products require EU notified bodies to participate in certification | Can be completed independently, no mandatory third-party requirements |
Products that have obtained CE certification do not need to repeat the full set of GPSR risk assessment, and only need to supplement the general risk analysis not covered by special regulations.
Differences Between Test Reports and Risk Assessments
There is another common confusion: thinking that having a test report is equivalent to having done a risk assessment. In fact, the two are completely different:
- Test report: It is evidence to verify a single indicator, such as how much temperature the material can withstand, how much tension the structure can bear, and it is a supporting material for risk assessment.
- Risk assessment: It is a complete process of systematically analyzing all hazards, usage scenarios, and user groups, covering the entire product life cycle and all possible risks.
They are complementary, not substitutive. A test report cannot be used alone as the entire content of a risk assessment.
5. Compliance Responsibilities of Different Market Subjects
The obligations of the GPSR do not only fall on manufacturers; every entity in the entire circulation chain has corresponding responsibilities.
Manufacturers/Brand Owners (Including EU Economic Operators)
Manufacturers or brand owners are the primary responsible subjects and are fully responsible for product safety.
- Under GPSD: Need to ensure that products meet general safety requirements, and retain compliance demonstration materials.
- Under GPSR: Must complete a formal internal risk assessment, establish product safety files, and retain technical documents for 10 years.
Core obligations include: completing risk assessment before marketing, retaining all documents, proactively recalling risky products, and updating assessment documents in a timely manner. Even for OEM or custom products, the brand owner still has to bear the corresponding safety responsibility and cannot push all the responsibility to the factory.
Importers to the EU
Importers are the first checkpoint for products entering the EU, and their responsibilities are also significant:
- Under GPSD: Need to verify the safety compliance of products, and cannot import unsafe products.
- Under GPSR: Also need to verify whether the manufacturer has completed the risk assessment, whether it has appointed an EU economic operator, and retain the supply traceability information.
Importers must also mark their name, address and contact information on the product, and cooperate with the regulatory traceability work.
Distributors/Offline Merchants
The responsibilities of distributors and offline merchants are relatively lighter, but they are not completely without obligations:
- Need to verify the safety certification of products, and cannot sell products with obvious safety hazards;
- Need to keep the information of supply sources well, and cooperate with the regulatory traceability work;
- Under GPSR, also need to cooperate with the recall actions of manufacturers or importers, such as notifying consumers who purchased, and returning problematic products.
Online Merchants/E-commerce Platforms (Applicable to Cross-border E-commerce)
This is the part that cross-border sellers are most concerned about. The requirements of GPSR for online sales are much stricter than in the GPSD era:
- Under GPSD: The requirements are relatively loose, as long as you don’t sell obviously unsafe products.
- Under GPSR:
- Online product pages must display product identification information, information of manufacturers and EU responsible entities, necessary safety warnings or safety instructions, and the unique product identification code in accordance with applicable requirements;
- E-commerce platforms must verify merchant qualifications, establish a disposal mechanism for illegal products, and promptly remove unsafe products from shelves;
- Merchants outside the EU that sell products to EU consumers must appoint an economic operator established in the EU, otherwise they cannot sell on the platform.
6. Common Misconceptions and Practical Cases
Many people’s risk assessments are invalid because they have fallen into the following pitfalls. We use an actual case to help you understand the correct approach.
Common Cognitive Misconceptions for Novices
- Misconception: It must be done by a third-party institution to be valid
Correct answer: There is no mandatory third-party requirement. A self-assessment is valid if it is logically reasonable and evidence-based. It is recommended to seek professional support for high-risk products, children’s products, and new categories. - Misconception: With the CE mark, there is no need to do risk assessment
Correct answer: CE only covers the risks required by special regulations, and uncovered general risks still need supplementary assessment, no need to redo the full set (see 4.4 for details). - Misconception: Risk assessment is just a formality, just write it casually
Correct answer: Regulators will check the rationality of the assessment, and you need to bear responsibility if an accident occurs. An invalid assessment is equivalent to not doing it, and may even be deemed as intentional evasion of responsibility. - Misconception: It is okay to make up the assessment after the product is launched
Correct answer: Risk assessment is a pre-marketing condition, which must be completed before the product enters the EU market. Making it up after marketing is already a violation. - Misconception: Small-batch/cross-border e-commerce can be exempted from obligations
Correct answer: As long as you sell products to EU consumers, you have compliance obligations, regardless of the batch size, and regardless of whether you are in the EU or not. Small batches are not exempted.
Practical Misconceptions That Lead to Invalid Assessments
- Misconception: Copy the general template without analyzing the actual situation of the product
Pitfall avoidance: The hazards of each product are different. You must list the hazards for your own product, and cannot directly copy the general template on the Internet. - Misconception: Only assess normal use, not consider reasonably foreseeable misuse
Pitfall avoidance: Before doing the assessment, first list the common wrong operations that users may make, such as overloading, reverse installation, children’s accidental contact, and check them one by one. You can’t only follow the correct usage in the instruction manual. - Misconception: High risks are only avoided by warning labels
Pitfall avoidance: High risks must first be modified in design. Warning labels can only cover the remaining low risks. Using warnings instead of design rectification is illegal, and it will be directly deemed unqualified if found by regulators. - Misconception: Test reports are risk assessments
Pitfall avoidance: Test reports are only supporting materials and cannot replace complete hazard identification, rating and control measure analysis. - Misconception: One assessment is permanently valid
Pitfall avoidance: Re-assessment is required when products are modified, regulations are updated, or accidents occur. After marketing, continuous monitoring is also required. You can’t just leave it aside after finishing.
Practical Case: Risk Assessment of Ordinary Plastic Water Cup
Let’s take the most common product as an example: an ordinary food-grade PP plastic water cup, intended for daily use by adults, without heating function, to see how a complete risk assessment is done.
First, collect basic information: product model SB-001, designed use is to hold normal temperature or warm drinking water, target group is adults, material is food-grade PP, notifications of similar products on Safety Gate mainly involve burr cuts, material migration, and scalding problems.
Then identify hazards, rate and treat them one by one:
- Hazard 1: Cut by burr on cup rim edge
Exposure frequency: High (users touch the cup rim many times a day when holding the cup)
Occurrence likelihood: Medium (if not polished well before leaving the factory, obvious burrs can easily cause cuts; if polishing is qualified, the probability is low)
Severity: Minor (at most abrasion, no need for medical treatment)
Initial risk: Low-Medium
Control measures: Polish the cup rim edge before leaving the factory, add factory spot checks to ensure no burrs
Remaining risk: Acceptable - Hazard 2: Scalding caused by softening and deformation of the cup body when holding hot drinks
Exposure frequency: Medium (users may fill hot drinks several times a week)
Occurrence likelihood: Low (if the temperature resistance of the PP grade used and finished product tests can prove that it will not soften and leak within the nominal use temperature and normal contact time, it can be rated as low)
Severity: Moderate (if it really deforms and leaks, it may cause mild scalds)
Initial risk: Low
Control measures: Mark the temperature resistance range on the label, remind not to hold boiling water for a long time
Remaining risk: Acceptable - Hazard 3: Chemical injury caused by plastic material migration
Exposure frequency: High (users drink water with the cup every day)
Occurrence likelihood: Low (on the premise of complying with applicable EU food contact material regulations and retaining corresponding test evidence such as overall migration and specific migration, the likelihood of excessive migration under normal use can be rated as low)
Severity: Moderate (long-term low-dose exposure may affect health)
Initial risk: Low-Medium
Control measures: Select raw materials that meet EU food contact material standards, and retain the supplier’s test reports
Remaining risk: Acceptable - Hazard 4: Scalding caused by children accidentally touching and knocking over (reasonably foreseeable misuse)
Exposure frequency: Low (the product is intended for adults, placed in adult usage scenarios, and the probability of children’s contact is not high)
Occurrence likelihood: Medium (if a child knocks it over, it is easy to spill)
Severity: Moderate (mild scald)
Initial risk: Low
Control measures: Mark “Please keep out of reach of children” on the label
Remaining risk: Acceptable
Finally, the conclusion is drawn: this water cup meets the general product safety requirements and can be placed on the market for sale.
Practical Suggestions for Dealing with Regulatory Spot Checks
If you encounter EU regulatory spot checks, doing these points well can help you pass smoothly:
- Store the risk assessment report and product technical documents in a unified manner, so that they can be retrieved at any time. Don’t look for them temporarily when they need to be checked;
- For high-risk products, try to retain test data and industry cases as the basis for assessment, which is more persuasive;
- If problems are found in the spot check, rectify in time, update the assessment report, and retain the rectification records to prove that you have taken measures;
- Regularly check the notifications of similar products on the EU Safety Gate, investigate in advance whether your own products have similar hidden dangers, and take the initiative to rectify to avoid being found.
7. GPSR New Regulation Adaptation Guide: How to Update Old GPSD Assessments
The GPSR has officially taken effect. Many sellers who have already done GPSD assessments will ask: Are the previous documents still useful? How to update them? Let’s make it clear.
Core Differences Between GPSD and GPSR
First, we must understand the core differences between the two to know what to change:
- Different legal levels: GPSD is a directive, which requires each member state to transpose it into domestic law for implementation, and requirements may vary from country to country; GPSR is an EU regulation, with core safety obligations directly applicable across the EU and a unified framework, but penalty standards, language requirements, and market supervision and enforcement details still need to follow the supporting rules of each member state.
- Different clarity of requirements: GPSD only requires product safety, and there is no mandatory requirement for a formal risk assessment document; GPSR explicitly requires manufacturers to establish an internal risk management process, complete a formal risk assessment, and retain product safety technical files.
- New coverage scope: GPSR adds safety risk requirements for cybersecurity, software updates, and AI-related products, and products with digital functions need additional assessment.
- E-commerce and traceability requirements: GPSR mandates that products sold remotely must appoint an EU economic operator, and products sold online must be marked with safety information and a unique identification code, with stricter traceability requirements.
- Different retention periods: GPSR uniformly requires technical documents to be retained for 10 years, while there was no EU-wide unified requirement in the GPSD era.
Adaptation Key Points for Existing GPSD Assessment Documents
If you already have GPSD assessment documents, you don’t need to redo all of them. Just supplement the following contents to meet the GPSR requirements:
- Supplement content: Check whether the new requirements of GPSR are covered. For example, products with digital functions need to supplement the risk assessment of cybersecurity and software updates, and also supplement the post-marketing monitoring process.
- Change the period: Uniformly adjust the retention period of assessment documents to 10 years, in line with the mandatory requirements of GPSR.
- Supplement traceability: If it is a product sold remotely, supplement the unique product identification code and the information of the EU economic operator.
- Supplement processes: Improve the internal written processes of risk management, post-marketing accident monitoring, and product recall. GPSR requires these processes to be formal and executable.
3 Core Tasks for Updating Old Documents
Products already sold in the EU need to complete the following 3 tasks as soon as possible to ensure compliance with GPSR requirements:
- Review the risk assessment documents of all products on sale, and supplement the missing contents in accordance with GPSR requirements;
- Update the internal risk assessment template, add the new modules required by GPSR, and new products will be made directly according to the new template;
- Establish a fixed process for post-marketing accident monitoring, notification and corrective measures, don’t wait until problems occur to make temporary preparations.
Summary
After reading this content, you should be able to independently complete these things:
Quickly judge whether your own products and business need GPSD/GPSR risk assessment, and clarify the applicable boundaries;
According to the evidence priority and practical steps, independently complete the risk assessment of ordinary low-risk products without relying on third parties;
Check whether a risk assessment is qualified against the four core checkpoints, and avoid the cognitive and practical pitfalls that novices often fall into;
Corresponding to your own market role — whether it is a brand owner, cross-border seller, importer or distributor, be clear about the statutory responsibilities to be borne;
Distinguish the different roles of CE mark, test report and risk assessment, and no longer confuse them;
Update the old GPSD assessment documents in place in accordance with GPSR requirements to meet current compliance requirements.
Product safety compliance is not a formality. It is not only responsible for consumers, but also protects your own business from losses due to compliance issues.