Selling Food Supplements in Latin America: How to Register in Argentina and Chile

A Spanish or EU brand that already sells food supplements under EU rules often assumes Latin America works the same way: get a Certificate of Free Sale (CLV), translate the label, and ship. It doesn’t. Argentina lets a CLV substitute for registration in most cases; Chile does not, and the same ingredient can be authorized in one country and unrecognized in the other. Treating the region as a single market is the single most expensive mistake we see exporters make, usually discovered only after a container is sitting in customs.

Why Latin America Is Not One Regulatory Market

Each country runs its own food and supplement authority, its own registration circuit, and its own list of authorized ingredients and maximum doses. There is no regional equivalent of the EU’s single market for food supplements, and a dossier built for one country rarely transfers to the next without rework. In our experience, the two most common failures are assuming a CLV always exempts the product from local registration, and carrying an ingredient limit from one country into another without checking the local ceiling.

A concrete example makes the point. Monk fruit extract is an authorized sweetener in Argentina under the Código Alimentario Argentino, but it is not a recognized ingredient in Chile. Biotin is capped at a maximum daily intake of 2,500 µg in Argentina, against a ceiling of just 150 µg in Chile — a difference large enough to force a full reformulation if the same dosage is exported to both markets. Neither gap shows up until someone checks the primary source for each country, which is exactly the step that gets skipped when a company applies «Latin America» as one label.

Argentina: a Fast Lane, but Only If Your Product Qualifies

Argentina is the one country in the region with a genuine shortcut. Under Decree 35/2025 and Disposition 537/2025, a supplement backed by a valid Certificate of Free Sale from the country of origin can be imported under the simplified Annex III regime: a sworn declaration (declaración jurada) instead of the full registration circuit — exempt from the RNE (establishment registration) and RNPA (product registration) that would otherwise apply under Article 1381 of the Código Alimentario Argentino, and administered by ANMAT through INAL.

That exemption comes with conditions. It only covers products that fit within the authorized ingredient list and the dose limits set by Joint Resolutions 3/2020 and 3/2026, and it does not remove the front-of-pack labeling obligation: Argentina’s Law 27.642 requires black octagonal warning seals («EXCESO EN…») on any supplement that exceeds the sugar, sodium, fat or calorie thresholds it sets, in Spanish, on the Argentine-market label — not the EU one. Skip that step and the product clears the sanitary review but gets stopped at the retail or customs stage anyway.

Chile: Full Supplement Registration, No Shortcut

Chile takes the opposite approach. There is no simplified regime comparable to Argentina’s Annex III, and a Certificate of Free Sale from the exporting country is accepted as supporting evidence but never substitutes for the local process. Every product needs its own file: a CDA (Certificado de Destinación Aduanera) to clear the shipment at the port of entry, followed by the Resolución de Uso y Disposición — the sanitary authorization — issued by the regional SEREMI de Salud, under the framework of the Reglamento Sanitario de los Alimentos (Decreto Supremo 977/96, articles 534 and 536–537) and the dose limits set out in Resolución Exenta 394/2002, with the Instituto de Salud Pública (ISP) providing the laboratory backing that supports the SEREMI’s review.

Labeling has its own logic too. Chile’s front-of-pack warning system (the black «ALTO EN» stop-sign seals under Law 20.606) is the best known feature of its food regulation, but food supplements are explicitly exempt from it — which is the reverse situation from Argentina, where supplements are inside the warning-seal net. An exporter who applies Argentina’s labeling logic to a Chilean shipment either adds seals that shouldn’t be there or misses an exemption they were entitled to use; both cost time and, in a private-label negotiation, money.

What EU Exporters Consistently Get Wrong

Across the files we’ve reviewed, five mistakes account for most of the delays. The first is assuming the CLV alone opens the market, when in fact it only exempts Argentina from full registration and nowhere else. The second is reusing an EU or Spanish label instead of building one in the target country’s own language and legal format. The third — the one that trips up even experienced exporters — is carrying an ingredient or dose approved in one Latin American country into another without checking the local ceiling, exactly as monk fruit and biotin illustrate above. The fourth is reaching for a health or disease-related claim, «reduces cholesterol,» «treats,» «prevents,» which reclassifies the product as a pharmaceutical in every country in the region; none of them allow therapeutic claims on a food supplement. And the fifth, specific to Peru, is shipping capsules or tablets without first confirming whether DIGESA or DIGEMID is the competent authority — the presentation format and any health claim decide which agency and which circuit applies, and the wrong choice restarts the whole file.

None of these five is a hard barrier. Each one has a legal, documented way through it — a reformulation that keeps the product inside the authorized dose, a label rebuilt in the target format, or a claim rewritten so it stays inside the food category. The real question isn’t whether your product can legally reach Argentina and Chile — it almost always can — but which fix applies to which country before it ships, not after it’s already held at the port.

How ASC Handles a Latin America Launch

We don’t hand a client a checklist and let them find their own way through ANMAT or the SEREMI. Our regulatory team builds the country-by-country legality file for the exact product and dosage — which ingredients and doses clear each authority, which registration or declaration route applies, and what the label must say — and then manages the registration or declaration itself with the relevant agency. Argentina and Chile are covered in full depth; the rest of the region (Mexico, Brazil, Colombia, Peru, Ecuador and the wider LATAM markets) follows the same rigor, verified against each country’s primary source rather than assumptions carried over from elsewhere.

After close to two decades advising importers and exporters through the EU’s own regulatory framework, we bring the same standard to Latin America: a licensed technical team signs off on the file, and if an authority raises a question about a submission we manage, we are the ones who answer it — not the exporter, working alone against a foreign agency in a language and a legal system they don’t operate in every day.

Frequently Asked Questions

Does a Certificate of Free Sale let me sell my supplement anywhere in Latin America?

No. It exempts a qualifying product from full registration only in Argentina, under the Annex III regime. In Chile and in most other Latin American countries, the CLV is supporting documentation, not a substitute for local registration or notification.

Can I use the same label across Argentina, Chile and the rest of the region?

No. Each country has its own labeling rules, its own front-of-pack warning system, and its own exemptions for supplements — Argentina applies its warning seals to supplements, Chile exempts them. The label has to be built for the destination country, not translated from the EU version.

What happens if my product contains an ingredient not authorized in the destination country?

The dossier gets rejected or held until the formulation is adjusted. This is why we verify every ingredient and dose against the country’s own primary source before filing, rather than assuming approval in one market carries over to another.

How long does registration take in Argentina versus Chile?

Argentina’s Annex III declaration route is materially faster when the product qualifies, since it replaces full registration with a sworn declaration. Chile’s process runs through the CDA at customs and the SEREMI’s Resolución de Uso y Disposición, which takes longer because there is no simplified alternative — timelines depend on the completeness of the file submitted.

If your catalogue is ready to move into Argentina, Chile or elsewhere in Latin America, get the country-by-country legality assessment done before you commit to a shipment — talk to our regulatory team about your specific product and destination markets.

Safety Data Sheets (SDS) under REACH: what importers of chemicals must provide

If your business imports chemical substances or mixtures into the European Union, you almost certainly have to provide a Safety Data Sheet (SDS). It is one of the most common — and most commonly botched — obligations under REACH. Customers, distributors and inspectors all expect a correct, up-to-date SDS in the right language, and getting it wrong can stop a shipment or a sale. Here is what an SDS is, when it is mandatory, and exactly what you, as an importer, must deliver.

What an SDS is and why REACH requires it

A Safety Data Sheet is the standardised document that communicates the hazards of a substance or mixture and how to handle, store, transport and dispose of it safely. The obligation comes from Regulation (EC) No 1907/2006 (REACH), Article 31 and Annex II. The format was most recently overhauled by Regulation (EU) 2020/878, mandatory for all SDS since 1 January 2023. The SDS is the backbone of hazard communication down the supply chain: it is how a downstream user knows what they are handling.

When an SDS is mandatory (and when it is not)

You must supply an SDS, free of charge, when a substance or mixture is:

  • Classified as hazardous under the CLP Regulation (EC) No 1272/2008;
  • Persistent, bioaccumulative and toxic (PBT) or very persistent and very bioaccumulative (vPvB); or
  • Included in the Candidate List of substances of very high concern (SVHC) for authorisation.

There are also cases where a mixture is not classified as hazardous but still requires an SDS on request — for example, mixtures containing certain concentrations of substances that are hazardous to health or the environment, or that have EU workplace exposure limits. When no SDS is required, you may still owe downstream users specific safety information under Article 32. In short: «not classified» does not automatically mean «no obligations».

The importer becomes the «supplier» — your obligations

This is the point importers most often miss. Under REACH, when you import a chemical into the EU you step into the shoes of the supplier. You cannot simply forward the SDS your non-EU manufacturer sent you: you are legally responsible for providing an SDS that is correct, complete and compliant with EU law. That means:

  • The classification must follow CLP, not the supplier’s home-country system (a US, Chinese GB or other national SDS is not, by itself, valid in the EU).
  • It must be in the official language(s) of every Member State where the product is placed on the market.
  • It must reference EU legislation, EU exposure limits and, where relevant, the substance’s REACH registration number.
  • You must keep it up to date and re-issue it when new hazard information, a new restriction or a registration changes the content.

Do not confuse the SDS with REACH registration: registration is a separate duty that applies to importers of substances at one tonne per year or more. The SDS is the communication document; registration is the dossier you file with ECHA. Many importers need both.

The 16-section format (Annex II)

Every compliant SDS follows the same 16-section structure, in order. Getting the structure right is not cosmetic — inspectors check it section by section:

  • 1. Identification · 2. Hazards identification · 3. Composition/information on ingredients · 4. First-aid measures
  • 5. Firefighting · 6. Accidental release · 7. Handling and storage · 8. Exposure controls/personal protection
  • 9. Physical and chemical properties · 10. Stability and reactivity · 11. Toxicological information · 12. Ecological information
  • 13. Disposal · 14. Transport information · 15. Regulatory information · 16. Other information

Since Regulation (EU) 2020/878, sections must also address nanoforms, endocrine-disruptor information and, where assigned, the Unique Formula Identifier (UFI) in Section 1.1.

Extended SDS and exposure scenarios

For a registered substance manufactured or imported at 10 tonnes/year or more that is hazardous, the registrant must carry out a chemical safety assessment and annex the relevant exposure scenarios to the SDS. This «extended SDS» (eSDS) tells the downstream user the conditions under which use is safe. If you import such substances, your SDS must carry those scenarios — a bare 16-section sheet is not enough.

Language and updates

The SDS must be provided in the official language of the Member State where the product is placed on the market (Spanish for Spain, and so on), unless that State provides otherwise. You must update it without delay when new information on hazards or risk management becomes available, when an authorisation is granted or refused, or when a restriction is imposed — and provide the updated version to everyone you supplied in the previous 12 months.

Common mistakes importers make — checklist

  • Reusing a non-EU SDS as-is — the classification and legal references are wrong for the EU market.
  • Wrong or missing language — an English-only SDS for the Spanish market is non-compliant.
  • Outdated format — still using the pre-2020/878 layout.
  • No exposure scenarios where the tonnage triggers an eSDS.
  • Confusing SDS with registration — providing an SDS but skipping the REACH registration you also owe.
  • Never updating — the SDS is a living document, not a one-off.

A practical example

Imagine you import a cleaning concentrate from a supplier in Asia. Their sheet classifies it under the local system and is written in English only. Before you can sell it in Spain you must: reclassify the mixture under CLP from the actual composition; build a 16-section SDS in Spanish (and any other market language) to Regulation (EU) 2020/878; check whether any component is on the Candidate List or restricted; confirm whether the tonnage triggers REACH registration and, if a registered substance is present at 10 t/y or more, attach the exposure scenarios. Only then is the document fit to hand to a customer or an inspector. Skipping any of these steps is the difference between «we have an SDS» and «we have a compliant SDS».

Frequently asked questions

My Chinese supplier already sent an SDS — isn’t that enough? No. As the EU importer you are the supplier under REACH and are responsible for an SDS that complies with CLP and EU rules, in the correct language. A foreign SDS is a starting point, not a compliant document.

Do I need an SDS if my mixture isn’t classified as hazardous? Sometimes yes — on request, or where specific substances or exposure limits are present. And even without an SDS you may owe Article 32 safety information.

Is the SDS the same as REACH registration? No. The SDS communicates hazards; registration is a dossier filed with ECHA for substances at ≥1 t/y. Importers often need both.

How we handle it at ASC

At ASC we prepare and validate Safety Data Sheets for importers and distributors: we reclassify under CLP, build the 16-section SDS in the required language(s) to Regulation (EU) 2020/878, add exposure scenarios where the tonnage demands it, and check whether you also trigger REACH registration — with a qualified specialist validating and signing off each document. We do not simply relabel your supplier’s sheet: we produce a document you can put in front of a customer or an inspector with confidence. If you import chemicals into the EU, talk to us through our contact page; see also our note on food contact materials and on the EU Packaging Regulation (PPWR). Official sources: ECHA — Safety Data Sheets and REACH (Reg. 1907/2006).

The EU AI Act just got simpler: what Regulation (EU) 2026/1744 changes

On 24 July 2026, the Official Journal of the European Union published Regulation (EU) 2026/1744, the so-called Digital Omnibus on AI. It amends Regulation (EU) 2024/1689 (the AI Act) — and, along the way, the aviation and machinery regulations — to simplify how the harmonised AI rules apply. The headline is the deferral of the high-risk obligations, but the detail matters: some duties are postponed and others still apply on their original date. Here is what actually changed.

What Regulation (EU) 2026/1744 is

It is a simplification («omnibus») regulation adopted by the European Parliament and the Council. It responds to a practical problem: delays in drafting the harmonised standards — which give providers the technical means to comply — and in setting up national governance and conformity-assessment frameworks had created a heavier burden than expected. The legislator answers by granting more time and clarifying application without lowering the level of protection of health, safety and fundamental rights that the AI Act pursues.

The key change: high-risk obligations are deferred

The AI Act timeline is re-ordered as follows:

  • General application: 2 August 2026 — unchanged. Most of the regulation still starts on this date.
  • Chapter III, sections 1, 2 and 3 (high-risk AI systems): 2 December 2027 — deferred.
  • High-risk systems under Article 6(1): 2 August 2028 — deferred.

In plain terms: if your company develops or uses an AI system classified as high-risk, you now have more room to prepare for conformity. But «more room» is not «no longer applies»: the obligations are coming, and technical documentation, risk management and human oversight cannot be improvised at the last minute.

What does NOT change (and applies now)

This is the trap many companies will fall into. The omnibus does not postpone everything:

  • Prohibited AI practices (Title II) have applied since February 2025.
  • Rules for general-purpose AI (GPAI) models and governance have applied since August 2025.
  • The transparency obligations of Article 50 — disclosing that content or an interaction is AI-generated — still apply from 2 August 2026. The omnibus only extends the deadline for the technical detail of marking synthetic content (Art. 50(2)), not the transparency duty itself.

Provider or deployer: your role defines your duties

The AI Act distinguishes two roles that are often confused. The provider develops the AI system (or markets it under its name); the deployer uses it under its authority in a professional context. Most SMEs — and most importers and manufacturers entering the EU — will be deployers of third-party AI tools. Deployer duties are lighter than provider duties, but not zero: for high-risk systems they include human oversight, use in line with the instructions, and record-keeping. Knowing which side you are on is the first step to neither over-complying nor missing an obligation that is genuinely yours.

Not just the AI Act: machinery and aviation too

The omnibus also amends Regulation (EU) 2023/1230 (machinery) and Regulation (EU) 2018/1139 (aviation) to set out how they interact with the AI rules and to avoid overlaps or inconsistent interpretation between sectoral and horizontal AI legislation. For a machinery manufacturer with AI components, this means the conformity assessment of the product and the AI Act assessment must be read together, in a coordinated way — not as two separate worlds. It is a recurring theme of the regulation: reduce friction between regimes without weakening any of them.

AI literacy: from strict duty to a duty to support

Article 4 (AI literacy of staff) is relaxed: it moves from a strict obligation to a duty to support and promote the training of the people operating the AI. It remains a strategic priority — a workforce that does not understand the tool is a risk — but the approach is now one of encouragement rather than immediate penalty.

Harmonised standards and presumption of conformity

The regulation reaffirms that harmonised standards cited in the Official Journal confer a presumption of conformity, and opens alternative routes (common specifications, guidance) while those standards arrive. This matters for EN 18286:2026, the European AI quality-management standard: it is already published, but not yet cited in the Official Journal, so it does not yet grant an automatic presumption of conformity. Aligning with it today is good practice; presenting it as «a standard in force that grants presumption» would be premature.

What it means for your company — a checklist

  • Classify your AI systems by risk level (prohibited, high, limited, minimal). Everything starts here.
  • If you have high-risk AI (for example, AI-enabled medical device software), use the new 2027-2028 timeline to prepare technical documentation, risk management and human oversight — not to forget about it.
  • Comply with Article 50 transparency now if you generate content with AI or deploy chatbots: it applies from August 2026.
  • Train your team on the responsible use of AI (Art. 4).
  • Document who reviews, validates and signs off each AI output with regulatory impact.

The bottom line

Regulation (EU) 2026/1744 buys time where the market needed it most — high-risk conformity, where the standards were not ready — while keeping the parts that protect people (prohibitions, transparency, governance) firmly in force. For most companies the right reading is not «the AI Act is delayed, relax», but «we now have a realistic runway to do this properly». The organisations that use the extra eighteen-plus months to classify their systems, build the documentation and put real human oversight in place will arrive at 2027-2028 ready; those that read it as a reprieve will arrive late.

Frequently asked questions

Has the AI Act been postponed entirely? No. Only the high-risk obligations (Chapter III and Art. 6(1)) move to 2027-2028. General application stays on 2 August 2026, and prohibitions, GPAI and transparency already apply.

Can I stop worrying about the AI Act until 2027? No. Transparency applies now, and preparing high-risk conformity takes months: the extra time is for working, not for waiting.

What about AI-enabled medical devices (SaMD)? AI medical software is both a medical device (MDR/IVDR) and, depending on its function, a high-risk AI system. Under the omnibus the AI Act high-risk layer aligns with the 2027-2028 timeline, but MDR/IVDR obligations run on their own schedule: read both together, do not pick one.

Who is liable if the AI gets a file wrong? In an operated service like ASC’s, the specialist who validates and signs the output answers for it — not a disclaimer that shifts the risk onto the client. That is the difference between an accountable service and a self-service tool.

How we handle it at ASC

At ASC we help companies bring order to their use of AI within the regulatory framework: we classify systems by risk, prepare the documentation and the Article 50 transparency duties, and — most importantly — we operate a model where AI produces and a qualified specialist validates and signs off every output. We do not sell a tool for you to use on your own: we provide an operated service with accountability. If the regulator stops your file, we answer — the file carries our specialist’s signature, not a disclaimer that shifts the risk to you. If your company uses AI in a regulated context, let’s talk through our contact page; see also our note on EN 18286:2026 and on regulatory affairs automation. Official sources: Regulation (EU) 2026/1744 and Regulation (EU) 2024/1689 (AI Act).

FDA 510(k): how to clear your medical device in the US

FDA 510(k) medical device clearance is the route most manufacturers use to legally place a device on the US market, and it hinges on one argument: that your device is substantially equivalent to a device already being sold legally. That single word — equivalence — decides whether your submission moves through FDA’s review in a matter of months or comes back with an Additional Information request that resets the clock. A 510(k) is not a rubber stamp and it is not a formality bolted onto product launch; it is a technical and legal argument that has to be built correctly from the predicate up.

What a 510(k) actually is

A premarket notification, commonly called a 510(k) after Section 510(k) of the Federal Food, Drug, and Cosmetic Act, is the submission a manufacturer files with FDA to demonstrate that a device is as safe and effective as — substantially equivalent to — a legally marketed predicate device that does not require premarket approval (PMA). The procedural requirements sit in 21 CFR Part 807, Subpart E, which sets out when a submission is required (§ 807.81), what must be included (§ 807.87), the required format (§ 807.90) and how FDA acts on it (§ 807.100). Most manufacturers required to register their establishment under Part 807 must also submit a 510(k) at least 90 days before introducing the device into commercial distribution, unless a specific exemption applies.

Substantial equivalence, under FDA’s own framework, means the device has the same intended use as the predicate and either the same technological characteristics, or different technological characteristics that do not raise different questions of safety and effectiveness — provided the performance data submitted demonstrates the device is as safe and effective as the predicate. It does not mean identical. It means the differences, if any, do not introduce new questions FDA has to resolve from scratch.

Which devices need one

Device classification drives the pathway. Class I devices are largely exempt from 510(k) in practice, though not automatically — exemption status has to be verified against the specific product code, not assumed from the class alone. Class II is where the 510(k) does most of its work: it is the standard premarket pathway for the majority of Class II device types, alongside device-specific exemptions that also need to be checked individually. Class III devices, which sustain or support life, are implanted, or present a potential unreasonable risk, generally require Premarket Approval (PMA) rather than a 510(k) — with a narrowing set of legacy exceptions still working through 510(k). In our experience, the single most common strategic error we see from manufacturers arriving from outside the US is treating device classification as self-evident from how the product is classified in the EU under the MDR. It rarely maps cleanly, and getting the US product code wrong early cascades into every decision that follows — predicate search, testing scope, even which submission type applies.

The three types of 510(k), and when each one applies

Not every 510(k) is built the same way, and choosing the wrong type is a common source of avoidable delay.

The Traditional 510(k) is the default and the most heavily used pathway. It requires a full substantial equivalence comparison against the predicate, complete performance data, and the most comprehensive documentation package of the three. Use it when the device is genuinely new to your company’s portfolio, the predicate relationship is not a simple modification, or the device does not cleanly qualify for either of the other two routes.

The Special 510(k) exists for a narrower case: a manufacturer modifying its own already-cleared device, where the change can be evaluated using the manufacturer’s own design control procedures under 21 CFR Part 820. It is the fastest of the three routes, but it is only available when the modification does not alter the fundamental scientific technology of the device and the existing risk analysis and verification/validation methods can support the change. A manufacturer discovering mid-review that its “minor modification” is not eligible for Special 510(k) treatment loses time it did not need to lose.

The Abbreviated 510(k) relies on FDA guidance documents, special controls, or recognized consensus standards instead of a full head-to-head predicate comparison. Instead of reproducing extensive predicate data, the submitter provides summary reports and declarations of conformity to recognized standards. It works well for device types where FDA has already published clear special controls or a device-specific guidance document, and it can meaningfully shorten what has to be written and reviewed — but only if the device genuinely fits within the guidance’s scope.

Picking among the three is a strategic decision, not an administrative one. Get it wrong and FDA does not gently redirect you; it stops the clock and asks you to justify the choice, or rejects the submission at acceptance review before substantive review even starts.

Refuse to Accept: where most avoidable delay happens

Before FDA reviewers ever evaluate whether your device is substantially equivalent, the submission goes through an acceptance review against the Refuse to Accept (RTA) checklist. This is a binary administrative-completeness gate, not a scientific judgment: FDA checks the submission against the applicable checklist — Traditional, Abbreviated or Special each has its own — covering administrative information, device description, the substantial equivalence discussion, proposed labeling, and, where relevant, sterilization, shelf-life, biocompatibility, software, cybersecurity, electrical safety/EMC and performance data. FDA notifies the submitter within the first calendar days after receipt whether the submission is administratively complete or which specific elements are missing.

Is this a technicality or a real risk? It is both, and that is exactly the problem. A submission bounced at RTA has not failed on the merits — it has failed on completeness, often over something as mechanical as a missing labeling section or an incomplete substantial equivalence table. But the practical effect is identical to a substantive rejection: the review clock has not started, and the manufacturer is back at the start of the queue. We have seen manufacturers with genuinely strong technical files lose months to RTA issues that had nothing to do with whether their device actually worked.

Timelines and user fees

FDA’s stated performance goal under the current Medical Device User Fee Amendments (MDUFA) framework is to reach a decision on the large majority of Traditional 510(k) submissions within roughly 90 FDA days — calendar days net of any time the submission sits on hold while FDA waits for an Additional Information response. That clock-stopping mechanic matters more than the headline number: every Additional Information request pauses the countdown, so a submission that generates two or three rounds of FDA questions can take substantially longer in real time than the stated goal suggests, even though the “FDA days” figure looks compliant on paper. Special 510(k)s are reviewed on a materially shorter track; Abbreviated 510(k)s sit closer to Traditional in practice, depending on how much the guidance-based summary approach actually reduces review burden for that device type.

Submissions are also subject to a Medical Device User Fee, reassessed annually by FDA, with a reduced fee available to businesses that qualify through FDA’s Small Business Determination (SBD) program. Qualification has its own filing deadline ahead of the fiscal year it applies to, and missing that window means paying the standard fee regardless of company size — a detail that catches manufacturers who assume small-business status is automatic.

No predicate? The De Novo pathway

Not every innovative device has a fair predicate to point to, and forcing an equivalence argument onto a device that is not truly equivalent to anything on the market is a losing strategy. For low-to-moderate-risk devices with no legally marketed predicate, FDA’s De Novo classification request lets the agency evaluate the device on its own merits rather than by comparison. If FDA agrees that general and special controls are sufficient to reasonably assure safety and effectiveness, it grants the De Novo request and creates a new device classification and product code — which then becomes a predicate that later devices, including your own next generation, can cite in a standard 510(k). A De Novo request can be filed directly, or after FDA issues a Not Substantially Equivalent (NSE) decision on a prior 510(k) attempt. Recognizing early that De Novo, not a forced 510(k), is the right pathway saves a manufacturer an entire review cycle it did not need to spend.

Practical checklist before you file

  • Confirm the device classification and product code against FDA’s own classification database — not against the EU MDR classification, which does not map directly.
  • Identify and justify one or more predicates that share intended use and, where technology differs, show the difference raises no new safety or effectiveness questions.
  • Decide the submission type — Traditional, Special or Abbreviated — based on what the modification and available guidance actually support, not on which is fastest to write.
  • Run the submission against the applicable RTA checklist before filing, section by section, including labeling, biocompatibility, software and cybersecurity where relevant.
  • Build the substantial equivalence comparison as a structured, side-by-side technical argument, not a narrative summary.
  • Confirm Small Business Determination eligibility and file it ahead of the FDA deadline if it applies to you.
  • Plan for at least one round of Additional Information requests in your commercial timeline — and have the technical team ready to respond inside FDA’s response window.

How ASC Services gets your device cleared

Knowing what FDA requires is the easy part; it is published. What decides whether a 510(k) clears on the first cycle or drags through two or three rounds of Additional Information is the work behind it — and that is where we operate. We run the predicate search and build the equivalence strategy before a single test is commissioned, so the technical program is built around a defensible comparison rather than retrofitted to one. We run a gap analysis of your existing technical file against what the chosen predicate and submission type demand, so testing gaps surface before FDA finds them. We prepare the full submission package — device description, substantial equivalence comparison, labeling, performance data — screened against the same RTA checklist FDA itself uses, and we draft the response when FDA comes back with questions, because how that response is framed often determines whether it closes the issue or opens a second one.

Every submission we prepare is validated and signed off by a qualified ASC regulatory professional before it goes to FDA — not generated and shipped by a tool with no one accountable for it. That is the same standard we apply across two decades and hundreds of approved regulatory dossiers on both sides of the Atlantic: for manufacturers already navigating the EU technical file requirements under the MDR, our guide on why notified bodies reject MDR technical documentation covers the equivalent pressure points on the European side. If you are preparing to bring a device to the US market, talk to us through our contact page, or see the full scope of what we handle for regulated manufacturers on our consultancy services page.

Frequently Asked Questions

How long does FDA 510(k) clearance actually take?

FDA’s stated performance goal for a Traditional 510(k) is a decision within roughly 90 FDA days, but that clock stops every time FDA places the submission on hold for an Additional Information request. A clean submission with no Additional Information rounds can land close to the goal; a submission that generates two or three rounds of questions can run well beyond it in real calendar time, even though it stays within the technical FDA-days goal.

Can I use a predicate device that is not exactly like mine?

Yes — substantial equivalence does not require an identical device. It requires the same intended use and either matching technological characteristics or differences that do not raise new questions of safety and effectiveness, supported by data. A predicate chosen for commercial similarity rather than genuine regulatory alignment is one of the most common reasons submissions stall.

What happens if my 510(k) gets a Refuse to Accept notice?

The submission is administratively incomplete against the applicable RTA checklist and has not entered substantive review. FDA identifies the missing elements; you correct and resubmit. The review clock has not started, so an RTA bounce, while not a rejection on the merits, still costs real time.

What if there is no predicate for my device at all?

That is exactly the case the De Novo classification pathway exists for: FDA evaluates the device on its own merits rather than by comparison, and a successful request creates a new device classification that later submissions, including your own, can then use as a predicate.

AI-generated regulatory files: who validates and signs them (FDA + EU AI Act)

Artificial intelligence can now draft a medical device technical file, a cosmetic safety report or a declaration of conformity in minutes. Under deadline pressure, that speed feels like a gift. But it has quietly changed the question a regulator asks when the file lands on their desk. It is no longer “did you use AI?” — almost everyone does. It is “who reviewed this, and whose name is on it?”

That shift is not theoretical. In 2026 the US FDA issued a warning to a cosmetics laboratory that had relied on AI-generated documentation without meaningful human review. In the European Union, the EU AI Act (Regulation (EU) 2024/1689) turns the same expectation into law: its Article 14 requires effective human oversight of high-risk AI systems — a person who understands the output, can question it, and can override it. On both sides of the Atlantic the direction is identical, and it is only tightening.

The regulator’s question has changed

For years the compliance conversation was about whether a document existed: was there a technical file, a CPSR, a declaration of conformity? Now that AI can produce a plausible version of any of them on demand, the mere existence of the document proves very little. What an inspector wants to know is whether a qualified person stands behind it — because that person is who answers when something is wrong.

This is the single most important thing to understand about AI in regulatory work: the risk was never the technology. The risk is delivering what the technology produces without a professional validating it and signing for it.

What the FDA case actually tells us

The detail that matters in the FDA action is not that AI was used. It is that the output reached a regulatory context without a human who could vouch for it. Regulators are not banning AI; they are refusing to accept unaccountable AI. A submission that is fast but unverified is worse than a slow one, because it carries the appearance of rigour without the substance — and appearances are exactly what an inspection strips away.

Expect the pattern to spread. As more companies lean on generative tools for regulatory content, authorities are learning to look for the fingerprints of unreviewed AI: confident language around claims that do not hold, references that cannot be traced, and gaps where a specific requirement should be.

What the EU AI Act requires: oversight, not a rubber stamp

Article 14 of the EU AI Act sets out human oversight for high-risk AI systems. In plain terms, a person must be able to understand what the system produced, judge whether it is correct, and intervene or stop it — not simply click “accept”. “A human glanced at it” is not oversight. “A qualified professional validated it and takes responsibility for it” is.

Even where a specific regulatory task falls outside the Act’s high-risk list, the principle has already reset expectations across the sector. And it converges with a professional obligation that predates any AI law: the person who signs a regulatory document answers for it. The EU AI Act simply makes the absence of that person visible and, increasingly, unacceptable.

Where unreviewed AI output actually fails

In the files we review, the failure modes of AI-generated regulatory content are consistent:

  • Citations that do not exist. A regulation number, an article or a standard that reads perfectly but corresponds to nothing real — or that has been superseded.
  • Out-of-date limits. A migration limit, a permitted concentration or a classification taken from a version of the rule that no longer applies.
  • Silently dropped requirements. A test, an annex or a labelling element the model simply did not include, so the gap is invisible unless someone checks against the source.
  • Fabricated confidence. Conclusions stated as certain (“this product complies”) that the underlying evidence does not support.

None of these is exotic. Every one is exactly what an inspector, a notified body or a customs authority is trained to find — and exactly what a qualified reviewer catches before it leaves the building.

What “validated and signed” means in practice

At ASC Services we work the opposite way round to a self-service tool:

  • AI prepares the dossier: faster, and covering everything.
  • A qualified regulatory technician reviews every claim against the primary source — the regulation, the standard, the test report.
  • An adversarial check hunts specifically for the failure modes above: the hallucinated citation, the outdated limit, the missing requirement.
  • The technician validates the file and signs it in their own name, with full traceability of what backs each claim.

Our process is built to the EU AI Act and to EN 18286:2026, the European quality-management standard for AI published in 2026 — not yet cited in the Official Journal as a harmonised standard, so it does not yet confer an automatic presumption of conformity; we build to it as good practice, never as a claim of certification. The point is not the technology on the inside. It is the accountable professional on the outside.

Tool versus operated service: who carries the liability

Read the terms of the cheap regulatory-AI tools. Almost all of them make you accept, in the small print, that the responsibility for what you submit is yours. They automate a notification or generate a document; they do not take on the file, and they do not sign it. If the AEMPS, the FDA or customs stops your product, you are alone with an output no one validated.

The laboratory the FDA sanctioned had the tool. What it lacked was someone to validate and sign. That is the whole difference between a tool and a service: when the inspection comes, one leaves you holding the file, and the other answers for it with you.

How to tell a validated service from a wrapper

If you are evaluating an AI-assisted regulatory provider, four questions separate a real service from a thin wrapper around a language model:

  • Does a named, qualified professional sign the deliverable — or only “the platform”?
  • Who responds if an authority challenges the file: them, or you?
  • Can they show the traceability — which source backs each claim?
  • Does their contract accept responsibility, or transfer it to you?

If the answers point back to you, you have bought a tool, not compliance.

It applies to every regulated product

The same logic runs through every sector we work in: an MDR technical file for a medical device, a Cosmetic Product Safety Report, a food-contact declaration of conformity, a safety data sheet. AI can accelerate all of them; none of them should reach an authority without a qualified person validating and signing. The higher the regulatory stakes, the more the signature matters.

Frequently asked questions

Does the EU AI Act ban AI in regulatory work? No. Article 14 requires effective human oversight of high-risk AI systems — a person who understands the output and can intervene. AI plus a qualified human who validates and signs is exactly what it asks for.

Is a signed regulatory file just a formality? No. The signature is who answers for the file in an inspection. “An AI generated it” is not a defence; “a qualified technician validated and signed it” is.

Will using AI make my submission look weaker to a regulator? Not if a professional validates and signs it. What weakens a submission is unreviewed content — inconsistencies and unsupported claims that signal no one checked.

How ASC Services helps

We produce your regulatory documentation with AI, and a qualified technician validates and signs every output — for the EU (AEMPS, EU AI Act) and for the US (FDA). Twenty years and hundreds of approved dossiers, none that you have to answer for alone. Whether it is an MDR technical file, a cosmetic safety report, or regulatory affairs run with AI, we make the speed of AI safe to submit. Talk to our team through our contact page.

Who is the Responsible Person for cosmetics in the EU, and why your product cannot be sold without one

A cosmetic brand outside the EU can have flawless formulations, a spotless safety record and full compliance back home, and still be legally unable to sell a single unit in Europe — because under Regulation (EC) 1223/2009, no cosmetic product may be placed on the EU market without a designated Responsible Person. It is not a formality: Article 4 makes it a precondition, and it is the name that ends up on the label, on the CPNP notification and in front of the inspector if something goes wrong. This guide explains what the role actually is, the obligations that come with it, how it differs from being an importer or distributor, and the mistakes non-EU brands make.

What Article 4 actually requires

Article 4 states that only cosmetic products for which a legal or natural person is designated within the Union as Responsible Person may be placed on the market. For a product manufactured in the EU, the manufacturer is the default Responsible Person unless they designate someone else in writing. For a product manufactured outside the EU, the importer becomes the Responsible Person by default — again, unless a written mandate designates a different person established in the Union.

In practice this means a Chinese, Korean or Brazilian brand with no EU entity cannot self-appoint: someone established in the Union has to formally accept the role and the liability that comes with it. The designation has to be in writing and accepted — a name on a label without a real mandate behind it does not satisfy Article 4.

The obligations that come with the role (Article 5)

Being Responsible Person is not a mailbox address on a label. Article 5 makes the Responsible Person accountable for the product’s compliance, and in concrete terms that means:

  • ensuring Good Manufacturing Practice (Article 8, generally demonstrated through ISO 22716);
  • keeping the Product Information File (PIF, Article 11) available to the competent authority, at the address on the label, within a short timeframe of a request;
  • maintaining the Cosmetic Product Safety Report (CPSR, Article 10) — the safety assessment that underpins the whole file;
  • notifying the product through the Cosmetic Products Notification Portal (CPNP, Article 13) before it reaches the market;
  • ensuring the labelling and claims comply, and cooperating with authorities on any non-conformity, including corrective action and, if required, product withdrawal or recall.

In our experience, the last point is where non-EU brands get caught out. They treat the Responsible Person as a paperwork checkbox and only discover the operational weight of the role when an inspector, a Safety Gate alert or a serious undesirable effect shows up — and by then the Responsible Person is the one who has to act.

The documents behind the role

The Responsible Person does not just hold a title; they hold a file that has to be complete and current. The Product Information File gathers the product description, the CPSR, the manufacturing method and a GMP statement, evidence of any claimed effects, and data on animal testing. At its core is the Cosmetic Product Safety Report, signed by a qualified safety assessor. When an authority asks, the Responsible Person has to produce this, in the language the Member State requires, quickly. A PIF that is incomplete, out of date or held by someone who cannot access it is a finding waiting to happen.

Responsible Person, importer and distributor are not the same role

The three roles overlap in practice but are legally distinct. The importer places the product on the EU market from a third country and, by default, inherits the Responsible Person obligations unless someone else is designated. A distributor who only makes available a product already placed on the market by someone else has narrower duties — mainly checking labelling, language and dates, and storage conditions — but can trigger Responsible Person obligations if they market the product under their own name or modify it in a way that affects compliance. The Responsible Person is the one who carries the full accountability for conformity. One entity can hold more than one of these roles, but the obligations of each still apply in full and have to be documented as such.

Who can be the Responsible Person

The Responsible Person must be a legal or natural person established in the EU. It can be the EU manufacturer, the importer, a distributor who takes on the role, or a third party appointed by written mandate — for example a specialised regulatory partner acting as Responsible Person on behalf of a non-EU brand. What matters is not the label of the entity but its capacity to actually perform the duties: hold and update the PIF, respond to authorities, manage vigilance and corrective action. A Responsible Person that cannot do these things in practice exposes the brand precisely when it is most vulnerable.

The mistakes non-EU brands make

  • Assuming the distributor “sorts it out” — without a written mandate, no one has legally accepted the role.
  • Treating it as an address, not a function — a name on the label with no PIF behind it fails the first inspection.
  • No CPSR, or a weak one — the safety report is the backbone; a notification reference does not replace it.
  • Forgetting vigilance — the Responsible Person has to react to undesirable effects and Safety Gate alerts, not just file paperwork at launch.
  • Confusing CPNP notification with approval — the CPNP reference confirms the product exists in the database; it is not a safety clearance, and it does not transfer the liability away from the Responsible Person.

Frequently asked questions

Can a non-EU brand be its own Responsible Person? No. The Responsible Person must be established in the EU. A non-EU brand designates an EU-established person or partner by written mandate.

Is the Responsible Person the same as the CPNP notifier? The Responsible Person is who notifies (or delegates the notification), but the role is far broader: they hold the PIF and the CPSR and answer for the product’s compliance and safety throughout its life on the market.

Does a CPNP reference number mean the product is approved? No. It only confirms the product is in the database. The Responsible Person remains fully liable for its safety and conformity from day one.

Can the importer and the Responsible Person be the same company? Yes, and by default the importer is the Responsible Person unless another EU-established person is designated in writing. The duties of the role apply in full either way.

How ASC Services helps

We act as Responsible Person, or support your own, through the full obligation: we build and maintain the Product Information File, produce the Cosmetic Product Safety Report, run the CPNP notification, review labelling and claims, and stand behind the vigilance and corrective-action duties — with our Technical Manager validating and signing each regulatory output. If a market surveillance authority asks for the file, it is ready. Talk to our team through our contact page.

EUDAMED importer registration in Spain: how to get your SRN under the MDR

If you import medical devices into the EU through Spain, registering as an economic operator in EUDAMED is not administrative paperwork you can leave until later. Under the Medical Devices Regulation (EU) 2017/745 (MDR), it is a legal precondition before any device you handle reaches the market, and it produces a Single Registration Number (SRN) that identifies you across the entire EU system. This guide covers what you submit, how the AEMPS validates it, what it costs, the mistakes that delay it, and why the SRN is not the same as the Spanish import licence.

Who has to register — and why the importer specifically

Under Article 13 of the MDR an importer is an EU-established economic operator that places a device from a third country on the EU market. Article 31 then requires manufacturers, authorised representatives and importers to register in EUDAMED’s actor module before the device is placed on the market.

The reason the importer is named explicitly is structural. When the manufacturer sits outside the Union, the importer is one of the first operators the regulation can hold accountable inside the EU — the entity an authority contacts, the name that keeps the supply chain traceable. Registration is per legal entity, not per device or per shipment: you register once as an operator, and that identity then attaches to everything you import.

What you actually submit: Annex VI, Part A

Registration runs through the electronic system for economic operators set up under Article 30. The information you provide is listed in Annex VI, Part A, and in practice it covers:

  • the legal entity: name, registered trade name and full address;
  • the type of economic operator (here, importer) and the range of devices concerned;
  • the contact details of the person responsible;
  • the identification of your Person Responsible for Regulatory Compliance (PRRC).

The data has to be consistent with your other records — company registry, tax identifier, the details the manufacturer holds about you. Inconsistencies here are the single most common reason a registration is bounced back for correction.

The SRN: one number for the whole EU

Once the competent authority verifies the data (Article 31(2)), the system issues and assigns you a Single Registration Number. In Spain, the authority that validates the actor registration is the AEMPS. From that point the SRN identifies you in every EUDAMED module, in your dealings with notified bodies, and along the supply chain. It is not a formality you file and forget: it becomes your regulatory identity in the system.

The PRRC: the role behind the registration

The MDR requires economic operators to have a Person Responsible for Regulatory Compliance — someone with the qualifications and authority to ensure conformity, oversee vigilance and keep documentation in order. For a small importer, the PRRC can be someone within the company or engaged externally, but the role is real: it is the person an authority expects to reach when there is a regulatory question. Naming a PRRC who does not actually perform the function is a weakness an inspection will find.

Step by step

  1. Create an EU Login account — the Commission’s authentication used across EUDAMED.
  2. In the actor registration module, submit the Annex VI Part A data for your legal entity and declare your role as importer.
  3. Identify your PRRC and record their details.
  4. Submit the request; the AEMPS reviews and validates it.
  5. On validation, the SRN is issued. Keep it: you quote it in every later EUDAMED action and along the supply chain.

How long it takes, and what it costs

The EUDAMED actor registration itself carries no fee, and the SRN does not expire. What determines the timeline is the quality of the data you submit and the AEMPS validation queue: a clean, consistent submission is validated far faster than one the authority has to send back. And the obligation is continuous — Article 31(4) requires you to update the data within one week of any change: a new address, a change of PRRC, a change of activity or legal entity. An SRN tied to outdated data is a finding waiting to happen.

The mistakes that delay an importer registration

  • Registering the wrong legal entity — a trading name instead of the registered company, or the group parent instead of the entity that actually imports.
  • No real PRRC — a name on the form with no one performing the function.
  • Data that does not match the manufacturer’s records or the company registry.
  • Treating it as a one-off — forgetting the one-week update duty when something changes.
  • Confusing it with the Spanish licence and assuming one covers the other (see below).

EUDAMED registration is not the Spanish import licence

This is where importers most often get caught. The EUDAMED SRN is an EU-level identifier; it does not authorise your facility or your import activity in Spain. To import medical devices into Spanish territory you also need the national prior operating licence for importers, granted by the AEMPS under Real Decreto 192/2023 — a separate procedure we cover in our guide on importing medical devices into Spain. A company importing from outside the EU into Spain typically needs both: the SRN identifies the operator across the EU; the AEMPS licence authorises the activity nationally.

Where EUDAMED registration sits among your other obligations

The actor registration is the first EUDAMED step, not the last. It underpins device registration and UDI (Article 29), the vigilance and market surveillance modules, and, for the Spanish market, the AEMPS communication of commercialisation. Getting the actor registration right and keeping it current is what lets the rest of the system work; a wrong or stale SRN propagates errors into every module that references it. Your general duties as importer — verifying CE marking, the EU Declaration of Conformity, labelling and UDI — are set out in Article 13 and summarised in our guide to the importer’s obligations under the MDR.

Frequently asked questions

Is the EUDAMED SRN the same as my AEMPS import licence? No. The SRN (Article 31) is an EU-wide operator identifier; the AEMPS import licence (RD 192/2023) authorises your activity in Spain. You generally need both.

Do I need an SRN if the device already has a CE mark? Yes. CE marking is the manufacturer’s; importer registration and the SRN are your own obligations under Articles 13 and 31, independent of the device’s CE status.

One SRN per company or per device? Per legal entity. You register once as an operator; the SRN then attaches to the devices you import.

What happens if my details change? You must update EUDAMED within one week (Article 31(4)). An outdated registration is a compliance gap an inspection can act on.

How ASC Services helps

We set up and run your position as importer of record: we register you as an economic operator in EUDAMED, prepare the Annex VI data so it validates first time, obtain your SRN, support your PRRC, and coordinate the AEMPS national import licence so neither the EU nor the Spanish obligation is left half-done — with our Technical Manager validating and signing each regulatory output. Whether you import from Asia or the Americas, we make your position legally sound. Read our guide on the importer’s obligations under the MDR or talk to our team through our contact page.

CPNP notification for cosmetics: the Responsible Person’s step-by-step process

Before a single unit of your cosmetic product reaches an EU shelf, it has to exist somewhere else first: inside the Cosmetic Products Notification Portal (CPNP), the European Commission’s database created to implement Regulation (EC) No 1223/2009. Article 13 of the Regulation makes this notification a precondition for placing the product on the market — not a formality you can leave for later. We have seen shipments cleared at customs and then held at the distributor’s warehouse because nobody had actually completed the CPNP step; the paperwork existed, the notification did not.

Who can notify, and why it is not the manufacturer by default

Only the Responsible Person (RP) — a natural or legal person established within the EU — can submit a CPNP notification. If your company manufactures outside the Union, you cannot notify directly: you need to designate an EU-established Responsible Person, who takes on legal accountability for the product’s safety file, labelling and market surveillance response. This is frequently where non-EU brands lose time: they assume notification is an administrative step their distributor will «sort out», without realising that whoever signs as RP is the one an inspector will call first.

The three steps of a CPNP notification

The process itself is not complex once the underlying documentation is ready. First, the Responsible Person creates an EU Login account, the Commission’s shared authentication system used across CPNP and other EU portals. Second, within CPNP’s organisation module (SAAS), the RP sets up or joins an organisation profile and declares its role — Responsible Person, distributor or delegate — since CPNP allows a delegate to submit on the RP’s behalf while the legal responsibility still sits with the RP. Third, the RP notifies each product individually: category (skin care, hair care, oral hygiene, decorative cosmetics, among CPNP’s predefined categories), the product name exactly as it appears on the label, the RP’s name and address, the country of origin when manufactured outside the EU, and the member state(s) where it will first be placed on the market.

The formulation itself can be declared either as a frame formulation — a reference to a pre-registered formulation template, when one applies to your product type — or as the full ingredient list with concentration ranges. Where the formula contains a substance classified as CMR (carcinogenic, mutagenic or toxic for reproduction, category 1A or 1B under the CLP Regulation), CPNP requires its concentration and function to be declared separately, and the presence of any nanomaterial must be flagged as such. A legible copy of the original label, and ideally a product photo, complete the file.

Notified does not mean cleared

Here is the detail that catches out companies moving fast to launch: CPNP has no official review process. The notification reference is issued immediately once the form is submitted, and that reference number is not an approval — it simply confirms the product exists in the database. Responsibility for the product’s actual safety and conformity with the Regulation, including the Cosmetic Product Safety Report (CPSR) and the ingredient assessment behind it, remains entirely with the Responsible Person from day one. A market surveillance authority can request the full file at any point, notification reference notwithstanding.

The obligation does not end at launch either. Under Article 13(7) of the Regulation, the Responsible Person must update the CPNP notification whenever the information submitted changes — a reformulation that alters the ingredient list or concentration ranges, a change of manufacturing country, or discontinuation of the product all trigger an update. In our experience, this is the step companies forget most often: they treat the initial notification as a one-time task, then reformulate a product eighteen months later without touching CPNP, leaving the database out of step with what is actually being sold.

CPNP is not Spain’s own import declaration

CPNP notification is frequently confused with Spain’s national declaración responsable for cosmetics manufacturing or import activity, processed through AEMPS via the COSMET2 platform under Royal Decree 85/2018 — we cover that process in detail in our guide to importing cosmetics into Spain. The two are not alternatives: CPNP notifies the product, at EU level, before it reaches any market; the Spanish declaración responsable authorises the company’s facility and activity to manufacture or import cosmetics on Spanish territory. A company placing cosmetics on the Spanish market from outside the EU typically needs both in place, each satisfying a different legal requirement.

Frequently asked questions

Does a CPNP notification reference number mean my product is approved for sale?

No. The reference is issued automatically and only confirms the product is in the database. The Responsible Person remains fully liable for the product’s safety file and its conformity with Regulation (EC) 1223/2009.

What happens if I reformulate a product after it has been notified?

Article 13(7) requires an updated notification whenever the submitted information changes, including ingredient list or concentration ranges. Selling the reformulated product under the old notification is a non-conformity.

How ASC Services helps

We act as Responsible Person or support your own RP through the full CPNP notification — formulation review, CMR and nanomaterial flagging, frame formulation matching where it applies — alongside the CPSR that has to back it up, and we keep the notification updated whenever your formula or your markets change. If you are also entering the Spanish market specifically, we coordinate the CPNP notification with the COSMET2 declaración responsable so neither obligation is left half-done. Talk to our team before you launch, not after a market surveillance authority asks for the file you assumed was already complete.

Importer of medical devices under the MDR: your obligations before you place a device on the market

Buying a CE-marked medical device from outside the EU and reselling it here does not make you a passive middleman. Under the Medical Devices Regulation (EU) 2017/745 (MDR), the importer is an economic operator with its own legal obligations, set out in Article 13. If the manufacturer sits outside the EU, you are one of the first lines of defence the regulation relies on — and you carry liability. This article is the checklist of what you must verify and do before the device reaches the market, distinct from the Spanish AEMPS licensing route covered in our guide on importing medical devices into Spain.

Who is an “importer” under the MDR

An importer is any natural or legal person established in the EU that places a device from a third country on the EU market. The key word is places on the market: the moment a device from outside the Union is first made available here, an EU-established importer must be behind it. This is different from a distributor (who moves devices already on the EU market) and different from the manufacturer’s authorised representative. If your device is made outside the EU, someone has to be the importer of record — and that role has non-delegable duties.

What you must verify before importing (Article 13)

Before placing the device on the market, the importer must verify that:

  • The device bears the CE marking and the manufacturer has drawn up the EU Declaration of Conformity.
  • The manufacturer is identified and, being outside the EU, has designated an authorised representative under Article 11.
  • The device is labelled in accordance with the MDR and accompanied by the instructions for use, in the language(s) required by the Member State.
  • Where applicable, the manufacturer has assigned a Basic UDI-DI and UDI.

If you believe, or have reason to believe, that the device is not in conformity, you must not place it on the market until it is brought into conformity — and you must inform the manufacturer and, for a device presenting a risk, the competent authority.

What you must do once you are importing

  • Add your details: indicate your name, registered trade name and address on the device, its packaging or an accompanying document.
  • Register in EUDAMED: importers register to obtain a Single Registration Number (SRN) and are recorded against the devices they import, so the supply chain is traceable.
  • Storage and transport: ensure conditions do not jeopardise conformity with the general safety and performance requirements (Annex I).
  • Complaints and vigilance: keep a register of complaints, non-conforming devices, recalls and withdrawals, forward this information to the manufacturer and authorised representative, and cooperate on corrective actions.
  • Records: keep a copy of the EU Declaration of Conformity and, where relevant, the certificate, available for the competent authorities.

Frequently asked questions

The device already has a CE mark. Is that enough for me to sell it?

No. CE marking is a manufacturer obligation; as importer you have your own verification and registration duties under Article 13. A CE mark that is present but unsupported by a valid Declaration of Conformity or a designated authorised representative does not make you compliant.

Can the manufacturer’s EU authorised representative act as importer?

They are separate roles with separate duties. One entity can, in some structures, hold more than one role, but the obligations of each role still apply in full and must be documented as such.

How ASC Services helps

We set up and run the importer role for you under the MDR: we verify CE marking, the EU Declaration of Conformity and the manufacturer’s authorised representative, check labelling, IFU and UDI, register you as importer in EUDAMED and obtain your SRN, and put in place the complaints, vigilance and record-keeping system Article 13 requires. Whether you import from Asia or the Americas, we make sure your position as importer of record is legally sound. Talk to us through our contact page or explore our consultancy services.

Importing tableware and food packaging from Asia: EU compliance for importers

Plates, cups, jugs, cutlery, storage boxes, kitchen utensils, food packaging: anything that will touch food is a food contact material (FCM), and in the European Union it cannot be placed on the market just because it is cheap and looks good. The most expensive mistake importers make is to assume that a certificate from the Asian manufacturer covers them. It does not. The EU requires the importer’s own Declaration of Conformity and migration tests to European norms, and legal responsibility sits with whoever imports. This article sets out what each reference needs before the goods reach the port.

The legal framework that applies to your goods

The foundation is Regulation (EC) No 1935/2004, the framework for all food contact materials: the material must not transfer its constituents to food in quantities that could endanger health, change the food’s composition, or alter its taste or smell. On top of that framework sit material-specific measures:

  • Plastics (cups, boxes, jugs, utensils): Regulation (EU) No 10/2011, with its positive list of authorised substances and migration limits.
  • Glazed ceramics (plates, mugs, bowls): Directive 84/500/EEC, which sets the release limits for lead and cadmium from the glaze — a frequent failure point in decorated imported tableware.
  • Good manufacturing practice: Regulation (EC) No 2023/2006 (GMP), applicable to every operator, including the importer.

A single container of “assorted tableware” can contain three different materials and therefore three regulatory blocks. There is no single conformity: there is one per material type.

Melamine and “bamboo” ware: handle with extra care

Cups and tableware made of melamine, and products sold as “bamboo” or “bamboo fibre”, are a standing source of EU alerts for migration of formaldehyde and melamine above the limits, especially with hot food and drink. Plastic-melamine articles with added bamboo or other plant fibres used as unauthorised fillers fall, in fact, outside Regulation 10/2011. If your order includes these references, they need specific scrutiny: many are not compliant as they stand, and it is far better to know that before you buy than after.

Why the manufacturer’s LFGB, FDA or GB report does not cover you

Asian manufacturers typically hand over an LFGB (Germany), FDA (United States) or GB (Chinese national standard) test report. These belong to other legal frameworks and do not demonstrate conformity with the European regulation. The EU requires migration testing carried out under the simulants, times and temperatures of Regulation 10/2011 (overall migration and, where relevant, specific migration of individual substances). An LFGB report can be a useful indication, but it does not replace the EU Declaration of Conformity or testing to EU norms. Presenting an LFGB report as if it were EU conformity is exactly what triggers a hold at customs. We cover this in detail in why FDA, LFGB and Chinese GB tests are not valid for EU food contact compliance.

What each reference needs to clear customs

For every model — not for the order “as a batch” — you should hold, before importing: a Declaration of Conformity identifying the material, the applicable specific measure and the intended conditions of use (aqueous / fatty / acidic contact, temperature, repeated use); migration test reports to EU norms from an accredited laboratory, consistent with those conditions; for plastics, information on substances with a specific migration limit (SML) and any dual-use additives or restricted substances; traceability of product and supplier (Reg. 1935/2004, Art. 17); and correct labelling — the glass-and-fork symbol or the wording “for food contact”, plus use instructions where safe use requires them (e.g. “not microwave safe”).

Frequently asked questions

My supplier gave me an LFGB certificate. Do I still need EU testing?

Yes. LFGB is a German methodology under a different legal basis. It may be informative, but EU market access requires a Declaration of Conformity and migration testing under Regulation 10/2011 (for plastics) or the relevant specific measure for the material.

Do I need one Declaration of Conformity for the whole shipment?

No. Conformity is per material and per reference. A mixed shipment of plastic, ceramic and melamine items needs separate conformity documentation for each type.

How ASC Services helps

We prepare the compliance of your imported tableware and food packaging reference by reference: we classify each model by material, identify the norms and tests it needs, review the manufacturer’s reports to see what is usable and what is missing, arrange the missing migration tests to EU norms, and draft the Declaration of Conformity ready to accompany the import. If a product (melamine-bamboo, ceramics exceeding lead limits) is not compliant, we tell you before you buy it. Talk to us through our contact page or explore our consultancy services.