← Insights

GPSR

GPSR Due Diligence: What PE Funds Miss Before E-Commerce Acquisitions

What is GPSR? The EU General Product Safety Regulation creates hidden COGS liabilities invisible to standard financial due diligence. Here is what to check before opening the data room.

What is GPSR? The EU General Product Safety Regulation is an EU regulation, applicable since 13 December 2024, requiring non-EU manufacturers placing products on the EU market to meet product safety, conformity, and documentation requirements: CE marking, an EU Authorised Representative, and local-language technical documentation among them.

GPSR is one of the least-examined liabilities in e-commerce M&A. Financial due diligence does not surface it; legal due diligence treats it as a box to tick. Neither prices what non-compliance does to post-acquisition margins.

Why GPSR Creates Fake EBITDA

A non-compliant e-commerce target reports product margins based on its current cost structure. That cost structure assumes:

  • No CE testing costs
  • No EU Authorised Representative registration fees
  • No local-language technical documentation
  • No conformity assessment processes

Each of these is mandatory under GPSR for products placed on the EU market by non-EU manufacturers. Sooner or later a post-acquisition compliance programme arrives. When it does, these costs land in COGS across the entire portfolio, and they do not leave.

The GP1 margin the acquirer modelled no longer exists.

The Three Compliance Costs Hidden in Non-Compliant E-Commerce Targets

CE Marking and Declaration of Conformity

CE marking is not a sticker. It requires a formal conformity assessment process, a Declaration of Conformity document, and in many product categories, third-party testing by a notified body. For targets sourcing from third countries such as China, Turkey, or Southeast Asia, these processes have typically never been completed.

Cost impact: Third-party testing runs €500–€5,000 per product SKU depending on category. For targets with large, diversified catalogues, this is a structural COGS addition, not a one-time remediation.

EU Authorised Representative Registration

Non-EU manufacturers placing products on the EU market must appoint an EU Authorised Representative and register them with each relevant national authority. This obligation cannot be waived. The representative must be named in product documentation and be reachable for regulator queries.

Cost impact: Representative services cost €200–€800 per product category per year. These are ongoing operational costs, not one-time compliance fees. They compress GP1 permanently.

Local-Language Technical Documentation

GPSR requires that safety information, instructions, and declarations be provided in the official language of each EU member state where the product is sold. For pan-EU e-commerce targets, this means documentation in up to 24 languages per product family.

Cost impact: Translation and ongoing documentation maintenance adds material cost per SKU that does not appear in the pre-acquisition cost base.

The Listing Itself Is Now Part of the Compliance Surface

Since 13 December 2024, Article 19 of the GPSR requires that any product offered for distance sale display, in the listing itself, the manufacturer’s name and contact details, the EU responsible person where the manufacturer sits outside the EU, information identifying the product, and any applicable warnings or safety information. Not in a policy page, not available on request: in the listing.

That changes the diligence picture in two ways. First, non-compliance became observable from the outside. A product page with no manufacturer named and no responsible person listed is not a gap a data room can reframe; it is published, timestamped evidence of where the compliance programme stands. Second, enforcement no longer waits for a market-surveillance authority. Online marketplaces carry their own obligations under GPSR, and under the Digital Services Act they must collect and verify trader information before letting a seller trade at all. The practical consequence: listings missing required safety information get suspended by the platform, through business logic rather than legal process. For a target with meaningful marketplace revenue, an unfixed Article 19 gap is less a fine risk than a revenue interruption waiting on the next policy sweep. How aggressively each marketplace polices each category varies, and that variation is itself worth mapping per target rather than assuming.

Why This Slips Through Due Diligence

Financial diligence has no natural place to find a cost that was never paid: absent CE testing, an unappointed representative, and untranslated documentation leave no trace in a P&L, and QoE reconciles what was spent, not what should have been. Legal diligence samples contracts and policies, not product pages, and a compliance representation from the seller is only as good as the seller’s own understanding. That understanding is often sincere and wrong: a brand that has sold into the EU for years without a complaint genuinely believes its products are compliant, because nothing has yet forced the question. The gap is structural, which is why it recurs deal after deal.

GPSR is also not the only EU regime that attaches manufacturer-grade obligations to a sourcing relationship the target doesn’t fully control. The incoming Digital Product Passport regime raises the same exposure in a sharper form for white-label operators. See You Are the Manufacturer Now for why that gap is often harder to close with money alone.

What Outside-In Analysis Can Detect

Outside-in analysis can establish, before the data room opens:

  • Product portfolio origin (third-country sourcing indicators from public listing data and brand registrations)
  • CE marking presence or absence across representative SKU samples
  • Article 19 listing checks across representative SKUs: whether manufacturer identity, an EU responsible person, product identification, and warnings appear in the listing itself, on the target’s own store and on each marketplace it sells through
  • EU Authorised Representative registration status via public authority databases
  • Documentation compliance signals from storefront language implementations
  • The share of revenue flowing through marketplace channels that enforce these requirements by suspension, as a proxy for how fast a compliance gap could become a revenue gap

These signals are sufficient to establish a directional liability range, and to scope the GP1 questions the formal diligence should quantify, before any data room access is granted. As throughout this series, they are indications for aiming the real work, not conclusions.

The Pre-LOI Question Every PE Fund Should Ask

Before submitting a Letter of Intent on an e-commerce target, the question is not whether GPSR applies. It applies to every product sold into the EU market. The question is: how much of the reported GP1 margin is structurally dependent on not complying with it?

Quantifying that correction before LOI gives the acquirer direct leverage on valuation. Discovering it post-close gives the seller that leverage instead.


This analysis is part of Tronvik’s GP1 Product Margin Security pillar. Nothing in this article constitutes legal advice. To initiate an outside-in GPSR mapping on a specific acquisition target, contact info@tronvik.com.