Compliance
Retailers want a 2D barcode beside the UPC. The FDA wants traceability lot codes on food at every handoff. Privacy law wants personal and health data kept out of systems that don't need it. Qpro+ handles each one as a template change or a field setting, so the systems that call the API don't change.
01 · Retail
Add a GS1 DataMatrix or Digital Link QR beside the UPC on the templates you already print, and move each retailer on its own date.
Sunrise 2027 →02 · Food safety
Print the traceability lot code on the case at the moment it's packed, in GS1-128 or DataMatrix, so the label matches the record.
FSMA 204 →03 · Privacy
Mark any field pass-through and it renders on the label without being written to our database. Watch the record to verify it.
GDPR, HIPAA & PII →GS1 Sunrise 2027
GS1 Sunrise 2027 is the industry's target for retail point-of-sale systems to scan 2D barcodes (GS1 DataMatrix, or a QR code carrying a GS1 Digital Link) by the end of 2027. It's a retail commitment, not a regulation, and the UPC isn't going away. The practical result is dual marking: both codes on the same artwork, on timelines each retailer sets for its own suppliers.
Add a GS1 DataMatrix or Digital Link QR next to the existing UPC or GS1-128 on the template you already print. GS1 guidance keeps the two codes close together so either scanner finds its code, and the canvas gives you precise placement to follow it.
A 2D code can carry batch or lot, expiry, and serial number alongside the GTIN. Bind those to the fields your system already sends, and the values are encoded when the label renders, the same way every other field on the template resolves.
Clone the approved template, add the 2D code, and leave the clone in Draft until that retailer or brand is ready. Promote it on their date. There's no single cutover for your whole library.
The request that prints today's label prints the dual-marked version. The new code lives in the template, so no calling system needs a release.
{
"label_name": "RETAIL-CASE-2D",
"amount": 1,
"apiData": {
"gtin": "00012345678905",
"lot": "L25-8814",
"expiry": "2028-12-31",
"serial": "SN000417"
}
}
Same request as before the 2D code was added. The template decides what's encoded and where it sits: the UPC-A still comes from gtin, and the GS1 DataMatrix resolves at render to (01)00012345678905(10)L25-8814(17)281231(21)SN000417.
Check your retailers' dates, not just 2027. Sunrise 2027 sets when scanners should be ready. When your labels need the 2D code is up to each retailer's supplier requirements, and some will ask sooner.
FSMA 204 food traceability
The FDA's Food Traceability Rule covers foods on the Food Traceability List. It requires key data elements at each critical tracking event, all keyed to a traceability lot code, and records you can produce as a sortable spreadsheet within 24 hours of an FDA request. Congress has directed the FDA not to enforce it before July 20, 2028. The rule doesn't prescribe a label or barcode format, but the lot code has to travel with the food to the next party, and in practice it travels on the case label.
| Tracking event | What the label needs to carry | What Qpro+ does |
|---|---|---|
| Initial packing | The newly assigned traceability lot code, product identity, and pack date | Renders the case label when the case is packed, with the lot code your system just assigned, so no label is printed ahead of the record. |
| Transformation | A new traceability lot code for the new product | The new lot code prints the moment it exists. There's no pre-printed stock to relabel when a batch is split or reworked. |
| Shipping | Lot code on each case, SSCC on the pallet, and shipping documents for the receiver | Case and pallet labels with GS1-128 and SSCC, plus packing lists as PDF, from the same template library and the same data. |
| Receiving | A lot code the receiver can capture without typing it | Lot codes encoded in GS1-128 or DataMatrix scan straight into the receiver's system, which removes the transcription errors that break a trace. |
With no FDA-mandated format, suppliers follow GS1 US guidance and customer requirements: GTIN, batch or lot, and dates in GS1-128, with Produce Traceability Initiative case labels common in fresh produce. Qpro+ supports the full GS1 symbology set, and a PTI voice pick code prints like any other field your system supplies.
Labels render when the API is called, with values from your ERP or WMS at that moment. The lot code on the carton is the one in the record because both come from the same call.
Customers will add their own traceability requirements to their routing guides. Each one is a template variant, cloned from your base and approved before it prints.
Version history records which template was active and who approved it. Print history by date shows what was produced, and you can reprint from the list when a label is damaged.
It prints the traceability lot code and whatever other key data elements you put on the label, in standard scannable formats, at the moment of the event. That keeps the physical label and the traceability record in agreement.
Qpro+ is not your traceability record system. The key data elements, the traceability plan, and the 24-hour sortable spreadsheet come from your ERP, WMS, or traceability software. Qpro+ prints what that system knows, and we'll tell you plainly where that line sits for your setup.
GDPR, HIPAA & PII · Pass-through data
Labels can carry regulated information: personal data of EU residents under GDPR, protected health information under HIPAA, and personally identifiable information under a growing set of state and national privacy laws. Mark any mapped field as pass-through, and it's used to render the label without ever being written to our database. You set this per field when you map it, so you decide which values are kept for history and reprint and which are discarded once the label is rendered.
A lot number probably belongs in your print history. A recipient's name probably doesn't. You set that per field, not per account.
The value is used to produce the label output and is not committed to the database record for that render.
The render is still logged for metrics and audit. The retained record just doesn't contain the pass-through values.
Data we never store is data that doesn't need to appear in your processing inventory, your retention schedule, or your breach exposure.
{
"label_name": "SHIP-DOC-4x6",
"amount": 1,
"apiData": {
"order_ref": "SO-88214",
"ship_date": "2026-08-16",
"recipient": "J. Rivera",
"address_line": "100 Harbor Way"
}
}
recipient and address_line are marked pass-through in the canvas field mapping, so the request looks like any other. They're used to produce the PDF and left out of the stored render record.
Verification
We built this because a customer operating in the EU needed to prove it, not just be told it. The walkthrough follows a single value from the canvas to the database and shows you what's there at the end.
We place the field on the canvas together, so you can see exactly where the value lands on the rendered output.
The field is marked pass-through in the mapping step. You choose which fields, live, during the session.
A real render request is sent with a real value in that field, and the finished label comes back with the value printed on it.
We open the stored record for that render in front of you. The label rendered correctly. The pass-through value isn't there.
You'll also get it in writing. The walkthrough comes with documentation of the data flow, so your compliance reviewer has something to file alongside what your engineer watched happen.
Regulations
Pass-through doesn't make a regulation go away. It removes Qpro+ from the part of the data flow the regulation is concerned with, which is usually the harder part to solve.
| Regime | Typical label data | What pass-through changes |
|---|---|---|
| GDPR | Recipient names, addresses, and contact details on shipping labels and documents | The value is rendered and released rather than retained, so it isn't sitting in a vendor system subject to retention, access, and erasure obligations. |
| HIPAA | Patient identifiers on specimen, pharmacy, and chart labels | Identifiers produce the label without being stored, which narrows what a business associate agreement has to cover. |
| PII (state and national) | Names, account numbers, and device serials tied to individuals | Data we never store doesn't appear in your processing inventory, your retention schedule, or your breach exposure. |
| UDI and traceability | Device identifiers, FSMA 204 lot codes, expiry, serialization | Retained deliberately, because you need this history. Pass-through is set per field, so traceability data stays and personal data doesn't. |
Qpro+ gives you a technical control: named fields render without being persisted, and you can watch it work on your own data. That materially reduces your exposure under GDPR, HIPAA, and PII regimes, because it reduces what a vendor holds in the first place.
A control is not a certification. Compliance depends on your whole data flow, not on one vendor inside it. If your use requires a signed business associate agreement, a data processing agreement, or a specific attestation, ask us directly. We'd rather tell you exactly where we stand than let a web page imply something we haven't signed.
Pass-through is available on paid plans. If you're evaluating and need it to assess fit, tell us and we'll enable it for your test account.
The walkthrough is live, uses your data, and takes about thirty minutes. Bring a Sunrise 2027 retail label, an FSMA 204 case label, or a document with personal data on it, and we'll build it on a call.
Qpro+ is a product of Quando Solutions, a supply chain & manufacturing IT company