Pharmaceutical serialisation: what the Data Matrix code proves and what it does not

Every prescription pack moving through the European supply chain carries a 2D Data Matrix code. Under the Falsified Medicines Directive and Delegated Regulation (EU) 2016/161, the marketing authorisation holder uploads a unique identifier to the EU Hub and the pharmacy checks and decommissions it at the point of dispensing. As an architecture for keeping falsified medicines out of the legal supply chain, it works.

The trouble starts one step to the side of the code. Pharmaceutical serialisation answers a single question with precision: is this pack the one the manufacturer registered? It says nothing about the pallet that arrived with a crushed corner, the hours a consignment spent on a hot dock, or which operator signed for it.

Serialisation proves the identity of a pack, not the conditions it passed through. The evidence around the code is what settles disputes, closes alerts and satisfies inspectors, and it only holds up if origin, time and integrity are fixed when it is created rather than reconstructed later.

Pharmaceutical serialisation is the system that gives each pack of prescription medicine a unique identifier, encoded in a 2D Data Matrix code and verified against national repositories. It confirms that a specific pack is registered and has not already been dispensed. It records nothing about storage, transport or handling.

What the unique identifier on the pack actually proves

The unique identifier proves registration and status, and stops there. A successful verification tells you the code was uploaded by the marketing authorisation holder, matches a record in the national repository and has not yet been decommissioned. It is a statement about a database.

What the 2D Data Matrix code on a medicine contains

The 2D Data Matrix code on a prescription medicine carries a unique identifier built from four mandatory data elements: a product code, normally a GTIN under the GS1 standard, a randomised serial number, the batch or lot number, and the expiry date. Some markets add a national reimbursement number. Delegated Regulation (EU) 2016/161 requires this code on every pack within its scope, together with an anti-tampering device on the carton. The two safety features answer different questions. The code says which pack this is. The anti-tampering device says whether the carton has been opened. Neither records temperature, handling or who signed for the pallet. The identifier is uploaded by the marketing authorisation holder to the EU Hub, distributed to the relevant national repositories, and checked against them by wholesale distributors and pharmacies before the medicine reaches a patient.

How verification works across manufacturer, wholesaler and pharmacy

Verification is a chain of scans against a shared set of repositories, with a defined role for each actor:

  1. The marketing authorisation holder uploads unique identifiers to the EU Hub.
  2. The EU Hub distributes those identifiers to national repositories.
  3. Wholesale distributors verify packs on risk-based or mandatory checks.
  4. The pharmacy verifies and decommissions the pack when dispensing.
  5. Any mismatch raises an alert for investigation.

The wholesaler’s position is the one most often misread. A wholesale distributor under Good Distribution Practice is not required to scan everything, and the packs it does not verify still pass through its warehouse, its vehicles and its temperature-controlled rooms.

The limit of the repository: pack identity, not batch history

The European Medicines Verification System is a status register, not a history. It knows a serial number exists and whether it is active or decommissioned. It holds no route, no timeline and no chain of custody for the physical goods. When a customer disputes a shipment, the repository confirms the packs were genuine and says nothing about what arrived, in what state, on what day.

System traceability and data provenance are not the same thing

Traceability records that something happened. Digital Provenance demonstrates who produced a piece of evidence, when, and under what conditions. Track and trace gives you the first, almost nothing in a pharmaceutical warehouse gives you the second, and it is the second that a dispute turns on.

A recorded fact is not a demonstrable fact

A recorded fact is a database entry. A demonstrable fact is one whose origin, timing and integrity can be shown to a third party months later. The European verification system makes the gap visible. The European Medicines Verification Organisation targets an alert rate below 0.05%, yet the overall European rate stood at 0.26% in week 13 of 2024, with seven countries reporting between 0.16% and 1.17%. The three dominant causes are not falsification: errors in the data uploaded by the marketing authorisation holder, scanner problems, and the same pack being decommissioned twice. Each alert still has to be investigated and closed, and the investigation runs on evidence the system never captured, such as what the carton looked like, what the operator did, and what the reader displayed. The repository proves a pack was flagged. It does not prove what was in front of the person who scanned it.

National figures show the pattern maturing rather than disappearing. Germany saw around 5% of packs unrecognised in the first month of 2019, 0.42% by year end and 0.07% the year after. France sits between 0.2% and 0.3%, with roughly 400 pharmacies still running incompatible or misconfigured scanners and only about 75% of dispensed packs actually verified and decommissioned.

What serialisation proves What serialisation does not prove
That a pack carries a unique identifier registered in the national repository The temperature range the pack travelled through
That the identifier has not already been decommissioned Who physically received the pallet, and in what condition
The product code, batch number and expiry date declared by the marketing authorisation holder Whether the outer carton was damaged before or after delivery
That the anti-tampering device is intact when someone inspects it When and where a photograph of that damage was actually taken
That the pack was switched to a supplied status at a given time What the operator saw on screen when an alert was raised

The evidence nobody certifies: goods receipt, storage, transport

The events that generate liability are the ones with no evidential layer at all. Goods-in, storage and transport produce photographs, delivery notes, logger exports and screenshots, all created by interested parties on ordinary devices, all easy to challenge, none of them sealed at capture.

The disputed delivery at goods-in

A goods receipt dispute is decided by the documentation of the handover, not by the serialisation record. Consider a depot receiving a pallet of temperature-sensitive medicines. The outer carton is dented, the data logger shows an excursion, and the operator scans the Data Matrix codes: the repository answers “authentic” on every pack, because Delegated Regulation (EU) 2016/161 concerns identity, not condition. Four months later the supplier rejects the debit note and argues the damage happened in the customer’s warehouse. At that point the case rests on three items: photographs of the carton, the temperature trace, and the delivery note signed with a reservation. If none of them were certified when they were created, each one is a party’s own reconstruction, produced on a device the other side has no reason to trust, and the dispute is settled by commercial weight rather than by evidence.

Good Distribution Practice expects you to check consignments on arrival and record any deviation. The requirement stops at recording, and says nothing about making that record resistant to a challenge raised a year later.

Storage conditions reconstructed after the fact

Cold chain evidence has the same weakness in a different form. A logger export is a file anyone can open and edit, and its link to a shipment is usually an operator typing a reference into a field. Reconstructing storage conditions after a quality defect means assembling documents whose provenance was never fixed.

Type of evidence Who produces it What makes it hold up
Verification of the unique identifier The NMVS, on a wholesaler or pharmacy scan The repository record: identity is what the system attests
Goods receipt photographs of pallets, cartons and labels The operator at the loading bay Origin, time and integrity sealed at capture
Cold chain temperature traces A data logger or vehicle telemetry An unbroken link between file, device and consignment
Non-conformity reports and reservations on delivery notes Warehouse and quality staff Content that cannot be altered after signing
Screenshots of traceability systems and alert screens Whoever operates the scanner or the warehouse system Certification at capture, with verified metadata

What an inspection asks for months later

An inspection asks you to demonstrate that your records describe what actually happened, long after the fact. GDP and GMP inspectors work backwards from a batch, a deviation or a complaint, and the question is always the same: show me the evidence, and show me it has not moved since.

Regulatory inspections test the reliability of records, not their existence. A GDP inspector examining a returned consignment will ask when the goods receipt photographs were taken, on what device, by whom, and whether anything could have changed between capture and filing. Under Delegated Regulation (EU) 2016/161 you must also be able to reconstruct how alerts were investigated and closed. Files sitting in a shared folder with editable creation dates answer none of these questions, and the gap tends to surface at the worst moment, when a recall or a quality defect is already under way. Evidence sealed at capture with a qualified timestamp under eIDAS Regulation (EU) 910/2014 arrives at the inspection with its own history attached: the moment, the place and the operator are part of the record rather than a claim made about it afterwards.

The same logic governs medical devices under EU MDR 2017/745, where post-market surveillance depends on evidence gathered by field staff. The US DSCSA hits the same limit from a different direction: unit-level traceability of identity, silence on condition.

What makes the record of a pharmaceutical supply chain handover hold up

A record of a handover holds up when its origin, time and integrity are fixed at the moment the evidence is created. TrueScreen, the Data Authenticity Platform, certifies each photograph, video, screenshot and document at the instant of capture, so the state of the goods on arrival stays demonstrable months later.

Organisations in pharmaceutical distribution use TrueScreen to document batch receipt, storage conditions and inspection findings with a verifiable chain of custody. Each item is sealed at capture with a digital seal, a qualified timestamp issued by a QTSP integrated in the platform under eIDAS Regulation (EU) 910/2014, and verified metadata covering GPS position, date, time and device. In practice that covers photographs of batches, packs, labels and Data Matrix codes, video of inspections in plants and distribution centres, screenshots of traceability systems and digital registers, non-conformity documents and audit reports, and recordings of temperature and humidity during storage and transport. The result is a continuous chain: every piece of evidence is tied to the moment, the place and the operator who produced it. Adoption runs through the app, the web platform, an API or an SDK, supporting compliance with Delegated Regulation (EU) 2016/161 and EU MDR 2017/745.

Take the dented pallet again. The operator photographs the carton and the delivery note on the loading bay, the temperature trace is certified as it is exported, and the reservation is signed on the spot. Four months later the file is not an argument about who took what and when: it is a set of sealed items with their own provenance. The same approach runs across healthcare and pharma operations and in pharmaceutical and medical device verification, and it sits behind the digital product passport in other regulated sectors.

FAQ: common questions about pharmaceutical serialisation

What exactly does the unique identifier on a medicine pack prove?
It proves the pack carries a serial number registered by the marketing authorisation holder in the national repository, and whether that number has already been decommissioned. Under Delegated Regulation (EU) 2016/161 the identifier holds a product code, a randomised serial number, the batch number and the expiry date. It records nothing about storage or handling.
Does serialisation show how a batch was stored and transported?
No. Serialisation and the European Medicines Verification System deal with pack identity and status, not physical conditions. Temperature excursions, damaged cartons and delayed shipments leave no trace in the repository. That information exists only in data logger exports, delivery notes and photographs, produced outside the verification system and carrying no built-in guarantee of when they were created.
What is the difference between a Data Matrix code and a QR code?
Both are 2D barcodes following different standards for different purposes. The 2D Data Matrix used on medicines is specified under GS1 rules and encodes a structured unique identifier readable by verification systems. A QR code is a general-purpose symbol, typically pointing to a web address. The Falsified Medicines Directive framework relies on Data Matrix, not QR.
Why are alert rates so much higher than the target?
The European Medicines Verification Organisation targets an alert rate below 0.05%, while the overall European rate reached 0.26% in week 13 of 2024, with seven countries between 0.16% and 1.17%. Most alerts come from data upload errors by marketing authorisation holders, scanner problems and double decommissioning, not from falsified medicines.
How do you contest a delivery when the codes verify as authentic?
You contest it with evidence of condition, since the codes only settle identity. That means photographs of the packaging taken at goods-in, the temperature trace covering the journey, and a delivery note signed with an explicit reservation. Those items carry weight in proportion to how reliably their origin, time and integrity were fixed when they were produced.

Certify goods-in evidence the moment it is created

Photographs of pallets, temperature traces and verification screenshots captured with a digital seal and a qualified timestamp, still holding up years later.

Start now
Request a demo

TrueScreen