From 30 December 2026 (Art. 38(2) EUDR), the core obligations of the Deforestation Regulation (EU) 2023/1115 apply. Wholesalers selling furniture, pallets, paper and board, wood-based panels, tyres, coffee or chocolate take on a duty that sounds less like a sustainability report and more like master data: every delivery of an affected product needs details on the supplier and the customer and, where the supplier is itself an operator, the reference number of its due diligence statement (Art. 5(3) EUDR). These details must be kept for at least 5 years (Art. 5(4) EUDR). If the number only arrives as a PDF attachment in the purchasing inbox, it is practically invisible to the warehouse, sales and accounting. This article shows how it can instead travel as a data field from goods receipt through ERP and shop to delivery note, invoice and customer account, and why the B2B shop takes on the role of a data chain rather than a shop window.
Key takeaways
- The core obligations of the EUDR apply from 30 December 2026 (Art. 38(2) EUDR). For micro and small companies that were established as operators on 31 December 2024, the date is 30 June 2027 (Art. 38(3) EUDR).
- Traders and downstream operators record supplier and business customer for each delivery and, where the supplier is an operator, the reference or identification number (Art. 5(3) EUDR).
- These details must be kept for at least 5 years from the date of supply and made available to the authorities on request (Art. 5(4) EUDR).
- The reference number belongs to goods receipt and batch, not to the item master: one delivery can contain goods from several statements, and one number can recur in several goods receipts.
- The B2B shop already holds most of the customer details: company name, postal address and email address from the business account cover the core of what Art. 5(3) EUDR requires for customers; the web address is added where available.
- Without the required information, affected products may not be made available (Art. 5(1) EUDR). An availability rule in the shop puts this into practice.
What applies from 30 December 2026
The regulation governs placing on the market, making available on the Union market and exporting products that contain, or were made using, 7 relevant commodities: cattle, cocoa, coffee, oil palm, rubber, soya and wood (Art. 1(1) EUDR). Such products may only be traded if three conditions are met together: they are deforestation-free, they were produced in accordance with the relevant legislation of the country of production, and they are covered by a due diligence statement or a simplified declaration (Art. 3 EUDR). Deforestation-free essentially means that the commodities were produced on land that has not been subject to deforestation after 31 December 2020 (Art. 2(13) EUDR).
The dates deserve a closer look. The articles containing the actual obligations apply from 30 December 2026 (Art. 38(2) EUDR). For micro and small companies established on 31 December 2024, the start moves to 30 June 2027 (Art. 38(3) EUDR). The wording of this exception refers to operators; whether it also covers small traders is something each company should clarify with its legal advisers. For micro and small companies whose products were already covered by the EU Timber Regulation (EUTR), the date remains 30 December 2026 (European Commission). Products newly added to the scope by Delegated Regulation (EU) 2026/2102, including soluble coffee, only become subject to the regulation from 30 December 2027 (European Commission).
The regulation has been adjusted several times since it was adopted: in December 2024 and December 2025 the EU amended it and introduced simplification measures (European Commission). In addition, Art. 34(1a) EUDR required the Commission to carry out a simplification by 30 April 2026 and to report on it, where appropriate with a legislative proposal. The data duties in this article follow the wording of the consolidated version of 26 December 2025; anyone planning an implementation should check the legal status again before starting. As with the Data Act and its data disclosures before purchase, what matters in the end is not reading the legal text, but whether the required field exists in the system and is filled in.
Three roles with different duties
Which product groups in a B2B range are affected
Annex I EUDR defines the products in scope by reference to the Combined Nomenclature, the same commodity codes used in customs declarations and Intrastat reports. For B2B trade these areas matter most: wooden furniture in furniture and contract wholesale, pallets and crates as well as paper and board in the packaging trade, wood-based panels for construction and trades, tyres and rubber goods, coffee and chocolate in food wholesale and cattle leather.
| Product group | Entry in Annex I | Typical B2B case | Note |
|---|---|---|---|
| Wooden furniture | ex 9401 (wooden seats), 9403 30, 9403 40, 9403 50, 9403 60, 9403 91 (wooden furniture and parts) | Office, contract and shop fittings | Wooden parts are covered as well |
| Pallets, crates, cable drums | 4415 | Load carriers sold as goods in their own right | Not covered when used solely to support, protect or carry another product |
| Paper and board | Chapters 47 and 48 | Cardboard packaging, labels, office and printing paper | Recovered paper (waste and scrap) and bamboo-based products are excluded |
| Wood-based panels | 4410, 4412 | Particle board, OSB, plywood | When cutting to size, carry the number of the source panel |
| Tyres and rubber goods | ex 4010, ex 4011, ex 4012 | Tyre trade, conveyor belts, transmission belts | The ex prefix covers only part of the heading |
| Coffee and chocolate | 0901, 1806 | Catering and office supplies | Soluble coffee only from 30 Dec 2027 (Delegated Regulation (EU) 2026/2102) |
| Cattle leather | ex 4107 | Upholstery and saddlery supplies | Leather of bovine animals further prepared; hides and skins are listed separately |
Traders with international business keep the commodity code for customs and trade statistics anyway; how it sits cleanly in the item master is covered in the article on customs codes, origin and supplier declarations. For the EUDR, the code becomes a filter: every commodity code listed in Annex I marks a candidate. If the heading carries an "ex" prefix, the regulation covers only part of the goods in that heading. These cases need a qualified decision that is then stored as an attribute on the item instead of being made again with every order.
Two exceptions directly affect the packaging trade. Wooden pallets, crates and other load carriers under heading 4415 are not covered when they are used solely as packaging to support, protect or carry another product (Annex I EUDR). Anyone selling pallets as goods is covered; anyone delivering machines on pallets is not covered for the pallet. For shipping cartons from chapter 48, the annex does not state this exception explicitly, so a separate clarification is worthwhile here. In addition, the regulation does not apply to goods produced entirely from material that has completed its lifecycle and would otherwise have been discarded as waste (preliminary note to Annex I EUDR). For cardboard packaging made entirely from recycled material, it therefore pays to keep the recycled share as an attribute on the item.
Which data must be available per delivery
The principle is set out in Art. 5(1) EUDR: downstream operators and traders may only place relevant products on the market, make them available or export them if they are in possession of the required information. Art. 5(3) EUDR defines that information in two directions. Upstream: name, registered trade name or trademark, postal address, email address and, where available, web address of the supplier, plus the reference numbers of the due diligence statements or the identification numbers, but only where the supplier is an operator. Downstream: the same contact details of the downstream operators and traders to whom products were supplied.
Three things follow for the system landscape. First, consumers do not appear in the customer list, because the provision only names downstream operators and traders. A shop serving both business customers and consumers has to separate the two groups cleanly. Second, if a trader buys from another trader, it needs that trader's contact details but no reference number. The number is created by the operator and travels one step further from there. Third, the information must be kept for at least 5 years from the date of supply and made available to the authorities on request (Art. 5(4) EUDR).
Companies that are not SMEs have an additional task: they register in the EU information system before placing relevant products on the market, making them available or exporting them (Art. 5(2) EUDR). And a trader that receives new information or substantiated concerns that a product already supplied does not comply with the regulation informs the competent authorities and the customers it supplied without delay (Art. 5(5) EUDR). At the latest at this point it becomes clear whether the system can quickly tell which customers received a particular delivery.
- Supplier with name, trade name, postal address, email address and, where available, web address
- Reference or identification number per delivery, where the supplier is an operator
- Business customer with the same details, kept separate from consumer customers
- Date of supply as the start of the retention period
- Link between number, item, quantity, batch and delivery
- Registration in the information system if the company is not an SME
The core in one sentence
The reference number as a data object
The number is created in the EU information system. When an operator submits a due diligence statement there, the system transmits a reference number for exactly that statement (Art. 33(2) EUDR). The system has been in operation since 4 December 2024 (European Commission). Micro and small primary operators instead submit a one-off simplified declaration and receive an identification number (Art. 4a(2) EUDR). The operator communicates the reference or identification numbers to its customers in the downstream supply chain (Art. 4(7) EUDR).
For the data model this means: the number is not an item attribute. One delivery can contain goods from several statements, and the same number can recur in several goods receipts, for example with partial deliveries. The relationship between number and goods receipt is therefore many-to-many. Anyone who keeps the number as a text field on the item overwrites it with the next delivery and loses exactly the link that will be asked for later. The right place for it is the goods receipt and, where used, the batch. How batches move through warehouse and shop is described in the article on traceability with batch and serial numbers.
Number as a record of its own
Number, type of number, supplier, date of receipt and origin of the information sit in a dedicated table instead of a free-text field.
Link to goods receipt
Every goods receipt line refers to one or more numbers. If the number is missing, the line stays in open status.
Batch and storage bin
Where batches are managed, the number is attached to the batch. This keeps the link intact after transfers and partial withdrawals.
Flag in the PIM
An attribute marks items whose commodity code is listed in Annex I. It controls mandatory fields, blocks and document texts.
Number on the document
Delivery note and invoice carry the number per line. The customer finds the information where they look for it.
Storage with a period
Every record carries an earliest deletion date derived from the date of supply. Nothing is cleaned up before then.
How the number arrives determines the effort. If it comes as free text in an email, someone types it in, with every typo that implies. If it arrives in structured form, it can be checked and assigned automatically. A digital supplier portal for purchasing and goods receipt can make the number a mandatory field in the advance shipping notice. For suppliers who send their shipping notices via EDI, whether the number comes along depends on the agreed message; this belongs in the coordination with the supplier before the first affected delivery arrives.
From goods receipt to the invoice line
The chain has five links, and each needs clear ownership. At goods receipt the number is captured and checked. In the ERP it is attached to batch and stock. The shop reads from there which stock may be sold. The order connects stock and customer. Delivery note, invoice and customer account pass the result on and store it. The ERP is usually the leading system; shop and PIM read the numbers but do not write them. How the connection between ERP and shop is built in principle is shown in the overview of ERP integration in B2B e-commerce.
The customer side is the easier part in a B2B shop, because the data already exists. A business account contains company name, billing and delivery address and an email address, which is the core of the details Art. 5(3) EUDR requires for customers; an additional field holds the web address where the customer has one. Every order therefore automatically produces the customer record for the delivery. What needs checking is whether the mandatory fields are really maintained and whether consumer accounts are clearly flagged. The integrations between shop, ERP and archive keep these details linked to the delivery, even if the customer changes its address later.
On the item side, the PIM handles the flagging. Commodity code and EUDR attribute sit on the item, together with a note on whether the classification has been checked. Through PIM integration the attribute reaches shop and ERP, so all systems use the same list of affected items. At the end of the chain is the document: the number appears per line on delivery note and invoice. In the electronic invoice it can be passed on as line information, so the customer can take it over by machine.
Four places where the chain breaks
What the B2B shop takes on
Art. 5(1) EUDR leads to a clear rule for sales: an affected product for which the required information is missing may not be made available. In the shop, this can be modelled as an availability rule. For flagged items, the ERP reports as available only the stock whose goods receipt is fully documented; the rest stays blocked until the details have been added. In Shopware this can be modelled without a special path if the ERP connection transfers only the released stock, just as it transfers stock otherwise. A short note on the product page can explain why part of the quantity cannot be ordered yet.
For customers who resell, the customer portal becomes the information desk. If the shop operator is itself an operator, for example because it imports, it must pass the reference numbers on to its customers (Art. 4(7) EUDR). If it is a trader, passing them on is not an explicit duty under Art. 5 EUDR; customers may still request the numbers for their own documentation. In both cases a list in the customer account answers such requests without a detour through the sales back office: per delivery the lines, the related numbers and an export as a file.
The same data helps when something goes wrong. If a trader learns of substantiated concerns about goods already supplied, it must inform the authorities and the customers it supplied without delay (Art. 5(5) EUDR). With number, batch and order, the list of recipients can be generated directly from the system. How the same supply chain evidence also counts under the new product liability rules is described in the article on the product liability directive and the supplier trail.
Retention, checks and fines
The retention period of at least 5 years starts with the date of placing on the market or making available, not with the end of a financial year (Art. 5(4) EUDR). It therefore runs independently of commercial and tax retention periods, even where the same documents are affected. In practice, every EUDR record carries its own earliest deletion date. Where documents sit in the customer account and how long they stay there is covered in the article on where order documents live and how long they stay.
Member states check against fixed minimum quotas. The annual checks cover at least 1 % (Art. 16(10) EUDR) of operators as well as of downstream operators and traders that are not SMEs, where the commodities come from countries or parts of countries with low risk. For standard risk the figure is at least 3 % (Art. 16(8) EUDR), for high risk at least 9 % (Art. 16(9) EUDR), which there also applies to the quantity of each relevant product. The risk level follows the classification under Art. 29 EUDR.
Member states lay down penalties for infringements. For legal persons, the maximum amount of the fine must reach at least 4 % of annual Union-wide total turnover (Art. 25(2) EUDR). The figure describes a ceiling that may not be set lower, not a standard penalty. It does show, however, that the documentation is not a side topic for the sustainability team but belongs in the processes of purchasing, warehouse and sales.
Trial run before the deadline
Implementation in Shopware and ERP
The implementation does not have to be a major project if it runs in the right order. First comes the functional clarification, then the data model, and the interface last. Anyone who starts with the shop builds displays for data that does not exist yet.
- Clarify the role per product group: operator, downstream operator or trader, and determine the SME status of the company.
- Filter the range: match commodity codes against Annex I, decide ex headings on the merits and set the EUDR attribute in the PIM.
- Involve suppliers: agree channel and format for reference and identification numbers, preferably as a field in the shipping notice or the supplier portal.
- Extend goods receipt: mandatory field for flagged items, link to batch and storage bin, open status when the number is missing.
- Check the customer master: company name, postal address and email address complete, business customers clearly separated from consumers.
- Adjust shop logic: availability only from documented stock, note on the item, no orders for quantities that have not been released.
- Extend documents: number per line on delivery note and invoice, list and export in the customer account.
- Set up storage: earliest deletion date per record derived from the date of supply, export for requests from the authorities.
Where commodity code, batch, customer account and document archive already exist, it may be enough to build the connection between them. We build that connection in Shopware projects together with the ERP integration. Anyone who wants an early assessment of which items are affected and where the chain breaks today can reach us through the contact form.
Sources and legal status
Related Articles
New Product Liability: Proving the Supply Chain in B2B Shops
The new EU product liability rules apply from 9 December 2026. The data a B2B shop needs per order line to name its upstream supplier within one month.
Data Act in the B2B shop: data disclosure before purchase
Before a connected product is sold, the Data Act requires four data disclosures. How to keep them in the PIM and show them on product page, quote and punchout.
Where Order Documents Live and How Long They Stay
Order confirmation, delivery note, invoice and price list in the customer account: which retention period applies, when it starts and where the files may sit.