The GPSR technical file, explained, with a real example
Article 9(2) of the GPSR makes every maker a manufacturer with documentation duties. Here is exactly what the technical file must contain, shown section by section on a real handmade necklace.
Most sellers meet the phrase "technical file" in one of three ways. An email from Etsy about EU product compliance. A buyer, or more often a wholesale enquiry, asking for "your documentation". Or a forum thread at eleven at night where someone confidently says you need a 50-page dossier for a pair of earrings.
None of those tell you what actually goes in it. So here is the answer, and then the same answer applied to a real product so you can see what "done" looks like.
What a technical file is, in one paragraph
Under Article 9(2) of the GPSR (Regulation (EU) 2023/988, applicable since 13 December 2024), before you place a product on the EU market you must carry out an internal risk analysis and draw up technical documentation. That documentation is the technical file. It is your written evidence that you thought about how your product could hurt someone, and did something about it.
The catch is who counts as a manufacturer. Under Article 3, a manufacturer is anyone who makes a product, or has it made, and sells it under their own name or trademark. If you make it, you are the manufacturer. There is no craft exemption and no size threshold. A one-person candle business has the same Article 9(2) duty as a factory.
What it is not
Two things get confused with the technical file constantly, so let us kill both now.
It is not a Declaration of Conformity. A DoC is a signed legal statement that a product meets specific harmonised EU legislation, and it belongs to CE-marked categories like toys, electronics and PPE. Most jewellery, home decor and adult clothing is non-harmonised, which means no CE mark and no DoC. What GPSR asks for instead is risk analysis plus technical documentation.
It is not a test certificate. You do not need a lab report for every product. Testing is one kind of evidence you can put in the file, not the file itself. For a lot of handmade products, supplier declarations and material specifications do the same job.
The four things it has to contain
Article 9(2) sets a core requirement and then adds two more "where appropriate", which in practice means whenever your product has a real hazard, so almost always. In plain English, four sections:
1. A general description of the product. What it is, what it is made of, dimensions, weight, how it is used, and who it is for. Boring, and the section people skip. It matters because everything else is judged against it: a necklace for adults and a necklace marketed for a four-year-old are different products with different risks.
2. Its essential characteristics relevant to assessing its safety. The specific properties that could matter to somebody's safety. For jewellery that is metal composition, coatings, clasp type, chain strength, presence of small detachable parts, magnets. Not the colourway, not the packaging design.
3. An analysis of the possible risks, and what you did about them. The heart of it. Each realistic hazard, who it affects, how likely and how serious, and the measure you took to remove or reduce it. If you have test reports, they go here.
4. The list of European standards or other elements applied. Which standards you worked to, or, where no standard fits, what else you relied on: national requirements, a recognised code of practice, supplier declarations, your own documented method.
The same four sections, on a real product
Take a sterling silver chain necklace, 45cm, with a lobster clasp, sold to adults. Here is what each section actually says.
1. General description
Fine sterling silver (925) cable chain necklace, 45cm length, 1.2mm link width, weight 4.1g. Lobster clasp in sterling silver with a stainless steel spring. Rhodium plated. Sold unpackaged in a cotton pouch. Intended for adult wear. Not intended for or marketed to children under 14. Batch identifier SS-CH45-2026-03.
That last line matters more than it looks. GPSR expects a product identifier (type, batch or serial number) so a specific run can be traced if something goes wrong. Pick a scheme and use it consistently.
2. Safety-relevant characteristics
Materials in prolonged skin contact: sterling silver 925 (92.5% Ag, balance Cu), rhodium plating, stainless steel spring. No nickel intentionally added; supplier declaration on file (ref SUP-2026-011). Smallest detachable component: clasp spring, 3mm. Chain breaking load: approx 40N. No magnets, no coatings containing cadmium or lead.
3. Risk analysis
This is the section that most benefits from being a table rather than prose.
| Hazard | Who is at risk | Assessment | What I did about it |
|---|---|---|---|
| Nickel release causing allergic contact dermatitis | Adult wearers, especially the roughly 15% with nickel sensitivity | Prolonged skin contact. REACH Annex XVII entry 27 limits release to 0.5 µg/cm²/week | Sourced nickel-free sterling from a supplier providing a written declaration; EN 1811 test report on file for the 2026 alloy batch |
| Cadmium or lead in the alloy or plating | All wearers, children if handled | REACH restricts cadmium in jewellery to 0.01% by weight and lead to 0.05% | Supplier material certificate confirms both below limits; certificate retained with this file |
| Small parts, choking | Children who might handle the item | Clasp spring is under the small parts threshold if detached. Product is not aimed at children | Not marketed to under-14s; "keep away from small children" warning on the care card |
| Strangulation from chain length | Children | 45cm is a length that can pass over a child's head | Adult product only; no children's sizing offered in this line |
| Skin injury from a broken chain or sharp link ends | Wearers | Low, given link construction | 100% visual and tension check on every piece before dispatch, documented in the QC log |
Five rows. Not fifty pages.
4. Standards and other elements applied
- EN 1811:2023, reference test method for release of nickel
- EN 12472, method for simulating wear and corrosion, applied to the plated clasp
- REACH Regulation (EC) 1907/2006 Annex XVII, entries 23 (cadmium), 27 (nickel) and 63 (lead)
- Supplier material declarations SUP-2026-011 and SUP-2026-014
- Internal QC procedure QC-02, visual and tension inspection
That is a complete technical file for that necklace. Four sections, roughly two pages, and every claim in it traceable to a document you can actually produce.
How much is enough
The regulation is explicit that documentation is proportionate to the complexity of the product. This is the single most reassuring sentence in the whole GPSR and nobody quotes it.
A silver chain is a simple product. A scented candle with a wooden wick, a child's wooden toy, a lamp with mains wiring: each of those is progressively more complex, has more failure modes, and earns a longer file. What you cannot do is skip the exercise because the product is simple. A short honest file beats no file, and it beats a padded one that a market surveillance officer can tell you copied off the internet.
The test I use: could someone who has never seen your product understand what it is, what could go wrong, and why you are satisfied it will not? If yes, the file is long enough.
Housekeeping: how long, and who can ask
- Keep it for 10 years from the date the product was placed on the market. Not 10 years from when you made it, and not until you delist it.
- Keep it up to date. Change your supplier, your alloy, your clasp, or your target age group and the file needs to change with it. A file that describes a product you stopped making in 2025 protects nobody.
- Market surveillance authorities can demand it, and you are expected to produce it. In practice the requests that reach small sellers usually come first from the marketplace or from an EU Responsible Person acting for you, both of whom need the same information.
- If you have appointed an EU Responsible Person under Article 16, they will ask for this file. It is the thing they hold on your behalf. Read our guide to whether you need one if you have not sorted that yet.
Doing it yourself, or not
Everything above is genuinely doable by hand. The structure is not secret, the sections are the four listed in Article 9(2), and for a simple product you are looking at an afternoon per product line the first time and much less after that.
What makes it painful is scale. Twelve product lines, each needing its own description, hazard rows, standards list and identifiers, all kept current when you change a supplier, is where sellers quietly give up. That is the specific problem GPSRHub exists to solve: you answer questions about your products, and it generates the technical file, the risk assessment, the labelling sheet and, where the product needs one, the Declaration of Conformity.
If you are not sure which of those you actually need, the compliance checker is ten questions and about two minutes, and it tells you exactly which documents are missing for your specific products. It is free, and it will at least stop you building the wrong thing.
Quick FAQ
What must a GPSR technical file contain? A general description of the product, its safety-relevant characteristics, an analysis of the possible risks and what you did about them, and the list of European standards or other elements you applied.
How long must I keep it? Ten years from the date the product was placed on the EU market.
Do handmade sellers need one? Yes. If you make the product and sell it under your own name you are the manufacturer under Article 3, and Article 9(2) applies. There is no handmade or small-business exemption.
Is a technical file the same as a Declaration of Conformity? No. A DoC belongs to CE-marked products under harmonised legislation. Most jewellery, decor and adult clothing is non-harmonised and needs risk analysis plus technical documentation instead.
Does it have to be in a particular format? No prescribed format. It has to contain the required content, be kept current, and be producible on request.
Do I need one file per product or per range? Per product, but a range sharing materials, construction and intended user can sensibly be documented together, with the variants listed. Different materials or a different target age group means a different file.
Sources
Need your GPSR compliance handled for you?
GPSRHub generates authority-grade Technical Files, Risk Assessments, and Declarations of Conformity for Etsy & Amazon sellers, and can act as your EU Responsible Person.
See plans