Skip to content
7 min read

EUDR Compliance System: How Precise Geodata Secures Market Access and Reduces Supply Chain Risks

Featured Image

The EU Deforestation Regulation makes market access conditional on one document: a due diligence statement filed in the EUDR Information System before a covered product is placed on the EU market or exported from it. Large and medium companies file from 30 December 2026, micro and small operators from 30 June 2027.

Who must comply with the EUDR, and by when?

The regulation covers seven commodities, cattle, cocoa, coffee, oil palm, rubber, soya and wood, plus the products derived from them, including leather, chocolate, furniture, paper, charcoal and printed matter. If a company places any of these on the EU market under its own name or exports them, it is an operator and owes a full due diligence statement. A company that only buys and resells goods already on the market is a trader, and the depth of its obligation depends on its size.

I have covered this in more depth here: Satellite Deforestation Monitoring for EUDR: Tools and Plot Data.

Company class Obligation Applies from
Large and medium operators and traders Full due diligence: information gathering, risk assessment, mitigation, own due diligence statement 30 December 2026
Micro and small operators Full due diligence, with the reliefs the regulation grants smaller operators 30 June 2027
Micro and small traders Collect and keep the reference numbers of upstream statements, no own risk assessment 30 June 2027

The classification decides more than the deadline. A mid-sized roaster importing green coffee is an operator even though it never sets foot on a farm, and it carries the geolocation obligation for every plot behind every lot.

What must the geolocation data look like?

This is where most EUDR programmes are won or lost, and it is the part vendor pages describe least precisely.

  • Coordinates in decimal degrees, WGS84, with at least six decimal places. Latitude between -90 and +90, longitude between -180 and +180.
  • A single point for plots of four hectares or less and for livestock establishments.
  • A polygon of at least four coordinate points for plots larger than four hectares, exchanged as GeoJSON.
  • Every plot linked to the supplier that farms it and to the lot it delivered into.
  • The whole set retained for at least five years from the date the product was placed on the market.

The last point is the one that turns a plot list into supply chain mapping. Coordinates on their own prove nothing; what a competent authority asks is which plot fed which lot through which supplier. Companies that already run structured supplier data for compliance mostly need to extend it by a plot level, not to start over.

How do you get from supplier data to a submitted due diligence statement?

Four steps, in this order, and only the fourth one produces the document that grants market access.

  1. Gather information: commodity, quantity, country of production, plot geolocation, supplier identity and evidence that production was legal under the law of the country of origin.
  2. Assess risk: check the collected data against the cut-off date of 31 December 2020, country risk class, complexity of the chain and any indication of illegal harvesting.
  3. Mitigate: where risk is more than negligible, gather additional evidence, audit or drop the plot, then reassess.
  4. Submit: file the statement in the EUDR Information System and receive a reference number and a verification number, which are passed to downstream operators and quoted at customs.

Two practical limits shape the design. Statements can be filed in bulk through the system's API rather than one by one, which matters as soon as plot counts run into the thousands. And a single statement is capped at roughly 25 MB, around 30,000 to 40,000 coordinate points, so large networks split one shipment across several statements and have to keep the reference numbers straight afterwards.

What does simplified due diligence actually remove?

The Commission classifies producing countries as low, standard or high risk, and for goods from low-risk countries operators may apply simplified due diligence. The relief is narrower than the name suggests: it removes the risk assessment and mitigation steps, steps two and three above. It does not remove the geolocation obligation, the information gathering or the statement itself.

Low risk is also not a permanent verdict on a given lot. If an operator obtains information pointing to deforestation after 31 December 2020, or to illegal production, the full procedure applies again for that consignment, whatever the country classification says.

Where EUDR compliance data projects fail, and when to build instead of buy

The failure modes I see in geodata projects are dull and repetitive, which is exactly why they are worth naming. Supplier plot data arrives as a scanned hand-drawn map or a PDF sketch instead of coordinates. The same plot appears under different IDs from two suppliers, so one field is counted twice. And coordinates land in the sea or in the wrong hemisphere, usually because latitude and longitude were transposed or a decimal separator was lost in an export.

Before I call a supplier's geodata good enough to file, it has to pass three checks: every plot resolves to a location on land inside the stated country of production, every plot carries one named supplier and one lot, and the underlying evidence document exists and can be produced on request. Data that fails any of the three is not a small quality issue, it is a statement you cannot defend.

If you want to go deeper: Scope 3 Supply Chain Tracking: From Data Sources to a Workable Approach.

On building versus buying: I have built compliance tooling myself, and the deciding question is not the feature list. It is whether the system stores the evidence and its provenance, or only the resulting green flag. A handful of plots and stable suppliers can be run in a controlled spreadsheet plus a document archive. Hundreds of suppliers delivering in a dozen formats need bought infrastructure, and the selection criterion should be evidence handling, not dashboards. The same logic applies to other supply chain risk data you already collect.

Frequently asked questions

What are the penalties for EUDR non-compliance?

Member states set penalties that must be effective, proportionate and dissuasive, with fines of up to 4 percent of annual EU turnover as the ceiling set by the regulation. Beyond fines, competent authorities can ban the sale of non-compliant products, order recalls, confiscate the goods or the revenue from them, and exclude a company from simplified due diligence.

Does the EUDR allow mass balance chain of custody?

No. Mass balance accounting, where compliant and non-compliant material is physically mixed and the compliant share is tracked on paper, does not satisfy the EUDR. Every consignment must be traceable to the plots it actually came from, which means physical separation between verified and unverified material.

What counts as forest degradation, as opposed to deforestation?

Deforestation is the conversion of forest to agricultural use after 31 December 2020. Degradation is a structural change within land that stays forest, in particular the conversion of primary or naturally regenerating forest into plantation forest or into other wooded land. A production site can therefore remain green on a satellite image and still fail the test.

How do you verify data accuracy and reporting compliance in supply chain systems before a multi-year commitment?

Test against the hardest case, not the demo case. Traceability depth: can the system carry a claim back to the plot or the batch, or does it stop at the supplier entity? Evidence handling: does it store the underlying document and its provenance, or only the resulting flag? A system that cannot produce the evidence behind a green status is a dashboard, not a compliance system. Change management: what happens when a supplier updates its data after a statement has been filed, and does the system flag the divergence or overwrite it silently?

Johannes Fiegenbaum

Johannes Fiegenbaum

ESG and sustainability consultant based in Hamburg, specialised in VSME reporting and climate risk analysis. Has supported 300+ projects for companies and financial institutions, from mid-sized manufacturers to major banks and insurers.

More about