Temperature control in a pharmaceutical warehouse is not demonstrated by a single wall sensor or by an annual calibration certificate. A storage area can show an acceptable average temperature while exposing medicinal products at upper racks, loading doors, cold walls, heater zones, return areas, or poorly ventilated corners to conditions outside their approved storage requirements. For a third-party logistics provider, the problem is broader: the warehouse must generate reliable records, but the contract giver must also define responsibilities, review performance, and retain oversight of the outsourced activity.
The EU Guidelines on Good Distribution Practice of medicinal products for human use, 2013/C 343/01, translate these risks into a quality-system obligation. They require suitable environmental controls, temperature mapping before use, risk-based placement of permanent monitors, traceable calibration, functional alarms, protected records, qualification or validation where appropriate, documented deviation handling, and control of outsourced activities. The guideline does not prescribe one universal warehouse temperature, one logging interval, or one sensor accuracy for every product. Those specifications must be justified from the medicinal product’s approved storage conditions, the facility risk assessment, and the intended use of the monitoring system.
This guide explains what EU GDP requires, how warehouses and pharmaceutical 3PLs can convert the clauses into an implementable monitoring architecture, which evidence auditors commonly expect, and how to evaluate representative monitoring systems without confusing vendor features with a compliance conclusion.
EU GDP expects pharmaceutical warehouses to prove that approved storage conditions are maintained through a controlled system: representative temperature mapping, permanent monitoring at risk-based locations, traceable calibration, tested alarms, protected and retrievable records, documented incident handling, and periodic review. Outsourcing storage to a 3PL does not transfer the contract giver’s responsibility for oversight.

EU GDP temperature control is demonstrated by a connected quality system: product-specific requirements, representative mapping, risk-based permanent monitors, traceable calibration, tested alarms, protected records, qualified response, CAPA, and contract-giver oversight of outsourced storage.
The formal source is the European Commission’s Guidelines of 5 November 2013 on Good Distribution Practice of medicinal products for human use, published as 2013/C 343/01. The guideline is based on Articles 84 and 85b(3) of Directive 2001/83/EC and applies within the EU and EEA framework. A person acting as a wholesale distributor must hold the applicable wholesale distribution authorisation, and manufacturers that distribute their own authorised medicinal products must also follow GDP for those distribution activities.

A pharmaceutical 3PL may perform the storage activity, but the contract giver remains responsible for assessment, written allocation of GDP duties, access to records, performance review, subcontractor control, audit, and quality decisions.
The guideline is not limited to businesses that call themselves pharmaceutical wholesalers. It covers the activities of procuring, holding, supplying, and exporting medicinal products, apart from supply to the public. Warehousing, cross-docking, pick-and-pack operations, quarantine storage, cold rooms, returns handling, and transport handoffs may therefore fall within the controlled distribution chain when performed for medicinal products.
For a pharmaceutical 3PL, the decisive issue is not the commercial label “3PL” but the regulated activity being performed and the authorisation required in the relevant Member State. Chapter 1.3 requires the quality system to extend to outsourced activities, while Chapter 7 requires the outsourced activity to be defined, agreed, and controlled through a written contract. The contract giver remains responsible for the contracted activity; it must assess the contract acceptor, define responsibilities and communication, and monitor performance. A warehouse contract therefore needs more than service-level language about uptime or response times: it must allocate GDP quality responsibilities, deviation reporting, access to records, calibration, mapping, subcontracting, and audit rights.
EU GDP is also not a global licence. Great Britain operates under the Human Medicines Regulations 2012 and current MHRA requirements; WHO TTSPP guidance provides a global model for time- and temperature-sensitive pharmaceutical products but states that local legislation takes precedence. Singapore, Hong Kong, Australia, and other markets maintain separate licensing and wholesaling requirements. A multinational 3PL should maintain a jurisdiction matrix rather than treating EU GDP as a universal substitute.
| Framework | Primary role | Use in this article |
| EU GDP 2013/C 343/01 | EU/EEA requirements and guidance for wholesale distribution of human medicinal products | Primary compliance framework |
| WHO TTSPP / GS&DP guidance | Global model guidance and technical supplements for time- and temperature-sensitive products | Implementation support; local law remains controlling |
| UK / other national regimes | National authorisation, inspection, records, and storage requirements | Must be checked separately before cross-border use |
EU GDP does not impose a universal “2°C to 8°C” or “15°C to 25°C” warehouse limit. Chapter 5 requires medicinal products to be handled according to the information on the outer packaging, and Chapter 9 requires defined storage conditions to be maintained during transportation as described by the manufacturer or packaging. A warehouse must therefore maintain a controlled product-condition matrix covering ambient, controlled-room-temperature, refrigerated, frozen, light-sensitive, and any humidity-sensitive stock actually held at the site.

Warehouse limits and environmental controls must follow the approved conditions of the products actually handled; EU GDP does not impose one universal 2°C to 8°C or 15°C to 25°C range for every medicinal product.
Chapter 3.2.1 identifies temperature, light, humidity, and cleanliness as environmental factors to consider. This does not mean that every warehouse must continuously monitor every parameter. It means the site must evaluate which factors can affect the products or the operation and then document the control strategy. Relative humidity monitoring is justified where product information, packaging sensitivity, condensation risk, facility design, or the quality risk assessment makes it relevant.
Before a storage area is used, Chapter 3.2.1 calls for an initial temperature mapping exercise under representative conditions. Permanent monitoring devices should then be positioned according to the mapping results, particularly in locations that experience the greatest fluctuations. Mapping should be repeated according to risk assessment or whenever significant changes are made to the facility or temperature-control equipment.
Mapping and routine monitoring are different controls. Mapping characterises the three-dimensional distribution of temperature across time and operating conditions. Routine monitoring provides continuous evidence at selected control points. A permanent sensor installed for convenience near an office door is not a substitute for a mapping study that identifies upper-rack hot zones, cold walls, evaporator discharge, loading-door exposure, or areas affected by seasonal conditions. WHO technical supplements provide useful methods for mapping and qualification, but the protocol, logger density, study duration, loading state, and seasonal strategy must be justified for the actual facility.

Initial mapping characterises three-dimensional temperature behaviour under representative conditions; the approved results then justify permanent monitors at mapped extremes and other locations most likely to fluctuate.
Chapter 3.3 requires environmental control and monitoring equipment to be calibrated at defined intervals based on a risk and reliability assessment. Calibration should be traceable to a national or international measurement standard. For warehouse monitoring, the EU guideline does not specify one accuracy limit or one fixed calibration interval. The user requirement specification should therefore define the required accuracy, uncertainty, calibration points, acceptance limits, and interval based on product limits and process risk. For transport monitoring equipment, Chapter 9 specifically states that regular calibration should occur at least once a year.
Appropriate alarm systems must alert users when predefined storage conditions are exceeded; alarm levels must be set appropriately and alarms tested regularly. The practical system requirement extends beyond a high-temperature notification. It should address warning and action thresholds, delay logic, repeat notifications, offline-device alarms, low-power conditions, local visibility, after-hours escalation, acknowledgement, and evidence that the complete alarm path was challenged. Planned maintenance and retained records of repair, maintenance, and calibration are also expected for key equipment.

A defensible monitoring point combines risk-based measurement specifications, traceable calibration, controlled maintenance, approved alarm logic, end-to-end challenge testing, backup readiness, and documented responder acknowledgement.
EU GDP documentation can be paper-based or electronic, but it must be clear, approved, retrievable, controlled, and retained for the period stated in national legislation and for at least five years. Changes to documentation should be signed and dated while preserving the original information. This requirement affects monitoring reports, calibration certificates, mapping protocols and reports, alarm histories, deviation records, user administration, maintenance records, and quality agreements.
Chapter 3.3.1 adds controls for computerised systems. Before use, the system should be shown through validation or verification studies to achieve the intended results accurately, consistently, and reproducibly. The system description should explain scope, security, functions, use, and interfaces. Only authorised persons should enter or amend data. Records must be protected against accidental or unauthorised change, checked for accessibility, backed up regularly, and recoverable after failure. Backup data should be retained separately and securely for the applicable period, at least five years.
EU GDP does not require every warehouse record to use an electronic signature, and a vendor’s FDA 21 CFR Part 11 statement is not automatically evidence of EU Annex 11 suitability. The regulated company must define whether the monitoring platform is a GxP computerised system, establish intended use, review supplier evidence, assess audit trails and permissions, test backup and restoration, and validate or verify the configured system according to risk.

For a GxP monitoring system, intended use, authorised access, validated configuration, audit evidence, backup, restore, readable retrieval, retention, change control, and periodic review protect the record from measurement through long-term use.
A monitoring system does not close a GDP deviation by sending an email. Chapter 1 requires deviations from established procedures to be documented and investigated, with appropriate corrective and preventive action (CAPA). The response procedure should preserve the raw data, identify the affected product and duration, evaluate product impact with authorised quality personnel, document disposition, identify root causes, and track actions to completion. For a 3PL, the quality agreement must define who is notified, who owns the investigation, who can release or reject stock, and how evidence is transferred to the contract giver.

An alarm begins a controlled response: protect product, preserve raw data, define the affected time, locations and batches, assess impact under authorised quality authority, document disposition, investigate root cause, and close effective CAPA.
| EU GDP requirement | Clause area | Monitoring control | Expected evidence |
| Approved storage conditions | Ch. 3, 5 and 9 | Product-condition matrix and approved alarm limits | Product labels, quality agreements, SOPs |
| Initial temperature mapping | 3.2.1 | Representative mapping before use | Approved protocol, raw data, report, deviations |
| Risk-based monitor placement | 3.2.1 | Permanent devices at mapped extremes and risk points | Sensor map linked to mapping conclusions |
| Traceable calibration | 3.3 | Defined accuracy, points, interval, and traceability | Current certificates and calibration status |
| Functional alarms | 3.3 | Defined thresholds, delays, escalation, and periodic challenge | Alarm-test records and incident logs |
| Protected electronic records | 3.3.1 and 4.2 | Authorised access, backup, restore, retention, version control | Validation/verification, access matrix, restore test |
| Outsourced activity control | 1.3 and 7 | Quality agreement, qualification, KPI review, audit and CAPA | Approved contract, audit reports, performance reviews |
Start with a documented scope: buildings, rooms, cold stores, freezers, loading interfaces, returns and quarantine zones, temporary staging, transport handoff, and any outsourced sites. Link each area to the medicinal products stored there and their approved conditions. The user requirement specification (URS) should define measurement range, accuracy and uncertainty, sampling and communication intervals, alarm functions, local memory, network behaviour, power backup, data retention, user roles, audit evidence, reports, interfaces, and calibration requirements. Where the guideline does not prescribe a number, the URS should state the risk-based rationale rather than inventing a universal value.
The mapping plan should be approved before data collection. It should describe the room configuration, HVAC and refrigeration system, rack layout, operating state, loading condition, logger locations, reference instruments, study duration, acceptance criteria, handling of door openings and defrost cycles, and treatment of deviations. Representative conditions may require studies during different seasons or operating scenarios. Significant HVAC work, changes to racking, expansion, altered airflow, new loading patterns, or adverse trend data should trigger a documented assessment of whether remapping is required.
Qualification and validation are not interchangeable. Equipment qualification demonstrates that hardware is installed and operates as intended; process validation or verification demonstrates that the configured system and process achieve the required result. EU GDP expects key equipment and processes to be qualified or validated before use and after significant changes, with the scope determined through documented risk assessment.
Select routine monitoring points from the mapping evidence, not from the number of available electrical outlets. Typical risk locations include mapped hot and cold points, high and low rack positions, exterior walls, evaporator discharge and return paths, loading doors, areas near heaters, and zones with poor air circulation. The exact number of permanent sensors is not specified by EU GDP. It should be sufficient to detect loss of control and should be justified in the monitoring plan. Sensor IDs, locations, calibration status, and associated alarm limits should be controlled in a master list and reflected on an approved floor plan.
Connectivity should be selected according to facility risk and IT policy. Ethernet can provide stable fixed connectivity; Wi-Fi can reduce cabling but requires coverage and security assessment; cellular can provide independence from the site network; LoRa or other sub-GHz networks can support many distributed points through gateways; RS485 is useful for wired external probes and industrial interfaces. No method is universally best. The design should document what happens when the network, gateway, cloud service, mains power, or device battery fails.
Local buffering is valuable because a network outage should not create an unrecorded period, but local storage alone does not preserve real-time alarms. The site should test both data continuity and notification continuity. For critical areas, consider independent power paths, gateway or router backup, cellular fallback, local audible/visual alarms, and a procedural fallback for manual review. Data recovery tests should confirm timestamps, sequence, duplicate handling, and the visibility of gaps.

Local buffering may preserve temperature records when a network, gateway, cloud service, or power path fails, but remote alarms may still be lost; both histories and response paths require independent challenge and recovery testing.
| EU GDP requirement | Clause area | Monitoring control | Expected evidence |
| Approved storage conditions | Ch. 3, 5 and 9 | Product-condition matrix and approved alarm limits | Product labels, quality agreements, SOPs |
| Initial temperature mapping | 3.2.1 | Representative mapping before use | Approved protocol, raw data, report, deviations |
| Risk-based monitor placement | 3.2.1 | Permanent devices at mapped extremes and risk points | Sensor map linked to mapping conclusions |
| Traceable calibration | 3.3 | Defined accuracy, points, interval, and traceability | Current certificates and calibration status |
| Functional alarms | 3.3 | Defined thresholds, delays, escalation, and periodic challenge | Alarm-test records and incident logs |
| Protected electronic records | 3.3.1 and 4.2 | Authorised access, backup, restore, retention, version control | Validation/verification, access matrix, restore test |
| Outsourced activity control | 1.3 and 7 | Quality agreement, qualification, KPI review, audit and CAPA | Approved contract, audit reports, performance reviews |
Architecture decisions should be documented in the URS and qualification plan. “Cloud-connected” is not a substitute for outage testing or data-governance assessment.
Alarm design should begin with approved product limits and the measurement uncertainty of the complete system. Many sites use an early-warning threshold inside the action limit, but any delay, dead band, repeat period, or suppression rule must be justified. The escalation matrix should identify primary and backup responders, after-hours contacts, acknowledgement expectations, and the point at which QA or the Responsible Person becomes involved.
During an excursion, personnel should protect product first, preserve evidence, and avoid changing or deleting raw data. The investigation should establish when the excursion began, its duration and magnitude, affected locations and batches, equipment and network status, door or loading activity, and any concurrent maintenance. Product disposition must be based on approved information and quality authority, not solely on a dashboard colour. Corrective and preventive actions may include HVAC repair, alarm redesign, sensor relocation, procedure changes, training, remapping, or supplier action.
The validation or verification package should be proportionate to risk and intended use. At minimum, the regulated company should document system scope and data flow, supplier assessment, user roles, configuration, alarm tests, data export, audit-trail behaviour where applicable, backup and restoration, time synchronisation, security, incident handling, change control, and periodic review. A vendor brochure that mentions GxP or Part 11 is evidence to review, not a substitute for the user organisation’s assessment and approval of the configured system.
For outsourced storage, the quality agreement should identify who owns mapping, calibration, maintenance, alarm response, deviation investigation, product-impact assessment, data retention, access management, validation documents, backup and recovery, subcontractor approval, and regulatory inspection support. The contract giver should review KPIs such as alarm response, overdue calibration, device offline time, repeat deviations, CAPA closure, and system changes. Where a 3PL uses its own platform, the client should have timely access to complete records and a defined exit or data-transfer plan.
|
1 |
Regulatory scope and product conditions
Define licences, products, areas, limits, and responsibilities. |
|
2 |
URS and quality risk assessment
Specify accuracy, logging, alarms, records, security, backup, and interfaces. |
|
3 |
Mapping, qualification, and approval
Characterise the facility under representative conditions before use. |
|
4 |
Permanent monitoring and calibration
Place calibrated sensors at mapped risk points and control the master list. |
|
5 |
Alarm, deviation, and CAPA workflow
Escalate, protect product, investigate, assess impact, and close actions. |
|
6 |
Periodic review and change control
Review trends, suppliers, calibration, access, incidents, and remapping triggers. |
| Control question | Evidence to retain | Primary owner |
| Are all products and approved storage conditions listed? | Current product-condition matrix and label references | QA / Responsible Person |
| Are the warehouse and 3PL activities within an authorised scope? | Authorisations, site scope, contracts, subcontractor list | QA / Regulatory |
| Was mapping completed before use under representative conditions? | Approved protocol, raw data, report, deviations, approval | Validation / QA |
| Are permanent sensors justified by mapping results? | Approved floor plan, sensor master list, placement rationale | QA / Facilities |
| Are accuracy, uncertainty, calibration points, and intervals defined? | URS, calibration SOP, current traceable certificates | Metrology / QA |
| Are alarm thresholds and delays approved? | Alarm rationale, configuration record, change history | QA / Operations |
| Is the full alarm path tested periodically? | Challenge-test records, after-hours test, corrective actions | Operations / IT |
| Does the system record during network loss? | Offline-buffer test, recovery test, timestamp review | IT / Validation |
| Are data access, backup, restore, and retention controlled? | Access matrix, backup logs, restore test, retention policy | IT / QA |
| Is the computerised system validated or verified for intended use? | System description, risk assessment, test evidence, approval | CSV / QA |
| Are deviations investigated and linked to product decisions? | Deviation report, impact assessment, disposition, CAPA | QA / Responsible Person |
| Does the 3PL quality agreement allocate GDP duties clearly? | Signed agreement, communication matrix, audit rights | Contract giver / 3PL QA |
| Are staff trained and backup responders assigned? | Training records, competency evidence, on-call roster | Operations / QA |
| Are changes reviewed for remapping or requalification? | Change control, risk assessment, periodic review | QA / Engineering |
The EU GDP guideline does not publish a single list of “most common” warehouse findings. The following are recurring failure patterns derived from the control requirements and inspection-oriented guidance; they should be treated as an audit-preparation checklist, not as a claim about enforcement statistics.
Product selection should follow the URS, not precede it. Accuracy is only one dimension. A GDP warehouse also needs suitable range, calibration evidence, local continuity, outage behaviour, alarm functionality, user access, data retention, export, integration, change management, supplier support, validation evidence, and a sustainable operating model. The following criteria should be approved before a vendor shortlist is finalised.

A monitoring platform should be approved only when the exact configured system satisfies the URS and demonstrates measurement suitability, continuity, alarm performance, electronic-record controls, supplier support, validation evidence, lifecycle ownership, and sustainable cost.
| Potential finding | Why it is weak | Likely consequence | Preventive action |
| A single sensor represents a large warehouse | Placement is not linked to mapping or temperature extremes | Excursions may remain undetected | Map first; justify permanent points and review trends |
| Mapping is treated as a one-time document | Changes and seasonal risks are not assessed | Old conclusions no longer reflect the facility | Define remapping triggers in change control |
| Calibration certificate is expired or incomplete | Accuracy and traceability cannot be demonstrated | Data reliability is challenged | Control calibration status, uncertainty, points, and due dates |
| Alarm configured but not challenged end-to-end | Email/SMS/router/after-hours routing may fail | Delayed or missed response | Test sensor input through recipient acknowledgement |
| Cloud system accepted without intended-use assessment | Permissions, backup, audit evidence, and restore are unverified | Electronic records may not be defensible | Perform supplier assessment and risk-based validation |
| Internet outage creates a data gap | No local buffering or tested recovery | Incomplete excursion history | Specify local memory and verify automatic recovery |
| 3PL contract says “maintain GDP” without detail | Roles, records, escalation, and subcontracting are unclear | Disputes and delayed investigations | Use a detailed quality agreement and performance review |
| HVAC or rack changes occur without monitoring review | Change control is disconnected from mapping and sensors | Risk points shift without detection | Assess remapping, sensor relocation, and requalification |
The table compares representative architectures using current official vendor information. It does not certify any system as EU GDP
| Comparison area | UbiBot GS1-AETH1RS / GS1-A1RS | ELPRO ECOLOG-PRO xG | Vaisala RFL100 + AP10 + viewLinc Cloud | Dickson DWE2 + DicksonOne |
| Positioning | Direct-connected fixed monitor; optional external RS485 probes; WS4-P4G1RS can support selected mobile/transport handoffs | Cellular IoT temperature or T/RH logger for rooms and equipment | Proprietary wireless logger + access point + regulated-environment monitoring platform | Wi-Fi/Ethernet display logger with replaceable sensors and cloud subscription |
| Connectivity | 2.4 GHz Wi-Fi; AETH model also RJ45 Ethernet; optional PoE splitter | LTE-M / NB-IoT direct to elproCLOUD | VaiNet to AP10; AP10 uses Ethernet and PoE or AC | Wi-Fi or Ethernet |
| Dedicated gateway | No for direct-connected GS1 models | No local gateway | Yes: AP10; up to 32 RFL100 loggers per AP10 | No |
| Local continuity | 300,000 sensor records | 31,000 values published for xG loggers | Up to 30 days in RFL100 internal memory | Approx. 400,000 backup sample points |
| Display / local visibility | 4-inch LCD | Device-dependent status interface; cloud is primary | RFL100 display plus AP10 status interface | LCD with resettable min/max and audible/visible indicators |
| Platform options | Public cloud; on-premises platform; APIs and custom integration options | elproCLOUD; optional API; vendor compliance services | viewLinc Cloud or viewLinc Enterprise ecosystem | DicksonOne cloud; subscription required |
| Vendor compliance positioning | Calibration and traceability guidance; public evidence for a complete EU Annex 11 validation package is not publicly specified | Vendor states GAMP 5 validation and FDA 21 CFR Part 11 support; ISO 17025 calibration on request | Designed for GxP-regulated monitoring; calibration traceability and system validation features | Vendor provides audit trails, reports, permissions, and compliance services; EU Annex 11 evidence should be assessed |
| Strong fit | Cost-conscious fixed points, mixed Wi-Fi/Ethernet sites, local data continuity, and integration flexibility | Rapid cellular deployment with minimal site IT and stronger packaged compliance services | Enterprise life-science sites requiring structured wireless architecture and mature validation support | Warehouses needing direct Wi-Fi/Ethernet, local display, replaceable sensors, and cloud reporting |
| Key caution | Regulated users must validate the configured platform, review access/audit/backup controls, and obtain suitable calibration evidence | Part 11 claims do not automatically prove EU Annex 11 or site-specific validation; recurring cloud/service model applies | Requires AP10 infrastructure and a more structured enterprise deployment; licensing and services should be scoped | Requires DicksonOne subscription; verify audit-trail, retention, validation, and regional service details |
| Relative implementation burden | Low to moderate | Low to moderate for xG; compliance service scope may increase project work | Moderate to high | Moderate |
Specifications and vendor claims were reviewed in July 2026. Exact models, probes, software versions, licenses, calibration services, and regional availability must be confirmed in the procurement and validation package.
For a small or medium fixed warehouse with existing Wi-Fi or Ethernet, a direct-connected architecture can reduce gateway infrastructure. UbiBot GS1-AETH1RS is relevant where Ethernet resilience, local display, large local memory, and RS485 expansion are valued; GS1-A1RS is the Wi-Fi-only alternative. The regulated user must still confirm probe suitability, calibration evidence, alarm testing, data governance, and validation for the chosen platform.
For a site that cannot depend on local IT, ELPRO ECOLOG-PRO xG offers direct LTE-M/NB-IoT communication and a stronger packaged GxP service proposition. For enterprise life-science networks that prioritise a mature proprietary wireless architecture, traceable probes, structured access-point design, and formal validation support, Vaisala RFL100 with AP10 and viewLinc is a more natural benchmark. Dickson DWE2 fits organisations that want a direct Wi-Fi/Ethernet display logger, replaceable sensors, substantial local backup memory, and DicksonOne reporting and alarms.
For a pharmaceutical 3PL operating multiple client zones, the preferred system may vary by customer contract. A practical approach is to standardise the core data-governance and alarm process while maintaining validated configurations for different sensor types or platforms. The most defensible selection is the one that meets the approved URS, can be supported throughout its lifecycle, and produces complete evidence during an excursion or inspection—not the product with the longest feature list.
EU GDP requires suitable equipment and procedures, initial mapping, risk-based permanent monitor placement, calibrated devices, and alarms. It does not use one sentence that prescribes the same continuous logging interval for every warehouse. In practice, an automated monitoring system should collect data frequently enough to detect and reconstruct excursions for the products and facility risk. The chosen interval must be documented in the URS and justified; manual spot checks alone are generally weak evidence for a large or temperature-sensitive storage area.
No. Storage and transport conditions are determined by the medicinal product’s approved labelling, manufacturer information, and quality agreements. Some products require refrigeration, others controlled room temperature, frozen conditions, or protection from light or moisture. The warehouse should maintain a product-condition matrix and segregate products appropriately. Alarm limits should be linked to approved requirements and measurement uncertainty rather than applying one generic temperature range to every stock item.
EU GDP requires mapping before use and repetition according to risk assessment or after significant changes to the facility or temperature-control equipment. It does not prescribe a universal annual interval for warehouse remapping. The site should define triggers such as HVAC modification, racking changes, expansion, altered loading patterns, repeated deviations, new storage zones, or evidence that seasonal conditions are no longer represented. The periodic review should document why the existing map remains valid or why a new study is required.
The guideline does not provide a sensor-per-square-metre formula. Permanent monitoring devices should be located according to the mapping results, especially where extremes or significant fluctuations occur. The site should justify sensor quantity and position based on mapped hot and cold points, rack height, airflow, loading doors, exterior walls, refrigeration design, product risk, and the consequence of a missed excursion. A floor plan and sensor master list should link every permanent point to the mapping rationale.
For fixed storage areas, EU GDP requires calibration at defined intervals based on risk and reliability, with traceability to national or international measurement standards. It does not specify one universal warehouse accuracy. The URS should define accuracy, uncertainty, calibration points, and acceptance limits that are appropriate relative to the product limits and alarm strategy. For transport monitoring equipment, the guideline explicitly calls for regular calibration at least annually. National rules or customer agreements may be more specific.
EU GDP documentation should be retained for the period stated in national legislation and for at least five years. Electronic backup data should likewise be retained for the applicable period at a separate and secure location. A site should confirm whether product, customer, tax, pharmacovigilance, clinical, or national requirements require longer retention. Retention must include the ability to retrieve readable records and associated metadata, not merely an assertion that the cloud provider stores data.
Yes, but outsourcing does not remove the contract giver’s responsibility. The company should assess the 3PL and its authorisation status, approve the monitoring and validation approach, define responsibilities in a written quality agreement, ensure access to complete records, review alarms and deviations, audit performance, and control subcontracting. The agreement should also cover data ownership, retention, system changes, calibration, mapping, backup, incident notification, product disposition, and data transfer when the contract ends.
No. Part 11, EU GDP, and EU GMP Annex 11 have overlapping data-integrity concerns but different legal scopes and expectations. A vendor’s Part 11 statement may be relevant supplier evidence, but the regulated organisation must still assess intended use, configuration, access control, audit trails, backup, electronic signatures where used, supplier management, validation, change control, incident management, and business continuity. The final compliance position belongs to the regulated company and its competent authority, not to a generic product label.
EU GDP temperature monitoring is a controlled quality process, not a hardware purchase. A defensible warehouse programme starts with approved product conditions and regulatory scope, characterises the facility through mapping, converts the evidence into permanent monitor placement, controls calibration and alarms, protects records, validates the computerised system according to risk, and connects excursions to product-impact assessment and CAPA. Pharmaceutical 3PL arrangements require the same technical controls plus explicit contract-giver oversight and transparent access to evidence.
UbiBot can offer a balanced architecture for fixed warehouse points where direct Wi-Fi or Ethernet, large local memory, RS485 expansion, public-cloud or on-premises options, and lower infrastructure complexity are valued. ELPRO, Vaisala, and Dickson may be more suitable where the buyer prioritises packaged GxP services, mature enterprise validation support, proprietary wireless architecture, or a specific regulated-industry workflow. None of these systems becomes compliant by model name alone. The configured system, calibration evidence, mapping, SOPs, contracts, validation, training, and quality decisions form the compliance case.
This article is provided for informational and editorial purposes and does not constitute legal, regulatory, validation, quality, or engineering advice. EU GDP compliance depends on the authorised activity, applicable national law, medicinal-product requirements, competent-authority expectations, quality agreements, validated procedures, and the configured monitoring system. Product specifications, software functions, licences, calibration services, network support, and vendor compliance claims may vary by model, region, software version, probe, and contract. Verify current official documentation and obtain approval from qualified QA/RA and legal personnel before implementation.
No related resources found