UBiBot Logo
UBiBot Logo
  • UBiBot Logo
  • Home
  • Products

    NEW

  • Pricing
  • Support
  • About Us
  • Download
  • magnifying-glass  Search
  • magnifying-glass header-close
  • Sign in Sign in
    Public Web Console Public Web Console
    On-Premises App Center On-Premises App Center
  • Home
  • Products

    NEW

  • Pricing
  • Support
  • About us
  • Download
  •  Public Web Console
  •  On-Premises App Center
  • Where to Buy

Learn Hub

Explore Knowledge Academic Research In-depth Tech

Share

LinkedIn

Facebook

X (Twitter)

Newsletter Signup

Table of contents

    EU GDP Temperature Monitoring for Pharmaceutical Warehouses and 3PLs

    Temperature control in a pharmaceutical warehouse is not demonstrated by a single wall sensor or by an annual calibration certificate. A storage area can show an acceptable average temperature while exposing medicinal products at upper racks, loading doors, cold walls, heater zones, return areas, or poorly ventilated corners to conditions outside their approved storage requirements. For a third-party logistics provider, the problem is broader: the warehouse must generate reliable records, but the contract giver must also define responsibilities, review performance, and retain oversight of the outsourced activity.

    The EU Guidelines on Good Distribution Practice of medicinal products for human use, 2013/C 343/01, translate these risks into a quality-system obligation. They require suitable environmental controls, temperature mapping before use, risk-based placement of permanent monitors, traceable calibration, functional alarms, protected records, qualification or validation where appropriate, documented deviation handling, and control of outsourced activities. The guideline does not prescribe one universal warehouse temperature, one logging interval, or one sensor accuracy for every product. Those specifications must be justified from the medicinal product’s approved storage conditions, the facility risk assessment, and the intended use of the monitoring system.

    This guide explains what EU GDP requires, how warehouses and pharmaceutical 3PLs can convert the clauses into an implementable monitoring architecture, which evidence auditors commonly expect, and how to evaluate representative monitoring systems without confusing vendor features with a compliance conclusion.

    Key compliance answer

    EU GDP expects pharmaceutical warehouses to prove that approved storage conditions are maintained through a controlled system: representative temperature mapping, permanent monitoring at risk-based locations, traceable calibration, tested alarms, protected and retrievable records, documented incident handling, and periodic review. Outsourcing storage to a 3PL does not transfer the contract giver’s responsibility for oversight.

    EU GDP temperature control is demonstrated by a connected quality system: product-specific requirements, representative mapping, risk-based permanent monitors, traceable calibration, tested alarms, protected records, qualified response, CAPA, and contract-giver oversight of outsourced storage.

    1.What Is EU GDP, and Who Needs to Comply?

    The formal source is the European Commission’s Guidelines of 5 November 2013 on Good Distribution Practice of medicinal products for human use, published as 2013/C 343/01. The guideline is based on Articles 84 and 85b(3) of Directive 2001/83/EC and applies within the EU and EEA framework. A person acting as a wholesale distributor must hold the applicable wholesale distribution authorisation, and manufacturers that distribute their own authorised medicinal products must also follow GDP for those distribution activities.

    A pharmaceutical 3PL may perform the storage activity, but the contract giver remains responsible for assessment, written allocation of GDP duties, access to records, performance review, subcontractor control, audit, and quality decisions.

    The guideline is not limited to businesses that call themselves pharmaceutical wholesalers. It covers the activities of procuring, holding, supplying, and exporting medicinal products, apart from supply to the public. Warehousing, cross-docking, pick-and-pack operations, quarantine storage, cold rooms, returns handling, and transport handoffs may therefore fall within the controlled distribution chain when performed for medicinal products.

    For a pharmaceutical 3PL, the decisive issue is not the commercial label “3PL” but the regulated activity being performed and the authorisation required in the relevant Member State. Chapter 1.3 requires the quality system to extend to outsourced activities, while Chapter 7 requires the outsourced activity to be defined, agreed, and controlled through a written contract. The contract giver remains responsible for the contracted activity; it must assess the contract acceptor, define responsibilities and communication, and monitor performance. A warehouse contract therefore needs more than service-level language about uptime or response times: it must allocate GDP quality responsibilities, deviation reporting, access to records, calibration, mapping, subcontracting, and audit rights.

    EU GDP is also not a global licence. Great Britain operates under the Human Medicines Regulations 2012 and current MHRA requirements; WHO TTSPP guidance provides a global model for time- and temperature-sensitive pharmaceutical products but states that local legislation takes precedence. Singapore, Hong Kong, Australia, and other markets maintain separate licensing and wholesaling requirements. A multinational 3PL should maintain a jurisdiction matrix rather than treating EU GDP as a universal substitute.

    Framework Primary role Use in this article
    EU GDP 2013/C 343/01 EU/EEA requirements and guidance for wholesale distribution of human medicinal products Primary compliance framework
    WHO TTSPP / GS&DP guidance Global model guidance and technical supplements for time- and temperature-sensitive products Implementation support; local law remains controlling
    UK / other national regimes National authorisation, inspection, records, and storage requirements Must be checked separately before cross-border use

    2.Key EU GDP Requirements That Affect Temperature Monitoring

    Storage Conditions Must Follow the Product Requirement

    EU GDP does not impose a universal “2°C to 8°C” or “15°C to 25°C” warehouse limit. Chapter 5 requires medicinal products to be handled according to the information on the outer packaging, and Chapter 9 requires defined storage conditions to be maintained during transportation as described by the manufacturer or packaging. A warehouse must therefore maintain a controlled product-condition matrix covering ambient, controlled-room-temperature, refrigerated, frozen, light-sensitive, and any humidity-sensitive stock actually held at the site.

    Warehouse limits and environmental controls must follow the approved conditions of the products actually handled; EU GDP does not impose one universal 2°C to 8°C or 15°C to 25°C range for every medicinal product.

    Chapter 3.2.1 identifies temperature, light, humidity, and cleanliness as environmental factors to consider. This does not mean that every warehouse must continuously monitor every parameter. It means the site must evaluate which factors can affect the products or the operation and then document the control strategy. Relative humidity monitoring is justified where product information, packaging sensitivity, condensation risk, facility design, or the quality risk assessment makes it relevant.

    Temperature Mapping Determines Permanent Sensor Placement

    Before a storage area is used, Chapter 3.2.1 calls for an initial temperature mapping exercise under representative conditions. Permanent monitoring devices should then be positioned according to the mapping results, particularly in locations that experience the greatest fluctuations. Mapping should be repeated according to risk assessment or whenever significant changes are made to the facility or temperature-control equipment.

    Mapping and routine monitoring are different controls. Mapping characterises the three-dimensional distribution of temperature across time and operating conditions. Routine monitoring provides continuous evidence at selected control points. A permanent sensor installed for convenience near an office door is not a substitute for a mapping study that identifies upper-rack hot zones, cold walls, evaporator discharge, loading-door exposure, or areas affected by seasonal conditions. WHO technical supplements provide useful methods for mapping and qualification, but the protocol, logger density, study duration, loading state, and seasonal strategy must be justified for the actual facility.

    Initial mapping characterises three-dimensional temperature behaviour under representative conditions; the approved results then justify permanent monitors at mapped extremes and other locations most likely to fluctuate.

    Calibration, Alarms, Maintenance, and Backup Must Be Controlled

    Chapter 3.3 requires environmental control and monitoring equipment to be calibrated at defined intervals based on a risk and reliability assessment. Calibration should be traceable to a national or international measurement standard. For warehouse monitoring, the EU guideline does not specify one accuracy limit or one fixed calibration interval. The user requirement specification should therefore define the required accuracy, uncertainty, calibration points, acceptance limits, and interval based on product limits and process risk. For transport monitoring equipment, Chapter 9 specifically states that regular calibration should occur at least once a year.

    Appropriate alarm systems must alert users when predefined storage conditions are exceeded; alarm levels must be set appropriately and alarms tested regularly. The practical system requirement extends beyond a high-temperature notification. It should address warning and action thresholds, delay logic, repeat notifications, offline-device alarms, low-power conditions, local visibility, after-hours escalation, acknowledgement, and evidence that the complete alarm path was challenged. Planned maintenance and retained records of repair, maintenance, and calibration are also expected for key equipment.

    A defensible monitoring point combines risk-based measurement specifications, traceable calibration, controlled maintenance, approved alarm logic, end-to-end challenge testing, backup readiness, and documented responder acknowledgement.

    Records, Computerised Systems, and Data Integrity Matter

    EU GDP documentation can be paper-based or electronic, but it must be clear, approved, retrievable, controlled, and retained for the period stated in national legislation and for at least five years. Changes to documentation should be signed and dated while preserving the original information. This requirement affects monitoring reports, calibration certificates, mapping protocols and reports, alarm histories, deviation records, user administration, maintenance records, and quality agreements.

    Chapter 3.3.1 adds controls for computerised systems. Before use, the system should be shown through validation or verification studies to achieve the intended results accurately, consistently, and reproducibly. The system description should explain scope, security, functions, use, and interfaces. Only authorised persons should enter or amend data. Records must be protected against accidental or unauthorised change, checked for accessibility, backed up regularly, and recoverable after failure. Backup data should be retained separately and securely for the applicable period, at least five years.

    EU GDP does not require every warehouse record to use an electronic signature, and a vendor’s FDA 21 CFR Part 11 statement is not automatically evidence of EU Annex 11 suitability. The regulated company must define whether the monitoring platform is a GxP computerised system, establish intended use, review supplier evidence, assess audit trails and permissions, test backup and restoration, and validate or verify the configured system according to risk.

    For a GxP monitoring system, intended use, authorised access, validated configuration, audit evidence, backup, restore, readable retrieval, retention, change control, and periodic review protect the record from measurement through long-term use.

    Deviations and CAPA Must Connect the Data to Decisions

    A monitoring system does not close a GDP deviation by sending an email. Chapter 1 requires deviations from established procedures to be documented and investigated, with appropriate corrective and preventive action (CAPA). The response procedure should preserve the raw data, identify the affected product and duration, evaluate product impact with authorised quality personnel, document disposition, identify root causes, and track actions to completion. For a 3PL, the quality agreement must define who is notified, who owns the investigation, who can release or reject stock, and how evidence is transferred to the contract giver.

    An alarm begins a controlled response: protect product, preserve raw data, define the affected time, locations and batches, assess impact under authorised quality authority, document disposition, investigate root cause, and close effective CAPA.

    EU GDP requirement Clause area Monitoring control Expected evidence
    Approved storage conditions Ch. 3, 5 and 9 Product-condition matrix and approved alarm limits Product labels, quality agreements, SOPs
    Initial temperature mapping 3.2.1 Representative mapping before use Approved protocol, raw data, report, deviations
    Risk-based monitor placement 3.2.1 Permanent devices at mapped extremes and risk points Sensor map linked to mapping conclusions
    Traceable calibration 3.3 Defined accuracy, points, interval, and traceability Current certificates and calibration status
    Functional alarms 3.3 Defined thresholds, delays, escalation, and periodic challenge Alarm-test records and incident logs
    Protected electronic records 3.3.1 and 4.2 Authorised access, backup, restore, retention, version control Validation/verification, access matrix, restore test
    Outsourced activity control 1.3 and 7 Quality agreement, qualification, KPI review, audit and CAPA Approved contract, audit reports, performance reviews

    3.How to Turn EU GDP Requirements into an Implementable System

    Step 1: Define Scope, Products, and User Requirements

    Start with a documented scope: buildings, rooms, cold stores, freezers, loading interfaces, returns and quarantine zones, temporary staging, transport handoff, and any outsourced sites. Link each area to the medicinal products stored there and their approved conditions. The user requirement specification (URS) should define measurement range, accuracy and uncertainty, sampling and communication intervals, alarm functions, local memory, network behaviour, power backup, data retention, user roles, audit evidence, reports, interfaces, and calibration requirements. Where the guideline does not prescribe a number, the URS should state the risk-based rationale rather than inventing a universal value.

    Step 2: Perform Risk Assessment, Qualification, and Mapping

    The mapping plan should be approved before data collection. It should describe the room configuration, HVAC and refrigeration system, rack layout, operating state, loading condition, logger locations, reference instruments, study duration, acceptance criteria, handling of door openings and defrost cycles, and treatment of deviations. Representative conditions may require studies during different seasons or operating scenarios. Significant HVAC work, changes to racking, expansion, altered airflow, new loading patterns, or adverse trend data should trigger a documented assessment of whether remapping is required.

    Qualification and validation are not interchangeable. Equipment qualification demonstrates that hardware is installed and operates as intended; process validation or verification demonstrates that the configured system and process achieve the required result. EU GDP expects key equipment and processes to be qualified or validated before use and after significant changes, with the scope determined through documented risk assessment.

    Step 3: Convert Mapping Results into Permanent Monitoring Points

    Select routine monitoring points from the mapping evidence, not from the number of available electrical outlets. Typical risk locations include mapped hot and cold points, high and low rack positions, exterior walls, evaporator discharge and return paths, loading doors, areas near heaters, and zones with poor air circulation. The exact number of permanent sensors is not specified by EU GDP. It should be sufficient to detect loss of control and should be justified in the monitoring plan. Sensor IDs, locations, calibration status, and associated alarm limits should be controlled in a master list and reflected on an approved floor plan.

    Step 4: Design Connectivity and Data Continuity

    Connectivity should be selected according to facility risk and IT policy. Ethernet can provide stable fixed connectivity; Wi-Fi can reduce cabling but requires coverage and security assessment; cellular can provide independence from the site network; LoRa or other sub-GHz networks can support many distributed points through gateways; RS485 is useful for wired external probes and industrial interfaces. No method is universally best. The design should document what happens when the network, gateway, cloud service, mains power, or device battery fails.

    Local buffering is valuable because a network outage should not create an unrecorded period, but local storage alone does not preserve real-time alarms. The site should test both data continuity and notification continuity. For critical areas, consider independent power paths, gateway or router backup, cellular fallback, local audible/visual alarms, and a procedural fallback for manual review. Data recovery tests should confirm timestamps, sequence, duplicate handling, and the visibility of gaps.

    Local buffering may preserve temperature records when a network, gateway, cloud service, or power path fails, but remote alarms may still be lost; both histories and response paths require independent challenge and recovery testing.

     

    EU GDP requirement Clause area Monitoring control Expected evidence
    Approved storage conditions Ch. 3, 5 and 9 Product-condition matrix and approved alarm limits Product labels, quality agreements, SOPs
    Initial temperature mapping 3.2.1 Representative mapping before use Approved protocol, raw data, report, deviations
    Risk-based monitor placement 3.2.1 Permanent devices at mapped extremes and risk points Sensor map linked to mapping conclusions
    Traceable calibration 3.3 Defined accuracy, points, interval, and traceability Current certificates and calibration status
    Functional alarms 3.3 Defined thresholds, delays, escalation, and periodic challenge Alarm-test records and incident logs
    Protected electronic records 3.3.1 and 4.2 Authorised access, backup, restore, retention, version control Validation/verification, access matrix, restore test
    Outsourced activity control 1.3 and 7 Quality agreement, qualification, KPI review, audit and CAPA Approved contract, audit reports, performance reviews

    Architecture decisions should be documented in the URS and qualification plan. “Cloud-connected” is not a substitute for outage testing or data-governance assessment.

    Step 5: Establish Alarm Escalation, Deviation Handling, and CAPA

    Alarm design should begin with approved product limits and the measurement uncertainty of the complete system. Many sites use an early-warning threshold inside the action limit, but any delay, dead band, repeat period, or suppression rule must be justified. The escalation matrix should identify primary and backup responders, after-hours contacts, acknowledgement expectations, and the point at which QA or the Responsible Person becomes involved.

    During an excursion, personnel should protect product first, preserve evidence, and avoid changing or deleting raw data. The investigation should establish when the excursion began, its duration and magnitude, affected locations and batches, equipment and network status, door or loading activity, and any concurrent maintenance. Product disposition must be based on approved information and quality authority, not solely on a dashboard colour. Corrective and preventive actions may include HVAC repair, alarm redesign, sensor relocation, procedure changes, training, remapping, or supplier action.

    Step 6: Validate the Computerised System and Control the 3PL Relationship

    The validation or verification package should be proportionate to risk and intended use. At minimum, the regulated company should document system scope and data flow, supplier assessment, user roles, configuration, alarm tests, data export, audit-trail behaviour where applicable, backup and restoration, time synchronisation, security, incident handling, change control, and periodic review. A vendor brochure that mentions GxP or Part 11 is evidence to review, not a substitute for the user organisation’s assessment and approval of the configured system.

    For outsourced storage, the quality agreement should identify who owns mapping, calibration, maintenance, alarm response, deviation investigation, product-impact assessment, data retention, access management, validation documents, backup and recovery, subcontractor approval, and regulatory inspection support. The contract giver should review KPIs such as alarm response, overdue calibration, device offline time, repeat deviations, CAPA closure, and system changes. Where a 3PL uses its own platform, the client should have timely access to complete records and a defined exit or data-transfer plan.

    4.EU GDP Monitoring Implementation Flow

    1

    Regulatory scope and product conditions

    Define licences, products, areas, limits, and responsibilities.

    2

    URS and quality risk assessment

    Specify accuracy, logging, alarms, records, security, backup, and interfaces.

    3

    Mapping, qualification, and approval

    Characterise the facility under representative conditions before use.

    4

    Permanent monitoring and calibration

    Place calibrated sensors at mapped risk points and control the master list.

    5

    Alarm, deviation, and CAPA workflow

    Escalate, protect product, investigate, assess impact, and close actions.

    6

    Periodic review and change control

    Review trends, suppliers, calibration, access, incidents, and remapping triggers.

    5.EU GDP Temperature-Monitoring Compliance Checklist

    Control question Evidence to retain Primary owner
    Are all products and approved storage conditions listed? Current product-condition matrix and label references QA / Responsible Person
    Are the warehouse and 3PL activities within an authorised scope? Authorisations, site scope, contracts, subcontractor list QA / Regulatory
    Was mapping completed before use under representative conditions? Approved protocol, raw data, report, deviations, approval Validation / QA
    Are permanent sensors justified by mapping results? Approved floor plan, sensor master list, placement rationale QA / Facilities
    Are accuracy, uncertainty, calibration points, and intervals defined? URS, calibration SOP, current traceable certificates Metrology / QA
    Are alarm thresholds and delays approved? Alarm rationale, configuration record, change history QA / Operations
    Is the full alarm path tested periodically? Challenge-test records, after-hours test, corrective actions Operations / IT
    Does the system record during network loss? Offline-buffer test, recovery test, timestamp review IT / Validation
    Are data access, backup, restore, and retention controlled? Access matrix, backup logs, restore test, retention policy IT / QA
    Is the computerised system validated or verified for intended use? System description, risk assessment, test evidence, approval CSV / QA
    Are deviations investigated and linked to product decisions? Deviation report, impact assessment, disposition, CAPA QA / Responsible Person
    Does the 3PL quality agreement allocate GDP duties clearly? Signed agreement, communication matrix, audit rights Contract giver / 3PL QA
    Are staff trained and backup responders assigned? Training records, competency evidence, on-call roster Operations / QA
    Are changes reviewed for remapping or requalification? Change control, risk assessment, periodic review QA / Engineering

    6.Common Audit Findings and How to Avoid Them

    The EU GDP guideline does not publish a single list of “most common” warehouse findings. The following are recurring failure patterns derived from the control requirements and inspection-oriented guidance; they should be treated as an audit-preparation checklist, not as a claim about enforcement statistics.

    7.How Should Monitoring Systems Be Evaluated?

    Product selection should follow the URS, not precede it. Accuracy is only one dimension. A GDP warehouse also needs suitable range, calibration evidence, local continuity, outage behaviour, alarm functionality, user access, data retention, export, integration, change management, supplier support, validation evidence, and a sustainable operating model. The following criteria should be approved before a vendor shortlist is finalised.

    A monitoring platform should be approved only when the exact configured system satisfies the URS and demonstrates measurement suitability, continuity, alarm performance, electronic-record controls, supplier support, validation evidence, lifecycle ownership, and sustainable cost.

    Potential finding Why it is weak Likely consequence Preventive action
    A single sensor represents a large warehouse Placement is not linked to mapping or temperature extremes Excursions may remain undetected Map first; justify permanent points and review trends
    Mapping is treated as a one-time document Changes and seasonal risks are not assessed Old conclusions no longer reflect the facility Define remapping triggers in change control
    Calibration certificate is expired or incomplete Accuracy and traceability cannot be demonstrated Data reliability is challenged Control calibration status, uncertainty, points, and due dates
    Alarm configured but not challenged end-to-end Email/SMS/router/after-hours routing may fail Delayed or missed response Test sensor input through recipient acknowledgement
    Cloud system accepted without intended-use assessment Permissions, backup, audit evidence, and restore are unverified Electronic records may not be defensible Perform supplier assessment and risk-based validation
    Internet outage creates a data gap No local buffering or tested recovery Incomplete excursion history Specify local memory and verify automatic recovery
    3PL contract says “maintain GDP” without detail Roles, records, escalation, and subcontracting are unclear Disputes and delayed investigations Use a detailed quality agreement and performance review
    HVAC or rack changes occur without monitoring review Change control is disconnected from mapping and sensors Risk points shift without detection Assess remapping, sensor relocation, and requalification

    8.Representative Monitoring Architectures

    The table compares representative architectures using current official vendor information. It does not certify any system as EU GDP

    Comparison area UbiBot GS1-AETH1RS / GS1-A1RS ELPRO ECOLOG-PRO xG Vaisala RFL100 + AP10 + viewLinc Cloud Dickson DWE2 + DicksonOne
    Positioning Direct-connected fixed monitor; optional external RS485 probes; WS4-P4G1RS can support selected mobile/transport handoffs Cellular IoT temperature or T/RH logger for rooms and equipment Proprietary wireless logger + access point + regulated-environment monitoring platform Wi-Fi/Ethernet display logger with replaceable sensors and cloud subscription
    Connectivity 2.4 GHz Wi-Fi; AETH model also RJ45 Ethernet; optional PoE splitter LTE-M / NB-IoT direct to elproCLOUD VaiNet to AP10; AP10 uses Ethernet and PoE or AC Wi-Fi or Ethernet
    Dedicated gateway No for direct-connected GS1 models No local gateway Yes: AP10; up to 32 RFL100 loggers per AP10 No
    Local continuity 300,000 sensor records 31,000 values published for xG loggers Up to 30 days in RFL100 internal memory Approx. 400,000 backup sample points
    Display / local visibility 4-inch LCD Device-dependent status interface; cloud is primary RFL100 display plus AP10 status interface LCD with resettable min/max and audible/visible indicators
    Platform options Public cloud; on-premises platform; APIs and custom integration options elproCLOUD; optional API; vendor compliance services viewLinc Cloud or viewLinc Enterprise ecosystem DicksonOne cloud; subscription required
    Vendor compliance positioning Calibration and traceability guidance; public evidence for a complete EU Annex 11 validation package is not publicly specified Vendor states GAMP 5 validation and FDA 21 CFR Part 11 support; ISO 17025 calibration on request Designed for GxP-regulated monitoring; calibration traceability and system validation features Vendor provides audit trails, reports, permissions, and compliance services; EU Annex 11 evidence should be assessed
    Strong fit Cost-conscious fixed points, mixed Wi-Fi/Ethernet sites, local data continuity, and integration flexibility Rapid cellular deployment with minimal site IT and stronger packaged compliance services Enterprise life-science sites requiring structured wireless architecture and mature validation support Warehouses needing direct Wi-Fi/Ethernet, local display, replaceable sensors, and cloud reporting
    Key caution Regulated users must validate the configured platform, review access/audit/backup controls, and obtain suitable calibration evidence Part 11 claims do not automatically prove EU Annex 11 or site-specific validation; recurring cloud/service model applies Requires AP10 infrastructure and a more structured enterprise deployment; licensing and services should be scoped Requires DicksonOne subscription; verify audit-trail, retention, validation, and regional service details
    Relative implementation burden Low to moderate Low to moderate for xG; compliance service scope may increase project work Moderate to high Moderate

    Specifications and vendor claims were reviewed in July 2026. Exact models, probes, software versions, licenses, calibration services, and regional availability must be confirmed in the procurement and validation package.

    9.Scenario-Based System Selection

    For a small or medium fixed warehouse with existing Wi-Fi or Ethernet, a direct-connected architecture can reduce gateway infrastructure. UbiBot GS1-AETH1RS is relevant where Ethernet resilience, local display, large local memory, and RS485 expansion are valued; GS1-A1RS is the Wi-Fi-only alternative. The regulated user must still confirm probe suitability, calibration evidence, alarm testing, data governance, and validation for the chosen platform.

    For a site that cannot depend on local IT, ELPRO ECOLOG-PRO xG offers direct LTE-M/NB-IoT communication and a stronger packaged GxP service proposition. For enterprise life-science networks that prioritise a mature proprietary wireless architecture, traceable probes, structured access-point design, and formal validation support, Vaisala RFL100 with AP10 and viewLinc is a more natural benchmark. Dickson DWE2 fits organisations that want a direct Wi-Fi/Ethernet display logger, replaceable sensors, substantial local backup memory, and DicksonOne reporting and alarms.

    For a pharmaceutical 3PL operating multiple client zones, the preferred system may vary by customer contract. A practical approach is to standardise the core data-governance and alarm process while maintaining validated configurations for different sensor types or platforms. The most defensible selection is the one that meets the approved URS, can be supported throughout its lifecycle, and produces complete evidence during an excursion or inspection—not the product with the longest feature list.

    10.Frequently Asked Questions

    Does EU GDP require continuous temperature monitoring in a warehouse?

    EU GDP requires suitable equipment and procedures, initial mapping, risk-based permanent monitor placement, calibrated devices, and alarms. It does not use one sentence that prescribes the same continuous logging interval for every warehouse. In practice, an automated monitoring system should collect data frequently enough to detect and reconstruct excursions for the products and facility risk. The chosen interval must be documented in the URS and justified; manual spot checks alone are generally weak evidence for a large or temperature-sensitive storage area.

    Does EU GDP require all pharmaceutical warehouses to stay between 2°C and 8°C?

    No. Storage and transport conditions are determined by the medicinal product’s approved labelling, manufacturer information, and quality agreements. Some products require refrigeration, others controlled room temperature, frozen conditions, or protection from light or moisture. The warehouse should maintain a product-condition matrix and segregate products appropriately. Alarm limits should be linked to approved requirements and measurement uncertainty rather than applying one generic temperature range to every stock item.

    How often must a pharmaceutical warehouse be temperature mapped?

    EU GDP requires mapping before use and repetition according to risk assessment or after significant changes to the facility or temperature-control equipment. It does not prescribe a universal annual interval for warehouse remapping. The site should define triggers such as HVAC modification, racking changes, expansion, altered loading patterns, repeated deviations, new storage zones, or evidence that seasonal conditions are no longer represented. The periodic review should document why the existing map remains valid or why a new study is required.

    How many permanent sensors are required?

    The guideline does not provide a sensor-per-square-metre formula. Permanent monitoring devices should be located according to the mapping results, especially where extremes or significant fluctuations occur. The site should justify sensor quantity and position based on mapped hot and cold points, rack height, airflow, loading doors, exterior walls, refrigeration design, product risk, and the consequence of a missed excursion. A floor plan and sensor master list should link every permanent point to the mapping rationale.

    What accuracy does EU GDP require for warehouse temperature sensors?

    For fixed storage areas, EU GDP requires calibration at defined intervals based on risk and reliability, with traceability to national or international measurement standards. It does not specify one universal warehouse accuracy. The URS should define accuracy, uncertainty, calibration points, and acceptance limits that are appropriate relative to the product limits and alarm strategy. For transport monitoring equipment, the guideline explicitly calls for regular calibration at least annually. National rules or customer agreements may be more specific.

    How long should temperature records be retained?

    EU GDP documentation should be retained for the period stated in national legislation and for at least five years. Electronic backup data should likewise be retained for the applicable period at a separate and secure location. A site should confirm whether product, customer, tax, pharmacovigilance, clinical, or national requirements require longer retention. Retention must include the ability to retrieve readable records and associated metadata, not merely an assertion that the cloud provider stores data.

    Can a pharmaceutical company rely on a 3PL’s monitoring system?

    Yes, but outsourcing does not remove the contract giver’s responsibility. The company should assess the 3PL and its authorisation status, approve the monitoring and validation approach, define responsibilities in a written quality agreement, ensure access to complete records, review alarms and deviations, audit performance, and control subcontracting. The agreement should also cover data ownership, retention, system changes, calibration, mapping, backup, incident notification, product disposition, and data transfer when the contract ends.

    Does FDA 21 CFR Part 11 compliance prove EU GDP or Annex 11 compliance?

    No. Part 11, EU GDP, and EU GMP Annex 11 have overlapping data-integrity concerns but different legal scopes and expectations. A vendor’s Part 11 statement may be relevant supplier evidence, but the regulated organisation must still assess intended use, configuration, access control, audit trails, backup, electronic signatures where used, supplier management, validation, change control, incident management, and business continuity. The final compliance position belongs to the regulated company and its competent authority, not to a generic product label.

    11.Conclusion

    EU GDP temperature monitoring is a controlled quality process, not a hardware purchase. A defensible warehouse programme starts with approved product conditions and regulatory scope, characterises the facility through mapping, converts the evidence into permanent monitor placement, controls calibration and alarms, protects records, validates the computerised system according to risk, and connects excursions to product-impact assessment and CAPA. Pharmaceutical 3PL arrangements require the same technical controls plus explicit contract-giver oversight and transparent access to evidence.

    UbiBot can offer a balanced architecture for fixed warehouse points where direct Wi-Fi or Ethernet, large local memory, RS485 expansion, public-cloud or on-premises options, and lower infrastructure complexity are valued. ELPRO, Vaisala, and Dickson may be more suitable where the buyer prioritises packaged GxP services, mature enterprise validation support, proprietary wireless architecture, or a specific regulated-industry workflow. None of these systems becomes compliant by model name alone. The configured system, calibration evidence, mapping, SOPs, contracts, validation, training, and quality decisions form the compliance case.

    12.Official Reference

    1. Guidelines of 5 November 2013 on Good Distribution Practice of medicinal products for human use (2013/C 343/01) — European Commission / EUR-Lex. Official source Primary source for EU/EEA wholesale distribution, mapping, calibration, alarms, computerised systems, documentation, outsourced activities, transport, and CAPA.
    2. EudraLex Volume 1 — current listing of EU pharmaceutical legislation and guidelines — European Commission. Official source Confirms the current official listing of 2013/C 343/01.
    3. TRS 961, Annex 9: Model guidance for the storage and transport of time- and temperature-sensitive pharmaceutical products — World Health Organization. Official source Global TTSPP implementation context; local law remains controlling.
    4. TRS 992, Annex 5: Technical supplements to the WHO TTSPP model guidance — World Health Organization. Official source Technical support for mapping, qualification, monitoring, calibration, transport, and facility design.
    5. Cold chain equipment and dry store temperature mapping tool — World Health Organization. Official source Current WHO mapping resource and implementation tool.
    6. Temperature mapping — an introduction — MHRA Inspectorate. Official source Inspection-oriented explanation of GDP Chapter 3.2.1; UK context only.
    7. GS1-AETH1RS specifications and product information — UbiBot. Official source Official product data for connectivity, sensors, display, local memory, power, and external probes.
    8. GS1-A1RS specifications — UbiBot. Official source Official product data for the Wi-Fi-only GS1 configuration.
    9. WS4-P4G1RS product information — UbiBot. Official source Official product data for 4G, GNSS, RS485 support, local memory, and transport-oriented use.
    10. Public Cloud Pricing and On-Premises Platform — UbiBot. Official source Official platform architecture, subscription, API, and deployment options.

    13.Sources and Product Information Disclaimer

    This article is provided for informational and editorial purposes and does not constitute legal, regulatory, validation, quality, or engineering advice. EU GDP compliance depends on the authorised activity, applicable national law, medicinal-product requirements, competent-authority expectations, quality agreements, validated procedures, and the configured monitoring system. Product specifications, software functions, licences, calibration services, network support, and vendor compliance claims may vary by model, region, software version, probe, and contract. Verify current official documentation and obtain approval from qualified QA/RA and legal personnel before implementation.

    Related Resources

    No related resources found

    menu-header-svg
    Search
    • Explore Knowledge
      • Comparison & Selection
      • Industry Solution
      • Product & Device
      • Criterion & Compliance
      • Deployment & Usage
      • Technology & Principle
    • Academic Research
    • In-depth Tech

    Criterion & Compliance

    See More >>

    EU GDP Temperature Monitoring for Pharmaceutical Warehouses and 3PLs

    Temperature control in a pharmaceutical warehouse is not demonstrated by a single wall sensor or by an annual calibration certificate. A storage area can show an acceptable average temperature while exposing medicinal products at upper racks, loading doors, cold walls, heater zones, return areas, or poorly ventilated corners to conditions outside their approved storage requirements. For a third-party logistics provider, the problem is broader: the warehouse must generate reliable records, but the contract giver must also define responsibilities, review performance, and retain oversight of the outsourced activity.

    The EU Guidelines on Good Distribution Practice of medicinal products for human use, 2013/C 343/01, translate these risks into a quality-system obligation. They require suitable environmental controls, temperature mapping before use, risk-based placement of permanent monitors, traceable calibration, functional alarms, protected records, qualification or validation where appropriate, documented deviation handling, and control of outsourced activities. The guideline does not prescribe one universal warehouse temperature, one logging interval, or one sensor accuracy for every product. Those specifications must be justified from the medicinal product’s approved storage conditions, the facility risk assessment, and the intended use of the monitoring system.

    This guide explains what EU GDP requires, how warehouses and pharmaceutical 3PLs can convert the clauses into an implementable monitoring architecture, which evidence auditors commonly expect, and how to evaluate representative monitoring systems without confusing vendor features with a compliance conclusion.

    Key compliance answer

    EU GDP expects pharmaceutical warehouses to prove that approved storage conditions are maintained through a controlled system: representative temperature mapping, permanent monitoring at risk-based locations, traceable calibration, tested alarms, protected and retrievable records, documented incident handling, and periodic review. Outsourcing storage to a 3PL does not transfer the contract giver’s responsibility for oversight.

    EU GDP temperature control is demonstrated by a connected quality system: product-specific requirements, representative mapping, risk-based permanent monitors, traceable calibration, tested alarms, protected records, qualified response, CAPA, and contract-giver oversight of outsourced storage.

    1.What Is EU GDP, and Who Needs to Comply?

    The formal source is the European Commission’s Guidelines of 5 November 2013 on Good Distribution Practice of medicinal products for human use, published as 2013/C 343/01. The guideline is based on Articles 84 and 85b(3) of Directive 2001/83/EC and applies within the EU and EEA framework. A person acting as a wholesale distributor must hold the applicable wholesale distribution authorisation, and manufacturers that distribute their own authorised medicinal products must also follow GDP for those distribution activities.

    A pharmaceutical 3PL may perform the storage activity, but the contract giver remains responsible for assessment, written allocation of GDP duties, access to records, performance review, subcontractor control, audit, and quality decisions.

    The guideline is not limited to businesses that call themselves pharmaceutical wholesalers. It covers the activities of procuring, holding, supplying, and exporting medicinal products, apart from supply to the public. Warehousing, cross-docking, pick-and-pack operations, quarantine storage, cold rooms, returns handling, and transport handoffs may therefore fall within the controlled distribution chain when performed for medicinal products.

    For a pharmaceutical 3PL, the decisive issue is not the commercial label “3PL” but the regulated activity being performed and the authorisation required in the relevant Member State. Chapter 1.3 requires the quality system to extend to outsourced activities, while Chapter 7 requires the outsourced activity to be defined, agreed, and controlled through a written contract. The contract giver remains responsible for the contracted activity; it must assess the contract acceptor, define responsibilities and communication, and monitor performance. A warehouse contract therefore needs more than service-level language about uptime or response times: it must allocate GDP quality responsibilities, deviation reporting, access to records, calibration, mapping, subcontracting, and audit rights.

    EU GDP is also not a global licence. Great Britain operates under the Human Medicines Regulations 2012 and current MHRA requirements; WHO TTSPP guidance provides a global model for time- and temperature-sensitive pharmaceutical products but states that local legislation takes precedence. Singapore, Hong Kong, Australia, and other markets maintain separate licensing and wholesaling requirements. A multinational 3PL should maintain a jurisdiction matrix rather than treating EU GDP as a universal substitute.

    Framework Primary role Use in this article
    EU GDP 2013/C 343/01 EU/EEA requirements and guidance for wholesale distribution of human medicinal products Primary compliance framework
    WHO TTSPP / GS&DP guidance Global model guidance and technical supplements for time- and temperature-sensitive products Implementation support; local law remains controlling
    UK / other national regimes National authorisation, inspection, records, and storage requirements Must be checked separately before cross-border use

    2.Key EU GDP Requirements That Affect Temperature Monitoring

    Storage Conditions Must Follow the Product Requirement

    EU GDP does not impose a universal “2°C to 8°C” or “15°C to 25°C” warehouse limit. Chapter 5 requires medicinal products to be handled according to the information on the outer packaging, and Chapter 9 requires defined storage conditions to be maintained during transportation as described by the manufacturer or packaging. A warehouse must therefore maintain a controlled product-condition matrix covering ambient, controlled-room-temperature, refrigerated, frozen, light-sensitive, and any humidity-sensitive stock actually held at the site.

    Warehouse limits and environmental controls must follow the approved conditions of the products actually handled; EU GDP does not impose one universal 2°C to 8°C or 15°C to 25°C range for every medicinal product.

    Chapter 3.2.1 identifies temperature, light, humidity, and cleanliness as environmental factors to consider. This does not mean that every warehouse must continuously monitor every parameter. It means the site must evaluate which factors can affect the products or the operation and then document the control strategy. Relative humidity monitoring is justified where product information, packaging sensitivity, condensation risk, facility design, or the quality risk assessment makes it relevant.

    Temperature Mapping Determines Permanent Sensor Placement

    Before a storage area is used, Chapter 3.2.1 calls for an initial temperature mapping exercise under representative conditions. Permanent monitoring devices should then be positioned according to the mapping results, particularly in locations that experience the greatest fluctuations. Mapping should be repeated according to risk assessment or whenever significant changes are made to the facility or temperature-control equipment.

    Mapping and routine monitoring are different controls. Mapping characterises the three-dimensional distribution of temperature across time and operating conditions. Routine monitoring provides continuous evidence at selected control points. A permanent sensor installed for convenience near an office door is not a substitute for a mapping study that identifies upper-rack hot zones, cold walls, evaporator discharge, loading-door exposure, or areas affected by seasonal conditions. WHO technical supplements provide useful methods for mapping and qualification, but the protocol, logger density, study duration, loading state, and seasonal strategy must be justified for the actual facility.

    Initial mapping characterises three-dimensional temperature behaviour under representative conditions; the approved results then justify permanent monitors at mapped extremes and other locations most likely to fluctuate.

    Calibration, Alarms, Maintenance, and Backup Must Be Controlled

    Chapter 3.3 requires environmental control and monitoring equipment to be calibrated at defined intervals based on a risk and reliability assessment. Calibration should be traceable to a national or international measurement standard. For warehouse monitoring, the EU guideline does not specify one accuracy limit or one fixed calibration interval. The user requirement specification should therefore define the required accuracy, uncertainty, calibration points, acceptance limits, and interval based on product limits and process risk. For transport monitoring equipment, Chapter 9 specifically states that regular calibration should occur at least once a year.

    Appropriate alarm systems must alert users when predefined storage conditions are exceeded; alarm levels must be set appropriately and alarms tested regularly. The practical system requirement extends beyond a high-temperature notification. It should address warning and action thresholds, delay logic, repeat notifications, offline-device alarms, low-power conditions, local visibility, after-hours escalation, acknowledgement, and evidence that the complete alarm path was challenged. Planned maintenance and retained records of repair, maintenance, and calibration are also expected for key equipment.

    A defensible monitoring point combines risk-based measurement specifications, traceable calibration, controlled maintenance, approved alarm logic, end-to-end challenge testing, backup readiness, and documented responder acknowledgement.

    Records, Computerised Systems, and Data Integrity Matter

    EU GDP documentation can be paper-based or electronic, but it must be clear, approved, retrievable, controlled, and retained for the period stated in national legislation and for at least five years. Changes to documentation should be signed and dated while preserving the original information. This requirement affects monitoring reports, calibration certificates, mapping protocols and reports, alarm histories, deviation records, user administration, maintenance records, and quality agreements.

    Chapter 3.3.1 adds controls for computerised systems. Before use, the system should be shown through validation or verification studies to achieve the intended results accurately, consistently, and reproducibly. The system description should explain scope, security, functions, use, and interfaces. Only authorised persons should enter or amend data. Records must be protected against accidental or unauthorised change, checked for accessibility, backed up regularly, and recoverable after failure. Backup data should be retained separately and securely for the applicable period, at least five years.

    EU GDP does not require every warehouse record to use an electronic signature, and a vendor’s FDA 21 CFR Part 11 statement is not automatically evidence of EU Annex 11 suitability. The regulated company must define whether the monitoring platform is a GxP computerised system, establish intended use, review supplier evidence, assess audit trails and permissions, test backup and restoration, and validate or verify the configured system according to risk.

    For a GxP monitoring system, intended use, authorised access, validated configuration, audit evidence, backup, restore, readable retrieval, retention, change control, and periodic review protect the record from measurement through long-term use.

    Deviations and CAPA Must Connect the Data to Decisions

    A monitoring system does not close a GDP deviation by sending an email. Chapter 1 requires deviations from established procedures to be documented and investigated, with appropriate corrective and preventive action (CAPA). The response procedure should preserve the raw data, identify the affected product and duration, evaluate product impact with authorised quality personnel, document disposition, identify root causes, and track actions to completion. For a 3PL, the quality agreement must define who is notified, who owns the investigation, who can release or reject stock, and how evidence is transferred to the contract giver.

    An alarm begins a controlled response: protect product, preserve raw data, define the affected time, locations and batches, assess impact under authorised quality authority, document disposition, investigate root cause, and close effective CAPA.

    EU GDP requirement Clause area Monitoring control Expected evidence
    Approved storage conditions Ch. 3, 5 and 9 Product-condition matrix and approved alarm limits Product labels, quality agreements, SOPs
    Initial temperature mapping 3.2.1 Representative mapping before use Approved protocol, raw data, report, deviations
    Risk-based monitor placement 3.2.1 Permanent devices at mapped extremes and risk points Sensor map linked to mapping conclusions
    Traceable calibration 3.3 Defined accuracy, points, interval, and traceability Current certificates and calibration status
    Functional alarms 3.3 Defined thresholds, delays, escalation, and periodic challenge Alarm-test records and incident logs
    Protected electronic records 3.3.1 and 4.2 Authorised access, backup, restore, retention, version control Validation/verification, access matrix, restore test
    Outsourced activity control 1.3 and 7 Quality agreement, qualification, KPI review, audit and CAPA Approved contract, audit reports, performance reviews

    3.How to Turn EU GDP Requirements into an Implementable System

    Step 1: Define Scope, Products, and User Requirements

    Start with a documented scope: buildings, rooms, cold stores, freezers, loading interfaces, returns and quarantine zones, temporary staging, transport handoff, and any outsourced sites. Link each area to the medicinal products stored there and their approved conditions. The user requirement specification (URS) should define measurement range, accuracy and uncertainty, sampling and communication intervals, alarm functions, local memory, network behaviour, power backup, data retention, user roles, audit evidence, reports, interfaces, and calibration requirements. Where the guideline does not prescribe a number, the URS should state the risk-based rationale rather than inventing a universal value.

    Step 2: Perform Risk Assessment, Qualification, and Mapping

    The mapping plan should be approved before data collection. It should describe the room configuration, HVAC and refrigeration system, rack layout, operating state, loading condition, logger locations, reference instruments, study duration, acceptance criteria, handling of door openings and defrost cycles, and treatment of deviations. Representative conditions may require studies during different seasons or operating scenarios. Significant HVAC work, changes to racking, expansion, altered airflow, new loading patterns, or adverse trend data should trigger a documented assessment of whether remapping is required.

    Qualification and validation are not interchangeable. Equipment qualification demonstrates that hardware is installed and operates as intended; process validation or verification demonstrates that the configured system and process achieve the required result. EU GDP expects key equipment and processes to be qualified or validated before use and after significant changes, with the scope determined through documented risk assessment.

    Step 3: Convert Mapping Results into Permanent Monitoring Points

    Select routine monitoring points from the mapping evidence, not from the number of available electrical outlets. Typical risk locations include mapped hot and cold points, high and low rack positions, exterior walls, evaporator discharge and return paths, loading doors, areas near heaters, and zones with poor air circulation. The exact number of permanent sensors is not specified by EU GDP. It should be sufficient to detect loss of control and should be justified in the monitoring plan. Sensor IDs, locations, calibration status, and associated alarm limits should be controlled in a master list and reflected on an approved floor plan.

    Step 4: Design Connectivity and Data Continuity

    Connectivity should be selected according to facility risk and IT policy. Ethernet can provide stable fixed connectivity; Wi-Fi can reduce cabling but requires coverage and security assessment; cellular can provide independence from the site network; LoRa or other sub-GHz networks can support many distributed points through gateways; RS485 is useful for wired external probes and industrial interfaces. No method is universally best. The design should document what happens when the network, gateway, cloud service, mains power, or device battery fails.

    Local buffering is valuable because a network outage should not create an unrecorded period, but local storage alone does not preserve real-time alarms. The site should test both data continuity and notification continuity. For critical areas, consider independent power paths, gateway or router backup, cellular fallback, local audible/visual alarms, and a procedural fallback for manual review. Data recovery tests should confirm timestamps, sequence, duplicate handling, and the visibility of gaps.

    Local buffering may preserve temperature records when a network, gateway, cloud service, or power path fails, but remote alarms may still be lost; both histories and response paths require independent challenge and recovery testing.

     

    EU GDP requirement Clause area Monitoring control Expected evidence
    Approved storage conditions Ch. 3, 5 and 9 Product-condition matrix and approved alarm limits Product labels, quality agreements, SOPs
    Initial temperature mapping 3.2.1 Representative mapping before use Approved protocol, raw data, report, deviations
    Risk-based monitor placement 3.2.1 Permanent devices at mapped extremes and risk points Sensor map linked to mapping conclusions
    Traceable calibration 3.3 Defined accuracy, points, interval, and traceability Current certificates and calibration status
    Functional alarms 3.3 Defined thresholds, delays, escalation, and periodic challenge Alarm-test records and incident logs
    Protected electronic records 3.3.1 and 4.2 Authorised access, backup, restore, retention, version control Validation/verification, access matrix, restore test
    Outsourced activity control 1.3 and 7 Quality agreement, qualification, KPI review, audit and CAPA Approved contract, audit reports, performance reviews

    Architecture decisions should be documented in the URS and qualification plan. “Cloud-connected” is not a substitute for outage testing or data-governance assessment.

    Step 5: Establish Alarm Escalation, Deviation Handling, and CAPA

    Alarm design should begin with approved product limits and the measurement uncertainty of the complete system. Many sites use an early-warning threshold inside the action limit, but any delay, dead band, repeat period, or suppression rule must be justified. The escalation matrix should identify primary and backup responders, after-hours contacts, acknowledgement expectations, and the point at which QA or the Responsible Person becomes involved.

    During an excursion, personnel should protect product first, preserve evidence, and avoid changing or deleting raw data. The investigation should establish when the excursion began, its duration and magnitude, affected locations and batches, equipment and network status, door or loading activity, and any concurrent maintenance. Product disposition must be based on approved information and quality authority, not solely on a dashboard colour. Corrective and preventive actions may include HVAC repair, alarm redesign, sensor relocation, procedure changes, training, remapping, or supplier action.

    Step 6: Validate the Computerised System and Control the 3PL Relationship

    The validation or verification package should be proportionate to risk and intended use. At minimum, the regulated company should document system scope and data flow, supplier assessment, user roles, configuration, alarm tests, data export, audit-trail behaviour where applicable, backup and restoration, time synchronisation, security, incident handling, change control, and periodic review. A vendor brochure that mentions GxP or Part 11 is evidence to review, not a substitute for the user organisation’s assessment and approval of the configured system.

    For outsourced storage, the quality agreement should identify who owns mapping, calibration, maintenance, alarm response, deviation investigation, product-impact assessment, data retention, access management, validation documents, backup and recovery, subcontractor approval, and regulatory inspection support. The contract giver should review KPIs such as alarm response, overdue calibration, device offline time, repeat deviations, CAPA closure, and system changes. Where a 3PL uses its own platform, the client should have timely access to complete records and a defined exit or data-transfer plan.

    4.EU GDP Monitoring Implementation Flow

    1

    Regulatory scope and product conditions

    Define licences, products, areas, limits, and responsibilities.

    2

    URS and quality risk assessment

    Specify accuracy, logging, alarms, records, security, backup, and interfaces.

    3

    Mapping, qualification, and approval

    Characterise the facility under representative conditions before use.

    4

    Permanent monitoring and calibration

    Place calibrated sensors at mapped risk points and control the master list.

    5

    Alarm, deviation, and CAPA workflow

    Escalate, protect product, investigate, assess impact, and close actions.

    6

    Periodic review and change control

    Review trends, suppliers, calibration, access, incidents, and remapping triggers.

    5.EU GDP Temperature-Monitoring Compliance Checklist

    Control question Evidence to retain Primary owner
    Are all products and approved storage conditions listed? Current product-condition matrix and label references QA / Responsible Person
    Are the warehouse and 3PL activities within an authorised scope? Authorisations, site scope, contracts, subcontractor list QA / Regulatory
    Was mapping completed before use under representative conditions? Approved protocol, raw data, report, deviations, approval Validation / QA
    Are permanent sensors justified by mapping results? Approved floor plan, sensor master list, placement rationale QA / Facilities
    Are accuracy, uncertainty, calibration points, and intervals defined? URS, calibration SOP, current traceable certificates Metrology / QA
    Are alarm thresholds and delays approved? Alarm rationale, configuration record, change history QA / Operations
    Is the full alarm path tested periodically? Challenge-test records, after-hours test, corrective actions Operations / IT
    Does the system record during network loss? Offline-buffer test, recovery test, timestamp review IT / Validation
    Are data access, backup, restore, and retention controlled? Access matrix, backup logs, restore test, retention policy IT / QA
    Is the computerised system validated or verified for intended use? System description, risk assessment, test evidence, approval CSV / QA
    Are deviations investigated and linked to product decisions? Deviation report, impact assessment, disposition, CAPA QA / Responsible Person
    Does the 3PL quality agreement allocate GDP duties clearly? Signed agreement, communication matrix, audit rights Contract giver / 3PL QA
    Are staff trained and backup responders assigned? Training records, competency evidence, on-call roster Operations / QA
    Are changes reviewed for remapping or requalification? Change control, risk assessment, periodic review QA / Engineering

    6.Common Audit Findings and How to Avoid Them

    The EU GDP guideline does not publish a single list of “most common” warehouse findings. The following are recurring failure patterns derived from the control requirements and inspection-oriented guidance; they should be treated as an audit-preparation checklist, not as a claim about enforcement statistics.

    7.How Should Monitoring Systems Be Evaluated?

    Product selection should follow the URS, not precede it. Accuracy is only one dimension. A GDP warehouse also needs suitable range, calibration evidence, local continuity, outage behaviour, alarm functionality, user access, data retention, export, integration, change management, supplier support, validation evidence, and a sustainable operating model. The following criteria should be approved before a vendor shortlist is finalised.

    A monitoring platform should be approved only when the exact configured system satisfies the URS and demonstrates measurement suitability, continuity, alarm performance, electronic-record controls, supplier support, validation evidence, lifecycle ownership, and sustainable cost.

    Potential finding Why it is weak Likely consequence Preventive action
    A single sensor represents a large warehouse Placement is not linked to mapping or temperature extremes Excursions may remain undetected Map first; justify permanent points and review trends
    Mapping is treated as a one-time document Changes and seasonal risks are not assessed Old conclusions no longer reflect the facility Define remapping triggers in change control
    Calibration certificate is expired or incomplete Accuracy and traceability cannot be demonstrated Data reliability is challenged Control calibration status, uncertainty, points, and due dates
    Alarm configured but not challenged end-to-end Email/SMS/router/after-hours routing may fail Delayed or missed response Test sensor input through recipient acknowledgement
    Cloud system accepted without intended-use assessment Permissions, backup, audit evidence, and restore are unverified Electronic records may not be defensible Perform supplier assessment and risk-based validation
    Internet outage creates a data gap No local buffering or tested recovery Incomplete excursion history Specify local memory and verify automatic recovery
    3PL contract says “maintain GDP” without detail Roles, records, escalation, and subcontracting are unclear Disputes and delayed investigations Use a detailed quality agreement and performance review
    HVAC or rack changes occur without monitoring review Change control is disconnected from mapping and sensors Risk points shift without detection Assess remapping, sensor relocation, and requalification

    8.Representative Monitoring Architectures

    The table compares representative architectures using current official vendor information. It does not certify any system as EU GDP

    Comparison area UbiBot GS1-AETH1RS / GS1-A1RS ELPRO ECOLOG-PRO xG Vaisala RFL100 + AP10 + viewLinc Cloud Dickson DWE2 + DicksonOne
    Positioning Direct-connected fixed monitor; optional external RS485 probes; WS4-P4G1RS can support selected mobile/transport handoffs Cellular IoT temperature or T/RH logger for rooms and equipment Proprietary wireless logger + access point + regulated-environment monitoring platform Wi-Fi/Ethernet display logger with replaceable sensors and cloud subscription
    Connectivity 2.4 GHz Wi-Fi; AETH model also RJ45 Ethernet; optional PoE splitter LTE-M / NB-IoT direct to elproCLOUD VaiNet to AP10; AP10 uses Ethernet and PoE or AC Wi-Fi or Ethernet
    Dedicated gateway No for direct-connected GS1 models No local gateway Yes: AP10; up to 32 RFL100 loggers per AP10 No
    Local continuity 300,000 sensor records 31,000 values published for xG loggers Up to 30 days in RFL100 internal memory Approx. 400,000 backup sample points
    Display / local visibility 4-inch LCD Device-dependent status interface; cloud is primary RFL100 display plus AP10 status interface LCD with resettable min/max and audible/visible indicators
    Platform options Public cloud; on-premises platform; APIs and custom integration options elproCLOUD; optional API; vendor compliance services viewLinc Cloud or viewLinc Enterprise ecosystem DicksonOne cloud; subscription required
    Vendor compliance positioning Calibration and traceability guidance; public evidence for a complete EU Annex 11 validation package is not publicly specified Vendor states GAMP 5 validation and FDA 21 CFR Part 11 support; ISO 17025 calibration on request Designed for GxP-regulated monitoring; calibration traceability and system validation features Vendor provides audit trails, reports, permissions, and compliance services; EU Annex 11 evidence should be assessed
    Strong fit Cost-conscious fixed points, mixed Wi-Fi/Ethernet sites, local data continuity, and integration flexibility Rapid cellular deployment with minimal site IT and stronger packaged compliance services Enterprise life-science sites requiring structured wireless architecture and mature validation support Warehouses needing direct Wi-Fi/Ethernet, local display, replaceable sensors, and cloud reporting
    Key caution Regulated users must validate the configured platform, review access/audit/backup controls, and obtain suitable calibration evidence Part 11 claims do not automatically prove EU Annex 11 or site-specific validation; recurring cloud/service model applies Requires AP10 infrastructure and a more structured enterprise deployment; licensing and services should be scoped Requires DicksonOne subscription; verify audit-trail, retention, validation, and regional service details
    Relative implementation burden Low to moderate Low to moderate for xG; compliance service scope may increase project work Moderate to high Moderate

    Specifications and vendor claims were reviewed in July 2026. Exact models, probes, software versions, licenses, calibration services, and regional availability must be confirmed in the procurement and validation package.

    9.Scenario-Based System Selection

    For a small or medium fixed warehouse with existing Wi-Fi or Ethernet, a direct-connected architecture can reduce gateway infrastructure. UbiBot GS1-AETH1RS is relevant where Ethernet resilience, local display, large local memory, and RS485 expansion are valued; GS1-A1RS is the Wi-Fi-only alternative. The regulated user must still confirm probe suitability, calibration evidence, alarm testing, data governance, and validation for the chosen platform.

    For a site that cannot depend on local IT, ELPRO ECOLOG-PRO xG offers direct LTE-M/NB-IoT communication and a stronger packaged GxP service proposition. For enterprise life-science networks that prioritise a mature proprietary wireless architecture, traceable probes, structured access-point design, and formal validation support, Vaisala RFL100 with AP10 and viewLinc is a more natural benchmark. Dickson DWE2 fits organisations that want a direct Wi-Fi/Ethernet display logger, replaceable sensors, substantial local backup memory, and DicksonOne reporting and alarms.

    For a pharmaceutical 3PL operating multiple client zones, the preferred system may vary by customer contract. A practical approach is to standardise the core data-governance and alarm process while maintaining validated configurations for different sensor types or platforms. The most defensible selection is the one that meets the approved URS, can be supported throughout its lifecycle, and produces complete evidence during an excursion or inspection—not the product with the longest feature list.

    10.Frequently Asked Questions

    Does EU GDP require continuous temperature monitoring in a warehouse?

    EU GDP requires suitable equipment and procedures, initial mapping, risk-based permanent monitor placement, calibrated devices, and alarms. It does not use one sentence that prescribes the same continuous logging interval for every warehouse. In practice, an automated monitoring system should collect data frequently enough to detect and reconstruct excursions for the products and facility risk. The chosen interval must be documented in the URS and justified; manual spot checks alone are generally weak evidence for a large or temperature-sensitive storage area.

    Does EU GDP require all pharmaceutical warehouses to stay between 2°C and 8°C?

    No. Storage and transport conditions are determined by the medicinal product’s approved labelling, manufacturer information, and quality agreements. Some products require refrigeration, others controlled room temperature, frozen conditions, or protection from light or moisture. The warehouse should maintain a product-condition matrix and segregate products appropriately. Alarm limits should be linked to approved requirements and measurement uncertainty rather than applying one generic temperature range to every stock item.

    How often must a pharmaceutical warehouse be temperature mapped?

    EU GDP requires mapping before use and repetition according to risk assessment or after significant changes to the facility or temperature-control equipment. It does not prescribe a universal annual interval for warehouse remapping. The site should define triggers such as HVAC modification, racking changes, expansion, altered loading patterns, repeated deviations, new storage zones, or evidence that seasonal conditions are no longer represented. The periodic review should document why the existing map remains valid or why a new study is required.

    How many permanent sensors are required?

    The guideline does not provide a sensor-per-square-metre formula. Permanent monitoring devices should be located according to the mapping results, especially where extremes or significant fluctuations occur. The site should justify sensor quantity and position based on mapped hot and cold points, rack height, airflow, loading doors, exterior walls, refrigeration design, product risk, and the consequence of a missed excursion. A floor plan and sensor master list should link every permanent point to the mapping rationale.

    What accuracy does EU GDP require for warehouse temperature sensors?

    For fixed storage areas, EU GDP requires calibration at defined intervals based on risk and reliability, with traceability to national or international measurement standards. It does not specify one universal warehouse accuracy. The URS should define accuracy, uncertainty, calibration points, and acceptance limits that are appropriate relative to the product limits and alarm strategy. For transport monitoring equipment, the guideline explicitly calls for regular calibration at least annually. National rules or customer agreements may be more specific.

    How long should temperature records be retained?

    EU GDP documentation should be retained for the period stated in national legislation and for at least five years. Electronic backup data should likewise be retained for the applicable period at a separate and secure location. A site should confirm whether product, customer, tax, pharmacovigilance, clinical, or national requirements require longer retention. Retention must include the ability to retrieve readable records and associated metadata, not merely an assertion that the cloud provider stores data.

    Can a pharmaceutical company rely on a 3PL’s monitoring system?

    Yes, but outsourcing does not remove the contract giver’s responsibility. The company should assess the 3PL and its authorisation status, approve the monitoring and validation approach, define responsibilities in a written quality agreement, ensure access to complete records, review alarms and deviations, audit performance, and control subcontracting. The agreement should also cover data ownership, retention, system changes, calibration, mapping, backup, incident notification, product disposition, and data transfer when the contract ends.

    Does FDA 21 CFR Part 11 compliance prove EU GDP or Annex 11 compliance?

    No. Part 11, EU GDP, and EU GMP Annex 11 have overlapping data-integrity concerns but different legal scopes and expectations. A vendor’s Part 11 statement may be relevant supplier evidence, but the regulated organisation must still assess intended use, configuration, access control, audit trails, backup, electronic signatures where used, supplier management, validation, change control, incident management, and business continuity. The final compliance position belongs to the regulated company and its competent authority, not to a generic product label.

    11.Conclusion

    EU GDP temperature monitoring is a controlled quality process, not a hardware purchase. A defensible warehouse programme starts with approved product conditions and regulatory scope, characterises the facility through mapping, converts the evidence into permanent monitor placement, controls calibration and alarms, protects records, validates the computerised system according to risk, and connects excursions to product-impact assessment and CAPA. Pharmaceutical 3PL arrangements require the same technical controls plus explicit contract-giver oversight and transparent access to evidence.

    UbiBot can offer a balanced architecture for fixed warehouse points where direct Wi-Fi or Ethernet, large local memory, RS485 expansion, public-cloud or on-premises options, and lower infrastructure complexity are valued. ELPRO, Vaisala, and Dickson may be more suitable where the buyer prioritises packaged GxP services, mature enterprise validation support, proprietary wireless architecture, or a specific regulated-industry workflow. None of these systems becomes compliant by model name alone. The configured system, calibration evidence, mapping, SOPs, contracts, validation, training, and quality decisions form the compliance case.

    12.Official Reference

    1. Guidelines of 5 November 2013 on Good Distribution Practice of medicinal products for human use (2013/C 343/01) — European Commission / EUR-Lex. Official source Primary source for EU/EEA wholesale distribution, mapping, calibration, alarms, computerised systems, documentation, outsourced activities, transport, and CAPA.
    2. EudraLex Volume 1 — current listing of EU pharmaceutical legislation and guidelines — European Commission. Official source Confirms the current official listing of 2013/C 343/01.
    3. TRS 961, Annex 9: Model guidance for the storage and transport of time- and temperature-sensitive pharmaceutical products — World Health Organization. Official source Global TTSPP implementation context; local law remains controlling.
    4. TRS 992, Annex 5: Technical supplements to the WHO TTSPP model guidance — World Health Organization. Official source Technical support for mapping, qualification, monitoring, calibration, transport, and facility design.
    5. Cold chain equipment and dry store temperature mapping tool — World Health Organization. Official source Current WHO mapping resource and implementation tool.
    6. Temperature mapping — an introduction — MHRA Inspectorate. Official source Inspection-oriented explanation of GDP Chapter 3.2.1; UK context only.
    7. GS1-AETH1RS specifications and product information — UbiBot. Official source Official product data for connectivity, sensors, display, local memory, power, and external probes.
    8. GS1-A1RS specifications — UbiBot. Official source Official product data for the Wi-Fi-only GS1 configuration.
    9. WS4-P4G1RS product information — UbiBot. Official source Official product data for 4G, GNSS, RS485 support, local memory, and transport-oriented use.
    10. Public Cloud Pricing and On-Premises Platform — UbiBot. Official source Official platform architecture, subscription, API, and deployment options.

    13.Sources and Product Information Disclaimer

    This article is provided for informational and editorial purposes and does not constitute legal, regulatory, validation, quality, or engineering advice. EU GDP compliance depends on the authorised activity, applicable national law, medicinal-product requirements, competent-authority expectations, quality agreements, validated procedures, and the configured monitoring system. Product specifications, software functions, licences, calibration services, network support, and vendor compliance claims may vary by model, region, software version, probe, and contract. Verify current official documentation and obtain approval from qualified QA/RA and legal personnel before implementation.

    分享

    LinkedIn2

    Facebook2

    X

    Newsletter Signup

    Related Resources

    No related resources found

    menu-header-svg
    Search
    • Explore Knowledge
      • Comparison & Selection
      • Industry Solution
      • Product & Device
      • Criterion & Compliance
      • Deployment & Usage
      • Technology & Principle
    • Academic Research
    • In-depth Tech
    Enter Your Information

    Confirm

    Products

    Dashboards

    Support

    Purchase

    Company

    Smart Sensing

    UbiBot Web Console

    APP Download

    UbiBot Online Store

    News

    Smart Control

    UbiBot Space

    Product Docs & APIs

    Find Distributors

    About Us

    Smart Video

    UbiBot On-Premises

    Helpdesk & FAQ

    Volume Pricing

    Contact Us

    LoRa Products

    Agency Web Console

    Video Center

    Architecture

    Software & Platform

     

    Pricing

     

    System Status

    External Sensors

       

    Become a Distributor

    Accessories

       

    Become an Affiliate

    Global SIM

         

    Positioning System

         

    Products

    Dashboards

    Business Partners

    WS1

    UbiBot Web Console

    Volume Pricing

    WS1 Pro

    UbiBot Space

    Become a Distributor

    GS1

    UbiBot Support Desk

    Affiliates

    GS2

    Agency Web Console

     

    MS1

     

    SP1

     

    Accessories

     
       

    Docs

    Purchase

    Company

    Platform API

    Pricing

    News

    Q&A

    UbiBot Partners

    About us

    Privacy Policy

    Online Store

    Contact

    Terms of Service

     

    System Status

    Products

    Dashboards

    Smart Sensing

    UbiBot Web Console

    Smart Control

    UbiBot Space

    Smart Video

    UbiBot On-Premises

    LoRa Products

    Agency Web Console

    Software & Platform

     

    External Sensors

     

    Accessories

     

    Global SIM

     

    Positioning System

     
     

    Support

    Purchase

    APP Download

    UbiBot Online Store

    Product Docs & APIs

    Find Distributors

    Helpdesk & FAQ

    Volume Pricing

    Video Center

     

    Pricing

     
     

    Company

    News

    About Us

    Contact Us

    Architecture

    System Status

    Become a Distributor

    Become an Affiliate

    Language:
    English 日本語 (ベータ)  
    Language:

    English

    日本語 (ベータ)



    IoT Product Family:
    ubibotico     Wireless environmental sensing products and smart building solutions
    ubitrackico     UWB-based real-time indoor tracking solutions with 30cm accuracy

    IoT Product Family:

    ubibotico  Wireless environmental sensing products and smart building solutions
    ubitrackico  UWB-based real-time indoor tracking solutions with 30cm accuracy

    © 2013-2026 UbiBot.com. All rights reserved.

    Terms of Service | Privacy Policy | Compliance

    youtube facebook twitter