Back to blog

Supply Chain Due Diligence Rules: The Data Apparel Brands Must Hold

Supply Chain Due Diligence Rules: The Data Apparel Brands Must Hold

Two EU legislative instruments now impose concrete, auditable data obligations on apparel brands operating in or selling into the European market. The Corporate Sustainability Due Diligence Directive (CSDDD) requires companies to map and monitor adverse impacts across their chains of activities. The EU Forced Labour Regulation enables authorities to ban products from the single market if supply chain evidence cannot rebut a forced labour finding. Together, they define a minimum data architecture that most existing PLM and sourcing systems do not yet satisfy.

Key takeaways

  • Both CSDDD and the Forced Labour Regulation require structured, tier-resolved supplier records — not just first-tier vendor lists.
  • The Forced Labour Regulation guidelines specify named data fields: legal name, trade name, contact details, unique identification number, and EORI number where available.
  • CSDDD, as amended by the Omnibus I simplification initiative, allows companies to prioritise areas where impacts are most likely and most severe — but that risk-based focus still requires evidence of how the prioritisation was made.
  • Most PLM systems capture product data well but hold shallow supplier records; sourcing platforms hold supplier contacts but rarely map sub-tier relationships or ownership structures.
  • Brands that cannot produce this data on request face product withdrawal, border interception, and reputational exposure.

What are the two regimes and how do they interact?

The CSDDD (Directive 2024/1760) entered into force in July 2024 and has since been amended by the Omnibus I package, which includes Directive (EU) 2025/794 and Directive (EU) 2026/470. Under the amended framework, Member States must adopt national transposition measures by 26 July 2028 and apply them from 26 July 2029. Companies in scope must identify and address actual and potential adverse human rights and environmental impacts in their own operations, those of their subsidiaries, and across their chains of activities.

The EU Forced Labour Regulation operates on a different enforcement mechanism. Approved by the European Parliament in April 2024, it enables Member State authorities and the European Commission to investigate goods, supply chains, and manufacturers. If a product is found to have been made using forced labour, it cannot be sold on the EU market — including online — and shipments are intercepted at the border.

The two instruments are not duplicative. CSDDD is a corporate governance obligation: it requires a process, a policy, a monitoring mechanism, and public communication. The Forced Labour Regulation is a product-market rule: it operates on the goods themselves and can be triggered by a third-party complaint or a Commission initiative investigation. A brand can be compliant with its CSDDD process and still have a product detained under the Forced Labour Regulation if it cannot produce adequate supply chain evidence during an investigation.

What data fields does the Forced Labour Regulation actually require?

The Commission Notice providing guidelines on the application of Regulation (EU) 2024/3015 is the most operationally specific document available. Published in June 2026, it sets out that economic operators should be able to provide:

  • A description of the supply chain covering key stages of production, manufacturing, or mining
  • A list of manufacturers, producers, and suppliers with regard to key production steps, including for each: legal name, trade name or registered trademark, contact details, unique identification number in the country of establishment, and — where available — their Economic Operators Registration and Identification (EORI) number
  • Supply chain maps covering tiers and sub-tiers, showing both direct and indirect suppliers
  • Information on ownership structures and relationships between entities in the chain

This is a structured data requirement, not a narrative one. Each field maps to a database column. The EORI number in particular is a customs-system identifier; its presence or absence signals whether a supplier has been formally registered for cross-border trade within the EU framework.

How does CSDDD define the scope of the chain?

The CSDDD uses the concept of 'chain of activities', which extends upstream to the sourcing of raw materials and downstream to distribution, but stops before the end consumer. For an apparel brand, this typically means:

  • Tier 1: Cut-make-trim (CMT) factories and finished goods manufacturers
  • Tier 2: Fabric mills, yarn spinners, and accessory suppliers
  • Tier 3 and beyond: Raw fibre producers, dyehouses, chemical input suppliers

The Omnibus I amendments allow companies to focus their due diligence on areas where adverse impacts are most likely and most severe, based on reasonably available information. This is a meaningful concession for brands with complex multi-country supply chains. However, it introduces a secondary data obligation: you must be able to demonstrate how you assessed likelihood and severity, which requires at minimum a documented risk-mapping exercise with evidence of the inputs used.

In practice, brands that have invested in supplier auditing at Tier 1 but have no structured data beyond that face a specific gap: they can show process compliance at the level they can see, but cannot demonstrate a reasoned basis for stopping there unless they have recorded why deeper tiers were assessed as lower risk.

Where do current PLM and sourcing systems fall short?

Most enterprise PLM platforms are designed around the product, not the supply chain entity. They hold bill of materials (BOM) data, tech pack specifications, sample approval workflows, and costing sheets. Supplier records in these systems typically amount to a vendor code, a contact name, and a country of origin — the minimum needed to place a purchase order, not the minimum needed to satisfy a regulatory investigation.

Sourcing platforms and supplier relationship management tools go further: they often hold audit certificates, factory assessments, and capacity data. But they rarely capture sub-tier relationships. A brand may know its CMT factory in detail and have nothing structured about where that factory sources its fabric.

The specific gaps that emerge when mapping current system capabilities against the regulatory data requirements include:

Unique identification numbers. Most sourcing systems store a vendor code assigned internally. The regulatory requirement is for the supplier's own unique identification number in its country of establishment — a company registration number, tax identification number, or equivalent. These are different fields and are rarely collected systematically.

EORI numbers. These are held by customs brokers and freight forwarders, not typically by sourcing or PLM teams. Retrieving them requires either a data-sharing arrangement with logistics partners or a direct collection exercise with suppliers.

Sub-tier mapping. Tier 2 and Tier 3 supplier data is almost never held in structured form in PLM or sourcing systems. It exists, if at all, in audit reports as narrative text or in spreadsheets maintained by sustainability teams outside the core systems.

Ownership structures. Knowing that a factory is owned by a holding company with operations in a high-risk jurisdiction is exactly the kind of information the guidelines reference. This is not product data; it is corporate intelligence, and it requires a different collection and verification process.

Supply chain maps. The requirement for visual or structured maps showing tiers and sub-tiers is not a standard output of any PLM system. Generating one requires integrating supplier data with a mapping or graph tool.

What does a compliant data architecture look like?

Building toward compliance involves three layers that most brands will need to develop in sequence.

Layer 1 — Structured supplier master. Every entity in the supply chain that touches a key production step should have a record containing the legally required fields: legal name, trade name, contact details, country-of-establishment identifier, and EORI where applicable. This is a data collection and governance problem before it is a technology problem. Brands typically need to run a supplier data remediation exercise to populate these fields, because the data was never collected at onboarding.

Layer 2 — Tier mapping. Direct suppliers should be contractually required to disclose their own key suppliers, at least one tier down. This is increasingly standard in responsible sourcing programmes but is rarely enforced with the structured data discipline the regulation now requires. The output should be a graph of entities and relationships, not a spreadsheet of factory names.

Layer 3 — Risk evidence. For brands relying on the Omnibus I risk-based focus, the prioritisation decisions must be documented. Which tiers, geographies, or material categories were assessed as lower risk? On what basis? This evidence layer is what converts a good-faith compliance posture into a defensible one during an investigation.

What are the enforcement mechanics brands should understand?

Under the Forced Labour Regulation, investigations can be initiated by the Commission or by Member State competent authorities. The process includes a preliminary phase in which the investigating authority assesses whether there is a substantiated concern. If it proceeds to an investigation, economic operators — which includes both manufacturers and importers — are required to provide information and access.

The consequence of a finding is not a fine in the first instance: it is a withdrawal order for products already on the market and a prohibition on placing further products. For a seasonal apparel business, a border interception or a market withdrawal order mid-season is operationally catastrophic in ways that a financial penalty is not.

This enforcement structure means the data readiness question is not abstract. An operator that can produce a complete, structured supplier file quickly — with named entities, identification numbers, and a tier map — is in a materially different position during an investigation than one that must reconstruct the information from emails and audit PDFs.

How are major European fashion operators approaching this?

Zalando operates across 29 markets and connects brands with tens of millions of active customers. As a marketplace and platform operator, it sits at the intersection of the brand and the end consumer, and its supplier data obligations extend to the brands it hosts as well as its own private label operations. Platform operators of this scale face a specific challenge: the data quality of their supply chain compliance posture depends partly on the data quality of thousands of third-party brand partners.

Otto Group operates a diversified retail and services conglomerate spanning e-commerce, logistics, and financial services, with active investment in AI-commerce capabilities across its retail brands. For a group of this structure, supply chain data governance is a cross-entity problem: different brands within the group may have different supplier bases, different legacy systems, and different levels of data maturity.

Both organisations illustrate a pattern visible across large European fashion operators: the compliance obligation is clear, but the data infrastructure to meet it is distributed across systems, teams, and legal entities that were not designed to interoperate for this purpose.

What is still unresolved?

Several questions remain open as the regulatory framework matures.

The definition of 'key production steps' is not exhaustively specified in the guidelines. For a garment, it is reasonable to include cutting, sewing, and finishing. Whether yarn spinning or raw fibre production constitutes a 'key step' for every product category, or only for those assessed as high-risk, is a question that enforcement practice will eventually answer.

The standard of evidence for sub-tier claims is unclear. The guidelines describe what information should be held; they do not specify what verification is required. A brand that holds a supplier-provided declaration of its own sub-suppliers is in a different evidential position than one that has independently verified those relationships. The gap between self-declaration and verified data is where enforcement risk concentrates.

Interoperability with Digital Product Passport requirements is not yet resolved. The DPP framework, which is being developed under the Ecodesign for Sustainable Products Regulation, will require product-level data to be machine-readable and accessible. The supply chain entity data required under due diligence rules and the product-level data required under DPP overlap but are not identical, and the data models have not been formally aligned.

SME applicability thresholds will affect how much supply chain transparency brands can realistically demand from smaller suppliers, many of whom will themselves be below the CSDDD scope threshold and may have limited capacity to produce structured data.

FAQ

What is the CSDDD and which apparel companies does it cover? The Corporate Sustainability Due Diligence Directive requires companies above certain size thresholds to identify and address adverse human rights and environmental impacts across their chains of activities. Member States must apply the rules from 26 July 2029. Thresholds and phase-in timing mean larger groups are in scope first, but supply chain data demands will cascade to smaller suppliers through contractual requirements.

What is the EU Forced Labour Regulation and how is it enforced? It is a product-market rule that enables the Commission and Member State authorities to ban goods made with forced labour from the EU single market, including online sales, and to intercept shipments at the border. Investigations can be triggered by complaints or on the authorities' own initiative; operators must provide supply chain information on request.

What specific data fields does the Forced Labour Regulation require brands to hold? The Commission guidelines specify: legal name, trade name or registered trademark, contact details, unique identification number in the country of establishment, and EORI number where available — for each manufacturer, producer, and supplier involved in key production steps, across all tiers.

Do brands need full Tier 3 and Tier 4 supplier data? Not necessarily for every product. The CSDDD Omnibus I amendments allow a risk-based focus on areas where impacts are most likely and most severe. However, brands must document the basis for that prioritisation, which itself requires structured risk data. For high-risk materials or geographies, deeper tier mapping is effectively required.

Where do PLM systems typically fall short for compliance purposes? Most PLM systems hold product-centric data — BOMs, tech packs, costing — with shallow supplier records. They rarely capture country-of-establishment identifiers, EORI numbers, sub-tier relationships, or ownership structures. Compliance-grade supplier data typically requires a separate data collection and governance programme.

What happens if a brand cannot produce the required supply chain data during an investigation? Under the Forced Labour Regulation, the consequence is a withdrawal order for products already on the market and a prohibition on placing further products. There is no grace period for data reconstruction once an investigation is under way. Border interceptions can affect in-transit inventory mid-season.

How does the Digital Product Passport relate to supply chain due diligence data? The DPP, being developed under the Ecodesign for Sustainable Products Regulation, will require machine-readable product-level data. It overlaps with due diligence data requirements but uses a different data model. The two frameworks have not yet been formally aligned, and brands building compliance data architectures now should plan for eventual interoperability requirements.

Further reading

Share this article:

Supply Chain Due Diligence: Apparel Data Obligations