For the head of brand, DTC and consumer insights at a co-manufactured mid-market CPG — the person the 2D barcode decision lands on as an artwork line item, and who has never had a first-party line to the consumer of a single unit.

You can tell the board what the category did last quarter. You cannot tell them one true thing about the person who opened your box this morning. Your view of your own customer is a syndicated panel, resold back to you eight weeks late at category grain, plus whatever your Shopify sliver says about the 3% who buy direct. That is not a supply-chain problem. It is a customer-blindness problem — and it is about to be solvable by an artifact you are already being forced to print.

Here is the whole of it in one line, and every clause survives a check by someone who knows GS1 cold:

A 1D UPC is a checkout token: it talks to someone else's POS and tells you nothing. If you print a QR carrying a GS1 Digital Link URI, the same square that clears the lane resolves in your customer's phone camera — and which mark you print is your decision as the GTIN owner, not your co-man's and not Sunrise's. Whether shoppers scan it at volume is a bet, not a fact — and every open gap on our side is a named entry in the open P0 ledger, where we will tell you the truth about it.


What is a GS1 Digital Link, and why is my retailer asking me to be "2D-ready"?

Your retailer is asking because of GS1 Sunrise 2027 — GS1's own programme, not our forecast and not a law. It expects retail point-of-sale to scan and process 2D barcodes and extract the GTIN by the end of December 2027. That is the whole of the baseline: the GTIN. Lot and expiry are optional additional AIs you may choose to encode; nothing in Sunrise obliges them.

A GS1 Digital Link is a way of writing the same product identity as a web-resolvable URI instead of the old element-string syntax. That distinction is the one to hold onto, because it is exactly where "2D-ready" gets muddled:

  • A 2D symbol carrying GS1 element strings (FNC1 syntax) is not a URI. Put it in a browser and it resolves to nothing. It clears a lane; it is not a link.
  • A 2D symbol carrying a GS1 Digital Link URI is web-resolvable. That is the form that can behave like an address.

And the sentence to strike from every deck you are shown: Sunrise 2027 puts nothing on your pack. You do, if you choose. The programme sets what the lane must read; it does not print your artwork. The symbology and the URI form are decided by the party that owns the GTIN — you.

(One correction your agency or your GS1 contact will make if we get it wrong, so we will make it first: the schema.org property hasGS1DigitalLink is pending, not core, and it is not new — it has shipped since schema.org v27.0.)

Can the QR code on my product tell me who my customers actually are?

This is the reframe the whole page turns on, and it has two halves that must never be blurred.

The half that is true today, and you can check it without us. A 1D barcode was never consumer-scannable — it is a lane token for a fixed scanner. A QR carrying a GS1 Digital Link URI resolves in an ordinary phone camera. So the same square you are being told to print for compliance is, in changing form, the first artifact of yours that a shopper's own device can read. That changes the mark from a checkout token into something that can carry an address. This is GS1's published design; it is not a claim about a product of ours.

The half that is a bet — and we are asking you to shoot it down. We think that once your pack carries a mark a phone can read, most scans of your product happen off your properties, by people who do not work for you — and that the pattern of those scans is a new first-party signal class: which SKUs got scanned, in which markets, how many times, how long after they shipped. Repeat scans on the same GTIN in the same market look like repeat rate. First scans in a market you do not sell into look like diversion. A promo week with no scan lift looks like a promo that did not run — from your own pack, not resold back to you by a panel weeks later.

We have no evidence for that, and neither does anyone else. It is a hypothesis, not a finding — the single question this whole exercise exists to test. If you tell us shoppers will never scan at volume in your category, that is the most useful thing that can happen today. What we will not do is dress the bet up as data.

What's the difference between a QR code and a DataMatrix on my packaging?

The easiest thing to get caught being wrong about, so here it is flat:

QR codeGS1 DataMatrix
Clears the lane at POSYes (Sunrise-capable)Yes (Sunrise-capable)
Reliably read by a native phone cameraYesNo — not reliably decoded by native camera apps
Where it fitsThe consumer-scannable symbologyThe lane and pharma symbology (space-efficient, regulated)

Both satisfy a Sunrise-ready lane. Only the QR reliably does the second job — resolving in the shopper's phone. So if the customer-facing option matters to you at all, the symbology choice is not neutral, and it is yours to make. Anyone who writes "a DataMatrix or QR is scannable by a consumer's phone" has just told you they are not the person to make this decision for you.

How do CPG brands get first-party consumer data without a big DTC business?

Today, mostly, they don't — and that is the trap this ICP is in. Your entire first-party view is the DTC sliver plus a retail-media account you rent. Everyone else is a stranger you buy back as a panel estimate.

The structural reason there is no record of your own customers is worth stating plainly, because it is the same reason your co-man trace-backs turn into archaeology. The event standard the industry runs on has no place for a performer. EPCIS 2.0 §7.2.2 defines five event dimensions — what, when, where, why, how — and its Who is a company. The party fields (EPCIS §7.3.6.4, CBV 2.0 §8.7.1, PGLN) are organisation-grain: they record that a company did a process, never which worker or which system observed the case at 06:12. No field names the performer. So when a lot goes wrong at a co-packer you don't own, "which stores, which shelves, on whose authority" is reconstructed by phone across a boundary where the data is contractually someone else's.

The 2D mark and the missing Who are the same opportunity seen from two ends. One end is your customer; the other is your custody. Both are answered by making the record carry a who it structurally cannot carry today:

  • who — the attested observer of an event: a human, an agent, or an embodied agent/robot.
  • capturedBy — the warrantor account that stands behind the record.

Party and organisation grain are derived at read time from grant chains, never stamped — so a co-man handoff survives a reorg and a revocation, and you can hold a co-manufacturer accountable without owning the plant.

The honest limit, to your face: we do not deliver consumer-scan analytics, and no claim of customers or adoption appears anywhere on this site. What exists is the record layer — translate, validate, hash — live at epcis.dev, one curl each. The consumer-signal product is not on any build path here, and we say so every time. If you want it, you are joining a seat list, not a pipeline. We would rather lose you here than have you catch us overselling in the next meeting.

What do I have to decide during my next artwork cycle for the 2D barcode?

The artwork cycle is the decision point, and it is your cycle — which is exactly why the Sunrise mark lands on your desk as a design change with an unexpected data consequence. Four decisions, all yours as GTIN owner:

  1. Symbology — QR (phone-readable) vs GS1 DataMatrix (lane/pharma). Choose in a pure compliance frame and you will likely default to a mark no shopper can read.
  2. URI form — a GS1 Digital Link URI (web-resolvable) vs element strings (not a link). Only the URI form can ever be a touchpoint.
  3. Which AIs travel — GTIN is the Sunrise baseline; lot and expiry are yours to add if the custody or freshness case justifies them.
  4. Where the events behind the mark are recorded, and by whom — the one decision no artwork brief contains, and the one that determines whether the mark is a dead square or a signal instrument.

The one thing you might regret: the square prints either way. Decide it as a line item and you will have printed a touchpoint and left it switched off — while a competitor who treated the same square as a signal instrument three years from now knows its customers by lot and by market, and you are still buying panel data.


The two clocks — neither of them ours, and used in one direction only

Lead with the business case, not the deadline. The reason to act is that the artwork cycle is a rare, cheap window to turn a compliance artifact into a customer signal and to fix the co-man trace-back at the same time. The dates are the floor under that, not the reason for it.

  • GS1 Sunrise 2027 supplies timing: retail POS expected to scan and process 2D and extract the GTIN by end of December 2027. GS1's programme. [A5]
  • FSMA 204 supplies a de-risking floor, never urgency. The date moved from January 20 2026 toward July 20 2028; the extension was never finalised as a rule — the 2028 date rests on the Continuing Appropriations Act of 2026 directing FDA not to enforce before then — and FDA is soliciting further flexibilities (Federal Register, 2026-05-28). Direction of travel is softening. Anyone selling you 2028 as a gun to your head is one search away from being caught. [A7]

What welded this together at exactly the wrong grain for you: schema.org v30.0 (2026-03-19) added formal GS1 equivalence annotations — 1 owl:equivalentClass (gs1:Organizationschema:Organization) and 15 owl:equivalentProperty annotations. The physical and digital vocabularies are now welded at the grain of a company — which is the grain above the one that is missing. The company is answered; the unit, the lot, the observer are not. [A6]

An honesty note we owe you: none of the widely cited traceability case studies — the McDonald's / Golden State Foods RFID pilot, Chipotle's national RFID rollout, McDonald's China's efficiency numbers — is a mid-market CPG artifact. They are QSR and QSR-supply. We will not borrow their scale to imply yours. The checkable evidence under this page is GS1's own published Sunrise 2027 programme and Digital Link design, and schema.org's v30.0 annotations. The consumer-signal thesis has no authority reference at all, because there is none — it is the bet.


For the person who forwards this — two blocks, on purpose

The executive gift (bring it to any vendor meeting)

EPCIS 2.0 §7.2.2 defines five event dimensions — what, when, where, why, how — and no performer among them. Party fields are organisation-grain (EPCIS §7.3.6.4 · CBV 2.0 §8.7.1, PGLN). So the standard the whole industry runs on records that a company did a process; it cannot record which person or which device made the observation. That is a structural gap — the Who it has stops at the company's GLN, and no field names the performer — which is why a co-man trace-back is archaeology and why your own customer never appears in your own record. §7.2.2 · §8.7.1 — ten minutes, the specs are public, don't take our word for it.

The engineering ledger (for whoever you forward it to)

A different reader needs a different proof. The record layer is real code, tested against real fixtures: EPCIS 1.1 / 1.2 / 2.0 XML translated to EPCIS 2.0 JSON-LD with a per-job round-trip fidelity report; every event validated against the pinned official GS1 EPCIS 2.0 JSON schema, provenance recorded in a sha256 PINS.json (EPCIS 2.0.1 pinned); the CBV 2.0 §8.9 event hash gated against OpenEPCIS reference vectors; errors as RFC 7807 application/problem+json. Live today: POST https://epcis.dev/translate, /validate and /hash — 683/683 spine tests pass. Recording an event never costs money — policy, stated ahead of published terms (policy — §0.13).


Put me on the seat list

You asked whether the mark on your own pack could be a first-party signal. That analytics product is not on any build path here, and we say so to your face. What the seat list provisions is the record layer under that signal — a capture workspace, in order. If the analytics picture ever changes you get one message; if we decide against it you get one message saying so.

Your capture workspace is provisioned from this list, in order. One email when your seat is ready — one, not a drip campaign. Nothing else, ever — no newsletter, no sequence. If we stop working on this, you get one message saying so and your address is deleted. Either way it is one message. The named human sender and the verified sending address are a launch gate — P0-V4 in the open P0 ledger; the message is not sent until both exist.

(Said plainly: the capture endpoint is not the consumer-signal capability. It is the one event we can honestly promise to tell you about, and it is a different thing from the thing you asked about.)

Get the written read for your situation → /get-started (The branching interview is live on this origin: your address first under the one-message promise, then questions that branch on your answers — branch M serves exactly this situation — ending in a written read that locks. No demo, no call, no script required.)

Or just: put me on the seat list → /first-trace?segment=manufacturer (Pick "Manufacturer or brand — you pack it out and you own the GTIN." One address in. No reply-to-book-time, no scheduling link.)

Two optional questions sit beside the field, both about the past — no rating scale, no "would you use this":

  1. The last time you wanted to know how a product actually performed in a market — what did you open first, and what did it cost you a year?
  2. The last time a co-packer had a quality issue — how did you find out, and how long from finding out to knowing which lots?

We answer in writing. We take at most five conversations a month, only when you ask for one, and only after you already have the written read.

Verified, plainly: the interactive interview is live at /get-started — branch M (midmarket-cpg-consumer-signal) is this pillar's own door, and the whole instrument is machine-readable at /flow.json. The seat list stores your row today; the named human sender and the verified sending address are a launch gate, P0-V4 in the open P0 ledger, stated here rather than papered over.

The same spine, from the developer side: epcis.dev — build the part that is yours; the standards layer is a pinned dependency. · The honest ledger: what ships today.