EC

European Commission — EudraLex

European UnionEuropeNational / regional regulator

Publisher of EudraLex Volume 4 (EU GMP Guide and its Annexes) and the EU GDP Guidelines.

What this page does not claim

SPEQ curates and cross-references these bodies. It is not affiliated with, accredited by, or endorsed by any of them, and a count of decoded standards is a measure of SPEQ’s coverage, not of a body’s importance.

WHAT EC COVERS

The European Commission is the EU’s executive and the source of the binding legal framework for medicines — Directive 2001/83/EC for human medicines, Directive 2001/82/EC and Regulation (EU) 2019/6 for veterinary, and Regulation (EC) No 726/2004 establishing the centralised procedure. It adopts the GMP guidelines that member-state inspectorates enforce and takes the legal decisions on centralised marketing authorisations.

WHAT EC PUBLISHES

  1. 01EudraLex Volume 4 — the EU GMP Guide, Parts I–III and the Annexes (Annex 1 sterile, Annex 11 computerised systems, Annex 15 qualification and validation, Annex 16 QP certification)
  2. 02EU Good Distribution Practice guidelines (2013/C 343/01)
  3. 03Directives and Regulations forming the pharmaceutical acquis
  4. 04Commission Implementing Regulations — including (EU) No 520/2012 on pharmacovigilance
  5. 05The Notice to Applicants and other procedural guidance

HOW ITS REQUIREMENTS BITE

The Commission legislates rather than inspects. Its instruments take effect through member states: a Regulation applies directly across the Union, while a Directive is transposed into national law. GMP and GDP guidelines published in EudraLex Volume 4 are then applied by the national competent authorities during inspection, which is why the enforcement you experience is national even though the requirement is European.

What practitioners get wrong

  • The GMP Annexes carry most of the operational detail — Annex 1 (2022) reshaped sterile manufacturing expectations.
  • A Regulation applies directly; a Directive must be transposed, so national implementations can differ in detail and timing.
  • EudraLex Volume 4 Part III holds the ICH texts (Q9, Q10) as adopted EU documents.
  • Do not conflate the Commission (legislator), EMA (scientific coordination), and national authorities (inspection).

WHERE IT SITS INTERNATIONALLY

The EU framework is the reference for PIC/S PE 009, which mirrors the EU GMP Guide closely, and adopts ICH guidelines into EudraLex. That triangle is why a site built to EU GMP is broadly aligned across most of the world.

EC STANDARDS SPEQ DECODES · 16

DISCIPLINES IN EC’S REMIT

TOPIC EXPLAINERS CITING EC STANDARDS
Software as a Medical Device (SaMD)
Software that is itself a medical device — the IMDRF definition, IEC 62304 lifecycle, ISO 14971 risk, EU MDR Rule 11, and how AI/ML changes the picture.
GLP Study Conduct: Study Director & QAU
What Good Laboratory Practice actually governs — the organisation, roles, and records that make a non-clinical safety study trustworthy and reconstructable, not the quality of its science.
Cold Chain & Temperature Control in Distribution
How Good Distribution Practice keeps a medicine within its qualified temperature range from the factory to the patient — mapping, the qualified cold chain, and what an excursion actually means.
Serialization & Falsified Medicines
How a unique identifier on every saleable pack, plus tamper-evidence and interoperable verification, keeps falsified product out of the legitimate supply chain — and why regulators specify the outcome while GS1 specifies the syntax.
Complaint Handling & Device Vigilance
Every complaint is not a reportable event, and every reportable event is not a recall — the three decisions a device maker must keep distinct, and why under-reporting is a classic finding.
Biocompatibility (ISO 10993)
Biocompatibility is not a checklist of tests to run — ISO 10993-1 reframed it as a risk-based evaluation, and testing is what you do only where existing data leaves a gap.
Clinical Evaluation & the CER
The clinical evidence that a device is safe and performs — why the how-to guidance and the legal requirement come from two different documents, and why the CER is never "done".
EU MDR & IVDR Transition Timelines
The extended MDR (2023/607) and IVDR (2024/1860) transition deadlines by device class — and the conditions to keep legacy devices on the market.
Temperature Excursion Management
Handling a temperature excursion in distribution — stability-budget assessment, quarantine, and the release-or-reject decision.
Transport Qualification in GDP
Qualifying shipping lanes, packaging, and vehicles so medicines stay in condition from dispatch to delivery.
Returns & Recalls in Distribution
How distributors handle returned medicines, execute recalls, and keep falsified product out of the legitimate supply chain.
Human Factors and Usability Engineering (IEC 62366-1)
The engineering discipline, and the standard behind it, for designing medical devices so that intended users can operate them safely and effectively.
Medical Device Cybersecurity
The engineering and regulatory discipline for securing connected medical devices against cyber threats across their design, submission, and post-market lifecycle.
Design Verification vs. Design Validation
The two distinct, commonly confused design-control activities that confirm a device was built right, and that the right device was built.
Post-Market Surveillance for Medical Devices
The proactive, systematic collection and analysis of real-world device performance data that a manufacturer runs for as long as the device is on the market.
MDR Vigilance Reporting
The threshold-triggered obligation to report device-related serious incidents and field safety corrective actions to regulators within defined timelines.
Regulatory Classification & Pathway Strategy
What the product legally is in each market, which authorisation route follows, and why the rationale has to be written down.
Health-Authority Engagement
Meetings, scientific advice, questions and responses — and why every undertaking given becomes a commitment the organisation is held to.
Regulatory Submission Strategy & Planning
The CTD, the eCTD, and how a dossier plan built on dependencies rather than document counts survives contact with a filing date.
Establishment Registration & Licensing
The permissions the business actually runs on — registrations, manufacturing and wholesale licences, importer roles — and why they lapse quietly.
Labelling, Artwork & Promotional Compliance
Approved labelling and its translations, artwork under change control, and the boundary between an authorised claim and promotion.
Regulatory Policy & Standards Engagement
Engaging with regulation while it is still being written — consultations, standards development, harmonisation — and routing what you learn back inside.
Cybersecurity Governance in Regulated Organisations
Who owns cyber risk, what residual risk the business has actually accepted, and how an ISMS meets a pharmaceutical quality system.
Data Privacy & Protection in GxP Environments
Where GDPR meets GxP record-keeping — the retention-versus-erasure conflict, health data as a special category, and encryption that survives an audit trail.
Network, Cloud & Endpoint Security for GxP Systems
Segmentation as the control that stops an ordinary compromise becoming a production outage — plus cloud responsibility and endpoints that cannot be touched.
Third-Party Cyber Risk in Regulated Supply
Suppliers hold credentials into the estate and copies of regulated data — and concentration is the risk that appears on nobody’s register.
Safety Governance & Benefit-Risk
Benefit-risk changes as evidence accumulates — and where safety governance reports into commercial ownership, the structure itself is a finding.
Postauthorisation Studies & Real-World Evidence
Real-world data were collected for another purpose — whether they can support the question is a judgement that must be made explicitly.
Medical Information & Inquiry Handling
A high-volume front door through which adverse events and complaints arrive disguised as questions.
Safety Systems & Partner Data Exchange
Every exchange with a partner is a place a case can be delayed or lost — and reconciliation only works if it is periodic and two-way.
Materials, Components & Packaging Controls
A specification that omits an attribute the process depends on will be met by material that does not work — and the supplier will be right.
Shortage Prevention & Supply Continuity
Most shortages trace to a single site or upstream supplier — which makes them foreseeable from the network map long before they occur.
Platforms, Cloud & Infrastructure for GxP
Moving to a managed platform moves the work, not the accountability.
Protect vs Disclose — The Trade-Secret Seam
One obligation requires the method and the data behind a regulated product to be written down and filed; another says their commercial value is that they are not. Where the two meet, and which disclosure bites hardest.

EC: frequently asked questions

Reference answers on European Commission — EudraLex’s mandate, what it publishes, and how its requirements acquire force.

What is EudraLex Volume 4?

EudraLex Volume 4 is the EU GMP Guide, published by the European Commission — Parts I–III and the Annexes, including Annex 1 (sterile), Annex 11 (computerised systems), Annex 15 (qualification and validation), and Annex 16 (QP certification). National competent authorities apply it during inspection.

What is the difference between an EU Regulation and a Directive?

A Regulation applies directly across the Union, while a Directive must be transposed into national law by each member state — so national implementations can differ in detail and timing. The Commission legislates; enforcement is carried out nationally.

Does the European Commission inspect sites?

No. The Commission legislates rather than inspects. It adopts the GMP guidelines that member-state inspectorates enforce and takes the legal decisions on centralised marketing authorisations. Do not conflate the Commission (legislator), EMA (scientific coordination), and national authorities (inspection).