RxTrace readers are well aware that the deadline is this November 27 for applying unique serial numbers within GS1 DataMatrix 2D barcodes to prescription drugs distributed in the United States under the Drug Supply Chain Security Act (DSCSA).  Once that happens, most prescription drugs entering the U.S. supply chain will be identified by 14-digit GS1 Global Trade Item Numbers (GTIN-14) for the first time (see “Anatomy of a GTIN”).  That’s because, you can’t fit the drug’s National Drug Code (NDC) along with the serial number, lot number and expiration date into a data matrix barcode, as required by the law, without first encoding it into a GTIN-14 (see “Anatomy Of The National Drug Code”, and “Depicting An NDC Within A GTIN”).  This fact forces companies to encode their NDCs into GTIN-14s, many for the first time. Continue reading Sponsored: How To Properly Define GTINs For Your NDCs

Is A GS1 GTIN Really Usable As An NDC For DSCSA Compliance? Part 2

QuestionBottle.Part 2Part 1 of this essay provided a wealth of hyperlinks into the Code of Federal Regulations (CFR) and FDA guidance documents with content related to placing the National Drug Code in human- and machine-readable form onto drug packages prior to November 27, 2017 (see “Is A GS1 GTIN Really Usable As An NDC For DSCSA Compliance?  Part 1”).  In Part 2, we will look at how the Drug Supply Chain Security Act (DSCSA) will change, or add-to, the requirements found in those earlier specifications.  And finally, we will be able to answer the question in the essay title.


First of all, the DSCSA does not change anything

Is A GS1 GTIN Really Usable As An NDC For DSCSA Compliance? Part 1

QuestionBottleAfter November 27, 2017 the U.S. Drug Supply Chain Security Act (DSCSA) requires drug manufacturers (2018 for repackagers) to affix a DSCSA “product identifier” to all drug packages entering the supply chain (see “The DSCSA Product Identifier On Drug Packages”).  According to the DSCSA, that product identifier must be present in both human-readable and 2D Data Matrix barcode forms.  Part of that product identifier is what is known as a Standardized Numerical Identifier (SNI).  The SNI is composed of the drug’s National Drug Code (NDC) and a serial number (see “DSCSA ‘Serial Numbers’”) that is unique on every individual package of that drug (see “FDA Aligns with GS1 SGTIN For SNDC” and “Anatomy Of An FDA SNI”).

Lately, I've heard people in the industry claim that it is acceptable to use a GS1 Global Trade Item Number (GTIN) that encapsulates an NDC (see "Depicting An NDC Within A GTIN") to satisfy the NDC part of this DSCSA requirement to affix the product identifier on a drug package.  I'm not so sure about that.  Let me explain.

Use of GLN and GTIN for Pedigree Regulatory Compliance

I am fortunate to have so many friends and colleagues who work in end-user and solution provider companies and who are impacted by the issues I cover in my blog. After each post I often exchange emails and phone calls with some of them and we discuss/debate what I’ve written about. These are great conversations because they sometimes confirm my opinions and sometimes challenge them, but I almost always come away with a more refined understanding of the technology or regulation we discussed. That is, I learn something.

This is exactly what has been happening with my recent series on Supply Chain Master Data (SCMD). As I’ve defined it, SCMD is just like regular old Master Data (MD) except that the identifier and the full data set behind each instance of SCMD has a single owner, and all parties in the supply chain who may encounter the identifier must have a way of obtaining the full set of data from the owner so they know what the identifier means. But this assumes that only the identifier will be used in supply chain data communications in place of the full data set that the ID refers to.

GLN’s On Electronic Invoices

Let’s take GS1’s GLN (Global Location Number), for example. You can use GLN’s in two ways: as true SCMD, or in a non-SCMD way.

An example of using GLN’s as SCMD in an invoice application would result in an electronic invoice that did not have any explicit addresses in it–no customer billing address, no customer shipping address and no “remit payment to” address. Instead, it would simply include the customer’s billing GLN, the customer’s shipping GLN and the “remit payment to” GLN. Each party in this example would have already obtained the full addresses from their respective owners in some way, either through a registry (like GS1 U.S.’s GLN Registry for Healthcare), or directly from the owner, so there is no need to include that data on each invoice between these parties.

The non-SCMD use of GLN's occurs when a company uses a GLN identifier as a way of obtaining their trading partner's full address, and then they would put the full address on each of their invoices for that partner. This approach makes use of GLN's to "synchronize" the address master data that each trading partner keeps locally.

Pedigree Models and Supply Chain Master Data

Important Notice To Readers of This Essay On November 27, 2013, President Barack Obama signed the Drug Quality and Security Act of 2013 into law. That act has many provisions, but one is to pre-empt all existing and future state serialization and pedigree laws like those that previously existed in California and Florida. Some or all of the information contained in this essay is about some aspect of one or more of those state laws and so that information is now obsolete. It is left here only for historical purposes for those wishing to understand those old laws and the industry’s response to them.Right now there is only one industry standard that can be used to comply with the various drug pedigree laws in the United States. That’s the GS1 Drug Pedigree Messaging Standard (DPMS), which was created in 2006 by a group of technology experts and participants from nearly all segments of the U.S. supply chain culminating in GS1 ratification in January 2007. Many of those companies began using DPMS even before it was ratified because the Florida Pedigree Law went into effect in July 2006. Since then, companies are using it to comply with other state pedigree laws as well as for the pedigree provisions of the federal government’s Prescription Drug Marketing Act (PDMA) of 1988 (stayed until December 2006). Interestingly, a few companies have chosen to require DPMS pedigrees today for trading partner risk mitigation even where there is no existing regulatory requirement to do so.

A few months after GS1 ratified the DPMS standard, they ratified the Electronic Product Code Information Services (EPCIS) standard. This is a more general purpose standard intended for use in all supply chains that have a need to track and trace serialized products. Everyone acknowledges that it doesn’t make sense to try to use it for compliance with PDMA, Florida or other state pedigree laws because they do not require serialization, but in 2015 the California Pedigree Law will go into effect and one of its unique provisions requires item-level serialization.  Some see this as an ideal place to apply EPCIS.

There are lots of ways to contrast these two standards and their use for pedigree law compliance, but probably the most striking difference is how they each treat Supply Chain Master Data (SCMD). I defined SCMD in a previous post as “…that persistent, non-transactional data that defines a business entity for which there is, or should be, an agreed upon view across the supply chain.


Addresses are an example of a "business entity" that can be treated as SCMD. GS1 defines a location identifier they call a Global Location Number (GLN) that can be used to refer to an address. A GLN is a structured series of digits that can be assigned to refer to a single address (among other things). Refer to the GS1 General Specification for the details.

Master Data, Supply Chain Master Data and Instance Data

We need to make a clear distinction between traditional Master Data (MD), Supply Chain Master Data (SCMD), and Instance Data (IData). This will help us understand some important differences in various supply chain track and trace technologies.

Master Data

Wikipedia defines “Master Data” like this today:

“…Master Data is that persistent, non-transactional data that defines a business entity for which there is, or should be, an agreed upon view across the organization.”

This isn’t detailed enough for me. MD must include a data element that serves as an identifier. An identifier that refers to a given MD record must be unique within the organization.

Good candidates for MD are customer information, location information, product information and employee information. The characteristic these all have in common is that the data behind them rarely change. For example, I have been issued an employee number by my company. My employee number is the unique identifier for the MD that describes me to the company. My mailing address, phone number, marital status, social security number rarely change.

Most organizations make use of MD so that they can maintain the definition of these entities in a single place, and they can simply refer to these definitions through the corresponding unique identifier. The identifier provides a quick way to get to the full set of information. In many cases, the identifier can serve as a stand-in for the full set of information.

Supply Chain Master Data

Wikipedia doesn’t yet have a definition for Supply Chain Master Data. I’ve coined the term to describe something that is similar, but distinctly different than Master Data as described above. I’ll define it like this:

"Supply Chain Master Data is that persistent, non-transactional data that defines a business entity for which there is, or should be, an agreed upon view across the supply chain."


I’ve been an active GS1 participant since EPCglobal was first acquired by GS1 in 2003. It is an interesting organization, often both vital and frustrating at the same time. GS1 is a single source for essential supply chain standards that have global applicability. Rather than attempting to dictate those standards they invite people and companies to work with them on the definitions and the application of their standards. They have really great facilitators for some of their work groups with the very best being Mark Frey and Gena Morgan. The quality of their standards documents is quite high. And they have some really smart people in their EPCglobal Architectural Review Committee (ARC), notably Ken Traub, John Williams and Sanjay Sarma.

My hope is that this blog will be of some value to both members and non-members of GS1, but, I can only cover topics related to the organization and their public documents. Specific details about work group activities cannot be covered. However, I do not think that is too limiting and I think members and non-members will find something of interest.

GS1 is a not-for-profit member organization. The way it is organized reminds me of something out of the UN with affiliate “Member Organizations”, or M.O.’s—one for each country in the world—which participate in developing and maintaining their global standards on behalf of end-user companies within their borders. End-user companies are also able to represent themselves … if they can afford the membership fee which is based on company global revenue (and that’s on top of the fees paid for use of your GS1 Company Prefix). Consequently, standards development proceeds mostly with input from employees of GS1 affiliates and from employees of large corporations. There are notable exceptions and GS1 has made a significant effort to recruit participation from hospitals and smaller pharmacies, traditionally under-represented because they are small.

My own experience as one of those employees of an end-user member company, who has participated in standards-making work groups and the end-user groups within GS1 and EPCglobal, has been very positive. I have met and collaborated with a wide range of very smart people from my own industry and others, from the U.S. and from around the globe. I’ve learned a lot about supply chains in general and about how to perform the kind of “techno-negotiations” necessary to move forward a work group of people with very diverse backgrounds and interests toward a positive conclusion. Sometimes it’s thrilling. Sometimes it’s aggravating. It’s always a lot of hard work, but I highly recommend it to anyone considering it.

GS1 also runs “adoption” end-user groups out of their M.O.’s. The purpose of these groups is to encourage the adoption of GS1 standards within the country that the M.O. represents. For example, the GS1 U.S. Member Organization operates the GS1 Healthcare U.S. group which has work groups targeted at accelerating the adoption of GTIN, GLN, GDSN and Traceability the GS1 way in the healthcare sector. These work groups do not work on standards, but they work on guidelines for use in applying those standards to solve various supply chain problems within the U.S. (also known as “toolkits”).

Actual standards have traditionally been developed in two different sub-organizations of GS1: EPCglobal and GSMP (Global Standards Management Process). GS1 is currently in a state of transition as they move the standards development arm of EPCglobal into GSMP. That’s a good thing, because these two organizations have had different approaches and, at times, seemed to operate as two independent organizations. Unfortunately, in my view, EPCglobal’s process operated better than GSMP. So far I am encouraged by the little evidence I have seen that they are retaining the good parts of the EPCglobal approach. We’ll see how far it goes.

One very commendable thing that EPCglobal has done that GSMP has not is to make their ratified standards documents freely available for download on the internet. The GSMP approach is to roll all of their diverse standards into a single and very large document known as the “GS1 General Specification” (or, “GenSpec”) and they’d like to charge you for a copy of it. Fortunately there are enough M.O.’s around the world that make it available that you can usually find a copy for free download by simply Googling it. I hope that the merged GSMP does not fold the individual EPCglobal specifications into the GenSpec and keep them hidden until you pay, but I must admit, even ANSI and ISO charge for their ratified standards documents.

GS1 also has a lobbying arm which applies pressure to governments around the world to adopt policies that are favorable to GS1 and the technologies that their standards are based on. For example, they applied considerable effort to get governments around the world to open up RF frequency bands around 915MHz so that UHF passive RFID tags could operate worldwide without violating the law somewhere. They have been very successful in that effort, as I understand it.

Another example of GS1 lobbying is when they act as technology experts before U.S. state and federal regulatory agencies. Here GS1 provides guidance toward the adoption of regulations and laws that can be met through the use of their standards. I get a little concerned about this type of lobbying because I fear that GS1 makes themselves out to be unbiased when, in fact, they do have a bias. I hope these agencies are aware of that and take it into consideration.

GS1 will be a frequent topic of this blog since they are focused on the same “intersection” as I am (see the tag line for this blog on the masthead).