By the VixQR team · published on · 9 min read
GS1 Sunrise 2027: The QR Code That Replaces the Barcode on Packaging
By end-2027, retail checkouts should read 2D codes. What GS1 Sunrise 2027 requires, why a normal QR code won't comply, and what brands should do now.
The striped barcode on the back of every product has been essentially unchanged since the 1970s. That's about to end, and the replacement is a QR code.
GS1 Sunrise 2027 — also called Ambition 2027 — is the global initiative to get retail point-of-sale systems reading 2D barcodes alongside the familiar 1D UPC and EAN codes by 31 December 2027. It covers 48 countries representing around 88% of global GDP, and Walmart, Carrefour, Tesco, Target, Woolworths and Kroger have all published supplier timelines.
If you put products on shelves, this reaches your packaging artwork. Here's what it actually means.
What Sunrise 2027 is — and isn't
Start with what it is not, because the misconceptions cause real damage:
- UPC and EAN barcodes do not become invalid in 2028. Linear and 2D codes are expected to coexist well past the deadline.
- It is not a compliance deadline for brands. It's a retailer readiness milestone — the commitment is that checkout systems will be able to process 2D codes. Adoption by brand owners is voluntary and paced by each brand.
- Every retailer will not be ready on the same date. Different regions, categories and chains are moving at different speeds.
- Adding a QR code to your packaging does not make you Sunrise-ready. This is the big one, and it's covered below.
What it is: an industry commitment that by end-2027, a retail scanner should be able to extract a product's Global Trade Item Number (GTIN) from a supported 2D barcode just as reliably as from the stripes today.
Why a normal QR code doesn't qualify
This is where most brands go wrong. They generate a QR code, print it on the pack, and consider the job done. It isn't.
A Sunrise-capable code must be a GS1 Digital Link QR code, which is a specific thing: a QR code whose content is a URL following the GS1 Digital Link URI syntax, with the product's GTIN embedded inside that URL.
That structure is what lets one code do two completely different jobs:
- At the checkout, a scanner parses the URL, extracts the GTIN, and rings up the sale — exactly as it would from the stripes.
- On a customer's phone, the same scan opens a web page: ingredients, allergens, provenance, recycling instructions, warranty registration.
A marketing QR code pointing at yourbrand.com/campaign does neither of those at the till. It's a link, and the POS system has no idea what product it is.
There's a second requirement people miss: the URL needs a GS1-conformant resolver behind it. The resolver is the service that routes a scan to the right destination depending on who's scanning — checkout, consumer phone, logistics scanner, or regulator. GS1 published Conformant Resolver version 1.2.0 in January 2026; any platform you're considering should be tested against that spec before it touches a print run.
A two-year live pilot run by GS1 UK and Tesco, presented at the 2026 GS1 Global Forum, found the same thing repeatedly: half-measures fail at point of sale. Strict Digital Link conformance is what makes it work at scale.
The timeline
2026 — the ramp year. Major retailers expect their largest suppliers to begin shipping dual-coded packaging: the existing linear barcode and the 2D GS1 Digital Link code on the same pack. Several European retailers have pulled acceptance dates forward for new product listings.
2027 — the target year. The 2D code becomes the expected primary carrier on new packaging across grocery, pharmacy and DIY at the major participating retailers. The 1D barcode stays supported, but it stops dictating the artwork.
2028 onward — the regulatory layer. The EU Digital Product Passport (Regulation 2024/1781) begins requiring a data carrier on textiles and batteries, with food, cosmetics and electronics scheduled to follow. Most working groups have specified the GS1 Digital Link QR code — the same carrier retailers will already be reading at the till.
That last point reframes the whole exercise. Sunrise isn't a standalone retail project; it's the foundation the EU's product-passport regime is being built on top of.
Who is moving fastest
Food and beverage — the largest category by SKU count, first to pilot, and where dual-coded packaging is already common on high-volume lines. EU wine labelling rules already require a digital carrier for nutrition and ingredient data.
Cosmetics — running ahead of the official timeline, pushed by ingredient-transparency expectations and imminent DPP scope. L'Oréal, Estée Lauder and Beiersdorf have all run public pilots.
Pharmaceutical — a special case. EU Falsified Medicines Directive and US DSCSA rules already mandate 2D codes on prescription packaging. Digital Link extends those existing codes to patient-facing information, consolidating regulatory tracking and consumer content into one scan.
DIY, electronics, appliances — slower on the retail side, but pulled in by the Digital Product Passport: repair instructions, energy data and end-of-life handling all become accessible from the same code.
What to do this year
Keep the linear barcode. GS1 guidance is explicit: until roughly 90% of POS scanning systems can read GS1 2D barcodes and capture the GTIN, products using retail 2D codes still need the accompanying linear barcode. Dual marking is the transition state, not a compromise.
Audit the QR codes already on your packs. Do they encode a GTIN, or just a marketing URL? Do they follow Digital Link URI syntax? Is there a conformant resolver behind them? If any answer is no, you are neither Sunrise-ready nor DPP-ready, regardless of how the code looks.
Verify your GTINs before anything else. Every product needs a valid, correctly assigned GTIN, with variants and packaging levels distinguished properly and the data consistent across your ERP, ecommerce, packaging and retailer systems. A 2D programme built on messy identifiers propagates the mess.
Run a small pilot. Pick five to ten reference SKUs with verified data, decent packaging space, and a clear consumer use case — deliberately not your most complex or most business-critical item. Dual-code them and put them in front of your retailer contact for POS validation. A pilot surfaces what specifications don't: how the substrate behaves, what the print contrast looks like on your actual press, and which internal systems need to know about the GTIN-to-URL mapping.
Mind the placement. GS1 testing found the 2D code should sit within 50 mm of the centre of the linear barcode to keep checkout speeds acceptable. Confirm final placement against the GS1 General Specifications and with your retail partner.
Test the physical code, not just the image. At final printed size, on the real packaging material, under realistic lighting, on curved or reflective surfaces where relevant, near folds and seams, and after normal handling and moisture. Then test the digital destination separately — barcode verification tells you nothing about whether the landing page works.
Get one team accountable. This is a cross-functional programme touching packaging design, procurement, IT, compliance and marketing simultaneously. It goes badly when those four negotiate during artwork sign-off instead of agreeing the SKU list, print spec and resolver content before the pilot starts.
The mistake that shows up in every pilot
Before the detail, the failure pattern worth inoculating against, because it recurs almost universally.
A brand treats Sunrise as a packaging project. Design adds a QR code to the artwork, procurement sources the print, and the programme is declared underway. Six months later the pilot fails at point of sale, and the diagnosis is always one of three things: the code wasn't Digital Link conformant, the GTIN data was wrong, or there was no resolver behind the URL.
None of those are packaging problems. They're data and systems problems that happened to surface on a pack.
The tell that you're in this failure mode: if your 2D programme is being run by the team that owns artwork, rather than jointly with whoever owns product master data, it will surface late and expensively. Sunrise is a data project that produces a printing requirement — not the other way around.
The resolver, explained properly
The resolver is the part most brands underestimate, because it sounds like plumbing and behaves like a product.
A GS1 Digital Link URL doesn't point at a web page. It points at a service that decides what to return based on who is asking. The same scan can produce completely different results:
- A checkout scanner wants the GTIN and nothing else, in milliseconds.
- A consumer's phone should get a human-readable page: ingredients, allergens, provenance, recycling.
- A logistics scanner may want batch and expiry data.
- A regulator or recycler may need documentation the public never sees.
That routing logic is the resolver's job. GS1 published Conformant Resolver version 1.2.0 in January 2026, and any platform you consider should be tested against that specification before it touches a print run — not after.
Questions worth asking a prospective vendor, in this order:
- Are you tested against Conformant Resolver 1.2.0, and can you show the results?
- What is the URL structure, and does the domain belong to us or to you? (This determines whether you can ever leave.)
- What happens to our codes if we stop paying, or if you're acquired?
- What is the uptime commitment, and what happens at checkout if you're down?
- Can we export the full GTIN-to-destination mapping in a usable format?
Question two is the one that matters in five years. A resolver on a vendor's domain has exactly the migration problem that any rented redirect has, except it's printed on several million packs.
Get the GTINs right before anything else
Every 2D programme that goes badly goes badly here, and it's never a technology problem.
A short data-quality audit before you start:
- Does every product have a valid, correctly assigned GTIN? Not reused, not borrowed from a discontinued line.
- Are variants distinguished properly? Different sizes, flavours and pack counts are different GTINs. Sharing one across variants breaks both checkout and consumer data.
- Are packaging levels handled? The consumer unit, the case and the pallet each carry their own identifier.
- Is the data consistent across systems? ERP, ecommerce, packaging artwork, and what you've published to retailers should agree. They frequently don't, and nobody notices until a scan surfaces the discrepancy publicly.
- Who owns the mapping? One named team, not a shared spreadsheet.
A 2D programme built on messy identifiers doesn't fix the mess. It publishes it, at scale, to consumers and regulators.
How this connects to the EU Digital Product Passport
Worth being explicit, because the two programmes are constantly confused.
GS1 Sunrise 2027 is an industry initiative about retail checkout readiness, targeting end-2027. The EU Digital Product Passport is law under the Ecodesign Regulation, with its first hard deadline on 18 February 2027 for batteries, and other categories following.
Different origins, different enforcement, different scope. But they converge on one technical answer: a QR code carrying a persistent, resolvable identifier. A properly configured GS1 Digital Link code can satisfy both at once.
One correction worth carrying, because vendors get it wrong in both directions: GS1 Digital Link is not legally mandatory for the DPP. The relevant standard requires a resolvable, globally unique identifier; Digital Link is one conforming option among several. It's the practical choice if you also need retail checkout scanning — and unnecessary overhead if you don't.
The DPP side is covered in detail in our guide to the EU Digital Product Passport, including the ten-year data-persistence obligation that should shape your resolver decision more than any feature comparison.
What this means if you're not a packaged-goods brand
If you print QR codes for a shop, restaurant, event or service, Sunrise 2027 doesn't apply to you. There's no GTIN, no checkout scan, no resolver requirement. A plain QR code pointing at your own URL is exactly right, and adding GS1 syntax would be pure overhead.
The one thing worth borrowing is the underlying principle: point your codes at a URL you control, so the destination can evolve without reprinting. That's the same instinct behind the resolver, at a scale that costs nothing.
For that, a static QR code aimed at your own domain does the job permanently. VixQR generates them free, in your browser, with SVG and PDF export for print — no account and no subscription that can lapse and take your printed codes with it.