blog · 2026-07-31 · written for: ED-1 — the supply-chain ISV engineering org (the VP Engineering / CTO doing build-vs-buy diligence); B2D spec-citation deep dive

Why there is no honest GTIN cache: the GS1 licensing wall, clause by clause

One thesis: every GS1 data rail short of a negotiated agreement licenses display-and-verify use only — so any vendor serving you cached GS1-sourced product attributes is running on rights it cannot show you, and your diligence should ask to see them.

If you are doing build-vs-buy on a product-data layer, the licensing question is not a compliance footnote; it is the foundation question. The clauses below are quoted from the actual agreements, with links, because this is the kind of claim that should never be taken on a vendor's word — including ours.

The wall, contract by contract

GS1 UK GTIN Check API — the anti-caching clause. Section 8.6.1 of the terms requires that users "not create, copy or store permanent copies of the API Data." That is the sharpest sentence in the ecosystem: the verification rail is real and useful, and a permanent copy of what it returns is contractually excluded. A cache is a permanent copy.

Verified by GS1 — commercial-use exclusion. The GS1 UK VbG terms (sections 19.1–19.2) scope the content to "your business and for your own business processes, excluding commercial use," and provide it cannot be "sold, sublicensed, distributed or otherwise made available" — except within a defined "Value-Added Product." Hold that phrase; it returns below.

GS1 US Data Hub — internal use only, plus the category clause. The Access and Use Agreement licenses the platform in section 5(A) "solely for the Company's internal business or educational purposes," with an explicit "You agree You will not distribute, sell or resell the Platform, Platform Data or allow third parties to access the Platform or Platform Data." Section 5(B)(c) forbids making data available to third parties "without GS1 US prior express written authorization." And section 5(B)(c)(vi) reaches past the data to the product category itself: no using the platform to "create (or allow third parties to create) any software product capable of emulating or competing with the Platform." Read that one twice: even a fully paid tier is an internal-use license, and building a lookup product on it is barred in two independent ways.

GDSN — per-brand-owner consent. The Terms of Participation, section 3.G(a) (agreement PDF), provide that a trading partner "shall not disclose, disseminate, provide or make available the GDSN Data of a Source Trading Partner to a Non GDSN Member without the Source Trading Partner's prior written consent." Becoming a recipient trading partner is achievable; redistributing what you receive requires written consent from each brand owner, per source. GDSN is point-to-point governance, not a corpus — structurally, not incidentally.

Now apply the syllogism your diligence memo needs: the aggregators selling 500-million-row GTIN lookups did not negotiate per-brand-owner GDSN consent, are not operating inside a Value-Added-Product agreement, and their own terms disclaim that parts of their data "belong to third-party owners." If the licensed rails all exclude caching and redistribution, a cached redistribution product is running on rights it cannot produce. Ask any product-data vendor one question: show me the license chain for this attribute. The silence is the answer — the aggregator post walks that tier vendor by vendor.

What is genuinely open — and it is a lot

The wall surrounds the data rails. The standards layer is open by policy, and this distinction is the architecture:

  • The full GS1 General Specifications text is openly served at ref.gs1.org — every check digit, every AI, every symbology usage rule.
  • GS1 Digital Link URI Syntax 1.6.0 and the GS1-Conformant Resolver standard 1.2.0 are free downloads, royalty-free to implement under the GS1 IP Policy — section 4.A grants a "non-exclusive, worldwide, royalty-free, fully paid-up, perpetual, irrevocable" license, and section 4.C(1) prohibits charging "to use or access GS1 Standards, which are provided freely by GS1."

Validation, parsing, canonicalization, generation, and conformant resolution therefore cost nothing and violate nothing. That is why resolve, verify, and generate run pure and local on every GTIN on earth, no account, no agreement — the standards make it legal and the pinned tables make it correct.

Our posture, stated flat

The license enum in the provenance envelope contains gs1-licensed-display-only as a first-class value precisely because this wall exists: where display-scoped GS1 data ever appears, it is served display-scoped, and nothing display-only is ever cached — the enforcement is at response assembly, not in a footer. The enrichment that is served from durable rails is served from sources whose licenses permit it (public-domain USDA, openFDA, vPIC; ODbL as a segregated layer), which is why the food chain can run license-clean end to end.

And the one contractual door in the wall is named rather than assumed: the Value-Added-Product carve-out (GTIN Check API terms, section 7.4) covers an offering that adds "substantial independent" value by combining API data with other data or creating new functionality — negotiated per member organisation. Nothing on this surface presumes that negotiation; no page here implies general-merchandise coverage that would require it. The honest shape today is exactly what you can verify: identity free everywhere, enrichment deep and clean where the licenses are clean, and the gated territory labeled gated. The enrichment tiers behind keys are provisioned from the list, in order — get an API key and say what your product needs to look up.

Keys open the network half of the verb set. Get an API key — say what arrives at your door, and the provisioning order follows the list.

We answer in writing. We take at most five conversations a month, only when you ask for one, and only after you already have the written read.