Labelling, UDI and Supply-Chain Transparency for Trial DHTs
Why the labelled article is the software, the supplied unit or the sensor — never the phone, tablet or gateway that carries it — and why BYOD makes identification harder, not exempt
Labelling, UDI and traceability attach to the regulated article — the software, the supplied unit or the sensor — never to the phone, tablet or gateway that carries it.
Two threshold questions decide whether any duty arises: is the app a medical device, and is it investigational? The sponsor's three moves: name the article, settle its status, and hold the version trail of which build reached whom — the GCP control that device-law traceability, stopping at the economic operator, does not supply.
Each article carries its own duties; the platform is never the article
Annex I s.23 label; in-app IFU permitted. System-level UDI; new UDI-DI or UDI-PI per change (Annex VI C 6.5).
IFU for each market; relabelling or translation triggers Art. 16. Manufacturer's UDI, registered.
Manufacturer's label, IFU and UDI if a marketed device; none for a consumer wearable that is not a device.
Not the article: no label, no UDI. Documented as model and OS/firmware version; serial-tracked if provisioned.
'You can't assign a UDI to a phone' is true — and beside the point
Software that only stores, transmits or displays data is not a device (MDCG 2019-11 Rev. 1), so most eCOA / ePRO apps carry no labelling or UDI duty. An investigational device has no UDI.
With participant-owned hardware there is nothing to label, so identification moves onto the software, its distribution and its version — which build, pushed through which mechanism, to whom.
Language (MDR Art. 10(11)), mandatory content (Annex I s.23; 21 CFR Part 801) and acceptable form differ by jurisdiction. A single global package rarely suffices.
Art. 25 reaches operators and health institutions, not participants. The participant-level version trail is qointa's recommended GCP control, not a UDI duty.
Five steps, from naming the article to re-confirming on change
- 1Settle the article and its status — app, supplied unit or connected sensor; a device at all; investigational or marketed.
- 2Apply labelling and IFU per market — MDR Annex I s.23 in each Member State's language; 21 CFR Part 801 in the US; in-app IFU for software.
- 3Assign and register the UDI for a marketed device before placing on the market (Arts 27, 29; EUDAMED / GUDID); none if investigational.
- 4Trace the chain to the operator or site that received the device (Art. 25), and add the participant-level version trail as a GCP control.
- 5Re-confirm on every change: new UDI-DI for algorithm or data-interpretation changes, new UDI-PI for minor revisions; re-check per market.
MDR Arts 10(11), 16, 25, 27, 29; Annex I s.23; Annex VI Part C 6.5 · MDCG 2019-11 Rev. 1 · Reg. (EU) 2021/2226 as amended by 2025/1234 · Decision (EU) 2025/2371 · 21 CFR Parts 801, 812, 830 · ISO 14155:2020 · CTR Art. 58
© qointa 2026 – Public – Uncontrolled when printed · Not legal advice; this summary does not classify any device.
sales@qointa.com · qointa.com
More from the library
Digital Health Technologies in Clinical Trials — A Regulatory Position-Paper Series
One device, several perimeters: a framework for assessing the regulatory impact of the technologies a trial relies on.
Read more →Who Is the Manufacturer? Economic-Operator Roles in DHT Supply Chains
How provisioning, importing, kitting and modifying a device assign manufacturer, importer and distributor duties — often by operation of law.
Read more →You Can Delegate the Work, Not the Accountability: Vendor Qualification and Oversight under ICH E6(R3)
The sponsor’s duty to qualify and oversee its DHT vendors — distinct from who holds the economic-operator role.
Read more →Talk to a specialist
Bring one device and one protocol — a wearable, a sensor, an app, anything. We will tell you which regulatory perimeters it opens and what it takes to close them.
Book a 15-minute call