An EUDR due diligence statement — usually shortened to DDS — is the declaration you make available to your national competent authority through the EU Information System before you place a relevant product on the EU market or export it. Article 4 of Regulation (EU) 2023/1115 sets that duty, and it also requires you to communicate “the reference numbers of the due diligence statements or, if applicable, the declaration identifiers associated to those products” to the businesses you sell to.
So the DDS is two things at once: a statement you file, and a reference number your customers will ask you for. The second part is what catches people out, because that number does not exist at the moment you hit submit.
The short answer
- A DDS is submitted through the EUDR Information System before the product goes on the market or is exported (Article 4, Regulation (EU) 2023/1115).
- Its hardest content requirement is the geolocation of every plot of land where the commodity was produced, plus the date or time range of production (Article 9(1)(d)).
- Coordinates need at least six decimal digits. A plot over four hectares needs a polygon, not a point (Article 2 definition of “geolocation”).
- Submitting does not immediately give you a reference number. The Information System runs automated risk profiling first, and only assigns the number after that concludes.
- The risk status it assigns is never shown to you.
- A statement becomes locked — no amendments, no withdrawal — once it has been used as a grouping reference.
What has to be in an EUDR due diligence statement?
The heavy part isn’t the form. It’s the production-place data behind it.
Article 9(1)(d) of Regulation (EU) 2023/1115 requires “the geolocation of all plots of land where the relevant commodities that the relevant product contains, or has been made using, were produced, as well as the date or time range of production”. If your product draws on several plots, all of them go in — the article says so explicitly.
That same article carries a consequence worth reading twice: “any deforestation or forest degradation on the given plots of land shall automatically disqualify all relevant commodities and relevant products from those plots of land from being placed or made available on the market or exported”. There’s no risk-weighting step that softens this. One disqualifying plot takes its products with it.
Cattle are handled differently. For products containing or made using cattle, Article 9(1)(d) says the geolocation “shall refer to all the establishments where the cattle were kept” rather than to plots of land.
How precise does the location have to be? Article 2 of Regulation (EU) 2023/1115 defines geolocation as “the geographical location of a plot of land described by means of latitude and longitude coordinates corresponding to at least one latitude and one longitude point and using at least six decimal digits; for plots of land of more than four hectares used for the production of the relevant commodities other than cattle, this shall be provided using polygons with sufficient latitude and longitude points to describe the perimeter of each plot of land.”
In practice that means three rules you’ll apply over and over:
| Production place | What the geolocation may be |
|---|---|
| Plot of four hectares or less (not cattle) | A single latitude/longitude point, or a polygon if you have one |
| Plot larger than four hectares (not cattle) | A polygon tracing the plot’s perimeter |
| Establishment where cattle were kept | A single point, whatever its area |
Six decimals is not a rounding suggestion. It’s the floor in the definition, and a coordinate file that loses precision somewhere between your supplier’s phone and your submission is a file that no longer meets it.
This is the step where most of the real work sits, and it’s worth checking before it reaches a filing queue. Clearlane’s free EUDR GeoJSON validator checks a file’s structure, coordinates and geometry in your browser — the file never leaves it — and records the repairs it can make without changing what the file means. It’s a format and data-quality check, not a compliance verdict; more on that distinction below.
If your question is when these duties start applying to your business rather than what they contain, that’s a separate answer with separate dates: see EUDR deadlines in 2026 and 2027.
Why doesn’t the reference number arrive when you hit submit?
Because a check runs in between, and it isn’t instant.
The functioning of the Information System is governed by Implementing Regulation (EU) 2024/3084, which was substantially amended by Implementing Regulation (EU) 2026/1565 of 13 July 2026. Under Article 6(3) of the amended text, “upon its submission in the Information System, each Due Diligence Statement and Simplified Declaration shall be subjected to an automated electronic risk profiling and the Information System shall assign a risk status to each Due Diligence Statement and Simplified Declaration, which shall not be disclosed to the Information System user.”
Then, under Article 7(1), “the Information System shall, without undue delay after concluding the risk profiling referred to in Article 6, assign a reference number to the Due Diligence Statement and a declaration identifier to the Simplified Declaration.”
Two practical consequences follow, and both bite process design rather than paperwork.
The first: you cannot promise a customer a reference number in the same conversation in which you submit. Your buyer needs that number, and it arrives on the Information System’s schedule, not yours. Any internal process that treats “submitted” and “referenced” as one step will stall at exactly the wrong moment.
The second: a delay is not a verdict. The risk status is explicitly not disclosed to you, so a wait that feels long tells you nothing about how your statement was profiled. Reading a slow response as bad news — or as good news — is inventing information the system deliberately withheld.
For teams building against the API rather than using the web interface, the technical handle you hold while you wait, and the polling behaviour the Commission recommends, are covered in what changed in EUDR Information System API V3.
Can you correct a due diligence statement after filing it?
Up to a point, and that point is sharper than most summaries suggest.
Article 5(2) of Implementing Regulation (EU) 2024/3084, as amended, states that “Due Diligence Statements shall not be amended or withdrawn after the Due Diligence Statement was used as a reference in a Due Diligence Statement submitted by the same Information System user for grouping pursuant to Article 8a.”
Read that as a one-way door. While a statement stands alone, there’s room to correct it. Once you’ve referenced it inside a grouped statement, it’s fixed — and grouping is something you do, which means you control when that door closes. Grouping late, after you’re confident in the underlying data, keeps your options open longer than grouping early.
Simplified Declarations behave differently. Under Article 4a(3), an update is submitted through the Information System like the original, and “the declaration identifier associated to the Simplified Declaration shall be maintained in case of an update” — so an update doesn’t hand your customers a new number to chase. Article 4a(6) adds that the Information System “shall enable Information System users to withdraw Simplified Declarations.”
DDS, simplified declaration, or verification — which applies to you?
The Information System separates three jobs, and picking the wrong one wastes a filing cycle. The Commission’s EUDR Information System page is the authoritative starting point for the current manuals and technical files.
| Service | Who it’s for | What it does |
|---|---|---|
| Due Diligence Statement | Operators and their authorised representatives | The standard route: submits and manages a full DDS |
| Simplified Declaration | Eligible micro or small primary operators, and their authorised representatives | A separate declaration route with its own identifier, updatable and withdrawable |
| Verify Declaration | Authorised downstream users | Checks whether an upstream declaration is authentic and in a usable status |
One misreading is common enough to call out: a Simplified Declaration is not a shorter DDS for any small company. It’s a specific route for an eligible micro or small primary operator. Being small is not, by itself, the qualification.
And verification is not delegation. Checking an upstream declaration confirms that declaration’s authenticity and status; it does not transfer the upstream operator’s due diligence onto your file, or discharge your own EUDR duties.
What limits shape a large statement?
If you’re consolidating many suppliers into one filing, the Information System has documented ceilings that decide how you batch. The Commission’s May 2026 Operator API V3 reference, linked from the Information System page, documents these:
| Limit | Documented ceiling |
|---|---|
| Commodities per declaration | 100 |
| Producers per commodity | 1,000 |
| Producers per declaration | 10,000 |
| Scientific-name and common-name pairs per commodity | 500 |
| Grouping references | 2,000 |
| Geolocation data in the assembled declaration | 25 MB |
| HS heading length | Two to six digits |
The 25 MB figure applies to the assembled declaration, not to each file you started from. A set of individually modest polygon files can clear every upload check and still overflow the finished statement — which is why the size worth measuring is the one at the end of the process, not the beginning.
Grouping has its own boundary. It covers eligible declarations previously submitted by the same Information System user, or declarations submitted for the same operator by its authorised representative. That is narrower than a library of supplier references: holding a reference your supplier gave you does not make it eligible for same-user grouping.
Does the country of production change what you file?
It changes the risk picture, not the filing duty.
Implementing Regulation (EU) 2025/1093, effective 26 June 2025, classifies the countries listed in its Annex as low or high risk. Every country not listed in that Annex remains standard risk — Article 1 and the Annex work together that way, so the absence of a country from the list is itself the answer.
Two cautions. That default applies only to a valid ISO 3166-1 alpha-2 country code; a missing or malformed code is not a standard-risk classification, it’s an unresolved field. And country classification is one input to the EUDR risk framework — it is not a finding that a plot, product or shipment is deforestation-free, legally produced or compliant. A low-risk country of origin does not make a statement true.
You can check which of your products fall in scope, and where, with the free EU scope scanner.
What Clearlane does, and what it does not
Clearlane prepares and validates the work behind a due diligence statement, then hands it off. It turns supplier data into cited, reviewable compliance evidence: deterministic scope and geolocation checks, GeoJSON repair that preserves meaning, production-country validation, and an audit trail you can show someone.
What it does not do matters just as much. Clearlane does not submit a legally effective declaration to the EUDR Information System, does not issue an official reference number, does not expose the Information System’s hidden risk status, and does not certify that goods are deforestation-free. A successful technical file check means the supported format and data-quality checks passed. Risk assessment, risk mitigation and the statement itself remain your responsibility as the operator.
That boundary is deliberate. A tool that implied otherwise would be the most dangerous thing in your compliance file.
Start where the work actually is: check a GeoJSON file against the format rules — it’s free, it runs in your browser, and it takes about a minute. Then see how Clearlane’s preparation workflow fits together or read the plain-language EUDR guide.
This article is educational guidance. It is not legal advice, an Information System filing, or a compliance verdict.