PharmaLedger.org
Beratung buchen

AstraLabel SOLO — Legal & Compliance

The EU ePI transition is a regulatory requirement with a deadline. Not a digital transformation project.

AstraLabel SOLO is a GxP-validated, SDLC-ready platform with a full compliance documentation package. Built for pharmaceutical organisations that need to demonstrate compliance — not just claim it.

GxP-validatedSDLC-ready documentationData processing agreementSwiss law · Swiss data

Request a conversation

We respond within one business day.

No spam. No sales automation. Stefan responds personally.

COMPLIANCE POSTURE
GxP-validated platformSDLC-readySwiss nonprofit · CHE-178.875.143SOC 2 Type II scope H2 2026DPA available on request

The compliance landscape

Three regulatory requirements that converge on the same platform decision.

  • 01EU ePI transition — mandatory structured electronic product information for human health medicines. EMA is driving a transition to mandatory ePI across EU member states. The transition timeline is moving. For large MAHs, legal and compliance teams need to understand what structured ePI requires, what constitutes compliance, and what vendor qualification looks like for a GxP-regulated environment.
  • 02EU Regulation 2019/6 — electronic labelling for veterinary medicines by January 2027. For organisations with animal health divisions, this is an active mandatory deadline. Legal and compliance teams need to assess the regulatory risk of non-compliance against the procurement and implementation timeline for a compliant solution.
  • 03Data processing and cross-border data transfer requirements. Structured ePI involves personal data (in some jurisdictions), product data with regulatory significance, and cross-border transfers to national health authority repositories. A vendor that handles this data requires a DPA, a data transfer mechanism, and a clear statement of data residency and processing geography.

The compliance documentation package

What PLA provides to support your vendor qualification process.

GxP validation documentation

Full IQ/OQ/PQ documentation package. Validation summary report. Traceability matrix. Platform is maintained in a validated state — not validated once and left to drift. Ongoing change control process documented.

Data processing agreement

Standard DPA available for review at the pre-signature stage. Swiss law governing. Data processing geography: Switzerland and EU. Cross-border transfer mechanism: SCCs where applicable. No sub-processors without disclosure.

Security & audit

SOC 2 Type II scope in H2 2026. Information security overview available now. Blockchain-verified audit trail for all content events. Access control documentation. Incident response policy.

Governance structure

Swiss nonprofit with pharmaceutical industry board representation.

PharmaLedger Association is registered as a Swiss nonprofit association (Verein) under Swiss law, registered in Zürich (CHE-178.875.143 MWST). The Board of Directors includes representatives from GSK, MSD, and Takeda — organisations whose legal and compliance teams have conducted their own vendor qualification processes for PLA.

For legal and compliance teams conducting vendor risk assessments: PLA's governance documentation, financial statements (audited by an independent auditor), and board composition are available on request. The nonprofit structure means there is no private ownership, no investor pressure, and no exit event that changes the data governance posture.

Governing law

Swiss law. Contracts governed under Swiss law with jurisdiction in Basel or Zürich unless otherwise agreed. No England & Wales governing law in standard contracts. No uncapped liability provisions.

No data monetisation

As a Swiss nonprofit, PLA has no mechanism to monetise customer data. There are no advertising relationships, no data licensing arrangements, and no investor return obligation that creates commercial pressure to use customer data beyond the contracted scope.

The regulatory compliance argument

What constitutes a compliant ePI implementation under the EU framework.

A compliant ePI implementation requires: structured content in a machine-readable format (FHIR-native is the EMA direction), distribution to relevant national health authority repositories in each member state's required format, a GxP-validated system maintaining content integrity, and an audit trail demonstrating version control and change history.

AstraLabel SOLO was built to satisfy these requirements. The compliance argument is not a claim — it is documented in the validation package and demonstrated in the live repository integrations across 46 countries.

Common questions

Frequently asked questions

What is the data residency model for content stored on AstraLabel?
Content is processed and stored in Switzerland and EU-based infrastructure. PLA does not transfer content to non-EU/EEA jurisdictions without an appropriate transfer mechanism in place (SCCs or adequacy decision). Data residency specifics are documented in the DPA, available at the pre-signature stage.
Is AstraLabel SOLO a validated GxP system?
Yes. AstraLabel SOLO is maintained as a GxP-validated platform. Full IQ/OQ/PQ documentation is provided as part of the service — not as an additional cost. The platform is maintained under a documented change control process. Customers receive a validation summary report and traceability matrix as part of onboarding.
Our standard vendor contract requires English law and London ICC arbitration. Is this negotiable?
PLA's standard governing law is Swiss law with jurisdiction in Basel or Zürich. English law and London ICC arbitration are not in PLA's standard terms. We have experience negotiating governing law with major pharmaceutical companies — Swiss law with ICC or Swiss Chambers arbitration is the standard resolution in our contracts with Top-20 MAHs.
What is the liability cap in your standard contract?
PLA's standard contract includes a liability cap set as a percentage of annual fees paid. Uncapped liability is not accepted in standard terms. The specific cap percentage is set out in our standard terms, available on request before the commercial conversation.
When will SOC 2 Type II certification be available?
SOC 2 Type II is in scope for H2 2026. We provide a security overview and information security policy documentation in the interim. For organisations with a hard SOC 2 Type II requirement, we discuss timeline alignment in the pre-contract conversation.

Request the full compliance documentation package before the commercial conversation starts.

GxP validation summary, DPA, security overview, governance documentation, and standard contract terms — sent in advance so your legal team can review before any call.

Request compliance documentation