77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
Manage safety data sheets: obligations, processes, platform
Hazardous Substances & Occupational Health

Manage safety data sheets: obligations, processes, platform

4 July 202614 min readBy Stefan Möller
CIVAC

Safety data sheets are mandatory documents according to REACH Annex II. If you only save them as PDFs, you will miss the operational requirement. This article shows how you can maintain SDBs, convert them into directories and translate them into operating instructions.

A safety data sheet (SDS) is required in accordance with Art. 31 of the REACH Regulation (Regulation (EC) No. 1907/2006) in conjunction with. V. m. Annex II, the central information document for dangerous substances and mixtures. It is created by the supplier in 16 sections and sent free of charge in the official language of the destination country upon first purchase, with every change and at least on request. The German SDB is mandatory for German companies; alternative languages ​​are generally not sufficient for hazardous substances. The SDB is the basis for the risk assessment, the list of hazardous substances according to § 6 GefStoffV and the operating instructions according to § 14 GefStoffV.

This article is aimed at those responsible in manufacturing companies, laboratories, workshops, cleaning and care companies, safety specialists (SiFa) and hazardous substances officers (GSB). You will find out what obligations are associated with the administration of the SDB, what sound maintenance looks like (procurement, versioning, distribution), which platforms make sense, how the transfer to the list of hazardous substances and operating instructions is successful and where CIVAC supplements the compliance layer. You are reading a practical guide with specific deadlines, paragraphs and procedural steps.

We are consistently guided by REACH Annex II, CLP, GefStoffV and the relevant TRGS. Where a statement follows from a norm, the norm is named. This makes the content directly usable for audits, professional associations and trade supervision and shortens discussions about the legal basis.

Key Takeaways

  • According to Article 31 REACH and Annex II, safety data sheets are mandatory documents in 16 sections, in German and with documented updates.
  • The list of hazardous substances according to § 6 GefStoffV, risk assessment according to § 6 GefStoffV and operating instructions according to § 14 GefStoffV are derived from the SDB.
  • Sound management requires procurement, versioning, distribution and linking to activities, not just a PDF archive.

What a safety data sheet contains: The 16 sections according to Annex II

Annex II of the REACH regulation provides a fixed structure in 16 sections. Section 1 contains the name of the substance or mixture, identified uses and supplier data including emergency number. Section 2 covers classification according to the CLP Regulation (Regulation (EC) No. 1272/2008), label elements and other hazards. Section 3 lists ingredients with CAS, EC and registration numbers where relevant.

Sections 4 to 6 describe first aid measures, firefighting measures and accidental release measures. Sections 7 and 8 cover handling, storage and exposure controls, including personal protective equipment. Section 9 lists physical and chemical properties, Section 10 lists stability and reactivity.

Sections 11 to 12 contain toxicological and ecotoxicological information. Section 13 regulates disposal, Section 14 regulates transport (UN number, class, packing group, dangerous goods), Section 15 legal regulations and Section 16 other information including version status, change history and list of sources. Important for administration: Each SDB has a version and a date, both of which belong in the archive. Sound maintenance requires more than a PDF archive. You can find out more about the role of the Hazardous Substances Officer on the role pages.

In practice, Section 8 (Exposure Limitation), Section 13 (Disposal) and Section 14 (Transport) most often serve as the basis for internal decisions. Anyone who systematically checks these three sections when onboarding a new substance avoids follow-up costs for system adjustments, disposal contracts and ADR training in shipping logistics.

Important: For mixtures, sections 2 and 3 must be paid particular attention to because the classification is derived from the ingredients and can change if the recipe changes. Version tracking is mandatory here.

It is also helpful to have an internal profile for each substance, which extracts the most important fields of the SDB and links them to activity, warehouse and PPE. This creates a workplace-related protection document.

Obligations according to REACH, CLP and GefStoffV

The REACH Regulation obliges suppliers to submit the SDS when first purchasing it and when updating it. Recipients must make the SDB accessible and use internally, for example in risk assessment. The CLP Regulation regulates the classification, labelling and packaging of substances and mixtures. Changes in the CLP classification often lead to updates of the SDS, which the recipients then have to adopt immediately.

The Hazardous Substances Ordinance (GefStoffV) specifies the internal obligations in §§ 6 ff. Section 6 GefStoffV requires a risk assessment, a list of hazardous substances and the definition of protective measures. § 14 GefStoffV regulates the operating instructions and the instruction of employees, at least annually and in relation to the work area. § 15 GefStoffV regulates the employment ban for particularly vulnerable people, such as pregnant women.

In addition, industry-related requirements apply, such as the Technical Rules for Hazardous Substances (TRGS), which are announced by the Federal Ministry of Labour and Social Affairs. TRGS 400 (risk assessment), TRGS 510 (storage), TRGS 555 (operating instructions) and TRGS 900 (workplace limit values) are particularly relevant in practice. Anyone who only stores SDBs as PDFs can hardly fulfil these obligations. A platform with a link to activities, people and training makes more sense.

Anyone who has suppliers based in the EU and third country suppliers in parallel must also take REACH compliance, import declarations and SVHC notifications into account in accordance with Article 33 REACH. This interface is increasingly being examined in audits and requires consistent supplier communication in procurement.

Sector requirements such as the Chemicals Act (ChemG) and the Water Resources Act (WHG) with the AwSV requirements for substances hazardous to water also apply.

ECHA also maintains the candidate list of substances of very high concern (SVHC), which is regularly expanded. Anyone who contains SVHC substances in products has an obligation to notify the supply chain and consumers. List maintenance in the workspace is helpful here.

Retention and updating: what deadlines apply

The SDS must be kept at least as long as the hazardous substance is used in the company and for at least 10 years after the end of use. For carcinogenic, germ cell mutagenic and reproductively toxic substances (CMR) of categories 1A and 1B, the retention period is extended to 40 years after the end of the activity, derived from Section 14 GefStoffV and provisions of the ArbMedVV. Previous versions must also be retained because they may be relevant for the subsequent assessment of exposures.

The obligation to update is linked to Article 31 Para. 9 REACH: As soon as new information that influences risk management measures is available or an authorisation or restriction has been granted, an updated version must be created and sent free of charge to all recipients of the last 12 months. In the recipient company, the update must be included in the directory and in the operating instructions. The topicality should be checked and documented at least annually.

It is practically important to have a versioned storage with date, version, hash value and links to the affected activities. Anyone who replaces an older SDB version unnoticed loses the basis for assessing historical exposures. Audit-proof, documented, § 6 GefStoffV-proof. CIVAC maintains SDS as versioned attachments with links to the directory, activity and proof of training, so that the life cycle for each substance can be traced in the audit.

In addition, a short written assessment for each substance is recommended as to whether the update triggers changes to protective measures, PPE or emergency rules. This creates a trace of effectiveness instead of pure document maintenance, which has a much better effect in the audit.

Anyone who changes suppliers checks whether the SDB versions they receive are up to date, because changes to suppliers often lead to version crashes. A documented change workflow with key date comparison, directory update and subsequent adjustment of the operating instructions avoids gaps in the audit.

From the SDB to the list of hazardous substances according to Section 6 GefStoffV

The Hazardous Substances List according to Section 6 Paragraph 12 GefStoffV is a central inventory of all hazardous substances used in the company. It contains at least the name, classification or dangerous properties, quantity range, working area and reference to the SDS. It can be managed centrally for the company or decentrally for each work area, but must be up to date at all times and checked at least annually.

Maintenance typically takes place in four steps. Firstly, inventory of all hazardous substances, ideally per work area. Secondly, attach the SDB as an appendix and link it to the directory entry. Third, recording the relevant activities and quantities. Fourthly, link with risk assessment and operating instructions. Anyone who maintains all four steps in one platform can see the complete data flow in the audit, from the procurement form to the SDB to the instruction.

The interface to the substitution test according to Section 6 Paragraph 1 GefStoffV is important. For each hazardous substance, it must be checked whether it can be replaced by a less hazardous substance. This test must be documented and repeated at regular intervals. The substitution test is often a finding in audits because it was carried out incompletely or without proof of effectiveness. CIVAC manages it as a workflow with a documented decision and resubmission.

The quantity information per work area is important because it triggers storage, fire protection and approval obligations. Anyone who only maintains total quantities here can overlook fire compartments or reporting obligations under the BImSchG. A location-based view is mandatory, not an option.

The link with procurement is also important: Anyone who submits a substance request should automatically trigger the SDB check, the substitution check and the directory entry before the ordering process is completed. Otherwise, an inventory will be created before the assessment.

A four-eye principle when making directory changes significantly increases the data quality.

From the SDB to the operating instructions according to § 14 GefStoffV

The operating instructions are the written, work area and activity-related instructions to employees on how to handle hazardous substances. It is mandatory according to Section 14 GefStoffV and TRGS 555 and must be in a form and language that employees can understand. It contains dangers, protective measures and rules of conduct, what to do in the event of danger, first aid and proper disposal.

The operating instructions are not an excerpt from the SDB, but rather a separate translation for the specific workplace. SDB texts often contain standard formulations that do not provide guidance for the workforce. The operating instructions must describe the actual activities, quantities, rooms, PPE and emergency rules in plain text, ideally with pictograms and telephone numbers for first aid and fire.

The instruction according to Section 14 Paragraph 2 GefStoffV takes place before the first activity and at least annually, more frequently depending on the occasion, for example with new substances, changed procedures or after accidents. It must be proven in writing with content, date, participants and instructor. CIVAC links operating instructions, proof of instruction and SDB for each activity. The appointment certificate, signed, filed, verifiable. The SDB becomes a living protection concept, not a file folder.

Effectiveness only becomes apparent during the instruction. Anyone who asks short comprehension questions at the end of the instruction and documents the answers can prove in the event of a finding that the content has been received. This comprehension test is not expressly required, but in practice it is the most effective argument against findings on the depth of instruction.

Language versions are mandatory in many companies, for example for employees with other native languages. Section 14 (2) GefStoffV requires a form and language that employees can understand. Bilingual operating instructions with standard pictograms are best practice here and are positively noted during inspections.

Which platforms are suitable for SDB management

There are various classes of tools for SDB management on the market. First class are pure SDB libraries with procurement functions (pull from supplier systems), versioning and search. They are suitable for companies with a high volume of SDB but little ambition to link it to activities or training. Second class are hazardous substance management systems with a directory, risk assessment, operating instructions and training module.

Third class are compliance platforms such as CIVAC, which manage hazardous substance management as a module within a broader officer control system. Here the SDB and directory are linked to the appointment certificate from the hazardous substances officer, to the safety specialist, company doctor, emergency organisation and to the general training obligations. This depth makes sense if audits from different disciplines are expected (professional association, trade inspection, BG-specific inspections, ISO 14001).

Important selection criteria are data residency (EU server, ideally Germany), interfaces to supplier systems, versioning with hash value, link to personnel master data, audit trail with timestamp and person responsible, multilingual instructions and mobile view in the workshop area. Pragmatic preparation includes a list of requirements with weighted criteria, a shortlist of three providers and a 30-day test phase with one location as a pilot.

Before making an investment decision, the ownership perspective is important: Who owns the SDBs in the platform vendor? Can the content be exported in a standardised way, for example as a ZIP with a directory and PDFs, or does a change involve implementation effort? Anyone who works here without an export clause runs a long-term lock-in risk.

Mobile availability in manufacturing companies is not a convenience feature, but rather a protective effect. Anyone who can use their smartphone to jump to the right SDB in an emergency will gain crucial minutes compared to the file folder in the office.

A pilot phase with one location provides reliable data on data quality, training effect and supervisory response. Only then is it worth rolling out to all locations.

Interfaces with safety specialists, company doctors and emergency organisations

SDS management is not an isolated issue but touches on multiple roles. The safety specialist (SiFa, § 6 ASiG) advises the management on risk assessments, protective measures and instructions. The company doctor (§ 3 ASiG) carries out occupational health precautions in accordance with ArbMedVV, which are often triggered by hazardous substances, such as compulsory precautions for activities involving carcinogenic substances.

The emergency organisation uses SDB for first aid operations, firefighting and information for rescue workers. In the event of an accident involving hazardous substances, the responsible person must be able to access the correct SDS in minutes, ideally on mobile devices. If you only store SDBs in a file folder in the office, you will lose half of their value in an emergency. A mobile, offline-capable view is a real protective effect here, not just convenience.

CIVAC links SDB, risk assessment, operating instructions, proof of instruction and emergency plan in a workspace with defined roles for hazardous substances officers, SiFa, company doctor and emergency organisation. Reporting lines to management are documented and escalation paths are defined. The auditor calls, the evidence is ready. You can find an overview of all representative roles at civac.de/roles.

A good practice is a SDB emergency application on tablets or smartphones in workshops and laboratories, which works offline and synchronizes with the central workspace. In this way, rescue workers and employees are able to act immediately in case of doubt, without having to first look for a file folder.

Interfaces to materials management, ERP and warehouse logistics also avoid double data maintenance during goods receipt and inventory.

A joint steering group made up of hazardous substances officers, SiFa, company doctor, emergency organisation and management at least quarterly reduces friction significantly. It is also a place where substitution decisions are discussed and prioritised instead of shifting them to individual responsible persons.

A clear escalation rule for emergencies, including availability plan and replacement, belongs in the workspace module. Otherwise, an incident at the weekend will result in unclear responsibility.

Common findings in audits and inspections

In audits and inspections by professional associations, trade regulators or internal auditors, five themes emerge repeatedly. Firstly, outdated SDB without a documented effectiveness check of up-to-dateness. Secondly, incomplete directories in which inventory materials are missing or decentralized warehouses are not shown. Thirdly, lack of substitution testing for substances that could be replaced with less dangerous ones.

Fourthly, standard operating instructions, which were taken verbatim from the SDS and have no connection to the actual activity, such as references to protective suits in situations in which they are not worn, or emergency numbers from the supplier country instead of from Germany. Fifthly, Gaps in the instruction, for example for seasonal workers, temporary workers or service partners who carry out the activity but are not included in the training plan.

Pragmatic preparation includes a quarterly up-to-date check of the SDB with a documented effectiveness assessment, a cross-location directory revision, a substitution matrix with resubmission and a training matrix with personnel master data. The CIVAC audit templates manage these four building blocks as connected modules, so that findings from an inspection flow back into the overall system instead of disappearing in an Excel report.

In addition, storage rules according to TRGS 510 are often checked in audits, such as the separation of incompatible substances, the limitation of storage quantities per fire compartment and the requirements for collecting trays for water-polluting liquids. Anyone who links the storage rules in the directory for each substance avoids disputes during the inspection.

Experienced inspections also check the emergency handling: Are the emergency numbers up to date, are the safety showers and eye washes freely accessible and checked, are there collecting trays and absorbents available? These points cannot be read from the SDB, but are directly linked to the protective effect.

Well-founded preparation includes regular mock inspections.

From PDF archive to protection concept: How CIVAC supports

Safety data sheets are the bridge between chemical law and occupational safety. Anyone who only saves it as a PDF has formally fulfilled the obligation, but not the protection that the law wants to achieve. CIVAC sees itself as a compliance platform and officer-as-a-service and integrates SDB into the life cycle of hazardous substances, activities, training and emergencies. The workspace contains versioned SDBs, directories, risk assessments, operating instructions, training certificates and emergency plans, linked to personnel master data and location information.

Others run compliance like a filing cabinet. We run it like software. Licence the workspace for your internal representatives, or have our representatives order it. The dual model is kept open because company sizes, industries and risk profiles are different. The platform's SLA is two business days, measured at the time the request is received. Data residence: Germany. Authentication: SSO or SAML. Interfaces: common HR and materials management systems.

Turn reading into a mandate. Write to info@civac.de or use the contact form on civac.de. We will schedule a 30-minute initial consultation in which we will discuss your SDS inventory, your directories and the three next steps. By the next working day at the latest, you will receive a written proposal with a clear task list, timeline and transparent prices, in German and with EU data residency.

From our platform practice, we provide prepared templates for operating instructions, instruction protocols, substitution matrix and emergency plans. You adapt them to your materials and workspaces instead of restructuring them from scratch.

Beyond the platform, we deliver methodology. Workflow examples for procurement, versioning and substitution, training slides for instructions, templates for mock inspections and a checklist for supervisory communication are part of the standard scope of delivery.

FAQ

How long must a safety data sheet be kept?

At least as long as the hazardous substance is used in the company, plus 10 years after the end of use. For carcinogenic, germ cell mutagenic or reproductively toxic substances in categories 1A and 1B, the retention period is extended to 40 years after the end of the activity, derived from Section 14 GefStoffV and ArbMedVV. Previous versions should also be retained because they are essential for assessing historical exposures.

When does an SDS need to be updated?

Art. 31 Para. 9 REACH requires an update as soon as new information that influences risk management measures is available or an authorisation or restriction has been granted. The supplier sends the updated version free of charge to all recipients in the last 12 months. The directory, risk assessment and operating instructions must be adapted in the recipient company. An annual timeliness check should also be documented, otherwise findings will arise in the audit.

Is a PDF archive sufficient for SDB management?

Formally yes, operationally no. A PDF archive fulfils the retention obligation, but not the link with the risk assessment, directory, operating instructions and proof of training in accordance with Sections 6 and 14 GefStoffV. Audits check the life cycle of each substance, not just the existence of the document. A versioned platform with links to activities, people and training reduces findings and significantly speeds up supervisory communication.

Who is responsible for SDB management in the company?

Overall responsibility lies with the management. Operationally, the SDB administration is usually managed by a hazardous substances officer, often in conjunction with the safety specialist. There are interfaces to the company doctor, materials management, warehouse logistics and emergency organisation. CIVAC provides an appointment certificate in the workspace and defines the reporting line to management and escalation paths.

What is the difference between SDB and operating instructions?

The SDB is the supplier document with 16 standardised sections according to REACH Annex II. The operating instructions are the internal document according to § 14 GefStoffV and TRGS 555, which present the dangers, protective measures and rules of conduct for the specific activity, the work area and the workforce in plain text. The operating instructions are derived from the SDB, but do not copy it. It is the basis of the annual instruction.

How does CIVAC help with SDS management?

CIVAC maintains SDB as versioned attachments in the workspace, linked to a directory in accordance with Section 6 GefStoffV, risk assessment, operating instructions, proof of training and emergency plan. Reporting lines to management are documented, audit templates prepared, data residency in Germany. Licence the workspace for your internal representatives, or have our representatives order it. The SLA is two business days, measured from receipt of the request.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles