The short answer
The General Product Safety Regulation, better known by its English acronym GPSR, does not require any single standalone document. What the regulation does require is that you can demonstrate that a product is safe, that there is someone in the European Union who can be held responsible for that safety, and that users receive the correct information and warnings. In practice, this amounts to a risk assessment of the product, technical documentation that supports that assessment, instructions for use and safety information in the language of the country where you sell, and data by which the product and the responsible party can be traced.
Which documents you must have exactly depends on your role in the supply chain: manufacturer, importer or distributor. A manufacturer prepares the technical documentation and risk assessment themselves. An importer of electronics from outside the EU must check whether that documentation exists and must put their own name and address on the product or the accompanying documentation. A distributor has a lighter, but not non-binding, controlling role.
Why this subject differs from CE marking
Many entrepreneurs in electronics and ICT think that CE marking and the associated declaration of conformity already cover them. This is partly correct: for products that fall under specific EU directives, such as the low voltage directive or the radio equipment directive, that legislation remains the standard for technical safety requirements. The GPSR works alongside this, as a safety net for everything not explicitly regulated in sectoral legislation, and for the general obligation to monitor the market even after sale, for example in the event of complaints or accidents. This means that the documents for CE marking and the documents for the GPSR overlap, but do not replace each other.
The detail that plays the most in this subject
The point where companies most often stumble is not the technical documentation itself, but the obligation to designate a point of contact within the European Union and to document that as well. For electronics imported from outside the EU, a name, address and contact possibility must be available from a party within the Union that is responsible for product safety. This can be the importer themselves, or an authorised representative. Many companies do know who this is, but have not documented it anywhere in writing in a way that a supervisory authority can directly check. Precisely that documentation, regardless of whether the person is actually known, is what the regulation requires.
The documents listed by situation
For a manufacturer of electronics, it is about the technical documentation with the risk assessment, the instructions for use and safety warnings, and data by which the product can be identified, such as a type, batch or serial number. For an importer, their own name and address are added, plus verification that the manufacturer's documentation is complete before the product is resold. For a distributor, it is mainly about whether the required information is present on the product or packaging, and about a way to report complaints and signals about unsafe conditions to the party that is responsible.
The relationship with the digital product passport and the GDPR
Because the digital product passport for electronics records data on origin, materials and repair, there is in practice overlap with the documentation that the GPSR requires: both revolve around traceability of the product and the responsible party. Companies that address these two tracks separately often collect the same data twice from the same supplier. For personal data that plays a role in this, such as contact details of a responsible person, the ordinary GDPR rules apply in full; the GPSR does not change that. In the knowledge base per situation you can see how these subjects relate to each other.
What you can do with it
This regulation does not affect every company in the same way, and which documents exactly are needed depends on your role and the type of product. Supervisory authorities in the Netherlands and the EU look at the factual situation in case of doubt, not at a checklist that is the same everywhere. For an initial assessment of where your company stands, you can see where you stand in a few questions; for background on the data we use, read how the information is compiled. For your specific situation, a lawyer or the competent supervisory authority remains the appropriate point of contact.
Do you want to look broader than just this topic? Take the free quick scan or browse through the other topics in the knowledge base to see what is coming for your company.