SaltAISaltAI
Natasha's Law5 March 20269 min read

Why No Other Shopify App Covers Natasha's Law Compliance

Natasha's Law requires food businesses to provide full allergen information on PPDS food labels and online product pages. No generic Shopify app covers this. Allergen Matrix does.

Natasha's Law — the UK Food Information Amendment 2021 — came into force in October 2021. It requires food businesses producing pre-packed for direct sale (PPDS) food to label every item with the food's name and a full ingredient list with the 14 major allergens emphasised. For businesses selling PPDS food online, allergen information must also be available on the product page before the customer completes their purchase.

Four years after the law came into force, the Shopify app ecosystem still has no general-purpose app that addresses Natasha's Law compliance requirements. Here is why — and what food businesses should use instead.

What Natasha's Law Requires Online

For food businesses selling PPDS food through a Shopify store, Natasha's Law compliance requires:

Product page allergen information: Customers must be able to see full allergen information for every PPDS product before they add it to their cart. This means allergen declarations — not just dietary tags — must be visible on product pages.

Emphasis on the 14 allergens: When allergens appear in ingredient information, they must be emphasised — typically in bold, a different typeface, or a different colour. A plain text ingredient list with allergens not distinguished does not meet the requirement.

Accuracy and currency: Allergen information must accurately reflect the current product formulation. If a recipe changes, the allergen information must be updated. Stale allergen information that no longer reflects the product is a compliance failure.

PPDS label requirements: For the physical product labels on PPDS items, the legal requirements are separate from the online requirements — but the source data is the same. The allergen declarations on your Shopify product page must match the declarations on your physical labels.

Why Generic Shopify Apps Do Not Cover This

Generic Shopify apps that touch allergen-adjacent territory — dietary filter apps, nutrition display apps, label generation apps — were not built with Natasha's Law in mind. Specifically:

Dietary tags are not allergen declarations: A product tagged as "vegan" or "gluten-free" is not an allergen declaration under UK food law. These tags indicate dietary suitability; they do not constitute the legal allergen information requirement.

Static display is not management: An app that allows you to add a static allergen table to a product page handles display but not management. When a recipe changes, the table needs manual updating. There is no system to ensure it gets updated.

No regulatory framework awareness: Generic apps do not understand the distinction between Natasha's Law (UK PPDS), UK Food Information Regulations (online sales), and EU FIR 1169/2011. The allergen fields they provide may not map to the legal requirements of any specific regulation.

The Gap in the Shopify Ecosystem

Natasha's Law compliance requires three things working together: accurate allergen data at product level, that data displayed to customers before purchase, and a process for keeping it current when recipes change. No generic Shopify app provides all three.

The gap exists because Natasha's Law affects a specific segment of Shopify merchants — UK food businesses selling PPDS food online — and that segment is small enough that mainstream app developers have not prioritised it.

How the Problem Compounds as a Catalogue Grows

For a food business with a small catalogue — five or ten products — it is technically possible to manage allergen information manually through Shopify's native product description fields. A merchant can write ingredient lists by hand, bold the allergens, and update descriptions when recipes change. It is time-consuming and error-prone, but it is manageable at small scale. The problem is that manual processes do not scale, and they create exactly the kind of inconsistency that leads to compliance failures.

Once a catalogue reaches twenty, thirty, or fifty products, manual allergen management becomes a serious operational liability. Recipes change without the product description being updated. A new team member adds a product and formats the ingredient list differently. A seasonal product returns with a modified recipe and the old description is reused unchanged. None of these failures are deliberate — they are the predictable outcomes of relying on a manual process that has no built-in verification. For a food business, each one represents a potential enforcement trigger and, more importantly, a genuine risk to customers with allergies.

The structural problem is that Shopify's product description field was designed to hold marketing copy, not regulatory data. It has no concept of allergen status, no field validation, no change logging, and no way to enforce a consistent format across products. Using it for allergen compliance is a workaround, not a solution. As catalogues grow and teams expand, the gap between what the description field shows and what the product actually contains widens — silently, without any system alerting the merchant to the discrepancy.

What Happens When a Recipe Changes

Recipe changes are one of the most significant compliance risks for food businesses operating online. When an ingredient is swapped — whether to address a supply chain issue, reduce cost, improve shelf life, or refine flavour — the allergen profile of the product may change. A new ingredient may introduce an allergen that was previously absent. A reformulation may remove an allergen that was previously declared. Either scenario requires the product page allergen information to be updated immediately, before the next customer views the product.

Without a structured allergen management system, there is no automatic connection between a recipe change and a product page update. The merchant — or someone on their team — needs to remember to update the Shopify product description, remember to re-bold the allergens in the new ingredient list, and remember to check that the physical label order reflects the same changes. These are three separate manual steps, each of which can be missed. In a small business environment where the person changing the recipe and the person managing the Shopify store may be the same individual wearing many hats, the risk of a missed update is real and persistent.

The legal exposure from a recipe change that is not reflected online is significant. A customer with a sesame allergy who purchases a product based on an allergen declaration that no longer reflects the current formulation has not been given the information the law requires them to have. The merchant's liability in that scenario does not diminish because the update was simply forgotten. Natasha's Law does not provide a good-faith defence for inaccurate allergen information — accuracy is the requirement, not intent.

Understanding the 14 Allergens and Why All Must Be Declared

UK food law specifies 14 major allergens that must be declared when present in food: celery, cereals containing gluten, crustaceans, eggs, fish, lupin, milk, molluscs, mustard, peanuts, sesame, soybeans, sulphur dioxide and sulphites, and tree nuts. For PPDS food, all 14 must be considered for every product and declared appropriately — not just the ones most commonly associated with the product category. A bakery product that contains no obvious fish or crustacean ingredients still requires a considered declaration for those allergens, even if the declaration is simply that they are absent.

The emphasis requirement applies specifically to allergens that are present in the product. When an allergen appears in the ingredient list, it must be visually distinguished from the surrounding text — through bold type, capitalisation, italics, or a contrasting colour. This is not a stylistic choice; it is a legal requirement intended to make it easy for customers with allergies to identify relevant allergens quickly. A merchant who lists all ingredients in plain text without any emphasis does not meet the requirement, even if every allergen is technically named somewhere in the ingredient list.

May-contain declarations — sometimes called precautionary allergen labelling — are not mandated by Natasha's Law but are common in practice where cross-contamination risk exists. Businesses should apply these consistently and only where genuine cross-contamination risk has been assessed, not as a blanket disclaimer. Over-applying may-contain warnings undermines their usefulness for allergic consumers and does not substitute for accurate declared allergen information. A structured allergen management tool like Allergen Matrix supports accurate distinction between declared allergens and precautionary labelling at the product level.

What Allergen Matrix Provides for Natasha's Law Compliance

Allergen Matrix was built with UK food law compliance requirements as a core design principle:

Structured allergen records: Every product has a complete allergen record covering all 14 UK allergens with declared status (present, may contain, absent). These records are the source of truth for all downstream compliance.

Customer-facing allergen display: Allergen Matrix generates Natasha's Law compliant allergen information on Shopify product pages — with emphasis on declared allergens, filterable by dietary requirement.

Recipe change management: When a recipe changes, the allergen record is updated in Allergen Matrix. The product page updates automatically. There is no manual display update required.

Audit trail: Every record change is logged. This documentation supports regulatory inspection and demonstrates that allergen management processes are in place.

Label generation support: Allergen data in Allergen Matrix can be exported in formats suitable for physical label generation, ensuring product page and physical label allergen information stays aligned.

The Enforcement Reality

Food Standards Agency and Trading Standards have powers to investigate food businesses for allergen compliance failures. Enforcement actions — from improvement notices to prosecutions — are documented on the FSA website. The most common triggers include allergen information that is absent, inaccurate, or not accessible before purchase.

For a food business selling on Shopify, the question is not whether Natasha's Law applies — it does if you sell PPDS food online. The question is whether your Shopify setup meets the requirements. Without a tool specifically designed for this purpose, the honest answer is probably not fully.

Try Allergen Matrix free at saltai.app — no credit card required.

Implement Natasha's Law compliance on your Shopify store with Allergen Matrix at saltai.app

SaltAI Team

SaltAI builds focused Shopify apps for food merchants and general merchants. Every app is tested in production at a real food store — including Vanda's Kitchen — before it ships.