Skip to content

Industry Guide › Supply Chain Transparency and Traceability

Data Management and Blockchain in Cashew Supply Chains

Banner showing four cashew traceability technologies: QR codes, RFID tags, lot databases and distributed ledgers.

The Tools: What Each Technology Actually Does

The second module of Part 1 of this industry guide covered the protocols that govern how traceability information moves between parties in a cashew supply chain - the rules about lot identifiers, handover data fields, and audit-trail responsibility. This module covers the technology layer: the digital tools used to capture, store, transfer and verify that information in practice.

Four categories of technology are relevant to cashew traceability, and it’s worth clarifying what each does before assessing where it fits.

1. QR Codes (Quick Response Codes)

These are machine-readable labels that encode a string of data and can be scanned by a smartphone or dedicated reader. A QR code can store various types of information: a unique identifier, a URL, a GS1 Digital Link or a serial number. In most industrial traceability systems, however, the QR code stores only a unique identifier or URL that links to a database where the full traceability record is maintained. The database, not the code itself, holds the origin, processing and certification information that makes traceability useful.

2. RFID (Radio Frequency Identification) Tags

RFID tags contain a microchip and antenna that transmit data to a reader without requiring line-of-sight contact. Unlike QR codes, RFID tags can be read at a distance and in bulk, making them useful for automated scanning at gates, loading bays or checkpoints. They’re more expensive per unit than QR codes and require compatible reader infrastructure.

3. Lot Databases

These are centralised or cloud-based systems that hold the traceability records associated with each lot identifier. When someone scans a QR code or reads an RFID tag, they're retrieving data from a lot database. The database is where the actual work of traceability happens: recording what happened to a lot, when, and who was responsible. In cashew supply chains, the data held against a lot typically includes food safety testing results (such as aflatoxin levels, moisture content, Salmonella screening, pesticide residue analysis and metal detection outcomes) alongside origin, processing date, grade and certification status. The completeness and currency of this data is what determines whether a lot record is genuinely useful in an audit or incident response, or simply a timestamp with a location.

4. Distributed Ledgers (Commonly Called Blockchain)

These are databases where records are stored across multiple independent nodes rather than in a single centralised system. Each record is cryptographically linked to the one before it, making retrospective alteration detectable. In a supply chain context, multiple parties - farmer, processor, exporter, buyer - can access the same record without any single party controlling it. In practice, most enterprise blockchain implementations use role-based permissions: some participants can read records, others can submit transactions through approved interfaces, and write access is typically restricted rather than open to all. The shared, tamper-evident record remains the core benefit; equal access for all parties is not a given.

These four tools are not alternatives to each other. They operate at different layers and are typically used in combination - a point returned to throughout this module.

What QR codes, RFID, lot databases and blockchain do in cashew traceability, and their main limits
Tool What it does Main strength Main limit
QR codes Machine-readable label storing a unique identifier or URL that links to a lot database Low cost; works on standard smartphones Must be scanned deliberately; only as reliable as the database it points to
RFID tags Microchip and antenna that transmit data to a reader without line-of-sight contact Read at a distance and in bulk Higher cost per unit than QR labels; needs reader infrastructure
Lot databases Hold the traceability record for each lot identifier Where the work of traceability happens Only as accurate as the data entered
Distributed ledgers (blockchain) Records stored across independent nodes, each cryptographically linked to the one before Tamper-evident record shared by several parties No mechanism to verify data accuracy at the point of entry

Source: Cashew Coast Industry Guide, module 1.3; FAO and IFAD assessment of blockchain for agriculture.

QR Codes and Lot Databases: The Workhorse Combination

For most cashew traceability systems in use today, the practical workhorse is a QR code linked to a centralised lot database. This combination is relatively low-cost to implement, works on standard smartphones without specialist hardware, and is sufficient to meet the traceability expectations of most European buyers and certification auditors.

A typical implementation may assign a QR code to each lot at the point of packing or export, though many processors assign identifiers earlier in the process: at goods receiving, warehouse intake, processing batch, or roasting stage. Scanning the code retrieves the lot record from the database, which may include origin, processing date, grade, certification status, and any quality testing results associated with that shipment. For buyers conducting due diligence or auditors verifying certification claims, this provides a fast and accessible trace-back route.

One dimension that a basic QR-and-database implementation needs to account for is lot genealogy: the parent-child relationships between incoming and outgoing lots. Cashew processing involves many-to-many lot relationships: a single incoming RCN (raw cashew nut) lot may be processed into multiple output streams - WW320, WW240, SP, LP kernels, shell, testa - while multiple incoming RCN lots may simultaneously be merged into a single production batch. A traceability system that records only the final output lot without capturing these upstream relationships can't answer the full trace-back question: which farms or cooperatives contributed to this shipment, and which other shipments contain material from the same origin lot? Any serious cashew traceability programme needs to record these parent-child lot relationships explicitly, not just the end-point lot identifier.

The limits of this combination are worth stating clearly. The QR code is only as reliable as the database it points to, and the database is only as accurate as the data entered into it. If a cooperative records incorrect origin information at the aggregation stage, or a processor logs the wrong processing date, the QR code will return that incorrect information to anyone who scans it. The technology provides no mechanism for verifying that the data is true, only that it exists and is retrievable.

A second limit is that QR codes require deliberate scanning. They don’t automatically log when a unit moves between locations or changes hands, which means gaps in the audit trail can develop if scanning discipline is inconsistent along the chain.

Despite these limits, QR codes and lot databases remain the most practical starting point for cashew processors building or upgrading a traceability system, particularly where budget, infrastructure and staff capacity are constrained.

RFID: When Automated Tracking Pays Off

RFID offers something QR codes can’t: automated, contactless reading of multiple units simultaneously, without requiring a person to scan each one individually. At a warehouse gate or loading bay equipped with RFID readers, an entire pallet load can be logged in seconds as it passes through, with the data written automatically to the lot database.

For cashew supply chains, the case for RFID is strongest at high-volume processing and export facilities where manual scanning creates bottlenecks, where the cost of a missed scan is high (for example in a bonded warehouse or a facility under continuous certification audit), or where the unit value of the product justifies the additional cost per tag.

The cost-per-unit consideration matters in commodity contexts. RFID tags come in two main types: passive tags, which have no internal power source and are activated by the reader's electromagnetic field, and active tags, which carry their own battery and can transmit over longer distances. Industrial food traceability systems almost exclusively use passive RFID, which is significantly cheaper than active tags but still costs more per unit than QR code labels. Reader infrastructure adds a further capital outlay.

For a high-volume processor shipping large export containers, the cost may be justified by the reduction in manual handling and the improvement in scan completeness. For smaller cooperatives or buying agents operating at the farm-aggregation stage, the economics are usually less straightforward, and QR codes or paper records at that stage may be more practical.

RFID also requires that tags survive the physical conditions of the cashew supply chain: humidity, heat, pressure in packed containers, and sometimes extended periods in storage. Tag selection and placement need to account for these conditions, and implementation should be tested under realistic field conditions before full deployment. A standard engineering consideration worth noting is that RFID signal performance can be affected by proximity to metal surfaces and liquids. Neither presents a significant issue for dry cashew kernels in standard packaging, but it is a relevant factor in facility design and tag placement decisions.

Blockchain in Commodity Supply Chains: Promise vs Reality

Blockchain has been applied to agricultural traceability in a range of contexts, and the results have been mixed enough to warrant a measured assessment of what it does and doesn’t solve before committing to a blockchain-based platform.

What Blockchain Addresses

In a multi-party supply chain where no single organisation controls all the records, a distributed ledger provides tamper-evident, independently verifiable documentation. Records are cryptographically linked so that unauthorised changes are detectable. In permissioned blockchain systems commonly used for enterprise supply chains - such as Hyperledger Fabric - integrity is maintained through distributed validation and access controls rather than reliance on a single central database.

For buyers or regulators who want assurance that a traceability record has not been modified after the fact, this is meaningful. It's also useful where multiple parties - a processor, an exporter, a certification body and a buyer - need to write to and read from the same record without any single party being able to unilaterally alter the shared history. In practice, most enterprise implementations use role-based permissions: some participants can read records, others can submit transactions through approved interfaces, and write access is typically restricted rather than open to all. The shared, tamper-evident record remains the core benefit; equal access for all parties is not a given.

What Blockchain Doesn’t Address

The most important limitation is that blockchain has no mechanism for verifying the accuracy of data at the point of entry. If a farmer records an incorrect harvest date, or a processor logs a quantity that doesn’t reflect what was actually packed, that inaccurate data is written to the ledger with the same tamper-evidence as accurate data.

The phrase commonly used in this context is ‘garbage in, garbage out,’ and it applies regardless of how sophisticated the ledger technology is. Blockchain makes it harder to alter records after the fact, but it doesn’t make it easier to ensure they were correct in the first place.

Blockchain in cashew traceability: garbage in, garbage out. Blockchain makes it harder to alter records after the fact, but it doesn’t make it easier to ensure they were correct in the first place.

A related issue is that many blockchain implementations in agricultural supply chains have not delivered the transparency they set out to provide. Protocol gaps of the kind covered in module 1.2 are one reason: inconsistent lot identifiers and incomplete handover data produce a tamper-evident record of an unreliable system regardless of how sophisticated the ledger technology is.

But implementations have also failed due to governance weaknesses, misaligned incentives between supply chain participants, and business models that didn't sustain engagement beyond the pilot phase. Even a well-designed protocol layer won't save an implementation where the participating organisations can't agree on who owns the data, who pays for the infrastructure, or what they each get from the arrangement.

FAO and IFAD's joint assessment of blockchain for agriculture documents both the potential and the implementation failures in detail, and is worth reviewing before choosing a blockchain-based platform.

The EU Digital Product Passport initiative, and the European Business Wallet infrastructure under development alongside it, are relevant context for cashew traceability system design, though with an important qualification: the Digital Product Passport currently focuses on products covered by the Ecodesign for Sustainable Products Regulation: primarily textiles, electronics and batteries. Food commodities including cashew are not within the current DPP scope but it’s indirectly relevant as the DPP is establishing a data architecture and interoperability standard for product-level sustainability information that may influence how traceability requirements are structured in adjacent regulatory frameworks over time. Both initiatives are still developing, and any direct implications for cashew supply chains remain undefined. This is therefore an area worth monitoring rather than acting on now.

System Integration: The Layer That Decides Success

The choice of traceability technology is rarely the factor that determines whether a system succeeds. More often, success or failure is decided by how well the traceability platform integrates with the other systems it needs to communicate with.

For a cashew processor, this typically means integration with an ERP (Enterprise Resource Planning) system that manages production orders, inventory and dispatch records; a quality management system that holds testing results and certification documentation; and potentially a customer portal through which buyers can retrieve lot records or certification evidence. How those records are evaluated by buyers is covered in module 1.6, Metrics for Trust.

Diagram of a cashew processor's traceability platform linked to its ERP, quality system and customer portal.
In cashew processing, connecting the traceability platform to ERP, quality management and customer-facing systems decides whether it works day to day. Source: Cashew Coast Industry Guide, module 1.3.

Where these systems are not integrated, traceability data has to be manually transferred between them, reintroducing the transcription errors that digital systems are supposed to eliminate. A processor might have a functioning traceability platform that captures accurate lot data at the packing stage, but if that data is manually re-entered into the ERP for stock management and the customer portal for buyer access, the chain of custody is only as reliable as those manual transfer steps.

Common integration issues include data format mismatches between systems, where lot identifier formats that work in the traceability platform are not recognised by the ERP; timing gaps, where traceability records are updated in batches rather than in real time, creating a lag during which a buyer query cannot be answered; and access control issues, where buyer-facing portals can’t selectively expose lot data without also exposing commercially sensitive information.

Integration work is frequently underestimated in project planning. Budgets and timelines that account for the technology but not the integration tend to produce systems that work in demonstration conditions, but underperform in daily operations.

Data Governance: Ownership, Access and Retention

Technology selection and system integration get most of the attention in traceability projects, but data governance - the rules governing who owns, can access, can edit and must retain the data - is increasingly where food companies focus their concern. The question 'who owns my supplier data?' is more practically pressing for many operators than any choice between blockchain and a lot database.

Data Ownership

In a multi-party traceability system, ownership of the data generated at each stage of the supply chain is rarely defined by default. A processor who inputs lot-level data into a buyer-owned platform may find that data is accessible to the buyer's other suppliers, used for benchmarking without consent, or retained after the commercial relationship ends. Defining data ownership explicitly in commercial agreements and platform terms before implementation begins is more straightforward than attempting to renegotiate it after data has already been shared.

Access and Edit Rights

Role-based access controls - determining who can read, submit or edit records - are a governance requirement as much as a technical one. The practical questions are: which parties in the supply chain can see which records, under what conditions can records be amended after the fact, and is there an audit trail of who made changes and when? These questions need documented answers before a system goes live, not after an access dispute arises.

Retention Periods and Backups

Food safety regulations in most markets specify minimum record retention periods, typically two years under EU General Food Law, though specific requirements vary by product category and market. A traceability system needs to retain records for at least the legally required period, with backup procedures that ensure records survive platform changes, vendor transitions or system failures. The vendor lock-in risk discussed earlier is directly relevant here: a platform that stores data in a proprietary format may make it difficult to retrieve records if the commercial relationship with the vendor ends.

GDPR and Personal Data

Where traceability records include personal data (farmer names, cooperative member details, individual employee records) GDPR obligations apply to EU-facing supply chains. This includes data minimisation (collecting only what's necessary), defined retention limits and documented lawful basis for processing. In practice, many cashew traceability systems collect more personal data than they need, often because farmer registration forms are designed for cooperative management rather than traceability purposes.

Commercial Confidentiality

Supplier lists, origin volumes and quality testing results are commercially sensitive. A traceability platform that makes this data visible to buyers, certification bodies or other supply chain participants without explicit consent creates competitive exposure. Confidentiality provisions need to be defined at the platform design stage, not managed retrospectively through contractual workarounds.

Operating in Low-Connectivity Environments

A traceability system that depends on continuous internet connectivity will encounter practical problems in cashew-producing regions where connectivity is intermittent or unreliable. This isn’t a reason to avoid digital traceability, but it’s a design constraint that should be addressed early rather than discovered during implementation.

Offline-capable systems, where data is captured locally on a device and synchronised to the central database when connectivity is available, are generally more suitable for farm and cooperative-level data capture than systems that require a live connection at the point of entry. The synchronisation process needs to handle conflicts, where the same lot has been updated by multiple parties during an offline period, and needs to be auditable so that the timing of each entry can be verified.

QR codes work well in low-connectivity environments for the capture step, since generating and printing a code doesn’t require internet access. The retrieval step, scanning a code to access the lot record, does require connectivity, which means that offline operation needs to be accounted for at the database access layer, as well as the data capture layer.

RFID in low-connectivity environments adds a further consideration: reader infrastructure typically requires power and, in automated configurations, network connectivity to write scan events to the database in real time. Ruggedised, store-and-forward RFID readers exist for this purpose but add to implementation cost and complexity.

The World Bank's digital agriculture research documents connectivity conditions and digital infrastructure across a range of agricultural producing countries, and provides a useful reference for assessing what's realistic in a given context before committing to a technology approach.

Cost, ROI, and How to Decide

The return on traceability investment in cashew rarely comes from a higher selling price. It tends to show up elsewhere: in reduced recall scope when a contamination incident occurs, in lower audit preparation time when a certification body or buyer requests documentation, in fewer customer complaints when lot-level records can answer provenance questions quickly, and in reduced labour costs as manual record-keeping is replaced by digital capture. These returns are real but often indirect and delayed, which is one reason traceability investment is underestimated in project planning; the cost is visible upfront and the benefit arrives in the form of problems that don't occur.

With that context in mind, technology selection in cashew traceability is a question of which combination of tools, at which stages of the chain, delivers the required traceability outcomes at a cost the operation can sustain. A practical decision framework might start with the following questions.

What does the buyer actually need? Some buyers require full farm-to-export traceability with digital lot records; others require certification documentation and a paper audit trail. Understanding the specific requirements before selecting technology avoids over-engineering.

Where are the highest-risk handover points? The stages where data is most likely to be lost, altered, or incorrectly recorded are the stages where investment in more reliable capture and verification is most justified. For many cashew supply chains, this is the cooperative aggregation stage, where multiple farm-level lots are combined and individual origin links can be lost.

What infrastructure exists, and what needs to be built? A technology that requires hardware a supplier can’t maintain, connectivity a region cannot reliably provide, or staff training that exceeds available capacity isn’t a practical solution, regardless of its technical merits.

What is the total cost of ownership? Licensing fees, hardware, implementation, integration, training and ongoing maintenance all need to be accounted for, and technology vendors' pricing structures are rarely straightforward, with costs that can escalate significantly as usage scales or contract terms change. Pilots are useful for stress-testing cost assumptions under real operating conditions before committing to full deployment.

What can be phased? As established in module 1.2, phased adoption is more common than full-chain rollouts implemented all at once. A decision framework that identifies a first phase, with clear criteria for what a successful pilot looks like, is more useful than a comprehensive technology roadmap that can’t be funded or staffed in the near term.

Can the system be ported? A traceability platform that locks data into a proprietary format or makes migration to another provider costly creates long-term dependency on a single vendor. Preferring open-source systems or platforms that export data in standard formats gives operators the flexibility to reassess providers as costs and capabilities evolve, and to fully leverage existing systems before adding new ones.

Cashew Coast's own implementation followed this pattern. The process began with small-scale tests before expanding along value chain segments in sequence: supply side first, where traceability starts, then the marketing and sales team, then the factory floor, the most complex phase.

Each segment used the system most appropriate to it: SAP for supply chain management, HubSpot for the commercial team. The final and most demanding step was connecting these systems so they could share data; what practitioners sometimes call the last mile of integration. The broader lesson is that data infrastructure grows alongside the implementation plan rather than being designed in full at the outset.

Common Pitfalls in Technology Selection

Several recurring mistakes affect traceability technology projects in agricultural supply chains, and cashew supply chains are no exception.

Buying the Platform Before the Protocol

The most common error is selecting and implementing a traceability technology before the underlying protocol is in place. If lot identifiers are not consistent, if handover data fields are not agreed, and if audit-trail responsibility isn’t assigned, a digital platform will automate the same gaps that existed on paper. Module 1.2 covers what needs to be in place at the protocol level before technology selection becomes meaningful.

Over-Engineering for the Current Requirement

Blockchain implementations have been deployed in cashew and other nut supply chains where a QR code linked to a lot database would have met the buyer's actual requirements at a fraction of the cost and complexity. The right question is not what the most advanced technology available is, but what a specific buyer needs and what is the simplest system that reliably delivers it.

Assuming Connectivity

Systems designed for well-connected environments that are then deployed in producing regions with intermittent connectivity tend to either fail silently, losing data that was never successfully synchronised, or generate workarounds that undermine the purpose of digital capture. Connectivity should be assessed and documented before system design is finalised.

Underestimating Integration Work

As discussed above, the cost and complexity of connecting a traceability platform to existing ERP, quality management and customer-facing systems is frequently underestimated. ERP systems commonly used in food and agricultural businesses include SAP, Microsoft Dynamics and Odoo, each with different data structures and integration requirements. Projects that treat integration as an afterthought tend to produce systems that work in isolation but create more manual work overall.

Locking into a single vendor

Proprietary platforms that store data in formats that can't be easily exported or migrated create long-term dependency that can become costly as vendor pricing changes. Open-source systems, or platforms that support standard data formats, reduce this risk. It's also worth assessing whether existing systems (such as ERP, cooperative management tools, certification databases) are being used to their full capability before adding a new platform. The most cost-effective traceability investment is often a more thorough implementation of infrastructure already in place.

Treating Technology as the End Point

A traceability system that captures accurate data reliably and makes it retrievable on request has done its job. The goal is to be able to answer a buyer's or auditor's trace-back query accurately and quickly. Technology is the means, and keeping that distinction clear helps avoid investment in capability that serves the system rather than the outcome. The wider sustainability and ESG context in which traceability data is increasingly used is covered in Part 2, Sustainability and Regenerative Practices.

Continue to module 1.4, Case Studies: Resilience During Global Disruptions, for real-world examples of these tools in use.

For enquiries about contributing traceability or food safety standards data or case studies, or to request expert comment, please get in touch.

Evidence and methodology: you can learn about our source vetting standards, data attribution policy, editorial independence and amendment policy here.