Primi Tecnologia: How UK Brands Can Beat Counterfeiters

Counterfeiting cost Brazil R$ 473 billion in 2025. The physical seal is only a third of the solution—the rest is serialised codes, APIs, and logs.

by Cleverson Gouvêa

Primi Tecnologia: How UK Brands Can Beat Counterfeiters

Primi Tecnologia caught the attention of Brazilian searchers the same week the National Forum Against Piracy and Illegality released a figure hard to ignore: R$ 473 billion lost to the illegal market in 2025. It's no coincidence. When counterfeiting makes headlines, companies rush to get seals, traceability, and proof of authenticity—only to discover that the expensive part isn't the sticker. It's the system behind it.

TL;DR

  • Primi Tecnologia is a Brazilian security printing and RFID/IoT identification company based in Santana de Parnaíba (SP).
  • The illegal market cost Brazil between R$ 473 billion (FNCP) and R$ 514 billion (ABCF) in 2025—the difference is methodology, not error.
  • Inmetro and GS1 have already pushed traceability digital: QR Code seals printed by the Brazilian Mint, mandatory unique identification for footwear, and 2D codes at retail by 2027.
  • The physical seal solves maybe a third of the problem. The rest is a verification endpoint, serialised database, logs, and a customer service channel.
  • If your company sells branded products and doesn't have a public authenticity verification page, you're leaving the answer in the hands of the counterfeiter.

Primi Tecnologia presents itself as a security technology company: it produces holographic seals, authenticity seals, traceability seals, tickets, event wristbands, diplomas, and certificates. It is based in Santana de Parnaíba, in Greater São Paulo, and serves cosmetics, food and beverages, the chemical industry, and government bodies.

What separates this type of supplier from an ordinary print shop is the stack of certifications. Primi Tecnologia declares ISO 9001 (quality), ISO 14001 (environment), ISO 27001 (information security), ISO 45001 (occupational health and safety), and NBR 15540—the specific Brazilian standard for security printing. ISO 27001 in a print shop is not a footnote decoration: it means that your seal file, exactly what the counterfeiter wants, is treated as an information asset with access control and audit trail.

The company also has seven Fernando Pini awards for printing excellence and maintains a line called Primi ID, described as identity management with RFID and IoT. In practice, the label stops being just a seal and becomes an addressable object: radio-frequency reading for access control, anti-theft, and material flow.

None of this was born this week. What changed was the context. Counterfeiting became a daily topic in Brazil, and a technical name that previously only circulated in industry purchasing departments began to be searched by people who have never bought a seal in their lives.

It's worth making the distinction that no one makes in sales: Primi Tecnologia sells the security item and radio-frequency identification. It does not deliver the website that responds to the consumer when they read the code. That piece is yours—and it's where the project usually stops.

R$ 473 billion or R$ 514 billion? Why the numbers don't match

On 5 August 2026, the National Forum Against Piracy and Illegality (FNCP) announced that the illegal market—smuggling, counterfeiting, piracy, and tax evasion—caused losses of R$ 473 billion in Brazil in 2025, combining industry losses and tax evasion across 15 sectors. That's a 64% increase in five years.

Three months earlier, on 27 May, the Brazilian Association for Combating Counterfeiting (ABCF) published its 2026 Counterfeiting Yearbook with a different figure: R$ 514 billion in 2025, 8% above 2024. The ranking by sector:

Sector Estimated loss in 2025
Alcoholic beverages R$ 89.5 billion
Clothing R$ 55 billion
Fuels R$ 30 billion

The difference between the two studies is not a contradiction: they are different sectoral scopes and methodologies. Use either one, but cite the source. And be wary of a supplier that throws a round number in a sales presentation without saying where it came from.

The most uncomfortable figure in the ABCF yearbook is the estimate that 36% of alcoholic beverages sold in the country are counterfeit. Between September and December 2025, the methanol poisoning outbreak resulted in 22 confirmed deaths. In this sector, traceability stopped being a marketing topic and became a matter of autopsies.

Real traceability has three layers

Serious suppliers like Primi Tecnologia deliver the first layer well, and the sales material usually stops there. Those who have implemented it know there are three layers, and that the third is the one that breaks schedules.

Physical layer: make copying expensive

Holograms, reactive ink, microtext, destructive tamper-evident seals that shatter on removal. The goal was never to be impossible to copy—it was to make copying too expensive to be worthwhile. A counterfeiter is an economic agent: they abandon the product when the margin disappears.

Identification layer: each unit with a unique code

This is where most go wrong. A beautiful, identical seal on a million units doesn't track anything—it only confirms that someone bought seals. Traceability requires serialisation: a unique number per unit, encoded in a QR Code, DataMatrix, or RFID/NFC chip, with a map of which series went to which batch, which distributor, which state.

Digital layer: the endpoint that answers "is it original?"

The consumer points the camera. Something needs to respond in under two seconds. That "something" is an API, a database, and a public page—and it's exactly the piece no one budgeted for. Remember that this endpoint becomes a target: it's software exposed to the internet, with all the supply chain risk we discussed in the case of the NPM packages infected by Shai-Hulud.

Inmetro and GS1: the regulatory calendar has already started

If you think you can delay, look at the dates. Inmetro replaced the traditional conformity seal with a digitalised model, with a QR Code printed by the Brazilian Mint and verification via the free app "Inmetro Na Palma da Mão", which shows manufacturer, technical standards, and validity. The first phase covered motorcycle helmets, fire extinguishers, and CNG cylinders, with lamps, electrical wires, auto parts, mattresses, lighters, and pressure cookers in the queue.

In footwear, Ordinance No. 459/2025 made unique product identification mandatory. The original deadline was 31 July 2026, and it was extended, at the request of Abicalçados, to 31 December 2026—news published on 3 August 2026.

Front Requirement Deadline
Inmetro (phase 1) Digital seal with QR Code from the Mint In force
Inmetro — Ordinance 459/2025 Unique identification of footwear 31/12/2026
GS1 Sunrise 2027 GS1 standard QR Code read at the point of sale End of 2027
PL 3375/24 (Chamber) Penalty of 2 to 4 years for trademark counterfeiting In progress

The GS1 Sunrise 2027 initiative is the most structural: by the end of 2027, the 2D code must be universally scannable at the point of sale, alongside the traditional EAN-13. While the EAN carries only the GTIN, the GS1 standard QR Code carries batch, expiry, origin, and a link for the consumer. It's the definitive fusion of label and web page.

In the criminal field, PL 3375/24, approved in a Chamber committee, raises the penalty for improper reproduction of a registered trademark from three months to one year to two to four years.

The reading for manufacturers is direct: the seal that Primi Tecnologia and its competitors print will come with a mandatory unique code, and someone will need to answer for that code on the internet.

Where projects stall: the software

I've seen the script repeat. The company signs the seal contract with Primi Tecnologia or a competitor, receives the rolls, applies them on the production line—and only then discovers that the QR Code needs to point somewhere. Then comes improvisation: a spreadsheet on Drive, a link to the brand's Instagram, a static page that says "original product" for any code, including invented ones.

A page that always answers "original" is worse than having no page. It teaches consumers to trust a test that tests nothing, and gives counterfeiters a free stamp of approval.

The minimum digital layer that works has five pieces: a database with the serialised codes issued, a query API with rate limiting, a public result page, a log of every reading (date, time, IP, approximate geolocation), and an internal alert dashboard. The log is the most underestimated asset of the set: if the same code was read 4,000 times in nine states in the same month, you don't have a very popular original product—you have an industrial-scale clone, and you know where it is.

This dashboard is a security system like any other, with the same credential and audit requirements we discussed when analysing the attack via malicious VS Code extension on GitHub.

How to build the digital layer in six steps

Suppliers like Primi Tecnologia handle the physical side well. The order below is what's usually missing on the software side, and it applies both to industry and to e-commerce brands that outsource production.

  1. Define the granularity before buying seals. Tracking by batch is cheap and detects channel diversion. Tracking by unit is expensive and detects cloning. These are different and irreversible decisions after purchase.
  2. Generate the codes yourself, not the supplier. Use non-sequential, non-guessable identifiers (UUIDv4 or truncated hash). A numeric sequence is an invitation: the counterfeiter prints from 1 to 100,000 and gets them all right.
  3. Put the verification endpoint up before the first roll. Short URL, HTTPS, response in under two seconds, working on poor 3G. If the consumer needs to install an app, the verification rate plummets.
  4. Write the negative response carefully. "Code not found" is not the same as "fake product". Explain what to do, offer a contact channel, and capture a photo of the product.
  5. Log everything and alert by default. Repeated readings, readings outside the distribution region, sudden spikes. An automated agent—along the lines of what we described in AI agents for businesses—handles initial triage without a human on call.
  6. Close the loop with legal. Logs with date, time, and location become evidence. Agree in advance with whoever will use it: format, retention, and chain of custody.

Five mistakes that kill a traceability project

  • Identical seal on everything. Without serialisation, there is no traceability—there is decoration.
  • QR Code pointing to the website home page. The consumer doesn't want to learn about the brand; they want to know if the bottle in their hand is genuine.
  • Verification behind a login. No one creates an account to check a jar of cream. Verification is public or it doesn't happen.
  • Ignoring repeated readings. It's the cheapest and most reliable sign of cloning, and almost everyone throws it away.
  • Treating the dashboard as a marketing project. It's security infrastructure. It needs backup, access control, and a named responsible person.

WhatsApp: the channel where reports actually arrive

QR Code verification answers yes or no. What comes next—"I bought it at such a store", "the box was tampered with", "I have a photo"—needs a conversation. In Brazil, that conversation happens on WhatsApp.

A flow that works: the negative result page opens WhatsApp with a pre-filled message containing the code read. The consumer just presses send. On the other side, customer service already receives the context and asks for photos. In two weeks, you have a map of suspicious points of sale that no field audit would deliver in the same timeframe.

For significant volume, this requires the official API, not the regular app—the difference between the two models is detailed in WhatsApp Business App vs Official API. With the official API, you can automate triage, classify by region, and trigger internal alerts when the same address appears three times.

Where to start

If the topic reached you because of Primi Tecnologia or any other security printing supplier, the recommendation is simple: ask for two separate quotes. One for the seal, another for the digital layer. Compare the timelines. If the digital layer won't be ready when the roll arrives, delay the seal purchase—not the other way around.

A good security printing supplier, whether Primi Tecnologia or any other, will ask you what granularity you want to track. Arrive at the meeting with the answer ready and the verification endpoint already specified. This single change of order saves months.

At Agathas Web, I've been developing custom systems for industry, education, and services since 2008, and the architecture of an authenticity verifier is well known: serialised database, public API with rate limiting, lightweight page, and WhatsApp integration. The hard work isn't technical. It's deciding, before printing a million stickers, what exactly you want to be able to prove.