As I understand it, The key bits of data are in the QR code, they are just encoded as a URL - a highly structured URL that point of sale systems can decode without visiting the URL.
Doing it this way means the QR code is directly usable by consumers to get to a product info / marketing page, and directly usable by the POS systems.
Edit: I looked it up. An example URL:
https://example.com/01/09521207311511/21/1234ABDE1235
01 is a marker before the traditional barcode.
21 is a marker before the serial number.
There seems to be many other codes like 17 (expiry date) and 10 (batch number).
It just encodes...codes?
We have the technology to encode a short, plain human-readable description of an item into a 2D barcode, with born-on and/or sell-by dates, and/or things like serialization and/or lot codes, or other useful things.
Brevity is important; fields can have a standardized-but-flexible format that fits the particular item's needs.
A single-quantity small Fuji apple, picked today (October 3, 2026), with a PLU of 4129, and a magic-number lot code of b29sF, distributed by Stemilt Growers might present as such:
Apple Fuji Sm,B0261003,P4129,Lb29sF,MStemilt
A single 1.5 liter bottle of Crystal Geyser spring water with a UPC of 07514000500, a best-by date of January 12 of 2028, and a lot code of kek67: Water Spring 1.5l,D0280112,U07514000500,Lkek67,MCG
We can even add more real information and still have less data to encode than: https://example.com/01/09521207311511/21/1234ABDE1235
...but, I mean: A coded URL for a website that might be designed to avoid being forthcoming with information isn't necessarily any better for consumers, long-term, than the UPC we've had for over 50 years. It's still just a pointer that relates to someone else's database. It has no informational value on its own.
This is correct. The canonical reference is: https://ref.gs1.org/standards/digital-link/uri-syntax/