In this article:

Digital Product Passport: What It Is and What the EU Requires

Compliance
/
October 1, 2026
Digital Product Passport: What It Is and What the EU Requires

A digital product passport (DPP) is a structured digital record of a product's identity, materials, repair, and compliance data, reached by scanning a data carrier such as a QR code. The Ecodesign for Sustainable Products Regulation (ESPR), Regulation (EU) 2024/1781, sets the rules in Articles 9 to 15, and each ESPR delegated act decides which products need a passport. The Battery, Toy Safety, and Detergents Regulations add passport duties of their own.

The Commission cited six harmonized DPP standards in the Official Journal on July 15, 2026 and opened the EU DPP registry on July 20, 2026. The first mandatory passports, for electric vehicle, light means of transport, and industrial batteries above 2 kWh, apply from February 18, 2027.

What a digital product passport contains

No single EU dataset defines a passport. The required content changes with the product category, the regulation that applies, the passport's granularity, and the access rights each stakeholder group holds. Article 9(2)(a) of the ESPR has each delegated act specify "the data to be included in the digital product passport pursuant to Annex III." The Joint Research Centre's March 2026 DPP methodology report maps Annex III to identification data such as the unique product identifier and manufacturer and operator details, compliance documentation such as declarations of conformity, and user manuals, warnings, and safety information. The rest comes from Article 7: performance information on parameters such as durability and repairability; instructions for installation, use, maintenance, and repair; information for treatment facilities; and the substances of concern that Article 7(5) requires operators to track.

Depending on the rules that apply to a product, a passport draws on eight categories of data.

CategoryWhat it can includeWhere the requirement comes from
Product identityProduct name, model, batch or serial number, unique identifiers, manufacturer, and the responsible economic operatorAnnex III identification data; ESPR Article 12
Materials and componentsComposition, critical raw materials, recycled content, substances of concern, and component relationshipsArticle 7(5) for substances of concern; recycled content is an Article 5(1) parameter
SustainabilityCarbon or environmental footprint, energy performance, resource efficiency, and category-specific measuresArticle 7(2)(b)(i) performance information
Durability and performanceExpected lifetime, performance characteristics, warranties, and test information where requiredArticle 7(2)(b)(i), which names a durability score
Repair and circularityRepair instructions, compatible spare parts, disassembly, reuse, remanufacturing, and recyclability guidanceArticle 7(2)(b)(i) and (ii), including a repairability score
Compliance documentationDeclarations of conformity, certificates, safety information, technical documentation, and regulatory markingsAnnex III compliance and user information data
Supply chainFacility, sourcing, due diligence, custody, or provenance data where the product rules require itAnnex III and Article 12 facility identifiers; sector laws
End-of-life guidanceSafe handling, collection, disposal, material recovery, and recycling instructionsArticle 7(2)(b)(iii) information for treatment facilities

The Commission's DPP FAQ allows voluntary data points as long as the passport keeps them clearly separate from the mandatory ones. Where a separate delegated act covers a component, that component may need its own passport, linked to the product's passport, according to the Commission's 2024 ESPR FAQ. The JRC report adds that energy label and EPREL registration duties under Regulation (EU) 2017/1369 continue alongside the passport.

How a digital product passport works

A passport links four pieces: a data carrier on the product, an identifier that resolves to a web link, the passport data itself, and the EU registry that customs authorities check at import. Each delegated act sets the data, the carrier, the granularity, who can read and update what, and how long the passport stays available, which Article 9 fixes at no less than the product's expected lifetime.

Diagram of how a digital product passport works: a data carrier on the product resolves to a unique product identifier and the passport data, which customers, repairers, recyclers, authorities, and civil society read according to access rights, while the operator registers identifiers in the EU DPP registry that customs check and keeps a back-up copy with an independent service provider.
How a digital product passport links the data carrier, identifier, passport data, access groups, EU registry, customs check, and back-up copy, based on ESPR Articles 9 to 15 and Implementing Regulation (EU) 2026/1778.

Data carriers

ESPR Article 2 defines a data carrier as a linear barcode, a two-dimensional symbol such as a QR code, or another automatic identification and data capture medium, a definition that covers NFC and RFID tags. Article 10 requires the carrier on the product, its packaging, or the documents that come with it, and each delegated act picks the carrier and its placement. The Commission's DPP FAQ says it is assessing QR codes and NFC chips. EN 18220 sets the technical requirements for carriers, from symbology and error correction to print quality, durability, and an indicator that helps people recognize a DPP carrier. Our guide to GS1 Digital Link covers GS1's standard for putting a web-resolvable product identifier in a QR code.

Identifiers

The carrier resolves to a persistent unique product identifier, which ESPR defines as a string of characters that identifies the product and enables a web link to its passport. Two more identifiers name the actors and sites behind it: a unique operator identifier for each actor in the value chain and a unique facility identifier for each location (Article 12). When a supplier or site has no identifier yet, the operator creating or updating the passport must request one on its behalf. EN 18219 standardizes all three identifiers.

Granularity

Each delegated act decides whether the passport exists per model, per batch, or per item (Article 9(2)(d)). The choice drives cost and process, because item-level passports need a serialized identifier on every unit. In its April 2026 draft preparatory study for iron and steel, the JRC proposed the heat number as the batch-level identifier.

Access rights and security

Article 11 gives customers, economic operators, professional repairers, independent operators, refurbishers, remanufacturers, recyclers, market surveillance and customs authorities, civil society organizations, trade unions, and other relevant actors free access according to their access rights. The Commission's DPP FAQ says general product information is open without identification, and Article 10 bars storing customers' personal data in a passport without their explicit consent under the GDPR. Article 11 also requires data authentication, reliability, and integrity, a high level of security and privacy, and fraud prevention. Our article on digital product passport security covers the controls behind those requirements.

Storage, back-up copy, and insolvency

The passport data stays decentralized. The economic operator responsible for the passport, or a DPP service provider it authorizes, stores it (Article 11). The operator placing the product on the market must also make a back-up copy available through a DPP service provider, which ESPR defines as an independent third party (Articles 2 and 10). The passport must stay available for the period the delegated act sets, including after an insolvency, liquidation, or cessation of activity in the EU. Service providers may not sell, reuse, or process passport data beyond what their storage or processing service requires, and the data must follow open standards and move without vendor lock-in. The Commission's DPP page lists a delegated act on DPP service providers for 2027, and our guide on how to choose a DPP platform applies these rules to vendor selection.

The EU DPP registry and customs checks

The Commission opened the EU DPP registry on July 20, 2026, with a testing environment, technical documentation, implementation guidelines, and a helpdesk. The registry stores unique identifiers, registration data, and high-level metadata for each product and links each identifier to the passport's location, while the detailed data stays with the operator or its provider. It serves ESPR product groups and the large batteries, construction products, toys, detergents, and end-user surfactants that other EU laws cover. The Commission's registry page states that the operator must register the passport before the product is placed on the EU market.

Implementing Regulation (EU) 2026/1778, adopted July 16, 2026 and in force since August 6, 2026, sets the mechanics. A company first becomes a verified economic operator by proving its identity with a qualified electronic seal or a qualified electronic attestation of attributes, and that status lasts up to three years (Article 4). The verified operator placing the product on the market then registers each passport at the model, batch, or item level the delegated act sets, through a secure user interface or an API (Article 8). The registry checks semantic conformity, granularity, the commodity code, and the link to the back-up copy, then records the identifiers, commodity code, service provider reference, and the passport's integrity. A downloadable proof of registration carries a hash of the registered passport version and stays available for 90 days (Article 9). ESPR Article 13(5) adds that the registration identifier the registry returns is not proof of compliance.

Under ESPR Article 15, anyone declaring a product for release for free circulation provides its unique registration identifier, and customs release the product only after an automatic check that the identifier and commodity code match the registry. Article 15(3) also has the Commission connect the registry to the EU Customs Single Window Certificates Exchange System. Article 14 adds a public web portal for searching and comparing passport data within each user's access rights, which the Commission's DPP FAQ describes as planned.

Digital product passport standards

CEN and CENELEC's joint technical committee JTC 24 wrote eight DPP standards under the Commission's standardization request M/604. Commission Implementing Decision (EU) 2026/1736, adopted July 14, 2026 and published July 15, 2026, cites six of them. A passport system that follows those six carries a presumption of conformity with the corresponding requirements of ESPR Articles 10 and 11.

StandardScopeStatus
EN 18216:2026Data exchange protocolsCited July 15, 2026
EN 18219:2026Unique identifiersCited July 15, 2026
EN 18220:2026Data carriersCited July 15, 2026
EN 18221:2026Data storage, archiving, and persistenceCited July 15, 2026
EN 18222:2026APIs for passport lifecycle management and searchabilityCited July 15, 2026
EN 18223:2026System interoperabilityCited July 15, 2026
EN 18239Access rights management, information system security, and business confidentialityNot among the six cited
EN 18246Data authentication, reliability, and integrityNot among the six cited

Two further standards, on access rights and security and on data authentication and integrity, complete the set. CEN-CENELEC lists them as EN 18239 and EN 18246, and the Commission's DPP page scheduled the decision citing them for September 2026. Until the Official Journal cites them, a passport's security and integrity design has to show conformity with Article 11 directly.

Which products need a passport and when

An ESPR passport reaches a product group only through a Commission delegated act, and Article 4(4) of the ESPR sets at least 18 months between a delegated act's entry into force and its application, except in duly justified cases. The Commission's DPP page publishes the schedule below. Its dates for ESPR product groups mark adoption of the delegated act, so compliance dates come at least 18 months later, and the Commission's DPP FAQ notes that a product group's place in the working plan does not by itself make a passport mandatory. The battery, detergent, and toy dates are application dates written into those regulations.

Product groupLegal basisPublished dateWhat the date marks
Electric vehicle, light means of transport, and industrial batteries above 2 kWhBattery Regulation (EU) 2023/1542, Article 77February 18, 2027Passport required
Iron and steelESPR delegated actQ4 2026Adoption, per Commission schedule
Construction productsConstruction Products Regulation (EU) 2024/3110Q2 2027Adoption, per Commission schedule
Textiles, aluminum, and tiresESPR delegated actsQ3 to Q4 2027Adoption, per Commission schedule
FurnitureESPR delegated act2028Adoption, per Commission schedule
Mattresses; recycled contentESPR delegated acts2029Adoption, per Commission schedule
Detergents and end-user surfactantsDetergents Regulation (EU) 2026/405September 23, 2029Regulation applies
ToysToy Safety Regulation (EU) 2025/2509August 1, 2030Regulation applies
Vertical timeline of digital product passport milestones from ESPR's entry into force on July 18, 2024 to the Toy Safety Regulation's application on August 1, 2030, separating live milestones, legal application dates, and the Commission's schedule for delegated act adoption.
Digital product passport milestones as published in EU law and on the Commission's DPP page; schedule dates mark adoption of delegated acts, with application at least 18 months later under ESPR Article 4(4).

Battery passports use the same EU registry, and our guides to the EU battery passport and the EU Battery Regulation cover the battery obligations in detail. Apparel brands face a second ESPR rule that already applies: since July 19, 2026, Article 25 of the ESPR has barred large enterprises from destroying unsold apparel, clothing accessories, and footwear, which our guide to digital product passports for textiles covers alongside the textile passport.

Who is responsible for the passport

The economic operator that places the product on the EU market answers for the passport. ESPR Article 27 requires manufacturers to ensure a passport is available when they place a product on the market, and Article 29 requires importers to ensure the same before they place an imported product on the market. The same operator uploads the identifiers to the registry (Article 13) and arranges the back-up copy (Article 10). The Commission's DPP FAQ puts "the primary responsibility for the DPP's creation and accuracy" on the operators placing products on the EU market. Its 2024 ESPR FAQ makes them responsible for getting upstream data from suppliers and keeping it accurate and complete, including for products made outside the EU.

Products covered by ESPR requirements also need an economic operator established in the EU under Article 4 of Regulation (EU) 2019/1020: an EU manufacturer, an importer, an authorized representative with a written mandate, or a fulfillment service provider, as the Commission explains. A US manufacturer that ships directly to EU customers needs one of these operators named for each covered product.

Distributors and dealers carry duties of their own under ESPR Articles 30 and 31. ESPR defines a dealer broadly, as anyone who offers products for sale, hire, or hire purchase or displays them to customers. A&O Shearman's analysis groups dealers, fulfillment service providers, and online marketplaces, under Articles 31, 33, and 35, as the actors that display labels and make the passport easily accessible. The Commission's DPP FAQ says online marketplaces must make the passport easily accessible on the product page so consumers can review it before they buy.

The Commission's DPP FAQ divides enforcement: customs check the registry data at import, and market surveillance authorities in each Member State check whether passport data is accurate, complete, and reliable. Member States set the penalties, which must include at least fines and temporary exclusion from public procurement, as White & Case summarizes Article 74.

How to prepare for digital product passport requirements

Most of the work is data and supplier management, and it can start before a delegated act covers your products, because the registry, the cited standards, and the battery and toy rules already fix much of the architecture. We recommend this sequence:

  1. Map each product line to its product group, the delegated act or other law that governs it, and your role as manufacturer, importer, distributor, or dealer. The map tells you which dates apply and who must create, register, and host each passport.
  2. Inventory the data you already hold in enterprise resource planning (ERP), product lifecycle management (PLM), product information management (PIM), and compliance systems against the eight categories above. Declarations of conformity, bills of materials, and substance of concern records feed several categories at once.
  3. Write supplier data requirements into contracts and onboarding. The operator placing the product on the market answers for upstream data, so composition, recycled content, substance, and facility data need defined formats, deadlines, and evidence.
  4. Choose an identifier and data carrier strategy: the identifier scheme, the carrier (QR code, NFC, or RFID), and the granularity for each product line. Item-level passports need serialization on the production line.
  5. Select a DPP platform that hosts the passport, supports registration through the registry API, keeps the back-up copy with an independent provider, and exports data in open formats. Test it against the six cited standards.
  6. Design access rights and security for each stakeholder group: how you authenticate privileged users, sign or hash passport data, log access, and keep customer personal data out of the passport unless the customer gives explicit consent.
  7. Plan registry registration: obtain verified economic operator status with a qualified electronic seal, choose between the user interface and the API, and run test registrations in the Commission's testing environment before the first live product.

BD Emerson's ESPR compliance and digital product passport practice runs this sequence with product, compliance, and IT teams. We map products, roles, and dates, design the passport data model and access rights, run supplier data collection, select the platform, integrate it with ERP, PLM, and PIM systems, design passport security, and register identifiers. The platform vendor hosts the passport, and BD Emerson does not build, sell, or host DPP platforms.

Frequently asked questions

Is there a separate EU digital product passport regulation? No single regulation covers the passport. The rules sit in Articles 9 to 15 of the Ecodesign for Sustainable Products Regulation, Regulation (EU) 2024/1781, and in product laws such as the Battery Regulation (EU) 2023/1542, the Toy Safety Regulation (EU) 2025/2509, and the Detergents Regulation (EU) 2026/405. Implementing Regulation (EU) 2026/1778 sets the registry rules, and Implementing Decision (EU) 2026/1736 cites the first six standards.

Is a digital product passport mandatory today? No product needs an ESPR passport until a delegated act for its product group applies, and Article 4(4) of the ESPR sets at least 18 months between a delegated act's entry into force and its application. The first mandatory passports come from the Battery Regulation, which requires them for electric vehicle, light means of transport, and industrial batteries above 2 kWh from February 18, 2027.

Do US companies need digital product passports? A US company needs a passport for every product it sells into the EU that a delegated act or another EU law brings into scope, because the rules apply to imports in the same way as to EU-made goods. Covered products also need an economic operator established in the EU, such as an importer or an authorized representative. Online marketplaces must make the passport accessible on the product page for EU customers.

Where is digital product passport data stored? The economic operator responsible for the passport, or a DPP service provider it authorizes, stores the passport data, and the operator must keep a back-up copy with an independent DPP service provider. The EU registry holds identifiers, the commodity code, and registration metadata, and it links each identifier to the location of the passport.

What happens to the passport when a product is refurbished or remanufactured? The Commission's 2024 ESPR FAQ says a refurbished product keeps its original passport, while a remanufactured product placed on the market as new needs a new one. The Commission expects a link between the old and new passports where the technical solution allows it.

What are the penalties for a missing or inaccurate passport? A product that needs a passport cannot be placed on the EU market without one under ESPR Article 9, and customs release an import only after its registration identifier and commodity code match the registry under Article 15. Member States set the penalties, which must include at least fines and temporary exclusion from public procurement.

Passport readiness depends on data your suppliers and systems hold today. If you sell physical products into the EU, our ESPR compliance practice can map which passports you need and when, design the data model, and run the supplier data collection that feeds it.

About the author

Drew Danner is a Managing Director at BD Emerson. He leads engagements across technology strategy, enterprise AI, M&A technology diligence, and the firm's governance, risk, and security practice, advising buyers, operators, and portfolio companies on decisions where the technical call drives the commercial outcome. His work spans build vs buy decisions, platform implementations, and the security and compliance programs that keep them defensible.
Drew Danner
Drew Danner
Managing Director