Digital Product Passport: What It Is and What the EU Requires
A digital product passport (DPP) is a structured digital record of a product's identity, materials, repair, and compliance data, reached by scanning a data carrier such as a QR code. The Ecodesign for Sustainable Products Regulation (ESPR), Regulation (EU) 2024/1781, sets the rules in Articles 9 to 15, and each ESPR delegated act decides which products need a passport. The Battery, Toy Safety, and Detergents Regulations add passport duties of their own.
The Commission cited six harmonized DPP standards in the Official Journal on July 15, 2026 and opened the EU DPP registry on July 20, 2026. The first mandatory passports, for electric vehicle, light means of transport, and industrial batteries above 2 kWh, apply from February 18, 2027.
What a digital product passport contains
No single EU dataset defines a passport. The required content changes with the product category, the regulation that applies, the passport's granularity, and the access rights each stakeholder group holds. Article 9(2)(a) of the ESPR has each delegated act specify "the data to be included in the digital product passport pursuant to Annex III." The Joint Research Centre's March 2026 DPP methodology report maps Annex III to identification data such as the unique product identifier and manufacturer and operator details, compliance documentation such as declarations of conformity, and user manuals, warnings, and safety information. The rest comes from Article 7: performance information on parameters such as durability and repairability; instructions for installation, use, maintenance, and repair; information for treatment facilities; and the substances of concern that Article 7(5) requires operators to track.
Depending on the rules that apply to a product, a passport draws on eight categories of data.
| Category | What it can include | Where the requirement comes from |
|---|---|---|
| Product identity | Product name, model, batch or serial number, unique identifiers, manufacturer, and the responsible economic operator | Annex III identification data; ESPR Article 12 |
| Materials and components | Composition, critical raw materials, recycled content, substances of concern, and component relationships | Article 7(5) for substances of concern; recycled content is an Article 5(1) parameter |
| Sustainability | Carbon or environmental footprint, energy performance, resource efficiency, and category-specific measures | Article 7(2)(b)(i) performance information |
| Durability and performance | Expected lifetime, performance characteristics, warranties, and test information where required | Article 7(2)(b)(i), which names a durability score |
| Repair and circularity | Repair instructions, compatible spare parts, disassembly, reuse, remanufacturing, and recyclability guidance | Article 7(2)(b)(i) and (ii), including a repairability score |
| Compliance documentation | Declarations of conformity, certificates, safety information, technical documentation, and regulatory markings | Annex III compliance and user information data |
| Supply chain | Facility, sourcing, due diligence, custody, or provenance data where the product rules require it | Annex III and Article 12 facility identifiers; sector laws |
| End-of-life guidance | Safe handling, collection, disposal, material recovery, and recycling instructions | Article 7(2)(b)(iii) information for treatment facilities |
The Commission's DPP FAQ allows voluntary data points as long as the passport keeps them clearly separate from the mandatory ones. Where a separate delegated act covers a component, that component may need its own passport, linked to the product's passport, according to the Commission's 2024 ESPR FAQ. The JRC report adds that energy label and EPREL registration duties under Regulation (EU) 2017/1369 continue alongside the passport.
How a digital product passport works
A passport links four pieces: a data carrier on the product, an identifier that resolves to a web link, the passport data itself, and the EU registry that customs authorities check at import. Each delegated act sets the data, the carrier, the granularity, who can read and update what, and how long the passport stays available, which Article 9 fixes at no less than the product's expected lifetime.
Data carriers
ESPR Article 2 defines a data carrier as a linear barcode, a two-dimensional symbol such as a QR code, or another automatic identification and data capture medium, a definition that covers NFC and RFID tags. Article 10 requires the carrier on the product, its packaging, or the documents that come with it, and each delegated act picks the carrier and its placement. The Commission's DPP FAQ says it is assessing QR codes and NFC chips. EN 18220 sets the technical requirements for carriers, from symbology and error correction to print quality, durability, and an indicator that helps people recognize a DPP carrier. Our guide to GS1 Digital Link covers GS1's standard for putting a web-resolvable product identifier in a QR code.
Identifiers
The carrier resolves to a persistent unique product identifier, which ESPR defines as a string of characters that identifies the product and enables a web link to its passport. Two more identifiers name the actors and sites behind it: a unique operator identifier for each actor in the value chain and a unique facility identifier for each location (Article 12). When a supplier or site has no identifier yet, the operator creating or updating the passport must request one on its behalf. EN 18219 standardizes all three identifiers.
Granularity
Each delegated act decides whether the passport exists per model, per batch, or per item (Article 9(2)(d)). The choice drives cost and process, because item-level passports need a serialized identifier on every unit. In its April 2026 draft preparatory study for iron and steel, the JRC proposed the heat number as the batch-level identifier.
Access rights and security
Article 11 gives customers, economic operators, professional repairers, independent operators, refurbishers, remanufacturers, recyclers, market surveillance and customs authorities, civil society organizations, trade unions, and other relevant actors free access according to their access rights. The Commission's DPP FAQ says general product information is open without identification, and Article 10 bars storing customers' personal data in a passport without their explicit consent under the GDPR. Article 11 also requires data authentication, reliability, and integrity, a high level of security and privacy, and fraud prevention. Our article on digital product passport security covers the controls behind those requirements.
Storage, back-up copy, and insolvency
The passport data stays decentralized. The economic operator responsible for the passport, or a DPP service provider it authorizes, stores it (Article 11). The operator placing the product on the market must also make a back-up copy available through a DPP service provider, which ESPR defines as an independent third party (Articles 2 and 10). The passport must stay available for the period the delegated act sets, including after an insolvency, liquidation, or cessation of activity in the EU. Service providers may not sell, reuse, or process passport data beyond what their storage or processing service requires, and the data must follow open standards and move without vendor lock-in. The Commission's DPP page lists a delegated act on DPP service providers for 2027, and our guide on how to choose a DPP platform applies these rules to vendor selection.
The EU DPP registry and customs checks
The Commission opened the EU DPP registry on July 20, 2026, with a testing environment, technical documentation, implementation guidelines, and a helpdesk. The registry stores unique identifiers, registration data, and high-level metadata for each product and links each identifier to the passport's location, while the detailed data stays with the operator or its provider. It serves ESPR product groups and the large batteries, construction products, toys, detergents, and end-user surfactants that other EU laws cover. The Commission's registry page states that the operator must register the passport before the product is placed on the EU market.
Implementing Regulation (EU) 2026/1778, adopted July 16, 2026 and in force since August 6, 2026, sets the mechanics. A company first becomes a verified economic operator by proving its identity with a qualified electronic seal or a qualified electronic attestation of attributes, and that status lasts up to three years (Article 4). The verified operator placing the product on the market then registers each passport at the model, batch, or item level the delegated act sets, through a secure user interface or an API (Article 8). The registry checks semantic conformity, granularity, the commodity code, and the link to the back-up copy, then records the identifiers, commodity code, service provider reference, and the passport's integrity. A downloadable proof of registration carries a hash of the registered passport version and stays available for 90 days (Article 9). ESPR Article 13(5) adds that the registration identifier the registry returns is not proof of compliance.
Under ESPR Article 15, anyone declaring a product for release for free circulation provides its unique registration identifier, and customs release the product only after an automatic check that the identifier and commodity code match the registry. Article 15(3) also has the Commission connect the registry to the EU Customs Single Window Certificates Exchange System. Article 14 adds a public web portal for searching and comparing passport data within each user's access rights, which the Commission's DPP FAQ describes as planned.
Digital product passport standards
CEN and CENELEC's joint technical committee JTC 24 wrote eight DPP standards under the Commission's standardization request M/604. Commission Implementing Decision (EU) 2026/1736, adopted July 14, 2026 and published July 15, 2026, cites six of them. A passport system that follows those six carries a presumption of conformity with the corresponding requirements of ESPR Articles 10 and 11.
| Standard | Scope | Status |
|---|---|---|
| EN 18216:2026 | Data exchange protocols | Cited July 15, 2026 |
| EN 18219:2026 | Unique identifiers | Cited July 15, 2026 |
| EN 18220:2026 | Data carriers | Cited July 15, 2026 |
| EN 18221:2026 | Data storage, archiving, and persistence | Cited July 15, 2026 |
| EN 18222:2026 | APIs for passport lifecycle management and searchability | Cited July 15, 2026 |
| EN 18223:2026 | System interoperability | Cited July 15, 2026 |
| EN 18239 | Access rights management, information system security, and business confidentiality | Not among the six cited |
| EN 18246 | Data authentication, reliability, and integrity | Not among the six cited |
Two further standards, on access rights and security and on data authentication and integrity, complete the set. CEN-CENELEC lists them as EN 18239 and EN 18246, and the Commission's DPP page scheduled the decision citing them for September 2026. Until the Official Journal cites them, a passport's security and integrity design has to show conformity with Article 11 directly.
Which products need a passport and when
An ESPR passport reaches a product group only through a Commission delegated act, and Article 4(4) of the ESPR sets at least 18 months between a delegated act's entry into force and its application, except in duly justified cases. The Commission's DPP page publishes the schedule below. Its dates for ESPR product groups mark adoption of the delegated act, so compliance dates come at least 18 months later, and the Commission's DPP FAQ notes that a product group's place in the working plan does not by itself make a passport mandatory. The battery, detergent, and toy dates are application dates written into those regulations.
| Product group | Legal basis | Published date | What the date marks |
|---|---|---|---|
| Electric vehicle, light means of transport, and industrial batteries above 2 kWh | Battery Regulation (EU) 2023/1542, Article 77 | February 18, 2027 | Passport required |
| Iron and steel | ESPR delegated act | Q4 2026 | Adoption, per Commission schedule |
| Construction products | Construction Products Regulation (EU) 2024/3110 | Q2 2027 | Adoption, per Commission schedule |
| Textiles, aluminum, and tires | ESPR delegated acts | Q3 to Q4 2027 | Adoption, per Commission schedule |
| Furniture | ESPR delegated act | 2028 | Adoption, per Commission schedule |
| Mattresses; recycled content | ESPR delegated acts | 2029 | Adoption, per Commission schedule |
| Detergents and end-user surfactants | Detergents Regulation (EU) 2026/405 | September 23, 2029 | Regulation applies |
| Toys | Toy Safety Regulation (EU) 2025/2509 | August 1, 2030 | Regulation applies |
Battery passports use the same EU registry, and our guides to the EU battery passport and the EU Battery Regulation cover the battery obligations in detail. Apparel brands face a second ESPR rule that already applies: since July 19, 2026, Article 25 of the ESPR has barred large enterprises from destroying unsold apparel, clothing accessories, and footwear, which our guide to digital product passports for textiles covers alongside the textile passport.
Who is responsible for the passport
The economic operator that places the product on the EU market answers for the passport. ESPR Article 27 requires manufacturers to ensure a passport is available when they place a product on the market, and Article 29 requires importers to ensure the same before they place an imported product on the market. The same operator uploads the identifiers to the registry (Article 13) and arranges the back-up copy (Article 10). The Commission's DPP FAQ puts "the primary responsibility for the DPP's creation and accuracy" on the operators placing products on the EU market. Its 2024 ESPR FAQ makes them responsible for getting upstream data from suppliers and keeping it accurate and complete, including for products made outside the EU.
Products covered by ESPR requirements also need an economic operator established in the EU under Article 4 of Regulation (EU) 2019/1020: an EU manufacturer, an importer, an authorized representative with a written mandate, or a fulfillment service provider, as the Commission explains. A US manufacturer that ships directly to EU customers needs one of these operators named for each covered product.
Distributors and dealers carry duties of their own under ESPR Articles 30 and 31. ESPR defines a dealer broadly, as anyone who offers products for sale, hire, or hire purchase or displays them to customers. A&O Shearman's analysis groups dealers, fulfillment service providers, and online marketplaces, under Articles 31, 33, and 35, as the actors that display labels and make the passport easily accessible. The Commission's DPP FAQ says online marketplaces must make the passport easily accessible on the product page so consumers can review it before they buy.
The Commission's DPP FAQ divides enforcement: customs check the registry data at import, and market surveillance authorities in each Member State check whether passport data is accurate, complete, and reliable. Member States set the penalties, which must include at least fines and temporary exclusion from public procurement, as White & Case summarizes Article 74.
How to prepare for digital product passport requirements
Most of the work is data and supplier management, and it can start before a delegated act covers your products, because the registry, the cited standards, and the battery and toy rules already fix much of the architecture. We recommend this sequence:
- Map each product line to its product group, the delegated act or other law that governs it, and your role as manufacturer, importer, distributor, or dealer. The map tells you which dates apply and who must create, register, and host each passport.
- Inventory the data you already hold in enterprise resource planning (ERP), product lifecycle management (PLM), product information management (PIM), and compliance systems against the eight categories above. Declarations of conformity, bills of materials, and substance of concern records feed several categories at once.
- Write supplier data requirements into contracts and onboarding. The operator placing the product on the market answers for upstream data, so composition, recycled content, substance, and facility data need defined formats, deadlines, and evidence.
- Choose an identifier and data carrier strategy: the identifier scheme, the carrier (QR code, NFC, or RFID), and the granularity for each product line. Item-level passports need serialization on the production line.
- Select a DPP platform that hosts the passport, supports registration through the registry API, keeps the back-up copy with an independent provider, and exports data in open formats. Test it against the six cited standards.
- Design access rights and security for each stakeholder group: how you authenticate privileged users, sign or hash passport data, log access, and keep customer personal data out of the passport unless the customer gives explicit consent.
- Plan registry registration: obtain verified economic operator status with a qualified electronic seal, choose between the user interface and the API, and run test registrations in the Commission's testing environment before the first live product.
BD Emerson's ESPR compliance and digital product passport practice runs this sequence with product, compliance, and IT teams. We map products, roles, and dates, design the passport data model and access rights, run supplier data collection, select the platform, integrate it with ERP, PLM, and PIM systems, design passport security, and register identifiers. The platform vendor hosts the passport, and BD Emerson does not build, sell, or host DPP platforms.
Frequently asked questions
Is there a separate EU digital product passport regulation? No single regulation covers the passport. The rules sit in Articles 9 to 15 of the Ecodesign for Sustainable Products Regulation, Regulation (EU) 2024/1781, and in product laws such as the Battery Regulation (EU) 2023/1542, the Toy Safety Regulation (EU) 2025/2509, and the Detergents Regulation (EU) 2026/405. Implementing Regulation (EU) 2026/1778 sets the registry rules, and Implementing Decision (EU) 2026/1736 cites the first six standards.
Is a digital product passport mandatory today? No product needs an ESPR passport until a delegated act for its product group applies, and Article 4(4) of the ESPR sets at least 18 months between a delegated act's entry into force and its application. The first mandatory passports come from the Battery Regulation, which requires them for electric vehicle, light means of transport, and industrial batteries above 2 kWh from February 18, 2027.
Do US companies need digital product passports? A US company needs a passport for every product it sells into the EU that a delegated act or another EU law brings into scope, because the rules apply to imports in the same way as to EU-made goods. Covered products also need an economic operator established in the EU, such as an importer or an authorized representative. Online marketplaces must make the passport accessible on the product page for EU customers.
Where is digital product passport data stored? The economic operator responsible for the passport, or a DPP service provider it authorizes, stores the passport data, and the operator must keep a back-up copy with an independent DPP service provider. The EU registry holds identifiers, the commodity code, and registration metadata, and it links each identifier to the location of the passport.
What happens to the passport when a product is refurbished or remanufactured? The Commission's 2024 ESPR FAQ says a refurbished product keeps its original passport, while a remanufactured product placed on the market as new needs a new one. The Commission expects a link between the old and new passports where the technical solution allows it.
What are the penalties for a missing or inaccurate passport? A product that needs a passport cannot be placed on the EU market without one under ESPR Article 9, and customs release an import only after its registration identifier and commodity code match the registry under Article 15. Member States set the penalties, which must include at least fines and temporary exclusion from public procurement.
Passport readiness depends on data your suppliers and systems hold today. If you sell physical products into the EU, our ESPR compliance practice can map which passports you need and when, design the data model, and run the supplier data collection that feeds it.
