EU compliance
Digital Product Passport (DPP)
A Digital Product Passport is a structured electronic product record connected to a persistent unique product identifier and accessed through a data carrier. Regulation (EU) 2024/1781 establishes the common EU DPP architecture, while the products, data requirements, access rights and application dates are determined by the applicable Union legislation or product-specific measure.
Overview
Regulation (EU) 2024/1781 establishing a framework for the setting of ecodesign requirements for sustainable products (ESPR) establishes the common Digital Product Passport architecture in Articles 9 to 15.
Under ESPR, a product becomes subject to a DPP requirement where the applicable delegated act adopted for the relevant product group requires one. That act determines the product scope, required information, data carrier, passport level, access rights, update responsibilities and relevant transition period.
The common technical infrastructure can also support Digital Product Passports required by other Union legislation. The Battery Passport under Regulation (EU) 2023/1542 is the first major example: its legal obligation comes from the Battery Regulation rather than from an ESPR product-specific delegated act.
The existence of the common DPP infrastructure and operational EU Registry does not by itself make a Digital Product Passport mandatory for every product placed on the EU market.
Who is affected
- Manufacturers of products covered by an applicable DPP legal measure
- Importers and distributors placing covered products on the EU market
- Authorised representatives mandated for product-compliance purposes
- Dealers, online marketplaces and distance sellers required to make Passport access available
- Suppliers and facilities holding product, material and identifier data
- Economic operators using Digital Product Passport service providers for hosting or back-up
- Actors with access rights, such as repairers, refurbishers, remanufacturers, recyclers, market-surveillance authorities and customs authorities
Key obligations
- Identify the Union legal measure that creates the DPP obligation for the specific product.
- Confirm whether the Passport applies at model, batch or item level.
- Attribute and maintain a persistent unique product identifier.
- Apply the data carrier required by the applicable measure, in the required location and presentation.
- Provide the information required by Annex III and the applicable product measure.
- Keep Passport data accurate, complete and up to date.
- Implement access rights so that each actor reaches only the information intended for it.
- Avoid storing customer personal data without explicit consent.
- Make a back-up copy available through a Digital Product Passport service provider as required.
- Register the required DPP information in the EU Registry where the applicable framework requires registration before placing the product on the market.
- Provide dealers and online-marketplace providers with the data-carrier or identifier information needed for distance selling.
- Keep DPP work separate from, and coordinated with, technical documentation, the Declaration of Conformity and national EPR obligations.
Documentation and readiness
DPP readiness begins with legal scoping before software selection.
For each affected product group, the implementation file should identify: the Union legal measure creating the DPP obligation; the applicable product definition; the legal application date; whether the Passport is required at model, batch or item level; the data fields required; the source and owner of each data field; the unique product, operator and facility identifiers required; the data carrier and its required location; access rights; actors permitted or required to create and update data; the required availability period; Registry-registration requirements; technical-documentation and Declaration-of-Conformity links; lifecycle and change-control requirements; hosting and back-up architecture; and interfaces with marketplaces, customs or other systems where applicable.
Only after this legal and data map is established should the technical DPP solution be finalised.
Applicability
Digital Product Passport implementation is progressive. Current framework milestones include:
18 July 2024 — Regulation (EU) 2024/1781 entered into force.
July 2026 — the first group of harmonised DPP standards was referenced through Commission Implementing Decision (EU) 2026/1736.
20 July 2026 — the EU Digital Product Passport Registry became operational under the implementation framework established by Commission Implementing Regulation (EU) 2026/1778.
18 February 2027 — the Battery Passport becomes mandatory for the battery categories defined by Regulation (EU) 2023/1542.
For ESPR product groups, DPP application dates follow the relevant delegated acts and their transition periods. There is no single date on which every physical product becomes subject to an ESPR DPP.
When a DPP is required
Under Article 9 ESPR, the applicable product information requirements determine whether a Digital Product Passport is required.
For ESPR product groups, the relevant delegated act specifies, among other elements: the product group covered; the data to be included; the data carrier to be used; where and how the data carrier is presented; whether the Passport operates at model, batch or individual-item level; how customers can access the information, including for distance selling; which actors can access which data; which actors can create or update data; and the period during which the Passport must remain available.
A company should therefore not create a generic “ESPR Passport” from a standard template before identifying the Union measure applicable to the specific product.
Model, batch or item level
A Digital Product Passport is not necessarily created at the same identification level for every product.
Article 9 requires the applicable product measure to specify whether the DPP is established at model level, batch level or item level.
The identification architecture, data volume, update logic and lifecycle responsibilities can therefore differ materially between product groups.
The correct passport level must be taken from the applicable Union measure rather than selected solely as an IT preference.
Data carrier and unique product identifier
Article 10 requires the DPP to be connected through a data carrier to a persistent unique product identifier.
The applicable product measure determines whether the data carrier is placed on the product itself, on its packaging or in accompanying documentation, and specifies the relevant presentation and positioning rules.
A QR code can be used as a data carrier where the applicable framework provides for it, but “DPP” and “QR code” are not synonymous. The QR code or other data carrier is the access mechanism; the Digital Product Passport is the structured electronic data system behind it.
Data structure
The precise DPP data set is product-specific. Annex III and the applicable product measure provide the framework for information that can include, where relevant: the persistent unique product identifier; commodity-code information; compliance documentation and declarations; product instructions, warnings or safety information required under Union law; manufacturer and other economic-operator identifiers; facility identifiers; importer information; information identifying the relevant EU-established responsible economic operator where required; and reference information for the DPP service provider holding the back-up copy.
Product-specific sustainability, circularity, repair, material, environmental or other information is added where required by the applicable Union measure.
Not every Annex III information element applies identically to every product.
Data quality and responsibility
Article 9 requires data in the Digital Product Passport to be accurate, complete and up to date.
The applicable product measure identifies which economic operators create or update the relevant information and what data they are permitted or required to manage.
Using external software, a DPP platform, consultants or data-service providers does not by itself transfer the legal responsibilities assigned to the relevant economic operator by Union legislation.
A DPP implementation therefore requires both a technical architecture and a controlled product-data governance process.
Open standards and interoperability
Articles 10 and 11 establish common technical principles for the DPP architecture. DPP data must be based on open standards and use an interoperable format. As appropriate, the data must be machine-readable, structured, searchable and transferable through an open interoperable data-exchange network without vendor lock-in.
The DPP architecture must also support interoperability between different Digital Product Passports at technical, semantic and organisational level.
In July 2026, Commission Implementing Decision (EU) 2026/1736 published references to the first group of harmonised European standards supporting the DPP framework.
The technical standardisation framework continues to develop and must be checked against the standards and legal measures applicable at implementation.
Access rights
A Digital Product Passport is not necessarily one fully public data set.
Article 11 requires easy and free access for relevant actors according to their respective access rights, while the applicable product measure determines which actors can access which information.
Depending on the product framework, relevant users can include customers, manufacturers, importers, distributors and dealers, repairers, refurbishers and remanufacturers, recyclers, market-surveillance authorities, customs authorities and other relevant actors identified by the applicable measure.
The technical solution must therefore support the access logic established for the relevant product rather than publishing every data field to every user.
Personal data
Article 10 also limits the treatment of personal data. Personal data relating to customers must not be stored in the Digital Product Passport without the customer's explicit consent in accordance with the applicable data-protection framework.
DPP data design should therefore distinguish regulatory product information from personal customer information and avoid collecting personal data merely because the technical system is capable of doing so.
Decentralised data architecture
The DPP system is decentralised. The detailed product information contained in the Passport is not generally stored as one complete product file inside the EU DPP Registry.
It remains under the responsibility of the relevant economic operator and can be hosted by that operator or through a Digital Product Passport service provider in accordance with the applicable rules. The Registry acts primarily as the common EU indexing and registration layer.
This distinction is important: registering a product identifier in the EU Registry and maintaining the underlying Passport data are related but separate technical functions.
Back-up copy and DPP service providers
Article 10 requires the economic operator placing the product on the market to make available a back-up copy of the Digital Product Passport through a Digital Product Passport service provider.
The Regulation allows the Passport itself to be stored by the responsible economic operator or by a DPP service provider, while the back-up mechanism is intended to preserve availability if the responsible operator can no longer maintain the Passport.
The detailed regulatory framework for DPP service providers continues to be supplemented through implementing and delegated measures. Selection of a provider should therefore take account of both the current ESPR requirements and the technical rules applicable when the product-specific DPP obligation takes effect.
EU DPP Registry
Article 13 establishes the EU Digital Product Passport Registry. The Registry became operational on 20 July 2026. Commission Implementing Regulation (EU) 2026/1778 sets out its implementation arrangements.
The Registry stores at least the required unique identifiers and registration data. For products intended for release for free circulation, it also supports the commodity-code and customs-control framework established by ESPR. Additional high-level information can be stored where required by the applicable Union measure.
Before placing a product subject to a DPP registration obligation on the market or putting it into service, the responsible economic operator must register the required DPP information in accordance with the applicable legal framework. The Registry returns a unique registration identifier for the registered identifiers.
That registration does not itself constitute proof that the product complies with ESPR or other Union legislation.
Registry vs product data
The EU Registry is not the Digital Product Passport itself.
Registry: EU-level indexing and registration infrastructure; unique identifiers; registration information and high-level metadata; authority and customs-support functions.
Digital Product Passport: the product-specific electronic information required by the applicable legislation; maintained through the decentralised DPP architecture; accessed according to the applicable data carrier and access-right rules.
A compliant implementation can therefore involve both Registry registration and a separate system for maintaining and serving the detailed Passport data.
Registry implementation — current status
Commission Implementing Regulation (EU) 2026/1778 of 16 July 2026 establishes operational arrangements for the Registry, including user verification, access management, data registration and storage, technical architecture and the semantic repository.
The Registry went live on 20 July 2026 together with a testing environment.
This operational readiness is an infrastructure milestone. It does not replace the need for the product-specific or sector-specific Union measure that makes a DPP mandatory for the product concerned.
Semantic repository
The 2026 Registry framework also establishes a semantic repository supporting consistent machine-readable DPP information. The repository provides common data models, semantic definitions and vocabularies across relevant product groups.
This supports interoperability and reduces the risk that identical product information is represented differently across incompatible DPP systems.
Product-specific data requirements still derive from the applicable Union legislation; the semantic repository does not itself create new substantive product obligations.
Distance selling and online access
ESPR also anticipates DPP use in distance selling. The applicable delegated act must specify how customers can access the Digital Product Passport before being bound by a sales, hire or hire-purchase contract, including where they cannot physically access the product.
Article 10 also requires the economic operator placing the product on the market to provide dealers and online-marketplace providers with the relevant digital data-carrier or unique-identifier information needed to make that access available.
The exact product-facing implementation must therefore be mapped to the applicable delegated act.
Customs
Articles 13 and 15 connect the DPP Registry with customs controls for products entering the Union.
For products covered by the applicable DPP legal measure and placed under the customs procedure for release for free circulation, the relevant unique registration identifier forms part of the customs-verification framework.
The Regulation provides for electronic verification through the Registry/customs interconnection when that interconnection is operational.
Customs release does not constitute proof that the product complies with all applicable Union product requirements.
DPP vs technical documentation
A Digital Product Passport and technical documentation are not the same file.
Technical documentation contains the detailed evidence supporting conformity with the applicable product requirements. The DPP contains the information that the applicable Union measure requires to be digitally accessible to the relevant actors.
Certain compliance documents or references can form part of the DPP where required, but the DPP does not automatically replace the complete technical file or the manufacturer's underlying conformity evidence.
DPP vs Declaration of Conformity
The EU Declaration of Conformity is also a separate legal document.
Where the applicable product legislation requires both a Declaration of Conformity and a DPP, the relevant declaration or its required information can be linked to or included in the Passport as specified by the applicable legal framework.
Providing a declaration through a DPP does not change who legally issues that declaration or who assumes responsibility for product conformity.
DPP vs Battery Passport
The Battery Passport uses the wider EU Digital Product Passport infrastructure but has its own legal basis.
From 18 February 2027, Regulation (EU) 2023/1542 requires a Battery Passport for LMT batteries, industrial batteries with a capacity greater than 2 kWh and electric-vehicle batteries.
The battery obligation does not depend on an ESPR product-specific delegated act. The Battery Passport and ESPR DPP therefore share infrastructure and interoperability principles but must not be treated as one identical legal requirement.
DPP vs PPWR digital information
PPWR also uses QR codes and other standardised open digital data carriers for specified packaging information and labelling purposes. Those PPWR digital-information requirements arise under Regulation (EU) 2025/40 and should not automatically be described as an ESPR Digital Product Passport.
A packaged product may therefore use digital carriers under more than one Union framework.
Where Union law requires information for both the packaged product and its packaging to be provided digitally, the applicable interoperability and single-carrier rules must be checked under the relevant legislation.
DPP vs EPR
A Digital Product Passport does not replace extended producer responsibility.
DPP: product identification, sustainability, compliance and lifecycle information as required by the applicable Union product framework.
EPR: producer status, national registration, authorised representation, fulfilment and financing, collection and treatment obligations, records and reporting.
The same product can require both systems, and some source data may overlap, but the legal purposes remain separate.
How we assist
- Identify whether and when a DPP obligation applies
- Identify the applicable Union legal measure
- Define the model, batch or item Passport level
- Map required data fields
- Define legal-requirement-to-data matrices
- Identify data owners and source systems
- Map unique-identifier requirements
- Define public and restricted-access requirements
- Map Registry-registration requirements
- Coordinate DPP data with technical documentation and Declaration of Conformity workflows
- Identify marketplace, distance-selling and customs interfaces where applicable
- Coordinate DPP data with Battery Passport or other sector-specific requirements
- Distinguish DPP requirements from national EPR obligations
- Assess technical solution requirements
- Coordinate implementation with external software or DPP service providers
- Identify where cybersecurity, systems integration, engineering, laboratory testing or formal legal interpretation is required
EPR Entry is the commercial coordination platform. Digital Product Passport support is delivered through the legal service provider identified for the relevant engagement.
Our scope can cover regulatory scoping, DPP data mapping, documentation readiness and coordination of technical implementation. The responsible economic operator retains the legal responsibilities assigned by the applicable Union legislation.
Where dedicated DPP hosting, software development, systems integration, cybersecurity work, laboratory testing, engineering assessment or formal legal interpretation is required, that work is identified separately.
Frequently asked questions
Need this assessed against your own product range?
Tell us what you sell and where you sell it. We will come back with the obligations that actually apply — per country and per product stream.
