What a brand is actually responsible for
Under the Ecodesign for Sustainable Products Regulation, the duty attaches to whoever places the product on the EU market. For most brands that is you, or your authorised representative. It does not matter that the fibre was spun in one country, dyed in another and sewn in a third — the passport carries your name, and a market surveillance authority will ask you, not your mill.
This is the point most brands underestimate. Compliance software can publish a passport in minutes. Getting trustworthy data into it takes months, because that data is held by companies who have no legal obligation to you beyond your contract.
Collecting supplier data without a year-long project
The instinct is to send a spreadsheet to every supplier and wait. It rarely works: each supplier answers in their own format, half the fields come back empty, and the version you receive in March is stale by September.
What works better is narrowing the ask. Start with the fields your buyers are already asking for — composition and origin — rather than the full future field list. Ask per SKU rather than per supplier, so the answer maps directly onto a product. And give suppliers a route that does not require them to buy software of their own; a supplier who has to purchase a platform to answer you will simply not answer.
- Ask for the three fields buyers request today, not the twenty the delegated act may require in 2028
- Request data per SKU, so it attaches to a product rather than to a relationship
- Accept documents as well as fields — a test report PDF is evidence, a typed number is a claim
- Version everything, because the passport must stay accurate after the first publication
Publishing a passport that looks like your brand
The regulation requires the data. It does not require an ugly page on someone else's domain. The passport is reached by scanning a code on your own packaging — for many products it will be the most-scanned digital surface the brand has, and it opens on a phone at the moment of purchase or use.
Two decisions determine whether that surface is yours. The first is the resolver domain: whether the URL a customer sees belongs to your brand or to a vendor. The second is presentation: whether the passport renders in your typography and colours or as a generic compliance table.
Both are worth deciding early, because the domain is printed on packaging you cannot recall. Changing a passport's destination later is easy; changing the domain on a million labels is not.
The tiered access most brands forget
A passport does not show the same thing to everyone. Consumers see care, composition and provenance. Market surveillance authorities and customs see compliance records. Recyclers see materials and disassembly guidance. Some fields are public, some restricted.
This matters commercially as well as legally: it means the passport can carry information you would not put on a public page — supplier detail, internal references, regulatory documentation — without exposing it to competitors. A system that publishes one flat public page for every scanner is not implementing the regulation, and it is also wasting the feature that makes the passport useful to you.
Turning the obligation into something customers want to scan
Most compliance projects end at "the data is published". The brands that get value from this go one step further and treat the scan as a moment: provenance the customer can follow, care instructions that extend the garment's life, repair and resale routes, and an honest account of what the product is made of.
The asymmetry is that the cost is already sunk. You are going to collect this data and publish it because the law says so. Presenting it well costs a fraction of collecting it, and it is the only part of the exercise a customer will ever see.
Questions brands ask before starting
Do we need a passport for every SKU?
For products in a regulated group, yes — the passport is per product, and where serialisation is required, per item. Products outside the scope of an adopted delegated act do not need one yet, which is why scoping is the first task rather than a formality.
Can our existing PIM handle this?
It handles part of it. A PIM stores product attributes well; it usually does not handle supplier evidence, tiered access, identifier resolution or the persistence requirement in EN 18221. Most brands end up connecting a PIM rather than replacing it.
What happens if a supplier refuses to provide data?
Then you cannot publish a compliant passport for that product, and the commercial answer arrives before the legal one: retailers who require DPP readiness will delist products that lack it. In practice, supplier data clauses are being written into new contracts now rather than after the deadline.