Founding offer The Founding Partner Program is open — 20 companies, 50% off for life. Claim a spot →
For brands & retailers

The passport is a customer touchpoint. Most brands are treating it as paperwork.

You own the shelf, the packaging and the customer. You do not own the fibre percentages, the mill certificates or the carbon figure — and the EU is about to make all three public under your name.

10 min read· Updated Aug 2026
Retail shelf with branded products Retail
Brands & retailers
The passport appears under your name, not your supplier's
Denim garments on a rail 2027 H2
Textiles & apparel
First ESPR wave — fibre, origin and circularity
Wooden furniture in a showroom 2028+
Furniture
Later wave, same data architecture
Why this is harder for brands

Your name goes on data you do not hold

A brand sits at the end of the chain with the most exposure and the least raw information. Three structural problems follow from that, and none of them are solved by buying software alone.

The data lives upstream

Fibre composition, country of dyeing, recycled content and substance declarations sit with mills and suppliers — often as PDFs, often in three slightly different versions. Your passport project is a supplier communication project first.

The deadline is commercial, not legal

Your regulatory date may be 2027 or 2028. Your real date is whenever your largest retail partner makes DPP readiness a listing condition — and those letters are already going out.

A wrong QR breaks the till

Replace the barcode with a marketing QR and the product stops scanning at checkout. The passport code has to be a GS1 code, or packaging becomes a retail problem instead of a brand asset.

What you are working toward

The numbers that set your timeline

18 Feb 2027

First enforceable DPP date, from the EU Battery Regulation

2027 H2

Textile delegated act expected, transition period after

EN 18216–18223

The CEN/CENELEC series a compliant system must follow

1 code

Serves checkout, consumer, customs and recycler

What a brand is actually responsible for

Under the Ecodesign for Sustainable Products Regulation, the duty attaches to whoever places the product on the EU market. For most brands that is you, or your authorised representative. It does not matter that the fibre was spun in one country, dyed in another and sewn in a third — the passport carries your name, and a market surveillance authority will ask you, not your mill.

This is the point most brands underestimate. Compliance software can publish a passport in minutes. Getting trustworthy data into it takes months, because that data is held by companies who have no legal obligation to you beyond your contract.

Collecting supplier data without a year-long project

The instinct is to send a spreadsheet to every supplier and wait. It rarely works: each supplier answers in their own format, half the fields come back empty, and the version you receive in March is stale by September.

What works better is narrowing the ask. Start with the fields your buyers are already asking for — composition and origin — rather than the full future field list. Ask per SKU rather than per supplier, so the answer maps directly onto a product. And give suppliers a route that does not require them to buy software of their own; a supplier who has to purchase a platform to answer you will simply not answer.

  • Ask for the three fields buyers request today, not the twenty the delegated act may require in 2028
  • Request data per SKU, so it attaches to a product rather than to a relationship
  • Accept documents as well as fields — a test report PDF is evidence, a typed number is a claim
  • Version everything, because the passport must stay accurate after the first publication

Publishing a passport that looks like your brand

The regulation requires the data. It does not require an ugly page on someone else's domain. The passport is reached by scanning a code on your own packaging — for many products it will be the most-scanned digital surface the brand has, and it opens on a phone at the moment of purchase or use.

Two decisions determine whether that surface is yours. The first is the resolver domain: whether the URL a customer sees belongs to your brand or to a vendor. The second is presentation: whether the passport renders in your typography and colours or as a generic compliance table.

Both are worth deciding early, because the domain is printed on packaging you cannot recall. Changing a passport's destination later is easy; changing the domain on a million labels is not.

The tiered access most brands forget

A passport does not show the same thing to everyone. Consumers see care, composition and provenance. Market surveillance authorities and customs see compliance records. Recyclers see materials and disassembly guidance. Some fields are public, some restricted.

This matters commercially as well as legally: it means the passport can carry information you would not put on a public page — supplier detail, internal references, regulatory documentation — without exposing it to competitors. A system that publishes one flat public page for every scanner is not implementing the regulation, and it is also wasting the feature that makes the passport useful to you.

Turning the obligation into something customers want to scan

Most compliance projects end at "the data is published". The brands that get value from this go one step further and treat the scan as a moment: provenance the customer can follow, care instructions that extend the garment's life, repair and resale routes, and an honest account of what the product is made of.

The asymmetry is that the cost is already sunk. You are going to collect this data and publish it because the law says so. Presenting it well costs a fraction of collecting it, and it is the only part of the exercise a customer will ever see.

Questions brands ask before starting

Do we need a passport for every SKU?

For products in a regulated group, yes — the passport is per product, and where serialisation is required, per item. Products outside the scope of an adopted delegated act do not need one yet, which is why scoping is the first task rather than a formality.

Can our existing PIM handle this?

It handles part of it. A PIM stores product attributes well; it usually does not handle supplier evidence, tiered access, identifier resolution or the persistence requirement in EN 18221. Most brands end up connecting a PIM rather than replacing it.

What happens if a supplier refuses to provide data?

Then you cannot publish a compliant passport for that product, and the commercial answer arrives before the legal one: retailers who require DPP readiness will delist products that lack it. In practice, supplier data clauses are being written into new contracts now rather than after the deadline.

How brands get there

Five steps, in the order that actually works

Step 1
Scope
List product families, map each to a likely product group and its expected delegated act.
Step 2
Audit data
Find where composition, origin and certificates actually live today. Expect surprises.
Step 3
Identifiers
GTINs, operator and facility identifiers, and a resolver domain that belongs to you.
Step 4
One SKU
Take a single product end to end, from raw data to published passport.
Step 5
Scale
Roll out by family, starting with the lines closest to a regulatory or retailer deadline.

Build the passport your customers will actually scan

Passmith is pre-launch. The Founding Partner Program is open — 20 companies, 50% off for life.

Get early access