Under ESPR, the Digital Product Passport is designed to be enforced at the border, not just on the shelf: customs declarations for in-scope products will carry the passport's unique registration identifier, and customs authorities will verify it against the EU's central DPP registry, launched on . For exporters into the EU, this turns product data from a marketing nicety into a customs document. Here is the flow, the actors, the plumbing behind it, and a container-level walkthrough of what breaks it.
The flow in five steps
- Passport created. The responsible economic operator compiles the product's digital product passport with the data its category's rules require.
- Registry registration. The passport's unique identifier is registered in the EU's central DPP registry before the product is placed on the EU market. This registry — launched on , though no passport can be registered successfully in it yet — is the anchor of the whole enforcement design.
- Declaration. At import, the declarant includes the registration identifier in the customs declaration.
- Automated verification. Once the registry is connected to EU customs systems, customs systems check that the registration identifier and the commodity code match the registry. This is a data lookup, which is what makes the mechanism scalable across millions of consignments.
- Risk-based escalation. Whether the registration identifier and the commodity code match will be checked automatically; deeper checks of passport content remain risk-based, consistent with how EU customs handles other product compliance.
From sampling to lookup: why this is a different enforcement era
Product compliance at EU borders used to work on paper logic: documents accompanied goods, authorities sampled a fraction, and failures surfaced slowly. The registry model, once connected to customs, inverts the economics of getting caught.
| Paper era | Registry era | |
|---|---|---|
| Check coverage | Sampled fraction of consignments | Every declaration, automatically |
| Failure discovery | Weeks to years (market surveillance) | Instant, at the lookup |
| Who finds it first | An inspector, occasionally | A database, always |
| Fixing after the fact | Often possible quietly | Visible: the hold itself is the record |
| Compliance strategy that worked | React when asked | Be correct before shipping |
The practical translation for a supply chain: strategies built on "we'll fix it if anyone asks" stop working the day your category's obligation starts. Correctness moves from the warehouse of the importer to the ERP of the manufacturer.
Who does what: the actor map
| Actor | Role in the customs flow |
|---|---|
| Contract manufacturer (often non-EU) | Source of the passport data; contractually bound to deliver it |
| Manufacturer/brand and importer | The manufacturer ensures the digital product passport exists (Art. 27(1)(c)); the operator placing the product on the market — for imports, the importer — registers it before market placement (Art. 13(4)); an authorised representative cannot hold these duties (Art. 28(1)) |
| Declarant / customs broker | Files the declaration including the registration identifier |
| Customs authority | Will verify registration automatically once connected to the registry; escalates on risk signals |
| Market surveillance | Content-level scrutiny after goods are on the market |
The map explains why a factory thousands of kilometres from Rotterdam should care about a lookup it never performs: every upstream data failure surfaces at a desk downstream, with the factory's name attached to the purchase order.
The plumbing: where the digital product passport check plugs in
The digital product passport lookup is not being bolted onto customs from scratch. The EU has spent years building a Single Window Environment for Customs (Regulation (EU) 2022/2399): an architecture that lets customs systems automatically cross-check declarations against non-customs databases — health certificates, licences, and, once connected, product registries. The DPP registry is, structurally, one more database on that grid.
Two consequences follow. First, feasibility scepticism ("customs can't check millions of products") misreads the design — the infrastructure for automated cross-checks already clears other certificate types at scale. Second, the interface details being finalised are about connection, not concept: the direction of travel has been set since the Commission launched the registry on , even though the connection itself is still to be built.
What "risk-based" means in practice
Once running, automated registration checks will cover every declaration of a covered product; everything deeper is driven by risk scoring. Signals that typically raise a consignment's profile: a first-time importer or supplier, product categories under fresh obligations, inconsistencies between declaration fields and registry data, and past holds in the trade lane. Signals that lower it: a history of clean, consistent declarations.
This is the quiet commercial argument for data discipline: an importer whose digital product passports always verify builds a low-risk profile, which means faster clearance for every future container — and importers know which suppliers make that possible.
What this means on the factory side
The customs check validates a chain that starts months earlier in the factory: identifiers assigned, data collected, digital product passport compiled, registration completed. A supplier who delivers late or inconsistent data doesn't just create paperwork friction — they create a shipment that cannot legally clear. That is why EU buyers are moving DPP readiness into supplier contracts well before category deadlines, a shift we unpack in our guide for non-EU manufacturers.
Four failure modes to engineer out now:
- Identifier mismatch: the GTIN in the passport doesn't match what's on the product or in the commercial documents. Cheap to prevent with GTIN hygiene; expensive at a border.
- Late registration: goods shipped before the passport was registered. Process rule: registration is a pre-shipment gate, not a post-arrival cleanup.
- Orphaned data: the passport exists but required fields are empty because upstream suppliers never delivered evidence. Contracts should pass data obligations up the chain.
- Document drift: invoice, packing list and passport describing the same goods differently — mixed SKUs in one consignment are the classic trigger. Align the commercial paperwork with passport identifiers before shipment, not after arrival.
Walkthrough: a textile consignment, start to finish
Assume the textile delegated act is in force and the registry is connected to EU customs systems, and a manufacturer in İzmir ships 12,000 garments across three SKUs to a brand in Hamburg.
T minus 6 weeks: production completes; the factory delivers structured data per SKU — composition, facility ID, certificates matched to batches — to the brand. T minus 4 weeks: the brand (the economic operator) compiles three digital product passports and registers their identifiers in the EU registry; confirmation lands before anything is containerised. T minus 2 weeks: the factory's export documents are aligned — the same three GTINs appear identically on labels, packing list, invoice and passports. Arrival, Hamburg: the broker files the declaration with three registration identifiers; the automated lookup confirms all three; the consignment's clean history keeps its risk score low; release follows without physical inspection.
Now the counterfactual: one SKU's passport was registered with a GTIN that differs by one digit from the label. The automated lookup passes, because it compares only the registration identifier and the commodity code; a risk-based document check spots the mismatch instead, the consignment is held, storage charges start, the brand's compliance team spends three days regularising — and the factory's next purchase order arrives with a new clause and a smaller volume. Same goods, same quality, one digit.
Edge cases exporters ask about
Transit through the EU. The obligation attaches to placing goods on the EU market — typically release for free circulation. Goods crossing the EU under transit to a third country are a different procedure; but lanes change, and cargo occasionally gets diverted to EU buyers. If that is plausible for you, prepare as if the digital product passport is required.
Samples and small quantities. Commercial samples travel under their own customs treatments, but "it's just samples" is not a compliance category — clarify treatment with your broker per consignment rather than assuming exemption.
E-commerce parcels. Direct-to-consumer flows still constitute placing on the market, and the EU's wider customs reform is squeezing exactly this channel. Distance-selling manufacturers should assume parcel-level scrutiny will tighten, not loosen.
Returns and re-imports. Goods coming back and re-entering later inherit their original passport — one more reason identifiers must be stable and batch-linked rather than improvised per shipment.
A pre-shipment checklist for exporter–importer pairs
Agree these in writing while the rules are still landing: (1) registration is completed and confirmed before goods leave the factory; (2) a single reference sheet maps GTINs across product labels, passport records and commercial documents for every consignment; (3) data delivery deadlines for the manufacturer are tied to production milestones, not to shipping dates; (4) cost allocation for a held consignment is defined in advance. Pairs that settle these four points in 2026 will treat the first passport deadlines as a routine Tuesday.
The bigger picture: the border is becoming a data checkpoint
The digital product passport lane does not open in isolation. CBAM already requires embedded-emissions data for covered imports; the deforestation regulation ties commodities to geolocation data; and the DPP will tie products to registered passports. Three different regulations, one direction: EU market access increasingly means machine-verifiable data accompanying goods. Manufacturers who build one disciplined product-data backbone will satisfy each new lane at marginal cost; those who treat each regulation as a separate fire drill will pay for the same fix repeatedly. The passport is the best place to start, because its data structure — identity, composition, evidence — is the common denominator.
Timeline honesty
Digital product passport obligations start category by category: batteries from , though their registration identifier is not entered in the customs declaration; iron and steel after a delegated act indicated for (expected); textiles after one indicated for (expected), each plus a transition period. The automated customs check does not follow that sequence: it starts for every covered product once the registry is connected to EU customs systems, due by at the latest and expected by the Commission around (expected). Treat this article as the architecture, and your category's delegated act as the letter of the law.
Further reading: DPP for non-EU manufacturers · DPP for textiles · GS1 Digital Link vs QR
Frequently asked questions
Will customs physically scan QR codes on every imported product?
What happens if a shipment arrives without a registered digital product passport?
Who provides the registration identifier at import?
Is this live today?
Does the customs check look at the passport's content?
Do goods transiting the EU to a non-EU destination need a DPP?
Can good data history reduce our inspection rates?
What should exporters and importers agree on now?
Sources
- — Corrected: the automated customs check compares the registration identifier and the commodity code with the registry, and starts only once the registry is connected to EU customs systems; a battery's registration identifier is not entered in the customs declaration; the registry has launched but cannot accept passport registrations yet.

