Founding offer The Founding Partner Program is open — 1,000 companies, 6 months free. Start free →
Supplier Data

Digital Product Passport Supplier Data: How to Request, Contract and Verify It

A buyer-side playbook: the field map, a copyable request sheet, the identifier routine, contract clauses checked against the Data Act, verification rules and an escalation ladder for suppliers that cannot deliver.

14 min read · Updated Oct 2026
Container terminal with stacked freight

To get digital product passport supplier data, map the fields, send each supplier one structured request, put the duties in a contract annex, verify every value against evidence and escalate on a dated ladder. This playbook is for the brand or importer placing goods on the EU market.

New to passports? Start with what a digital product passport is. Suppliers being asked should read our guide for non-EU manufacturers.

What is digital product passport supplier data?

Digital product passport supplier data is any information a product passport must or may carry that originates with your tier-1, tier-2 or tier-3 suppliers: operator and facility identifiers, material composition, substances of concern, origin, certificates and test reports, plus the evidence behind each value. The operator placing the product on the EU market answers for its accuracy.

Tier 1 is the supplier you buy from; tier 2 supplies it (a fabric mill, a cell maker); tier 3 sits further up (a spinner, a refiner).

Why not leave it to suppliers? Passport data must be "accurate, complete and up to date" under Article 9(1) of Regulation (EU) 2024/1781, the ESPR (Ecodesign for Sustainable Products Regulation), and that duty is yours.

As the Commission's Joint Research Centre (JRC) notes, "data collection across the value chain is not regulated by the ESPR." So each duty below becomes a request, a clause or a check.

Which data comes from which supplier tier?

Start with a field map of your digital product passport supplier data, tagged by source and status. Tier 1 can answer most rows itself; the rest it must collect from tier 2 and 3, so the map also tells you whom to chase:

Field groupSourceEvidenceStatus
Operator and facility identifiersOwn system; tier 1–2 sitesGS1 licence, lookup recordESPR Annex III(g)–(i): expected
Product and part identifiersOwn licence; component makersGTIN lookup recordAnnex III(b)–(c): expected
Composition, substancesTier 1–2Bill of materials, REACH data, lab reportBattery Annex XIII 1(b): law; ESPR: expected
Origin, traceabilityTier 2–3 via tier 1Chain-of-custody recordsBattery Art. 49(2): from ; ESPR: expected
Recycled content, footprint inputsTier 1–3Certificates; energy and process dataBattery: not at passport start (FAQ Q7.2); ESPR: expected
Spare-part sourcesTier 1; component makersPart numbers, contactsBattery Annex XIII 2(b): law

Battery Annex XIII is the only list in adopted law, applying from . Guidance from the Commission's internal-market department (DG GROW), by its own terms not the Commission's official position, marks each data point mandatory, optional, applicable only in certain cases, or not to be filled at passport start.

ESPR fields stay expected until each act is adopted: steel (expected), textiles (expected). See our textile data guide and battery passport guide.

Limit the request to fields a law or act asks for. Labour and social questionnaires add supplier burden and, unless another law requires them, get no shelter from Data Act Article 13(2) (see the fairness check).

What should your data request contain?

A digital product passport supplier data request needs one row per field and value, never free text. Paste this header into a sheet or portal:

supplier_id,site_gln,your_gtin,your_batch,supplier_lot,field,value,unit,evidence_id,evidence_expiry,access,signed_by,date

Values go in the sheet; documents arrive as PDFs named by evidence_id. The fields:

FieldLevelUnit or vocabularyEvidenceAccess
Legal name, address, operator ID or signed "none exists"OperatorISO 3166 country; legal-entity GLNRegister extract; GS1 lookup or signed formPer act
Each production siteFacilityLocation GLN, addressSite certificatePer act
Part GTIN (Annex III(c))ModelGTIN from the supplier's licenceVerified by GS1Per act
Supplier lot ↔ your GTIN and batchBatchLot ID per deliveryDelivery noteRestricted
ComponentsModel or batch% by mass, total 100Bill of materialsRestricted
Substances of concernModel or batchName, EC/CAS, location, % w/wREACH data, lab reportPer act
Recycled shareBatch% by massCertificate IDBattery: public (XIII 1(e)); ESPR: per act
Recycled-content evidenceBatchCertificates, mass-balance recordsCertificateAuthorities
Processing countriesBatchISO 3166 per stageTransaction recordsRestricted
Test reportsBatchLab, date, standardLab reportAuthorities
CertificatesSite or batchHolder, scope, expiryCertificateRestricted
DeclarationOperatorSignatory, role, dateSignatureInternal

Vocabulary and access. All passport data must follow the data models of the Commission's semantic repository (Implementing Regulation (EU) 2026/1778, Art. 11(3)), which the registry checks at registration, so ask for those units and code lists from day one. "Per act" means the delegated act decides; treat such rows as restricted and agree every tag in writing.

Granularity. The battery FAQ (Q7.7) treats a 1% or 0.1% composition threshold as potentially reasonable, but not a bare label such as "LFP". Write the threshold into the row.

Cover letter (copy and adapt):

Subject: Product passport data request — [product group], reply by [date]

We place [products] on the EU market and must keep their digital product passports accurate, complete and up to date (Regulation (EU) 2024/1781, Article 9(1)).

Please complete the attached sheet for each product and site by [date]; name each document by its evidence ID.

We will use your data only for passports, legal obligations and authority requests, and show each field only to its agreed audience unless Union law requires wider disclosure. We will tell you before any field becomes public. Contact: [name, email].

How do you get missing operator and facility identifiers?

ESPR Article 12(2)–(3) sets a routine whenever your digital product passport supplier data names a supplier or site without an identifier:

  1. Ask (procurement): a legal-entity GLN for the company, a location GLN per site. GS1's provisional, unratified DPP standard names the GLN as operator and facility identifier.
  2. Confirm in writing (procurement): if none exists, get a signed, dated confirmation. The law requires this first.
  3. Request on the supplier's behalf (compliance): through an ISO/IEC 15459 issuing agency, such as a GS1 member organisation for a GLN; the licence will be in the supplier's name.
  4. Send and record (compliance, data owner): give the supplier full details once issued; enter the identifier with its evidence.

Pick the route by the supplier's situation:

SupplierWhat you do
Holds a GS1 licenceIt allocates a legal-entity GLN and a location GLN per site; you check both
No licence, willingPrepare its application to its national GS1 member organisation together, in its name; log this as your Article 12 request; agree who pays the fee
No licence, unwilling or unableLog the signed confirmation and your request; ask the issuing agency what it can issue; mark the field "pending: Art. 12(4) act not adopted"

Never hand a supplier an operator GLN from your own prefix: GS1 says an organisation "SHALL NOT use a GLN from another organisation's licence to represent itself as a party."

GS1 lets a primary user allocate a site's GLN, but whether that satisfies Article 12(3) is unsettled until the Article 12(4) act; prefer the supplier's own. See step 3 of our implementation plan.

In what order should you send requests?

Send digital product passport supplier data requests in waves, so early answers shape later questions:

WaveWeeksAsk forFrom
11–4Identity, identifiers, sites, contactsTier 1
25–10Composition, substances, certificates, test reportsTier 1; tier 2 for components
311–20Origin per stage, recycled-content evidenceTier 2–3 through tier 1

Wave 2 starts from REACH. Under REACH Article 33, an EU supplier of an article containing a Candidate List substance above 0.1% by weight, measured per component article (Court of Justice, C-106/14), must already give you at least its name. Ask for that data first.

Wave 3 runs on a flow-down clause. Model it on the battery traceability list (Batteries Regulation Art. 49(2)) and have tier 1 collect, per input:

  • material description and trade name;
  • each upstream supplier's name and address;
  • country of origin and transactions back to extraction;
  • quantities, by percentage or weight;
  • third-party verification reports.

Few upstream suppliers owe you this by law; for batteries, see our due diligence guide.

Count back from the date your digital product passport supplier data must be live:

  1. Battery operators. Finish and verify waves 1–2 (Annex XIII 1(a)–(b), 2(a)–(b)) before . Run wave 3 after go-live: footprint, recycled content and due diligence information "will not yet be required" then (battery FAQ Q7.2). With under about 14 weeks left (10 for waves 1–2, plus verification), send waves 1 and 2 together.
  2. ESPR operators. An act normally applies at least 18 months after entry into force, so the 20-week plan fits. Start identifiers now, the rest once your act is adopted.
  3. Everyone. Draft the wave-3 flow-down clause in week 1: upstream replies take longest.

Which contract clauses secure the data?

Put every digital product passport supplier data clause in one annex, with the duty each clause protects. One annex is easier to flow down to tier 2 than clauses scattered through a supply agreement:

ClauseWhat it saysLegal hook
DeliveryTemplate fields, deadline per order or batchESPR Art. 9(1)
Accuracy warrantyData true and complete; named signatoryArt. 9(1)
Change noticeBefore any material, site or sub-supplier changeArt. 27(4)
Retention10 years after your last placement of a product with the input; longer if the act saysArt. 27(3); Annex IV
Evidence on requestWithin 5 working daysYour 15 days (Art. 27(10), 29(8))
AuditDocument review, site visit, sample testsArt. 9(1)
ConfidentialityAudience per field; authority and later-act disclosure allowedRecital 33; battery Annex XIII tiers
Flow-downSame duties for sub-suppliersBattery Art. 49(1)(e) model
Update rightsWritten, field-limited, revocableBattery Art. 77(4); ESPR Art. 9(2)(g)
RemediesCure period, agreed re-test cost split, suspensionBattery FAQ Q10.2: responsibility is not liability

Three sample wordings:

  • Change notice. "The Supplier shall notify the Buyer in writing at least [60] days before any change of material, formulation, production site or sub-supplier, and deliver updated data before the first changed delivery."
  • Retention. "The Supplier shall keep all evidence supporting Supplier Data until 10 years after the Buyer last places on the market a Product containing the Supplier's input, as notified by the Buyer, or for any longer period set by the applicable delegated act."
  • Use limit. "The Buyer shall use Supplier Data only for product passports, its legal obligations and authority requests, and shall disclose each field only to the audience agreed in this annex unless Union law requires wider disclosure, notifying the Supplier first."

You need the use limit because Article 11 bars only DPP service providers from reusing passport data, not you.

Fairness check. Under Article 13 of the EU Data Act, Regulation (EU) 2023/2854, an unfair data term one company imposes unilaterally on another is not binding: in contracts concluded after , and from in certain older long-term contracts. Test each clause:

  • Required by law? Terms reflecting mandatory Union law are not unfair (13(2)). The ESPR gives suppliers no delivery duty, so tying demands to it lowers risk but guarantees nothing; REACH Article 33 data fits best.
  • Reuse? Using supplier data in a way significantly detrimental to the supplier is presumed unfair (13(5)(b)).
  • Liability? Extending the supplier's liability, or inappropriately limiting its remedies, is presumed unfair (13(5)(a)); keep cost recovery proportionate and negotiated.
  • Who judges conformity? An exclusive right to decide whether data conforms is unfair (13(4)(c)); write objective acceptance rules.
  • Negotiated? A term the supplier tried and failed to influence counts as imposed (13(6)); keep a negotiation record.

The Digital Omnibus proposal leaves Article 13 untouched.

How do you verify what suppliers send?

The Commission's DPP FAQ gives market surveillance authorities the main role in verifying passport accuracy. Your own checks on digital product passport supplier data come first, so run these before anything is published:

CheckRuleIf it fails
CertificateHolder, site, scope and validity match the batchDrop the claim; request a current certificate
IdentifierCheck digit valid; record in Verified by GS1Bad digit: return it. No record: ask for the licence or member organisation confirmation
CompositionMass shares total 100%Return the row
Recycled shareNot above certified recycled input boughtCut to the documented share
SiteAddress matches the certificate, not just a found GLN; traders name the plantAsk which site produced
Lot linkEvery batch traces to supplier lotsPublish no batch-level claim
Spot testRisk-based: new suppliers, claims, tradersEscalate

Store an evidence ID next to every value of your digital product passport supplier data. The semantic repository covers links between passport attributes and underlying evidence from the value chain (Implementing Regulation (EU) 2026/1778, Art. 12(2)(a)).

What if a supplier cannot or will not deliver?

When digital product passport supplier data is missing, escalate one rung at a time, each with a date:

  1. Clarify (weeks 1–2). Send a filled example row; many gaps are format problems.
  2. Dated gap plan (by week 4). A committed date per missing field.
  3. Leave it empty, not guessed. Mark the field "pending: supplier" and publish no claim. The JRC expects "default values are to be used" at first, but that is analysis, not law: use a flagged default only where the act governing that field permits one.
  4. Generate the evidence (weeks 4–8). A lab test of composition or substances, costs shared as the annex agrees.
  5. Make delivery an order condition (next order) and qualify a second source.
  6. Suspend. The Batteries Regulation models it: consider "suspending or discontinuing engagement with a supplier" after failed mitigation (Art. 50(1)(b)(iii)).

Track each supplier's rung in one sheet:

supplier,wave,sent,due,received,verified,open_fields,rung,next_action,next_date,owner

The importer's hard stop. An importer must not place a non-conforming product on the market until it conforms (ESPR Art. 29(2)), so missing supplier data can stop an import. See also DPP for importers.

Confidentiality fallback. If a supplier will disclose only to authorities, hold the evidence for them; the JRC calls recycled-content evidence "a trade secret" that "would not be public". But substances of very high concern above 0.1% "shall not be exempted" (ESPR Art. 7(6)(b)).

Record each rung in the supplier's file: if an authority later asks why a field was empty, the dated trail of your digital product passport supplier data requests is your answer.

How do you keep supplier data current?

Digital product passport supplier data goes stale the day a supplier changes a recipe, a site or a certificate. Give every supplier field a trigger, a watcher and an action:

TriggerWho noticesAction
Change notice: material, formula or siteSupplierRe-collect; reassess conformity (Art. 27(4))
New sub-supplierSupplier, via flow-downIdentifier routine; re-run wave 3 for that input
REACH Candidate List updateComplianceSuppliers re-confirm substances
Yearly cycleData ownerSupplier re-signs the declaration

Version your digital product passport supplier data in your own system: what changed, who, which evidence. Push every update to the live passport and its back-up (ESPR Art. 27(1)(c)).

Walkthrough: a hypothetical workwear brand in Tilburg

Take a hypothetical workwear brand in Tilburg, the Netherlands, with 140 SKUs. Assume the textile act, not yet adopted, is in force and requires identifiers, composition and recycled content. Tier 1: sewing plants in Porto and Bursa; tier 2: three fabric mills; tier 3: spinners. Here is how its digital product passport supplier data moves through the plan.

  • Weeks 1–2: the field map lists 23 fields: 9 from the brand's own systems, 11 from tier 1, 3 from tiers 2–3.
  • Week 3: the digital product passport supplier data request goes to Porto and Bursa.
  • Week 5: Porto returns a legal-entity GLN and a location GLN, both in Verified by GS1. Bursa confirms in writing it has none. The brand logs this, then, as its Article 12 request, prepares with Bursa an application to the GS1 member organisation in Türkiye, licence in Bursa's name.
  • Week 6: Bursa objects to the audit clause; the brand narrows it to document review and one announced visit a year, filing the exchange as its negotiation record (Data Act Art. 13(6)).
  • Week 9: checks catch two errors. A jacket lists 65% polyester and 36% cotton (101%); the fabric specification says 64/36. A fleece claims 30% recycled polyester, but certificates cover purchases equal to 18%, so the claim drops to 18%.
  • Weeks 11–20: one mill will not name its spinners. Rung 1: a filled sample row. Rung 2: a week-16 date for two of three. The third stays "pending: supplier", with no origin claim for that yarn.

Two counterfactuals. Had Bursa's head-office GLN been entered as the facility identifier, the digital product passport supplier data would point to an office, not the plant; the site check catches it. Had the fleece gone live at 30%, an authority's reasoned request would have needed the evidence within 15 days (ESPR Art. 27(10)), and the certificates would have covered only 18%.

The adopted-law contrast. A hypothetical Graz assembler of 10 kWh home-storage batteries (industrial batteries above 2 kWh) needs Annex XIII 1(b) and 2(a)–(b) data from its cell maker from . The cell maker uploads it under a written Article 77(4) authorisation limited to those fields; the assembler stays responsible.

Edge cases: when does collection work differently?

These cases change where digital product passport supplier data comes from, not the routine.

The supplier is a trader. A trading office is not the production site: have the trader name the plant that made the goods, or reveal the next tier.

Private label. You are the manufacturer (ESPR Art. 2(42)), so put the clause annex into your private-label agreement.

Authorised representative. Its mandate cannot include the Article 27(1) duties (Art. 28(1)). Contract supplier data yourself.

Battery cells and modules. Normally, imported cells that are merely components "are not themselves treated as the finished battery" (battery FAQ Q3.4), except do-it-yourself kits sold ready for end users. The cell maker then has no passport duty; your contract is the route to its data.

Zoom out: one supplier request, several laws

RegimeSupplier dataStatus
Battery due diligence, Art. 49(2)Name, address, origin, quantitiesLaw from ; scope may change
EUDR, Art. 9(1)(e)Name, postal address, emailLaw from ; micro and small operators from
Conflict minerals, Reg. (EU) 2017/821 Art. 4(f)–(g)Name, address; origin and quantities (minerals) or smelters and refiners (metals)Law for Union importers of tin, tantalum, tungsten, gold above Annex I thresholds
REACH Art. 33Candidate List substances above 0.1%Law for EU suppliers

They overlap with digital product passport supplier data at the core: who the supplier is, where material comes from, how much. Build one annex with a module per regime, not one questionnaire per law. See our EUDR guide.

Watch these pending items; each would change your digital product passport supplier data request or clauses:

Pending itemWhat it would changeDo now
ESPR product-group actsFields, level, accessKeep "expected" rows; collect identifiers
Article 12(4) actWho issues identifiersLog every confirmation and request
Battery access-rights act, Art. 77(9): overdue, Commission timeline (expected)Who counts as a legitimate-interest person for Annex XIII point 2Keep the disclosure carve-out
Battery proposal COM(2025) 981Label substance list, also in the passport, redefined as substances of very high concern at or above 0.1%Ask cell suppliers for Candidate List concentrations
Omnibus IV, COM(2025) 501Higher due diligence threshold; fewer suppliers owe disclosureKeep the flow-down clause

The practical conclusion: build one digital product passport supplier data request and one evidence file per supplier, and let each law draw on it. A second questionnaire for the next regulation is the expensive path.

What should you do in the next 60 days?

Seven steps start your digital product passport supplier data programme. None of them waits for your delegated act:

  1. Field map (weeks 1–2, compliance): every field, source tier, adopted or expected.
  2. Request sheet (week 3, procurement): send it, with the cover letter, to your top five suppliers.
  3. Identifier routine (weeks 3–6, compliance): ask, confirm, request, send, record.
  4. Contract annex (weeks 3–6, legal): draft the clauses; run the Data Act check.
  5. Verification rules (week 6, quality): checks plus the evidence-ID rule.
  6. Escalation ladder (week 7, management): rungs, deadlines and the tracker.
  7. Change calendar (week 8, data owner): triggers, certificate expiries, yearly re-signature.

Once your GTINs and batches link to supplier lots, make a test code for one GTIN: Passmith's free GS1 Digital Link QR generator needs no signup and runs in your browser. Passmith also has a free plan.

Further reading: What is a digital product passport? · DPP implementation in 8 steps · Battery passport · CSDDD due diligence · GS1 Digital Link

Frequently asked questions

Are suppliers legally required to provide digital product passport supplier data?
Mostly not. The ESPR puts the passport duty on the operator placing the product on the EU market and gives suppliers no data-delivery duty. A few supplier duties exist elsewhere: EU suppliers of articles must already pass on Candidate List substance information under REACH Article 33, and in-scope battery operators will have to share due diligence information downstream. Everything else needs a contract clause.
What format should suppliers deliver data in?
One structured sheet, such as CSV, or direct entry in your supplier portal, with one value per row. A PDF questionnaire cannot be mapped into a passport. Ask for units and vocabularies that match the registry's semantic repository, because all passport data must follow its data models. Certificates and test reports can stay PDFs, each named by the evidence ID of the value it proves.
Who requests a facility identifier if the factory has none?
The economic operator that creates or updates the passport. Under ESPR Article 12(3), it must first seek confirmation that no facility identifier exists, then request one on behalf of the actor responsible for the site and give that actor full details once issued. For a GLN, that means a GS1 member organisation, with the licence in the supplier's name, not yours.
Can a supplier update our passport directly?
For batteries, yes, if you give it written authorisation under Article 77(4) of the Batteries Regulation; you remain responsible for accuracy. For ESPR products, each delegated act decides which actors may create or update passport data (Article 9(2)(g)), and no such act exists yet. Whatever the route, limit the authorisation to named fields and keep an audit trail of each change.
How do we protect a supplier's confidential data?
Classify each field by audience (public, legitimate interest, authorities only) and agree that classification in writing, allowing wider disclosure where a later act requires it. The ESPR provides for access that differs by data and stakeholder, and bars DPP service providers from reusing passport data without your agreement. That bar does not bind you, so promise to use supplier data only for passport and compliance purposes.
Who pays for lab tests when a supplier cannot document composition?
Whoever your contract names. Passport law makes you answer for accuracy but leaves costs and liability between you and your supplier to the contract; the Commission's battery FAQ notes that regulatory responsibility differs from legal liability. Agree the split in the supplier annex before a test is needed. If you impose it unilaterally, keep it proportionate: the Data Act presumes unfair a term that extends the supplier's liability.
Should we collect supplier data before our product group's act is adopted?
Partly. Start with items useful whatever your act says: supplier and site identifiers, which ESPR Annex III lists as passport elements, the REACH Article 33 information EU suppliers already owe you, and a signed contract annex. Leave product-specific fields until your act is adopted; it normally applies at least 18 months after entry into force. Batteries differ: their passport list is already adopted law.

Sources

  1. Regulation (EU) 2024/1781 (ESPR) — EUR-Lex — 2026-10-07
  2. Regulation (EU) 2023/1542 (Batteries Regulation) — EUR-Lex — 2026-10-07
  3. Regulation (EU) 2025/1561 amending Regulation (EU) 2023/1542 as regards battery due diligence dates — EUR-Lex — 2026-10-07
  4. Commission Implementing Regulation (EU) 2026/1778 on the digital product passport registry — EUR-Lex — 2026-10-07
  5. Regulation (EU) 2023/2854 (Data Act) — EUR-Lex — 2026-10-07
  6. Proposal COM(2025) 837 (Digital Omnibus) — EUR-Lex — 2026-10-07
  7. Regulation (EC) No 1907/2006 (REACH), Article 33 — EUR-Lex — 2026-10-07
  8. Court of Justice, Case C-106/14 (FCD and FMB), judgment on REACH Article 33 — EUR-Lex — 2026-10-07
  9. Regulation (EU) 2023/1115 (EUDR) — EUR-Lex — 2026-10-07
  10. Regulation (EU) 2025/2650 amending the EUDR — EUR-Lex — 2026-10-07
  11. Regulation (EU) 2017/821 (Conflict Minerals Regulation) — EUR-Lex — 2026-10-07
  12. European Parliament Legislative Observatory — procedure 2025/0397(COD), battery simplification proposal COM(2025) 981 — 2026-10-07
  13. European Parliament Legislative Observatory — procedure 2025/0130(COD), Omnibus IV proposal COM(2025) 501 — 2026-10-07
  14. European Commission — Frequently Asked Questions on the Digital Product Passport — 2026-10-07
  15. European Commission — EU Digital Product Passport FAQ for Batteries — 2026-10-07
  16. European Commission (DG GROW) — Guidance Document: Digital Batteries Passport – data points by category, Version 2.0 (15 August 2026) — 2026-10-07
  17. European Commission — Digital Product Passport (indicative timeline) — 2026-10-07
  18. JRC — Methodology for defining data requirements for the Digital Product Passport under the ESPR framework (JRC145830, 2026) — 2026-10-07
  19. GS1 — DPP provisional application standard, GSCN 26-226, release 2 (Jun 2026, not ratified) — 2026-10-07
  20. GS1 General Specifications Standard, Release 26.0 (Jan 2026), section 4.5.1 (GLN allocation) — 2026-10-07
  21. GS1 — Global Location Number (GLN) — 2026-10-07
  22. GS1 — Verified by GS1 — 2026-10-07
Digital Product Passport platform

Built on GS1 Digital Link and EN 18216, 18219–18223, from offices in the Netherlands, Türkiye and Azerbaijan.

Last updated:

You're in time

6 months free

Worth up to€1,4946 × €249

First 6 months€0

Reserved for the first 1,000 companies

Create your account, choose Starter or Growth, and pay €0 for six months. No credit card required.