To get digital product passport supplier data, map the fields, send each supplier one structured request, put the duties in a contract annex, verify every value against evidence and escalate on a dated ladder. This playbook is for the brand or importer placing goods on the EU market.
New to passports? Start with what a digital product passport is. Suppliers being asked should read our guide for non-EU manufacturers.
What is digital product passport supplier data?
Digital product passport supplier data is any information a product passport must or may carry that originates with your tier-1, tier-2 or tier-3 suppliers: operator and facility identifiers, material composition, substances of concern, origin, certificates and test reports, plus the evidence behind each value. The operator placing the product on the EU market answers for its accuracy.
Tier 1 is the supplier you buy from; tier 2 supplies it (a fabric mill, a cell maker); tier 3 sits further up (a spinner, a refiner).
Why not leave it to suppliers? Passport data must be "accurate, complete and up to date" under Article 9(1) of Regulation (EU) 2024/1781, the ESPR (Ecodesign for Sustainable Products Regulation), and that duty is yours.
As the Commission's Joint Research Centre (JRC) notes, "data collection across the value chain is not regulated by the ESPR." So each duty below becomes a request, a clause or a check.
Which data comes from which supplier tier?
Start with a field map of your digital product passport supplier data, tagged by source and status. Tier 1 can answer most rows itself; the rest it must collect from tier 2 and 3, so the map also tells you whom to chase:
| Field group | Source | Evidence | Status |
|---|---|---|---|
| Operator and facility identifiers | Own system; tier 1–2 sites | GS1 licence, lookup record | ESPR Annex III(g)–(i): expected |
| Product and part identifiers | Own licence; component makers | GTIN lookup record | Annex III(b)–(c): expected |
| Composition, substances | Tier 1–2 | Bill of materials, REACH data, lab report | Battery Annex XIII 1(b): law; ESPR: expected |
| Origin, traceability | Tier 2–3 via tier 1 | Chain-of-custody records | Battery Art. 49(2): from ; ESPR: expected |
| Recycled content, footprint inputs | Tier 1–3 | Certificates; energy and process data | Battery: not at passport start (FAQ Q7.2); ESPR: expected |
| Spare-part sources | Tier 1; component makers | Part numbers, contacts | Battery Annex XIII 2(b): law |
Battery Annex XIII is the only list in adopted law, applying from . Guidance from the Commission's internal-market department (DG GROW), by its own terms not the Commission's official position, marks each data point mandatory, optional, applicable only in certain cases, or not to be filled at passport start.
ESPR fields stay expected until each act is adopted: steel (expected), textiles (expected). See our textile data guide and battery passport guide.
Limit the request to fields a law or act asks for. Labour and social questionnaires add supplier burden and, unless another law requires them, get no shelter from Data Act Article 13(2) (see the fairness check).
What should your data request contain?
A digital product passport supplier data request needs one row per field and value, never free text. Paste this header into a sheet or portal:
supplier_id,site_gln,your_gtin,your_batch,supplier_lot,field,value,unit,evidence_id,evidence_expiry,access,signed_by,date
Values go in the sheet; documents arrive as PDFs named by evidence_id. The fields:
| Field | Level | Unit or vocabulary | Evidence | Access |
|---|---|---|---|---|
| Legal name, address, operator ID or signed "none exists" | Operator | ISO 3166 country; legal-entity GLN | Register extract; GS1 lookup or signed form | Per act |
| Each production site | Facility | Location GLN, address | Site certificate | Per act |
| Part GTIN (Annex III(c)) | Model | GTIN from the supplier's licence | Verified by GS1 | Per act |
| Supplier lot ↔ your GTIN and batch | Batch | Lot ID per delivery | Delivery note | Restricted |
| Components | Model or batch | % by mass, total 100 | Bill of materials | Restricted |
| Substances of concern | Model or batch | Name, EC/CAS, location, % w/w | REACH data, lab report | Per act |
| Recycled share | Batch | % by mass | Certificate ID | Battery: public (XIII 1(e)); ESPR: per act |
| Recycled-content evidence | Batch | Certificates, mass-balance records | Certificate | Authorities |
| Processing countries | Batch | ISO 3166 per stage | Transaction records | Restricted |
| Test reports | Batch | Lab, date, standard | Lab report | Authorities |
| Certificates | Site or batch | Holder, scope, expiry | Certificate | Restricted |
| Declaration | Operator | Signatory, role, date | Signature | Internal |
Vocabulary and access. All passport data must follow the data models of the Commission's semantic repository (Implementing Regulation (EU) 2026/1778, Art. 11(3)), which the registry checks at registration, so ask for those units and code lists from day one. "Per act" means the delegated act decides; treat such rows as restricted and agree every tag in writing.
Granularity. The battery FAQ (Q7.7) treats a 1% or 0.1% composition threshold as potentially reasonable, but not a bare label such as "LFP". Write the threshold into the row.
Cover letter (copy and adapt):
Subject: Product passport data request — [product group], reply by [date]
We place [products] on the EU market and must keep their digital product passports accurate, complete and up to date (Regulation (EU) 2024/1781, Article 9(1)).
Please complete the attached sheet for each product and site by [date]; name each document by its evidence ID.
We will use your data only for passports, legal obligations and authority requests, and show each field only to its agreed audience unless Union law requires wider disclosure. We will tell you before any field becomes public. Contact: [name, email].
How do you get missing operator and facility identifiers?
ESPR Article 12(2)–(3) sets a routine whenever your digital product passport supplier data names a supplier or site without an identifier:
- Ask (procurement): a legal-entity GLN for the company, a location GLN per site. GS1's provisional, unratified DPP standard names the GLN as operator and facility identifier.
- Confirm in writing (procurement): if none exists, get a signed, dated confirmation. The law requires this first.
- Request on the supplier's behalf (compliance): through an ISO/IEC 15459 issuing agency, such as a GS1 member organisation for a GLN; the licence will be in the supplier's name.
- Send and record (compliance, data owner): give the supplier full details once issued; enter the identifier with its evidence.
Pick the route by the supplier's situation:
| Supplier | What you do |
|---|---|
| Holds a GS1 licence | It allocates a legal-entity GLN and a location GLN per site; you check both |
| No licence, willing | Prepare its application to its national GS1 member organisation together, in its name; log this as your Article 12 request; agree who pays the fee |
| No licence, unwilling or unable | Log the signed confirmation and your request; ask the issuing agency what it can issue; mark the field "pending: Art. 12(4) act not adopted" |
Never hand a supplier an operator GLN from your own prefix: GS1 says an organisation "SHALL NOT use a GLN from another organisation's licence to represent itself as a party."
GS1 lets a primary user allocate a site's GLN, but whether that satisfies Article 12(3) is unsettled until the Article 12(4) act; prefer the supplier's own. See step 3 of our implementation plan.
In what order should you send requests?
Send digital product passport supplier data requests in waves, so early answers shape later questions:
| Wave | Weeks | Ask for | From |
|---|---|---|---|
| 1 | 1–4 | Identity, identifiers, sites, contacts | Tier 1 |
| 2 | 5–10 | Composition, substances, certificates, test reports | Tier 1; tier 2 for components |
| 3 | 11–20 | Origin per stage, recycled-content evidence | Tier 2–3 through tier 1 |
Wave 2 starts from REACH. Under REACH Article 33, an EU supplier of an article containing a Candidate List substance above 0.1% by weight, measured per component article (Court of Justice, C-106/14), must already give you at least its name. Ask for that data first.
Wave 3 runs on a flow-down clause. Model it on the battery traceability list (Batteries Regulation Art. 49(2)) and have tier 1 collect, per input:
- material description and trade name;
- each upstream supplier's name and address;
- country of origin and transactions back to extraction;
- quantities, by percentage or weight;
- third-party verification reports.
Few upstream suppliers owe you this by law; for batteries, see our due diligence guide.
Count back from the date your digital product passport supplier data must be live:
- Battery operators. Finish and verify waves 1–2 (Annex XIII 1(a)–(b), 2(a)–(b)) before . Run wave 3 after go-live: footprint, recycled content and due diligence information "will not yet be required" then (battery FAQ Q7.2). With under about 14 weeks left (10 for waves 1–2, plus verification), send waves 1 and 2 together.
- ESPR operators. An act normally applies at least 18 months after entry into force, so the 20-week plan fits. Start identifiers now, the rest once your act is adopted.
- Everyone. Draft the wave-3 flow-down clause in week 1: upstream replies take longest.
Which contract clauses secure the data?
Put every digital product passport supplier data clause in one annex, with the duty each clause protects. One annex is easier to flow down to tier 2 than clauses scattered through a supply agreement:
| Clause | What it says | Legal hook |
|---|---|---|
| Delivery | Template fields, deadline per order or batch | ESPR Art. 9(1) |
| Accuracy warranty | Data true and complete; named signatory | Art. 9(1) |
| Change notice | Before any material, site or sub-supplier change | Art. 27(4) |
| Retention | 10 years after your last placement of a product with the input; longer if the act says | Art. 27(3); Annex IV |
| Evidence on request | Within 5 working days | Your 15 days (Art. 27(10), 29(8)) |
| Audit | Document review, site visit, sample tests | Art. 9(1) |
| Confidentiality | Audience per field; authority and later-act disclosure allowed | Recital 33; battery Annex XIII tiers |
| Flow-down | Same duties for sub-suppliers | Battery Art. 49(1)(e) model |
| Update rights | Written, field-limited, revocable | Battery Art. 77(4); ESPR Art. 9(2)(g) |
| Remedies | Cure period, agreed re-test cost split, suspension | Battery FAQ Q10.2: responsibility is not liability |
Three sample wordings:
- Change notice. "The Supplier shall notify the Buyer in writing at least [60] days before any change of material, formulation, production site or sub-supplier, and deliver updated data before the first changed delivery."
- Retention. "The Supplier shall keep all evidence supporting Supplier Data until 10 years after the Buyer last places on the market a Product containing the Supplier's input, as notified by the Buyer, or for any longer period set by the applicable delegated act."
- Use limit. "The Buyer shall use Supplier Data only for product passports, its legal obligations and authority requests, and shall disclose each field only to the audience agreed in this annex unless Union law requires wider disclosure, notifying the Supplier first."
You need the use limit because Article 11 bars only DPP service providers from reusing passport data, not you.
Fairness check. Under Article 13 of the EU Data Act, Regulation (EU) 2023/2854, an unfair data term one company imposes unilaterally on another is not binding: in contracts concluded after , and from in certain older long-term contracts. Test each clause:
- Required by law? Terms reflecting mandatory Union law are not unfair (13(2)). The ESPR gives suppliers no delivery duty, so tying demands to it lowers risk but guarantees nothing; REACH Article 33 data fits best.
- Reuse? Using supplier data in a way significantly detrimental to the supplier is presumed unfair (13(5)(b)).
- Liability? Extending the supplier's liability, or inappropriately limiting its remedies, is presumed unfair (13(5)(a)); keep cost recovery proportionate and negotiated.
- Who judges conformity? An exclusive right to decide whether data conforms is unfair (13(4)(c)); write objective acceptance rules.
- Negotiated? A term the supplier tried and failed to influence counts as imposed (13(6)); keep a negotiation record.
The Digital Omnibus proposal leaves Article 13 untouched.
How do you verify what suppliers send?
The Commission's DPP FAQ gives market surveillance authorities the main role in verifying passport accuracy. Your own checks on digital product passport supplier data come first, so run these before anything is published:
| Check | Rule | If it fails |
|---|---|---|
| Certificate | Holder, site, scope and validity match the batch | Drop the claim; request a current certificate |
| Identifier | Check digit valid; record in Verified by GS1 | Bad digit: return it. No record: ask for the licence or member organisation confirmation |
| Composition | Mass shares total 100% | Return the row |
| Recycled share | Not above certified recycled input bought | Cut to the documented share |
| Site | Address matches the certificate, not just a found GLN; traders name the plant | Ask which site produced |
| Lot link | Every batch traces to supplier lots | Publish no batch-level claim |
| Spot test | Risk-based: new suppliers, claims, traders | Escalate |
Store an evidence ID next to every value of your digital product passport supplier data. The semantic repository covers links between passport attributes and underlying evidence from the value chain (Implementing Regulation (EU) 2026/1778, Art. 12(2)(a)).
What if a supplier cannot or will not deliver?
When digital product passport supplier data is missing, escalate one rung at a time, each with a date:
- Clarify (weeks 1–2). Send a filled example row; many gaps are format problems.
- Dated gap plan (by week 4). A committed date per missing field.
- Leave it empty, not guessed. Mark the field "pending: supplier" and publish no claim. The JRC expects "default values are to be used" at first, but that is analysis, not law: use a flagged default only where the act governing that field permits one.
- Generate the evidence (weeks 4–8). A lab test of composition or substances, costs shared as the annex agrees.
- Make delivery an order condition (next order) and qualify a second source.
- Suspend. The Batteries Regulation models it: consider "suspending or discontinuing engagement with a supplier" after failed mitigation (Art. 50(1)(b)(iii)).
Track each supplier's rung in one sheet:
supplier,wave,sent,due,received,verified,open_fields,rung,next_action,next_date,owner
The importer's hard stop. An importer must not place a non-conforming product on the market until it conforms (ESPR Art. 29(2)), so missing supplier data can stop an import. See also DPP for importers.
Confidentiality fallback. If a supplier will disclose only to authorities, hold the evidence for them; the JRC calls recycled-content evidence "a trade secret" that "would not be public". But substances of very high concern above 0.1% "shall not be exempted" (ESPR Art. 7(6)(b)).
Record each rung in the supplier's file: if an authority later asks why a field was empty, the dated trail of your digital product passport supplier data requests is your answer.
How do you keep supplier data current?
Digital product passport supplier data goes stale the day a supplier changes a recipe, a site or a certificate. Give every supplier field a trigger, a watcher and an action:
| Trigger | Who notices | Action |
|---|---|---|
| Change notice: material, formula or site | Supplier | Re-collect; reassess conformity (Art. 27(4)) |
| New sub-supplier | Supplier, via flow-down | Identifier routine; re-run wave 3 for that input |
| REACH Candidate List update | Compliance | Suppliers re-confirm substances |
| Yearly cycle | Data owner | Supplier re-signs the declaration |
Version your digital product passport supplier data in your own system: what changed, who, which evidence. Push every update to the live passport and its back-up (ESPR Art. 27(1)(c)).
Walkthrough: a hypothetical workwear brand in Tilburg
Take a hypothetical workwear brand in Tilburg, the Netherlands, with 140 SKUs. Assume the textile act, not yet adopted, is in force and requires identifiers, composition and recycled content. Tier 1: sewing plants in Porto and Bursa; tier 2: three fabric mills; tier 3: spinners. Here is how its digital product passport supplier data moves through the plan.
- Weeks 1–2: the field map lists 23 fields: 9 from the brand's own systems, 11 from tier 1, 3 from tiers 2–3.
- Week 3: the digital product passport supplier data request goes to Porto and Bursa.
- Week 5: Porto returns a legal-entity GLN and a location GLN, both in Verified by GS1. Bursa confirms in writing it has none. The brand logs this, then, as its Article 12 request, prepares with Bursa an application to the GS1 member organisation in Türkiye, licence in Bursa's name.
- Week 6: Bursa objects to the audit clause; the brand narrows it to document review and one announced visit a year, filing the exchange as its negotiation record (Data Act Art. 13(6)).
- Week 9: checks catch two errors. A jacket lists 65% polyester and 36% cotton (101%); the fabric specification says 64/36. A fleece claims 30% recycled polyester, but certificates cover purchases equal to 18%, so the claim drops to 18%.
- Weeks 11–20: one mill will not name its spinners. Rung 1: a filled sample row. Rung 2: a week-16 date for two of three. The third stays "pending: supplier", with no origin claim for that yarn.
Two counterfactuals. Had Bursa's head-office GLN been entered as the facility identifier, the digital product passport supplier data would point to an office, not the plant; the site check catches it. Had the fleece gone live at 30%, an authority's reasoned request would have needed the evidence within 15 days (ESPR Art. 27(10)), and the certificates would have covered only 18%.
The adopted-law contrast. A hypothetical Graz assembler of 10 kWh home-storage batteries (industrial batteries above 2 kWh) needs Annex XIII 1(b) and 2(a)–(b) data from its cell maker from . The cell maker uploads it under a written Article 77(4) authorisation limited to those fields; the assembler stays responsible.
Edge cases: when does collection work differently?
These cases change where digital product passport supplier data comes from, not the routine.
The supplier is a trader. A trading office is not the production site: have the trader name the plant that made the goods, or reveal the next tier.
Private label. You are the manufacturer (ESPR Art. 2(42)), so put the clause annex into your private-label agreement.
Authorised representative. Its mandate cannot include the Article 27(1) duties (Art. 28(1)). Contract supplier data yourself.
Battery cells and modules. Normally, imported cells that are merely components "are not themselves treated as the finished battery" (battery FAQ Q3.4), except do-it-yourself kits sold ready for end users. The cell maker then has no passport duty; your contract is the route to its data.
Zoom out: one supplier request, several laws
| Regime | Supplier data | Status |
|---|---|---|
| Battery due diligence, Art. 49(2) | Name, address, origin, quantities | Law from ; scope may change |
| EUDR, Art. 9(1)(e) | Name, postal address, email | Law from ; micro and small operators from |
| Conflict minerals, Reg. (EU) 2017/821 Art. 4(f)–(g) | Name, address; origin and quantities (minerals) or smelters and refiners (metals) | Law for Union importers of tin, tantalum, tungsten, gold above Annex I thresholds |
| REACH Art. 33 | Candidate List substances above 0.1% | Law for EU suppliers |
They overlap with digital product passport supplier data at the core: who the supplier is, where material comes from, how much. Build one annex with a module per regime, not one questionnaire per law. See our EUDR guide.
Watch these pending items; each would change your digital product passport supplier data request or clauses:
| Pending item | What it would change | Do now |
|---|---|---|
| ESPR product-group acts | Fields, level, access | Keep "expected" rows; collect identifiers |
| Article 12(4) act | Who issues identifiers | Log every confirmation and request |
| Battery access-rights act, Art. 77(9): overdue, Commission timeline (expected) | Who counts as a legitimate-interest person for Annex XIII point 2 | Keep the disclosure carve-out |
| Battery proposal COM(2025) 981 | Label substance list, also in the passport, redefined as substances of very high concern at or above 0.1% | Ask cell suppliers for Candidate List concentrations |
| Omnibus IV, COM(2025) 501 | Higher due diligence threshold; fewer suppliers owe disclosure | Keep the flow-down clause |
The practical conclusion: build one digital product passport supplier data request and one evidence file per supplier, and let each law draw on it. A second questionnaire for the next regulation is the expensive path.
What should you do in the next 60 days?
Seven steps start your digital product passport supplier data programme. None of them waits for your delegated act:
- Field map (weeks 1–2, compliance): every field, source tier, adopted or expected.
- Request sheet (week 3, procurement): send it, with the cover letter, to your top five suppliers.
- Identifier routine (weeks 3–6, compliance): ask, confirm, request, send, record.
- Contract annex (weeks 3–6, legal): draft the clauses; run the Data Act check.
- Verification rules (week 6, quality): checks plus the evidence-ID rule.
- Escalation ladder (week 7, management): rungs, deadlines and the tracker.
- Change calendar (week 8, data owner): triggers, certificate expiries, yearly re-signature.
Once your GTINs and batches link to supplier lots, make a test code for one GTIN: Passmith's free GS1 Digital Link QR generator needs no signup and runs in your browser. Passmith also has a free plan.
Further reading: What is a digital product passport? · DPP implementation in 8 steps · Battery passport · CSDDD due diligence · GS1 Digital Link
Frequently asked questions
Are suppliers legally required to provide digital product passport supplier data?
What format should suppliers deliver data in?
Who requests a facility identifier if the factory has none?
Can a supplier update our passport directly?
How do we protect a supplier's confidential data?
Who pays for lab tests when a supplier cannot document composition?
Should we collect supplier data before our product group's act is adopted?
Sources
- Regulation (EU) 2024/1781 (ESPR) — EUR-Lex — 2026-10-07
- Regulation (EU) 2023/1542 (Batteries Regulation) — EUR-Lex — 2026-10-07
- Regulation (EU) 2025/1561 amending Regulation (EU) 2023/1542 as regards battery due diligence dates — EUR-Lex — 2026-10-07
- Commission Implementing Regulation (EU) 2026/1778 on the digital product passport registry — EUR-Lex — 2026-10-07
- Regulation (EU) 2023/2854 (Data Act) — EUR-Lex — 2026-10-07
- Proposal COM(2025) 837 (Digital Omnibus) — EUR-Lex — 2026-10-07
- Regulation (EC) No 1907/2006 (REACH), Article 33 — EUR-Lex — 2026-10-07
- Court of Justice, Case C-106/14 (FCD and FMB), judgment on REACH Article 33 — EUR-Lex — 2026-10-07
- Regulation (EU) 2023/1115 (EUDR) — EUR-Lex — 2026-10-07
- Regulation (EU) 2025/2650 amending the EUDR — EUR-Lex — 2026-10-07
- Regulation (EU) 2017/821 (Conflict Minerals Regulation) — EUR-Lex — 2026-10-07
- European Parliament Legislative Observatory — procedure 2025/0397(COD), battery simplification proposal COM(2025) 981 — 2026-10-07
- European Parliament Legislative Observatory — procedure 2025/0130(COD), Omnibus IV proposal COM(2025) 501 — 2026-10-07
- European Commission — Frequently Asked Questions on the Digital Product Passport — 2026-10-07
- European Commission — EU Digital Product Passport FAQ for Batteries — 2026-10-07
- European Commission (DG GROW) — Guidance Document: Digital Batteries Passport – data points by category, Version 2.0 (15 August 2026) — 2026-10-07
- European Commission — Digital Product Passport (indicative timeline) — 2026-10-07
- JRC — Methodology for defining data requirements for the Digital Product Passport under the ESPR framework (JRC145830, 2026) — 2026-10-07
- GS1 — DPP provisional application standard, GSCN 26-226, release 2 (Jun 2026, not ratified) — 2026-10-07
- GS1 General Specifications Standard, Release 26.0 (Jan 2026), section 4.5.1 (GLN allocation) — 2026-10-07
- GS1 — Global Location Number (GLN) — 2026-10-07
- GS1 — Verified by GS1 — 2026-10-07


