The Ecodesign for Sustainable Products Regulation (ESPR) is the framework that makes the Digital Product Passport a legal requirement across the European Union. It replaces the older Ecodesign Directive, and where that directive mostly governed the energy efficiency of appliances, ESPR reaches into almost every physical product sold in the EU — how it is made, what it contains, how long it lasts, and what happens to it at the end of its life.
What the regulation actually asks for
ESPR itself does not list the data fields your product must disclose. It creates the machinery: the Commission adopts a delegated act per product group, and that act defines the ecodesign requirements and the passport data for that group. This is why there is no single “DPP checklist” that applies to everyone — a textile passport and a battery passport share a structure but not a content list.
What is common across groups is the shape of the obligation. A product in scope must carry a data carrier — in practice a QR code or similar 2D symbol — that resolves to a passport. The passport must be accessible to different actors with different permissions: consumers see care and composition information, market surveillance authorities and customs see compliance records, recyclers see material and disassembly data. The identifiers behind it must be registered in the EU’s central DPP registry before the product is placed on the market.
Who is in scope
Three points matter more than any other:
The rules apply to products placed on the EU market, not to EU companies. A manufacturer in Türkiye, Vietnam or Bangladesh producing for a European brand is inside the system, even though the legal duty formally sits with the importer or authorised representative. In practice that duty flows upstream as a contractual data request, which is why suppliers are being asked for DPP readiness well before their category’s deadline.
Small companies are not exempt. ESPR contains support measures for SMEs, but no blanket exemption. Where thresholds appear, they appear in specific delegated acts, not in the framework.
Distributors and retailers carry verification duties. If you place a product on the EU market that lacks a valid passport, the responsibility does not simply stay with the party that made it.
The timeline, honestly stated
The first hard deadline does not come from ESPR at all. It comes from the Battery Regulation: from 18 February 2027, industrial and EV batteries above 2 kWh require a battery passport. That is the earliest date on which a European authority can ask a company for a working product passport and expect one.
Under the ESPR working plan, iron and steel are expected to be among the first groups with delegated acts, followed by textiles, aluminium and tyres, with furniture and further categories later in the decade. Each act carries its own transition period after adoption, so the enforcement date is always later than the adoption date — a nuance frequently lost in vendor marketing.
The practical consequence: your regulatory deadline may be 2028, but your commercial deadline is whenever your largest European customer decides that DPP readiness is a condition of supply. Those conversations are happening now.
The standards layer most companies miss
In 2026, CEN and CENELEC published a family of European standards that define how a DPP system must actually work. They are not optional colour: conformity with harmonised standards is the practical route to demonstrating compliance.
Six of them matter to anyone selecting software. EN 18216 covers data exchange protocols; EN 18219 defines the unique identifier types — for the product, the operator and the facility; EN 18220 covers data carriers and their durability; EN 18222 defines APIs and lifecycle management; EN 18223 covers system interoperability. And EN 18221 — the one that quietly reshapes vendor selection — requires the persistence of passport data independently of any single economic operator.
Read that last one carefully. A passport must remain accessible even if the company hosting it disappears. If your provider cannot explain, concretely, what happens to your passports if they go out of business, they have not read the standard.
What to do in your first 90 days
Start by scoping: list your product families, map each to a likely product group, and note the expected delegated act. This tells you which deadline is yours and prevents you from over-engineering for categories that will not be regulated for years.
Then audit your data. The single most common surprise is not the regulation — it is discovering that fibre composition lives in a spreadsheet, supplier certificates live in a shared mailbox, and nobody owns the connection between them. Passport software does not fix a broken data supply chain; it exposes it.
Third, identify your identifier strategy. If you already use GTINs, you are most of the way there, but you will also need operator and facility identifiers, and you will need a resolver that turns each identifier into the right destination for the right audience.
Finally, run one product end to end. A single SKU taken from raw data to published passport will teach you more about your real gaps than three months of internal workshops.
Where the DPP meets Sunrise 2027
There is a second, non-regulatory deadline arriving on a similar schedule. GS1’s Sunrise 2027 is the global retail transition from 1D barcodes to 2D barcodes carrying GS1 Digital Link, so that a single code can serve both the checkout and the web.
These are separate initiatives with separate authorities, but they converge on the same physical square on your packaging. Companies that treat them as one project print one code. Companies that treat them separately often end up printing two — and then explaining to a retailer why their packaging carries a marketing QR that a till cannot read.