A Digital Product Passport (DPP) is a digital record holding a product's identity, composition, environmental characteristics and lifecycle information, reached through a data carrier on the product — usually a QR code. It is becoming mandatory in stages: batteries under their own regulation from , then ESPR product groups such as textiles, whose delegated act is indicated for (expected). This guide gathers what a manufacturer selling into the EU needs to know — the architecture, the data fields, the timeline, the legal chain and the preparation steps — in one place.
What is a Digital Product Passport?
At its shortest, the DPP is the machine-readable answer to "what is this product made of, where and how was it made, how is it repaired and how is it recycled". A consumer, a customs officer or a recycling plant scanning the QR code on the product each reach the information their own role allows.
Information too deep for a physical label — supply chain, test reports, repair manuals, evidence for recycled content — lives in the digital record and can be updated across the product's life. A paper label ages with the product; the passport lives with it.
It helps to separate the two legs of the concept from the start: the carrier (the QR code or chip on the product — the door) and the record (the data infrastructure behind it — the building). Most of the confusion in the market comes from mixing the two; the architecture section below takes them apart.
The three forces behind the DPP
The DPP is not a Brussels whim; it is three separate pressures meeting in the same solution.
1. Regulatory pressure. The EU's circular economy goals require the durability and recyclability of products to be auditable. Auditable means structured data — the ecodesign criteria ESPR introduces would stay on paper without it. The DPP is the data backbone of those criteria.
2. The retail transition. Global retail is moving from the forty-year-old linear barcode to 2D codes: the GS1 Sunrise 2027 target is for checkouts to read 2D codes by the end of 2027. If a QR code is going to be on the product anyway, having that same code also open the passport is the single cheapest solution for manufacturer and retailer alike.
3. Buyer pressure. EU brands are converting their own legal exposure into supply contracts and pushing it upstream. In 2026 the "DPP readiness" question in supplier questionnaires is no longer the exception — the commercial reality is already in place before the delegated acts are final.
How it works: the four components of the architecture
1. Unique identifier. Every product is identified uniquely — in most scenarios through a GTIN. The EN 18219 standard defines three identifier types at once: product, economic operator and facility. So "which company, which plant" is as much part of the passport identity as "which product". For companies producing in more than one facility, that distinction belongs in the data model now.
2. Data carrier. The physical access point on the product: QR code, Data Matrix, RFID or NFC; EN 18220 is the harmonised standard for data carriers. Which carrier a product uses, its layout and its placement are set by each product group's delegated act (ESPR Articles 9(2) and 10(1)) — that is where the "wash-resistant carrier" debate in textiles will be settled. The format leading in retail is the GS1 Digital Link QR, which embeds the GTIN in web-URI syntax; we covered why an ordinary QR code is not enough separately.
3. Passport record and hosting. The data itself lives in a system: structured fields, documents, version history. Two standards are critical here: EN 18216 defines machine-readable protocols for data exchange (an HTML page written for human eyes alone does not qualify), and EN 18221 governs persistence — under the ESPR, passport data must stay available even after the economic operator that created it becomes insolvent or ceases activity (Article 11(e)), backed by a back-up copy held by a DPP service provider (Article 10(4)). The practical consequence for a manufacturer: when choosing a provider, data export and an archiving commitment are not negotiating points but preconditions.
4. The central registry. The EU's central registry, opened on (though no passport can be registered successfully yet), is the enforcement anchor of the architecture: the unique identifier is registered there before the product is placed on the market, and at import that registration can be verified by customs once the registry is connected to EU customs systems, by at the latest. This is the link that turns the passport from a "website" into an official document; we walked through the customs flow step by step.
What data will the passport carry?
Exact field lists arrive with the category delegated acts; but the parameters of the ESPR framework and the signal from the first implementations (batteries) already make the table clear:
| Data category | Content | Textile example |
|---|---|---|
| Identity | GTIN, operator and facility identifiers, model | GTIN per SKU; production facility |
| Composition | Material/fibre percentages, substances of concern | 60% cotton, 40% polyester — with the official fibre names from (EU) 1007/2011 |
| Care and use | Care instructions, user manuals | ISO 3758 symbol codes |
| Conformity | Test reports, declarations of conformity, certificates | Batch-matched, dated documents |
| Circularity | Durability, repairability, recycled content, disassembly information | Recycled fibre share plus its evidence |
| Footprint | Carbon/environmental footprint (by category) | Written into battery law (Art. 7), but applies only after the Commission's methodology and format acts enter into force — they have not yet, so it is not part of the battery passport at its start on ; for textiles it depends on the delegated act |
| Traceability | Links in the supply chain | Trending towards fabric and yarn origin |
Two practical warnings. First: most of this data is not new — the fibre composition declaration is already mandatory under 1007/2011, care symbols are already on the label. What is new is that this information, currently living in scattered PDFs, becomes structured and machine-readable. Second: the "claim equals evidence" principle. In the passport era every statement like "recycled", "organic" or "water-saving" has to be tied to a document; an unevidenced claim turns into a greenwashing risk.
Who sees what? Role-based access
The passport is not a single public page. Who may see which data is set product group by product group in each delegated act (ESPR Art. 9(2)(f), 10(1)(g), 11(b)). EN 18239, the access-rights standard (published September 2026, not cited in the Official Journal), does not itself grant rights. A typical split looks like this — illustrative, not taken from any adopted act:
| Role | Layer they see |
|---|---|
| Consumer | Identity, composition, care, repair and a circularity summary |
| Retailer / buyer | Plus conformity documents, supplier data (per contract) |
| Customs / market surveillance | Plus registration verification, official declarations |
| Recycler | Plus disassembly information, material detail |
The question manufacturers ask most often — "will my trade secrets become visible to a competitor?" — finds its answer here: no, not by design. Sensitive data such as supplier lists and cost structures does not sit in the public layer; who accesses what is set by the product group's delegated act; anything beyond it is a matter of contract.
The timeline: which category, when?
| Category | Status | Basis |
|---|---|---|
| Batteries | — fixed | (EU) 2023/1542, Article 77 |
| Iron and steel | First ESPR delegated act indicated for (expected) | ESPR working plan |
| Construction products | Delegated act indicated for (expected); duty 18 months after it enters into force, per product family | CPR 2024 |
| Textiles | Delegated act indicated for (expected), plus a transition period | ESPR working plan |
| Furniture | Delegated act indicated for (expected) | ESPR working plan |
| Mattresses | Delegated act indicated for (expected) | ESPR working plan |
There are three rules for reading this timeline. One: separate "expected" from "fixed" — the battery date is written into the regulation, the textile one still hangs on a delegated act. Two: the date of the delegated act is not the date of application; every act grants an additional transition period. Three: the transition period will not save you — if data collection, aligning the supplier chain and building systems do not start before the delegated act, the transition period is spent firefighting. The April 2025 working plan prioritising textiles, and batteries becoming the live rehearsal in February 2027, are a clear "start in 2026" signal for textile companies.
The legal chain: who carries the duty, who does the work?
The passport duty sits with the manufacturer — whoever markets the product under its own name or trademark, wherever it is based (ESPR Art. 2(42), 27(1)(c)). For imported products, the importer must check that a passport is available and, as the operator placing the product on the market, registers it (Art. 29(2)(c), 13(4)). An authorised representative cannot take this duty over (Art. 28(1)). A contract manufacturer in Türkiye, Bangladesh or Vietnam producing for an EU brand has no passport duty of its own. The passport may still carry its operator and facility identifiers (Annex III(h)–(i)).
The practical reality is the opposite: the brand does not know the fibre composition, the production facility or the test reports — the factory does. Liability travels down by contract, data travels up by contract. In the supply conversations of 2026 this chain takes three concrete forms: data-provision clauses entering purchase agreements, a "DPP readiness" line added to supplier audits, and questionnaire response speed turning into a supplier selection criterion. Our guide written from the exporter's side takes the whole dynamic in detail.
The gain for the manufacturer who prepares early is symmetrical: the position of "passport-ready supplier" is the cheapest route to non-price differentiation in 2026-27.
The passport journey of one t-shirt
Let us follow the four components in a single product — a forward-looking, representative scenario. A 100% cotton t-shirt made in Denizli, to be sold in the Netherlands while the textile delegated act is in force.
At the factory: the t-shirt's GTIN is assigned; composition (as "cotton 100%", the official name in 1007/2011), care codes (ISO 3758) and the production facility identifier enter the structured record; the azo dye test report is matched to the batch. The passport is created: the brand in the EU (the economic operator) compiles the data into the passport and registers the unique identifier in the central registry — before the container leaves port. At the border: once the registry is connected to EU customs systems, the registration identifier in the customs declaration is verified automatically; if the match is clean no physical inspection is needed. In the shop: the QR code on the woven label identifies the product at the checkout (the counterpart of the Sunrise 2027 target) and opens the care and composition page on the customer's phone. Five years later: the t-shirt goes into a collection bin; the recycling plant scans the same code and sees the fibre composition in its own role layer — the sorting decision takes seconds.
One code, five different readers, five different answers — that is precisely what makes the passport "a living record, not a static label". The counterfactual is just as simple: had one digit of the GTIN differed from the label, the automated customs lookup would not have caught it, since it compares only the registration identifier and the commodity code — but a risk-based check or a market-surveillance inspection could, and the journey would have stopped there.
Four concepts that get confused
DPP is not an e-label. The passport is not a static product page; it involves role-based access, updatable data, a link to the registry and an archiving obligation.
DPP is not a QR code. The code is the door, the passport is the building. Having a code does not mean having a passport — structured, registered data has to sit behind it.
DPP is not a sustainability report. A report is voluntary and free-form; a passport is mandatory, standardised and auditable. One is marketing, the other is a condition of market access.
DPP is not a one-off project. The passport lives as long as the product does: new batches, updated documents, changing suppliers. This is a process, not an installation — which is where the weight of the software choice comes from.
A little-known fact: DPP service providers will be regulated too
The software companies offering passport infrastructure fall inside the regulation as well: requirements for "DPP service providers" are coming in a separate delegated act (ESPR Article 11) — the Commission's calendar points at the second or third quarter of (expected). The expected headings are data accessibility, portability and certification or accreditation obligations.
For a manufacturer this means that choosing a provider is not an ordinary SaaS subscription — you are choosing an infrastructure operator who is about to be regulated. Four questions to ask before contracting: (1) In what format and within what time is my data exported? (2) In which jurisdiction is it hosted? (3) How is the persistence requirement of EN 18221 met — what is the archive or continuity plan? (4) Is there a commitment to prepare for the coming certification requirements? A provider who cannot answer these clearly becomes your compliance risk in 2027.
Five common mistakes
1. The "we have a QR code, we are ready" fallacy. The code is the door; without structured, registered data behind it there is no passport. The difference between a marketing QR and a compliant data carrier surfaces in the audit.
2. Waiting for the delegated act before collecting data. Even before the field lists are final, 80% of the work is knowable: identifiers, composition, documents. Collecting data takes months; the transition period of a delegated act was not calculated with that work in mind.
3. Duplicate GTINs and identifier sprawl. Using the same GTIN on two variants is the most expensive error to fix later — printed labels, registered identifiers and customer systems are affected in a chain.
4. The document exists, the match does not. Test reports sitting in a folder with no clarity about which batch they belong to produce the same outcome in an audit as no document at all. Matching document to product to batch matters as much as the archive itself.
5. Provider lock-in. If QR codes are printed on the provider's domain, the printed codes die when the contract ends. Having codes point at a domain you control (for example id.yourbrand.com) is the cheapest insurance there is against the provider.
A five-step start for manufacturers outside the EU
- Category and timeline analysis: which categories does your range fall into, and what is the delegated-act status of each? For anyone exporting products containing batteries, the clock is already running.
- GTIN hygiene: a unique GTIN for every SKU. A duplicate GTIN across colour and size variants is the most expensive mistake in the whole chain.
- Data inventory: where do composition, care and documents live today — how many systems, how many spreadsheets, how many mailboxes? Plan the move to a single structured source.
- The supplier chain conversation: the data you cannot provide yourself (yarn origin, evidence for recycled content) will come from your supplier. Ask about their readiness today.
- A pilot product family: run one product family end to end — data collection, QR code, passport page. If you are in textiles, our eight-point checklist carries the audit questions for these steps.
Mini glossary
GTIN — Global Trade Item Number; the product's globally unique number (the identity inside the barcode). GS1 Digital Link — the standard that embeds the GTIN in a web-URI syntax inside the QR code, letting one code work both at the checkout and on the web. Delegated act — the secondary EU legislation that sets the concrete, category-level requirements of the framework regulation (ESPR). Economic operator — ESPR's umbrella term for the manufacturer, authorised representative, importer, distributor, dealer and fulfilment service provider (Art. 2(46)); each has its own obligations. Authorised representative — an EU-established party a manufacturer mandates in writing for specified tasks (Art. 2(43)); the passport duty cannot be part of that mandate (Art. 28(1)). Registry — the central EU system, opened in July 2026, where unique identifiers are registered before market placement; no passport can be registered successfully in it yet.
Further reading: What is the ESPR? · Textile exporter checklist · Battery passport guide · GS1 Sunrise 2027
Frequently asked questions
When does the Digital Product Passport become mandatory?
Does the DPP cover manufacturers outside the EU?
What data will the DPP contain?
Who creates the DPP — the manufacturer or the importer?
Which QR code will be used for the DPP?
Will all passport data be public?
What happens to my passports if my software provider shuts down?
Sources
- Regulation (EU) 2024/1781 (ESPR) — EUR-Lex — 2026-08-15
- Regulation (EU) 2023/1542 (Battery Regulation) — EUR-Lex — 2026-08-15
- European Commission — Digital Product Passport — 2026-08-08
- Commission Implementing Decision (EU) 2026/1736 — harmonised standards for the digital product passport — EUR-Lex — 2026-10-07
- — Corrected: registry and customs status, data carrier rules (set in each delegated act), passport availability (ESPR Articles 10(4) and 11(e)), the status of EN 18239, the type of act for DPP service providers, the construction products timeline and the ESPR timeline (delegated-act years, not application years); the standards source is now EUR-Lex.


