QR codes, data carriers and unique identifiers for the DPP
ESPR never says 'QR code'. The European standards published in May 2026 are where the real requirements live — and they permit more than most people assume.
The mental image of a Digital Product Passport is a QR code on a label. That is what it will look like in practice, but it is not what the regulation says — and the gap matters when you are choosing an identifier scheme you will be stuck with.
What ESPR actually requires
Article 10 requires that the passport be connected to a persistent unique product identifier, via a data carrier physically present on the product, its packaging or accompanying documentation. The carrier and the identifier must comply with the standards named in Annex III, or equivalent European or international standards, until harmonised standards are cited in the Official Journal.
Annex III names the ISO/IEC 15459 family — parts 1 through 6. These cover unique identification of transport units, registration procedures, common rules, individual items, item groupings and product groupings. Part 6 is the GTIN hook.
ESPR names neither QR codes nor GS1 Digital Link. It defines a shape, and left the specifics to standardisation.
The standards that filled the gap
CEN/CLC/JTC 24, working to Commission standardisation request M/604, published the first six European standards for the DPP on 27 May 2026:
| Standard | Covers |
|---|---|
| EN 18216 | Data exchange protocols — RESTful APIs over HTTPS/TLS, authenticated and tamper-resistant. |
| EN 18219 | Unique identifiers. Five permitted schemes; three identifier types. |
| EN 18220 | Data carriers. QR Code, Data Matrix and RFID, with print quality, error correction, durability and placement. |
| EN 18221 | Data storage, archiving and persistence. |
| EN 18222 | APIs for passport lifecycle management and searchability. |
| EN 18223 | System interoperability — shared data model, metadata container, semantic linking. |
Two more are expected around September 2026: access rights management and information system security, and data authentication and integrity.
EN 18219 — the five identifier schemes
This is the standard that decides your architecture. It permits:
- GS1 Digital Link URIs — the most widely deployed option, and the natural choice if you already use GTINs.
- IEC 61406 identification links — self-issued, useful where you control the whole chain.
- W3C Decentralised Identifiers (DIDs).
- RFID and 2D identifiers.
- DOIs.
It also defines three identifier types — product, economic operator and facility — mirroring the Annex III requirement for all three.
EN 18220 — the carrier requirement that matters
QR Code, Data Matrix and RFID (HF, NFC and UHF) are all permitted, with specifications for print quality, error correction level, durability and placement. The provision worth committing to memory: at least one carrier must be free to use and readable with an ordinary smartphone.
So you may use NFC or UHF RFID, but not only those. A consumer with a normal phone and no special app has to be able to reach the passport.
Commission Implementing Decision (EU) 2026/1736 cites the six published standards in the Official Journal. Note that the reported publication and entry-into-force dates for that decision are internally inconsistent in secondary reporting — verify against the OJ if the exact date matters to you.
On GS1 Digital Link and "Sunrise 2027"
GS1 Digital Link is not named in ESPR, but it is explicitly one of the five permitted schemes in EN 18219, and it is the most practical option for most retailers: a GTIN plus a serial number encoded as a URL in a QR code, resolving to a web resource.
Sunrise 2027 is not an EU deadline. GS1's migration to 2D barcodes at point of sale is an industry initiative on its own track. It is frequently presented alongside DPP dates in a way that implies legal force. It has none. Plan for it if it suits your retail channels; do not treat it as regulatory.
Decisions that are expensive to reverse
Almost everything about a DPP can be changed later. These cannot, cheaply, once product is printed and in the field.
Identifier scheme
Changing scheme after products are in circulation means running two resolution systems indefinitely. Decide once, and prefer the scheme your industry already uses.
URL structure
The URL is encoded into the carrier and cannot be changed for products already printed. Keep it short — every character costs module density and therefore physical print size. Do not put a category, a year, or a language in the path, because all three change. Key it on the passport identifier, not on an internal product ID that will change during your next migration.
Granularity
Model, batch or item level is set by the delegated act, but if you have a choice, serialising is much easier to do from the start than to retrofit. Item-level identifiers also let you satisfy per-item data requirements later without re-printing.
Persistence
The passport must remain reachable for at least the expected product lifetime, and must survive the responsible operator's insolvency or withdrawal from the EU. Practically: the URL must outlive your CMS, your platform migration, and possibly your company. Design it as an archival identifier that happens to resolve over HTTP today.
Practical print testing
A QR code that scans on a monitor is not a QR code that scans on a product. Test at final print size, on the real substrate, after whatever finishing the packaging goes through — matte lamination, varnish and curved surfaces all degrade readability. Test in poor light, at an angle, with a cracked phone screen. Then pick your error correction level.
Questions
Does the passport have to use a QR code?
Should we use GS1 Digital Link?
Can the QR code point at our normal product page?
What happens if the QR code is damaged?
Sources
Keep reading
Required data fields
The fixed framework elements you can design against today, and the product-specific fields that do not exist yet.
DPP on product pages
The distance-selling rule makes the passport a storefront problem. Where to put it, and how to render it well.
The EU DPP Registry
Live since 20 July 2026. What it stores, what it doesn't, and why it is not a registration deadline.
Turn this into a plan for your catalogue
The readiness checklist walks your product groups one at a time and tells you what data to start collecting from suppliers now.