QR codes, data carriers and unique identifiers for the DPP

ESPR never says 'QR code'. The European standards published in May 2026 are where the real requirements live — and they permit more than most people assume.

The mental image of a Digital Product Passport is a QR code on a label. That is what it will look like in practice, but it is not what the regulation says — and the gap matters when you are choosing an identifier scheme you will be stuck with.

What ESPR actually requires

Article 10 requires that the passport be connected to a persistent unique product identifier, via a data carrier physically present on the product, its packaging or accompanying documentation. The carrier and the identifier must comply with the standards named in Annex III, or equivalent European or international standards, until harmonised standards are cited in the Official Journal.

Annex III names the ISO/IEC 15459 family — parts 1 through 6. These cover unique identification of transport units, registration procedures, common rules, individual items, item groupings and product groupings. Part 6 is the GTIN hook.

ESPR names neither QR codes nor GS1 Digital Link. It defines a shape, and left the specifics to standardisation.

The standards that filled the gap

CEN/CLC/JTC 24, working to Commission standardisation request M/604, published the first six European standards for the DPP on 27 May 2026:

StandardCovers
EN 18216Data exchange protocols — RESTful APIs over HTTPS/TLS, authenticated and tamper-resistant.
EN 18219Unique identifiers. Five permitted schemes; three identifier types.
EN 18220Data carriers. QR Code, Data Matrix and RFID, with print quality, error correction, durability and placement.
EN 18221Data storage, archiving and persistence.
EN 18222APIs for passport lifecycle management and searchability.
EN 18223System interoperability — shared data model, metadata container, semantic linking.

Two more are expected around September 2026: access rights management and information system security, and data authentication and integrity.

EN 18219 — the five identifier schemes

This is the standard that decides your architecture. It permits:

  • GS1 Digital Link URIs — the most widely deployed option, and the natural choice if you already use GTINs.
  • IEC 61406 identification links — self-issued, useful where you control the whole chain.
  • W3C Decentralised Identifiers (DIDs).
  • RFID and 2D identifiers.
  • DOIs.

It also defines three identifier types — product, economic operator and facility — mirroring the Annex III requirement for all three.

EN 18220 — the carrier requirement that matters

QR Code, Data Matrix and RFID (HF, NFC and UHF) are all permitted, with specifications for print quality, error correction level, durability and placement. The provision worth committing to memory: at least one carrier must be free to use and readable with an ordinary smartphone.

So you may use NFC or UHF RFID, but not only those. A consumer with a normal phone and no special app has to be able to reach the passport.

Commission Implementing Decision (EU) 2026/1736 cites the six published standards in the Official Journal. Note that the reported publication and entry-into-force dates for that decision are internally inconsistent in secondary reporting — verify against the OJ if the exact date matters to you.

On GS1 Digital Link and "Sunrise 2027"

GS1 Digital Link is not named in ESPR, but it is explicitly one of the five permitted schemes in EN 18219, and it is the most practical option for most retailers: a GTIN plus a serial number encoded as a URL in a QR code, resolving to a web resource.

Sunrise 2027 is not an EU deadline. GS1's migration to 2D barcodes at point of sale is an industry initiative on its own track. It is frequently presented alongside DPP dates in a way that implies legal force. It has none. Plan for it if it suits your retail channels; do not treat it as regulatory.

Decisions that are expensive to reverse

Almost everything about a DPP can be changed later. These cannot, cheaply, once product is printed and in the field.

Identifier scheme

Changing scheme after products are in circulation means running two resolution systems indefinitely. Decide once, and prefer the scheme your industry already uses.

URL structure

The URL is encoded into the carrier and cannot be changed for products already printed. Keep it short — every character costs module density and therefore physical print size. Do not put a category, a year, or a language in the path, because all three change. Key it on the passport identifier, not on an internal product ID that will change during your next migration.

Granularity

Model, batch or item level is set by the delegated act, but if you have a choice, serialising is much easier to do from the start than to retrofit. Item-level identifiers also let you satisfy per-item data requirements later without re-printing.

Persistence

The passport must remain reachable for at least the expected product lifetime, and must survive the responsible operator's insolvency or withdrawal from the EU. Practically: the URL must outlive your CMS, your platform migration, and possibly your company. Design it as an archival identifier that happens to resolve over HTTP today.

Practical print testing

A QR code that scans on a monitor is not a QR code that scans on a product. Test at final print size, on the real substrate, after whatever finishing the packaging goes through — matte lamination, varnish and curved surfaces all degrade readability. Test in poor light, at an angle, with a cracked phone screen. Then pick your error correction level.

Questions

Does the passport have to use a QR code?
No. EN 18220 permits QR Code, Data Matrix and RFID in HF, NFC and UHF forms. But at least one carrier must be free to use and readable with an ordinary smartphone, which in practice means a printed 2D code unless you have an unusual product. NFC can supplement it; it cannot replace it.
Should we use GS1 Digital Link?
For most retailers, yes. It is one of the five schemes EN 18219 permits, it is widely deployed, and it builds on GTINs you probably already have. The alternatives are better suited to specific situations — DIDs where decentralised verification matters, IEC 61406 where you control the whole chain.
Can the QR code point at our normal product page?
It is better to point at a dedicated passport URL and link between the two. The product page changes with merchandising, gets restructured, and disappears when the product is discontinued — none of which is acceptable for a passport that must stay reachable for the product's lifetime. Keep the passport URL boring and permanent, and let the product page be a marketing surface.
What happens if the QR code is damaged?
EN 18220 covers error correction and durability, which is why error correction level is a real decision rather than a default. Beyond that, the passport should be reachable by entering the identifier directly, so a damaged carrier is a degraded experience rather than a dead end.

Sources

Turn this into a plan for your catalogue

The readiness checklist walks your product groups one at a time and tells you what data to start collecting from suppliers now.

Open the readiness checklist