What is a Digital Product Passport?

A structured data record attached to a physical product, reachable from a code on it. Simple in concept; the detail is where the work lives.

A Digital Product Passport is a structured, machine-readable set of data about a specific product, hosted online and reachable from a data carrier — in practice almost always a QR code — attached to the product, its packaging or its documentation.

That is the whole concept. The complexity is in four questions: what data, reachable by whom, for how long, and who has to produce it.

Why the EU is doing this

The stated purpose is circularity. You cannot repair, refurbish or recycle a product efficiently if nobody knows what is in it. A recycler receiving a mixed stream has no way to identify which items contain a substance of concern; a repairer cannot source a part they cannot identify; a consumer cannot compare durability that nobody publishes.

The passport is an attempt to make that information travel with the product instead of dying in the manufacturer's files. A useful side effect, from the regulator's point of view, is that once sustainability data is published in a structured and checkable form, environmental claims become falsifiable in a way marketing copy never was.

What a passport contains

Two layers, and conflating them causes most of the confusion in this area.

Layer one — the framework data elements

ESPR Annex III sets a closed list that delegated acts draw from. It includes the unique product identifier; unique operator identifiers for the manufacturer, other operators and the EU-established responsible operator; unique facility identifiers; the importer's details and EORI number; commodity codes such as TARIC; compliance documentation; user manuals and safety information; and a reference to the DPP service provider hosting the back-up copy.

This layer is fixed by the framework and is the same shape whatever the product. It is safe to design against today.

Layer two — the sustainability content

This arrives through information requirements over the Annex I parameters: durability and reliability, ease of repair and maintenance, upgradability, design for recycling, use of substances of concern, resource use, recycled content, renewable content, weight and packaging ratio, incorporation of used components, and environmental footprint.

Which of these apply, at what granularity, and against what test methods, is decided per product group by a delegated act. This layer does not exist for any product group yet.

The single most important fact about the DPP today. No product-specific ESPR delegated act has been adopted for any product group. Until one exists for your products, nobody can tell you what fields your passport must carry. Vendors selling "compliant DPP" software today are selling an anticipation — which has genuine value for data collection, but is not compliance and should not be priced as such.

Who sees what

A passport is not one document shown to everyone. Article 11 requires free access for customers, manufacturers, importers, distributors, dealers, repairers, refurbishers, remanufacturers, recyclers, market surveillance authorities, customs, civil society organisations and trade unions — each according to their access rights.

The Batteries Regulation, being further ahead, shows how this works concretely. Annex XIII defines four tiers: public model-level information; a tier for those with a legitimate interest covering detailed composition, spare parts and dismantling instructions; a tier for notified bodies and authorities containing test reports; and a fourth tier of per-individual-battery data including state of health, cycle counts and recorded incidents.

That fourth tier is worth noticing, because it is not a catalogue field. It is telemetry, and it implies infrastructure most sellers do not have.

How it is reached

A persistent unique product identifier, encoded in a data carrier physically present on the product, its packaging or accompanying documentation. ESPR itself names neither QR codes nor any particular identifier scheme — it points to the ISO/IEC 15459 family of standards.

The European standards published in May 2026 fill that gap: EN 18219 permits five identifier schemes including GS1 Digital Link URIs and W3C decentralised identifiers, and EN 18220 covers QR codes, Data Matrix and RFID, requiring that at least one carrier be free to use and readable with an ordinary smartphone. See QR codes and data carriers.

For how long

Each delegated act sets the period, and it must be at least the expected lifetime of the product. Article 11 adds a requirement that is easy to skip past and hard to implement: the passport must survive the responsible operator's insolvency, liquidation or cessation of activity in the EU.

That is why Article 10(4) requires a back-up copy held by a DPP service provider. The delegated act establishing requirements and a certification scheme for those providers has not been adopted and is reportedly scheduled for 2027 — so the obligation currently exists without the regime that is supposed to support it.

Four things a DPP is not

  • Not a certification. Nobody awards you a passport. It is a declaration you make and are accountable for, closer to a datasheet than to a certificate.
  • Not a central EU database. The registry that went live on 20 July 2026 stores identifiers, not passport content. The data stays with you or your service provider. See the DPP registry.
  • Not a marketing asset. It can be used well in marketing, but its content is fixed by regulation, not chosen for its flattering qualities. If your recycled content is 4%, the passport says 4%.
  • Not optional once it applies. Article 9 is drafted as a market access condition: covered products can only be placed on the market if a passport is available in accordance with the applicable delegated act.

Where to go next

If you want to know whether this applies to you and when, start with your product group. If you want to know whether the obligation is yours or your supplier's, read who is responsible. If you already know both and want to start work, the readiness checklist is ordered by lead time.

Questions

Is the Digital Product Passport law yet?
The framework is. ESPR entered into force on 18 July 2024 and is binding law. But the framework alone does not require a passport for any specific product — that comes from product-specific delegated acts, and none has been adopted yet. The exception is batteries, which get their passport from separate legislation with a firm date of 18 February 2027.
Does the DPP apply outside the EU?
It applies to products placed on the EU market, whoever makes them and wherever they are made. A manufacturer outside the EU selling into the EU is fully within scope. Conversely, an EU company selling only to non-EU markets is not — the obligation follows the market, not the company.
Who hosts the passport data?
The responsible economic operator, or a DPP service provider acting for them. There is no EU-hosted store of passport content. ESPR also requires a back-up copy with a service provider, so the record survives the operator's insolvency or withdrawal from the EU.
Can one passport cover a whole product model?
That depends on the delegated act, which specifies whether the passport operates at model, batch or item level. Model level is simplest and will be common. Batteries show the other extreme: parts of the battery passport are explicitly per individual battery, including usage data and state of health.

Sources

Turn this into a plan for your catalogue

The readiness checklist walks your product groups one at a time and tells you what data to start collecting from suppliers now.

Open the readiness checklist