Foundations

The regulation & what a passport must contain

The Digital Product Passport is created by the EU's Ecodesign for Sustainable Products Regulation (ESPR). Here is how the law works, what data is required, how it is carried and accessed, and the standards that make it interoperable.

The legal basis

What the ESPR is

The Ecodesign for Sustainable Products Regulation (ESPR) - Regulation (EU) 2024/1781 - entered into force on 18 July 2024. It replaces the earlier Ecodesign Directive and dramatically widens its scope: instead of only energy-related products, it can cover almost all physical goods placed on the EU market.

ESPR is a cornerstone of the EU Green Deal and Circular Economy Action Plan. It sets requirements for durability, reparability, recycled content, energy and resource efficiency, the presence of substances of concern - and it establishes the Digital Product Passport as the digital backbone that makes those requirements enforceable at scale.

Framework go-live: 19 July 2026. ESPR reaches full application and the EU Central DPP Registry switches on. This is the framework activation - actual product obligations arrive category by category through delegated acts.

How delegated acts define your obligations

ESPR is a framework. The specific, binding rules for each product group are set through delegated acts - legally binding instruments that translate the regulation into concrete obligations. Until a delegated act for your product enters into force, its DPP requirements remain indicative.

Each delegated act typically defines:

  • Required data fields - e.g. material composition, origin, carbon footprint, durability, recycled content.
  • Data access rights - which stakeholders (regulators, consumers, repairers, recyclers) may see which data.
  • Verification requirements - validation methods, third-party checks and audit expectations.
  • Timelines - when the passport becomes mandatory for that category.

Requirements differ by product because risk profiles differ: a battery needs deep critical-raw-material and recycling data, while textiles focus on fibre composition, durability and traceability.

What data a DPP must include

Exact fields are finalised per category, but ESPR defines a common baseline that all regulated products carry. A compliant passport is structured, machine-readable and available across the product's lifecycle.

Product identification

Model, SKU, serial or batch identifiers that link the physical item to its digital record at unit or batch level.

Economic operator details

Manufacturer, brand owner, importer or authorised representative responsible for placing the product on the market.

Materials & substances of concern

Bill of materials, recycled-content percentages and disclosure of restricted or hazardous substances for safe recycling and repair.

Environmental & carbon footprint

Product carbon footprint over the lifecycle plus energy, water and resource-use indicators, using recognised methodologies.

Repair, durability & recyclability

Expected lifespan, spare-part availability, repair and disassembly guidance, and end-of-life recycling pathways.

Compliance declarations

Declarations of conformity, test results, CE references and applicable certifications - compliance evidence, digitalised.

Minimum vs. extended data

LayerPurposeExamples
Minimum (baseline) Non-negotiable data to place any regulated product on the EU market Unique identifier, economic operator, material composition, conformity declarations, core sustainability indicators
Extended (sector-specific) Deeper disclosures defined by each product's delegated act Battery state-of-health & recycled content; textile fibre origin & treatments; electronics repairability scores

Tiered access: who sees what

A DPP is not "all data, public to everyone." Access is layered so that transparency and commercial confidentiality can coexist.

Public

Consumer-facing data via QR: care instructions, warranty, sustainability credentials, recycling guidance.

Restricted (authorities)

Compliance documentation and verification records available to regulators and market-surveillance bodies.

Proprietary

Commercially sensitive information shared only with authorised parties (e.g. recyclers, repairers).

Data carriers & the golden rule

ESPR permits several data carriers on the product or its packaging. They must be durable, easily accessible and linked to the passport through the EU Registry.

QR code - cheap, any smartphone RFID tag - automated scanning NFC tag - contactless tap

The passport data does not live on the product. The carrier holds only a static identifier. The live data is fetched at read time - so retrieving current data needs backend internet connectivity.

How the decentralised model works

The EU model is deliberately decentralised. There is no single central database holding everyone's product data. Instead:

The product carries a static ID

A QR / RFID / NFC carrier encodes only a persistent identifier - for example a GS1 Digital Link built on a GTIN.

The EU Registry resolves it

The EU Central DPP Registry uses that identifier to route the request to the manufacturer's approved data host.

Your host serves the live passport

Your approved data host returns the current passport content. You store, control and stay legally responsible for your own data.

This is why the data supply chain - not the QR code - is the real engineering challenge. The passport must be assembled from ERP, PLM, MES and supplier systems that were never designed to talk to each other.

Standards & interoperability

Passports must be readable and comparable across borders. The technical layer is consolidating around a few reference points:

Standard / bodyRole in the DPP
GS1 Digital Link + GTINRecognised product-identifier pattern under ESPR; a QR resolves via the GS1 resolver to the passport. Serialised GTINs enable item-level identity.
CIRPASS-2 - EU DPP Core OntologyDe-facto interoperability reference (delivered March 2025) for sector pilots in textiles, electronics, tyres and construction.
ISO/IEC JTC 5Joint Technical Committee on Digital Product Passports (established April 2026); the global standards venue, with first deliverables expected from 2028.
ISO 14040 / 14044Life-cycle assessment methodology - ensures carbon and environmental data are calculated consistently.
ISO 22095Chain-of-custody models for material and recycled-content claims.
JSON-LD, EPCIS, APIsMachine-readable data schemas and event formats enabling secure cross-platform exchange.
CEN/CENELEC & EBSIHarmonised European data formats; the European Blockchain Services Infrastructure offers optional cryptographic verification.

Enforcement & penalties

Compliance is enforced as a condition of EU market access, so the stakes are commercial as well as legal.

  • CE marking & market surveillance - inspectors can seize products or exclude them from the market.
  • Third-party verification - required specifically for claims such as carbon footprint.
  • Financial penalties - set by Member States and product-group delegated acts, reported up to 4% of EU turnover, plus rejected-shipment costs.

Next step: see when your product group is affected, then open the guide for your company size.