A DPP data model is incomplete if it only lists business attributes. Article 10 requires the passport to connect through a data carrier to a persistent unique product identifier and requires passport data to use open standards and interoperable formats, to be, as appropriate, machine-readable, structured, and searchable, and to be transferable through an open interoperable data exchange network without vendor lock-in. Article 11 adds interoperability across DPPs, storage by the responsible economic operator or service provider, links between new and original passports, availability after business cessation, data authentication, reliability, integrity, security, privacy, and fraud prevention.
These technical requirements should become fields and acceptance tests. For example, an identifier cannot be approved until the team records the identifier standard or equivalent standard, carrier placement rule, resolver test, backup-provider reference, registry upload status, access-right matrix, and evidence that the displayed data matches the governed source record.
Commission Implementing Decision (EU) 2026/1736 now cites six 2026 editions: EN 18216 for data exchange protocols, EN 18219 for unique identifiers, EN 18220 for data carriers, EN 18221 for storage, archiving and persistence, EN 18222 for lifecycle-management and search APIs, and EN 18223 for system interoperability. Conformity with a cited standard gives a presumption of conformity only for the ESPR Articles 10 and 11 requirements that standard covers. It does not decide which products need a passport or which fields a delegated act selects.