- Supports using a DPP design record for implementation decisions involving data carriers, portal contents, and information exchanges.
"information exchanges and applications"
A workflow for checking which DPP data is public, restricted, or available to customs authorities before an ESPR-covered product is imported or released.
Use it to align access rights, registry evidence, portal expectations, and customs release checks. The Commission launched the DPP Registry on 20 July 2026; product-specific registration duties still depend on the applicable EU legislation.
Structured answer sets in this page tree.
Cited legal and guidance references.
This workflow helps product, trade compliance, and DPP implementation teams review customs access for an EU Digital Product Passport under the Ecodesign for Sustainable Products Regulation. It covers the passport data carrier and unique product identifier, stakeholder access rights set in product-specific delegated acts, the Commission registry, the planned public search portal, and customs checks for . The Registry became operational on 20 July 2026, but a product must be registered only when the applicable ESPR delegated act or other Union legislation requires a DPP and registration.
Start by separating DPP data into three access routes. Public data is the information that stakeholders can search or compare through the Commission web portal when access rights allow it. Restricted data is DPP information available only to named actor types under product-specific access rights. Customs access is the authority route for customs duties, including risk management, customs controls, and .
Do not treat the passport as one public document. ESPR requires access to DPP data to be regulated by delegated-act access rights, and it requires free and easy access for listed actors, including customs authorities, based on those respective access rights.
The registry handoff is not the same as publishing the whole passport. The live Registry stores unique identifiers, registration data, and high-level metadata rather than the full DPP. Commission Implementing Regulation (EU) 2026/1778, published on 17 July 2026 and entering into force on 6 August 2026, sets rules for registration through a secure user interface or API, automated checks, and generation of a unique and persistent registration identifier.
The public search portal is a separate ESPR service. Article 14 requires the Commission to provide it for searching and comparing DPP data according to product-group access rights; the Commission's July 2026 DPP timeline says that portal is planned for a later launch. Do not record a successful Registry lookup as a public-portal test.
This workflow helps check access rights, registry identifiers, portal exposure, and customs handoff evidence before ESPR-covered products reach release-for-free-circulation review.
For customs release readiness, stay inside the ESPR mechanics. From the Registry's operational launch on 20 July 2026, a person placing a product covered by an ESPR delegated act under the customs procedure for must provide or make available its unique registration identifier. For other products, the same mechanism applies only where the applicable Union legislation requires that customs handoff.
The minimum customs match is the unique registration identifier and commodity code against Registry data. Article 15 makes the electronic and automatic verification obligation depend on the EU CSW-CERTEX interconnection becoming operational, so teams should confirm the current customs-system route instead of assuming that Registry availability alone proves the automated customs exchange is active. Customs release is not proof of compliance with ESPR or other Union law.
Close the review with evidence that proves the access model is deliberate. The evidence should show which actor type can see, create, update, or retrieve each field; how public portal data differs from restricted data; and how customs receives the registry identifier needed for .
The evidence should also show that DPP data remains accurate, complete, up to date, reliable, and protected. ESPR requires data authentication, reliability, integrity, security, privacy, and fraud avoidance, and it restricts rights to introduce, modify, or update DPP data based on delegated-act access rights.
"information exchanges and applications"
"consumers, businesses and relevant public authorities"
"digital identity card for products"
"data authentication, reliability and integrity"