Concise answers on how the EU Digital Product Passport works under the Ecodesign for Sustainable Products Regulation.
Covers who creates and updates passports, which product groups are first in scope, what goes into the registry, how customs access works, and how public and restricted data should be separated.
The EU is the ESPR mechanism for making product sustainability, circularity, traceability, and compliance information available electronically. The exact passport content, access rights, , and product level are set in product-specific delegated acts, so implementation starts with the applicable product group rule rather than a one-size-fits-all passport template.
Browse sub-FAQs
Choose the question set you need
These focused FAQ modules break this artifact into narrower answer sets so teams can move straight to the right source-backed guidance.
Who creates EU Digital Product Passports and when are they required?
Under ESPR, a product covered by a can be placed on the EU market or put into service only if a is available as required by that delegated act. The passport data must be accurate, complete, and up to date.
The for the product group specifies which actors create the passport, which actors may update which data, whether the passport is at model, batch, or item level, how long it remains available, and how customers can access it before purchase. Manufacturers must ensure the passport is available for covered products; the economic operator placing the product on the market must also provide access support to dealers and online marketplaces and make a back-up copy available through a DPP service provider.
Start by identifying whether a product-specific ESPR covers the product.
Use that to assign the passport creator, data updater, passport level, access method, and availability period.
Do not assume every passport is item-level; ESPR allows the to choose model, batch, or item level.
Do not treat the registry response as proof of product compliance; ESPR says the unique registration identifier communication is not proof of compliance.
ESPR is framework legislation: concrete DPP duties arrive through product-specific or horizontal delegated acts. The adopted 2025-2030 working plan prioritises new work on textiles and apparel, furniture, tyres, mattresses, iron and steel, aluminium, repairability, and recycled content and recyclability of electrical and electronic equipment. It also carries forward work on specified energy-related products.
The working plan is narrower than the list in ESPR Article 18. Detergents, paints, lubricants, and chemicals were not included as product groups in the adopted plan; footwear is subject to a separate study. A working-plan date is an indicative date for adopting a measure, not the date every product in that group must carry a passport.
Indicative adoption sequence for the new product work: iron and steel in 2026; textiles and apparel, tyres, aluminium, and repairability in 2027; furniture in 2028; mattresses and recycled-content and recyclability rules for electrical and electronic equipment in 2029.
ICT products are covered through the horizontal measures and some energy-related product work rather than one generic ICT in the working-plan table.
Separate working-plan monitoring from active delegated-act compliance. The sets the covered products, DPP fields, access rights, carrier, product level, transition period, and application date.
What data is public, restricted, or available to customs?
ESPR does not make every DPP field public. It requires free and easy access for customers, manufacturers, importers, distributors, dealers, repairers, refurbishers, remanufacturers, recyclers, market surveillance authorities, customs authorities, civil society organisations, trade unions, and other relevant actors based on the access rights set in the applicable .
The went live on 20 July 2026 and stores the identifiers and metadata required by the applicable legal act. Under ESPR, it stores at least unique identifiers and, for products intended for release for free circulation, the commodity code. The separate automatic customs verification applies only when the EU CSW-CERTEX interconnection is operational.
Public-facing DPP views should expose only the fields the makes accessible to customers and other public stakeholders.
Restricted views should protect fields whose access is limited to authorities, supply-chain actors, or other named roles.
Customs workflows need the unique registration identifier and commodity code path, not only a consumer-facing QR landing page.
The Commission web portal is for search and comparison of DPP data according to each stakeholder's access rights.
Prepare the Digital Product Passport evidence model
Use the applicable delegated act to map passport fields, access rights, registry data, identifiers, data carriers, owners, and update controls before publishing a DPP endpoint.
How should teams handle identifiers, QR codes, NFC, and governance?
The DPP must be connected through a to a persistent . The data carrier must be physically present on the product, packaging, or accompanying documentation as specified by the , and the data must be open-standard, interoperable, machine-readable where appropriate, structured, searchable, and transferable without vendor lock-in.
ESPR does not hard-code QR or NFC as the universal answer in the main regulation. The product specifies the and layout. QR codes are a common candidate for electronic access, while NFC or RFID may be relevant where the selected standard and product rule allow them; the governance control is that identifiers, data carriers, access rights, update rights, back-up copies, security, privacy, and service-provider arrangements remain traceable and documented.
Since 15 July 2026, six cited harmonised standards cover DPP data exchange, unique identifiers, data carriers, storage and persistence, lifecycle APIs, and system interoperability. Conformity with a cited standard gives a presumption of conformity for the ESPR Articles 10 and 11 requirements it covers. It does not decide whether a product needs a DPP or which fields and access rights apply.
Maintain a , relevant operator identifiers, facility identifiers where required, commodity code, compliance documentation links, instructions, importer details, and DPP service-provider reference where the requires them.
Keep customer personal data out of the DPP unless there is explicit consent under EU data-protection rules.
Restrict who can introduce, modify, or update DPP data according to delegated-act access rights.
Use open, interoperable formats and avoid vendor lock-in in the passport data exchange layer.
For NFC or RFID implementations, check the product and the selected identification standard before treating a tag as an accepted DPP .
Confirms that the DPP is intended for consumers, businesses, and relevant public authorities and that future DPP rules cover data storage, management, and service-provider governance.
"available to consumers, businesses and relevant public authorities"
Current binding source for the six cited EN 182xx:2026 standards and their presumption-of-conformity effect for covered ESPR Articles 10 and 11 requirements.
Commission working plan identifying the adopted product priorities, indicative adoption years, horizontal measures, carried-over energy-related products, and exclusions from the Article 18 list.
Explains the DPP as an electronic identity card for products, components, and materials that supports sustainability, circularity, and legal compliance.
"a digital identity card for products, components, and materials"