What evidence should teams keep?
Keep evidence that proves the access decision for each data field. A visitor, auditor, authority, supplier, repairer, or customs broker should be able to see why a field was public, restricted, authority-only, customs-relevant, or excluded from publication.
The evidence should also show who can change passport data. Read access for a recycler, repairer, authority, or customer does not automatically mean write access.
- A DPP data inventory mapped to the applicable delegated act or sector rule.
- An access-rights matrix by field, actor, purpose, read permission, update permission, and authentication method.
- A confidential-business-information review for data proposed for public display.
- Registry evidence: uploaded identifiers, commodity code where relevant, and the returned unique registration identifier.
- Customs evidence: process controls for making the unique registration identifier available when a covered product is released for free circulation.
- Change-control evidence showing who created, modified, or updated each restricted passport field.
Articles 10 and 11 require open, interoperable data, protection of personal data, restricted update rights, data integrity, security, and privacy.
The guidance links restricted DPP data to logins or authentication and says public data should be available without personal data collection.