FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
29of29items
Across 7 modules • Updated Jul 25, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Public vs restricted EU Digital Product Passport data

What evidence should teams keep?

Keep evidence that proves the access decision for each data field. A visitor, auditor, authority, supplier, repairer, or customs broker should be able to see why a field was public, restricted, authority-only, customs-relevant, or excluded from publication.

The evidence should also show who can change passport data. Read access for a recycler, repairer, authority, or customer does not automatically mean write access.

  • A DPP data inventory mapped to the applicable delegated act or sector rule.
  • An access-rights matrix by field, actor, purpose, read permission, update permission, and authentication method.
  • A confidential-business-information review for data proposed for public display.
  • Registry evidence: uploaded identifiers, commodity code where relevant, and the returned unique registration identifier.
  • Customs evidence: process controls for making the unique registration identifier available when a covered product is released for free circulation.
  • Change-control evidence showing who created, modified, or updated each restricted passport field.
Citations
Regulation (EU) 2024/1781 (ESPR)

Articles 10 and 11 require open, interoperable data, protection of personal data, restricted update rights, data integrity, security, and privacy.

CWA 18186:2025 DPP guidelines

The guidance links restricted DPP data to logins or authentication and says public data should be available without personal data collection.

Public vs restricted EU Digital Product Passport data

How should teams decide what is public or restricted?

  • Start with the applicable delegated act or sector rule and list each mandatory passport field.
  • Classify every field by read audience, update audience, purpose, authentication method, and evidence owner.
  • Keep registry and customs data controls separate from the public web portal view.
  • Escalate fields that expose confidential business information, personal data, safety-sensitive detail, or conformity evidence before publication.
Citations
What is the EU Digital Product Passport registry?

What does the EU Digital Product Passport registry do?

The Registry is the central EU register for DPP identifier data and associated mandatory metadata. Article 13 requires it to store at least unique identifiers; for products intended for release for free circulation, it also stores the commodity code. Applicable legal acts can require additional registration data.

The Registry is not the public product passport page or a complete product-data repository. The economic operator or a DPP service provider stores the complete passport, while the Registry supports registration, authentication, authority access, and future automated customs checks.

  • Store at least the unique identifiers required for the DPP system.
  • Store commodity codes for products intended for customs release for free circulation.
  • Return a unique registration identifier after the economic operator uploads the required registry data.
  • Give the Commission, competent national authorities, and customs authorities access for their legal duties.
  • Avoid presenting registry acknowledgement as proof that the product complies with ESPR or other EU law.
Citations
What is the EU Digital Product Passport registry?

Who uploads registry data and what gets a registration identifier?

The economic operator placing the product on the market or putting it into service uploads the data required for the registry. Once that data is uploaded, the registry automatically communicates a unique registration identifier associated with the unique identifiers uploaded for that product.

The Commission also says an economic operator can request proof of registration as a secure electronic document. That document evidences registration; ESPR separately says the Registry's identifier communication is not proof of compliance with ESPR or other Union law.

  • Treat the economic operator as the registry uploader unless the applicable legal process says otherwise.
  • Keep the returned unique registration identifier tied to the product's unique identifiers and commodity code where relevant.
  • Do not use the registry response as a general compliance certificate.
  • Preserve upload and correction history so changes to registry data remain auditable.
Citations
Regulation (EU) 2024/1781 (ESPR)

Article 13 assigns registry upload duties to the economic operator placing the product on the market or putting it into service and states that the registry response is not proof of compliance.

What is the EU Digital Product Passport registry?

How do customs checks use the registry?

For products intended to be placed under the customs procedure for release for free circulation, customs authorities verify at minimum that the unique registration identifier and the commodity code correspond to the registry data. The verification is electronic and automatic once the registry-to-customs interconnection is operational.

The Registry is live, but the EU CSW-CERTEX interconnection has its own timetable: ESPR requires it to become operational within four years after the Registry implementing act enters into force. Until the interconnection is operational, do not describe automatic DPP customs matching as live. A later successful customs release will still not prove compliance with ESPR or other Union law.

  • Prepare the unique registration identifier before customs release workflows start.
  • Map the commodity code to the product record before registry upload.
  • Test the customs handoff electronically once the interconnection is operational.
  • Keep customs release records separate from general product-compliance evidence.
Citations
What is the EU Digital Product Passport registry?

What are the Registry's limits?

The Registry is a secure identifier and metadata record. It is neither the public passport page nor a complete product-data store, and its identifier communication does not prove compliance. The passport itself remains distributed across economic operators and service providers.

The Registry does not expose every passport field. It stores at least unique identifiers and, in customs cases, commodity codes. Delegated acts can specify additional stored data under the criteria in Article 13.

  • Registry acknowledgement is not proof of compliance.
  • The Registry and the public web portal are separate systems.
  • Additional registry fields depend on delegated acts, not on page-level convenience.
  • Passport storage can remain decentralised even when registry data is centralised.
Citations
Regulation (EU) 2024/1781 (ESPR)

Articles 13 to 15 distinguish the secure registry, the web portal, customs checks, and the limits on what registry communication proves.

Which products come first for the EU Digital Product Passport?

Which products come first for the EU Digital Product Passport?

For binding passport planning, separate the battery passport from the ESPR Digital Product Passport. The Batteries Regulation says that from 18 February 2027 each LMT battery, each industrial battery with a capacity greater than 2 kWh, and each electric vehicle battery placed on the market or put into service must have an electronic battery passport.

For ESPR product groups, there is no single universal DPP start date. The adopted working plan gives indicative years for adopting measures. After an ESPR delegated act is adopted, economic operators normally receive at least 18 months before its requirements apply, subject to the act's stated transition.

  • Treat covered batteries as a separate first-passport workstream under Regulation (EU) 2023/1542.
  • Treat ESPR priority product groups as a watchlist for upcoming ecodesign and DPP requirements, not as automatic passport obligations.
  • Do not publish a product-group DPP launch date unless the applicable delegated act or official working-plan material supports it.
Citations
Which products come first for the EU Digital Product Passport?

Which ESPR product groups are priority candidates?

The adopted 2025-2030 working plan selects textiles and apparel, furniture, tyres, mattresses, iron and steel, and aluminium for new product work. It also includes horizontal work on repairability and on recycled content and recyclability of electrical and electronic equipment, plus carried-over measures for specified energy-related products.

Its indicative adoption sequence is iron and steel in 2026; textiles and apparel, tyres, aluminium, and repairability in 2027; furniture in 2028; and mattresses plus the electrical and electronic equipment horizontal measure in 2029. These are dates for planned adoption of measures, not product compliance dates.

  • Start inventory work with the product groups and horizontal measures in the adopted working plan, while keeping the broader Article 18 list visible for future reviews.
  • Keep batteries in a separate regulatory tracker because their passport rule is in the Batteries Regulation.
  • Do not treat detergents, paints, lubricants, or chemicals as adopted first-plan product groups. The Commission excluded them from the current plan, while chemicals remain a candidate for later review and footwear has a separate study. Detergents and end-user surfactants now have separate DPP rules under Regulation (EU) 2026/405, which, apart from Article 4(3) and (4), applies from 23 September 2029.
  • For each ESPR product group, link the watch item to the future delegated act rather than copying a generic DPP deadline across all products.
Citations
Which products come first for the EU Digital Product Passport?

Why does the delegated act matter?

Under ESPR, the delegated act is where the general framework becomes product-specific. ESPR Article 9 says products can be placed on the market or put into service only if a digital product passport is available in accordance with the applicable delegated acts, and Article 9 also says those acts specify which data must be included, the data carriers to be used, and how the carrier is presented and positioned.

A priority category, consultation, or technical standard can support early architecture work but does not create the final product duty. Check the delegated act before locking product labels, carrier placement, access tiers, registry fields, or contractual supplier-data duties.

  • Create one tracking row per product group and delegated act, not one generic DPP row for every SKU.
  • Record the affected product models, market role, passport data owner, carrier decision owner, and supplier-data dependencies.
  • Update the row when the delegated act defines the product scope, data elements, carrier layout, access rights, conformity assessment route, and application timing.
Citations
Which products come first for the EU Digital Product Passport?

What should teams do now?

For batteries, use the Batteries Regulation passport scope if the business places covered LMT, industrial greater-than-2 kWh, or electric vehicle batteries on the EU market or puts them into service. That work should include the battery category decision, the responsible economic operator, QR-code access, and the information set in Annex XIII.

For ESPR products, prepare the parts that are unlikely to be wasted: product-group mapping, supplier data ownership, identifier strategy, data-quality controls, and change monitoring. Hold back from asserting final product-group passport dates, mandatory fields, or carrier layout until the delegated act for that group exists and has been reviewed.

  • Segment the portfolio into battery-passport products, adopted ESPR working-plan groups, broader Article 18 candidates, and products not yet matched to an official DPP measure.
  • Assign a regulatory owner for delegated-act monitoring and a data owner for each product family likely to need passport data.
  • For public pages, customer notices, supplier questionnaires, and internal roadmaps, label unfinalised ESPR product-group timing as dependent on the delegated act.
Citations
Who must create an EU Digital Product Passport?

Who is responsible for creating an EU Digital Product Passport?

For an ESPR product covered by a delegated act, start with the economic operator that places the product on the EU market or puts it into service. ESPR Article 10 requires the operator placing the product on the market to make available a back-up copy of the DPP through a DPP service provider. Article 13 requires the operator placing the product on the market or putting it into service to upload the required registry data.

For manufacturers, Article 27 adds a direct duty to ensure that a DPP and its current back-up copy are available for covered products. Article 9 then requires the product-group delegated act to specify the actors that create the DPP or update passport data, what they may change, and the arrangements for doing so.

  • Manufacturer: ensure the covered product has the required DPP and current back-up copy, and keep the passport data accurate, complete, and up to date.
  • Imported product: the importer must check before placing the product on the EU market that a DPP is available in accordance with ESPR Article 9 and the applicable delegated act.
  • Distribution: the distributor must verify, before making a covered product available, that it is labelled or linked to a DPP where the delegated act requires it.
  • Authorised representative: a manufacturer may appoint one by written mandate, but Article 28 says the manufacturer's Article 27(1) obligations, including DPP availability, cannot form part of that mandate.
  • Updates: do not give write access broadly; follow the delegated act's rules on which actors may introduce or update which data.
Citations
Regulation (EU) 2024/1781 establishing ESPR

Articles 9, 10, 13, 27, and 28 identify creation and update rules, placing-on-market duties, manufacturer DPP availability, and the limit on an authorised representative's mandate.

Who must create an EU Digital Product Passport?

How do manufacturer, importer, and distributor duties differ?

The manufacturer obligation is the strongest anchor in ESPR. For covered products, Article 27 requires manufacturers to ensure the product is accompanied by required information and that a DPP is available, including a back-up copy of the most up-to-date passport version stored by a DPP service provider.

Importers and distributors are not passive. Before placing a covered product on the market, importers must ensure that the manufacturer has handled conformity assessment, required information, and DPP availability. Before making the product available, distributors must verify that the product is labelled or linked to a DPP where the delegated act requires it, and they must stop making it available if the product or manufacturer is not compliant.

  • Assign manufacturer accountability to the legal manufacturer named for the product; do not use 'brand owner' as a substitute unless that entity is also the manufacturer under the applicable facts.
  • For non-EU manufacturers, require the EU importer file to show that the passport exists, is accessible, and has the required back-up copy before market placement.
  • Give distributors and dealers a checkable acceptance rule: no required DPP link, data carrier, documents, or instructions means the product should not move forward.
  • Keep marketplace and distance-selling teams supplied with the data carrier copy or unique product identifier so customers can access required passport information before purchase where ESPR requires it.
Citations
Who must create an EU Digital Product Passport?

What responsibility do suppliers and service providers have?

Suppliers are usually data contributors, not the default public owner of the final-product passport. ESPR Article 38 says that, when the delegated act specifies it, supply-chain actors must provide relevant information free of charge to manufacturers, notified bodies, and competent national authorities, allow manufacturer assessment when information is absent, and enable verification of information related to their activities.

DPP service providers are different from suppliers. They may store or process passport data for the economic operator, but ESPR Article 11 limits their processing to what is necessary for the service unless specifically agreed with the operator placing the product on the market or putting it into service.

  • Put supplier evidence in contract and onboarding records: material composition, substance data, component identifiers, production or environmental data, and verification access where the delegated act requires those data.
  • Give suppliers clear data ownership and correction paths so the manufacturer can keep passport data accurate, complete, and up to date.
  • Treat service-provider hosting as governance infrastructure: back-up copy, availability, access control, security, privacy, and continuity after insolvency or cessation of activity.
  • Separate 'can contribute data' from 'is legally responsible for creating the passport' unless the delegated act assigns that creation or update role.
Citations
Who must create an EU Digital Product Passport?

What governance record should a company keep?

A useful DPP responsibility record should identify the legal trigger, the product group, the market-placement actor, the delegated-act rule, and the teams allowed to create or update passport data. It should also show how supplier data is requested, checked, corrected, and locked before publication.

Before the product-specific delegated act exists, keep a product-group watchlist rather than assigning unsupported legal roles. Once the act defines product scope, passport level, data content, access rights, creation and update actors, registry data, and application details, turn those rules into named internal owners.

  • Product identity: model, batch, or item level required by the delegated act.
  • Responsible operator: manufacturer, importer, authorised representative, dealer, distributor, fulfilment service provider, or other actor identified for the product fact pattern.
  • Passport operations: creator, updater, approval owner, service provider, back-up copy location, registry upload owner, and access-rights owner.
  • Supplier controls: data fields requested, supplier source, validation method, correction owner, and evidence retained for authority or notified-body checks.
  • Review trigger: delegated-act changes, product design changes, supplier changes, importer changes, DPP service-provider changes, or non-conformity concerns.
Citations
Page 2 of 2