CirculeID

concept

DPP Rules for Non-EU Manufacturers

Selling into the EU brings passport obligations regardless of where you manufacture. How the rules reach you, and who carries the responsibility.

CirculeID Research6 min read1,271 words

Passport obligations attach to products placed on the EU market, not to EU-based companies. A manufacturer outside the EU is in scope through its importer or authorised representative, and the practical effect is that EU customers pass the requirement up the chain contractually.

What this gives you

Whether the ESPR reaches you as a non-EU manufacturer, who holds the legal obligation in your chain, and what your EU customers will ask you to sign.

Key takeaways

  • The trigger is placing a product on the EU market, not where you are established.
  • The importer carries manufacturer obligations if you have no authorised representative.
  • Your EU customers will impose the requirement contractually before any authority does.
  • Other jurisdictions are developing comparable rules, so this is not only an EU question.

A manufacturer outside the European Union sometimes concludes that EU product rules are somebody else’s problem. That conclusion is wrong in a specific and expensive way.

The obligation follows the product, not the company, and it arrives through commercial pressure long before it arrives through enforcement.

How the obligation reaches you

EU product legislation applies to products placed on the EU market. Placing on the market means the first making available of a product in the Union, and it happens regardless of where the product was made.

Who carries the obligation depending on how you sell into the EU
ArrangementWho is the responsible operatorWhat it means for you
You sell to an EU importerThe importerThey will require the data from you
You appoint an authorised representativeYou, through themYou hold the obligation directly
You sell direct to EU consumers onlineYou, and the fulfilment providerDirect exposure
You supply components to an EU makerThey do, for the finished productThey require your component data
Who carries the obligation depending on how you sell into the EU

The first row is where most non-EU manufacturers actually sit, and it explains why the requirement feels commercial rather than regulatory. The importer bears the legal obligation and has no way to meet it without data from you.

Importers cannot comply alone

An importer placing a product on the EU market takes on obligations that closely resemble a manufacturer’s, and almost none of them can be discharged from the importing side.

The practical consequence is that non-EU manufacturers frequently encounter the passport as a purchase order condition rather than as a regulation, arriving from a customer who has read the regulation and concluded they need it.

The authorised representative option

Appointing an authorised representative established in the EU is the alternative to relying on importers, and it changes the commercial position more than the legal one.

With a representative, you hold the obligation directly and control the compliance narrative for your own products. Without one, every importer builds their own compliance position around your product, frequently inconsistently and always at your expense in time spent answering the same questions repeatedly.

For a manufacturer selling through several importers into several member states, consolidating that into one representative relationship is usually cheaper than servicing each importer’s separate interpretation of what they need.

What actually has to be produced

The data requirements do not change based on where a manufacturer sits, but the difficulty of producing some of them does.

  • Substance data to EU thresholds — which may differ from your domestic requirements.
  • Footprint figures to EU-recognised methods — a domestic calculation may not use the required boundary.
  • Conformity evidence in an EU-recognised form — domestic certification does not automatically transfer.
  • Data in EU languages where consumer-facing information is required.
  • A resolvable identifier reachable from within the EU, reliably.

The second point catches manufacturers who already calculate a product footprint. A figure computed to a domestic standard with a different boundary is not automatically acceptable, and discovering that late means recalculating rather than merely reformatting.

The infrastructure question

A passport must resolve for anybody scanning a product in the EU, which raises hosting questions that are easy to underestimate.

Each of these has failed for real programmes.

The third node deserves particular attention. If your passport records scans, that is personal data processing concerning people in the EU, and GDPR applies to you regardless of where your servers are.

This is not only an EU question

Treating passports as an EU-specific burden misjudges the direction of travel, and a design built solely for EU compliance will need rework.

Several jurisdictions are developing product transparency, right-to-repair and extended producer responsibility requirements with overlapping data needs. The specifics differ and the underlying data — composition, origin, repairability, end-of-life handling — is substantially the same.

The defensible approach is to build the product data foundation once and generate jurisdiction-specific outputs from it, rather than building an EU compliance system that a second requirement will duplicate.

There is also a commercial argument that has nothing to do with compliance. A manufacturer able to answer a European buyer’s data request quickly wins business from competitors who cannot, and that advantage arrives well before any deadline does.

Procurement teams inside EU companies are already screening suppliers on this. A supplier who responds to a substance or footprint request within days rather than months is materially easier to buy from, and that difference is visible in sourcing decisions now.

Frequently asked questions

Do EU passport rules apply to non-EU manufacturers?

They apply to products placed on the EU market rather than to EU-established companies, so a manufacturer outside the Union is in scope through its importer or authorised representative. Where you manufacture does not affect whether the obligation attaches to your product.

Who is legally responsible if we sell through an importer?

The importer carries obligations closely resembling a manufacturer’s, and almost none of them can be discharged from the importing side. Material composition, substance data, footprint figures and conformity evidence all originate at manufacture, so they must obtain everything from you.

Why do importer data requests feel so inflexible?

Because the importer is personally exposed to enforcement for a product they did not design and cannot produce the data themselves. That is a materially different position from an ordinary commercial request, and it is why these requests do not bend the way others do.

Should we appoint an authorised representative?

It is usually cheaper if you sell through several importers into several member states. Without one, each importer builds their own compliance position around your product, frequently inconsistently, and you spend time answering the same questions repeatedly in slightly different forms.

Can we reuse our domestic compliance data?

Partly, and less than expected. Substance thresholds may differ, a footprint calculated to a domestic standard may use a boundary the EU does not accept, and domestic certification does not automatically transfer. Discovering that late means recalculating rather than simply reformatting.

Does GDPR apply to our passport hosting?

If your passport records scans, that is personal data processing concerning people in the EU, and GDPR applies regardless of where your servers sit. Scan telemetry is useful for duplicate detection and it needs a lawful basis and a retention policy.

Is this only an EU requirement?

No, and building solely for EU compliance will eventually need rework. Several jurisdictions are developing product transparency, right-to-repair and extended producer responsibility requirements with substantially overlapping data needs, so build the product data foundation once and generate jurisdiction-specific outputs from it rather than duplicating the whole exercise.

Sources

  1. Regulation (EU) 2024/1781 establishing a framework for ecodesign requirementsEUR-Lex, European Union, 2024-06
  2. Regulation (EU) 2019/1020 on market surveillance and compliance of productsEUR-Lex, European Union, 2019-06

Continue reading

Next step

Einen darauf aufgebauten Pass ansehen

CirculeID macht aus den oben beschriebenen Anforderungen einen funktionierenden digitalen Produktpass für Ihre Produkte.

Index