concept
What Data Must a Digital Product Passport Contain?
The five data families a Digital Product Passport draws from, the fields inside each, where the data comes from, and which parts are hardest to obtain.
A Digital Product Passport must carry identity, material composition, environmental impact, durability and repair information, and end-of-life handling instructions. Exact fields are set per product group by ESPR delegated acts, so passports are built on a standards-based product model and mapped to each regulation rather than to one fixed form.
What this gives you
Every data category a passport must carry under the ESPR, what is confirmed today versus still in draft, and how to structure fields that are not final yet.
Key takeaways
- Passport data falls into five families: identity, composition, impact, durability, and end-of-life.
- Identity data you already hold; composition data is the family that stalls most programmes because it sits with tier-2 and tier-3 suppliers.
- Exact field lists are set by each product group's delegated act, so no universal schema exists yet — only universal categories.
- Model data against the product, then map to each regulation, so a new delegated act is a mapping exercise rather than a rebuild.
- A field that is present but unverifiable is worth less than one that is absent, because it creates liability without creating evidence.
Ask five vendors what a Digital Product Passport must contain and you will get five different field lists. They are all partly right, because the ESPR deliberately does not specify a universal schema — each product group's delegated act sets its own. What is common is the categories the data is drawn from, and those are stable enough to build against today.
The five data families
- 1IdentidadWhich product, batch or item is this, and where does its record live?
- 2CompositionWhat is it made of, where did that come from, and what is hazardous?
- 3ImpactWhat did making it cost the environment, stage by stage?
- 4Durability & repairHow long should it last, and how is it kept working?
- 5End of lifeHow is it taken back, disassembled and recovered?
Step 5 returns to step 1 — the loop closes.
Family one: identity
Identity answers "which thing is this?" It is the only family most organisations already hold in a usable state, because it lives in the ERP or PIM and has commercial value independent of regulation.
| Field | What it is | Source |
|---|---|---|
| GTIN | Global Trade Item Number identifying the product model | GS1 / ERP |
| Serial or batch number | Which specific item or production lot | MES or production system |
| Resolvable link | The URI a scan resolves to, typically GS1 Digital Link | Passport platform |
| Manufacturer identity | Legal entity placing the product on the market | Corporate records |
| Model and variant | Commercial designation and configuration | PIM |
| Date and place of manufacture | When and where it was produced | MES |
Family two: composition
Composition is where DPP programmes go wrong. The data is unambiguous, technically simple, and almost never available — because it lives with suppliers who have never been asked, do not measure it, and are not contractually obliged to provide it.
| Field | Why it is required | Typical source tier |
|---|---|---|
| Material breakdown by mass | Enables sorting and recovery at end-of-life | Tier 1–2 |
| Recycled content share | Recycled-content thresholds under ESPR and PPWR | Tier 2–3 |
| Material origin | EUDR geolocation, conflict minerals, due diligence | Tier 3+ |
| Substances of concern | REACH and SCIP disclosure obligations | Tier 2–3 |
| Hazardous components | Safe handling and treatment at end-of-life | Tier 1–2 |
| Critical raw materials | Strategic supply and recovery priority | Tier 3+ |
Read the right-hand column carefully. Nearly everything a regulator wants sits two or three steps beyond the supplier you have a relationship with. That is a commercial and contractual problem long before it is a technical one.
Family three: environmental impact
Impact data quantifies what producing the item cost. The methodology matters as much as the number: a footprint calculated to a different boundary is not comparable, and a regulator will ask which standard you used.
- Carbon footprint by lifecycle stage — raw material, manufacturing, distribution, use and end-of-life, calculated to ISO 14040 and 14044 or the GHG Protocol Product Standard.
- Water and energy consumption — increasingly required for textiles and electronics, where use-phase or processing impact dominates.
- The methodology declaration itself — the standard applied, the system boundary, and whether data is primary or secondary. Without it, the number is not auditable.
Family four: durability and repair
This family is the ESPR's most direct intervention in product design, because it makes design decisions publicly visible and comparable.
- Expected lifetime under defined conditions, which for batteries becomes cycle life and state of health.
- Spare parts availability — which parts, for how long after the last unit is sold, and at what price.
- Repair documentation — instructions detailed enough for an independent repairer, not only an authorised one.
- Disassembly sequence — the order and tools needed to take the product apart without destroying recoverable material.
- Repairability score where the delegated act defines one.
Family five: end of life
This is the family the passport exists for. Everything else is instrumentation; this is the payload, and it is read by someone who has no relationship with you and no reason to call.
- Recyclability by material stream, so a sorter knows what can actually be recovered.
- Take-back routes — where the product can be returned, and by whom.
- Hazardous handling instructions for safe treatment.
- Depollution steps for regulated components such as batteries and capacitors.
How to model this without guessing the final schema
Since no universal field list exists yet, the architectural question is what you model against. There are two options, and one of them is a trap.
| Approach | What happens when a new delegated act lands | Verdict |
|---|---|---|
| Model against the regulation | Fields do not fit; schema and integrations are rewritten per act | Fails at the second product group |
| Model against the product, map to regulations | A new act is a new mapping over existing data | Scales across groups and jurisdictions |
The second approach also handles the case where two regulations want the same fact in different shapes — CSRD wants aggregate emissions, the ESPR wants them per product — because both become views over one underlying record.
The field nobody lists: attribution
Every field above needs one more thing attached: who said so. A passport that asserts 22% recycled cobalt without recording which party asserted it, when, and on what basis is a marketing claim in structured form.
Issuing each material claim as a signed W3C Verifiable Credential from the party who actually knows it turns the passport from a store of assertions into a chain of evidence a third party can check without trusting the platform hosting it. That distinction is what an auditor is looking for.
Frequently asked questions
Is there a standard list of Digital Product Passport fields?
Not universally. The ESPR sets the categories requirements may address, and each product group's delegated act specifies the exact fields. CIRPASS and CEN-CENELEC JTC 24 are converging on a common data model, but until your group's act is adopted, the precise field list is not fixed.
Which passport data is hardest to obtain?
Material composition and origin, because it sits with tier-2 and tier-3 suppliers who have never been asked for it, may not measure it, and are often not contractually obliged to provide it. Identity data is usually already available; composition data typically takes four to six months of supplier engagement.
Does every passport need a carbon footprint?
Only where the applicable delegated act requires it. The EU Battery Regulation (EU) 2023/1542 already requires a carbon footprint declaration for batteries in scope. For other groups it depends on the act, though the direction of travel across ESPR, CSRD and CBAM makes product-level carbon data broadly expected.
Can commercially sensitive data be kept out of the passport?
Yes. Passports are role-scoped: commercial data such as unit cost and supplier identity is restricted to the brand owner and, where relevant, regulators. Restriction must be enforced by verified role on the server, not by omitting links, since anything reachable without a credential is effectively public.
How precise must material composition be?
Precise enough to support sorting and recovery, and to meet any substance-disclosure threshold that applies. REACH SCIP obligations attach at 0.1% weight by weight for substances of very high concern, which in practice sets the granularity most composition data must reach.
What if a supplier refuses to provide composition data?
The obligation still sits with the economic operator placing the product on the market, so refusal is a commercial problem rather than a defence. Options are contractual requirements at renewal, third-party testing, or substitution. Confidentiality concerns can often be resolved with selective disclosure rather than full transparency.
Should passports be per item, per batch or per model?
It depends on whether the relevant data varies between units. Batteries are serialised individually because state of health is per unit. Textiles are usually batch-level because fibre composition is constant across a lot. The choice drives data volume enormously and is expensive to reverse.
Sources
- Regulation (EU) 2024/1781 establishing a framework for the setting of ecodesign requirements for sustainable products — EUR-Lex, European Union, 2024-06
- Verifiable Credentials Data Model 2.0 — W3C, 2025
- SCIP database: substances of concern in articles — European Chemicals Agency (ECHA), 2025
Continue reading
- ¿Qué es un pasaporte digital de producto?The complete guide to the record, who must produce it and how it works.
- ESPR explained: Regulation (EU) 2024/1781The framework that decides which of these fields become mandatory for you.
- GS1 Digital Link explainedHow identity data becomes a resolvable link that machines can follow.
- Traceability on the CirculeID platformCapturing EPCIS 2.0 events so composition data has a verifiable history.