CirculeID

Complete guide

What Is a Digital Product Passport?

A Digital Product Passport is the machine-readable record of what a product is made of and what happens to it next. What it contains, and who must have one.

CirculeID Research10 min read2,257 words

A Digital Product Passport is a structured, machine-readable record of a product's materials, origin, carbon footprint, repairability and end-of-life handling, accessed by scanning a QR code or NFC tag. Under the EU Ecodesign for Sustainable Products Regulation, passports become mandatory per product group through delegated acts phased from 2026 to 2030.

What this gives you

A precise definition of the passport, what separates it from a product page, and which regulations require one for which products and from when.

Key takeaways

  • A Digital Product Passport is a data record attached to a physical product through a scannable carrier, not a document or a certificate.
  • The Ecodesign for Sustainable Products Regulation (EU) 2024/1781 makes passports mandatory product group by product group, through delegated acts adopted from 2026 onwards.
  • Each delegated act allows roughly 18 months before enforcement, so the real deadline for a product group is set the day its act is adopted.
  • One passport serves five different audiences — consumers, recyclers, regulators, brand owners and suppliers — each seeing a different subset of the same record.
  • The hard part is not storing the data. It is obtaining it from suppliers who have never been asked for it before.

For thirty years, the data that describes a physical product has been thrown away at every handoff. A smelter knows the exact alloy composition of the aluminium it ships. The component maker who buys it does not. The brand who buys the component knows even less. By the time the finished product reaches a recycler, the only way to find out what is inside is to shred it and analyse the pieces.

The Digital Product Passport exists to stop that loss. It is the European Union's answer to a simple question: if we want products to be repaired, resold and recycled rather than discarded, what does someone at the end of the chain need to know — and how do we make sure they still know it years later?

¿Qué es un pasaporte digital de producto?

Digital Product Passport (DPP)
A structured, machine-readable set of data about a specific product, batch or item, made accessible through a data carrier such as a QR code, NFC tag or RFID tag. It travels with the product across its whole lifecycle and can be read by anyone with the right access, without contacting the manufacturer.

Three things in that definition do the work, and each rules out something a passport is often mistaken for.

  • Structured and machine-readable. A PDF datasheet is not a passport. The data must be queryable by a machine — a recycler's sorting system, a regulator's surveillance tool, a marketplace's listing check — without a human transcribing it.
  • Attached to the physical product. The link between the atoms and the data is the point. A database of product information that you cannot reach by scanning the object in your hand solves nothing at end-of-life.
  • Persistent across the lifecycle. The passport must still resolve when the product is resold in 2034. That is an obligation about hosting and identity, not about file formats.

Why does the EU require one?

The policy logic runs backwards from a target. The EU wants far more material kept in circulation. Circulating material requires that someone can identify, sort and recover it economically. That requires knowing what is in the product. And that information only exists at the moment of manufacture — so it has to be captured there and carried forward.

The Ecodesign for Sustainable Products Regulation (EU) 2024/1781 is the framework that makes this mandatory. It replaces the older Ecodesign Directive, which applied mainly to energy-related products, and extends the same logic — set requirements at the design stage — to almost every physical product sold in the EU.

Critically, the ESPR itself does not list the data your product needs. It creates the power to require it. The actual requirements arrive later, product group by product group, in delegated acts.

The ESPR is a framework. The obligation that applies to your product is created by its delegated act, and the clock starts when that act is adopted.

What data does a Digital Product Passport contain?

The exact fields are set per product group, but the ESPR names the categories every passport draws from. In practice these break into five families.

The five data families in a Digital Product Passport, with typical fields and where the data comes from
Data familyTypical fieldsWhere it comes from
IdentityGTIN, serial or batch number, model, manufacturer, resolvable linkYour own ERP or PIM
CompositionMaterial breakdown, recycled content, substances of concernSuppliers, often tier 2 and below
Environmental impactCarbon footprint by lifecycle stage, water, energyLCA, supplier primary data
Durability & repairExpected lifetime, spare parts, repair and disassembly instructionsEngineering and service teams
End of lifeRecyclability, take-back routes, hazardous handlingProduct stewardship, recyclers
The five data families in a Digital Product Passport, with typical fields and where the data comes from

The first family is easy — you already have it. The second is where every programme stalls, and we will come back to it.

Who can see what? The five-view problem

A passport has to serve audiences with irreconcilable needs. A consumer wants to know how to wash the jacket. A recycler wants to know whether the coating is a PFAS. A regulator wants the evidence chain behind every claim. The brand wants none of its supplier pricing visible to any of them.

The resolution is one identity with role-scoped views: the same scan returns different data depending on who is asking and what they can prove about themselves.

The five role-scoped views of a single Digital Product Passport
AudienceWhat they seeHow access is granted
ConsumerCare, repair, provenance, recyclability, take-backNone — an open public scan
RecyclerDisassembly steps, material breakdown, hazardous substancesVerified role credential
RegulatorFull compliance dataset with its evidence chainVerified authority credential
Brand ownerEverything, including commercial dataTenant authentication
SupplierOnly the segment they contributedScoped tenant authentication
The five role-scoped views of a single Digital Product Passport

How is a passport actually built?

A working passport is four decisions, in this order. Getting the order wrong is the most common cause of expensive rework.

Each layer depends on the one below it. Choosing a carrier before you have decided your identity scheme is the classic sequencing error.

The bottom layer is the one that separates a passport from a product page. If your passport says "38% recycled aluminium" and the only basis is that you typed it, a regulator has no more reason to believe it than a marketing claim. Signing that assertion as a W3C Verifiable Credential, issued by the party who actually knows it, is what makes it evidence.

What standards does a passport use?

There is no need to invent anything here, and inventing is actively harmful — a proprietary passport format is a passport that stops working the moment the customer changes vendor.

The core standards a Digital Product Passport is built on, and what each one solves
StandardWhat it solvesBody
GS1 Digital LinkTurning a product identifier into a resolvable web URIGS1
EPCIS 2.0Capturing supply chain events: what happened, when, where, to which objectGS1
Verifiable Credentials 2.0Signed, independently checkable claimsW3C
Decentralized IdentifiersPortable identity for the organisations making claimsW3C
CIRPASS / CEN-CENELEC JTC 24The DPP data model and system architectureEU / CEN-CENELEC
ISO 14040 & 14044Life cycle assessment methodology behind footprint figuresISO
The core standards a Digital Product Passport is built on, and what each one solves

What actually goes wrong?

Every DPP programme discovers the same three problems, usually in the same order, and usually later than it should have.

The data does not exist yet

Teams budget for a platform and discover the platform was the cheap part. The expensive part is that your tier-2 supplier has never been asked for recycled content, does not measure it, and is not contractually obliged to tell you. Start supplier engagement before you start procurement.

Every supplier sends a different spreadsheet

You will receive the same field named Country of Origin, COO, Herkunftsland and Made In in the same week. Mapping this is genuinely tedious work, and it is where most programmes quietly lose their first year. It is also the part most amenable to automation, because the mapping problem is repetitive and checkable.

The requirements change after you build

If you model your data against a specific regulatory form, the next delegated act is a rewrite. If you model it against a standards-based product model and map to each regulation, the next act is a mapping change. This single architectural decision is the difference between a programme that scales across product groups and one that is rebuilt for each.

What should you do now?

  1. Find out whether your product group is named in the ESPR working plan, and when its delegated act is indicatively expected.
  2. Inventory what data you already hold against the five families above. Most organisations are stronger on identity and weaker on composition than they expect.
  3. Identify the suppliers who hold the rest, and how far down the chain they sit. This determines your timeline more than anything else.
  4. Get supplier data obligations into contracts at the next renewal. Retrofitting them later is much harder.
  5. Choose a standards-based data model before choosing a vendor, so the vendor decision stays reversible.
  6. Build one passport end to end for a single product before scaling. It will surface every problem above at 1% of the cost.

The organisations that will find this easy in 2028 are the ones treating it as a data-supply problem in 2026. The ones that will find it painful are the ones treating it as a document-production problem three months before their delegated act bites.

Frequently asked questions

Is a Digital Product Passport the same as a QR code?

No. The QR code is only the data carrier — the thing you scan. The passport is the structured record the scan resolves to, plus the identity scheme and access rules behind it. You can change the carrier from QR to NFC without changing the passport at all.

When does my product need a Digital Product Passport?

When the delegated act covering your product group takes effect. Delegated acts are adopted progressively from 2026 to 2030, each with roughly an 18-month transition. Iron and steel are expected among the first. Until your group is named, no passport obligation applies to you under the ESPR.

Who is legally responsible for the passport?

The economic operator placing the product on the EU market — usually the manufacturer, or the importer where the manufacturer is outside the EU. That party is responsible for the passport existing, being accurate and remaining available, even though much of the underlying data comes from suppliers.

How long must a Digital Product Passport remain available?

For at least the expected lifetime of the product, and typically beyond it, because the passport is most valuable at end-of-life. This makes hosting and identity persistence a design requirement rather than an operational detail, and it is a reason to prefer resolvable open standards over vendor-specific URLs.

Does a Digital Product Passport require blockchain?

No. Neither the ESPR nor the Battery Regulation requires any distributed ledger. What is required is that data be accurate, available and attributable. Anchoring records to a ledger is one way to make tampering detectable, but signed verifiable credentials achieve attribution without one.

What happens if a product is sold without a compliant passport?

It can be treated as non-compliant and refused market access, and national market surveillance authorities may require corrective action, withdrawal or recall. Penalties are set by member states, so the specific consequence depends on the jurisdiction where the product was placed on the market.

Can one passport cover a batch rather than each item?

Yes, where the delegated act permits it. Batch-level passports suit products whose relevant data does not vary between units, such as a run of textile from one fibre lot. Item-level passports are required where per-unit history matters, which is why batteries are serialised individually.

Do passports apply to products made outside the EU?

Yes, if they are placed on the EU market. The obligation attaches to market access, not to where manufacturing happened. In practice this means non-EU manufacturers selling into Europe face the same data requirements, usually mediated through their EU importer.

Sources

  1. Regulation (EU) 2024/1781 establishing a framework for the setting of ecodesign requirements for sustainable productsEUR-Lex, European Union, 2024-06
  2. Regulation (EU) 2023/1542 concerning batteries and waste batteriesEUR-Lex, European Union, 2023-07
  3. GS1 Digital Link standardGS1, 2024
  4. Verifiable Credentials Data Model 2.0W3C, 2025
  5. CIRPASS: Digital Product Passport preparatory studyCIRPASS Consortium, 2024

Continue reading

Next step

Ver un pasaporte construido sobre esto

CirculeID convierte los requisitos descritos arriba en un pasaporte digital de producto operativo para sus productos.

Index