Complete guide
What Is a Digital Product Passport?
A Digital Product Passport is the machine-readable record of what a product is made of and what happens to it next. What it contains, and who must have one.
A Digital Product Passport is a structured, machine-readable record of a product's materials, origin, carbon footprint, repairability and end-of-life handling, accessed by scanning a QR code or NFC tag. Under the EU Ecodesign for Sustainable Products Regulation, passports become mandatory per product group through delegated acts phased from 2026 to 2030.
What this gives you
A precise definition of the passport, what separates it from a product page, and which regulations require one for which products and from when.
Key takeaways
- A Digital Product Passport is a data record attached to a physical product through a scannable carrier, not a document or a certificate.
- The Ecodesign for Sustainable Products Regulation (EU) 2024/1781 makes passports mandatory product group by product group, through delegated acts adopted from 2026 onwards.
- Each delegated act allows roughly 18 months before enforcement, so the real deadline for a product group is set the day its act is adopted.
- One passport serves five different audiences — consumers, recyclers, regulators, brand owners and suppliers — each seeing a different subset of the same record.
- The hard part is not storing the data. It is obtaining it from suppliers who have never been asked for it before.
For thirty years, the data that describes a physical product has been thrown away at every handoff. A smelter knows the exact alloy composition of the aluminium it ships. The component maker who buys it does not. The brand who buys the component knows even less. By the time the finished product reaches a recycler, the only way to find out what is inside is to shred it and analyse the pieces.
The Digital Product Passport exists to stop that loss. It is the European Union's answer to a simple question: if we want products to be repaired, resold and recycled rather than discarded, what does someone at the end of the chain need to know — and how do we make sure they still know it years later?
O que é um passaporte digital de produto?
- Digital Product Passport (DPP)
- A structured, machine-readable set of data about a specific product, batch or item, made accessible through a data carrier such as a QR code, NFC tag or RFID tag. It travels with the product across its whole lifecycle and can be read by anyone with the right access, without contacting the manufacturer.
Three things in that definition do the work, and each rules out something a passport is often mistaken for.
- Structured and machine-readable. A PDF datasheet is not a passport. The data must be queryable by a machine — a recycler's sorting system, a regulator's surveillance tool, a marketplace's listing check — without a human transcribing it.
- Attached to the physical product. The link between the atoms and the data is the point. A database of product information that you cannot reach by scanning the object in your hand solves nothing at end-of-life.
- Persistent across the lifecycle. The passport must still resolve when the product is resold in 2034. That is an obligation about hosting and identity, not about file formats.
Why does the EU require one?
The policy logic runs backwards from a target. The EU wants far more material kept in circulation. Circulating material requires that someone can identify, sort and recover it economically. That requires knowing what is in the product. And that information only exists at the moment of manufacture — so it has to be captured there and carried forward.
The Ecodesign for Sustainable Products Regulation (EU) 2024/1781 is the framework that makes this mandatory. It replaces the older Ecodesign Directive, which applied mainly to energy-related products, and extends the same logic — set requirements at the design stage — to almost every physical product sold in the EU.
Critically, the ESPR itself does not list the data your product needs. It creates the power to require it. The actual requirements arrive later, product group by product group, in delegated acts.
- Step 1ESPR enters forceRegulation (EU) 2024/1781 creates the framework and the power to set requirements.
- Step 2Working plan names a groupThe Commission signals which product groups are next, and roughly when.
- Step 3Delegated act adoptedThe specific data fields, thresholds and passport rules for that group are fixed in law.
- Step 4~18 month transitionThe period in which you must actually collect the data and build the passport.
- Step 5Enforcement beginsProducts placed on the EU market without a compliant passport can be refused.
What data does a Digital Product Passport contain?
The exact fields are set per product group, but the ESPR names the categories every passport draws from. In practice these break into five families.
| Data family | Typical fields | Where it comes from |
|---|---|---|
| Identity | GTIN, serial or batch number, model, manufacturer, resolvable link | Your own ERP or PIM |
| Composition | Material breakdown, recycled content, substances of concern | Suppliers, often tier 2 and below |
| Environmental impact | Carbon footprint by lifecycle stage, water, energy | LCA, supplier primary data |
| Durability & repair | Expected lifetime, spare parts, repair and disassembly instructions | Engineering and service teams |
| End of life | Recyclability, take-back routes, hazardous handling | Product stewardship, recyclers |
The first family is easy — you already have it. The second is where every programme stalls, and we will come back to it.
Who can see what? The five-view problem
A passport has to serve audiences with irreconcilable needs. A consumer wants to know how to wash the jacket. A recycler wants to know whether the coating is a PFAS. A regulator wants the evidence chain behind every claim. The brand wants none of its supplier pricing visible to any of them.
The resolution is one identity with role-scoped views: the same scan returns different data depending on who is asking and what they can prove about themselves.
| Audience | What they see | How access is granted |
|---|---|---|
| Consumer | Care, repair, provenance, recyclability, take-back | None — an open public scan |
| Recycler | Disassembly steps, material breakdown, hazardous substances | Verified role credential |
| Regulator | Full compliance dataset with its evidence chain | Verified authority credential |
| Brand owner | Everything, including commercial data | Tenant authentication |
| Supplier | Only the segment they contributed | Scoped tenant authentication |
How is a passport actually built?
A working passport is four decisions, in this order. Getting the order wrong is the most common cause of expensive rework.
The QR, NFC or RFID tag a person or machine scans. The most visible layer, and the last one to decide.
A URI that turns a scan into a request, and a request into the right record. GS1 Digital Link is the standard here.
What fields exist, what they mean, and how they map to each regulation you are subject to.
Who asserted each fact, when, and how a third party can verify it without trusting you.
The bottom layer is the one that separates a passport from a product page. If your passport says "38% recycled aluminium" and the only basis is that you typed it, a regulator has no more reason to believe it than a marketing claim. Signing that assertion as a W3C Verifiable Credential, issued by the party who actually knows it, is what makes it evidence.
What standards does a passport use?
There is no need to invent anything here, and inventing is actively harmful — a proprietary passport format is a passport that stops working the moment the customer changes vendor.
| Standard | What it solves | Body |
|---|---|---|
| GS1 Digital Link | Turning a product identifier into a resolvable web URI | GS1 |
| EPCIS 2.0 | Capturing supply chain events: what happened, when, where, to which object | GS1 |
| Verifiable Credentials 2.0 | Signed, independently checkable claims | W3C |
| Decentralized Identifiers | Portable identity for the organisations making claims | W3C |
| CIRPASS / CEN-CENELEC JTC 24 | The DPP data model and system architecture | EU / CEN-CENELEC |
| ISO 14040 & 14044 | Life cycle assessment methodology behind footprint figures | ISO |
What actually goes wrong?
Every DPP programme discovers the same three problems, usually in the same order, and usually later than it should have.
The data does not exist yet
Teams budget for a platform and discover the platform was the cheap part. The expensive part is that your tier-2 supplier has never been asked for recycled content, does not measure it, and is not contractually obliged to tell you. Start supplier engagement before you start procurement.
Every supplier sends a different spreadsheet
You will receive the same field named Country of Origin, COO, Herkunftsland and Made In in the same week. Mapping this is genuinely tedious work, and it is where most programmes quietly lose their first year. It is also the part most amenable to automation, because the mapping problem is repetitive and checkable.
The requirements change after you build
If you model your data against a specific regulatory form, the next delegated act is a rewrite. If you model it against a standards-based product model and map to each regulation, the next act is a mapping change. This single architectural decision is the difference between a programme that scales across product groups and one that is rebuilt for each.
What should you do now?
- Find out whether your product group is named in the ESPR working plan, and when its delegated act is indicatively expected.
- Inventory what data you already hold against the five families above. Most organisations are stronger on identity and weaker on composition than they expect.
- Identify the suppliers who hold the rest, and how far down the chain they sit. This determines your timeline more than anything else.
- Get supplier data obligations into contracts at the next renewal. Retrofitting them later is much harder.
- Choose a standards-based data model before choosing a vendor, so the vendor decision stays reversible.
- Build one passport end to end for a single product before scaling. It will surface every problem above at 1% of the cost.
The organisations that will find this easy in 2028 are the ones treating it as a data-supply problem in 2026. The ones that will find it painful are the ones treating it as a document-production problem three months before their delegated act bites.
Frequently asked questions
Is a Digital Product Passport the same as a QR code?
No. The QR code is only the data carrier — the thing you scan. The passport is the structured record the scan resolves to, plus the identity scheme and access rules behind it. You can change the carrier from QR to NFC without changing the passport at all.
When does my product need a Digital Product Passport?
When the delegated act covering your product group takes effect. Delegated acts are adopted progressively from 2026 to 2030, each with roughly an 18-month transition. Iron and steel are expected among the first. Until your group is named, no passport obligation applies to you under the ESPR.
Who is legally responsible for the passport?
The economic operator placing the product on the EU market — usually the manufacturer, or the importer where the manufacturer is outside the EU. That party is responsible for the passport existing, being accurate and remaining available, even though much of the underlying data comes from suppliers.
How long must a Digital Product Passport remain available?
For at least the expected lifetime of the product, and typically beyond it, because the passport is most valuable at end-of-life. This makes hosting and identity persistence a design requirement rather than an operational detail, and it is a reason to prefer resolvable open standards over vendor-specific URLs.
Does a Digital Product Passport require blockchain?
No. Neither the ESPR nor the Battery Regulation requires any distributed ledger. What is required is that data be accurate, available and attributable. Anchoring records to a ledger is one way to make tampering detectable, but signed verifiable credentials achieve attribution without one.
What happens if a product is sold without a compliant passport?
It can be treated as non-compliant and refused market access, and national market surveillance authorities may require corrective action, withdrawal or recall. Penalties are set by member states, so the specific consequence depends on the jurisdiction where the product was placed on the market.
Can one passport cover a batch rather than each item?
Yes, where the delegated act permits it. Batch-level passports suit products whose relevant data does not vary between units, such as a run of textile from one fibre lot. Item-level passports are required where per-unit history matters, which is why batteries are serialised individually.
Do passports apply to products made outside the EU?
Yes, if they are placed on the EU market. The obligation attaches to market access, not to where manufacturing happened. In practice this means non-EU manufacturers selling into Europe face the same data requirements, usually mediated through their EU importer.
Sources
- Regulation (EU) 2024/1781 establishing a framework for the setting of ecodesign requirements for sustainable products — EUR-Lex, European Union, 2024-06
- Regulation (EU) 2023/1542 concerning batteries and waste batteries — EUR-Lex, European Union, 2023-07
- GS1 Digital Link standard — GS1, 2024
- Verifiable Credentials Data Model 2.0 — W3C, 2025
- CIRPASS: Digital Product Passport preparatory study — CIRPASS Consortium, 2024
Continue reading
- ESPR explained: Regulation (EU) 2024/1781The framework regulation behind the passport, in plain English.
- The ESPR delegated acts timelineWhich product groups are affected, and the dates that apply to each.
- What data must a Digital Product Passport contain?The five data families, field by field, and where each one comes from.
- GS1 Digital Link explainedHow a single QR code serves consumers, regulators and machines differently.
- The CirculeID passport platformIssue, host and resolve compliant passports for any product category.