CirculeID

concept

What Data Must a Digital Product Passport Contain?

The five data families a Digital Product Passport draws from, the fields inside each, where the data comes from, and which parts are hardest to obtain.

CirculeID Research7 min read1,537 words

A Digital Product Passport must carry identity, material composition, environmental impact, durability and repair information, and end-of-life handling instructions. Exact fields are set per product group by ESPR delegated acts, so passports are built on a standards-based product model and mapped to each regulation rather than to one fixed form.

What this gives you

Every data category a passport must carry under the ESPR, what is confirmed today versus still in draft, and how to structure fields that are not final yet.

Key takeaways

  • Passport data falls into five families: identity, composition, impact, durability, and end-of-life.
  • Identity data you already hold; composition data is the family that stalls most programmes because it sits with tier-2 and tier-3 suppliers.
  • Exact field lists are set by each product group's delegated act, so no universal schema exists yet — only universal categories.
  • Model data against the product, then map to each regulation, so a new delegated act is a mapping exercise rather than a rebuild.
  • A field that is present but unverifiable is worth less than one that is absent, because it creates liability without creating evidence.

Ask five vendors what a Digital Product Passport must contain and you will get five different field lists. They are all partly right, because the ESPR deliberately does not specify a universal schema — each product group's delegated act sets its own. What is common is the categories the data is drawn from, and those are stable enough to build against today.

The five data families

  1. 1
    Identity
    Which product, batch or item is this, and where does its record live?
  2. 2
    Composition
    What is it made of, where did that come from, and what is hazardous?
  3. 3
    Impact
    What did making it cost the environment, stage by stage?
  4. 4
    Durability & repair
    How long should it last, and how is it kept working?
  5. 5
    End of life
    How is it taken back, disassembled and recovered?

Step 5 returns to step 1 — the loop closes.

End-of-life data feeds back into composition for the next product generation — which is the entire point of the passport.

Family one: identity

Identity answers "which thing is this?" It is the only family most organisations already hold in a usable state, because it lives in the ERP or PIM and has commercial value independent of regulation.

Identity fields in a Digital Product Passport and their typical source system
FieldWhat it isSource
GTINGlobal Trade Item Number identifying the product modelGS1 / ERP
Serial or batch numberWhich specific item or production lotMES or production system
Resolvable linkThe URI a scan resolves to, typically GS1 Digital LinkPassport platform
Manufacturer identityLegal entity placing the product on the marketCorporate records
Model and variantCommercial designation and configurationPIM
Date and place of manufactureWhen and where it was producedMES
Identity fields in a Digital Product Passport and their typical source system

Family two: composition

Composition is where DPP programmes go wrong. The data is unambiguous, technically simple, and almost never available — because it lives with suppliers who have never been asked, do not measure it, and are not contractually obliged to provide it.

Composition fields, why each is required, and how far down the supply chain the data usually sits
FieldWhy it is requiredTypical source tier
Material breakdown by massEnables sorting and recovery at end-of-lifeTier 1–2
Recycled content shareRecycled-content thresholds under ESPR and PPWRTier 2–3
Material originEUDR geolocation, conflict minerals, due diligenceTier 3+
Substances of concernREACH and SCIP disclosure obligationsTier 2–3
Hazardous componentsSafe handling and treatment at end-of-lifeTier 1–2
Critical raw materialsStrategic supply and recovery priorityTier 3+
Composition fields, why each is required, and how far down the supply chain the data usually sits

Read the right-hand column carefully. Nearly everything a regulator wants sits two or three steps beyond the supplier you have a relationship with. That is a commercial and contractual problem long before it is a technical one.

Family three: environmental impact

Impact data quantifies what producing the item cost. The methodology matters as much as the number: a footprint calculated to a different boundary is not comparable, and a regulator will ask which standard you used.

  • Carbon footprint by lifecycle stage — raw material, manufacturing, distribution, use and end-of-life, calculated to ISO 14040 and 14044 or the GHG Protocol Product Standard.
  • Water and energy consumption — increasingly required for textiles and electronics, where use-phase or processing impact dominates.
  • The methodology declaration itself — the standard applied, the system boundary, and whether data is primary or secondary. Without it, the number is not auditable.

Family four: durability and repair

This family is the ESPR's most direct intervention in product design, because it makes design decisions publicly visible and comparable.

  • Expected lifetime under defined conditions, which for batteries becomes cycle life and state of health.
  • Spare parts availability — which parts, for how long after the last unit is sold, and at what price.
  • Repair documentation — instructions detailed enough for an independent repairer, not only an authorised one.
  • Disassembly sequence — the order and tools needed to take the product apart without destroying recoverable material.
  • Repairability score where the delegated act defines one.

Family five: end of life

This is the family the passport exists for. Everything else is instrumentation; this is the payload, and it is read by someone who has no relationship with you and no reason to call.

  • Recyclability by material stream, so a sorter knows what can actually be recovered.
  • Take-back routes — where the product can be returned, and by whom.
  • Hazardous handling instructions for safe treatment.
  • Depollution steps for regulated components such as batteries and capacitors.

How to model this without guessing the final schema

Since no universal field list exists yet, the architectural question is what you model against. There are two options, and one of them is a trap.

Two approaches to modelling passport data, and what happens when requirements change
ApproachWhat happens when a new delegated act landsVerdict
Model against the regulationFields do not fit; schema and integrations are rewritten per actFails at the second product group
Model against the product, map to regulationsA new act is a new mapping over existing dataScales across groups and jurisdictions
Two approaches to modelling passport data, and what happens when requirements change

The second approach also handles the case where two regulations want the same fact in different shapes — CSRD wants aggregate emissions, the ESPR wants them per product — because both become views over one underlying record.

The field nobody lists: attribution

Every field above needs one more thing attached: who said so. A passport that asserts 22% recycled cobalt without recording which party asserted it, when, and on what basis is a marketing claim in structured form.

Issuing each material claim as a signed W3C Verifiable Credential from the party who actually knows it turns the passport from a store of assertions into a chain of evidence a third party can check without trusting the platform hosting it. That distinction is what an auditor is looking for.

Frequently asked questions

Is there a standard list of Digital Product Passport fields?

Not universally. The ESPR sets the categories requirements may address, and each product group's delegated act specifies the exact fields. CIRPASS and CEN-CENELEC JTC 24 are converging on a common data model, but until your group's act is adopted, the precise field list is not fixed.

Which passport data is hardest to obtain?

Material composition and origin, because it sits with tier-2 and tier-3 suppliers who have never been asked for it, may not measure it, and are often not contractually obliged to provide it. Identity data is usually already available; composition data typically takes four to six months of supplier engagement.

Does every passport need a carbon footprint?

Only where the applicable delegated act requires it. The EU Battery Regulation (EU) 2023/1542 already requires a carbon footprint declaration for batteries in scope. For other groups it depends on the act, though the direction of travel across ESPR, CSRD and CBAM makes product-level carbon data broadly expected.

Can commercially sensitive data be kept out of the passport?

Yes. Passports are role-scoped: commercial data such as unit cost and supplier identity is restricted to the brand owner and, where relevant, regulators. Restriction must be enforced by verified role on the server, not by omitting links, since anything reachable without a credential is effectively public.

How precise must material composition be?

Precise enough to support sorting and recovery, and to meet any substance-disclosure threshold that applies. REACH SCIP obligations attach at 0.1% weight by weight for substances of very high concern, which in practice sets the granularity most composition data must reach.

What if a supplier refuses to provide composition data?

The obligation still sits with the economic operator placing the product on the market, so refusal is a commercial problem rather than a defence. Options are contractual requirements at renewal, third-party testing, or substitution. Confidentiality concerns can often be resolved with selective disclosure rather than full transparency.

Should passports be per item, per batch or per model?

It depends on whether the relevant data varies between units. Batteries are serialised individually because state of health is per unit. Textiles are usually batch-level because fibre composition is constant across a lot. The choice drives data volume enormously and is expensive to reverse.

Sources

  1. Regulation (EU) 2024/1781 establishing a framework for the setting of ecodesign requirements for sustainable productsEUR-Lex, European Union, 2024-06
  2. Verifiable Credentials Data Model 2.0W3C, 2025
  3. SCIP database: substances of concern in articlesEuropean Chemicals Agency (ECHA), 2025

Continue reading

Next step

See a passport built on this

CirculeID turns the requirements described above into a working Digital Product Passport for your products.

Index