CirculeID

By role

One passport. Five people who need different things from it.

A consumer wants to know how to wash it. A recycler wants to know how to take it apart. A regulator wants the evidence chain. Publishing one document for all three is how passport programmes stall.

Public tier
No login
Restricted tier
Credential-gated
Evaluated
At resolution

Definition

How does role-based access work in a Digital Product Passport?

A Digital Product Passport has one identity and several role-scoped views. Consumers scanning a data carrier receive the public tier with no login. Recyclers, repairers and regulators present verifiable credentials and receive the restricted tiers those credentials entitle them to. Commercial data stays with the brand and its suppliers.

The tiering is not a product convenience; it is written into the ESPR, which distinguishes information available to the public from information restricted to specified parties. A platform without it either over-publishes or under-serves the recycler the regulation is trying to help.

One passport, five views

Transparency does not mean publishing your supplier list

A CirculeID passport has one identity and role-scoped views over it. The consumer scanning a QR code and the regulator auditing the same product see different slices of the same record, resolved from their credentials.
Passport data categories and the access each role has to them
Data categoryConsumerRetailerRecyclerRegulatorBrand
Identity and originGTIN, model, manufacture date, country of assemblyOpenOpenOpenOpenOpen
Care, repair and take-backInstructions, spare parts, return routesOpenOpenOpenOpenOpen
Material compositionDeclared composition and recycled contentOn requestOn requestOpenOpenOpen
Substances of concernREACH-SCIP declarations and safe handlingOn requestOn requestOpenOpenOpen
Disassembly instructionsSequence, fasteners, hazardous component locationsRestrictedRestrictedOpenOn requestOpen
Supplier identitiesTier-n facility names and site identifiersRestrictedRestrictedRestrictedOn requestOpen
Cost and commercial termsNever part of the passport recordRestrictedRestrictedRestrictedRestrictedOpen

Illustrative default policy. Access is configured per product group and per regulation; where a delegated act requires a field to be public, the policy cannot be set to restrict it.

Resolution

What happens when someone scans

Four steps, and the third is the one that makes a passport programme survivable inside a commercially cautious business.
  1. 01

    Resolve the identifier

    The data carrier holds a GS1 Digital Link URL. Scanning it reaches the resolver with the product identity and nothing else.

  2. 02

    Establish the caller

    A consumer presents nothing. A recycler, repairer or authority presents a verifiable credential issued by a party the policy trusts.

  3. 03

    Apply the policy

    The access policy for that product group and regulation decides which fields the caller receives. Policy is evaluated now, not at issuance.

  4. 04

    Return the view

    The caller receives their tier — as a page for a person, as JSON for a system — with the credential evidence for every claim in it.

Answers

Frequently asked questions

Does a Digital Product Passport mean publishing our supplier list?

No. The ESPR (EU) 2024/1781 distinguishes between information available to the general public and information restricted to specified parties such as market surveillance authorities, repairers and recyclers. Supplier identities and commercial terms are not in the public tier, and CirculeID’s default policy keeps them restricted to the brand.

How does the platform know who is asking?

By what they present, not by who they say they are. A consumer scanning a QR code presents nothing and receives the public view. A recycler or a repairer presents a credential issued by an accreditation body or by you, and the resolver returns the tier that credential entitles them to.

Can a regulator see everything?

A market surveillance authority sees the full compliance dataset and its evidence chain, which is what an inspection requires. It does not automatically include commercial information that no regulation asks for. Access is defined per product group and per regulation, and where an act requires a field to be public the policy cannot restrict it.

What stops someone claiming to be a recycler?

The credential has to be issued by a party you or the accreditation regime trust, and it is cryptographically verifiable. A claim without a valid credential resolves to the public view. Credentials can also be revoked, which matters when a facility loses its permit.

Can access policies change after passports are issued?

Yes, and they need to. A delegated act may move a field from restricted to public, or a supplier agreement may change what you are permitted to share. Policy is evaluated at resolution time rather than baked into the issued document, so a change applies to every passport already in the field.

Next step

See the policy against your own data

Bring a product group and the fields you would never publish. We will show you the four views it produces and what each party sees.

Index