ComplianceLaws & RegulationsProduct SustainabilitySupply Chain & Sustainable Procurement

Digital Product Passport: Technical Requirements and EU Compliance Guide

Last updated: 2 May 2026

The EU's Digital Product Passport (DPP) is one of the most significant product compliance obligations to emerge from the European Green Deal. From 2027, manufacturers and importers placing certain products on the EU market must attach a machine-readable record containing standardised sustainability, circularity, and supply chain data. By 2030, DPP requirements will extend to nearly all physical product categories sold in Europe.

This guide covers the actual technical requirements companies need to meet: what data a DPP must contain, how it must be attached and accessed, who is responsible, and when compliance deadlines fall — by product category.

Person scanning a QR code — digital product passport data access

What Is a Digital Product Passport?

A Digital Product Passport is a structured digital record linked to a physical product throughout its lifecycle. It is accessible via a data carrier — typically a QR code — embedded on or in the product, containing verified information about the product's materials, environmental performance, repairability, and end-of-life handling.

DPPs are mandated under two EU regulations:

  • Ecodesign for Sustainable Products Regulation (ESPR, EU 2024/1781) — the primary framework, covering most physical products. Came into force July 2024. Product-specific requirements are issued via delegated acts.
  • Battery Regulation (EU 2023/1542) — the most advanced DPP implementation published to date, with specific technical schemas already confirmed. DPP obligations for industrial and EV batteries apply from February 2027.

Food, feed, medicines, living organisms, military equipment, and most vehicles fall outside scope.

Which Products Need a DPP — and When?

Product category

Regulatory basis

DPP compliance deadline

Batteries (industrial & EV)

EU 2023/1542 (published)

February 2027

Textiles and apparel

ESPR delegated act in development (2025)

2027–2028 (expected)

Electronics and ICT equipment

ESPR delegated act in development (2025–2026)

2027–2028 (expected)

Furniture

ESPR — delegated act under preparation

2028 (expected)

Construction products

Construction Products Regulation (signed 2022)

TBD per CPR implementing rules

Tyres, footwear, mattresses, paints, detergents

ESPR — planned, delegated acts not yet published

2028–2030 (expected)

Deadlines for non-battery categories will be confirmed in delegated acts. The European Commission has committed to issuing the first non-battery ESPR delegated acts by 2025, with rolling compliance windows thereafter. Any manufacturer or importer selling physical goods in Europe should be identifying their position now — compliance programmes for complex product lines typically require two to three years of lead time.

Technical Requirements: What a DPP Must Contain

1. Data Carrier

Every product subject to DPP requirements must carry a machine-readable data carrier that resolves to the product's digital record. The specification under ESPR and the Battery Regulation:

  • Primary carrier: QR code compliant with ISO/IEC 18004. The code must resolve to the DPP data access point URL.
  • Permitted alternatives: RFID (ISO 18000-63), NFC tags (ISO 15693), Data Matrix codes (ISO 16022), or other 2D identifiers approved in the relevant delegated act.
  • Durability: The carrier must remain legible for the product's expected lifetime — for batteries and most industrial products, at least ten years after the last unit is placed on the market.
  • Placement: Visible without disassembly or removing primary packaging where physically practicable.
  • Free access: Consumers must be able to read the DPP without any paid subscription, registration, or software beyond a standard smartphone camera.

2. Unique Product Identifier (UPI)

Each product or product model must be assigned a Unique Product Identifier encoded in the data carrier and registered in the EU's product passport registry. The UPI must:

  • Be unique and persistent — it cannot be reused or changed after assignment.
  • Conform to a recognised identifier standard. GS1 Digital Link (GTIN + serial or batch number), ISO/IEC 15459, and UUID formats are all referenced as compliant approaches. For manufacturers already using EAN/UPC barcodes, extending existing GTINs to GS1 Digital Links is the lowest-friction route.
  • Be resolvable to a URL — the identifier format must allow direct resolution to the DPP data access point without a separate lookup service.
  • Remain valid for the full commercial lifetime plus the prescribed post-market retention period (ten years under Battery Regulation; similar or longer expected under ESPR delegated acts).

3. Required Data Fields

Required data fields vary by product category and are defined in each delegated act. The following reflects the ESPR general framework plus the Battery Regulation's published schema — the most detailed DPP data model confirmed to date.

General ESPR data categories (applies across product types)

  • Product identification: product name and model identifier, batch or serial number, manufacturer name and contact details, authorised representative (if applicable), country of origin, date of manufacture.
  • Environmental performance: product performance class where applicable, lifecycle carbon footprint broken down by stage (production, use phase, end-of-life), energy consumption during use.
  • Material composition: percentage by weight of key material types, recycled content declaration per material type.
  • Substances of concern: for each substance present above 0.1% by weight — name, CAS number, location within the product, and concentration range. Applies to substances on the ESPR Annex I list and the REACH SVHC list.
  • Repairability and durability: repairability score (where mandated), availability and pricing of spare parts, links to repair manuals, estimated product lifetime, software update availability and end-of-support date for connected products.
  • End-of-life information: disassembly instructions, recyclability rate by weight, identification of hazardous materials requiring specialist handling, take-back scheme details.
  • Compliance documentation: reference to the applicable EU regulation and delegated act, EU declaration of conformity, notified body number where conformity assessment was required.

Battery-specific DPP data fields (EU 2023/1542)

For industrial batteries ≥2 kWh and EV batteries, the following fields are required by February 2027:

  • Electrochemical performance: nominal capacity (Ah), nominal voltage, rated energy (Wh), maximum permitted power (W), internal resistance, expected battery lifetime in cycles, State of Health (SoH) thresholds for capacity and power fade.
  • Carbon footprint declaration: total lifecycle carbon footprint in kg CO₂e per kWh of energy content, broken down by lifecycle stage. A carbon footprint performance class (A–E, consistent with EU energy label format) is required for EV batteries from 2027.
  • Recycled content declaration: declared percentage of cobalt, lead, lithium, and nickel derived from post-consumer recycled sources, supported by third-party documentation.
  • Supply chain due diligence: reference to the manufacturer's due diligence policy for critical raw materials (cobalt, lithium, nickel, natural graphite), with audit or certification references aligned to OECD guidance.
  • Hazardous substance declaration: all hazardous substances present above thresholds in Annex XIII of EU 2023/1542, including substance name, CAS number, and concentration.
  • Real-time SoH data (EV batteries): authorised operators — repair workshops, second-life processors, end-of-life handlers — must be able to retrieve current State of Health data via the DPP. This requires a live API endpoint, not just static declared parameters.

4. Data Access Levels

DPP data is not uniformly accessible to all parties. Both ESPR and the Battery Regulation define three access tiers, and companies must implement API controls that enforce this classification:

  • Public (no authentication): basic product identification, sustainability performance class, repairability score and instructions, end-of-life information.
  • Authenticated business access (supply chain actors, recyclers, repair operators): full material composition, substance locations and concentrations, proprietary component data, disassembly sequences.
  • Authority access (market surveillance, customs, enforcement): complete technical documentation, conformity assessment records, test reports. Accessible via EREVS using authority credentials.

Publishing business-sensitive substance data at the public tier, or locking repair information behind authentication, both constitute non-compliance. Getting access classification right from the outset matters.

5. Data Storage, Registry, and API Requirements

The DPP framework uses a decentralised data architecture. Companies are not required to upload all product data to a central EU database:

  • Manufacturers host their own data on their own infrastructure or via a certified third-party platform, provided availability, security, and access requirements are met.
  • The EU DPP Registry (EREVS) stores only the UPI, a pointer to the data access point URL, and compliance metadata — not the full product record. EREVS is the central index; the data stays with the economic operator.
  • API standards: data access points must expose machine-readable, structured APIs. Current Commission guidance points to W3C Verifiable Credentials, GS1 Digital Link resolution standards, and JSON-LD structured data.
  • Data retention: Battery Regulation requires accessibility for ten years after the last unit is placed on the market. ESPR delegated acts are expected to set equivalent or longer periods.
  • Audit trail and integrity: records must be tamper-resistant. Every amendment must be logged with a timestamp and responsible party identifier. The DPP must serve both the current version and the full revision history.
  • Multilingual: DPP data must be available in the official language(s) of each EU member state where the product is sold. Automated translation is permitted for most fields; substance names and safety information require manual verification.

Who Is Responsible?

DPP obligations fall on the economic operator who places the product on the EU market:

  • Manufacturers bear primary responsibility — including manufacturers established outside the EU who export to European markets.
  • Authorised representatives can act on behalf of non-EU manufacturers and assume DPP obligations, provided they are EU-established.
  • Importers must verify a DPP exists and is accessible before placing products on the market. Where the manufacturer has not complied, the importer assumes responsibility.
  • Distributors and online marketplaces must keep the data carrier and DPP link intact throughout the distribution chain. Online marketplaces must display the DPP link on the product listing page.

What Companies Need to Do: Eight Implementation Steps

DPP compliance is primarily a data infrastructure challenge, not a labelling exercise. Most companies need to build or significantly upgrade their product data management systems before they can generate and maintain valid DPPs.

  1. Map your product portfolio against ESPR scope. Identify which categories you manufacture or import, confirm whether a delegated act is in force or pending, and set your compliance timeline. Batteries have a confirmed 2027 deadline; textiles and electronics are close behind.
  2. Conduct a data gap assessment. Identify which required fields you currently hold and which are missing. The largest gaps are typically Scope 3 carbon footprint data, supplier material origin documentation, and certified recycled content figures.
  3. Establish supplier data collection processes. Tier 1 suppliers need to provide material composition, substance declarations, and sourcing documentation. Update contracts, data exchange formats, and questionnaires — and allow suppliers adequate lead time to collect what they need from their own chains.
  4. Assign Unique Product Identifiers. Implement a GS1 Digital Link or equivalent scheme across your range. If you already use GTINs, extending them to GS1 Digital Links requires relatively minor system changes.
  5. Build or procure a DPP data hosting solution. You need a system that stores DPP records, exposes them via a compliant API, enforces access tier controls, logs all amendments, and maintains availability for the required retention period.
  6. Register in EREVS. Once data hosting is operational, register each product's UPI and data access point URL in the EU DPP Registry. EREVS is in pilot phase; the Commission targets production readiness before the Battery Regulation's February 2027 deadline.
  7. Apply data carriers to products. Print or apply the QR code (or alternative carrier) to each product or its packaging. For existing lines this may require packaging redesign; build DPP carrier requirements into all new product development from the outset.
  8. Test and verify end-to-end. Confirm the carrier resolves correctly, the API returns the right payload for each access tier, and records are machine-readable and human-readable in the required languages. Market surveillance authorities in Germany, France, and the Netherlands have indicated active enforcement programmes for Battery Regulation DPPs from 2027.

The Core Challenge: Supply Chain Data Collection

Most companies have reasonable control over their own manufacturing data. The hard part is upstream: collecting verified material origin, substance composition, recycled content, and carbon footprint data from suppliers — often across multiple tiers and geographies with varying levels of digital infrastructure.

A DPP that contains inaccurate or unverifiable data is a compliance liability. Market surveillance authorities can demand verification of any claim, and that data must be traceable to primary sources. Recycled content percentages need third-party documentation. Substance declarations need analytical test results. Carbon footprint figures need calculation methodologies that would survive auditor scrutiny.

The data collection challenge is most acute for multi-tier supply chains where tier 1 suppliers source from manufacturers who may have no digital data systems at all, for complex assembled products where hundreds of components each contribute to substance and material declarations, and for carbon footprint calculations that require activity-based supplier data rather than spend-based estimates. Companies that build structured supply chain sustainability data collection processes now — before delegated acts finalise requirements for their product categories — will have a significant compliance advantage over those who wait.

Frequently Asked Questions

Does the DPP requirement apply to products manufactured outside the EU?

Yes. Any product placed on the EU market must comply regardless of manufacturing location. Non-EU manufacturers must designate an EU-established authorised representative, or their EU importers assume responsibility.

Is a Digital Product Passport the same as an Environmental Product Declaration (EPD)?

No. An EPD is a voluntary, third-party-verified document summarising lifecycle environmental impacts per ISO 14025 / EN 15804. A DPP is a mandatory regulatory record with standardised fields defined by EU law. EPD lifecycle data can feed into a DPP's carbon footprint fields, but a DPP must also include material composition, substance declarations, repairability information, and end-of-life instructions that a standard EPD does not cover.

Can a single QR code serve as both the DPP carrier and a brand QR?

Yes, provided it links to a data access point that returns DPP-compliant structured data. A GS1 Digital Link QR can function as a brand engagement code and a DPP carrier simultaneously, as long as the endpoint serves the required data alongside any commercial content.

What happens when a product's data changes after it has been placed on the market?

DPP records can be updated, but all amendments must be logged in the audit trail. The UPI remains constant; the data access point serves the current version alongside its full revision history. For material reformulations that alter substance declarations, some delegated acts are expected to require re-notification to EREVS.

Can I use a third-party platform to host DPP data?

Yes. The regulation places the compliance obligation on the economic operator, but does not mandate self-hosting. Specialist DPP platform providers are emerging, and some ESG data management platforms are extending their capabilities to support DPP data collection, structuring, and API exposure. The economic operator remains responsible for accuracy and availability regardless of who hosts it.

Build your data infrastructure for product passport compliance

Brightest helps companies collect, structure, and verify product and supply chain data for Digital Product Passports — from material composition and recycled content to supplier carbon footprints