Digital Product Passport

Digital Product Passport

The European Union is introducing the Digital Product Passport (DPP) as a major part of its product sustainability and circular-economy framework. Unlike the GPSR technical file, the DPP is not created by the General Product Safety Regulation. Its main horizontal legal framework is Regulation (EU) 2024/1781, the Ecodesign for Sustainable Products Regulation (ESPR).

The DPP is a structured digital record containing product-specific information that can be accessed electronically through a data carrier, such as a QR code or another machine-readable identifier. Depending on the applicable product-specific rules, it may contain information about product identification, materials, environmental performance, durability, repairability, recycled content, compliance, and end-of-life treatment.

The aim is to improve transparency, traceability, circularity, and regulatory enforcement throughout the product lifecycle. However, a DPP is not yet mandatory for every product sold in the EU. Obligations apply according to product-specific EU legislation and delegated acts adopted under the ESPR.

Prepare for the EU Digital Product Passport

Digital Product Passport requirements are being introduced progressively under the EU Ecodesign for Sustainable Products Regulation (ESPR) and other product-specific legislation. EaseCert helps manufacturers, importers, and online sellers prepare the product data, technical documentation, traceability information, and compliance records needed for upcoming DPP obligations.

  • DPP applicability and product-scope review
  • Product and economic operator identification
  • Materials, composition, and supply-chain data review
  • Technical and compliance documentation assessment
  • Gap analysis for future ESPR and product-specific DPP requirements
  • Preparation of structured data for future Digital Product Passport implementation

Our service is designed to help businesses prepare early, identify missing information, and build a structured compliance file before mandatory DPP requirements apply to their product category.

View DPP Preparation Service

What Is a Digital Product Passport?

A Digital Product Passport is defined under the ESPR as a set of data specific to a product that is accessible electronically through a data carrier.

The passport may be established at model, batch, or individual item level, depending on the applicable product-specific rules. The relevant delegated act determines which information must be included, where the data carrier must appear, who may access the data, and how long the passport must remain available.

The DPP should therefore not be confused with the technical documentation required under the General Product Safety Regulation (GPSR). GPSR technical documentation is primarily used to demonstrate product safety, while a DPP is a broader digital information framework intended to support sustainability, traceability, circularity, market surveillance, and access to product data.

The two systems may overlap. Information already contained in technical documentation or required under other EU legislation may also be incorporated into a DPP where the relevant product-specific rules provide for this.

Which Products Need a Digital Product Passport?

The ESPR establishes the general DPP framework, but it does not mean that every product immediately requires a passport.

For products covered by ESPR, the European Commission adopts product-specific delegated acts setting detailed ecodesign and information requirements. Where such a delegated act requires a DPP, the affected product may only be placed on the EU market or put into service if the required passport is available.

Future DPP requirements may cover a wide range of product groups, particularly products for which sustainability, durability, repairability, recyclability, material composition, or substances of concern are important.

Businesses should therefore assess:

  • Whether their product falls within the scope of ESPR or other DPP legislation.
  • Whether a product-specific delegated act has been adopted.
  • The date from which the DPP obligation becomes applicable.
  • Whether the passport must be created at model, batch, or individual-item level.
  • Which data must be publicly accessible and which information is restricted to authorities or other authorised parties.


Battery Passports From 2027

Batteries are one of the first major product groups for which the EU has established a concrete digital passport requirement.

Under Regulation (EU) 2023/1542 concerning batteries and waste batteries, from 18 February 2027, the following batteries must have an electronic battery passport:

  • Light means of transport (LMT) batteries.
  • Industrial batteries with a capacity greater than 2 kWh.
  • Electric vehicle batteries.

The battery passport is linked to a unique identifier through a QR code and contains information relating to both the battery model and, where applicable, the individual battery.

Information may include technical characteristics, composition, carbon-footprint information, recycled content, performance and durability, state of health, dismantling information, and other data required by the Batteries Regulation.

Access rights differ depending on the information. Some information is publicly accessible, while other data is restricted to authorities, notified bodies, recyclers, repairers, or other parties with a legitimate interest.

Key Components of a Digital Product Passport

The exact contents of a DPP depend on the product category and the applicable delegated act or sector-specific legislation. A passport may include information such as:

  • Product Identification: Product name, model, batch or item identifier, product category, and other information allowing the product to be uniquely identified.
  • Manufacturer and Economic Operator Information: Manufacturer details, importer information, EU responsible economic operator information where applicable, and unique operator identifiers.
  • Materials and Composition: Information on materials, components, substances of concern, recycled content, or other composition data required by the applicable legislation.
  • Environmental Performance: Information relating to environmental impacts, carbon footprint, resource use, energy efficiency, or other sustainability indicators.
  • Durability and Repairability: Expected product lifetime, repair information, spare-parts availability, maintenance requirements, and repairability information where applicable.
  • Recyclability and End-of-Life Information: Recycling instructions, dismantling information, material recovery information, and appropriate end-of-life treatment.
  • Compliance Information: Relevant conformity information, applicable legislation, standards, certificates, or other regulatory data where required.
  • Instructions and Safety Information: User manuals, warnings, and safety information where other EU legislation requires this information to be included.

The specific information required will vary significantly by product category.

How Is the Digital Product Passport Accessed?

Under the ESPR, the DPP is connected to a persistent unique product identifier through a data carrier.

The data carrier may take the form of:

  • A QR code.
  • A two-dimensional symbol.
  • A barcode or another automatic identification technology.
  • Another machine-readable data carrier specified under the applicable product rules.

The relevant product-specific legislation determines whether the data carrier must appear on the product itself, its packaging, or accompanying documentation.

The system is intended to remain interoperable and based on open standards so that authorised users can access and exchange data without being tied to a proprietary platform.

The economic operator responsible for the passport must ensure that required information is accurate, complete, and up to date.

Who Can Access DPP Information?

A Digital Product Passport is not necessarily a fully public database. Different users may receive different access rights.

Depending on the applicable product-specific rules, users may include:

  • Consumers.
  • Manufacturers.
  • Importers and distributors.
  • Online marketplaces and retailers.
  • Repairers.
  • Refurbishers and remanufacturers.
  • Recyclers.
  • Market surveillance authorities.
  • Customs authorities.
  • Other authorised economic operators.

Some data may be available to the general public, while commercially sensitive, technical, enforcement, or detailed composition information may have restricted access.

Personal information relating to customers must not be stored in the DPP without an appropriate legal basis and must comply with EU data-protection requirements.

DPP Registry and EU Web Portal

The ESPR also establishes an EU-level Digital Product Passport infrastructure.

This includes a central DPP registry containing at least the unique identifiers needed to support regulatory controls and enforcement. The Regulation required the European Commission to establish the registry by 19 July 2026.

The Commission is also establishing a publicly accessible web portal that will allow stakeholders to search for and compare DPP information according to their respective access rights.

The registry will also support customs enforcement. For products subject to a DPP requirement, customs authorities will be able to verify relevant registration identifiers when goods are imported into the EU.

Relationship Between the DPP and GPSR Technical Documentation

The GPSR technical file and the Digital Product Passport are two different compliance tools.

Under Article 9 of the GPSR, manufacturers must carry out an internal risk analysis and prepare technical documentation before placing a consumer product on the EU market.

This technical documentation must contain at least:

  • A general description of the product.
  • Essential product characteristics relevant to safety.
  • Where appropriate, an analysis of possible product risks.
  • Measures used to eliminate or mitigate identified risks.
  • Relevant test reports.
  • Applicable European standards or other safety specifications.

The GPSR technical file therefore focuses primarily on demonstrating product safety.

The DPP, by contrast, may include a much broader set of digital information relating to sustainability, environmental characteristics, traceability, circularity, repairability, materials, and regulatory compliance.

Information from the technical file may eventually feed into the DPP where the applicable delegated act requires it, but the DPP does not replace the manufacturer’s obligation to maintain the underlying technical documentation.

Internal Risk Assessment and Product Considerations

Where the product is subject to the GPSR, the foundation of the technical documentation remains an internal risk assessment conducted by the manufacturer.

This analysis evaluates relevant product-safety aspects, including:

  • General Characteristics: The design, technical features, composition, functionality, and other characteristics of the product.
  • Appearance and Presentation: How the product is designed, packaged, labelled, and presented to consumers.
  • Intended Consumer Category: The persons likely to use the product, particularly vulnerable consumers such as children, older persons, or persons with disabilities.
  • Interaction with Other Products: The potential effects when the product is foreseeably used together with other products.
  • Cybersecurity Features: Digital or connected functions where external influences or malicious interference could affect product safety.
  • Evolving Functionalities: Learning, predictive, or evolving functions that may change over time and affect product safety.

This assessment ensures that relevant risks are identified, evaluated, and mitigated before the product is placed on the EU market.

 

Role of the Responsible Person in GPSR Compliance

The GPSR requires products within its scope to have an economic operator established in the EU responsible for the functions set out in Article 16 and Regulation (EU) 2019/1020.

The responsible economic operator depends on the supply-chain structure:

  • EU-Based Manufacturer: Where the manufacturer is established in the EU, the manufacturer is the responsible economic operator.
  • Importer: Where a non-EU manufacturer's product is imported into the EU, the importer may perform the relevant responsible economic operator role.
  • Authorised Representative: An EU-established Authorised Representative may perform the relevant functions where properly appointed by written mandate.
  • Fulfilment Service Provider: In certain circumstances, an EU-established fulfilment service provider may become the responsible economic operator where no other qualifying EU economic operator exists.

The responsible economic operator must have access to the necessary technical documentation, cooperate with market-surveillance authorities, and perform the checks and other tasks required under EU law.

Their name, registered trade name or trademark, postal address, and electronic address must be indicated on the product, packaging, parcel, or accompanying document as permitted by the GPSR.

An Authorised Representative can therefore act as the responsible economic operator where the applicable legal requirements are met and the responsibilities are properly defined in the mandate.

 

Does the Responsible Person Manage the DPP?

Not automatically. The GPSR Responsible Person and the economic operator responsible for creating or maintaining a Digital Product Passport are legally distinct concepts.

Under the ESPR, the economic operator placing the product on the market is responsible for ensuring compliance with the applicable DPP obligations. Product-specific delegated acts may define additional responsibilities relating to creation, updating, hosting, data access, and maintenance of the passport.

Where relevant, the DPP may contain details of the EU economic operator responsible under the applicable product-safety legislation, but this does not make that operator automatically responsible for all DPP data or sustainability obligations.

Implications of Non-Compliance

Failure to comply with applicable GPSR, ESPR, or product-specific DPP requirements can result in regulatory action.

Depending on the violation, consequences may include:

  • Product Recalls: Dangerous or non-compliant products may have to be recalled from consumers.
  • Market Access Restrictions: Authorities may prohibit, restrict, withdraw, or prevent products from being placed on the EU market.
  • Customs Intervention: Products subject to DPP requirements may face customs issues where the required identifiers or passport information are missing or invalid.
  • Online Listing Restrictions: Marketplaces may suspend or remove listings where mandatory compliance information is missing.
  • Fines and Penalties: National authorities may impose financial or other penalties in accordance with applicable Member State law.

The DPP will therefore become an increasingly important element of EU product compliance, but only for products and requirements for which EU legislation specifically mandates it.

 

How Businesses Should Prepare for DPP Requirements

Even where a product is not yet subject to a mandatory Digital Product Passport, manufacturers and importers can prepare by improving the structure and quality of their product data.

Useful preparation steps include:

  • Maintain accurate product and model identification.
  • Keep structured Bills of Materials and material-composition records.
  • Collect supplier and manufacturing-location information.
  • Maintain current technical documentation and test reports.
  • Document substances of concern and restricted substances.
  • Maintain information on recycled content where relevant.
  • Collect durability, repairability, spare-parts, and end-of-life information.
  • Create consistent identifiers across technical files, ERP systems, packaging, labels, and online listings.
  • Monitor ESPR delegated acts affecting your specific product category.
  • Determine whether sector-specific legislation already introduces a passport requirement.

Businesses with structured product data will generally be better prepared as DPP requirements expand to additional product groups.

Conclusion

The Digital Product Passport represents a major change in how product information will be managed and exchanged across the European market. However, it is important to distinguish it from the General Product Safety Regulation.

The GPSR requires product-safety risk assessments and technical documentation, while the ESPR establishes the main framework for Digital Product Passports. Product-specific delegated acts and other EU legislation determine when a DPP becomes mandatory and what information it must contain.

For businesses selling in the EU, the practical approach is to maintain robust technical documentation today while preparing product, material, sustainability, traceability, and supply-chain data for future DPP requirements.

 

Get Expert Guidance on EU Product Compliance

At EaseCert, we help businesses understand and meet EU product-compliance requirements, including GPSR technical documentation, risk assessments, labeling, EU Responsible Person requirements, and related market-access obligations.

Our GPSR risk assessment template provides a practical framework for evaluating product-safety risks and documenting risk-control measures.

As Digital Product Passport requirements expand under the ESPR and other EU legislation, businesses should also prepare structured product and supply-chain data that can support future DPP obligations.

Contact us for guidance on regulatory obligations, technical documentation, risk assessments, Responsible Person services, and EU product compliance solutions.


Official Sources and Further Reading:

Show more insights

Get in Touch with EaseCert