EU Digital Product Passport: Registry, QR Codes and Timelines

EU Digital Product Passport: Registry, QR Codes and Timelines

The EU Digital Product Passport Registry Is Now Operational: What Manufacturers Need to Know

The European Commission has made the EU Digital Product Passport Registry operational, marking a significant step in the implementation of the Digital Product Passport framework.

The Registry became operational on 20 July 2026. It provides the central EU infrastructure through which economic operators will register Digital Product Passports for products covered by applicable EU legislation.

This development does not mean that every product placed on the EU market must immediately have a Digital Product Passport. It also does not mean that businesses must register every voluntary QR code, sustainability page or product-information database they currently use.

The legal obligation will apply progressively. A product must have a Digital Product Passport and be registered when the relevant product-specific delegated act or other applicable EU legislation requires it.

Businesses should nevertheless understand the system now. The Registry is operational, technical standards are being introduced, and the first mandatory Digital Product Passports will apply to certain batteries from 18 February 2027.

This article explains:

  • what a Digital Product Passport is;
  • what the DPP Registry does;
  • how registration differs from creating a QR code;
  • which businesses may be responsible;
  • what information will be registered;
  • how customs and market surveillance authorities will use the system;
  • which product groups are expected to be covered;
  • when the requirements are expected to apply;
  • what manufacturers, importers and other economic operators should do now.

Prepare for ESPR and Digital Product Passport Requirements

EaseCert helps manufacturers, importers, private-label brands, distributors and online sellers prepare for the EU Ecodesign for Sustainable Products Regulation and future Digital Product Passport requirements.

Our ESPR Compliance and Digital Product Passport Preparation Service is designed to improve product documentation, supplier transparency, sustainability data management and traceability readiness before the relevant product-specific requirements become mandatory.

What the service includes

  • Review of whether your products may fall within current or future ESPR priority product groups.
  • Guidance on preparing product-level information and structured data for future DPP requirements.
  • Review of bills of materials, supplier declarations, technical specifications, test reports, Safety Data Sheets and traceability records.
  • Support organising information on material composition, recycled content, durability, repairability, recycling and supply-chain transparency.
  • Identification of missing or incomplete documentation that may affect future ESPR or DPP readiness.
  • Guidance for coordinating compliance, sustainability, procurement, product development and IT teams.
  • Support aligning existing GPSR documentation, labelling and traceability records with future ESPR preparation.

The service is consultative and preparatory. Many detailed ESPR obligations will only become applicable after the European Commission adopts product-specific delegated acts. EaseCert helps businesses organise the available information, identify documentation gaps and build a practical foundation for future compliance.

One-time service fee: €500. The typical turnaround time is approximately five working days after receipt of the required product information and documentation.

View the ESPR and DPP Preparation Service

What Is a Digital Product Passport?

A Digital Product Passport, commonly referred to as a DPP, is a digital record associated with a product, component or material.

The European Commission describes the DPP as a digital identity card that provides access to relevant product information throughout the product lifecycle.

Depending on the applicable product legislation, the passport may contain information concerning:

  • product identification;
  • the manufacturer and other responsible economic operators;
  • materials and components;
  • substances of concern;
  • environmental performance;
  • durability;
  • repairability;
  • maintenance;
  • spare parts;
  • reuse;
  • remanufacturing;
  • recycling;
  • safe handling;
  • regulatory compliance;
  • conformity documentation;
  • product safety;
  • product origin.

The precise information will not be identical for every product. Product-specific requirements will be established through delegated acts adopted under the Ecodesign for Sustainable Products Regulation or through other EU legislation requiring a DPP.

The DPP is intended to make reliable product information available in a standardised digital format to different users, including:

  • consumers;
  • manufacturers;
  • importers;
  • distributors;
  • authorised representatives;
  • repairers;
  • refurbishers;
  • remanufacturers;
  • recyclers;
  • customs authorities;
  • market surveillance authorities;
  • other public authorities.

The legal basis for the general DPP framework is Regulation (EU) 2024/1781 establishing a framework for setting ecodesign requirements for sustainable products, commonly known as the Ecodesign for Sustainable Products Regulation or ESPR.

The DPP Is More Than a QR Code

A common misunderstanding is that adding a QR code to a product automatically creates a compliant Digital Product Passport.

A QR code may serve as the data carrier that connects a physical product to its DPP. However, the QR code is only one part of the system.

A compliant DPP framework contains several distinct elements:

1. The physical product

The product, its packaging or accompanying documentation carries a data carrier, such as a QR code.

2. The data carrier

The data carrier provides digital access to the relevant passport.

3. The unique product identifier

The product, model, batch or individual item is identified using the identification level required by the applicable legislation.

4. The Digital Product Passport

The DPP contains or provides controlled access to the required product information.

5. The data-storage system

The detailed DPP information remains stored by the economic operator or by a DPP service provider.

6. The EU DPP Registry

The Registry stores the relevant identifiers, registration data and required high-level metadata.

7. The Unique Registration Identifier

Once the DPP is registered, the Registry generates a Unique Registration Identifier associated with the registered passport.

A business may therefore have a product webpage accessible through a QR code without having a legally compliant DPP. Compliance depends on whether the complete system meets the applicable legal requirements for data content, identifiers, access rights, interoperability, storage, availability and registration.

The European Commission explains that the economic operator first gathers the legally required product information. The DPP is then created and registered, while the complete product information remains stored by the economic operator or its DPP service provider. A digital data carrier, such as a QR code, connects the physical product to the passport.

What Is the EU Digital Product Passport Registry?

The DPP Registry is the central EU database supporting the Digital Product Passport system.

It acts as an indexing service for DPPs relating to products placed on the EU market.

The Registry does not generally replace the passport itself and does not ordinarily store the complete body of detailed product information. Instead, it stores information needed to identify, register, locate and verify the DPP.

According to the European Commission, the Registry will store:

  • unique product identifiers;
  • DPP registration information;
  • required high-level metadata;
  • other information required under the applicable delegated act or EU legislation.

The DPP itself follows a decentralised architecture. The detailed product data remains under the responsibility of the relevant economic operator. The operator may host the information directly or use a DPP service provider.

The Registry therefore provides a common EU-level index, while the product information can be stored in decentralised systems.

Why Has the Registry Been Created?

A decentralised DPP system needs a reliable way to identify and verify passports across the EU.

Without a central registry, authorities could face difficulties determining:

  • whether a passport has been validly created;
  • which economic operator registered it;
  • whether the relevant product identifier is authentic;
  • where the passport information is stored;
  • whether an imported product has been registered before customs clearance;
  • whether an identifier has already been used;
  • whether the DPP remains accessible;
  • whether registration information has been updated.

The Registry provides a central reference point for these functions.

It is intended to support:

  • consistent DPP registration;
  • verification of economic operators;
  • reliable product identification;
  • interoperability between systems;
  • customs controls;
  • market surveillance;
  • access management;
  • secure logging;
  • structured data exchange;
  • proof of registration.

The Registry’s practical arrangements are governed by the Commission Implementing Regulation concerning the Digital Product Passport Registry.

Does Every DPP Have to Be Registered?

Where an applicable EU legal act requires a Digital Product Passport, the passport must be registered in the DPP Registry in accordance with that legislation.

Registration is therefore a separate compliance step. Creating the product information and attaching a QR code is not sufficient by itself.

However, the Registry becoming operational does not impose an immediate DPP obligation on all products.

A mandatory DPP requirement must arise from:

  • a product-specific delegated act adopted under the ESPR; or
  • another EU regulation or legal act that directly requires a DPP.

Until the relevant product legislation applies, a company may choose to create a voluntary digital product-information system. That voluntary system does not automatically have to be registered solely because the Registry is available.

The distinction is important:

Registry availability means the EU infrastructure is operational.

Legal applicability means a specific product is covered by a binding DPP requirement.

The applicable delegated act or sectoral legislation will determine:

  • which products are covered;
  • when the requirement begins;
  • who must register the passport;
  • the required identification level;
  • the required data fields;
  • where the data carrier must appear;
  • which information must be public;
  • which information may be restricted;
  • how long the data must remain available;
  • whether any exemptions apply.

When Must Registration Be Completed?

Where a mandatory DPP applies, registration must generally be completed before the product is placed on the EU market.

The European Commission states that relevant economic operators must register the DPP in accordance with the applicable legislation before the product is placed on the market.

This applies to:

  • products manufactured in the EU; and
  • imported products entering the EU market.

For imported products, customs authorities may verify registration before the products are released for free circulation.

This means DPP registration should be treated as a pre-market compliance requirement rather than a post-sale administrative formality.

How the Registration Process Works

The detailed process will depend on the product legislation and the final Registry functionality, but the European Commission describes the general DPP process as follows.

Step 1: Determine whether the product is covered

The economic operator must establish whether the product is subject to a mandatory DPP requirement.

This assessment requires identifying:

  • the product category;
  • the applicable EU legislation;
  • the relevant delegated act;
  • the compliance date;
  • any transitional provisions;
  • any exclusions or exemptions.

Businesses should not assume that a DPP requirement applies merely because their product falls within a broad sector named in the ESPR working programme.

For example, identifying textiles as a priority product group does not by itself establish the final data requirements, compliance date or scope. Those details will be established through the relevant delegated act.

Step 2: Determine the responsible economic operator

The applicable legislation will determine who must create and register the passport.

Depending on the supply chain and legal framework, the responsible party may be:

  • the EU manufacturer;
  • the non-EU manufacturer;
  • an importer;
  • an authorised representative;
  • another economic operator designated under the applicable legislation.

Businesses should establish responsibility contractually and operationally. The party creating the QR code, operating the website or supplying product data is not necessarily the party that bears the legal registration obligation.

Step 3: Gather the required product information

The economic operator must collect the information required by the applicable EU legislation.

This may require coordination across:

  • product development;
  • sourcing;
  • purchasing;
  • quality assurance;
  • sustainability;
  • regulatory compliance;
  • product safety;
  • information technology;
  • logistics;
  • customs;
  • legal;
  • after-sales support;
  • recycling and end-of-life operations.

Product data may need to be obtained from multiple tiers of the supply chain. A finished-product manufacturer may depend on material suppliers, component manufacturers, testing laboratories and factories for the underlying information.

Step 4: Establish the required identifier

The relevant legislation will determine the level at which a passport must be created.

Possible identification levels may include:

  • product model;
  • product type;
  • batch;
  • production lot;
  • individual item;
  • component;
  • material.

This distinction has major operational consequences.

A passport at model level may allow multiple units to share the same DPP. A passport at batch or item level may require substantially more identifiers, data-management capacity and registration activity.

Businesses should therefore avoid designing systems around a single identification assumption before the relevant delegated act is adopted.

Step 5: Create the DPP

The passport must be created in the required structure and format.

The information must be capable of being accessed, exchanged and interpreted in accordance with the applicable technical rules.

A consumer-facing webpage may form part of the user experience, but the underlying system may also need to support:

  • machine-readable data;
  • standardised vocabulary;
  • structured fields;
  • application programming interfaces;
  • role-based access;
  • data exchange between systems;
  • persistent identifiers;
  • long-term availability;
  • technical interoperability.

Step 6: Register the DPP

The economic operator registers the DPP in the EU Registry.

The Commission provides two principal routes:

  • a secure user interface; and
  • an application programming interface, or API.

The user interface may be suitable for manual registration and lower registration volumes.

An API may be more appropriate for businesses placing large numbers of products, models, batches or individually identified items on the EU market.

The Registry currently includes both a live environment and a separate testing environment. The testing environment allows businesses to explore enrolment and registration workflows without affecting live data or real processes.

Step 7: Receive the Unique Registration Identifier

After successful registration, the Registry generates a Unique Registration Identifier.

The Commission refers to this identifier as a URI. In this context, the URI is generated by the Registry following registration and can be used in the verification process.

For imported goods, customs authorities may check the identifier and associated registration data.

Step 8: Apply or connect the data carrier

A data carrier, such as a QR code, must provide access to the DPP.

The final placement requirements will depend on the applicable legislation. The data carrier may need to appear:

  • on the product;
  • on a label;
  • on the packaging;
  • in accompanying documentation;
  • at more than one location.

The applicable rules may also specify requirements concerning:

  • visibility;
  • legibility;
  • accessibility;
  • durability;
  • minimum size;
  • link persistence;
  • proximity to other markings;
  • digital accessibility.

Step 9: Maintain the passport

DPP compliance does not end after registration.

The responsible operator may need to ensure that:

  • the data remains accurate;
  • required updates are made;
  • the passport remains accessible;
  • links continue to function;
  • identifiers remain connected to the correct product;
  • access permissions remain appropriate;
  • obsolete records are handled correctly;
  • information remains available for the required retention period;
  • changes in product design or materials are reflected where necessary.

What Information Does the Registry Store?

The Registry is not intended to function as the sole database containing all product information.

The European Commission describes it as a secure database storing:

  • unique identifiers;
  • registration data;
  • high-level metadata;
  • other information required by the relevant legislation.

The complete DPP information remains stored by the economic operator or a DPP service provider.

This distinction allows the EU to maintain a central verification and indexing system without requiring every detailed passport record to be hosted in one central database.

The applicable delegated acts or other EU legislation may nevertheless require additional information to be registered for particular product groups.

What Is Registration Metadata?

Registration metadata is structured information describing the DPP and its relationship to the product and responsible operator.

The exact fields will depend on the applicable legal act. They may include information necessary to identify:

  • the product;
  • the product identifier;
  • the passport;
  • the responsible economic operator;
  • the relevant commodity code;
  • the location of the detailed passport information;
  • the applicable product category;
  • the registration status;
  • the date of registration;
  • changes to the registration.

Businesses should distinguish between:

Passport content, which consists of the substantive product information available through the DPP.

Registration metadata, which enables the Registry and authorities to identify, locate, validate and manage the passport.

Organisation Enrolment and User Verification

Before registering DPPs, an economic operator may need to enrol its organisation in the Registry.

The Commission’s Registry resources include functionality and guidance for:

  • enrolling an organisation;
  • registering DPPs;
  • managing registered DPPs.

The implementing framework also addresses user verification and access management.

This is important because the Registry must be able to establish that a user has authority to act for the relevant organisation.

Businesses should consider in advance:

  • which legal entity will enrol;
  • which personnel will administer the account;
  • who may register or amend DPPs;
  • how access will be controlled;
  • how personnel changes will be managed;
  • whether external providers will receive access;
  • how responsibilities will be documented;
  • who will retain evidence of registration.

The European Commission has published a dedicated DPP Registry page with access to the live Registry, testing environment, user guide and helpdesk.

Manual Registration and API Integration

The Registry permits registration through a user interface or API.

User interface

Manual registration may be suitable for:

  • small product portfolios;
  • pilot projects;
  • low-volume manufacturers;
  • initial testing;
  • occasional registrations;
  • organisations without integrated product-information systems.

However, manual registration may become difficult where a company has:

  • thousands of SKUs;
  • frequent seasonal product changes;
  • individual-item passports;
  • multiple manufacturing locations;
  • high-volume imports;
  • extensive batch-level data;
  • several legal entities.

API registration

API integration may allow economic operators to connect the Registry with existing systems, such as:

  • product lifecycle management systems;
  • enterprise resource planning systems;
  • product information management systems;
  • compliance databases;
  • master-data platforms;
  • supplier portals;
  • traceability systems;
  • DPP service-provider platforms.

API integration can reduce repetitive manual work, but it requires reliable master data, governance, validation and error handling.

Automating the submission of inaccurate data does not resolve compliance problems. Businesses must first establish reliable data ownership and verification processes.

Proof of Registration

The Registry framework allows economic operators to request proof of registration in the form of a secure electronic document.

Proof of registration may be useful in:

  • business-to-business transactions;
  • supplier qualification;
  • retailer onboarding;
  • marketplace compliance checks;
  • customs documentation;
  • internal audits;
  • regulatory inspections;
  • contractual compliance;
  • customer due diligence.

Proof of registration does not necessarily prove that every item of information in the DPP is accurate or that the product complies with all applicable EU legislation.

It demonstrates that the DPP has been registered in accordance with the Registry process. Product compliance still depends on the underlying product, documentation, data and conformity assessment.

Customs Controls

The DPP Registry is designed to support customs enforcement for imported products.

Customs authorities may use the Registry to verify electronically that:

  • an imported product has a registered DPP;
  • the registration is valid;
  • the relevant unique identifier is present;
  • the required commodity code has been provided;
  • the passport can be located.

The Commission states that, once registered, the Unique Registration Identifier may be checked at customs.

This makes product classification and customs data an important part of DPP preparation.

Manufacturers and importers should ensure consistency between:

  • customs declarations;
  • commodity codes;
  • product identifiers;
  • commercial invoices;
  • shipping documentation;
  • DPP records;
  • Registry submissions.

Conflicting identifiers or classifications may create delays, verification failures or enforcement questions.

Market Surveillance

The Registry will also support market surveillance authorities.

Authorities may use registered information to:

  • identify the responsible economic operator;
  • locate the DPP;
  • verify product registration;
  • review legally required product information;
  • investigate non-compliant products;
  • compare market information with registration records;
  • support coordinated enforcement.

The DPP does not replace existing product compliance obligations.

Products may remain subject to requirements concerning:

  • safety assessments;
  • risk analyses;
  • technical documentation;
  • declarations of conformity;
  • testing;
  • CE marking;
  • traceability;
  • warnings;
  • instructions;
  • responsible economic operators;
  • market surveillance cooperation.

The DPP may provide a structured method of accessing some of this information, but businesses must still comply with the underlying product legislation.

Public and Restricted Information

Not every DPP user will necessarily have access to the same information.

Different access levels may apply to:

  • consumers;
  • commercial partners;
  • repairers;
  • recyclers;
  • customs authorities;
  • market surveillance authorities;
  • other public bodies.

For example, consumer-facing information may include product composition, repair or recycling instructions, while authorities may have access to regulatory information not intended for general publication.

The applicable legislation will determine:

  • which information must be publicly accessible;
  • which information is restricted;
  • which roles may access restricted data;
  • whether authentication is required;
  • how access rights must be managed.

Businesses should therefore avoid building DPP systems that assume every data point will be displayed on one public webpage.

The Role of DPP Service Providers

Economic operators may store and manage DPP data themselves or use an external DPP service provider.

A provider may support:

  • passport creation;
  • data hosting;
  • QR code generation;
  • identifier management;
  • API integration;
  • Registry registration;
  • user-access management;
  • data validation;
  • system maintenance;
  • long-term availability.

However, outsourcing the technical platform does not automatically transfer legal responsibility.

Businesses should establish:

  • who is legally responsible for the DPP;
  • who registers it;
  • who validates the data;
  • where the data is stored;
  • how long it will remain accessible;
  • how information will be transferred if the contract ends;
  • how system failure will be handled;
  • who updates product records;
  • who manages corrections;
  • who maintains audit evidence;
  • how data portability is ensured.

The Commission’s indicative timeline refers to additional delegated acts concerning DPP service providers. Businesses should monitor these developments before finalising long-term provider arrangements.

Harmonised Standards for the DPP

Technical interoperability is essential to the DPP system.

A passport must be capable of functioning across:

  • different product groups;
  • different software platforms;
  • different Member States;
  • different supply-chain participants;
  • customs systems;
  • regulatory systems;
  • consumer devices;
  • repair and recycling environments.

The European Commission has published an official page concerning harmonised standards for the Digital Product Passport.

The page identifies Commission Implementing Decision (EU) 2026/1736 of 14 July 2026 concerning harmonised standards drafted in support of Regulation (EU) 2024/1781.

The DPP standards framework covers technical areas including:

  • unique identifiers;
  • data carriers;
  • interoperability;
  • application programming interfaces;
  • data exchange protocols;
  • data storage.

The Commission’s indicative timeline states that an implementing decision covering six DPP standards was adopted in July 2026, with a further implementing decision concerning the remaining two standards indicated for September 2026.

Why Interoperability Matters

A DPP must be more than a static webpage created by one supplier.

The system is intended to allow information to be exchanged and understood across different platforms and users.

Interoperability helps ensure that:

  • identifiers are structured consistently;
  • QR codes and other carriers can be interpreted reliably;
  • data can move between systems;
  • authorities can retrieve required information;
  • repairers and recyclers can access relevant data;
  • businesses are not locked into incompatible proprietary systems;
  • product data remains useful throughout the product lifecycle.

A proprietary DPP platform may offer a polished consumer interface but still require substantial modification if it does not support the applicable EU standards and technical architecture.

Which Products Will Require a DPP?

The DPP will be introduced progressively.

The European Commission identifies two main legal routes.

Product-specific delegated acts under the ESPR

The Commission’s current indicative schedule includes:

  • iron and steel;
  • energy-related products;
  • textiles;
  • tyres;
  • aluminium;
  • furniture;
  • mattresses;
  • ICT products.

The Commission currently indicates:

  • iron and steel requirements in 2026;
  • textiles, tyres and aluminium delegated acts in 2027;
  • furniture in 2028;
  • mattresses and certain further requirements in 2029.

These dates concern the anticipated adoption of product-specific rules, not necessarily the immediate date on which every operator must comply.

The Commission states that, after adoption of ESPR delegated acts, economic operators will generally receive a transition period of at least 18 months.

DPP requirements under other EU legislation

Digital Product Passports may also be required through separate legislation.

The Commission identifies examples including:

  • the Batteries Regulation;
  • the Packaging and Packaging Waste Regulation;
  • the Critical Raw Materials Act;
  • EU toy-safety legislation;
  • the Construction Products Regulation;
  • legislation concerning detergents and surfactants.

The timing, scope and content requirements must be determined from the applicable sector-specific legislation.

Batteries Are the First Mandatory Product Group

Certain batteries will be the first product group for which the DPP becomes mandatory.

The European Commission identifies 18 February 2027 as the first implementation deadline for certain battery categories, including:

  • electric-vehicle batteries;
  • light-means-of-transport batteries;
  • certain industrial batteries.

This deadline does not establish a universal DPP requirement for every consumer product.

Businesses should not apply the battery deadline automatically to textiles, furniture, toys or other product categories.

Each category must be assessed under its own applicable legal framework.

Textiles and Apparel

Textile apparel is identified as a priority product group under the ESPR.

The Commission’s indicative timeline anticipates the adoption of sector-specific DPP requirements for textiles in Q3 or Q4 of 2027.

The final delegated act will need to establish matters including:

  • the products within scope;
  • relevant tariff or product classifications;
  • applicable exemptions;
  • passport data requirements;
  • the required identification level;
  • data-carrier placement;
  • access rights;
  • data-retention requirements;
  • implementation dates;
  • transitional periods.

The Commission states that economic operators will have a transition period of at least 18 months after ESPR delegated acts are adopted.

Businesses in the textile, clothing, leather and footwear sectors can prepare now, but should not present anticipated requirements as final until the delegated act is adopted.

Does a Voluntary DPP Need to Be Registered?

A business may introduce a voluntary digital product-information system before a mandatory DPP requirement applies.

For example, a company may voluntarily use QR codes to provide:

  • care instructions;
  • material information;
  • sustainability information;
  • repair guidance;
  • recycling instructions;
  • supply-chain details;
  • authentication information.

Whether such a voluntary system can or should be registered depends on the Registry rules and whether the relevant product falls within an applicable legal requirement.

The fact that a company describes its system as a “Digital Product Passport” does not necessarily make it a DPP governed by a binding EU requirement.

Businesses should clearly distinguish between:

  • a voluntary product-information initiative;
  • a pilot designed in preparation for future DPP requirements;
  • a legally mandatory DPP established under applicable Union legislation.

Voluntary preparation can be valuable, but businesses should avoid making unsupported compliance claims.

The Registry Does Not Make Every Product Immediately Subject to the ESPR

The ESPR is a framework regulation.

It creates the legal structure through which detailed ecodesign and DPP requirements can be established for specific product groups.

Many of the practical obligations will arise only after product-specific delegated acts have been adopted.

The operation of the Registry should therefore not be interpreted as meaning that:

  • all products now require a DPP;
  • all products require a QR code;
  • every existing SKU must be registered;
  • all voluntary product pages must be entered in the Registry;
  • the same data requirements apply to every sector;
  • the same compliance date applies to every product.

The correct analysis must always begin with the applicable product legislation.

Preparing for the DPP: Practical Steps for Businesses

Although many product-specific requirements are still being developed, businesses can take practical preparatory measures.

1. Map the product portfolio

Create a structured list of products placed on the EU market.

Include:

  • product name;
  • SKU;
  • model number;
  • product category;
  • material composition;
  • manufacturing location;
  • supplier;
  • relevant EU legislation;
  • customs classification;
  • existing identifiers;
  • existing compliance documentation.

2. Identify likely priority categories

Compare the portfolio with the product groups identified in the Commission’s DPP timeline.

Products in early priority sectors may require earlier preparation.

3. Review current product identifiers

Determine which identifiers are currently used at:

  • model level;
  • SKU level;
  • batch level;
  • lot level;
  • individual-item level.

Assess whether identifiers are unique, persistent and consistent across systems.

4. Review QR-code architecture

Where QR codes are already used, establish:

  • who controls the destination;
  • whether the URL is permanent;
  • whether links can be updated;
  • whether redirects are controlled;
  • whether each code is uniquely linked to the correct product;
  • whether the data can remain accessible after a supplier contract ends;
  • whether the system supports structured and machine-readable information.

5. Conduct a product-data gap analysis

Review whether the business can reliably obtain information concerning:

  • materials;
  • components;
  • substances;
  • recycled content;
  • manufacturing origin;
  • durability;
  • repairability;
  • environmental characteristics;
  • maintenance;
  • end-of-life treatment;
  • conformity documentation.

6. Engage suppliers

Update supplier questionnaires and technical-documentation requirements.

Suppliers may need to provide structured data rather than unverified sustainability statements.

Contractual provisions should address:

  • data accuracy;
  • update obligations;
  • evidence;
  • document retention;
  • change notification;
  • audit rights;
  • responsibility for incorrect information.

7. Establish data governance

Assign ownership for each data field.

For example:

  • regulatory compliance may own applicable legislation;
  • quality assurance may own test and inspection data;
  • sourcing may own supplier information;
  • sustainability may own environmental data;
  • product development may own materials and design specifications;
  • IT may own integration and availability;
  • legal may own contractual governance.

8. Test the Registry environment

The Commission provides a separate DPP Registry testing environment.

Businesses can use it to understand:

  • organisation enrolment;
  • account management;
  • registration workflows;
  • DPP management;
  • expected technical processes.

Testing should not be confused with mandatory live registration.

9. Assess manual and automated registration needs

Estimate the likely number of passports and registrations.

This will help determine whether manual registration is realistic or API integration will be required.

10. Review service providers carefully

Do not assess providers solely on their ability to create attractive QR-code pages.

Review whether they can support:

  • EU identifiers;
  • Registry integration;
  • applicable standards;
  • machine-readable data;
  • role-based access;
  • data portability;
  • long-term availability;
  • evidence and audit trails;
  • transfer to another provider.

11. Monitor official EU developments

The Commission’s DPP timeline is expressly described as indicative.

Businesses should monitor:

  • new delegated acts;
  • implementing acts;
  • standards;
  • sector guidance;
  • Registry updates;
  • transition periods;
  • final compliance dates.

Common DPP Compliance Mistakes

Treating the QR code as the complete passport

A QR code is a data carrier, not the full compliance system.

Registering without confirming legal scope

Registration should be based on the applicable product legislation, not on a general assumption that every product is covered.

Using marketing claims instead of verified data

DPP information must be reliable and supported by evidence.

Assuming one passport structure will work for all products

Different delegated acts may require different data and identification levels.

Ignoring product changes

Changes to materials, suppliers, construction or regulatory status may require updates to the DPP.

Depending entirely on a proprietary provider

Businesses should maintain access to their data and plan for provider failure, termination or migration.

Failing to connect customs and regulatory data

Product identifiers, commodity codes and Registry information should be consistent.

Publishing confidential information to everyone

DPP systems may require differentiated access rights rather than unrestricted public access.

Waiting until the compliance date

Collecting reliable supply-chain data and integrating systems may require substantial preparation.

What the Registry Launch Means in Practice

The launch of the DPP Registry is an important operational milestone, but it should be interpreted carefully.

It means:

  • the EU-level registration infrastructure is operational;
  • organisations can access the live Registry;
  • a testing environment is available;
  • economic operators can begin learning the registration process;
  • technical and organisational preparations can advance;
  • the EU is moving from policy design toward practical implementation.

It does not mean:

  • every product already requires a DPP;
  • every QR code must be registered;
  • all voluntary DPP projects are subject to immediate registration;
  • final rules exist for every product group;
  • businesses should register products without checking the applicable legislation.

Frequently Asked Questions

What is a Digital Product Passport?

A Digital Product Passport, or DPP, is a digital record linked to a product, component or material. It provides access to information such as product identification, materials, substances of concern, durability, repairability, recycling instructions, regulatory compliance and responsible economic operators. The exact content depends on the applicable EU legislation for the product category.

Is a Digital Product Passport the same as a QR code?

No. A QR code is only a data carrier that provides access to the Digital Product Passport. A compliant DPP may also require a unique product identifier, structured product data, defined access rights, long-term data availability, interoperability with other systems and registration in the EU DPP Registry.

What is the EU Digital Product Passport Registry?

The DPP Registry is the central EU database used to register and verify Digital Product Passports. It stores unique identifiers, registration information and required metadata. The complete product information generally remains stored by the economic operator or its DPP service provider.

Does every product placed on the EU market already require a DPP?

No. The Digital Product Passport will be introduced progressively. A mandatory DPP applies only when a product-specific delegated act under the Ecodesign for Sustainable Products Regulation or another EU legal act requires one.

Does the launch of the DPP Registry make registration mandatory for all products?

No. The Registry becoming operational means that the EU technical infrastructure is available. It does not make every product immediately subject to a DPP or registration requirement. Businesses must first confirm whether the applicable product legislation requires a DPP.

Must a DPP be registered separately from the QR code?

Yes, where the applicable EU legislation requires a Digital Product Passport. Creating the product information and placing a QR code on the product does not by itself complete the registration requirement. The relevant economic operator must also register the DPP in the EU Registry.

When must a mandatory DPP be registered?

Where a DPP is legally required, registration must generally be completed before the product is placed on the EU market. For imported products, customs authorities may verify the registration before releasing the goods for free circulation.

Who is responsible for creating and registering the DPP?

The responsible party will be determined by the applicable EU legislation. Depending on the product and supply chain, responsibility may fall on the manufacturer, importer, authorised representative or another designated economic operator.

Can a DPP service provider register the passport?

A service provider may support DPP creation, hosting, identifier management, Registry integration and registration. However, using a service provider does not automatically transfer the legal responsibility of the economic operator. Responsibilities should be clearly defined in the service agreement.

What information is stored in the DPP Registry?

The Registry stores unique identifiers, registration data, required high-level metadata and any additional information required by the relevant product legislation. The full DPP content generally remains stored in a decentralised system managed by the economic operator or a service provider.

What is registration metadata?

Registration metadata is structured information used to identify and verify the passport. It may include the product identifier, responsible economic operator, product category, commodity code, location of the detailed DPP data, registration date and registration status.

What is a Unique Registration Identifier?

After a DPP is successfully registered, the Registry generates a Unique Registration Identifier. This identifier connects the registered passport to the relevant Registry record and may be used by customs and other authorities for verification.

Can businesses register DPPs manually?

Yes. The Registry supports registration through a secure user interface. This may be suitable for smaller product portfolios, pilot projects and businesses with a limited number of registrations.

Can DPP registration be automated?

Yes. The Registry also supports registration through an application programming interface, or API. API integration may be more suitable for companies with large product portfolios, frequent product changes, batch-level passports or individually identified products.

Is there a testing environment for the DPP Registry?

Yes. The European Commission provides a separate testing environment. Businesses can use it to practise organisation enrolment, understand registration workflows and assess technical integration without creating live registration records.

Can a business obtain proof of DPP registration?

Yes. The Registry framework allows an economic operator to request proof of registration in the form of a secure electronic document. This may be useful for business-to-business transactions, retailer onboarding, customs checks, audits and regulatory inspections.

Does proof of registration prove that the product is fully compliant?

No. Proof of registration confirms that the DPP was registered. It does not by itself prove that every item of product information is accurate or that the product complies with all applicable safety, environmental, testing, documentation and conformity-assessment requirements.

How will customs authorities use the DPP Registry?

Customs authorities may use the Registry to verify whether an imported product has a registered DPP, whether the registration is valid and whether the relevant product identifiers and commodity codes match the customs declaration.

Does the DPP replace technical documentation or a Declaration of Conformity?

No. The DPP does not replace existing EU compliance obligations. Products may still require technical documentation, risk assessments, testing, declarations of conformity, CE marking, traceability information, warnings and instructions under the applicable product legislation.

Will all DPP information be publicly available?

Not necessarily. Different access levels may apply to consumers, commercial partners, repairers, recyclers, customs authorities and market surveillance authorities. The applicable product legislation will determine which information must be public and which information may be restricted.

Which products will require a Digital Product Passport?

The DPP will be introduced progressively through product-specific delegated acts under the ESPR and through other EU legislation. Priority product groups include iron and steel, textiles, tyres, aluminium, furniture, mattresses, ICT products and certain energy-related products.

When will textiles require a DPP?

The European Commission’s indicative timeline anticipates the adoption of product-specific requirements for textiles in 2027. The final delegated act will establish the exact scope, data requirements, identification level, transitional period and compliance date.

Do all batteries require a DPP from February 2027?

No. The first implementation deadline of 18 February 2027 applies to specific battery categories identified under the EU Batteries Regulation, including certain electric-vehicle, light-means-of-transport and industrial batteries. It does not apply automatically to every battery or every consumer product.

Does a voluntary product-information page need to be registered?

Not automatically. A company may voluntarily use a QR code to provide care instructions, material information, sustainability information or recycling guidance. Registration becomes legally required when the product is covered by an applicable EU rule requiring a DPP.

Can a voluntary QR-code system be called a Digital Product Passport?

A company may use the term for a voluntary initiative, but it should avoid suggesting that the system is legally compliant unless it meets the applicable EU requirements. A customer-facing webpage alone may not satisfy future DPP rules on identifiers, data structure, interoperability, access rights and Registry registration.

What should manufacturers do now?

Manufacturers should map their EU product portfolio, review product identifiers, assess existing QR-code systems, identify product-data gaps, engage suppliers, establish data ownership and monitor the adoption of product-specific EU rules.

Should businesses already test the EU Registry?

Testing may be useful, particularly for businesses in priority product sectors or those planning large-scale DPP systems. However, using the testing environment should not be confused with mandatory live registration.

What should businesses check when selecting a DPP service provider?

Businesses should assess whether the provider supports EU identifiers, Registry integration, applicable standards, machine-readable data, role-based access, data portability, audit trails, long-term availability and transfer of data if the service agreement ends.

Where can businesses find the official EU DPP information?

Official information is available through the European Commission Digital Product Passport overview, the DPP Registry portal, the DPP harmonised standards page and the official text of Regulation (EU) 2024/1781.

Conclusion

The Digital Product Passport will become a central part of EU product regulation, sustainability policy, customs control and market surveillance.

The DPP Registry creates the common EU infrastructure needed to identify and verify passports while allowing the detailed product information to remain in decentralised systems managed by economic operators or service providers.

For products subject to a mandatory DPP requirement, Registry registration will be a separate step from creating the passport and applying a QR code. The DPP must be registered in accordance with the applicable legislation before the product is placed on the EU market.

However, the Registry’s launch does not create an immediate obligation for every product.

The legal requirement will apply progressively through product-specific delegated acts under the ESPR and through other EU legislation. Businesses must therefore assess each product category separately and follow the applicable scope, data requirements and implementation date.

Manufacturers, importers and other economic operators should use the current period to improve product data, review identifiers, assess technical systems, engage suppliers and test the EU Registry environment. Early preparation can reduce later implementation difficulties, but final compliance decisions must remain grounded in the applicable official EU rules.

Prepare for ESPR and Digital Product Passport Requirements

EaseCert helps manufacturers, importers and brands prepare for the Ecodesign for Sustainable Products Regulation and future Digital Product Passport requirements.

Our service includes a review of your product information, supplier documentation, traceability records and available sustainability data. We identify gaps and provide practical guidance for improving your ESPR and DPP readiness.

View the ESPR Compliance and DPP Preparation Service

Official EU References

  1. Regulation (EU) 2024/1781 establishing a framework for the setting of ecodesign requirements for sustainable products
  2. Commission Implementing Regulation concerning the Digital Product Passport Registry
  3. European Commission: Harmonised standards for the Digital Product Passport
  4. European Commission: Digital Product Passport overview
  5. European Commission: Digital Product Passport Registry
Show more insights

Get in Touch with EaseCert