Prepare / Practical guide
Digital Product Passport architecture
A practical DPP architecture connects product identity to a carrier, resolution or access service, governed data and permitted users. Keep identity, source data and presentation separable so systems and providers can change without breaking access to existing products.
The product-to-information chain
Permissions apply at the service and data layers, rather than relying on a hidden link. This is an illustrative architecture; the applicable regulation and technical specifications determine implementation constraints.
Source systems and the publication boundary
| System | Useful role | Design issue |
|---|---|---|
| ERP | Product master, operator and transaction context | SKU changes and identity reconciliation. |
| PLM | Engineering composition and technical records | Released versions versus work in progress. |
| PIM | Approved product descriptions and language | Marketing content versus evidence-backed fields. |
| MES | Production batches and item identity | Latency, serialisation and physical label joins. |
| Supplier systems | External records and evidence | Ownership, validation and correction. |
| Traceability systems | Events across production and lifecycle | Event semantics and relationship to passport identity. |
Use an integration layer to validate and normalise records before publication. Do not make the public service depend on unrestricted access to live ERP or engineering databases. Preserve provenance and approval state.
Centralise operations without confusing the registry
You can use a shared platform to operate many passports while source evidence remains distributed. Alternatively, multiple services can publish governed records. The choice depends on scale, ownership, continuity and integration needs—not an assumption that “decentralised” requires blockchain.
The Commission describes the registry as infrastructure for identifiers and associated metadata while product data remains decentralised. A registry is not a replacement for your hosting, access or quality controls. Read the July 2026 launch notice.
Identity and resolution must survive migration
Choose identifier rules before generating labels. Define collision prevention, model-to-batch-to-item relationships and who can retire or replace a reference. Keep a stable access address where your design allows it and make the resolver route independent of a provider-specific front-end URL.
Document redirects, authenticated API routes, failure responses and export formats. Test a migration using an existing carrier: it should still reach the correct record. A successful CSV download does not by itself demonstrate continuity.
Security and interoperability are testable
- Authenticate restricted users and authorise each requested field or operation.
- Separate public content from protected records and control write permissions.
- Maintain audit history for changes, approvals and access-policy updates.
- Document schemas, units, codes and version negotiation for machine users.
- Test exchanges with an independently implemented consumer.
- Test backup restore, provider exit and incident procedures.
CEN-CENELEC’s 2026 publications address system topics such as identifiers, carriers, protocols and persistence. Verify the applicable standard and version, and relevant Official Journal references; do not treat a generic standard claim as proof of product compliance. Standards overview.
Standards that have reached the Official Journal
| Reference | System topic |
|---|---|
| EN 18216:2026 | Data exchange protocols |
| EN 18219:2026 | Unique identifiers |
| EN 18220:2026 | Data carriers |
| EN 18221:2026 | Storage, archiving and persistence |
| EN 18222:2026 | Lifecycle management and search APIs |
| EN 18223:2026 | System interoperability |
Decision (EU) 2026/1736 publishes these six references. Conformity supports a presumption of conformity only for the ESPR requirements covered by the standards. It does not establish the product’s mandatory field list or certify an entire vendor platform.
Keep a standards register with reference, version, covered requirement, implementation evidence and test result. Access-rights/security and authentication/integrity are also part of the wider JTC 24 work; verify their current publication and citation status separately.
Make the design review a procurement input
Provide vendors with the identity model, source map, data volumes, access matrix and continuity expectations. Ask them to demonstrate the hardest integration and a portable export with history. Record which responsibilities stay with your team and which are delivered by the provider. Review the software capability guide.
Sources for this guide
- ESPR — Regulation (EU) 2024/1781
- Commission: DPP Registry launch, 20 July 2026
- CEN-CENELEC: DPP standards, 15 July 2026
- GS1 Digital Link standards library
- Official Journal: DPP harmonised standards — Decision (EU) 2026/1736
Reviewed 4 October 2026. Check the current legal text and applicable product measures before acting.