INDEPENDENT GUIDANCE EU regulation · Product data · Enterprise procurement

Understand / Practical guide

Digital Product Passport requirements

There is no single mandatory DPP dataset or universal implementation deadline for every product. ESPR establishes the framework; applicable product measures specify the operational requirements. Batteries must be assessed under their separate regulation.

Read requirements in layers

Maintain three layers in your requirements register: the governing law, the measure that applies to your exact product, and the technical specifications used to implement it. Keep interpretation and internal design decisions in separate columns. This prevents a vendor feature or an industry pilot from being treated as a legal obligation.

What is established—and what needs a product rule

ConceptEstablished frameworkProduct-specific detailWho should act
Product identityA persistent identifier connects to a carrierModel, batch or item level; carrier and placementProduct owner and manufacturing
InformationAccurate, complete, current passport dataRequired fields and applicable conditionsCompliance and data owners
InteroperabilityOpen, transferable data and interoperable operationApplicable formats and technical implementationArchitecture and procurement
AccessAccess reflects the user’s rightsWho can read or update which informationSecurity and governance
AvailabilityContinued availability is part of the frameworkApplicable availability periodOperations and service providers
Market accessA passport is required where the applicable measure requires itScope, exemptions and application dateResponsible economic operator

Basis: ESPR Articles 9–11 and Annex III. This table describes the framework; it is not a complete compliance checklist.

Continuity and data protection are core requirements

ESPR includes a backup-copy arrangement through a DPP service provider and requirements for continuing availability and controlled data operation. Capture backup, recovery and provider failure as separate controls. A backup file that nobody can resolve from the original product is not an operational continuity plan.

Customer personal data should not be added to the passport without the required explicit consent under the framework. Avoid using a product record as an uncontrolled customer-tracking system. Document permitted processing, access and provider use of the data alongside the field model. See Articles 10–11.

Turn a rule into a testable requirement

For each obligation, record the legal citation, affected products, effective date, responsible role, required evidence, implementation decision and acceptance test. Add an uncertainty owner where interpretation is unresolved.

Register fieldIllustrative entry
ObligationProvide authorised access to a restricted data class
EvidenceAccess matrix linked to a cited rule
ImplementationRole-based API and human-readable view
TestPublic user is denied; authorised user receives only permitted fields
Change triggerNew implementing measure or revised access interpretation

Examples here are engineering guidance. Validate the real scope and user rights before implementing them.

Avoid these scope errors

  • Treating a Commission working-plan year as a market-access deadline.
  • Copying a battery dataset to every product group.
  • Assuming every product must have an individual serialised passport.
  • Treating all supplier information as public.
  • Using a platform’s “compliance ready” claim instead of a rule-to-test mapping.

A company outside the EU can still be affected through products placed on the EU market. Location alone is not a scope test. Determine the product and responsible operator first.

What to do while details develop

Build an inventory of affected or potentially affected products, establish data owners and capture source evidence. Make the data model configurable. Separate confirmed fields from anticipated fields so you can change the specification without relabelling products or rewriting every integration. Use the readiness checklist to identify work that is useful before final product rules are available.

Sources for this guide

Reviewed 4 October 2026. Check the current legal text and applicable product measures before acting.