BrandGuard™
Menu

DIGITAL PRODUCT PASSPORT · EU READINESS

Digital Product Passport (DPP): What It Is, EU Requirements and How to Prepare

A practical, evidence-based guide to the EU Digital Product Passport: the legal framework, technical architecture, rollout timetable and the often-missed link between a product record and the physical item carrying it.

Product material samples linked to a Digital Product Passport record

The Digital Product Passport is moving from policy concept to operating infrastructure. The Ecodesign for Sustainable Products Regulation, or ESPR, created the horizontal framework. The European Commission brought the DPP Registry into operation in July 2026, and certain batteries become the first major regulated product group to require a passport from 18 February 2027.

That sequence matters. DPP is not one universal label specification and it is not a single database into which every manufacturer uploads the same fields. It is a regulated system for connecting a physical product to structured, interoperable information that different actors can access according to their role. The exact obligations are defined product group by product group.

For manufacturers, the difficult part is therefore not generating a QR code. It is deciding which product identity the code represents, who is responsible for each data point, how the information remains available and current, and how the physical carrier survives the product life for which the record is meant to be useful.

01

What is a Digital Product Passport?

A Digital Product Passport is a digital container for information about a product. Under the EU framework, it links a unique product identifier to data required by the applicable legislation. That information may support market surveillance, informed purchasing, repair, remanufacturing, reuse and recycling. Access is not necessarily identical for everyone: consumers, professional repairers, recyclers, customs authorities and market-surveillance bodies may see different information.

The complete product data remains decentralised—held by the responsible economic operator or an authorised DPP service provider—while the EU Registry stores unique identifiers and required registration metadata. This distinction is important: the Registry is an index and control point, not a central warehouse containing every passport field.

ESPR also requires DPP information to use open standards and interoperable formats and, where appropriate, to be machine-readable, structured, searchable and transferable without vendor lock-in. A durable implementation is therefore closer to a governed product-data service than to a static webpage.

02

From circular-economy policy to a working EU system

The DPP has developed through a framework regulation, sector legislation, product studies, technical standards and operating infrastructure. These milestones should not be confused with the date on which a particular business must comply.

  1. The ESPR framework enters into force

    Regulation (EU) 2024/1781 establishes the legal framework for ecodesign requirements and the Digital Product Passport across a broad range of physical goods.

  2. The first ESPR Working Plan sets priorities

    The Commission prioritises iron and steel, aluminium, textiles and apparel, furniture, tyres, mattresses and selected energy-related and ICT products for assessment between 2025 and 2030.

  3. The DPP Registry becomes operational

    The EU launches the registry and testing environment used to register unique product identifiers and the metadata needed to locate decentralised passport data.

  4. Iron and steel rules are planned

    The Commission timetable points to a sector-specific delegated act. Planned dates remain indicative until the relevant legal act is adopted and published.

  5. Battery passports become mandatory for specified batteries

    The Batteries Regulation applies the passport to EV batteries, light means of transport batteries and industrial batteries above the defined capacity threshold.

  6. Further product rules are expected

    Current planning covers textiles, tyres and aluminium in 2027, furniture in 2028, and mattresses and selected ICT-related measures in 2029.

Status as of 2 September 2026. ESPR Working Plan dates indicate when the Commission aims to adopt product rules; they are not universal compliance dates. The Commission states that economic operators will receive a transition period of at least 18 months after an ESPR delegated act is adopted.

03

How a DPP works: five connected layers

A reliable passport depends on the relationship between the object, its identifier and the governed data behind it. Treating only the visible code usually leaves the hardest operational questions unanswered.

  1. 01

    The physical product

    The product, component, batch or model to which the passport applies. The required level of granularity is set by the relevant product rules.

  2. 02

    Data carrier

    A machine-readable carrier on the product, its packaging or accompanying documentation, as permitted by the applicable rules. QR and NFC are possible technologies, not interchangeable legal assumptions.

  3. 03

    Unique product identifier

    A globally unique identifier resolves the scan or tap to the product’s official passport and supports registration and cross-system exchange.

  4. 04

    Passport data and access rules

    Structured information is maintained by the economic operator or service provider. Public, professional and authority-only fields can be separated by access rights.

  5. 05

    Registry and ecosystem

    The EU Registry indexes the passport and registration metadata. Customs, market surveillance, repair, resale and recycling systems can use the governed connection.

04

What information goes into a Digital Product Passport?

There is no universal DPP data template for every product. Product-specific legislation defines mandatory fields. The following categories explain the direction of travel, not a substitute for the applicable delegated act.

Identity and responsibility

Product and economic-operator identifiers, manufacturing or facility references, model or batch relationships and the party responsible for the passport.

Materials and environmental performance

Material composition, recycled content, substances of concern, carbon or other environmental indicators where the product rules require them.

Durability and circularity

Expected life, repairability, spare parts, disassembly, maintenance, reuse, remanufacturing and recycling information appropriate to the audience.

Compliance evidence

Declarations, certificates, test or conformity references and other regulatory information defined for the product category.

Lifecycle information

For passports operating at item level, selected events such as commissioning, service, ownership-relevant status or end-of-life handling may be recorded when legally and operationally appropriate.

Role-based access

Consumers need understandable information; repairers and recyclers may need technical detail; authorities require compliance access. Not every field should be public.

Model, batch or individual item: granularity changes the project

A model-level passport can describe facts shared by every unit of a product design. A batch-level passport can add production-lot information. An item-level passport can support a history unique to one physical object. The applicable delegated act decides the required level, but businesses may choose greater granularity when a legitimate use case justifies it.

The operational cost and value change sharply at item level. Unique identifiers must be issued and applied during production, associated with the correct record, protected against duplication or accidental reassignment, and maintained through returns, replacements and end-of-life events. That is a manufacturing and governance problem as much as a software problem.

05

QR code or NFC? Start with the required job

The ESPR does not make NFC mandatory, and it does not establish one universal carrier for every product. The product-specific delegated act will define the acceptable carrier. The European Commission confirms that QR codes and NFC are among the technologies considered by the standards work. Batteries are a clear sector example in which the regulation specifies a QR code linked to the battery passport.

A carrier should therefore be selected only after separating regulatory access from additional product functions. A QR code may provide inexpensive visual access. NFC can offer a deliberate tap experience, work where camera access is awkward and, with an appropriate secure chip and verification service, contribute dynamic evidence about the interaction. One product may legitimately use both.

Use QR when

The governing rule requires it, universal camera access is the priority, the printed area is suitable and a visible carrier provides the intended level of assurance.

Use NFC when

A tap is more practical, the carrier must be embedded or protected, repeated service interactions matter, or secure item-level verification adds value beyond opening the passport.

Use both when

A regulated or broadly accessible QR route is needed while NFC provides a complementary service, authentication or product-experience channel. Both carriers must resolve to governed identities rather than competing records.

The right question is not ‘Which technology is more advanced?’ It is ‘What must this carrier prove, for whom, over what product life, and under which product rule?’
06

The missing distinction: data access is not physical authentication

A valid DPP can make authoritative information available, but the presence of a valid URL does not prove that the carrier is still attached to the product for which the passport was issued. A copied QR code or static NFC link may lead to the correct official record from the wrong physical object.

That does not make the DPP defective. It means accessibility, data integrity and physical product identity are different security questions. When the commercial or safety risk justifies stronger evidence, the carrier can be combined with a secure item credential, server-side verification and a physical construction designed to resist transfer or reveal opening.

The claim must remain precise. Secure NFC can make copied static content insufficient and can provide interaction evidence. It cannot, by itself, guarantee that a genuine tag has never been moved. Adhesive selection, destructible structures, closure paths, cable seals, installation control and finished-product qualification address that physical side of the system.

Read how secure NFC verification goes beyond a URL
07

Where BrandGuard fits into a DPP programme

BrandGuard is not presented as a replacement for the economic operator’s compliance responsibility or for a DPP data platform. Its role is to make the physical-to-digital connection more dependable when a project needs engineered product integration, secure item identity and live verification.

1. Product-specific physical integration

Design the label, closure seal, cable seal, heat-applied badge or durable mounted tag around the actual product, surface, use environment and expected service life.

2. Secure item identity

Where justified, use a secure NFC profile so a tap can carry dynamic cryptographic evidence rather than only a copyable static destination.

3. Controlled production and binding

Encode identities through a controlled workflow and associate each issued carrier with the intended product record, reducing mix-ups between the digital identity and the manufactured item.

4. Verification and routing

Evaluate the secure interaction and direct an approved user journey to the customer’s DPP, product record or service experience according to the agreed architecture.

5. Finished-state qualification

Test read performance, placement, removal or opening behaviour and relevant environmental conditions on the finished product—not only on a loose inlay or chip.

6. Lifecycle operations

Define how exceptions, replacements, revocation, repeated reads and credential responsibilities will be handled throughout the agreed project life.

08

A practical DPP readiness plan

Companies do not need to wait for every delegated act before addressing the decisions that take longest. They should, however, avoid freezing speculative fields as if draft requirements were final.

  1. 01

    Confirm product scope and legal role

    Map the product category, EU market route and responsible economic operator. Track the legislation that actually applies rather than relying on a generic DPP checklist.

  2. 02

    Create a data ownership map

    List likely data domains, the source system, accountable owner, update trigger, evidence and audience. Mark unresolved or supplier-dependent fields.

  3. 03

    Choose the identity granularity

    Determine whether model, batch or item-level identity is required or commercially useful. Quantify issuance, production and lifecycle consequences.

  4. 04

    Design the resolver and access model

    Define how the identifier locates the official passport, which information is public or restricted, and how availability and backup obligations will be met.

  5. 05

    Engineer the physical carrier

    Select QR, NFC or a dual-carrier approach against legal rules, product materials, space, readability, durability, service life and transfer risk.

  6. 06

    Connect production to data

    Pilot identifier issuance, encoding or printing, association, quality control and exception handling on a real production path.

  7. 07

    Test the full lifecycle

    Verify access, data updates, repair and recycling use cases, replacement and end-of-life behaviour. Revisit the design when the final delegated act is published.

09

Digital Product Passport questions businesses ask

When does the Digital Product Passport become mandatory?

There is no universal date. Certain batteries require a battery passport from 18 February 2027. Under ESPR, each product group becomes subject to specific requirements only after the relevant delegated act is adopted and its transition period expires.

Which products will need a DPP?

The ESPR Working Plan prioritises products including iron and steel, aluminium, textiles and apparel, furniture, tyres, mattresses and selected energy-related and ICT products. Inclusion in the plan triggers assessment; it does not by itself make a passport immediately mandatory.

Does a DPP have to use a QR code?

Not in every sector. The acceptable carrier is defined by the relevant product rules. The Batteries Regulation specifies QR access for battery passports; the wider DPP framework also considers NFC and other standards-compliant carriers.

Does a DPP require blockchain?

No. The EU framework requires an interoperable, standards-based system with appropriate integrity, access and persistence. It does not prescribe blockchain as the universal architecture.

Is a Digital Product Passport an anti-counterfeit solution?

Not automatically. A DPP connects a carrier and identifier to governed product information. Stronger physical authentication requires additional controls such as secure item credentials, live verification and product-specific anti-transfer or tamper-evident construction.

Can an NFC tag be used for a Digital Product Passport?

Potentially, when the applicable product rules and standards permit it. NFC can also provide services beyond DPP access, but a secure NFC implementation must still integrate with the official identifier, data and governance architecture.

Do products made outside the EU need a DPP?

If a product-specific EU rule requires a DPP, imported products placed on the EU market are also covered. The responsible economic operator must ensure the passport is present and compliant.

What should a manufacturer do now?

Track the rules for its product group, establish data ownership, assess identifier granularity and test the physical-to-digital production flow. Avoid claiming compliance until the applicable final requirements have been checked.

10

Primary sources and further reading

This guide is based on published EU legislation, European Commission implementation material and European standardisation work. Regulatory programmes evolve; always check the current product-specific legal act before making a compliance decision.

  1. Regulation (EU) 2024/1781 — Ecodesign for Sustainable Products Regulation
  2. European Commission — Digital Product Passport
  3. European Commission — Digital Product Passport FAQs
  4. Regulation (EU) 2023/1542 — Batteries and waste batteries
  5. CEN-CENELEC JTC 24 — Digital Product Passport framework and system

Editorial status: 2 September 2026. This article is general technical and regulatory information, not legal advice. BrandGuard does not claim that NFC is mandatory for DPPs or that a secure tag alone establishes DPP compliance.

FROM PRODUCT RECORD TO PHYSICAL PRODUCT

Plan the physical identity layer before production decisions become fixed.

BrandGuard can help assess the product, operating environment, carrier format, secure identity and verification path as one implementation project.

Discuss your DPP project