Nabídka

Průvodce DPP Grid

Product passport for businesses: implementing a DPP step by step

Product passports for businesses are worth implementing in stages: choose the scope, organise the data, collect evidence, approve suggestions, publish a version and only then scale. The plan below uses existing DPP Grid processes and does not promise automatic compliance.

Autor DPP Grid Editorial posoudil/a DPP Grid regulatory review zveřejněno 2026-07-24 Aktualizováno 2026-07-24 13 min

Six stages of implementing a digital product passport in a company

Define the objective and scope

DPP implementation for a business starts with a business objective, not with choosing the longest list of fields. Establish whether the first project is intended to support materials, repairs, customer service, multichannel sales or preparation for future requirements. Define the products, markets and people who approve public data.

Next, decide whether the record is at model, batch or item level. For clothing, you often need a model and variant, while for withdrawal or repair you also need a batch. An overly broad scope creates a lot of work; an overly narrow one limits usefulness after sale.

The DPP action guide describes how this scope connects to identity, carrier and history. In this section, we turn those principles into an order of actions for the team.

Build a catalogue and field dictionary

Gather the existing catalogue from the ERP, spreadsheets, shop, supplier files and documents. Do not remove values simply because they are incomplete: label their source and status. Establish a single dictionary of names, types, units and permitted values. This will make subsequent mapping and localisation easier.

Every field should have an owner, a visibility scope and an evidence criterion. ‘Material’ may require a percentage and a report, whereas ‘colour’ may come from the catalogue. Do not use one confidence level for all fields.

DPP Grid can import CSV/XLSX, documents and manual data, and then show suggestions before publication. The Shopify guide explains how to separate the commercial source from the controlled DPP record.

Connect suppliers and evidence

Instead of sending an open spreadsheet, create a request for a specific supplier. Specify the field, expected format, example evidence, deadline and how to ask a question. The response should remain private until scanning, review and a decision.

Documents should be classified, scanned and linked to the product or material. Record the file hash, document type, effective date and status. When values conflict, pause publication of the field and show the conflict to the owner.

The supplier does not need access to the entire workspace. Restricting the view simplifies compliance with contracts and reduces the risk of disclosing commercial information. The history of the invitation, response and revocation is part of the process evidence.

Use Monster AI with oversight

Monster AI can speed up document reading and flag missing information. Start with a source that you have the right to process, and retain its provenance. The result should identify the text passage, the suggested value and a level of uncertainty described in language that a reviewer can understand.

The reviewer compares the suggestion with the current value and the evidence. They may approve it, edit and approve it, reject it, or ask the supplier for clarification. Do not build automation that publishes every model match. The human decision is visible and reversible before publication.

The process should record the model, task version, source and decision. Do not show the consumer the AI's internal confidence or reviewer comments. AI transparency describes the boundaries that must be maintained.

Prepare consumer content

Once the data has been approved, build a simple narrative for the person scanning the product. The name and brand matter more than the schema key. Materials, origin, care, repair, authenticity and next life should be sections that can be found within seconds.

Do not publish gaps as certainties. Use the labels “not provided”, “in preparation” or “checked against the source”, depending on the actual status. A safety warning should appear above the marketing story, and an active recall must be visible immediately.

Plan interface and content translations separately. The DPP Grid interface can be localised in 24 languages, but product data requires the owner's approval. The language link should retain the same product, version and access policy.

Sign, publish and generate a QR code

Before publication, carry out a check of the identifier, sources, evidence, visibility, content, language and address. The signed version is the reference point. A subsequent correction should not overwrite the history; it should create a new version with a description of the change.

Generate the QR code after accepting the resolver address. Check decoding on a phone, as well as contrast, margin and size at the planned point of use. Record the campaign, product scope and language if the code directs to a specific version.

Export JSON, JSON-LD and PDF, but treat them as representations of the same record. In QR Studio, do not allow the export of artwork that has not passed an independent decoding test.

Connect the shop and operations

If you use Shopify, specify which values are only catalogue sources and which can be safely displayed in the shop. Map them explicitly, retain conflicts, and do not overwrite DPP data without a rule. A theme app extension should be lightweight, accessible and secure.

A DPP does not end with the first sale. Create a process for consumer questions, repair, transfer, resale and take-back. Each action should have an owner, a data scope and an event log.

Measure scans, language, product and campaign without collecting unnecessary personal data. The report shows which information helps users and which is merely decorative. Public analytics must respect privacy choices.

Set roles, security and retention

Minimum roles include workspace owner, reviewer, supplier operator and read-only user. The principle of least privilege is more important than the ability to add everyone to one team. Sensitive actions require reconfirmation.

Define retention for evidence, account data, events and exports. A private document may be stored longer than scan analytics data. When deleting a product, do not delete the version that was public without leaving a trace; use a documented withdrawal.

Check tenant isolation, CSRF, headers, cookies and logging. Never place keys, supplier data or comments in public HTML or JavaScript. Security Centre shows DPP Grid's basic principles.

Launch a pilot and learn

The pilot should have a limited catalogue and a decision owner. Record the objective, number of models, expected timeframe, required evidence and publication criterion. Do not measure success only by the number of QR codes created; correctness and comprehensibility of the record matter more.

Carry out a scan on several devices, and check language, contrast, screen reader and links. Ask someone outside the team to find the material, care information and reporting procedure. User questions are data for improving the content, not a reason to hide sections.

After the pilot, close gaps, update the glossary and only then add a category. EU Digital Product Passport will help link the work to requirements that have already been specified and those that remain preparatory.

Operational checklist

Before every release, check the identifier and version, source completeness, evidence and dates, visibility, languages, QR link, exports, alt text, history and the limitations notice. This checklist should be part of the publication task, not one operator's private memory.

After release, monitor resolver errors, expiring documents, failed translations, conflicts and consumer reports. Suspend a field or withdraw a version if the evidence is invalid. Keep a record of who made the decision and what the next step was.

Review roles, plan, integrations and retention quarterly. A change of supplier or shop must not change the public meaning of the record without a new review. Also check that the backup and recovery procedure are still practicable.

Team and decision preparation

The best implementation plan starts with decisions that belong to the company. Appoint a product owner, a source owner, a reviewer and the person responsible for public communication. These roles may be combined in a small team, but their responsibilities should be clearly defined before the first import.

Set a rhythm of short reviews. At each meeting, discuss new sources, conflicts, expiring documents, supplier questions and decisions for publication. A decision log makes it possible to quickly reconstruct the context when a product moves to another team or the supplier changes.

Also define an escalation path. An unclear field may be referred to the data, security, quality or legal lead. The platform helps gather the context, but the company should know who makes the final decision and when publication should be put on hold.

Granularity of model, batch and item

Record granularity affects cost, QR codes and subsequent actions. A model is simple to maintain, but it will not capture differences between batches. A batch helps with recalls, but may be too broad for repairing a single item. An item provides the most detailed history, but requires a stable identifier and more operational work.

Start at the level that matches the actual risk and the way the product is sold. If you cannot unambiguously link an identifier to a document, do not increase the number of records. It is better to publish a smaller scope with a clear limitation than many passports that cannot be distinguished from one another.

Record the inheritance rule. Specify which values pass from the model to the batch and which must be provided separately. When the material, supplier or instructions change, create a new version or variant instead of overwriting data shared by all products.

Supplier data and agreements

Preparing a DPP often reveals that agreements do not specify the format, frequency or evidence required for material data. Add a simple checklist to the procurement process: which fields the supplier provides, in which unit, for which scope and through which channel. Also establish who may amend a response after it has been accepted.

Do not send suppliers the entire catalogue or private comments. Limit the invitation to a specific request, product and deadline. Record the form version and the document hash if the company needs evidence that later publication was based on a specified file.

If a supplier does not respond, show the missing data and the next step. Do not replace it with a default value or an AI suggestion without confirmation. The product owner should be able to put a public-facing field on hold and send a reminder without deleting the earlier history.

Cost, tools and sequencing

Implementation cost includes catalogue preparation, mapping, requests to suppliers, review, publication, languages and maintenance. When comparing tools, check not only import but also export, versioning, permissions, error handling and the ability to reconstruct a record after a failure.

Set the sequence according to value and risk. First choose a category for which you have available sources and a decision owner. Then add a product with a simple structure, test the public resolver and only then increase the number of models or connect additional sales channels.

Automation should shorten repetitive work, not remove the control point. Import, document classification and translation can be fast, but publication requires a clear status and a person who has approved it. This division also makes it easier to estimate the cost of subsequent stages.

Measuring impact and maintenance

After publication, measure whether the passport helps people. Check how long it takes to find information, the number of care-related questions, scan errors, the proportion of records with up-to-date evidence, and the number of conflicts awaiting a decision. Do not equate the number of scans with data quality.

Once a month, review sources that are about to expire, broken links, language versions, QR campaigns and consumer reports. Prepare a small test of restoring data from a backup and a rollback procedure. A DPP is credible when the team can respond to an error as well.

The quarterly review should end with a specific decision: keep the scope, improve the sources, change the data model or end the pilot. Document the reason. This cadence prevents the passport from becoming an outdated page that no one owns.

Prepare operational instructions

Implementation is easier when the most common tasks have concise instructions. Describe how to add a product, invite a supplier, assign a document, resolve a conflict, publish a version and withdraw an incorrect record. For each step, add a completion condition and the person to whom an exception should be escalated.

The instructions should not copy the entire technical documentation. The operator needs an answer to what to do now and what the next participant in the process will see. Screenshots or examples should use fictional data so as not to disclose real suppliers or customers.

Update the instructions whenever the process changes. If the form, visibility scope or export method has changed, record the date and owner. An old instruction is a source of errors, even when the product record itself remains correct.

Failure and rollback test

Before scaling, conduct a controlled failure test. Open an outdated link, withdraw a test version, restore the data from a backup and check whether the consumer receives a clear explanation. The aim is not to conceal the problem, but to understand the response time and who is responsible for responding.

Define the distinction between a text correction, a change to the evidence and a product withdrawal. Each situation may require a different version, message and audience. The history should show the decision without disclosing private notes.

After the test, improve the procedure and repeat it on a smaller scale. Record the result, limitations and the owner of the next action. This means that the company does not discover the recovery process only after an actual failure or an incorrectly printed QR code.

Scaling after the pilot

After a successful pilot, choose one element to scale at a time: another category, a larger number of suppliers, an additional language or a new sales channel. Keep the same rules for sources, review, visibility and versions. Changing several layers at once makes it harder to identify the cause of an error.

Set readiness thresholds. These could include a minimum proportion of fields with evidence, a working resolver, a tested export, an adequate number of reviewers and a plan for handling questions. The thresholds should be measurable, but must not turn into a statement of automatic compliance.

Every quarter, compare the new results with those from the pilot and decide whether the scope has remained consistent. If the number of conflicts or failed translations has increased, pause the expansion and improve the process. Responsible scaling is slower than a one-off import, but provides more stable value for customers and consumers.

Involve the content owner

Every public fragment should have an owner who can assess its significance. This may be someone from product, quality, customer service or compliance, depending on the field. The owner does not need to write code, but must be able to accept a value, reject a suggestion and identify missing evidence.

Define which changes require another review. A typo correction may follow a different path from a change to the material, manufacturer or safety instructions. Record the reason, person and date so that subsequent teams do not have to reconstruct decisions from emails.

After publication, monitor whether the owner actually has time for review. If tasks are consistently left waiting, reduce the pilot scope or appoint a deputy. Scaling without an available owner creates a queue that additional automation will not fix.

Closing the stage and next step

At the end of each stage, record what was completed, what was not completed and why. A brief record should indicate the number of products, sources, conflicts, reviews, published versions and open tasks. This gives the team a shared point of reference before the next import.

If the result meets the agreed thresholds, start the next stage with a small scope. If not, return to the cause: a missing document, an unclear owner, incorrect mapping or a problem with the resolver. Do not mask unfinished work by changing the label to “ready”.

A mature implementation grows through a rhythm of short, measurable decisions. The company retains control over the data, suppliers know what is expected of them, and the consumer receives a simple and up-to-date record. This process can later be extended without losing context.

Implementation plan

DPP implementation plan for a company in six stages

Scope → catalogue → evidence → review → publication → scale.

Human review

Human decision panel for a Monster AI suggestion

The source, suggestion, current value and decision remain visible together.

Readiness check

Product passport readiness checklist for a company

Check the record, QR code, language, export, security and history before publication.

How long does the initial implementation take?

It depends on the quality of the catalogue and evidence. Start with a small pilot to measure the actual time rather than promise a fixed timeframe.

Can I start with Shopify?

Yes, as a catalogue source. Data should be explicitly mapped and approved before publication in the passport.

Does Monster AI publish data on its own?

No. AI suggestions require review and a decision by an authorised human.

Do I need a QR code for every item?

The scope depends on the purpose and the product. The model, batch or item should have a stable identity appropriate to the level of risk.

How can I protect supplier data?

Limit the portal to the specific request, keep the document private and publish only the approved value.

Is a PDF sufficient?

A PDF is an export. A persistent resolver, version and machine-readable data are needed for continuity and integration.

How should I show that data is missing?

Be explicit: not provided, in preparation or requires review. Do not replace missing data with a marketing badge.

No. It organises data and evidence, but responsibility for applying the regulations remains with the company.

Oficiální zdroje

This practical guide is not legal advice or certification. Check the current official sources and the rules that apply to your product, market and role.