Menü

DPP Grid útmutató

EU Digital Product Passport Requirements: 2026 Compliance Guide

TL;DR: - The EU Digital Product Passport is a regulated, machine-readable data record that must be affixed to products for market access. Companies need to classify their products, map data owners, and start evidence collection now to meet upcoming deadlines, especially the fixed date for batteries in 2027. DPP implementation requires structured data, durable physical carriers, tiered access rights, and a…

Által DPP Grid Editorial áttekintette DPP Grid editorial review közzétéve 2026-08-02 Frissítve 2026-08-02 21 min

Overview

!Decorative title card illustration for digital product passport


TL;DR:

  • The EU Digital Product Passport is a regulated, machine-readable data record that must be affixed to products for market access. Companies need to classify their products, map data owners, and start evidence collection now to meet upcoming deadlines, especially the fixed date for batteries in 2027. DPP implementation requires structured data, durable physical carriers, tiered access rights, and a comprehensive data governance approach.

The EU Digital Product Passport (DPP) is a regulated, machine-readable product data record required under Regulation (EU) 2024/1781 — the Ecodesign for Sustainable Products Regulation (ESPR). Every product in an affected category must carry a persistent unique identifier linked to a physical data carrier (QR code or NFC tag) and a structured dataset covering materials, substances of concern, repairability, environmental footprint, and end-of-life guidance. No DPP means no placing the product on the EU market once the relevant delegated act applies.

The three things your team should do right now:

  • Classify your product portfolio against the Commission's Working Plan to identify which delegated acts are likely to affect you and when.
  • Map your data owners. Materials data, supplier attestations, and lifecycle assessments live in different parts of the business. Find them before a deadline forces you to.
  • Start evidence collection today. Supplier declarations, test reports, and material compositions are the hardest data to retro-collect, and they are mandatory across virtually every sector.

Timeline anchors to put in your planning calendar: The 18-month rule means a delegated act published today creates a compliance deadline 18 months from that publication date. For batteries, the deadline is fixed regardless of delegated acts: from February 18, 2027, no battery covered by the Batteries Regulation may be placed on the EU market without an operational digital passport.


Table of Contents

The ESPR, which entered into force in July 2024, is the primary legislation. It replaces the old Ecodesign Directive and extends the framework well beyond energy-related products to cover almost all physical goods sold in the EU. The DPP obligation sits within this broader ecodesign framework: the regulation establishes the architecture, and product-group-specific delegated acts fill in the exact data fields, granularity, and access-rights rules for each sector.

The ESPR's DPP provisions require that data be accurate, complete, and up to date, and that access rights be defined at the product-group level in each delegated act. That last point matters more than most compliance teams initially realize: a single "public DPP page" is not sufficient. Different stakeholders — consumers, recyclers, market surveillance authorities — get different views of the same underlying dataset.

Why does this matter for market access? Once a delegated act applies to your product group, a product without a valid DPP cannot legally be placed on the EU market. The Commission will operate a central registry and a web portal through which DPPs can be verified. The registry also stores the unique product identifiers that link physical products to their digital records.

Key structural points from the ESPR:

  • The DPP must be linked to a persistent unique product identifier (URI) that does not change over the product's lifetime.
  • The physical data carrier (QR code, NFC, or equivalent) must be affixed to the product, its packaging, or accompanying documentation.
  • Access rights are tiered: some data is public, some is restricted to specific actors (recyclers, regulators), and commercially sensitive data may be protected.
  • The economic operator placing the product on the market bears primary responsibility for the DPP's accuracy.
  • Delegated acts define the specific data fields, the required granularity (model, batch, or individual item), and the applicable timeline.

What data must a DPP contain?

The ESPR's Annex III and individual delegated acts define the mandatory data categories. The exact fields vary by product group, but the core categories are consistent across sectors. Think of these as the baseline you need to plan for regardless of which delegated act hits your portfolio first.

Core mandatory data categories:

  • Product identification: model identifier, batch number, serial number (where applicable), and the persistent URI.
  • Material composition: fiber content, material types, recycled content percentages, and origin of key materials.
  • Substances of concern: identity, location within the product, and concentration — this is one of the most demanding fields to collect from supply chains.
  • Environmental footprint / carbon data: lifecycle assessment (LCA) results, carbon footprint per functional unit, and energy consumption where relevant.
  • Durability and repairability: expected product lifetime, repairability score or index, availability of spare parts, and repair instructions.
  • End-of-life and recycling guidance: disassembly instructions, recyclability information, and waste-sorting guidance.
  • Economic operator contacts: manufacturer, importer, and authorized representative details.
  • Certificates and declarations: declaration of conformity, test reports, and any applicable certifications.
  • Care and use instructions: washing, maintenance, and storage guidance (particularly relevant for textiles under ESPR textile requirements).

Data granularity depends on the delegated act. Some product groups require a DPP at the model level only; others require batch-level or individual-item-level records. Batteries, for instance, require item-level passports. Textile products under ESPR textile requirements are expected to require model-level DPPs with batch-level traceability for certain fields. Plan your data architecture to support all three levels — retrofitting granularity later is expensive.

Evidence to collect now:

  • LCA reports or environmental product declarations (EPDs)
  • Material declarations and supplier attestations (fiber content, chemical compliance)
  • Test reports for substances of concern (REACH compliance documentation)
  • Repair manuals and spare-parts lists
  • Declarations of conformity and certificates

Pro Tip: Prioritize collecting material composition and substances-of-concern data first. These fields are mandatory across virtually every sector, they are the hardest to retro-collect from suppliers, and they are the most likely to trigger enforcement action if missing or inaccurate.


!Infographic showing steps for DPP compliance

How does the DPP work technically?

The technical architecture of a DPP has four layers: the data record itself, the persistent identifier, the physical carrier, and the access-control layer. Getting all four right is what separates a compliant DPP from a product webpage with a QR code on it.

!Compliance officer reviewing DPP documents at desk

The ESPR requires that DPPs be interoperable at technical, semantic, and organizational levels, based on open standards and machine-readable formats, with no vendor lock-in. That is a direct constraint on your platform choices.

Data flow in practice:

Source systems (PIM, ERP, supplier portals) feed structured product data into a DPP data store or a DPP service provider's platform. The service provider registers a unique URI with the Commission's Central Registry, which opened a testing environment in July 2026. The URI resolves to the DPP record, which is then accessible via APIs and a web portal with appropriate access controls applied.

Layer What it is Key requirement
Data record Structured dataset of mandatory fields Accurate, complete, up to date; machine-readable
Persistent identifier (URI) Unique product identifier registered with the Central Registry Must not change over product lifetime
Physical data carrier QR code, NFC tag, or permanent marking Durable and persistent for the product's full lifetime
Access control Tiered views for consumers, recyclers, regulators Defined per product group in delegated acts

On physical carriers: Durability is a compliance requirement, not a nice-to-have. A paper QR code sticker on a garment that washes off after three cycles is not compliant. Delegated acts will specify durability criteria; expect requirements for laser etching, durable NFC tags, or permanent markings for products with long lifetimes. For textiles, this is a live design challenge: the carrier must survive the product's use phase.

Standards and formats: GS1 has published a provisional DPP standard covering unique identifiers, data carriers, exchange protocols, and APIs. CEN-CENELEC JTC 24 has produced several standards in this space, with outputs under publication in 2026. IDTA templates provide a starting point for data modeling, but current templates do not cover all ESPR mandatory fields — substances of concern and multiple economic-operator contacts typically require schema extensions.

Access control in practice: Plan for at least three stakeholder views: a consumer-facing public view, a recycler/end-of-life operator view with disassembly and material data, and a regulator view with full documentation. Commercially sensitive data — supplier pricing, proprietary formulations — can be protected through controlled API endpoints and contractual agreements with your DPP service provider. The ESPR explicitly restricts service providers from reusing or selling DPP data beyond the contracted service.


Which sectors are affected, and when do deadlines hit?

The ESPR covers almost all physical products sold in the EU, but it phases in sector by sector through delegated acts. The 18-month rule is the mechanism that converts a delegated act's publication date into your actual compliance deadline. The Commission's Working Plan 2025–2030 is the official calendar — track it closely, because estimated adoption dates shift.

!Team discussing EU sector deadlines in meeting room

Product group Delegated act status (2026) Earliest mandatory-from estimate
Batteries Fixed by Batteries Regulation February 18, 2027
Iron and steel Delegated act in preparation 2027 (estimated)
Aluminium Delegated act in preparation 2027 (estimated)
Textiles and apparel Delegated act in preparation 2029 (estimated)
Tyres Delegated act in preparation
Furniture Delegated act in preparation 2029 (estimated)
Mattresses Delegated act in preparation 2029 (estimated)
Construction products Delegated act in preparation 2030 (estimated)
Toys Delegated act in preparation 2030 (estimated)

Estimated dates are based on the Commission's Working Plan and the 18-month rule; actual dates depend on delegated-act publication. Verify against the Commission's current Working Plan.

For fashion and textile businesses, ESPR textile requirements are among the most closely watched. The delegated act for textiles is expected to require material composition, fiber content, recycled content, country of origin, care instructions, and repairability data — fields that map directly to what DPP Grid's supplier collection workflows are designed to gather. The DPP Central Registry opened a testing environment in July 2026, which means battery-sector businesses can begin integration work now.

The battery deadline is the only fixed date in the current framework. Every other sector's deadline is a function of when the Commission publishes the relevant delegated act. That is why monitoring the Working Plan is not optional for compliance teams.


How should companies prepare for DPP compliance?

Preparation is a phased project, not a single task. The companies that will struggle are those treating DPP readiness as a last-minute documentation exercise. The ones that will be ready are those building data-governance infrastructure now.

Prioritized readiness checklist:

  1. Classify your product portfolio. Map every product group against the Commission's Working Plan. Identify which delegated acts are most likely to affect you and in what timeframe. Batteries are the immediate priority; textiles and furniture are next.

  2. Perform a data inventory. For each product group, identify what data you currently hold, where it lives (PIM, ERP, supplier files, test labs), and what is missing. Gap analysis by field and by granularity level (model/batch/item) is the output.

  3. Identify primary data owners. Materials data typically sits with procurement or product development. Environmental footprint data may require an external LCA provider. Certificates live with quality or regulatory affairs. Map ownership explicitly.

  4. Engage suppliers early. Substances-of-concern data and material declarations must come from your supply chain. Suppliers who have never been asked for this information will need time, guidance, and sometimes technical support to provide it in a usable format.

  5. Select a DPP service provider or build in-house. Evaluate platforms against schema flexibility, registry integration, evidence management, and access-rights management. In-house builds are feasible for large enterprises with dedicated engineering teams; most brands are better served by a purpose-built platform.

  6. Run a pilot on one representative SKU. End-to-end: data import, supplier attestation collection, evidence upload, QR code generation, URI registration, and access-rights verification. The pilot surfaces gaps before they become compliance failures at scale.

  7. Establish versioning and retention workflows. DPP data must be kept accurate and up to date. Plan for product updates, supplier changes, and regulatory amendments — each requires a documented version history.

Roles and responsibilities to assign:

  • DPP data owner: accountable for accuracy and completeness of the product record.
  • Supplier liaison: manages attestation requests and supplier onboarding.
  • IT/integration lead: owns PIM/ERP integration and registry connectivity.
  • Legal/compliance sign-off: reviews access-rights design, GDPR compliance, and declaration of conformity.
  • Publishing owner: controls when a DPP is published and manages version releases.

Pro Tip: Use your pilot to stress-test supplier attestation workflows and access-control configurations before you scale. The two most common failure points at scale are suppliers who cannot provide data in the required format and access-rights configurations that accidentally expose commercially sensitive information.


What standards and identifiers do you need to track?

The standards landscape for DPPs is still maturing, but several key outputs are already shaping what compliant implementations look like. Staying current with these bodies is part of your ongoing compliance work, not a one-time task.

Key standards bodies and outputs:

  • GS1 provisional DPP standard: covers unique identifiers (GTINs and serialized identifiers), data carriers (QR codes, NFC), data exchange protocols, and APIs. GS1's identifier infrastructure is widely expected to underpin DPP implementations across multiple sectors.
  • CEN-CENELEC JTC 24: the joint technical committee producing European standards for DPPs, covering identifiers, data carriers, data persistence, and interoperability. Several outputs were under publication in 2026.
  • IDTA (Industrial Digital Twin Association) templates: provide baseline data models for DPPs. The critical limitation: current IDTA templates require extensions to cover ESPR mandatory fields such as substances-of-concern concentrations and multiple economic-operator contacts. Plan for controlled schema extensions from the start.
  • ISO workstreams: ISO/IEC work on product data interoperability and digital twin standards is relevant for enterprise implementations, particularly where DPP data needs to integrate with existing product lifecycle management (PLM) systems.

The identifier landscape in practice:

The ESPR requires a persistent URI for each DPP. In practice, this URI will often be built on or mapped to existing product identifiers: GTINs for consumer goods, serialized GTINs for item-level passports, or proprietary model identifiers for products without retail barcodes. GS1's Digital Link standard provides a mechanism for encoding GTINs and serial numbers into URLs that resolve to DPP records — this is the most widely supported approach for consumer-goods sectors.

The interoperability requirement in the ESPR is not just about data formats. It covers semantic interoperability (the same field means the same thing across systems), syntactic interoperability (data is structured in a way that machines can parse), and organizational interoperability (different actors in the value chain can exchange data without bespoke integrations). Platforms that use proprietary schemas without mapping to open standards will create migration risk as the regulatory framework matures.

Align your PIM fields with GS1 and IDTA templates now, and build in the flexibility to extend those templates when delegated acts specify additional fields. That flexibility is what separates a platform that works for one sector from one that scales across your portfolio.


The ESPR requires open, machine-readable product data — but it also mandates access-rights management and explicitly excludes personal data from DPPs without consent. These two requirements pull in opposite directions, and the tension between them is where most implementation teams run into trouble.

Privacy and GDPR:

Personal data must not be stored in a DPP without explicit consent under GDPR. This sounds straightforward, but it creates practical challenges. If your DPP includes the name of a specific repair technician, the contact details of an individual economic operator, or ownership-transfer records that identify individual consumers, you are processing personal data. Privacy-by-design is not optional: build your DPP data model to separate personal data from product data from the start.

Commercial confidentiality:

The ESPR allows commercially sensitive data to be protected. The mechanism is tiered access: mandatory public data (material composition, care instructions, recycling guidance) is accessible to all; restricted data (detailed formulations, supplier pricing, proprietary processes) is accessible only to authorized actors via controlled API endpoints. Techniques to implement this:

  • Aggregate public summaries (e.g., "contains recycled polyester" rather than exact supplier and formulation details).
  • Controlled API endpoints with authentication for recyclers and regulators.
  • Contractual agreements with DPP service providers restricting data reuse.
  • Tiered data models that separate public fields from restricted fields at the schema level.

Compliance risks and mitigations:

  • Audit logs: maintain a complete log of who accessed what data and when. Market surveillance authorities may request this.
  • Authentication: where delegated acts require it, qualified electronic seals may be needed to authenticate DPP records.
  • Data retention beyond supplier insolvency: the ESPR requires that DPP data remain accessible even if the original economic operator ceases to exist. Plan for backup copies and escrow arrangements.
  • Evidence archival: supporting documents (test reports, LCAs, supplier attestations) must be retained and linked to the DPP record for the product's lifetime.

Pro Tip: Design your access-rights architecture before you build your data model. Retrofitting tiered access onto a flat data structure is significantly more expensive than building it in from the start. The Battery Regulation's implementation experience shows that access-rights design is one of the most operationally complex parts of DPP deployment.


How does DPP Grid support DPP readiness?

DPP Grid is a purpose-built platform for brands and manufacturers preparing for ESPR compliance. It addresses the core operational challenge: product and supplier data is fragmented across systems, teams, and geographies, and pulling it together into a structured, evidence-backed DPP record requires infrastructure that most businesses do not have in-house.

The platform's capabilities map directly to the requirements covered in this guide:

  • Product import: bring in product data from Shopify, CSV, or API — no manual re-entry for existing catalogs.
  • Supplier collection workflows: send structured data requests to suppliers and collect material declarations, substances-of-concern data, and attestations through a managed workflow.
  • AI-assisted data extraction with human review: AI surfaces and organizes data from uploaded documents; human reviewers approve before anything is published. AI suggestions are not automatically treated as verified facts.
  • Model, batch, and item-level support: the platform handles all three granularity levels required by different delegated acts.
  • Persistent URI and QR code publishing: product passport QR codes are generated and linked to permanent, registry-ready URIs.
  • Evidence archival: supporting documents are stored and linked to the product record, creating an audit-ready evidence trail.
  • Access-rights management: structured data templates support tiered access for different stakeholder groups.

For ecommerce businesses and Shopify merchants, DPP Grid's ecommerce integration connects existing product catalogs to DPP workflows without requiring a full ERP integration. The platform also supports consumer-facing features: product owners can scan a QR code without installing an app, access care and repair information, register ownership, and transfer ownership on resale.

DPP Grid does not provide legal certification and does not claim that using the platform automatically makes a product compliant. It provides the data infrastructure, evidence management, and publishing tools that help teams organize and demonstrate the information their products and markets require.


What does a DPP implementation roadmap look like?

A realistic implementation runs in four phases. The timelines below assume a mid-sized brand with an existing PIM and a supplier base that has not previously been asked for structured compliance data.

Phase 1: Discovery (4–8 weeks)

  1. Complete product-portfolio classification against the Commission's Working Plan.
  2. Conduct a data inventory: field by field, system by system, gap by gap.
  3. Map data owners and establish a governance structure.
  4. Select a DPP service provider or confirm in-house build scope.

Phase 2: Design (4–8 weeks)

  1. Map PIM/ERP fields to ESPR mandatory fields and GS1/IDTA templates.
  2. Design the access-rights architecture: public fields, restricted fields, and authentication requirements.
  3. Develop supplier data-request templates and onboarding materials.
  4. Establish evidence archival and versioning workflows.

Phase 3: Pilot (6–12 weeks)

  1. Select 1–3 representative SKUs across different product categories.
  2. Run end-to-end: data import, supplier attestation collection, evidence upload, URI registration, QR code generation, and access-rights verification.
  3. Validate supplier attestation quality and completeness.
  4. Stress-test access-control configurations.

Phase 4: Scale (3–12 months)

  1. Extend DPP creation across the full product catalog.
  2. Integrate supplier onboarding at scale.
  3. Establish ongoing update and versioning workflows.
  4. Prepare for market surveillance requests with audit-ready documentation.
Deliverable Owner Success criteria Typical time window
Portfolio classification Compliance lead All product groups mapped to delegated-act likelihood Weeks 1–2
Data gap analysis Data owner + procurement Field-by-field gap report by product group Weeks 3–6
Access-rights design IT lead + legal Tiered schema approved by legal Weeks 5–8
Pilot DPP published DPP data owner URI registered, QR functional, access verified Weeks 9–18
Full catalog live DPP data owner + IT All in-scope SKUs published with evidence Months 4–12

Budget-shaping factors: number of SKUs and product models, supplier complexity and geographic spread, whether LCAs or third-party testing are needed, integration effort with existing PIM/ERP systems, and whether you are using a DPP service provider or building in-house. In-house builds typically cost significantly more in engineering time and carry higher long-term maintenance risk as standards evolve.


Key Takeaways

The single most important action for compliance teams right now: start supplier data collection immediately, because material composition and substances-of-concern data are mandatory across every sector and take the longest to gather from supply chains.

Point Details
18-month rule drives all deadlines Every delegated act starts an 18-month countdown; monitor the Commission's Working Plan to know your actual deadline.
Battery passport is the first fixed date From February 18, 2027, batteries covered by the Batteries Regulation cannot be placed on the EU market without an operational DPP.
Supplier data is the critical path Material composition, substances of concern, and supplier attestations are mandatory across sectors and the hardest to retro-collect.
Technical architecture requires four layers A compliant DPP needs a structured data record, a persistent URI, a durable physical carrier, and tiered access-rights management.
DPP Grid accelerates readiness DPP Grid provides supplier collection workflows, evidence archival, persistent URI publishing, and QR code generation for brands preparing for ESPR compliance.

The DPP is a data-governance project, not a documentation exercise

Most compliance teams I see approach the DPP as a documentation problem: gather the right files, fill in the right fields, attach a QR code. That framing will get you to a first DPP. It will not get you to a scalable, audit-ready DPP program.

The ESPR's requirements are structured to force something more fundamental: a rethink of how product data is owned, governed, and maintained across the supply chain. The substances-of-concern requirement alone demands that brands have live, verifiable data from every tier of their supply chain, updated whenever formulations change. That is not a documentation task. It is a supplier-relationship and data-governance infrastructure challenge.

The teams that will handle DPP compliance well are the ones treating it the same way they would treat a major ERP implementation: with a project owner, a governance structure, defined data standards, and a pilot before a full rollout. The teams that will struggle are the ones assigning it to a single compliance officer with a spreadsheet and a deadline.

One practical recommendation on vendor selection: schema flexibility matters more than feature count. The delegated-act framework means your DPP data model will need to evolve as new acts are published. A platform that locks you into a fixed schema will create migration costs every time the regulatory landscape shifts. Prioritize platforms that support extendable templates, open formats, and registry integration from day one.


DPP Grid helps you move from planning to publishing

Getting from a compliance plan to a published, evidence-backed DPP is where most teams stall. The data exists, but it is scattered across supplier emails, test lab portals, PIM systems, and shared drives. DPP Grid is built specifically to solve that problem for fashion brands, ecommerce businesses, and consumer-product manufacturers selling into the UK and EU.

!DDP Grid

The platform lets you import products from Shopify, CSV, or API; send structured data requests to suppliers; upload and link supporting evidence; and publish permanent passport pages with registry-ready URIs and durable QR codes. Human reviewers approve all data before it goes live. The result is an audit-ready DPP record that maps to ESPR mandatory fields, supports model, batch, and item-level granularity, and gives different stakeholders the right level of access.

For compliance teams that need to move quickly, DPP Grid's supplier collection workflows and AI-assisted data extraction cut the time from data request to published passport significantly. Evidence is stored and versioned, so when market surveillance authorities ask for documentation, it is already organized and linked to the product record.

Ready to run your first pilot? Explore DPP Grid's solutions or review the full platform to see how it maps to your specific product groups and compliance timeline.


Authoritative resources and next steps

These are the primary sources your compliance team should bookmark and monitor:

  • Regulation (EU) 2024/1781 — EUR-Lex consolidated text: the full ESPR text, including DPP provisions, Annex III mandatory data categories, and access-rights requirements. This is the authoritative legal source — read the DPP articles directly rather than relying on summaries.
  • European Commission Digital Product Passport page: the Commission's official DPP hub, including the Working Plan, delegated-act status updates, and registry information. Check this regularly for delegated-act publication dates, which trigger your 18-month countdown.
  • GS1 provisional DPP standard: GS1's identifier and data-carrier standards are expected to underpin DPP implementations across consumer-goods sectors. Track updates to the provisional standard as delegated acts are finalized.
  • CEN-CENELEC JTC 24: the joint technical committee producing European standards for DPP identifiers, data carriers, and interoperability. Monitor their publication schedule for standards that will shape technical compliance requirements.
  • IDTA templates and DPP data model research: useful for understanding the current limits of standard templates and where schema extensions will be needed for ESPR mandatory fields.
  • EADTrust sector timeline map: a practical reference for tracking which sectors have DPP requirements before 2030, including the battery passport fixed deadline and estimated dates for other product groups.

The DPP is established by Regulation (EU) 2024/1781 (the ESPR), which entered into force in July 2024. Product-group-specific requirements are set through delegated acts adopted by the European Commission.

When does the first mandatory DPP deadline apply?

The first fixed deadline is February 18, 2027, when batteries covered by the Batteries Regulation must have an operational digital passport to be placed on the EU market. All other sectors follow the 18-month rule after their respective delegated acts are published.

What happens if a product does not have a DPP when required?

Once a delegated act applies to a product group, a product without a valid DPP cannot legally be placed on the EU market. Market surveillance authorities can enforce this requirement.

Do ESPR textile requirements apply to all clothing brands?

ESPR textile requirements will apply broadly to apparel and textile products sold in the EU, but the exact scope, mandatory data fields, and timeline will be defined in the textiles delegated act. Brands should monitor the Commission's Working Plan for the publication date, which starts the 18-month compliance countdown.

Can DPP Grid make my products automatically compliant with the ESPR?

DPP Grid provides product-data infrastructure, supplier collection workflows, evidence management, and DPP publishing tools that help teams organize the information required for ESPR compliance. It does not provide legal certification and does not guarantee compliance — legal sign-off on your DPP content remains the responsibility of your compliance team.

This article is operational guidance, not legal advice or certification.