Menu

Gids van DPP Grid

Start With Verification: DPP Steps for EU Economic Operators and SMEs

Under the Ecodesign for Sustainable Products Regulation, an economic operator is any manufacturer, authorized representative, importer, distributor, dealer, or fulfilment service provider that touches a covered product before it reaches an EU customer. The manufacturer normally carries primary responsibility for building and registering the Digital Product Passport, but that duty shifts to the importer when the…

Door DPP Grid Editorial beoordeeld door DPP Grid editorial review gepubliceerd 2026-09-18 Bijgewerkt 2026-09-18 18 min

Overview

!Decorative DPP verification title card illustration

Under the Ecodesign for Sustainable Products Regulation, an economic operator is any manufacturer, authorized representative, importer, distributor, dealer, or fulfilment service provider that touches a covered product before it reaches an EU customer. The manufacturer normally carries primary responsibility for building and registering the Digital Product Passport, but that duty shifts to the importer when the manufacturer sits outside the EU or when another party markets the product under its own name. Only economic operators who complete identity verification can register a DPP in the EU Registry at all, which makes verification the first real deadline on your compliance calendar, not registration itself.


TL;DR:

  • The verification process for EU Registry registration requires a qualified electronic signature from a certified trust provider, which often takes longer than technical setup.
  • The EU Registry only stores metadata and a link to your passport data, so your hosting infrastructure must ensure long-term stability and accessibility.
  • Correctly identifying your role as manufacturer, importer, or distributor is critical, as responsibilities for data provision and verification vary significantly between these roles.
  • A private-label reseller becomes a manufacturer for DPP purposes, inheriting full legal responsibilities regardless of factory involvement.
  • Automation platforms like DDP Grid facilitate data collection, proof management, and passport page creation but do not replace your legal verification and compliance obligations.

Table of Contents

Who Counts as an Economic Operator Under ESPR?

Regulation (EU) 2024/1781 defines "economic operator" broadly enough to catch almost every business that moves a physical product between a factory and a shopper's door. If you manufacture, brand, import, warehouse, or resell a product covered by an ESPR delegated act, you fall inside this definition somewhere. The trick isn't recognizing that you're covered. It's figuring out which specific role you occupy, because the obligations attached to each one are different enough that guessing wrong creates real exposure.

Here's how the roles break down in plain terms:

  • Manufacturer: the entity that makes the product or has it designed and made, then markets it under its own name or trademark. This is the default holder of DPP responsibility.
  • Authorized representative: a person or company established in the EU that a non-EU manufacturer formally appoints to carry out specific compliance tasks on its behalf.
  • Importer: the EU-based entity that places a product from a non-EU country on the EU market for the first time.
  • Distributor: any party in the supply chain, other than the manufacturer or importer, that makes a product available on the market.
  • Dealer: a narrower term often used for retail-facing resale, functionally treated like a distributor for DPP purposes in most delegated acts.
  • Fulfilment service provider: a company offering warehousing, packaging, or dispatch services for a product it does not own, typically relevant to cross-border ecommerce operations.

The confusion usually happens at the boundary between roles. A UK apparel brand that designs garments, has them cut and sewn in Bangladesh, then sells under its own label is the manufacturer, full stop, regardless of who owns the sewing machines. A separate EU company that buys finished stock from that brand and resells it under a private label becomes the manufacturer of record for that resale, inheriting the full weight of manufacturer duties. A logistics company that just stores and ships boxes for someone else's brand is a fulfilment service provider, with a much narrower set of obligations tied mostly to storage and dispatch conditions.

Legal persons (companies) and natural persons (individual traders or sole proprietors) can both be economic operators; ESPR doesn't exempt small or individual sellers just because they lack a corporate structure. The regulation also allows for groups of economic operators acting jointly, which matters for smaller manufacturers that pool resources through a trade association or shared compliance service to handle registry work collectively rather than duplicating the setup cost individually.

Getting your role right isn't an academic exercise. It determines who signs the verification documents, who hosts the passport data, and who answers to a market surveillance authority if something goes wrong.

Who Is Responsible for What: Role-by-Role DPP Duties

Each role under ESPR carries a distinct slice of the DPP workload, and the practical consequences of getting a duty wrong range from a rejected registration to genuine legal liability.

!DPP duties by economic operator role

The manufacturer does the heavy lifting. That means compiling the passport data itself (materials, origin, safety information, durability and repairability data as the relevant delegated act requires), carrying out the conformity assessment tasks tied to the product category, affixing the physical data carrier (usually a QR code) to the product or its packaging, hosting the passport data at a stable, resolvable location, registering the unique product identifier in the EU Registry, and retaining technical documentation for the required period. If you're a manufacturer, you own essentially every step in the chain.

The importer inherits a specific and important trigger point: verifying that the non-EU manufacturer whose product they're bringing into the EU has actually met its DPP obligations, then adding their own identity data to the record. If the importer can't confirm the manufacturer did its job, or chooses to place the product on the market under their own brand, the importer effectively becomes the party holding manufacturer-level responsibility. Legal analysis from White & Case confirms this liability shift applies whenever a distributor or importer brands a product as its own or modifies it in ways that affect compliance, which is exactly the scenario that catches private-label sellers off guard.

Distributors and dealers carry a lighter but still meaningful duty: verify that a DPP actually exists before putting a product up for resale, avoid damaging or obscuring the physical data carrier, and make sure the passport stays accessible for distance sales, where a shopper can't physically scan a code on a shelf. A distributor who resells a product with a broken QR code or a dead link has failed this duty even without touching a single line of the underlying data.

Authorized representatives and fulfilment service providers hold the narrowest scope. An authorized representative's job is usually retention of documentation and cooperation with authorities on the manufacturer's behalf, acting as the EU-based point of contact. A fulfilment provider's obligations are mostly about storage and dispatch conditions, keeping products in a state that doesn't damage or misrepresent the passport data attached to them.

Pro Tip: Write DPP obligations directly into your supplier contracts before you need them, not after a shipment arrives without documentation. Require suppliers to provide proof of data provision, a dated record confirming what information was sent and when, so you're not left guessing during an audit.

The legal implication that trips up the most businesses: brand ownership triggers manufacturer-level duties, even for a company that never touched a factory floor. If your business model involves buying generic stock and slapping your logo on it, you are the manufacturer for DPP purposes, and the registry, the retention rules, and the liability all follow accordingly.

How Do You Enroll and Get Verified in the EU DPP Registry?

Registration in the EU Registry is gated behind a verification process that only confirmed, identity-checked economic operators can pass, according to the DPP Registry user guide for economic operators. Here's what that process actually involves, step by step.

  1. Authenticate through EU Login. This is the European Commission's standard identity gateway, and it's the first thing any team member needs before touching the Registry.
  2. Enroll your organization. You'll register your company's legal identity, business registration details, and primary contact information in the Registry's organization records.
  3. Generate and sign a sealed declaration. The Registry requires an EC-sealed PDF declaration confirming your organization's identity and role. This document typically needs to be countersigned by a legal representative of your company.
  4. Apply a Qualified Electronic Signature or Qualified Seal. This has to come from a Qualified Trust Service Provider, an accredited certificate issuer under the eIDAS framework. This is not a step you can skip or fake with a scanned signature.
  5. Upload the signed documentation and submit it for review.
  6. Check verification status. The Registry performs cryptographic checks on the sealed document, and the process fails if the certificate details don't match what you entered during enrollment, so accuracy at every prior step matters.

The verification steps that require an actual legal representative's signature and a QTSP-issued credential cannot be delegated to software or outsourced to a third party acting without formal authorization. That single constraint is why verification, not the technical registration submission, is usually the longest pole in the tent for most businesses. Everything downstream of verification (building the payload, generating identifiers, submitting registration records) can be automated by a platform or an internal system. The identity check itself cannot.

Timelines vary by how quickly your organization can source a Qualified Electronic Signature or Qualified Seal from a QTSP, since procurement and internal legal sign-off often take longer than the actual document upload. Businesses that treat verification as a same-week task consistently underestimate it. Start that procurement process months before you plan to register your first product, not the week before a delegated act applies to your category.

What Are the Technical Requirements for Creating a DPP?

The single most common misunderstanding about the EU Registry is thinking it stores your passport data. It doesn't. The European Commission's own guidance describes the Registry as an indexing service: it holds registration metadata and a link, and the actual passport content lives wherever you or your designated hosting provider put it. That distinction matters because it means hosting reliability is entirely your problem, not the Commission's.

A handful of technical requirements determine whether your registration succeeds or fails:

  • The Unique Product Identifier (UPI) must be a resolvable URL that conforms to JTC 24 standards, the technical committee specification governing product identifier formats.
  • GS1 Digital Link is a commonly used structure for building UPIs, since it's already familiar to most manufacturers using barcodes and works cleanly with QR-based data carriers.
  • The physical data carrier, almost always a QR code, needs to be placed where a consumer can reasonably scan it without damaging the product or packaging.
  • The registry payload itself requires specific fields: the uniqueProductIdentifier, a hostedDataUrl pointing to your live passport data, the granularity level (model, batch, or individual item), your economicOperatorId, and a dppVersionHash.

That version hash deserves its own explanation because it's where a lot of technical implementations go wrong. According to practitioner guidance from PassportIQ, the Registry expects a SHA-256 hash computed over a canonical JSON serialization of your passport data. Every time you update the underlying content, that hash changes, and the Registry uses it to detect whether hosted data has actually been modified since the last check. Get the serialization wrong (different field ordering, inconsistent formatting) and you'll generate a hash that doesn't match on re-verification, even if the underlying content is identical.

A dead or redirecting UPI throws a NOT_RESOLVABLE_UPI error, and it's one of the most common failure points reported by early implementers. A URL that returns a 301 redirect, sits behind a login wall, or simply goes offline during a routine server migration breaks the resolution chain the Registry relies on. This is not a hypothetical edge case. Businesses that host passport data on infrastructure without long-term availability guarantees, a temporary marketing subdomain, a staging server, a URL tied to a specific ecommerce theme, are setting themselves up for exactly this failure mode months or years down the line.

The practical takeaway: pick hosting infrastructure built to stay stable for the entire expected lifetime of the product, not just through your next platform migration. That's a longer horizon than most companies plan their web infrastructure around, and it's worth treating as its own line item rather than an afterthought bolted onto an existing website.

When Do You Need to Update a DPP, and How Is It Enforced?

Not every product tweak requires a Registry update, but a substantive change (a material composition change, a new manufacturing location, an updated safety finding) does, and the registration identifier itself stays stable across those updates rather than generating a brand-new record each time. Think of the registration ID as a permanent address and the dppVersionHash as a signal that the contents at that address have changed.

Timing for when any of this actually becomes mandatory depends on delegated acts, the product-category-specific rules the Commission adopts under ESPR's framework. The regulation guarantees a minimum 18-month transition period between when a delegated act enters into force and when compliance actually becomes mandatory for that product category, with extra consideration built in for SMEs. That transition window is generous by regulatory standards, but it only helps if you're actually tracking which delegated acts apply to your product categories and when their clocks start. Waiting until a delegated act is already in force to start building your DPP workflow burns through most of that buffer before you've done anything.

Enforcement runs through the same customs and market surveillance channels already used for other product compliance checks. During checks at the border, or when a product is released for free circulation, authorities can query the Registry to confirm a valid DPP exists and resolves correctly. A missing or unreachable DPP at that checkpoint creates the same kind of friction as any other missing compliance document, potential delays, requests for documentation, and in persistent cases, market surveillance action against the responsible economic operator.

A few practical retention and readiness points worth locking in now:

  • Keep technical documentation retained for the full period specified by the relevant delegated act, not just until your next product refresh.
  • Treat delegated-act tracking as an ongoing task, not a one-time check, since new product categories get added over time.
  • Build your internal process so a "substantive change" trigger automatically flags a Registry update rather than relying on someone remembering to do it manually.
  • Assume market surveillance can and will spot-check DPP resolvability, particularly for high-volume product categories.

Your 90 to 180 Day DPP Readiness Plan

If you're a smaller manufacturer or importer trying to figure out where to actually start, the honest answer is: start with identity, not technology. Everything else depends on verification clearing first.

  1. Confirm your exact role (manufacturer, importer, distributor, and so on) for each product line you sell, since a single company can hold different roles for different product ranges.
  2. Begin QES/QSeal procurement immediately. Contact a Qualified Trust Service Provider now; this step alone often takes longer than every other item on this list combined.
  3. Enroll your organization in the Registry through EU Login once your legal identity documentation is ready.
  4. Map your essential supplier data fields. Identify exactly what material, origin, and safety data you need from each supplier and in what format.
  5. Choose your hosting strategy for resolvable UPIs before you generate a single identifier, since retrofitting a hosting decision later is expensive.
  6. Build your identifier generation and hash-computation process, deciding whether you'll register at model, batch, or item granularity based on your product complexity and volume.
  7. Add DPP clauses to every new and renewed supplier contract, including a required data template and a deadline for delivery.

Pro Tip: Don't wait for your supplier to volunteer material composition data in a usable format. Send them a fixed template with required fields spelled out explicitly. A supplier given a blank request will send you a PDF spec sheet; a supplier given a structured template will send you usable data.

Mapped against the 18-month transition window, a realistic milestone timeline looks like this: verification and organization enrollment in the first 60 to 90 days, supplier data collection and hosting infrastructure built out in months three through six, and full registration workflow testing on a pilot product line before the delegated act for your category actually applies. SMEs that start this early consistently report smoother rollouts than those that begin scrambling once a compliance deadline is already visible on the horizon.

The workload splits cleanly into two categories: legal identity verification, which only your organization and its legal representative can complete, and technical registration work, which software can automate almost entirely. That second category is where a platform earns its keep.

A tool like DDP Grid handles the operational side of this split: pulling product data in from Shopify, CSV files, or an API connection, collecting supplier information through structured request templates, storing uploaded evidence documents against each product record, and using AI to extract and organize raw supplier data into usable fields. Every AI-generated suggestion goes through human review before publication, so nothing gets treated as verified fact until a person actually confirms it. Once approved, the platform generates permanent passport pages with QR codes and machine-readable records covering materials, manufacturing locations, economic operators, and supporting evidence.

What a platform cannot do, and what DDP Grid does not claim to do, is provide legal certification or confirm your product meets regulatory requirements. The legal responsibility for accuracy, for verification, and for compliance with your role's specific obligations stays with your organization, full stop. What automation buys you is time and consistency: fewer spreadsheets, fewer missing supplier fields, and a clear evidence trail if a market surveillance authority ever asks how you arrived at a given claim.

  • Automate identifier generation and hosting checks rather than tracking them manually across product lines.
  • Centralize supplier evidence so nothing lives in a single employee's inbox.
  • Keep a version history of every approved change for audit purposes.

Why Verification, Not Registration, Is the Real Bottleneck

Most compliance guidance treats DPP registration as the finish line. It isn't. The bottleneck sits earlier, at the identity verification stage, and businesses that don't recognize this end up scrambling to source a Qualified Electronic Signature weeks before a delegated act applies to their category, when the procurement process alone can eat that entire runway.

The other pattern worth calling out: companies consistently underestimate how much of their DPP exposure comes from branding decisions rather than manufacturing decisions. If you private-label someone else's product, you've taken on manufacturer-level responsibility whether you meant to or not. I'd argue this catches more mid-size distributors off guard than any technical requirement in the Registry, because it's a legal consequence hiding inside a commercial decision that nobody flagged as a compliance trigger.

My practical advice, in order: start the QES or QSeal procurement conversation this quarter, not next. Pick hosting infrastructure for your UPIs that you'd trust to still be running in five years. And get your supplier contracts rewritten with explicit DPP data clauses before you're negotiating those contracts under deadline pressure. None of this is complicated once you sequence it correctly. Most of the failures I'd expect to see across this space come from sequencing it wrong, not from any single step being genuinely hard.

— Vytautas

How DDP Grid Supports Your DPP Registration Workflow

DDP Grid gives economic operators a practical way to manage the technical side of DPP readiness without pretending to replace your legal obligations. You import products from Shopify, CSV, or API, collect supplier data through structured request templates, and upload supporting evidence directly against each product record.

!DDP Grid

Every piece of AI-extracted data goes through human review before publication, so what ends up on a live passport page has been checked by someone at your organization, not just generated and pushed live. Once approved, the platform builds permanent passport pages with QR codes and machine-readable records covering materials, manufacturing locations, economic operators, and supporting documentation, at model, batch, or individual-item granularity depending on what your product line needs.

None of this replaces your legal responsibility for verification, accuracy, or the role-specific obligations covered earlier in this guide. DDP Grid does not provide legal certification, and using the platform doesn't automatically make a product compliant. What it does is remove the manual grind of tracking supplier documents across spreadsheets and email threads. If you want a quick read on where your own readiness gaps sit, run the free DPP readiness checker, or compare plans starting with Starter at £49 per month on the pricing page.

Sources

For the legal definition of economic operator and the delegated-act transition rules, the consolidated ESPR text on EUR-Lex is the primary source and the one that holds up in any dispute over role or obligation. For the actual mechanics of enrolling and registering, the DPP Registry user guide for economic operators is the operational manual, covering verification steps, sealed declarations, and payload fields in detail. For broader regulatory context and the architecture of the Registry itself, the Commission's DPP pages for economic operators explain how registry metadata and hosted passport data relate to each other.

  • Consolidated text: Regulation (EU) 2024/1781 (ESPR)
  • DPP Registry user guide for economic operators (DG Grow Digital Solutions)
  • How to Enrol and Register in the EU DPP Registry: A Step-by-Step Guide for Economic Operators — PassportIQ

What Does "Economic Operator" Mean Under EU Product Law?

An economic operator is any manufacturer, authorized representative, importer, distributor, dealer, or fulfilment service provider involved in getting a covered product to market, as defined under ESPR. The specific duties attached to that status depend on which of those roles you occupy for a given product.

Which Companies Are Approved as Authorized Economic Operators (AEO)?

Authorized Economic Operator (AEO) status is a separate customs simplification program run by EU member state customs authorities, distinct from the DPP economic operator roles covered in this guide. AEO-approved companies are listed by their national customs authority rather than in the DPP Registry, and holding AEO status doesn't substitute for DPP registration or verification.

How Do I Apply for an AEO License?

AEO authorization applications go through your national customs authority, not the EU DPP Registry, and typically require demonstrating compliance history, financial solvency, and adequate internal controls. This is a separate process from the EU Login and QES/QSeal verification steps required to register Digital Product Passports.

What Is a Group of Economic Operators?

A group of economic operators is a collection of businesses, often smaller manufacturers or trade association members, acting jointly to meet shared obligations rather than each building separate compliance infrastructure. ESPR permits this arrangement, which can reduce the individual cost of tasks like Registry enrollment for businesses that pool resources.

Can a Platform Like DDP Grid Register My DPP for Me?

A platform can automate the technical registration steps, identifier generation, payload construction, and evidence management, but the identity verification stage requires a legal representative's Qualified Electronic Signature or Seal and cannot be delegated to software. DDP Grid supports the operational workflow around data collection and passport publication, while final legal responsibility for compliance stays with your organization.

This article is operational guidance, not legal advice or certification.