English EN
Menu

DPP Grid guide

QR Code Authenticity for Digital Product Passports in 2026

TL;DR: - A QR code on a product is authentic only when it links to a complete, digitally signed Digital Product Passport registered with the EU Central Registry. - Compliance with EU standards, cryptographic signatures, and ongoing lifecycle management are essential for verifying QR code authenticity beyond just scanning. What does QR code authenticity actually mean for Digital Product Passports? A QR code on a…

By DPP Grid Editorial reviewed by DPP Grid editorial review published 2026-07-21 Updated 2026-07-21

Overview

Decorative hand-drawn title card illustration


TL;DR:

  • A QR code on a product is authentic only when it links to a complete, digitally signed Digital Product Passport registered with the EU Central Registry.
  • Compliance with EU standards, cryptographic signatures, and ongoing lifecycle management are essential for verifying QR code authenticity beyond just scanning.

What does QR code authenticity actually mean for Digital Product Passports?

A QR code on a product label is authentic when it reliably links to a Digital Product Passport that meets EU legal and technical requirements, not simply when it scans. The distinction matters more than most brands realize. A code can scan perfectly and still fail authenticity checks if the data behind it lacks a qualified electronic signature, misses mandatory fields, or hasn't been registered with the EU Central Registry.

Under the EU framework, authenticity has two layers:

  • Physical compliance: The QR code itself must meet technical specifications for size, error correction, durability, and symbology under EN 18220:2026, the harmonised standard for data carriers, adopted by Commission Implementing Decision (EU) 2026/1736.
  • Data integrity: The passport record the code links to must be complete, cryptographically signed, and verifiable, either through the EU Central Registry or via Verifiable Credentials technology.
  • Registry recognition: Only passports registered with the EU Central Registry, confirmed as complete and carrying a valid qualified electronic signature, receive a unique persistent identifier that market surveillance systems can check.
  • Interoperability: The QR code must encode a GS1 Digital Link URL so that EU infrastructure, customs systems, and third-party verification tools can resolve it consistently.
  • Ongoing validity: Authenticity isn't a one-time status. It must hold across the product's full lifecycle, including updates, ownership transfers, and resale.

The presence of a QR code on a product does not automatically guarantee regulatory compliance. Authenticity lies in the integrity of the linked data and registry verification, not in the physical mark alone.

EU regulatory framework: what standards govern QR code authenticity?

Commission Implementing Decision (EU) 2026/1736, published July 14, 2026, formally adopted six harmonised standards for Digital Product Passports under Regulation (EU) 2024/1781. EN 18220:2026 covers data carriers specifically, setting the technical baseline for QR codes used in DPPs. Brands whose codes conform to these standards gain a legal presumption of conformity with ESPR Articles 10 and 11, which is the most direct path to demonstrating compliance without additional testing.

The full suite of adopted standards covers:

  • EN 18216:2026 — Data exchange protocols
  • EN 18219:2026 — Unique identifiers
  • EN 18220:2026 — Data carriers (QR codes and equivalent)
  • EN 18221:2026 — Data storage, archiving, and persistence
  • EN 18222:2026 — APIs for passport lifecycle management
  • EN 18223:2026 — System interoperability

ESPR Article 11 also mandates that data carriers remain scannable throughout the product's expected lifetime, which directly affects printing quality, material choice, and error correction level.

Regulatory checkpoint: The EU Central Registry performs automatic verification of every submitted passport, confirming semantic completeness, correct granularity level (model, batch, or item), and the presence of a valid qualified electronic signature under Regulation (EU) No 910/2014. A successful verification triggers generation of a unique persistent registration identifier. Without it, a passport has no legal standing under EU market surveillance rules.

Brands operating in fashion and consumer goods need to treat this verification step as a hard gate, not a formality. Economic operators are legally responsible for the accuracy of the data they register, and the registry's timestamp becomes part of the proof of registration document.

How do cryptographic methods verify QR code authenticity?

Over-shoulder view of person verifying QR code authenticity

The technical side of QR code authentication goes well beyond whether a code scans. Several interlocking specifications determine whether the linked data can be trusted.

Physical QR code requirements under ESPR Article 11 and GS1 best practice include:

  • Symbology: QR Code (ISO/IEC 18004) or Data Matrix (ISO/IEC 16022)
  • Minimum size recommended for reliable scanning on product surfaces
  • Error correction at a sufficient level to maintain readability across the product lifecycle
  • Content: A GS1 Digital Link URL encoding the product's GTIN and, where required, serial number
  • Durability: Must remain scannable under expected environmental conditions for the product's full life

Cryptographic verification operates at the data layer. Verifiable Credentials technology enables decentralized, cryptographically secured product authenticity claims that can be independently verified across borders and supply chains without relying on a single central database. In 2025, the W3C published Verifiable Credentials 2.0 as a full web standard, establishing the credential format that enables tamper-proof, machine-verifiable claims about products moving through a supply chain.

Using JSON-LD and W3C standards, passport data can be structured so that a customs inspector in Rotterdam can verify a credential issued by a manufacturer in Vietnam without either party needing to share a platform. The verification is mathematical, not trust-based.

Common vulnerabilities and mitigations:

  • Cloning: A counterfeit QR code can copy the URL but cannot replicate the cryptographic signature on the underlying passport record. Qualified electronic signatures make cloned codes detectable.
  • Tampering: Any modification to the passport data invalidates the signature, flagging the record as altered.
  • Stale data: Brands must keep the live DPP current. A cached or outdated version can cause verification failures even when the code itself is valid.

Pro Tip: Test every QR code against at least three different smartphone models before printing, and run a GS1 resolver test to confirm the Digital Link URL redirects correctly for both browser and machine-readable requests.

User-side verification is straightforward: any standard smartphone camera resolves the GS1 Digital Link URL to a human-readable passport page. Market surveillance authorities send machine-readable HTTP requests to the same URL and receive structured JSON-LD data, using HTTP content negotiation to serve both audiences from one endpoint.

How should brands manage QR code authenticity across the product lifecycle?

Authenticity isn't something you set up once at launch. For fashion and consumer-product brands, it requires governance built into every stage of the product lifecycle.

Operational priorities:

  • Integrate qualified electronic signature workflows into passport creation and every subsequent update, so each version carries a verifiable timestamp.
  • Maintain a full audit trail of passport versions, including who approved changes and when, to satisfy market surveillance requests.
  • Register each passport with the EU Central Registry before the product reaches the EU market, and retain the proof-of-registration document as legal evidence.
  • Choose technology partners whose platforms generate GS1 Digital Link compliant URLs and support JSON-LD data serving, since non-compliant codes cannot be recognized by EU surveillance infrastructure.
  • Build re-issuance protocols for QR codes on products exposed to heat, moisture, abrasion, or UV, particularly for textiles where woven labels or high-durability print may be necessary.

Pro Tip: Schedule periodic scannability audits for products already in the market, especially seasonal fashion lines stored in warehouses. A code that scanned perfectly at production may degrade before the product reaches the consumer.

Platforms like DPP Grid combine AI-assisted data extraction, manual validation workflows, and compliance-ready publishing to help brands maintain product authenticity and resale infrastructure across the full product lifecycle. The platform supports passport updates, evidence management, and consumer-facing features including ownership transfer and resale, all tied to the same authenticated QR code. Brands can also use verified passport data to support take-back programs and circular economy obligations under ESPR and GPSR.

Infographic showing QR code authenticity steps

Automated registry verification reduces brand risk by catching data gaps before a passport goes live. That's a meaningful operational advantage: a rejection at the registry is far less costly than a market surveillance finding after the product is already in distribution.

What brands must act on now: key points on QR code authenticity

QR code authenticity under EU 2026 regulations is defined by legal, technical, and cryptographic criteria working together. A scannable code is the starting point, not the finish line.

  • Authenticity is determined by EN 18220:2026 compliance, qualified electronic signatures, and EU Central Registry registration, not by the QR code's visual design.
  • Verifiable Credentials and JSON-LD standards enable decentralized verification that customs, consumers, and market surveillance authorities can all use independently.
  • Brands bear legal responsibility for data accuracy and must maintain authenticity through every passport update and product lifecycle stage.
  • Non-compliant or cloned QR codes expose brands to market surveillance failure, product withdrawal, and loss of consumer trust in resale markets.
  • DPP Grid's platform helps brands build evidence-backed Digital Product Passports with secure QR codes, supporting registry readiness and ongoing lifecycle management without claiming automatic compliance.

DDP Grid makes QR code compliance manageable for fashion brands

Fashion and consumer-product brands preparing for EU Digital Product Passport requirements face a real operational challenge: the technical bar for authentic, registry-ready passports is high, and the data involved is fragmented across suppliers, factories, and internal teams.

Dppgrid

DDP Grid is built for exactly that situation. The platform lets brands import products from Shopify, CSV, or API, collect supplier data, upload supporting evidence, and publish permanent passport pages with QR codes that meet EU technical requirements. AI-assisted extraction speeds up data collection; human review keeps the record accurate. Brands get a full audit trail, version history, and the infrastructure to stay connected to products through resale, take-back, and ownership transfer. Start building your EU-ready product passports today and see how DDP Grid organizes the evidence your compliance team needs.

What makes a QR code on a Digital Product Passport authentic?

A DPP QR code is authentic when it encodes a GS1 Digital Link URL, meets EN 18220:2026 technical specifications, and links to a passport record that carries a valid qualified electronic signature and is registered with the EU Central Registry.

Does scanning successfully mean a QR code is compliant?

No. A code can scan and still fail authenticity requirements if the linked passport lacks mandatory data fields, a qualified electronic signature, or EU Central Registry registration.

What is EN 18220:2026 and why does it matter?

EN 18220:2026 is the harmonised standard for DPP data carriers, adopted under Commission Implementing Decision (EU) 2026/1736. Conformity with it provides a legal presumption of compliance with ESPR Articles 10 and 11.

How do Verifiable Credentials protect product passport data?

Verifiable Credentials embed cryptographic signatures directly in the passport record, making any tampering detectable and allowing customs or consumers to verify authenticity without accessing a brand's own database.

How can brands verify their QR codes meet EU requirements?

Test codes against multiple smartphone models, run a GS1 resolver test to confirm correct Digital Link URL behavior, validate JSON-LD output with a schema validator, and confirm the passport is registered with the EU Central Registry before market release.

Key Takeaways

QR code authenticity under EU 2026 regulations requires physical compliance with EN 18220:2026, cryptographic data integrity via qualified electronic signatures, and confirmed registration with the EU Central Registry.

Point Details
Authenticity is data-deep A scannable QR code is not enough; the linked passport must carry a qualified electronic signature and pass EU Central Registry verification.
EN 18220:2026 sets the bar This harmonised standard, adopted July 14, 2026, defines the technical requirements for DPP data carriers and grants presumption of ESPR conformity.
Verifiable Credentials enable cross-border trust Cryptographic credentials let customs, consumers, and authorities verify passport data independently, without accessing brand systems.
Lifecycle management is mandatory Brands must maintain scannability, update passport records with valid signatures, and re-issue codes that degrade over the product's lifetime.
DDP Grid supports registry-ready passports DDP Grid helps brands organize evidence, manage supplier data, and publish QR-coded passports built for EU Central Registry submission.

Recommended

This article is operational guidance, not legal advice or certification.