Regulatory reference
Digital product passport
The digital product passport is a framework created by the Ecodesign for Sustainable Products Regulation — Regulation (EU) 2024/1781 — that attaches structured, machine-readable product data to a physical item through a data carrier. Batteries are first, from February 2027. What comes after that is where published timelines stop agreeing, including the Commission's own.
What ESPR actually establishes
ESPR entered into force on 18 July 2024. Chapter III creates the passport across seven articles, and knowing which is which saves a lot of searching:
| Article | Subject |
|---|---|
| 9 | Digital product passport |
| 10 | Requirements for the passport |
| 11 | Technical design and operation |
| 12 | Unique identifiers |
| 13 | Digital product passport registry |
| 14 | Web portal for passport data |
| 15 | Customs controls |
ESPR itself does not make any product need a passport. It builds the machinery. The obligation for a specific product group arrives either through a product-specific delegated act under ESPR, or through standalone legislation. The Commission names the Batteries Regulation, the Packaging and Packaging Waste Regulation, the European Critical Raw Materials Act, the Toys Safety Regulation, the Construction Products Regulation and the Detergents and Surfactants Regulation as instruments that create passport obligations of their own.
So "when does the DPP apply to us" is never answered by ESPR alone.
The essential requirements, quoted
Article 10 sets what any passport must satisfy:
"it shall be connected through a data carrier to a persistent unique product identifier"
"the data carrier and the unique product identifier shall comply with one or more of the standards referred to in Annex III"
"all data included in the digital product passport shall be based on open standards, developed with an interoperable format"
"personal data relating to customers shall not be stored in the digital product passport without their explicit consent"
Article 11 adds that passports "shall be fully interoperable" with each other, that data "shall be stored by the economic operator responsible for its creation or by digital product passport service providers", and that "data authentication, reliability and integrity shall be ensured".
The architecture is decentralised, and this catches people out
The EU registry holds a minimal registration record. The substantive data stays with you:
"A DPP registry will be established at the EU level … The detailed product data is stored in a decentralized manner, hosted by the individual economic operators or by service providers."
Per the Commission's registry user guide, the unique product identifier is a
URL-based identifier, must start with https://, and is capped at
2,000 characters. You register the identifier; you host what it
points at, and you keep it available.
Which products, and when — with the disagreement stated
The confirmed position is the Ecodesign and Energy Labelling Working Plan 2025–2030, COM(2025) 187 final, adopted 16 April 2025:
| Product group | Target year |
|---|---|
| Iron and steel (intermediate) | 2026 |
| Textiles and apparel | 2027 |
| Tyres | 2027 |
| Aluminium (intermediate) | 2027 |
| Furniture | 2028 |
| Mattresses | 2029 |
The distinction almost every summary misses: these are target years for adopting the delegated act, not years obligations bite. The Commission states that economic operators then get "a transition period of at least 18 months" after adoption. A 2027 target year plausibly means obligations from 2029.
Three Commission sources, three different timelines
This is worth knowing before you build a plan on a date someone quoted you.
| Source | What it says |
|---|---|
| DPP FAQ page, citing the working plan | 2026 iron and steel; 2027 textiles, tyres, aluminium; 2028 furniture; 2029 mattresses, ICT |
| DPP main page | Q2–Q3 2027 construction products and textiles; 2028–2029 furniture, mattresses, ICT |
| DG GROW briefing, May 2026 | 2028 packaging, iron and steel, construction materials; 2029 ICT, tyres, aluminium, textiles, detergents; 2030 toys |
Part of the divergence is that the later lists mix in product groups whose passports come from other regulations entirely. The safe position: treat COM(2025) 187 as the confirmed ESPR schedule, remember the 18-month transition, and treat everything else as indicative.
Who carries the obligation, including on imports
The Commission's FAQ is direct about imports:
"Yes, the DPP is mandatory for all products imported into the EU market if a product-specific delegated act under the Ecodesign Regulation requires a product to have a DPP."
"The DPP must be active and registered when a product is placed on the EU market, i.e. first made available on the EU market."
For imported products the responsible party may be "the manufacturer, the authorised representative, the importer, the distributor, the dealer or the fulfilment service provider" depending on the arrangement — but someone in the EU carries it, and it is generally whoever first makes the product available here.
Customs is the enforcement point
Article 15 requires the unique registration identifier to be provided at "release for free circulation", and customs "may release a product for free circulation only after having verified as a minimum that the unique registration identifier … corresponds to the data stored in the registry".
That is a stoppage, not a fine. It applies at the border, before any market surveillance authority has formed a view about your product. For importers it is the single most operationally significant sentence in ESPR.
On penalties: Article 74 requires Member State penalties to be "effective, proportionate and dissuasive", and Article 76 allows consumers to claim damages. Levels are national.
Who gets to see the data
Access is tiered, and the public tier is anonymous — the Commission states that "general access to product information is anonymous, without a need of identification".
Article 11 requires that "customers, manufacturers, importers, distributors, dealers, professional repairers, independent operators … shall have free of charge and easy access" to the data relevant to them. Market surveillance authorities can scan a data carrier to reach documentation, with enforcement access "managed through the DPP Registry".
A caution about what you will read elsewhere. A three-tier model — general public, then notified bodies and market surveillance authorities, then those with legitimate interest — is widely repeated for the battery passport. We could not verify that mapping in a primary source, and it sits awkwardly with the four-part structure of Annex XIII evidenced by the Commission's own data-point guidance. Treat published access tables as indicative until the relevant implementing act is adopted.
What this means for procurement, specifically
The passport is a downstream artefact of an upstream data problem, and the gap between the two is where programmes fail.
The data you need is held by people who do not have to care about your deadline. Composition, recycled content, carbon footprint by life-cycle stage and due-diligence evidence all originate with suppliers, and for several of them with suppliers' suppliers.
The granularity is finer than most systems hold. Battery obligations are expressed per model per manufacturing plant. A corporate average does not satisfy an obligation written at plant level, and most supplier records are kept at entity level.
Non-response is the finding. The measure of readiness is not how many suppliers replied; it is which ones did not, and whether anyone is tracking them.
Evidence, not answers. Obligations route through technical documentation and, for battery due diligence, notified-body verification. A figure in a spreadsheet with no document behind it will not survive either.
For the battery-specific version of this, with the article references to quote at suppliers, see battery passport supplier data.
Common questions about digital product passport
Does ESPR itself require my product to have a passport?
No. ESPR builds the framework; the obligation for a specific product group arrives through a delegated act under ESPR or through separate legislation such as the Batteries Regulation. Check whether a delegated act covering your product group has been adopted — a working-plan target year is not an obligation.
When does the DPP apply to textiles?
The 2025–2030 working plan gives 2027 as the target year for adopting the textiles delegated act, and the Commission says operators get at least 18 months' transition after adoption. So obligations realistically land in 2029, not 2027 — and other Commission communications give different indicative years.
Where is the passport data actually stored?
With you. The EU registry holds a minimal registration record — the unique identifier and links. The detailed data is "hosted and maintained by you, the economic operator (or a service provider you designate)". Availability and accuracy are your responsibility, indefinitely.
What happens at the border without a passport?
Customs may release a product for free circulation only after verifying the unique registration identifier against the registry. No valid entry means no release — a supply-chain stoppage rather than a penalty, and it does not wait for anyone to investigate you.
Can we put the passport data on our own website?
The data must be reachable through the data carrier and meet Article 10's requirements — open standards, interoperable format, connected to a persistent unique identifier that is a URL beginning https:// and no more than 2,000 characters. Hosting it yourself is expressly contemplated; doing so casually is not.
Start with the suppliers who will not answer
Passport readiness is usually described as a data-modelling problem. In practice it is a collection problem with a fixed date, and the binding constraint is suppliers two tiers up who have no deadline of their own.
Qeluntra is supplier onboarding and evidence collection — structured requests, what is outstanding, and the audit trail behind each response. It does not generate passports or file them.
This reference is published by Qeluntra, which sells procurement and supplier management software. It is not legal advice, and Qeluntra is not a compliance certifier.