What a Digital Product Passport Is, and What EU Law Actually Requires Today
A Digital Product Passport is product data you hold, reachable by scanning the product. Here is what the ESPR framework really says, the one product group with a real deadline, and why most of the dates you have been quoted do not exist in law.
What a Digital Product Passport Is, and What EU Law Actually Requires Today
A Digital Product Passport, usually shortened to DPP, is a structured set of data about one product, held by whoever places that product on the EU market, and reachable by scanning a code carried on the product itself. That is the entire idea. Everything else is detail about which products, which data, which code, and who is entitled to read which parts.
The detail is where most of what you have read goes wrong. Search for a passport deadline and you will find confident dates for textiles, electronics, furniture and toys. Almost none of those dates exist in law. One does. It is narrow, it is real, and it is the one worth planning around.
This is the plain version: what the passport is, why the EU built it, what the legal position actually was when we last read the primary texts on 20 August 2026, and what a seller can usefully do now.
One disclosure before anything else. We build passport tooling, so we have a commercial incentive to tell you that a deadline is closing in on your category. We are not going to, because for most categories there is not one, and a false deadline on a regulated subject costs you a supplier data programme you did not need.
Why the EU built it
The passport exists because of a specific, boring failure: the people who could keep a product in use cannot get the data they need to do it.
A repairer does not know which screws hold the housing, or whether a spare part exists. A recycler does not know which flame retardant is in the casing, so the safe assumption is the expensive one. A second-life operator looking at a used battery pack cannot tell a healthy unit from a tired one, so the whole batch gets priced as scrap. A customs officer at the border has a declaration and a box. A consumer choosing between two jackets has two marketing pages.
Every one of those is an information problem, not a technology problem. The data usually exists. It sits with the manufacturer, in a spreadsheet, in a supplier email thread, in a certificate PDF, and it never travels with the product.
The Ecodesign for Sustainable Products Regulation, Regulation (EU) 2024/1781, usually called ESPR, is the instrument that attaches the data to the product. It came into force on 18 July 2024 and replaced the old Ecodesign Directive, widening the scope from energy related products to very nearly all physical goods. Chapter III of it, Articles 9 to 15, is the passport.
The single most important thing about ESPR
ESPR is a framework. It does not tell you what data your product needs.
Read Chapter III and you find the machinery. Article 9 creates the passport. Article 10 sets requirements, including that access be differentiated by audience. Article 11 covers technical design and operation. Article 12 covers unique identifiers. Article 13 has the Commission setting up a digital product passport registry, with a deadline on the Commission of 19 July 2026. Article 14 is the public web portal. Article 15 is customs.
What you will not find anywhere in that chapter is a field list for your product. ESPR delegates that. Each product group gets its own delegated act, and until that act is adopted, four things are legally undetermined for that group: the mandatory field list, the product granularity (model, batch or individual unit), the access rights split, and the transition period between adoption and the date the obligation bites.
This matters more than it sounds. "ESPR is in force" and "you have a passport obligation" are two different statements, and the first does not imply the second. Most of the confident category deadlines circulating are somebody's forecast of when a delegated act will be adopted, restated as a rule.
The one group with a real date
Batteries are the exception, and they are the exception because the obligation does not come from ESPR at all.
Regulation (EU) 2023/1542, the Batteries Regulation, is adopted, it is in force, its Article 77 creates a battery passport, and Annex XIII names the dataset field by field. The date is 18 February 2027.
The scope is the half that gets dropped, and it is the half that decides whether the date is yours. Article 77(1) covers:
- LMT batteries, meaning batteries for light means of transport such as e-bikes and e-scooters
- Electric vehicle batteries
- Rechargeable industrial batteries with a capacity above 2 kWh
It does not cover a portable cell. It does not cover an SLI starter battery in a conventional car. The word "batteries" on a product listing cannot separate a 60 kWh traction pack from a hearing aid cell, which is why any tool that shows every battery seller a February 2027 countdown is guessing, and guessing in the direction that sells more software.
If you sell in scope batteries, that date is real, the dataset is published, and there is no ambiguity to wait out.
Textiles, and everything else
Textiles and footwear are the category most often quoted a deadline. As of our last reading, the textiles delegated act had not been adopted. That means there is no textile field list in law, no textile granularity in law, no textile access split in law, and no textile date in law.
Indications point at adoption somewhere in the following couple of years with a transition period after it, which is why you see figures in the 2028 region in trade press. Those are forecasts. A forecast is a perfectly reasonable thing to plan against. It is not a rule, and anyone presenting it as one is telling you something they cannot support.
Every other product group is in the same position, only with less preparatory work behind it. You get the framework level and nothing more.
So the honest three line summary of the legal position is:
- In scope batteries: adopted dataset, 18 February 2027, plan for it.
- Textiles and footwear: framework in force, delegated act not adopted, no date.
- Everything else: framework in force, no product specific act, no date.
What data a passport actually carries
Where a dataset does exist, the fields sort into four working groups. The battery dataset is the concrete example, because it is the one you can read rather than predict.
Identification. The unique product identifier, the manufacturer, the battery category and model, the date and place of manufacture. This is the part that makes the passport addressable at all.
Material composition. Battery chemistry and materials including critical raw materials, recycled content declared per recovered metal (cobalt, lithium, nickel, lead) rather than as one blended figure, and the manufacturing facility identifier.
Circularity. Carbon footprint, expected lifetime and performance parameters, state of health and state of charge, dismantling and safe removal information, and separate collection and end of life information including what the end user is meant to do.
Compliance. Conformity documentation and test reports, and the supply chain due diligence report.
Two properties of that list are worth pausing on, because they are the ones that surprise people who have only built product catalogues before.
Some of it is per unit, not per model. State of health is a property of one physical battery and it decays. A model level catalogue cannot carry it at all. A merchant who is short on that field does not need a better spreadsheet, they need a telemetry path, and that is a different project with a different budget.
And a dated reading is not optional decoration. An undated state of health figure is a number of unknown age presented as current, and a second life operator pricing a pack on a two year old reading is the actual harm. A reading without a date should be treated as missing, not as data.
Not everyone sees everything
Article 10 of ESPR requires the passport to differentiate access, and the battery dataset splits along three audiences: anyone who scans the code, people with a legitimate interest such as repairers, remanufacturers, recyclers and second life operators, and authorities such as market surveillance, customs and notified bodies.
This is the part that gets built wrong most often, usually with good intentions. A passport that serves every field to every scanner is not a more generous passport. It is your supplier facility list, your due diligence report and your conformity file, published, permanently, to anyone with a phone. We wrote a separate piece on how the access tiers work and why withholding has to be disclosed rather than silent.
How it is reached
The passport is reached from a data carrier on the product, and Articles 11 and 12 require the identifier behind it to be persistent and free of vendor lock in. Article 77(6) of the Batteries Regulation is more pointed: the code on the battery has to resolve to a unique, permanent address serving that battery's passport. A QR pointing at a product marketing page does not satisfy that, and it stops working the first time you replatform.
The carrier form the Commission's preparatory work points at is GS1 Digital Link, built over the GTIN you already have. It is a strong candidate rather than a legal designation, and it should be described that way. The mechanics, including why a lot or serial qualifier narrows the answer and must never widen back to the model, are in our piece on the QR code and GS1 Digital Link.
The registry
Article 13 tasks the Commission with a digital product passport registry, and Implementing Regulation (EU) 2026/1778 lays down how it operates, with the registration record described in its Articles 8 and 9.
Two things follow that are easy to get wrong in a vendor pitch. The registration identifier is minted by the Commission, so any tool showing you one it generated itself is showing you a forged regulatory reference. And preparing a registration record is not the same act as submitting it. We prepare the record, validate it, and tell you what is still missing. We do not post it, because we hold no credentials for the interface.
What to do now, in order
- Find out whether you are actually in scope for anything. For batteries this is a specific question about kind and capacity, not a category label. Everyone else is at the framework level, which means no date and no field list.
- Fix your identifiers. A GTIN per product, correct, stable, and yours. Every dataset adopted or drafted so far starts here, and no passport work of any kind survives a broken identifier.
- Record the responsible economic operator and the country of manufacture. Both appear in every dataset so far, and country of manufacture is already required of textile sellers under Regulation (EU) 1007/2011 on textile fibre names and labelling. Collecting them early carries no regret.
- Ask your suppliers now for the slow fields. Facility identifiers, recycled content per metal, substance data and due diligence documentation take quarters to obtain, not days. This is the piece with a real lead time, and it is the same work whatever the eventual field list turns out to be.
- Decide the access tier of a field before you publish it. A field published cannot be unpublished.
What nobody can honestly tell you yet
For any group without an adopted delegated act, nobody knows the final field list, the granularity, the access split or the date. Anyone who tells you otherwise is selling a forecast as a fact.
What is knowable is how much of a named, cited dataset you already hold, and where the gaps are. That is a coverage measure, and it is deliberately not a compliance claim: coverage counts data, and compliance is a legal conclusion about conformity procedures that no software vendor is in a position to reach on your behalf.
That is exactly what our Digital Product Passport tooling does. Every field on your list names the regulation and the article that puts it there, law in force is scored separately from what is merely expected so neither can flatter the other, and where our own schema has no column for something a dataset asks for we report that as our gap rather than counting it against you.
None of this is legal advice. We cite the instrument and the article precisely so your own counsel can check the reading against the text instead of taking our word for it.
Related Topics
Ready to Automate Your Shopify Store?
19 operations keep running between your decisions, so less waits on you.
Start for Free