Resources

EU Digital Product Passport (DPP) Compliance Hub

The complete framework for ESPR compliance, sector timelines, data carrier standards, and supplier readiness.

Definition

The Digital Product Passport (DPP) is an EU-mandated digital record under the Ecodesign for Sustainable Products Regulation (ESPR). It tracks material composition, supply chain origin, carbon footprint, and repairability through a scannable data carrier such as a QR code.

Source: SupplyPassport

Timeline

Mandatory EU Compliance Timeline

Enforcement dates, legal basis, and required data points by sector, so you know exactly when your product group must carry a Digital Product Passport.

Mandatory EU Digital Product Passport compliance timeline by sector, including enforcement date, legal basis, and required data points
Sector / Product GroupEnforcement DateLegal BasisRequired Data Points
Batteries (EV, Industrial, LMT)Feb 18, 2027EU Battery Regulation 2023/1542Cell chemistry, carbon footprint, recycled content, durability
Unsold Textiles & ApparelJuly 2026 (Ban) / 2027 (DPP)ESPR Delegated ActFiber composition, origin, repairability, circularity index
Iron, Steel & AluminiumQ4 2026 – 2027ESPR Delegated ActEmbodied carbon, scrap ratio, supply chain origin
Electronics & ICT2026 – 2028 (Staggered)Energy-Label Carryover / ESPREnergy rating, spare part availability, disassembly guide
Furniture & Mattresses2028 – 2029ESPR Delegated ActRecycled content, chemical safety, durability metrics

Stakeholders

Who is Affected?

DPP obligations span the entire supply chain, from the brand placing a product on the market to the supplier shipping into the EU.

EU Manufacturers & Brands

Primary duty holders responsible for creating the DPP, aggregating tier-N supplier data, and attaching the data carrier.

Non-EU Exporters

Must supply compliant material data to EU buyers or face customs blocks at entry.

Importers & Distributors

Legal gatekeepers liable for verifying valid DPP records before placing products on the EU market.

Frequently Asked Questions

DPP Compliance FAQs

Is a DPP mandatory for non-EU suppliers?+

Yes. If a non-EU company exports products into the EU market within an affected product category, the goods must carry a compliant DPP regardless of where the manufacturer is headquartered.

What data carrier technology is required for a DPP?+

The EU mandates open, standardized data carriers such as QR codes, NFC tags, or RFID chips that route to a Unique Registration Identifier (URI) linked to the official EU DPP Registry.

What is the penalty for non-compliance with the EU DPP?+

Enforcement is managed at the member-state level, where non-compliant goods will be held at customs, blocked from sale, or subjected to commercial fines.

Will sensitive Bill of Materials (BOM) and trade secrets be visible to the public in a DPP?+

No. The EU DPP framework mandates granular role-based access control. Public users (consumers) only see high-level sustainability, repairability, and disposal information. Proprietary operational data, exact chemical formulas, and tier-N supplier identities are restricted to verified market surveillance authorities, auditors, and certified recyclers.

How are access rights managed for restricted DPP data?+

Data access is authorized via official EU identity verification protocols (such as eIDAS) and role-specific permissions. A user scanning a QR code on a product gets redirected based on their authenticated credential: consumers see public attributes, while an authorized customs officer or notified body unlocks restricted compliance records.

What physical data carriers are allowed for the EU Digital Product Passport?+

The EU mandates open, ISO-compliant data carriers affixed directly to the product, packaging, or accompanying documentation. Accepted carriers include QR codes (linked via GS1 Digital Link URIs), NFC tags, and RFID transponders. Barcodes must resolve to a Unique Registration Identifier (URI) registered in the EU DPP Registry.

Where is the actual DPP data hosted—on EU servers or on our own platform?+

Raw product data remains decentralized, hosted by the economic operator or an authorized DPP Service Provider (like SupplyPassport). Only mandatory metadata and unique identifiers (URIs) are transmitted to the central EU DPP Registry to allow searchability and validation by market surveillance.

How will EU Customs inspect Digital Product Passports at the border?+

The central EU DPP Registry integrates directly with the EU Customs Single Window Certificates Exchange (EU CSW-CERTEX). When an import declaration is lodged, customs algorithms cross-reference the consignment’s Unique Product Identifier against the EU Registry automatically. Shipments lacking a valid, active URI will be flagged for border holds or refusal of entry.

What is the difference between a CE Mark and a Digital Product Passport?+

The CE Mark is a manufacturer’s declaration that a product meets EU safety, health, and environmental standards. The DPP is the underlying digital repository that stores the evidence (e.g., test reports, carbon footprint calculation, bill of materials) proving those claims. For affected product categories, a CE mark cannot be legally affixed without a valid, linked DPP.

How far down the supply chain must a company collect data for a DPP?+

Depth depends on the specific product category’s delegated act. For batteries, data collection extends to Tier-3 mine sites and processing facilities for primary materials (cobalt, lithium, nickel, graphite). For textiles, traceability extends to yarn spinners, dye houses, and raw fiber suppliers.

What happens if a upstream supplier refuses to share compliance data?+

Under ESPR rules, products containing unverified components cannot receive a valid DPP URI, making them illegal to place on the EU market. Platforms like SupplyPassport utilize encrypted request portals to allow suppliers to submit verified data directly to the registry without exposing their proprietary pricing or sub-tier vendor lists to their customers.

Ready to get ahead of the DPP deadlines?