DPPAutomate
NewBattery Regulation 2027 compliance pack is live.Read
DPPAutomate

Digital Product Passport Requirements 2026: What Data Goes In and Who Can See It

Most guides list passport fields and stop. This one maps each data element to its access tier, so you know what a competitor, a recycler and a market surveillance authority can each pull from your product.

TechnologyBy DPPAutomate TeamPublished September 11, 202612 min read
digital product passport data requirements split across three access tiers

Regulation (EU) 2024/1781, the Ecodesign for Sustainable Products Regulation, names twenty product parameters in Annex I and twelve categories of passport content in Annex III, and it assigns exactly zero of them to a fixed access level. The tiering is real and written into the law, but the per-field decision sits where most summaries never look: in the delegated act for each product group. That is why "what goes in a Digital Product Passport" has no single answer, and why the answer that matters to you is not a field list. It is which of your data becomes public, which reaches your repairers, recyclers and dealers, and which stays with market surveillance authorities and the Commission.

The DPPAutomate team read Articles 9 to 13 and Annex III of ESPR, Article 77 and Annex XIII of the Battery Regulation, Commission Implementing Regulation (EU) 2026/1778 on the passport registry, and Commission Implementing Decision (EU) 2026/1736 on the harmonised standards, directly on eur-lex.europa.eu. Every date, article number and data element below was checked against those texts on 27 August 2026. Where a product group has no adopted delegated act, this article says so instead of inventing a field list.

What ESPR fixes for every passport

ESPR is a framework. It fixes the shape of the passport for every product group and leaves the contents to the product-specific delegated act.

Article 9(1) is the hard edge: products "can only be placed on the market or put into service if a digital product passport is available", and its data "shall be accurate, complete and up to date". Article 9(2) then lists the nine things a delegated act must specify: the data drawn from Annex III, one or more data carriers, the carrier's layout and positioning, whether the passport sits at model, batch or item level, how it reaches customers before they are bound by a contract, the actors that are to have access and to what data, who may create or update data and what they may change, the arrangements for updating, and how long the passport must stay available, which must be at least the product's expected lifetime.

Annex III is the outer boundary of what a delegated act may reach for, and it is a menu rather than a mandate: the unique product identifier, the GTIN or equivalent under ISO/IEC 15459-6, commodity codes such as TARIC, compliance documentation including the declaration of conformity and technical documentation, manuals and safety information, manufacturer and importer details with their unique operator identifiers and EORI number, other operator identifiers, unique facility identifiers, the EU-established responsible operator, the backup service provider reference, and whatever Article 7(2)(b) or 7(5) requires.

That last entry is where most of the work sits. Article 7(5) requires substances of concern to be trackable through the life cycle: IUPAC name or numerical code, EC and CAS numbers, the location of the substance within the product, the concentration or range at product, component or spare-part level, safe-use instructions and end-of-life handling. Article 7(7) adds that this information must sit on the product itself or be reachable through its data carrier. That is a physical requirement, not only a database one.

Article 10 then sets seven essential requirements that hold whatever the product group: a data carrier connecting to a persistent unique product identifier, physically present on the product, its packaging or accompanying documentation; carrier and identifier compliant with the ISO/IEC 15459 series until harmonised standards are cited; data that is open-standard, interoperable, machine-readable, structured, searchable and transferable "without vender lock-in"; no customer personal data without explicit consent under Article 6 of Regulation (EU) 2016/679; data at the granularity the delegated act sets; and access governed by that act's product-group access rights. Two adjacent duties catch brands out: Article 10(3) requires you to give dealers and online marketplaces a digital copy of the carrier or identifier free of charge within five working days of a request, and Article 10(4) requires a backup copy held through a digital product passport service provider.

The three access tiers in ESPR

ESPR never uses the word "tier". It builds tiering out of three separate mechanisms, and reading them together produces the structure most competitor pages describe only loosely.

Tier 1, open to everyone. Article 14 requires the Commission to run a publicly accessible web portal where stakeholders search and compare passport data "in a manner that is consistent with their respective access rights". Article 9(2)(e) requires the delegated act to specify how the passport reaches customers before they are bound by a contract of sale, hire or hire purchase, including in distance selling. Article 7(7) puts substances-of-concern data on the product or its carrier. Anything a delegated act places here is readable by anyone who scans, including your competitors.

Tier 2, specified actors with credentialed access. Article 11(b) enumerates who must get "free of charge and easy access" based on their respective access rights: customers, manufacturers, importers, distributors, dealers, professional repairers, independent operators, refurbishers, remanufacturers, recyclers, market surveillance authorities, customs authorities, civil society organisations, trade unions "and other relevant actors". Article 9(2)(f) is where the delegated act decides which of them sees which fields. Article 11(f) restricts write access the same way, and Article 11's fourth paragraph empowers the Commission to adopt implementing acts on issuing and verifying those actors' digital credentials.

Tier 3, authorities and the Commission only. Article 4(6)(a)(iii) lets a delegated act require manufacturers, authorised representatives or importers to make parts of the technical documentation digitally available to the Commission or market surveillance authorities without a request being necessary. Article 36(3) supplies the operative sentence: "Where the digital product passport is available, technical documentation shall be made available through it." Article 13(6) gives the Commission, competent national authorities and customs authorities access to the registry. Article 36(2) obliges economic operators, on a reasoned request, to name their upstream supplier and downstream customers with quantities and exact models, for ten years.

The stated reason for tiering is in the recitals: the passport must allow "differentiated access to the data in the digital product passport depending on the type of data and the typology of stakeholders", to optimise access "while also protecting intellectual property rights". The Toy Safety Regulation says the same operationally, requiring the Commission to weigh "the need to protect confidential business information and trade secrets" under Directive (EU) 2016/943 when it sets toy passport access rights (Regulation (EU) 2025/2509, Article 49(1)).

Which data element sits in which tier

The table maps representative Annex III elements to the tier they realistically land in, with the legal basis for each. Read the middle column as an expectation shaped by ESPR's own structure and by the two tiered lists already in binding law, not as a decision already made for your product group. Only a delegated act makes it binding for you.

Data elementExpected tierBasis
Unique product identifier, data carrierPublicAnnex III(b); Article 10(1)(a) makes it scannable by anyone
Manufacturer name, address, operator identifierPublicAnnex III(g); already required on distance-selling offers by Article 36(1)
EU responsible operator, importer, EORIPublic in partAnnex III(j), (k); a market-surveillance contact point
Declaration of conformity, certificatesPublicAnnex III(e); the Toys Regulation places the DoC in the passport outright
Substances of concern: name, location, concentrationPublicArticle 7(5) with Article 7(7), which forces it onto the product or carrier
Repairability, durability, carbon footprint scoresPublicArticle 7(2)(b)(i); Article 7(4) classes of performance only work if public
Install, use, maintain, repair and return instructionsPublicArticle 7(2)(b)(ii); written for customers
Disassembly, reuse, refurbishment, recycling instructionsSpecified actorsArticle 7(2)(b)(iii) addresses treatment facilities; actors named in Article 11(b)
Detailed composition, part numbers, spare-part sourcesSpecified actorsThe binding precedent: Battery Regulation Annex XIII point 2
Individual-item lifecycle and in-use dataSpecified actorsBattery Regulation Annex XIII point 4; write rights under Article 9(2)(g)
Operator and facility identifiers for upstream sitesSpecified actorsAnnex III(h), (i); exposes your supply base
Technical documentation, test reports, calculationsAuthorities onlyArticle 4(6)(a)(iii) with Article 36(3); Battery Annex XIII point 3
Supplier and customer names, quantities, modelsAuthorities only, on requestArticle 36(2); reachable from the same record for ten years
Registry entry: identifiers, commodity codeAuthorities onlyArticle 13(1) and 13(6); Regulation (EU) 2026/1778, Article 8(9)

Two structural points matter more than any single row. A delegated act can move a row. And nothing stops a delegated act from splitting one: publishing a carbon footprint value while reserving the calculation file, or publishing a recycled-content percentage while reserving the supplier declarations behind it. That split is the normal shape, not the exception.

What each tier exposes commercially

The compliance question is "which article". The board question is "who can read our data".

What a competitor can see. Everything in tier 1, at item granularity if your delegated act sets item-level passports, for every unit you ship. That is a machine-readable feed of your material composition at the level the substances-of-concern rules force, your declared performance class, your manufacturing responsibility chain and your compliance documentation. Article 14's portal exists specifically to "search for and compare" across passports, and Article 10(1)(d) requires the data to be machine-readable, structured and searchable. Competitive benchmarking of your public tier is not a leak, it is the design intent. Plan the public tier as published product marketing, because that is what it becomes.

What a recycler, repairer or dealer can see. Tier 2 is where your bill of materials lives. In the battery precedent that means cathode, anode and electrolyte materials, part numbers, spare-part sources, exploded diagrams, disassembly sequences, fastening types and tool lists. A recycler needs it to recover material; a competitor would happily buy it. That is why tier 2 runs through credentials rather than a public URL, and why Article 11 empowers the Commission to standardise how those credentials are issued and verified. Implementing Regulation (EU) 2026/1778 already operationalises the same idea at registry level: Article 5 defines a verification process, and only actors with "verified" status get access, with their role and permitted actions set by the applicable delegated act.

What only an authority can see. Tier 3 is the compliance evidence layer: test reports, whichever parts of the technical documentation a delegated act pulls forward, and the registry record. The commercial consequence is that Article 36(3) turns your passport into the delivery channel for technical documentation. If a delegated act requires digital availability of test data, it goes through the passport, not through an email to an inspector. The internal question stops being "who answers the auditor" and becomes "who keeps the evidence current in the system of record".

What nobody gets. Article 10(1)(e) bars storing customer personal data without explicit consent under Article 6 of the GDPR. Article 11's closing paragraph bars a passport service provider from selling, reusing or processing your data beyond what is necessary to provide the service, unless you specifically agree. If you are evaluating vendors, read that clause first.

The battery passport: the one specified list in force

The battery passport is the only fully specified, legally fixed, tiered data list in force, which makes it the reference implementation for everything above. Article 77(1) of Regulation (EU) 2023/1542 requires an electronic record from 18 February 2027 for each LMT battery, each industrial battery above 2 kWh and each electric vehicle battery placed on the market or put into service. Article 77(2) splits the content three ways; Annex XIII fills in four blocks.

Annex XIII blockWho sees itRepresentative content
Point 1, model levelThe publicAnnex VI Part A label data, composition and chemistry, hazardous substances, critical raw materials, carbon footprint (Article 7), responsible sourcing (Article 52(3)), recycled content (Article 8(1)), renewable share, capacity, voltage, expected cycles, round-trip efficiency, warranty, declaration of conformity (Article 18)
Point 2, model levelPersons with a legitimate interest and the CommissionDetailed composition including cathode, anode and electrolyte; part numbers and spare-part sources; dismantling information including exploded diagrams, disassembly sequences, fastening types, tools and cell layout; safety measures
Point 3, model levelNotified bodies, market surveillance authorities and the CommissionResults of test reports proving compliance
Point 4, individual batteryPersons with a legitimate interestPerformance and durability values (Article 10(1)), state of health (Article 14), status as original, repurposed, re-used, remanufactured or waste, and use data including charge cycles, negative events, operating temperature and state of charge

Note the asymmetry. Chemistry and critical raw materials are public at model level under point 1(b), while the detailed cathode, anode and electrolyte formulation is restricted under point 2(a). Disclose enough to make circularity possible, withhold enough to protect the formulation.

Article 77(9) required the Commission to adopt, by 18 August 2026, an implementing act specifying who counts as a person with a legitimate interest, which information in points 2 and 4 they receive, and how far they may download, share, publish and re-use it. We could not confirm that act had been adopted as of 27 August 2026. Until it is, the operative test remains the three criteria in Article 77(9) itself: necessity for evaluating the battery's status and residual value, necessity for reuse, repurposing, remanufacturing or recycling decisions, and keeping access to commercially sensitive information "limited to the minimum necessary". Our companion guide on the battery passport data model covers the model, batch and item structure behind these blocks.

Product groups that have a data list, and those that do not

This is where most competitor pages invent something. Here is the checked position on 27 August 2026.

The ESPR working plan, COM(2025) 187 final of 16 April 2025, sets the queue and its indicative adoption years. Those are planning dates for adopting an act, not compliance dates for you: under ESPR Article 4(4), a delegated act's date of application is normally at least 18 months after entry into force.

Product groupWhere the data list comes fromStatus on 27 August 2026
Batteries: LMT, industrial above 2 kWh, EVRegulation (EU) 2023/1542, Article 77 and Annex XIIISpecified in the regulation. Applies from 18 February 2027
ToysRegulation (EU) 2025/2509, Article 19 and Annex VIContent specified in the regulation. Applies from 1 August 2030. Access rights deferred to a delegated act under Article 49(1)(d)
Construction productsRegulation (EU) 2024/3110, Article 76Passport and registry duty established in the regulation
Detergents and end-user surfactantsRegulation (EU) 2026/405, Article 21Passport and registry duty established in the regulation
Iron and steel, aluminiumESPR Article 4 delegated actNo adopted act. Working plan indicates 2026 for iron and steel, 2027 for aluminium
Textiles and apparelESPR Article 4 delegated actNo adopted act. Working plan indicates 2027
TyresESPR Article 4 delegated actNo adopted act. Working plan indicates 2027
FurnitureESPR Article 4 delegated actNo adopted act. Working plan indicates 2028
MattressesESPR Article 4 delegated actNo adopted act. Working plan indicates 2029
Electronics and ICTESPR horizontal delegated actsNo adopted act. Working plan indicates 2027 for repairability including scoring, 2029 for recycled content and recyclability of electrical and electronic equipment

The construction, toy and detergent rows are confirmed by Article 1(1) of Implementing Regulation (EU) 2026/1778, which names each instrument as a source of registry-registrable passports. The delegated acts adopted under ESPR so far concern the destruction of unsold consumer products, not passport content. We found no adopted Article 4 delegated act specifying digital product passport data elements for any product group as of 27 August 2026. So there is no binding data element list yet for a digital product passport for textiles, and none for a digital product passport for electronics, furniture, tyres or steel.

What exists instead is preparatory work you can read. The Joint Research Centre runs the technical studies behind each delegated act and publishes the working documents, including DPP content proposals, on its product bureau site. CIRPASS, the Commission-funded coordination action that ran to March 2024, produced a cross-sector DPP definition and data model with roadmaps for electronics, batteries and textiles, and CIRPASS-2 continues it as sector pilots. For textiles or electronics, the CIRPASS material and the JRC study for your group are the best available proxy for your eventual list and the right thing to model against now. Our pages on textile DPP requirements and electronics DPP track each group's preparatory work, and which products need a DPP covers scope and timing.

Data carrier, identifier and registry requirements

The digital product passport data carrier has three separate legal hooks, and brands routinely satisfy one and miss the others.

Placement and format come first. Article 10(1)(b) requires the carrier to be physically present on the product, its packaging or accompanying documentation, with Article 9(2)(c) giving the delegated act control of layout and positioning. Article 10(1)(c) requires carrier and unique product identifier to comply with ISO/IEC 15459-1:2014 to 15459-6:2014 or equivalent until harmonised standards are cited. Article 12 governs the identifiers, including the duty on whoever creates or updates a passport to request a unique operator identifier on behalf of an actor that lacks one.

That "until harmonised standards are cited" clause is no longer hypothetical. Commission Implementing Decision (EU) 2026/1736 of 14 July 2026 cited six harmonised standards in the Official Journal: EN 18216:2026 on data exchange protocols, EN 18219:2026 on unique identifiers, EN 18220:2026 on data carriers, EN 18221:2026 on data storage, archiving and persistence, EN 18222:2026 on APIs for passport lifecycle management and searchability, and EN 18223:2026 on system interoperability. Under ESPR Article 41(2), a passport conforming to a cited harmonised standard is presumed to conform to the requirements of Articles 10 and 11 it covers. That answers the digital product passport standard question: the presumption route now exists, drafted by CEN, Cenelec and ETSI through CEN/CLC/JTC 24 under Commission Implementing Decision C(2024) 5423.

Nothing names the QR code as the only permitted carrier, but a QR code is what most European brands will print, because a QR code is the cheapest carrier that survives being small. Most will carry the identifier inside it as a GS1 Digital Link URI, because GS1 Digital Link expresses GS1 identifiers as resolvable web URIs and a GS1-conformant resolver can serve different link types to different requesters from a single scan. That resolver behaviour is the natural mechanism for tiered access: one carrier, several destinations, chosen by who is asking. Our GS1 Digital Link page covers the syntax, DPP identifiers covers GTIN, SKU, batch and serial, and creating QR codes at scale covers production volume.

The third hook is registration. ESPR Article 13 required the Commission to set up a digital registry by 19 July 2026; the Commission announced the registry live on 20 July 2026, and Implementing Regulation (EU) 2026/1778 of 16 July 2026 lays down its arrangements. Two provisions change your project plan. Article 8 requires registration at the granularity the applicable law sets, at the most granular level where several instruments disagree, and requires an item-level passport to carry linked batch and model identifiers where those designs exist. Article 12 establishes a semantic repository holding the authoritative data models, semantic definitions, role definitions and multilingual labels for every product group, free of charge through documented public APIs. That repository, not a PDF annex, is where your field mappings will come from.

Where your passport data lives today

For every data family above, the real question is not what the regulation calls it but which of your systems already holds it, and in what state.

Data familyUsual system of recordTypical gap
Identifiers, GTIN, model and SKU structureERP or PIMExists, but rarely at batch or item granularity, often duplicated across regions
Commercial attributes, images, manualsPIM or DAMClean, but versioned for campaigns rather than a ten-year retention duty
Bill of materials, part numbers, spare partsPLM or ERPEngineering BOMs are structured for manufacturing, not for disassembly sequences or recycler-readable composition
Material composition and substances of concernSupplier declarations, spreadsheets, emailThe largest gap. Location within the product and concentration at component level usually exist nowhere
Carbon footprint, recycled and renewable contentLCA tool output, supplier declarationsHeld at corporate or category level; rarely per functional unit, per model, with a traceable calculation file
Test reports and conformity certificatesDocument management, lab portalsPDFs with no structured link to the model or batch they cover
Declaration of conformity, technical documentationQuality or regulatory affairs file shareDocuments, not data an API can serve into a passport
Facility and operator identifiers for upstream sitesNowhereUsually has to be created; ESPR Article 12(2) and 12(3) put the request duty on the passport creator
Lifecycle and in-use eventsService, warranty or telematics systems, or nowhereFragmented across service partners, rarely joined to the item identifier

Two patterns show up in every data inventory. Roughly the top half of that table already exists and needs mapping, while the bottom half has to be gathered, and gathering means a specific question to a named supplier rather than a general survey. And the fields you have to gather are disproportionately the ones a delegated act will place in the public or specified-actor tier, because those are the circularity fields the instrument exists to expose.

DPPAutomate is built around that split: import what your ERP and PIM already hold, then issue supplier declaration requests for the fields that do not exist yet and watch them land against the same product record, so the passport and the evidence behind it stay in one place. Our guide to ERP and PIM integration covers the mapping side.

What to do next

Three decisions separate a six-week project from an eighteen-month one, and all three are data decisions rather than software decisions.

Decide granularity first. Model, batch or item changes every downstream estimate, because Implementing Regulation (EU) 2026/1778 Article 8 requires an item-level passport to carry linked batch and model identifiers, and because item-level lifecycle data has no home in most estates today. Our guide on whether you need a separate passport per product works through that choice.

Then run the tier assignment as a business exercise, not a legal one: mark each candidate field public, specified-actor or authority-only using the table above, and hand the public column to whoever owns competitive positioning. Any disagreement you surface there is one you would otherwise discover on the day your first passport goes live. Then inventory the gap, naming for every field in the bottom half of the systems table the supplier who holds it and the question you will ask them. The project-level sequence is in our DPP requirements checklist, and what a Digital Product Passport is shows rendered examples if you want to see the output before scoping the input.

The instrument that binds you is knowable today even where your field list is not. Batteries have Annex XIII. Toys have Annex VI. Everyone else has ESPR Articles 9 to 13 for the shape, the EN 18xxx family for the plumbing, the registry's semantic repository for the vocabulary, and a delegated act still to come for the contents. Build against the shape now and the contents become a mapping exercise instead of a rebuild.

This article is general information about EU product regulation, not legal advice. Delegated acts change what applies to your products and when. Confirm your own obligations against the current text of the instruments cited above, or with your legal counsel.

Not sure which delegated act lands on your products first? Check your readiness in under five minutes.

FAQ

Common questions,
answered.

Quick answers to what readers ask most about this topic.

Talk to a compliance expert
What must go into a Digital Product Passport?+

ESPR Article 9(2) requires each product group's delegated act to specify the data, drawn from the Annex III menu: unique product identifier, GTIN, commodity codes, compliance documentation, manuals and safety information, manufacturer and importer details, unique operator and facility identifiers, and the backup service provider reference. Article 7(5) adds substances-of-concern tracking. The exact list is fixed per product group by its delegated act, not by ESPR itself.

Which Digital Product Passport data is public and which is restricted?+

ESPR builds three levels. Public data is what the Commission web portal exposes under Article 14 and what customers see before purchase under Article 9(2)(e). Specified actors named in Article 11(b), including repairers, recyclers, refurbishers and dealers, get credentialed access to the fields their delegated act assigns them. Technical documentation and test reports go to market surveillance authorities and the Commission under Article 4(6)(a)(iii) and Article 36(3).

What are the requirements for the EU battery passport?+

Regulation (EU) 2023/1542 Article 77 requires a battery passport from 18 February 2027 for LMT batteries, industrial batteries above 2 kWh and EV batteries. Annex XIII fixes the content in four blocks: public model data, restricted composition and dismantling data for persons with a legitimate interest, test reports for notified bodies and authorities, and individual-battery lifecycle data. Our [battery passport data model](/blog/battery-passport-data-model) guide covers the field structure.

How does a Digital Product Passport work?+

A data carrier on the product, its packaging or its documentation resolves to a persistent unique product identifier, per ESPR Article 10(1)(a) and (b). Scanning it opens the passport, which is stored by the economic operator or a passport service provider, not by the Commission. What you see depends on your access rights: a consumer gets the public tier, a credentialed recycler gets more, an authority gets the compliance evidence.

What is the purpose of a Digital Product Passport?+

ESPR Article 9(3) states it directly: passport requirements must ensure value chain actors can easily access and understand the product information relevant to them, facilitate compliance verification by competent national authorities, and improve traceability along the value chain. In practice that means making circularity decisions possible at end of life and making market surveillance work on products that move across borders.

Is there a Digital Product Passport for textiles or electronics yet?+

Not as a binding data list. Textiles and apparel rank first among final products in the ESPR working plan, COM(2025) 187 final, with an indicative adoption year of 2027; electronics is addressed through horizontal measures indicated for 2027 and 2029. No such act had been adopted when we checked on 27 August 2026, and under ESPR Article 4(4) application normally follows at least 18 months later.

What standard does a Digital Product Passport data carrier have to meet?+

Until harmonised standards were cited, ESPR Article 10(1)(c) pointed to ISO/IEC 15459-1:2014 to 15459-6:2014. Commission Implementing Decision (EU) 2026/1736 of 14 July 2026 has now cited six harmonised standards, including EN 18220:2026 on data carriers and EN 18219:2026 on unique identifiers. Under ESPR Article 41(2), conforming to them gives a presumption of conformity with the parts of Articles 10 and 11 they cover.

Can you show an example of a Digital Product Passport?+

The battery passport is the only fully specified example in force, so its Annex XIII blocks are the most realistic model of what a rendered passport contains and how it splits by viewer. Our guide to [what a Digital Product Passport is](/blog/what-is-digital-product-passport) walks through rendered examples, and [electronics DPP repairability and recycling](/blog/electronics-dpp-repairability-recycling) shows how a non-battery group is preparing its content.

Share this articleLinkedInX