Regulation (EU) 2024/1781, the Ecodesign for Sustainable Products Regulation, names twenty product parameters in Annex I and twelve categories of passport content in Annex III, and it assigns exactly zero of them to a fixed access level. The tiering is real and written into the law, but the per-field decision sits where most summaries never look: in the delegated act for each product group. That is why "what goes in a Digital Product Passport" has no single answer, and why the answer that matters to you is not a field list. It is which of your data becomes public, which reaches your repairers, recyclers and dealers, and which stays with market surveillance authorities and the Commission.
The DPPAutomate team read Articles 9 to 13 and Annex III of ESPR, Article 77 and Annex XIII of the Battery Regulation, Commission Implementing Regulation (EU) 2026/1778 on the passport registry, and Commission Implementing Decision (EU) 2026/1736 on the harmonised standards, directly on eur-lex.europa.eu. Every date, article number and data element below was checked against those texts on 27 August 2026. Where a product group has no adopted delegated act, this article says so instead of inventing a field list.
What ESPR fixes for every passport
ESPR is a framework. It fixes the shape of the passport for every product group and leaves the contents to the product-specific delegated act.
Article 9(1) is the hard edge: products "can only be placed on the market or put into service if a digital product passport is available", and its data "shall be accurate, complete and up to date". Article 9(2) then lists the nine things a delegated act must specify: the data drawn from Annex III, one or more data carriers, the carrier's layout and positioning, whether the passport sits at model, batch or item level, how it reaches customers before they are bound by a contract, the actors that are to have access and to what data, who may create or update data and what they may change, the arrangements for updating, and how long the passport must stay available, which must be at least the product's expected lifetime.
Annex III is the outer boundary of what a delegated act may reach for, and it is a menu rather than a mandate: the unique product identifier, the GTIN or equivalent under ISO/IEC 15459-6, commodity codes such as TARIC, compliance documentation including the declaration of conformity and technical documentation, manuals and safety information, manufacturer and importer details with their unique operator identifiers and EORI number, other operator identifiers, unique facility identifiers, the EU-established responsible operator, the backup service provider reference, and whatever Article 7(2)(b) or 7(5) requires.
That last entry is where most of the work sits. Article 7(5) requires substances of concern to be trackable through the life cycle: IUPAC name or numerical code, EC and CAS numbers, the location of the substance within the product, the concentration or range at product, component or spare-part level, safe-use instructions and end-of-life handling. Article 7(7) adds that this information must sit on the product itself or be reachable through its data carrier. That is a physical requirement, not only a database one.
Article 10 then sets seven essential requirements that hold whatever the product group: a data carrier connecting to a persistent unique product identifier, physically present on the product, its packaging or accompanying documentation; carrier and identifier compliant with the ISO/IEC 15459 series until harmonised standards are cited; data that is open-standard, interoperable, machine-readable, structured, searchable and transferable "without vender lock-in"; no customer personal data without explicit consent under Article 6 of Regulation (EU) 2016/679; data at the granularity the delegated act sets; and access governed by that act's product-group access rights. Two adjacent duties catch brands out: Article 10(3) requires you to give dealers and online marketplaces a digital copy of the carrier or identifier free of charge within five working days of a request, and Article 10(4) requires a backup copy held through a digital product passport service provider.
The three access tiers in ESPR
ESPR never uses the word "tier". It builds tiering out of three separate mechanisms, and reading them together produces the structure most competitor pages describe only loosely.
Tier 1, open to everyone. Article 14 requires the Commission to run a publicly accessible web portal where stakeholders search and compare passport data "in a manner that is consistent with their respective access rights". Article 9(2)(e) requires the delegated act to specify how the passport reaches customers before they are bound by a contract of sale, hire or hire purchase, including in distance selling. Article 7(7) puts substances-of-concern data on the product or its carrier. Anything a delegated act places here is readable by anyone who scans, including your competitors.
Tier 2, specified actors with credentialed access. Article 11(b) enumerates who must get "free of charge and easy access" based on their respective access rights: customers, manufacturers, importers, distributors, dealers, professional repairers, independent operators, refurbishers, remanufacturers, recyclers, market surveillance authorities, customs authorities, civil society organisations, trade unions "and other relevant actors". Article 9(2)(f) is where the delegated act decides which of them sees which fields. Article 11(f) restricts write access the same way, and Article 11's fourth paragraph empowers the Commission to adopt implementing acts on issuing and verifying those actors' digital credentials.
Tier 3, authorities and the Commission only. Article 4(6)(a)(iii) lets a delegated act require manufacturers, authorised representatives or importers to make parts of the technical documentation digitally available to the Commission or market surveillance authorities without a request being necessary. Article 36(3) supplies the operative sentence: "Where the digital product passport is available, technical documentation shall be made available through it." Article 13(6) gives the Commission, competent national authorities and customs authorities access to the registry. Article 36(2) obliges economic operators, on a reasoned request, to name their upstream supplier and downstream customers with quantities and exact models, for ten years.
The stated reason for tiering is in the recitals: the passport must allow "differentiated access to the data in the digital product passport depending on the type of data and the typology of stakeholders", to optimise access "while also protecting intellectual property rights". The Toy Safety Regulation says the same operationally, requiring the Commission to weigh "the need to protect confidential business information and trade secrets" under Directive (EU) 2016/943 when it sets toy passport access rights (Regulation (EU) 2025/2509, Article 49(1)).
Which data element sits in which tier
The table maps representative Annex III elements to the tier they realistically land in, with the legal basis for each. Read the middle column as an expectation shaped by ESPR's own structure and by the two tiered lists already in binding law, not as a decision already made for your product group. Only a delegated act makes it binding for you.
| Data element | Expected tier | Basis |
|---|---|---|
| Unique product identifier, data carrier | Public | Annex III(b); Article 10(1)(a) makes it scannable by anyone |
| Manufacturer name, address, operator identifier | Public | Annex III(g); already required on distance-selling offers by Article 36(1) |
| EU responsible operator, importer, EORI | Public in part | Annex III(j), (k); a market-surveillance contact point |
| Declaration of conformity, certificates | Public | Annex III(e); the Toys Regulation places the DoC in the passport outright |
| Substances of concern: name, location, concentration | Public | Article 7(5) with Article 7(7), which forces it onto the product or carrier |
| Repairability, durability, carbon footprint scores | Public | Article 7(2)(b)(i); Article 7(4) classes of performance only work if public |
| Install, use, maintain, repair and return instructions | Public | Article 7(2)(b)(ii); written for customers |
| Disassembly, reuse, refurbishment, recycling instructions | Specified actors | Article 7(2)(b)(iii) addresses treatment facilities; actors named in Article 11(b) |
| Detailed composition, part numbers, spare-part sources | Specified actors | The binding precedent: Battery Regulation Annex XIII point 2 |
| Individual-item lifecycle and in-use data | Specified actors | Battery Regulation Annex XIII point 4; write rights under Article 9(2)(g) |
| Operator and facility identifiers for upstream sites | Specified actors | Annex III(h), (i); exposes your supply base |
| Technical documentation, test reports, calculations | Authorities only | Article 4(6)(a)(iii) with Article 36(3); Battery Annex XIII point 3 |
| Supplier and customer names, quantities, models | Authorities only, on request | Article 36(2); reachable from the same record for ten years |
| Registry entry: identifiers, commodity code | Authorities only | Article 13(1) and 13(6); Regulation (EU) 2026/1778, Article 8(9) |
Two structural points matter more than any single row. A delegated act can move a row. And nothing stops a delegated act from splitting one: publishing a carbon footprint value while reserving the calculation file, or publishing a recycled-content percentage while reserving the supplier declarations behind it. That split is the normal shape, not the exception.
What each tier exposes commercially
The compliance question is "which article". The board question is "who can read our data".
What a competitor can see. Everything in tier 1, at item granularity if your delegated act sets item-level passports, for every unit you ship. That is a machine-readable feed of your material composition at the level the substances-of-concern rules force, your declared performance class, your manufacturing responsibility chain and your compliance documentation. Article 14's portal exists specifically to "search for and compare" across passports, and Article 10(1)(d) requires the data to be machine-readable, structured and searchable. Competitive benchmarking of your public tier is not a leak, it is the design intent. Plan the public tier as published product marketing, because that is what it becomes.
What a recycler, repairer or dealer can see. Tier 2 is where your bill of materials lives. In the battery precedent that means cathode, anode and electrolyte materials, part numbers, spare-part sources, exploded diagrams, disassembly sequences, fastening types and tool lists. A recycler needs it to recover material; a competitor would happily buy it. That is why tier 2 runs through credentials rather than a public URL, and why Article 11 empowers the Commission to standardise how those credentials are issued and verified. Implementing Regulation (EU) 2026/1778 already operationalises the same idea at registry level: Article 5 defines a verification process, and only actors with "verified" status get access, with their role and permitted actions set by the applicable delegated act.
What only an authority can see. Tier 3 is the compliance evidence layer: test reports, whichever parts of the technical documentation a delegated act pulls forward, and the registry record. The commercial consequence is that Article 36(3) turns your passport into the delivery channel for technical documentation. If a delegated act requires digital availability of test data, it goes through the passport, not through an email to an inspector. The internal question stops being "who answers the auditor" and becomes "who keeps the evidence current in the system of record".
What nobody gets. Article 10(1)(e) bars storing customer personal data without explicit consent under Article 6 of the GDPR. Article 11's closing paragraph bars a passport service provider from selling, reusing or processing your data beyond what is necessary to provide the service, unless you specifically agree. If you are evaluating vendors, read that clause first.
The battery passport: the one specified list in force
The battery passport is the only fully specified, legally fixed, tiered data list in force, which makes it the reference implementation for everything above. Article 77(1) of Regulation (EU) 2023/1542 requires an electronic record from 18 February 2027 for each LMT battery, each industrial battery above 2 kWh and each electric vehicle battery placed on the market or put into service. Article 77(2) splits the content three ways; Annex XIII fills in four blocks.
| Annex XIII block | Who sees it | Representative content |
|---|---|---|
| Point 1, model level | The public | Annex VI Part A label data, composition and chemistry, hazardous substances, critical raw materials, carbon footprint (Article 7), responsible sourcing (Article 52(3)), recycled content (Article 8(1)), renewable share, capacity, voltage, expected cycles, round-trip efficiency, warranty, declaration of conformity (Article 18) |
| Point 2, model level | Persons with a legitimate interest and the Commission | Detailed composition including cathode, anode and electrolyte; part numbers and spare-part sources; dismantling information including exploded diagrams, disassembly sequences, fastening types, tools and cell layout; safety measures |
| Point 3, model level | Notified bodies, market surveillance authorities and the Commission | Results of test reports proving compliance |
| Point 4, individual battery | Persons with a legitimate interest | Performance and durability values (Article 10(1)), state of health (Article 14), status as original, repurposed, re-used, remanufactured or waste, and use data including charge cycles, negative events, operating temperature and state of charge |
Note the asymmetry. Chemistry and critical raw materials are public at model level under point 1(b), while the detailed cathode, anode and electrolyte formulation is restricted under point 2(a). Disclose enough to make circularity possible, withhold enough to protect the formulation.
Article 77(9) required the Commission to adopt, by 18 August 2026, an implementing act specifying who counts as a person with a legitimate interest, which information in points 2 and 4 they receive, and how far they may download, share, publish and re-use it. We could not confirm that act had been adopted as of 27 August 2026. Until it is, the operative test remains the three criteria in Article 77(9) itself: necessity for evaluating the battery's status and residual value, necessity for reuse, repurposing, remanufacturing or recycling decisions, and keeping access to commercially sensitive information "limited to the minimum necessary". Our companion guide on the battery passport data model covers the model, batch and item structure behind these blocks.
Product groups that have a data list, and those that do not
This is where most competitor pages invent something. Here is the checked position on 27 August 2026.
The ESPR working plan, COM(2025) 187 final of 16 April 2025, sets the queue and its indicative adoption years. Those are planning dates for adopting an act, not compliance dates for you: under ESPR Article 4(4), a delegated act's date of application is normally at least 18 months after entry into force.
| Product group | Where the data list comes from | Status on 27 August 2026 |
|---|---|---|
| Batteries: LMT, industrial above 2 kWh, EV | Regulation (EU) 2023/1542, Article 77 and Annex XIII | Specified in the regulation. Applies from 18 February 2027 |
| Toys | Regulation (EU) 2025/2509, Article 19 and Annex VI | Content specified in the regulation. Applies from 1 August 2030. Access rights deferred to a delegated act under Article 49(1)(d) |
| Construction products | Regulation (EU) 2024/3110, Article 76 | Passport and registry duty established in the regulation |
| Detergents and end-user surfactants | Regulation (EU) 2026/405, Article 21 | Passport and registry duty established in the regulation |
| Iron and steel, aluminium | ESPR Article 4 delegated act | No adopted act. Working plan indicates 2026 for iron and steel, 2027 for aluminium |
| Textiles and apparel | ESPR Article 4 delegated act | No adopted act. Working plan indicates 2027 |
| Tyres | ESPR Article 4 delegated act | No adopted act. Working plan indicates 2027 |
| Furniture | ESPR Article 4 delegated act | No adopted act. Working plan indicates 2028 |
| Mattresses | ESPR Article 4 delegated act | No adopted act. Working plan indicates 2029 |
| Electronics and ICT | ESPR horizontal delegated acts | No adopted act. Working plan indicates 2027 for repairability including scoring, 2029 for recycled content and recyclability of electrical and electronic equipment |
The construction, toy and detergent rows are confirmed by Article 1(1) of Implementing Regulation (EU) 2026/1778, which names each instrument as a source of registry-registrable passports. The delegated acts adopted under ESPR so far concern the destruction of unsold consumer products, not passport content. We found no adopted Article 4 delegated act specifying digital product passport data elements for any product group as of 27 August 2026. So there is no binding data element list yet for a digital product passport for textiles, and none for a digital product passport for electronics, furniture, tyres or steel.
What exists instead is preparatory work you can read. The Joint Research Centre runs the technical studies behind each delegated act and publishes the working documents, including DPP content proposals, on its product bureau site. CIRPASS, the Commission-funded coordination action that ran to March 2024, produced a cross-sector DPP definition and data model with roadmaps for electronics, batteries and textiles, and CIRPASS-2 continues it as sector pilots. For textiles or electronics, the CIRPASS material and the JRC study for your group are the best available proxy for your eventual list and the right thing to model against now. Our pages on textile DPP requirements and electronics DPP track each group's preparatory work, and which products need a DPP covers scope and timing.
Data carrier, identifier and registry requirements
The digital product passport data carrier has three separate legal hooks, and brands routinely satisfy one and miss the others.
Placement and format come first. Article 10(1)(b) requires the carrier to be physically present on the product, its packaging or accompanying documentation, with Article 9(2)(c) giving the delegated act control of layout and positioning. Article 10(1)(c) requires carrier and unique product identifier to comply with ISO/IEC 15459-1:2014 to 15459-6:2014 or equivalent until harmonised standards are cited. Article 12 governs the identifiers, including the duty on whoever creates or updates a passport to request a unique operator identifier on behalf of an actor that lacks one.
That "until harmonised standards are cited" clause is no longer hypothetical. Commission Implementing Decision (EU) 2026/1736 of 14 July 2026 cited six harmonised standards in the Official Journal: EN 18216:2026 on data exchange protocols, EN 18219:2026 on unique identifiers, EN 18220:2026 on data carriers, EN 18221:2026 on data storage, archiving and persistence, EN 18222:2026 on APIs for passport lifecycle management and searchability, and EN 18223:2026 on system interoperability. Under ESPR Article 41(2), a passport conforming to a cited harmonised standard is presumed to conform to the requirements of Articles 10 and 11 it covers. That answers the digital product passport standard question: the presumption route now exists, drafted by CEN, Cenelec and ETSI through CEN/CLC/JTC 24 under Commission Implementing Decision C(2024) 5423.
Nothing names the QR code as the only permitted carrier, but a QR code is what most European brands will print, because a QR code is the cheapest carrier that survives being small. Most will carry the identifier inside it as a GS1 Digital Link URI, because GS1 Digital Link expresses GS1 identifiers as resolvable web URIs and a GS1-conformant resolver can serve different link types to different requesters from a single scan. That resolver behaviour is the natural mechanism for tiered access: one carrier, several destinations, chosen by who is asking. Our GS1 Digital Link page covers the syntax, DPP identifiers covers GTIN, SKU, batch and serial, and creating QR codes at scale covers production volume.
The third hook is registration. ESPR Article 13 required the Commission to set up a digital registry by 19 July 2026; the Commission announced the registry live on 20 July 2026, and Implementing Regulation (EU) 2026/1778 of 16 July 2026 lays down its arrangements. Two provisions change your project plan. Article 8 requires registration at the granularity the applicable law sets, at the most granular level where several instruments disagree, and requires an item-level passport to carry linked batch and model identifiers where those designs exist. Article 12 establishes a semantic repository holding the authoritative data models, semantic definitions, role definitions and multilingual labels for every product group, free of charge through documented public APIs. That repository, not a PDF annex, is where your field mappings will come from.
Where your passport data lives today
For every data family above, the real question is not what the regulation calls it but which of your systems already holds it, and in what state.
| Data family | Usual system of record | Typical gap |
|---|---|---|
| Identifiers, GTIN, model and SKU structure | ERP or PIM | Exists, but rarely at batch or item granularity, often duplicated across regions |
| Commercial attributes, images, manuals | PIM or DAM | Clean, but versioned for campaigns rather than a ten-year retention duty |
| Bill of materials, part numbers, spare parts | PLM or ERP | Engineering BOMs are structured for manufacturing, not for disassembly sequences or recycler-readable composition |
| Material composition and substances of concern | Supplier declarations, spreadsheets, email | The largest gap. Location within the product and concentration at component level usually exist nowhere |
| Carbon footprint, recycled and renewable content | LCA tool output, supplier declarations | Held at corporate or category level; rarely per functional unit, per model, with a traceable calculation file |
| Test reports and conformity certificates | Document management, lab portals | PDFs with no structured link to the model or batch they cover |
| Declaration of conformity, technical documentation | Quality or regulatory affairs file share | Documents, not data an API can serve into a passport |
| Facility and operator identifiers for upstream sites | Nowhere | Usually has to be created; ESPR Article 12(2) and 12(3) put the request duty on the passport creator |
| Lifecycle and in-use events | Service, warranty or telematics systems, or nowhere | Fragmented across service partners, rarely joined to the item identifier |
Two patterns show up in every data inventory. Roughly the top half of that table already exists and needs mapping, while the bottom half has to be gathered, and gathering means a specific question to a named supplier rather than a general survey. And the fields you have to gather are disproportionately the ones a delegated act will place in the public or specified-actor tier, because those are the circularity fields the instrument exists to expose.
DPPAutomate is built around that split: import what your ERP and PIM already hold, then issue supplier declaration requests for the fields that do not exist yet and watch them land against the same product record, so the passport and the evidence behind it stay in one place. Our guide to ERP and PIM integration covers the mapping side.
What to do next
Three decisions separate a six-week project from an eighteen-month one, and all three are data decisions rather than software decisions.
Decide granularity first. Model, batch or item changes every downstream estimate, because Implementing Regulation (EU) 2026/1778 Article 8 requires an item-level passport to carry linked batch and model identifiers, and because item-level lifecycle data has no home in most estates today. Our guide on whether you need a separate passport per product works through that choice.
Then run the tier assignment as a business exercise, not a legal one: mark each candidate field public, specified-actor or authority-only using the table above, and hand the public column to whoever owns competitive positioning. Any disagreement you surface there is one you would otherwise discover on the day your first passport goes live. Then inventory the gap, naming for every field in the bottom half of the systems table the supplier who holds it and the question you will ask them. The project-level sequence is in our DPP requirements checklist, and what a Digital Product Passport is shows rendered examples if you want to see the output before scoping the input.
The instrument that binds you is knowable today even where your field list is not. Batteries have Annex XIII. Toys have Annex VI. Everyone else has ESPR Articles 9 to 13 for the shape, the EN 18xxx family for the plumbing, the registry's semantic repository for the vocabulary, and a delegated act still to come for the contents. Build against the shape now and the contents become a mapping exercise instead of a rebuild.
This article is general information about EU product regulation, not legal advice. Delegated acts change what applies to your products and when. Confirm your own obligations against the current text of the instruments cited above, or with your legal counsel.
Not sure which delegated act lands on your products first? Check your readiness in under five minutes.




