Digital Product Passport (DPP): a complete guide to the ESPR regulation
The Digital Product Passport (DPP) is an electronic record that travels with a product throughout its life cycle: origin of materials, composition, environmental footprint, repair instructions and recycling options. It is accessed through a physical identifier on the product —usually a QR code— and must be readable by consumers, economic operators, authorities and recyclers.
Its legal basis is Regulation (EU) 2024/1781 on Ecodesign for Sustainable Products (ESPR), in force since July 2024. ESPR does not impose the DPP on every product at once: it does so category by category through delegated acts. So the useful question for a company is not whether it will be affected, but when and with which data.
Which products are affected and when
Batteries are the first category with a firm date: the Batteries Regulation (EU) 2023/1542 requires the battery passport from February 2027 for industrial batteries above 2 kWh, electric-vehicle batteries and light means of transport batteries.
For everything else, the first ESPR working plan prioritises iron and steel, aluminium, textiles (especially apparel), furniture, tyres and mattresses, plus horizontal requirements such as repairability and recycled content. Each delegated act sets the mandatory data and a transition period, which in practice places most obligations between 2027 and 2030.
What information a DPP must contain
The exact content is defined by each category's delegated act, but the regulation sets a common core:
- Unique identifier of the product, the economic operator and the manufacturing facility.
- Composition, substances of concern and recycled content.
- Environmental and carbon footprint where the delegated act requires it.
- Use, repair, disassembly and end-of-life information.
- Certificates, declarations of conformity and technical documentation.
- Differentiated access levels: public, professionals and authorities.
Technical requirements: interoperability, persistence and integrity
ESPR requires passport data to be interoperable, accessible free of charge, available for the expected lifetime of the product and protected against tampering. The Commission also runs a central registry of DPP identifiers, and customs will be able to check that a passport exists at import.
The challenge is not generating a QR code but guaranteeing that the data behind it is authentic, that nobody altered it after issuance and that it remains accessible even if the manufacturer changes technology provider or disappears.
Why verifiable evidence is key
A digital passport is only as reliable as its weakest data point. If a recycled-content or origin claim can be changed without a trace, the DPP becomes a greenwashing tool instead of a transparency one, and the legal risk falls on the economic operator.
Sealing each piece of evidence —certificates, measurements, supply-chain events— with a timestamp and verifiable integrity on a distributed ledger lets any auditor or authority check that the data existed on that date and has not changed, without relying on a single provider's word.
How to prepare: a five-step roadmap
Companies that move early reduce cost and risk. A reasonable sequence is:
- Identify which products fall under the first delegated acts and their dates.
- Map data sources: ERP, PLM, suppliers and certifiers.
- Define the identification model (GS1 Digital Link or other open standards).
- Implement the verifiable-evidence layer for critical data.
- Pilot with one product reference before scaling to the catalogue.