Digital Product Passport: EU Requirements & Timeline
In brief
The ESPR (Ecodesign for Sustainable Products Regulation), officially Regulation (EU) 2024/1781, is the European framework that makes the Digital Product Passport (DPP) mandatory for almost every physical product sold in the EU. A DPP is a structured digital record, reached through a data carrier such as a QR code, holding a product's identification, durability and repairability, composition, environmental footprint and end-of-life data.
Three things to hold on to. Obligations arrive category by category, through delegated acts, with roughly 18 months between adoption and enforcement — the battery passport is first, on 18 February 2027. The registry is already live: it opened on 20 July 2026, and Implementing Regulation (EU) 2026/1778 applies from 6 August 2026. The technical layer is settled: six European standards were published on 27 May 2026, so you can start building before your delegated act exists.
Arianee has been running Digital Product Passports in production since 2018 — more than 3.4 million passports for 50+ brands.
Last updated: 27 July 2026.
What the ESPR requires
The ESPR replaces the 2009 Ecodesign Directive and extends it well beyond energy efficiency. It was published in July 2024, and the working plan 2025-2030 was adopted on 16 April 2025. Its headline measure is the Digital Product Passport.
The regulation itself does not list the data you owe. It creates the obligation and delegates the content: for each product group, a delegated act specifies which fields are required, at what granularity, and by when. That is why no single answer to "what does my DPP need?" exists yet for every sector — and why the framework matters more than the checklist.
Scope is broad by design: nearly all physical products placed on the EU market. The main exclusions are food, feed, medicinal products, living organisms and certain vehicles. For a side-by-side view of the five overlapping frameworks that can require a passport, see which regulations require a Digital Product Passport. For the regulation itself, see what is the ESPR.
ESPR implementation timeline
Only one date is firm and widely confirmed: 18 February 2027 for the battery passport. Everything else follows the adoption of its delegated act, and the usual rule is around 18 months between adoption and enforcement. Treat the rest as expected, not fixed.
| Sector | Milestone | Status |
|---|---|---|
| Batteries above 2 kWh, EV, light transport | 18 February 2027 | Firm — first mandatory DPP |
| Iron and steel | First pilot delegated act, 2026 | In progress |
| Textiles and footwear | From 2027 (delegated act expected, then ~18 months) | Expected |
| Electrical and electronic equipment | 2028 | In progress |
| Furniture | Delegated act expected 2028, obligations ~2029 | Planned |
| Near-complete coverage of physical products | 2030 | Planned |
The battery passport deserves separate attention: it carries continuously updated State of Health data from the battery management system, declared carbon footprint, recycled content thresholds and performance classes. See battery passport requirements for the detail.
What data is mandatory in a DPP
Whatever your category, required data falls into four families. The European Commission layers them further into essential, recommended and voluntary tiers.
- •Identification — globally unique identifier, brand, model, manufacturer, and the economic operator responsible for placing the product on the market.
- •Durability and repairability — expected lifespan, spare-part availability and cost, repair instructions, repairability score, digital manuals.
- •Composition and environment — materials and weight per component, substances of concern (SVHCs), lifecycle carbon footprint, recycled content, energy class, material provenance.
- •Compliance and end of life — declarations of conformity, certifications, dismantling and recycling instructions, take-back schemes, resale and repair pathways.
Two things people underestimate. First, this is not a launch-day snapshot: the data must stay accurate for the product's regulatory lifetime, which means an update process, not a one-off export. Second, not everything is public. The regulation separates freely readable data from data restricted by role — see who can access which DPP data.
For the field-by-field breakdown, see what data goes into a Digital Product Passport. For obligations and penalties by sector, see Digital Product Passport requirements.
Who must comply — including companies outside the EU
Any economic operator placing a covered product on the EU market is in scope, wherever it is established. A brand headquartered outside Europe selling into the single market carries the same obligation as a European manufacturer.
Responsibilities split along the chain. Manufacturers collect, structure and maintain the data, ideally from the design stage rather than retrofitted before a deadline. Importers verify that supplier data is complete and accurate, and assume responsibility for the products they bring in — in practice the heaviest new burden, because it means auditing data you did not produce. Distributors must make the passport reachable for consumers and for market surveillance authorities.
The EU DPP Registry
The registry is the central European infrastructure where every Digital Product Passport must be registered. It went live on 20 July 2026, together with a testing environment. Commission Implementing Regulation (EU) 2026/1778, published on 16 July 2026 and applicable from 6 August 2026, sets out access management, user verification, data registration and storage, and the registry's technical architecture.
The point most often misread: the registry does not hold your product data. It records the unique identifier and its metadata — a proof of registration. The data itself stays decentralised, hosted by you or by a DPP service provider acting on your behalf — a category the implementing regulation recognises explicitly.
That architecture is a deliberate choice, not an implementation detail, and it shapes how you should design your own setup. Read the decentralised architecture of the DPP registry, or the practical view on the EU DPP registry.
DPP standards: the technical layer is settled
This is the part that changes how you should plan. The ESPR sets the obligation, delegated acts set the sectoral content, and the CEN/CENELEC standards (committee JTC 24) define the "how": identifiers, data carriers, protocols, APIs, storage, security.
Six of the eight standards were published as European standards on 27 May 2026: EN 18219 (unique identifiers), EN 18220 (data carriers), EN 18216 (data exchange protocols), EN 18222 (lifecycle API and searchability), EN 18223 (system interoperability) and EN 18221 (storage, archiving and persistence). Two remain Final Drafts under formal vote: FprEN 18239 (access rights, information security, business confidentiality) and FprEN 18246 (authentication, reliability and data integrity).
One caveat worth stating plainly: published is not the same as presumption of conformity. That only applies once the references are cited in the Official Journal of the EU as harmonised standards under the ESPR. No serious provider can promise you "certified compliance" today.
What the standards actually impose, in five obligations that cut across every sector:
- 01.A resolvable, persistent identity — a globally unique, web-resolvable identifier that survives merger, sale, liquidation or bankruptcy. Nine identification schemes are accepted, including decentralised identifiers (DID).
- 02.Data that outlives its issuer — the passport must stay available even when the economic operator that created it no longer exists, which is why the standards introduce back-up service providers and replication.
- 03.Provable integrity — every data provider authenticated, every change tied to an identity, and a tamper-evident audit trail that anyone can verify free of charge.
- 04.Two-speed access — public data readable without friction, sensitive data partitioned by role, with no discrimination by location or jurisdiction.
- 05.Open interoperability — standardised identifiers, formats, APIs and semantics over an open network, without vendor lock-in.
That last point is worth pausing on: the requirement for an open, interoperable network without vendor lock-in is now written into the standard itself. Closed architectures start at a normative disadvantage.
On the methodology side, the Commission's Joint Research Centre published JRC145830 on 19 March 2026 — 121 pages setting out a five-tier access model, an immutable Core DPP paired with an append-only life-cycle log, and granularity at model, batch or item level. Our read of JRC145830 covers what it means operationally. Note that its pilot covers iron and steel, not textiles.
If you are choosing a data carrier, one myth is worth clearing up early: GS1 Digital Link is not mandatory. EN 18219 requires a resolvable, globally unique URL; GS1 Digital Link is one conforming option among several. See do you have to use GS1 Digital Link.
How to prepare now
Waiting for your delegated act is the wrong sequencing. The infrastructure requirements are known and stable; only the sectoral field lists are pending. Five steps that do not depend on your delegated act:
- 01.Map your products by granularity — decide what a passport covers: a model, a batch or an individual item. This choice drives volume, cost and every downstream system.
- 02.Audit your supply-chain data — list what exists, what is missing, and who owns it. Collecting data from suppliers is almost always the critical path, not the technology.
- 03.Choose an identifier scheme and a data carrier — QR, 2D barcode or RFID/NFC, with durability across the product's whole life.
- 04.Decide hosting: in-house or a DPP service provider — including a back-up arrangement, since persistence beyond your own existence is a requirement, not an option.
- 05.Run a pilot on one product range before scaling. It surfaces the data-quality problems that no architecture diagram will.
To size the work against your own sector and timeline, use the DPP readiness simulator. If EU vocabulary is slowing you down, the DPP glossary defines the 25 terms that matter.
Beyond compliance: the business case
One euro spent on DPP infrastructure covers three to five regulations, not one. ESPR, the Battery Regulation, WEEE, the French AGEC law and CSRD reporting all draw on the same product data. Treating them as five projects is the expensive path.
Past compliance, the passport is an asset. It creates a direct relationship with the end consumer at the moment of scan, gives resale and repair a verifiable provenance — which is what makes authenticated second-hand possible at all — and produces first-party data on how products are actually used and serviced. The brands treating the DPP as a coverage exercise will meet the deadline. The ones treating it as infrastructure will get something back for the spend.
What to do next
The regulation is not the hard part; the data is. Start with granularity and supplier data, pick an identifier scheme, and build against the published standards rather than waiting for a delegated act that will only tell you which fields to fill.
Arianee provides the open Digital Product Passport infrastructure for that: identifiers, compliance validation before publication, legal archiving, and a consumer-facing passport portal — in production since 2018, with 3.4 million passports deployed for 50+ brands. See the platform, or talk to us about your sector and timeline.
Are you ready for the EU DPP Registry?
Assess your DPP compliance in 10 questions — instant personalised result.
Take action
Discover how to implement your Digital Product Passport in compliance with European regulations.
Request a demo