EU Digital Product Passport: Regulation & Timeline
Planning a DPP project?
Discuss your use case βIn this guide
In brief
The ESPR (Ecodesign for Sustainable Products Regulation), officially Regulation (EU) 2024/1781, is the European framework that makes the Digital Product Passport (DPP) mandatory for almost every physical product sold in the EU. A DPP is a structured digital record, reached through a data carrier such as a QR code, holding a product's identification, durability and repairability, composition, environmental footprint and end-of-life data.
Three things to hold on to. Obligations arrive category by category, through delegated acts, with generally at least 18 months between an act entering into force and application, subject to Article 4(4) exceptions β the battery passport is first, on 18 February 2027. The registry is already live: it opened on 20 July 2026, and Implementing Regulation (EU) 2026/1778 applies from 6 August 2026. The technical layer is settled: six European standards were published on 27 May 2026, so you can start building before your delegated act exists.
Arianee has been running Digital Product Passports in production since 2018 β more than 4 million passports for 50+ brands.
Regulatory calendar checked: 11 September 2026.
What the ESPR requires
The ESPR replaces the 2009 Ecodesign Directive and extends it well beyond energy efficiency. It entered into force on 18 July 2024, and the working plan 2025-2030 was adopted on 16 April 2025. Its headline measure is the Digital Product Passport.
The regulation itself does not list the data you owe. It creates the obligation and delegates the content: for each product group, a delegated act specifies which fields are required, at what granularity, and by when. That is why no single answer to "what does my DPP need?" exists yet for every sector β and why the framework matters more than the checklist.
Scope is broad by design: nearly all physical products placed on the EU market. The main exclusions are food, feed, medicinal products, living organisms and certain vehicles. For a side-by-side view of the five overlapping frameworks that can require a passport, see which regulations require a Digital Product Passport. For the regulation itself, see what is the ESPR.
ESPR implementation timeline
| Scope | Milestone | Status |
|---|---|---|
| Batteries covered by Article 77 | 18 February 2027 | Passport requirement applies |
| Iron and steel | 2026 | Planned ESPR act adoption |
| Textile apparel | Q4 2027 | Planned adoption; application date to be set |
| Tyres and aluminium | 2027 | Planned ESPR act adoption |
| Furniture | 2028 | Planned ESPR act adoption |
| Mattresses and ICT products | 2029 | Planned ESPR act adoption |
ESPR generally provides at least 18 months between a delegated act entering into force and its application, with the exceptions specified in Article 4(4). The indicative schedule may change. Commission β timeline Β· Textiles Β· ESPR, Article 4.
What data is mandatory in a DPP
Whatever your category, required data falls into four families. The European Commission layers them further into essential, recommended and voluntary tiers.
- β’Identification β globally unique identifier, brand, model, manufacturer, and the economic operator responsible for placing the product on the market.
- β’Durability and repairability β expected lifespan, spare-part availability and cost, repair instructions, repairability score, digital manuals.
- β’Composition and environment β materials and weight per component, substances of concern (SVHCs), lifecycle carbon footprint, recycled content, energy class, material provenance.
- β’Compliance and end of life β declarations of conformity, certifications, dismantling and recycling instructions, take-back schemes, resale and repair pathways.
Two things people underestimate. First, this is not a launch-day snapshot: the data must stay accurate for the product's regulatory lifetime, which means an update process, not a one-off export. Second, not everything is public. The regulation separates freely readable data from data restricted by role β see who can access which DPP data.
For the field-by-field breakdown, see what data goes into a Digital Product Passport. For obligations and penalties by sector, see Digital Product Passport requirements.
Who must comply β including companies outside the EU
Any economic operator placing a covered product on the EU market is in scope, wherever it is established. A brand headquartered outside Europe selling into the single market carries the same obligation as a European manufacturer.
Responsibilities split along the chain. Manufacturers collect, structure and maintain the data, ideally from the design stage rather than retrofitted before a deadline. Importers verify that supplier data is complete and accurate, and assume responsibility for the products they bring in β in practice the heaviest new burden, because it means auditing data you did not produce. Distributors must make the passport reachable for consumers and for market surveillance authorities.
The EU DPP Registry
The registry is the central European infrastructure where every Digital Product Passport must be registered. It went live on 20 July 2026, together with a testing environment. Commission Implementing Regulation (EU) 2026/1778, published on 16 July 2026 and applicable from 6 August 2026, sets out access management, user verification, data registration and storage, and the registry's technical architecture.
The point most often misread: the registry does not hold your product data. It records the unique identifier and its metadata β a proof of registration. The data itself stays decentralised, hosted by you or by a DPP service provider acting on your behalf β a category the implementing regulation recognises explicitly.
That architecture is a deliberate choice, not an implementation detail, and it shapes how you should design your own setup. Read the decentralised architecture of the DPP registry, or the practical view on the EU DPP registry.
DPP standards: the technical layer is settled
This is the part that changes how you should plan. The ESPR sets the obligation, delegated acts set the sectoral content, and the CEN/CENELEC standards (committee JTC 24) define the "how": identifiers, data carriers, protocols, APIs, storage, security.
Six of the eight standards were published as European standards on 27 May 2026: EN 18219 (unique identifiers), EN 18220 (data carriers), EN 18216 (data exchange protocols), EN 18222 (lifecycle API and searchability), EN 18223 (system interoperability) and EN 18221 (storage, archiving and persistence). Two remain Final Drafts under formal vote: FprEN 18239 (access rights, information security, business confidentiality) and FprEN 18246 (authentication, reliability and data integrity).
One caveat worth stating plainly: published is not the same as presumption of conformity. That only applies once the references are cited in the Official Journal of the EU as harmonised standards under the ESPR. No serious provider can promise you "certified compliance" today.
What the standards actually impose, in five obligations that cut across every sector:
- 01.A resolvable, persistent identity β a globally unique, web-resolvable identifier that survives merger, sale, liquidation or bankruptcy. Nine identification schemes are accepted, including decentralised identifiers (DID).
- 02.Data that outlives its issuer β the passport must stay available even when the economic operator that created it no longer exists, which is why the standards introduce back-up service providers and replication.
- 03.Provable integrity β every data provider authenticated, every change tied to an identity, and a tamper-evident audit trail that anyone can verify free of charge.
- 04.Two-speed access β public data readable without friction, sensitive data partitioned by role, with no discrimination by location or jurisdiction.
- 05.Open interoperability β standardised identifiers, formats, APIs and semantics over an open network, without vendor lock-in.
That last point is worth pausing on: the requirement for an open, interoperable network without vendor lock-in is now written into the standard itself. Closed architectures start at a normative disadvantage.
On the methodology side, the Commission's Joint Research Centre published JRC145830 on 19 March 2026 β 121 pages setting out a five-tier access model, an immutable Core DPP paired with an append-only life-cycle log, and granularity at model, batch or item level. Our read of JRC145830 covers what it means operationally. Note that its pilot covers iron and steel, not textiles.
If you are choosing a data carrier, one myth is worth clearing up early: GS1 Digital Link is not mandatory. EN 18219 requires a resolvable, globally unique URL; GS1 Digital Link is one conforming option among several. See do you have to use GS1 Digital Link.
How to prepare now
Waiting for your delegated act is the wrong sequencing. The infrastructure requirements are known and stable; only the sectoral field lists are pending. Five steps that do not depend on your delegated act:
- 01.Map your products by granularity β decide what a passport covers: a model, a batch or an individual item. This choice drives volume, cost and every downstream system.
- 02.Audit your supply-chain data β list what exists, what is missing, and who owns it. Collecting data from suppliers is almost always the critical path, not the technology.
- 03.Choose an identifier scheme and a data carrier β QR, 2D barcode or RFID/NFC, with durability across the product's whole life.
- 04.Decide hosting: in-house or a DPP service provider β including a back-up arrangement, since persistence beyond your own existence is a requirement, not an option.
- 05.Run a pilot on one product range before scaling. It surfaces the data-quality problems that no architecture diagram will.
To size the work against your own sector and timeline, use the DPP readiness simulator. If EU vocabulary is slowing you down, the DPP glossary defines the 25 terms that matter.
Beyond compliance: the business case
One euro spent on DPP infrastructure covers three to five regulations, not one. ESPR, the Battery Regulation, WEEE, the French AGEC law and CSRD reporting all draw on the same product data. Treating them as five projects is the expensive path.
Past compliance, the passport is an asset. It creates a direct relationship with the end consumer at the moment of scan, gives resale and repair a verifiable provenance β which is what makes authenticated second-hand possible at all β and produces first-party data on how products are actually used and serviced. The brands treating the DPP as a coverage exercise will meet the deadline. The ones treating it as infrastructure will get something back for the spend.
What to do next
The regulation is not the hard part; the data is. Start with granularity and supplier data, pick an identifier scheme, and build against the published standards rather than waiting for a delegated act that will only tell you which fields to fill.
Arianee provides the open Digital Product Passport infrastructure for that: identifiers, compliance validation before publication, legal archiving, and a consumer-facing passport portal β in production since 2018, with 4 million passports deployed for 50+ brands. See the platform, or talk to us about your sector and timeline.
From requirements to deployment
Explore the Arianee DPP platform: ERP/PIM data sources, identifiers, access rights, a pilot and cost factors. For batteries, see our Battery Pass solution. Read the Ecosystem and Fnac Darty deployment.
Sources checked on 11 September 2026: ESPR, Battery Regulation, Commission β textiles.
Frequently asked questions
What does the ESPR require exactly?
The ESPR (Ecodesign for Sustainable Products Regulation), officially Regulation (EU) 2024/1781, is the EU framework that makes the Digital Product Passport mandatory for almost every physical product sold in the European Union. It does not impose requirements directly: for each product category, a delegated act sets the data to be provided, and ESPR generally allows at least 18 months from an act entering into force to its application, subject to the exceptions in Article 4(4). Food, feed, medicinal products, living organisms and certain vehicles are outside its scope.
What data must a Digital Product Passport contain?
The exact fields depend on the delegated act for your category, but they always fall into four families: identification (unique identifier, brand, model, manufacturer, economic operator responsible for placing the product on the market); durability and repairability (expected lifespan, spare-part availability and cost, repairability score); composition and environment (materials, substances of concern such as SVHCs, lifecycle carbon footprint, recycled content, energy class); and compliance (declarations, certifications, traceability). The European Commission distinguishes essential, recommended and voluntary data tiers.
When does the Digital Product Passport become mandatory?
The battery passport applies from 18 February 2027 to electric vehicle batteries, light means of transport batteries and industrial batteries above 2 kWh. For ESPR, the schedule concerns planned adoption of sector-specific acts: iron and steel in 2026, textiles, tyres and aluminium in 2027, furniture in 2028, mattresses and ICT products in 2029. The textile act is planned for Q4 2027. Each act will set its requirements and application date; these adoption dates are not compliance deadlines and do not guarantee full coverage by 2030.
Who has to comply with the DPP obligation?
Every economic operator placing a covered product on the EU market, regardless of where it is established. Manufacturers must collect, structure and update the data from the design stage. Importers must verify that the data supplied by manufacturers is complete and accurate, and take responsibility for imported products. Distributors must give consumers and market surveillance authorities access to the passport. A brand based outside Europe selling covered products into the EU is therefore in scope.
What is the EU DPP Registry and do I have to register?
The registry is the central European infrastructure where each Digital Product Passport must be registered. It went live on 20 July 2026 alongside a testing environment. Commission Implementing Regulation (EU) 2026/1778, published on 16 July 2026 and applicable from 6 August 2026, sets the rules for access management, user verification, data registration and storage, and the technical architecture. Importantly, the registry does not store your product data: it holds the unique identifier and its metadata, while the data itself stays decentralised, with you or with a DPP service provider acting on your behalf.
Should I wait for my delegated act before starting?
No, and that is the most common sequencing mistake. The technical layer is already settled: six European standards were published on 27 May 2026, covering identifiers, data carriers, exchange protocols, APIs, interoperability and storage. Only the sectoral content still depends on delegated acts. You can already map your products by granularity (model, batch, item), choose an identifier scheme and a data carrier, decide between self-hosting and a DPP service provider with a back-up, and prepare your public versus restricted access matrix. Collecting data from suppliers is usually the longest step.
From your product to its passport
See what a DPP can do for your products.
Bring your use case. Weβll show you how to connect your product data, validate your passports and activate services after the sale.
Ecosystem Γ Fnac DartySee a deployment, from the factory to repair and reuse βExplore the platform first βLetβs talk about your project
A demo based on your products and your data.
Loading the secure formβ¦