Digital Product Passport: Frequently Asked Questions (FAQ)
A non-binding European Commission living FAQ on the general Digital Product Passport framework under Regulation (EU) 2024/1781, covering scope, stakeholder roles, implementation, architecture, standards, trade and enforcement.
- 1ESPR does not impose a DPP on every product. Product-specific delegated acts determine whether a DPP is required, its data and the binding compliance date; separate sector legislation may also create DPP duties.
- 2Where a DPP duty applies, the economic operator placing the product on the EU market must create and maintain the passport, register its unique identifiers and provide the prescribed physical data carrier before the product is first placed on the market.
- 3The architecture is hybrid: the EU Registry indexes identifiers and the passport location, while detailed product data remains decentralised with the economic operator or its service provider and must be backed up through a third-party provider.
- 4The FAQ describes the implementation milestones and eight standardisation areas as they stood when the manuscript was completed in February 2026; current Registry, portal and standards status must be checked against later Commission material.
- 5Consumer access must be free and easy. General access is designed to be anonymous, customer personal data is not stored by default, and voluntary data must be clearly distinguished from mandatory data.
- 6National competent and market-surveillance authorities enforce the rules, customs checks imports, and Member States set effective, proportionate and dissuasive penalties that may apply beyond manufacturers.
Purpose and scope of the FAQ
Version 1.0 answers 32 questions about the common Digital Product Passport framework under Regulation (EU) 2024/1781, the Ecodesign for Sustainable Products Regulation (ESPR). It describes a DPP as a digital identity card for products, components and materials that can aggregate sustainability, lifecycle and compliance information to support circularity, transparency and enforcement.
The FAQ is limited to the general ESPR framework. It does not explain the detailed passport duties created by separate legislation for batteries, toys, construction products or other sectors. It nevertheless stresses that DPPs will use the same underlying technical system regardless of their legal origin, so information required by sector legislation and later ESPR measures can be accessed through an interoperable framework.
There is no universal ESPR passport requirement
A product group does not need a DPP merely because it appears in the ESPR working plan. A product-specific delegated act must determine the exact scope, required information, passport granularity, data carrier and binding compliance date. The preparatory process includes study, impact assessment and stakeholder consultation, and both the European Parliament and the Council may object to a delegated act.
- ESPR itself excludes food and feed, human and veterinary medicines, living plants, animals and microorganisms, and products of human origin.
- The Commission may avoid duplication where another EU law already provides a digital information system that achieves the same objectives.
- Separate sector legislation can still require a DPP, so businesses must always check the rules for their particular product.
Who does what
- Economic operators compile the data required by the applicable legislation, create and register the passport, attach the required data carrier and keep the information accurate throughout the product lifecycle. Depending on the supply chain, the responsible party may be a manufacturer, authorised representative, importer, distributor, dealer or fulfilment service provider.
- Consumers can use the passport before and after purchase to obtain the information made available to them. Depending on product rules, this may include materials, durability, repair, spare-part, maintenance and end-of-life information.
- Customs and market-surveillance authorities use identifiers, registration information and the passport itself to support import controls and targeted compliance checks.
- Repairers, refurbishers and recyclers may receive disassembly, diagnostic, spare-part, material and substances-of-concern information when the applicable product rules require those data points and grant access.
When a required passport must be active
Once a DPP requirement applies, the passport must be active and registered when the product is first placed on the EU market. An EU-made product therefore needs its passport before its first sale or distribution. An imported product needs it before customs releases the product for free circulation. Products made outside the EU are not exempt when the applicable product-specific measure requires a DPP, and online marketplaces selling into the EU must make the passport accessible.
The FAQ reproduces the first ESPR working plan's indicative timetable for studying and adopting product measures. Those years are planning milestones, not automatic passport deadlines. A final legal obligation and its compliance date come from the relevant delegated or sector-specific act.
Registry, web portal and decentralised data
The DPP combines centralised and decentralised elements. The EU Registry acts as a controlled index: it stores unique identifiers and links each identifier to the passport location, plus any additional registration data required by product legislation. Detailed product data is not normally stored in the Registry; it remains hosted by the economic operator or a service provider acting on its behalf.
- A data carrier connects a product at the model, batch or item level, as legally specified, to its unique identifier and official passport.
- The economic operator must arrange a backup copy through a third-party service provider so the passport remains available during the product's expected lifetime if the original operator becomes insolvent, is liquidated or ceases trading.
- A public web portal is intended to provide search and comparison functions, while Registry integration with customs is intended to support automated checks at the EU border.
- Common data structures, access controls, quality rules, persistence requirements and interoperability standards apply even though detailed data is managed by different operators.
At manuscript completion in February 2026, the FAQ described 19 July 2026 as the Registry's legal operational deadline, the public web portal as a later development and customs interconnection as due within four years after the relevant Registry rules entered into force. These are document-era statements, not a current service-status report; later Commission sources should be checked before planning an implementation.
Eight standardisation areas and the data carrier
The Commission's standardisation request, Commission Implementing Decision C(2024) 5423 final, asks the European standardisation organisations to establish the product-neutral technical framework. The FAQ groups the work into eight areas:
- Unique identifiers for products, economic operators and facilities.
- Data carriers and the link between a physical product and its digital representation.
- Access-rights management, information security and data protection.
- Technical, semantic and organisational interoperability.
- Data processing, exchange protocols and formats.
- Data storage, archiving and persistence.
- Data authentication, reliability and integrity.
- Application programming interfaces for passport lifecycle management.
The document expected this standardisation work to be completed around mid-2026, so readers must check the current standards and their legal status. It also explains that the relevant product act, not the general FAQ, selects the data carrier. QR codes and NFC were among the options under assessment, with product characteristics, practicality and sustainability informing the final choice.
Consumer access, privacy and voluntary data
- Access for consumers must be free and easy. Possible routes include scanning the carrier on a product, packaging or accompanying document, using an online product page or public portal, and accessing information through a computer or an in-store service.
- Privacy and data protection apply by design and by default. General access to product information should be anonymous and customer personal data must not be stored in the DPP by default.
- Personal data may be linked to a passport only with explicit, informed consent for a specific stated purpose and in full compliance with the GDPR.
- Voluntary data points are allowed only if they are clearly distinguished from mandatory data and do not compromise accuracy, interoperability or passport functionality.
Data quality, conformity assessment and enforcement
- The economic operator has primary responsibility for accurate, complete and current passport data. Member-State market-surveillance authorities check that information through their normal enforcement work, while customs checks registration at import.
- There is no universal third-party certification or conformity-assessment requirement for every DPP data point. A later product-specific measure may require accredited third-party assessment for selected information where the preparatory study and impact assessment justify it.
- Information on substances of concern is included where a required product passport and its delegated act call for it. Substances and mixtures do not automatically need their own DPP unless another EU rule or an ESPR measure requires one.
- Member States determine penalties, which ESPR requires to be effective, proportionate and dissuasive. Relevant duties and penalties can apply to economic operators and online platforms, not only manufacturers.
How to read this source
The Commission presents the FAQ as a living implementation aid developed from stakeholder exchanges. It expressly says the answers do not represent an official Commission position, extend rights or obligations, introduce additional requirements or prejudge future action by the Commission or the Court of Justice. Compliance decisions must therefore return to ESPR, the applicable delegated and implementing acts, and any sector-specific legislation.
The manuscript was completed in February 2026. The visible reference on the publication is Ares(2026)5136906 dated 20 May 2026, which is also the CIRCABC issue date. This brief treats the FAQ's implementation milestones as statements from that publication period and records later developments only through separately reviewed sources.
The manuscript was completed in February 2026 and the visible Ares reference and CIRCABC issue date are 20 May 2026. The FAQ describes itself as a living, non-authoritative document that does not represent an official Commission position or add legal requirements. Recheck its dated milestones against current Commission sources and applicable product legislation.
DPP Lens provides operational interpretation, not legal advice or an official conformity assessment. Always rely on the linked official text.
Other official-source briefs connected to this topic.
