1. What exactly is a DPP? (Definition)
A Digital Product Passport (DPP) is an electronic data record that stores product information about material, origin, repairability, recycling, and CO₂ footprint and makes it accessible via a data carrier such as a QR code or NFC tag. The legal basis in the EU is Regulation (EU) 2024/1781 (ESPR), in force since 18 July 2024. Mandatory from 2026/2027 for batteries, from 2030 for toys, and progressively for textiles, construction products, and electronics.
The DPP makes the most important information about a product available in a structured form along its entire life cycle — for consumers, recyclers, repair businesses, and authorities. It is not a marketing label but a regulatory data infrastructure.1
Who is affected? In principle, almost all physical goods on the EU market. Exemptions include, among others, food, animal feed, medical devices, living organisms, and vehicles (separate regulatory framework).2
The most important deadlines at a glance:
- 18 February 2027 — DPP obligation: Battery passport for EV batteries, industrial batteries > 2 kWh, and LMT (Light Means of Transport)3
- 1 August 2030 — DPP obligation: Toys under the new Toy Safety Regulation (EU) 2025/25096
- 19 July 2026 — two deadlines that are often confused: (a) the deadline for the European Commission to set up the central DPP Registry (ESPR Art. 13) — this is not an obligation for manufacturers and does not trigger any duty to register;4 (b) the destruction ban for unsold textiles/footwear has applied to large companies since that date (ESPR Art. 25) — a genuine company obligation, but a destruction matter, not a DPP one5
2. What's inside the Digital Product Passport?
The specific data scope varies per product category — the respective Delegated Act of the EU Commission specifies the mandatory data fields. As a common framework, the ESPR base regulation prescribes these core building blocks:12
Identification
- Unique product identifier (Unique Identifier per ISO/IEC 15459)
- Manufacturer identity and location
- Production date and batch
Compliance & Safety
- Declarations of conformity (Declaration of Conformity)
- Safety instructions and warnings
- Substance declarations (critical raw materials, pollutants)
Sustainability & Circular Economy
- Material composition and recycled content
- CO₂ footprint (mandatory for batteries from 20273)
- Repair instructions and end-of-life information (disposal, recycling routes)
Supply chain information
- Country of origin of raw material and production
- Supply chain due diligence (conflict minerals, mandatory for batteries)
Access layers (multi-tier access)
The DPP has different data levels. What the public sees, what recyclers see, and what authorities see is not the same. Using the example of the battery passport per EU Regulation 2023/1542 Annex XIII:3
| Access tier | Who? | Which data? |
|---|---|---|
| Public | End consumers | Basic info (model, manufacturer, safety notices) |
| Authorized actors | Recyclers, repair businesses | Extended technical data |
| Authorities | Market surveillance, EU Commission | Full access incl. compliance data |
| Notified Bodies | Certification bodies | Compliance-relevant data |
Important: The ESPR (Art. 10) requires that this data must remain available for at least 10 years — even if the manufacturer becomes insolvent or the product is dropped from the range.1 This is a demanding technical requirement profile for hosting and archiving.
3. Legal basis: ESPR (EU) 2024/1781
The Ecodesign for Sustainable Products Regulation (ESPR) is the umbrella framework. It replaces the old Ecodesign Directive 2009/125/EC and significantly expands its scope.1
| Fact | Value |
|---|---|
| Regulation number | (EU) 2024/1781 |
| Title | Regulation establishing a framework for the setting of ecodesign requirements for sustainable products |
| Adopted | 13 June 2024 (Parliament + Council) |
| In force | 18 July 2024 |
| First applicability | 19 July 2025 (disclosure for large companies, unsold goods) |
| Replaces | Ecodesign Directive 2009/125/EC |
Primary source: EUR-Lex — Regulation (EU) 2024/1781.1
Which products are covered?
In principle, almost all physical goods on the EU market — both finished products and components and intermediate products. Explicitly exempt (Art. 1(2)) are:12
- Food (EU 178/2002) and animal feed
- Medical devices (human and veterinary)
- Living plants, animals, microorganisms
- Products of human origin
- Products of animal/plant origin within the food chain
- Vehicles (separate regulatory framework)
For edge cases — such as packaging, which partly falls under the ESPR and partly under the Packaging Regulation — a specific assessment per product category is required.
The core articles on the DPP
| Article | Content |
|---|---|
| Art. 9 | DPP baseline requirements, data fields, multi-tier access |
| Art. 10 | Data management, hosting, decentralized data storage, 10-year availability |
| Art. 11 | Category-specific information requirements (repair, recycling, substances) |
| Art. 12 | Unique product identifier (ISO/IEC 15459) |
| Art. 13 | DPP Registry (EU-central; to be set up by the Commission by 19 July 2026) |
| Art. 25 | Destruction ban for unsold textiles/footwear |
| Art. 74 | Penalties (to be set by member states) |
Working Plan 2025–2030
The EU Commission adopted the Working Plan on 16 April 2025 and published it on 11 July 2025. It names six priority product groups for which Delegated Acts with ecodesign and DPP requirements will be developed between 2025 and 2030:10
| Product group | Type | Delegated Act — indicative adoption |
|---|---|---|
| Iron and steel | Intermediate product | 2026 |
| Textiles (apparel focus; footwear deferred for now) | Final product | 2027 |
| Tyres | Final product | 2027 |
| Aluminium | Intermediate product | 2027 |
| Furniture | Final product | 2028 |
| Mattresses | Final product | 2029 |
Important — adoption ≠ start of the obligation: The years above are the indicative dates on which the Commission adopts the respective legal act. The point from which manufacturers must meet the requirements comes afterwards — usually after a transition period set out in the act itself. Reading these years as a compliance deadline means planning too early; assuming the transition period without tracking the adoption means planning too late.
In addition, the Working Plan continues work on 14 energy-related product groups carried over from the previous Ecodesign working plan, and announces horizontal measures — on the repairability of products generally and on the recyclability of electrical and electronic equipment. Electronics is therefore addressed, but through horizontal requirements rather than as a dedicated DPP product group.10
A mid-term review is planned for 2028.
4. Which industries, from when? — The timeline
As of July 2026. For moving targets (Delegated Acts not yet final), the status is explicitly indicated.
Hard-verified — the exact deadlines are set
| Industry | Regulation | Mandatory from | DPP obligation |
|---|---|---|---|
| Batteries (EV, Industrial > 2 kWh, LMT) | (EU) 2023/1542 | 18 February 2027 | Yes3 |
| Toys | (EU) 2025/2509 | 1 August 2030 | Yes6 |
| Textiles/footwear — destruction ban | (EU) 2024/1781 Art. 25 | 19 July 2026 (large companies), 19 July 2030 (medium-sized). Micro and small enterprises are permanently exempt under Art. 25(1). | No (separate disclosure)5 |
| EU DPP Registry — Commission set-up deadline | (EU) 2024/1781 Art. 13 | 19 July 2026 — a deadline for the Commission, not for manufacturers | n/a (infrastructure, no duty for companies to register)14 |
Expected (Delegated Act not yet final)
| Industry | Basis | Expected obligation | Status |
|---|---|---|---|
| Textiles DPP | ESPR + DA | open — DA adoption indicatively 2027, obligation afterwards | DA in preparation (JRC study underway)11 |
| Electronics / ICT | ESPR + horizontal measures | open | No dedicated DPP product group in the Working Plan; addressed via horizontal requirements on repairability and recyclability10 |
| Furniture | ESPR + DA | open — DA adoption indicatively 2028, obligation afterwards | Priority Working Plan10 |
| Mattresses | ESPR + DA | open — DA adoption indicatively 2029, obligation afterwards | Priority Working Plan10 |
| Iron/steel | ESPR + DA | open — DA adoption indicatively 2026, obligation afterwards | Priority Working Plan, first group10 |
| Aluminium | ESPR + DA | open — DA adoption indicatively 2027, obligation afterwards | Priority Working Plan10 |
| Tyres | ESPR + DA | open — DA adoption indicatively 2027, obligation afterwards | Priority Working Plan10 |
| Construction products | (EU) 2024/3110 (CPR) | 18 months after DA adoption | DA not yet adopted12 |
What is NOT covered
Food and medical devices are exempt under Art. 1(2) ESPR; vehicles fall under a separate regulatory framework.
Common misinformation about the timeline
Some inaccurate dates circulate in public discussion. Two examples that we checked against the primary sources:26
- "Toy DPP from 2026": not correct. The Toy Safety Regulation (EU) 2025/2509 applies to toys only from 1 August 2030.
- "Toy Safety Regulation 2024/2865": This regulation number does not exist. The correct one is (EU) 2025/2509 — published in the Official Journal on 12 December 2025, in force since 23 December 2025, application from 1 August 2030. (Only Articles 28–44 and 49–55 — essentially the notified-body provisions — already apply from 1 January 2026.)6
In case of diverging date claims, it's worth checking the primary source (EUR-Lex).
5. Example: The battery passport (Battery Passport)
The EU Battery Regulation (EU) 2023/1542 is the first DPP regulation with a hard-verified date (18 February 2027). Annex XIII lists the mandatory data fields:320
- Unique battery identifier
- Basic characteristics: type, model, manufacturer, location, production date
- Compliance + performance: CO₂ footprint, recycled content
- Sustainability: CO₂ footprint, critical raw materials
- Supply-chain due diligence: conflict minerals
- Performance and durability
- Material composition and end-of-life information
Which batteries are covered?3
| Category | Battery passport obligation | Threshold |
|---|---|---|
| LMT (Light Means of Transport) | Yes — from 18 Feb 2027 | All |
| EV (Electric Vehicle) | Yes — from 18 Feb 2027 | All |
| Industrial batteries | Yes — from 18 Feb 2027 | > 2 kWh |
| Portable (Consumer) | No (labelling only) | — |
| SLI (Starting, Lighting, Ignition) | No (labelling only) | — |
"From 18 February 2027, a battery without a passport cannot legally be placed on the EU market or put into service." — EU Battery Regulation (EU) 2023/15423
In practice this means: anyone wanting to place EV batteries without a DPP on the EU market on 18 Feb 2027 will not get through market surveillance. There is no tolerance period.
6. Carrier technologies: QR, NFC, Blockchain
Important — carrier ≠ data: QR code, NFC, and blockchain are carrier technologies. The DPP itself is the data. A QR code or NFC tag points to the product data or makes it accessible — it "is" not the product passport. Carrier and data model are chosen independently of each other.
QR code
- What it is: static or dynamic 2D image that contains a URL
- Capability: points to a web resource with product data
- Limits: on its own, no tamper protection, no originality authentication, no cryptographic verification
- ESPR view: QR is allowed, but not exclusively mandated — the ESPR permits various data carriers. The Toy Safety Regulation 2025/2509 explicitly names QR code "or other data carrier"6
NFC (Near Field Communication)
- What it is: radio chip in the product, communicates with the smartphone on contact
- Capability: can cryptographically sign (e.g., NTAG 424 DNA with ECDSA signature), tamper protection, originality authentication
- Additional cost: hardware cost per tag (variable, depending on volume)
- Useful when in addition to DPP compliance, anti-counterfeiting or premium product authentication also matters
Blockchain
- What it is: distributed ledger for tamper-proof data hashes
- Capability: tamper evidence via hash anchoring
- Limits: does not store the data itself (too expensive on public chains), only hashes
- ESPR view: not mandated. The ESPR is technology-neutral. CIRPASS-2 (the EU-funded research project) discusses blockchain as one option among others, not as a standard13
In addition, research discusses decentralized identifiers and Verifiable Credentials (W3C) as architecture building blocks — however, these are not EU-mandatory.19
Vincent's Take: For pure ESPR compliance, a QR code is sufficient in many cases. For industries with an anti-counterfeiting need (luxury, pharma, high-priced branded goods), NFC is worthwhile as an additional layer. In 2026, blockchain is more than necessary in most cases — useful only when there is a concrete tamper-evidence need and the team knows what it's doing.
7. What does a DPP cost?
Honest answer: There are currently no consolidated public Tier-1 estimates for sector-specific DPP compliance costs per product category.14
What we know:
- ESPR Art. 14 explicitly requires the EU Commission to avoid "disproportionate administrative burden" — especially for SMEs1
- The EU Commission Impact Assessment SWD(2022)82 contains aggregated cost estimates, but is cross-sector and not directly transferable to individual products14
- Provider prices vary widely — from very low unit costs (QR-only, self-service SaaS) to high four-figure setup costs plus monthly platform fees for enterprise solutions
Key cost factors
| Factor | Driver |
|---|---|
| Platform/software costs | Number of products, API calls, multi-tenancy |
| Data maintenance | Who maintains it — internal employee, manufacturer partner, agency? |
| Carrier technology | QR (cheap) vs NFC (higher) vs hybrid |
| Integration | ERP/PIM/PLM connection — usually the biggest chunk |
| Hosting & 10-year availability | GDPR-compliant, EU-hosted |
| Audit & compliance consulting | Auditor support, legal review |
Blanket "a DPP costs X EUR per product" answers are misleading: the costs depend so heavily on product portfolio, data maturity, and industry that model calculations without a concrete data basis are hardly reliable. Serious cost estimates therefore require an analysis of the specific product portfolio — flat-rate offers without a prior inventory assessment should be treated with caution.
8. Penalties for non-compliance
- Member states set penalties nationally
- EU requirement: "effective, proportionate, and dissuasive"
- Three assessment factors: (1) nature, gravity, and duration of the infringement; (2) economic benefit from the infringement; (3) environmental damage caused by the infringement
For the Battery Regulation (Art. 93), a similar scheme applies — here too, member states set the penalties.3
What is still open as of July 2026:7
- Concrete fine amounts in Germany are not yet fixed in the national penalty rules under ESPR Art. 74
- There are no known enforcement cases (ESPR DPP not yet active)
- Recommendation: verify with the competent authority or a specialized lawyer before making binding statements
From comparable EU regulations (e.g., GDPR with revenue-dependent fines), such a pattern is known — whether the ESPR implementation follows it is open and here expressly speculation, not an ESPR fact.
The hard deadline counts more than any fine: No one today knows the concrete fine amounts of the German market surveillance. But the Battery Regulation is unambiguous — no passport, no market entry from 18 Feb 2027. For EV batteries or industrial batteries > 2 kWh, this means: a fixed deadline, no leeway. Non-compliant products simply generate zero revenue from that date.
9. The DPP market 2026
According to MarketsandMarkets, the global DPP market is growing from USD 185.9 million (2024) to USD 1,780.5 million (2030) — CAGR 45.7 percent.8 An alternative estimate by Grand View Research is USD 213.9 million (2024) → USD 1,230.9 million (2030) with 34.9 percent CAGR.15 Both are commercial market research — not peer-reviewed, but industry standard.
Europe holds 36.29 percent of the market (2024), according to Grand View Research driven by ESPR and the Circular Economy Action Plan.9 Fashion & Textiles (dominant in 2024) is considered the driving sector, followed by pharma, electronics, automotive (EV batteries), and luxury goods.8
Market structure in the DACH/EU region
The market roughly splits into two camps: enterprise platforms focused on corporate supply chains (decentralized-identity approaches, ESG suites, battery/mining specialists) and pragmatic mid-market solutions focused on fast implementation. These segments are occupied by several DACH and EU providers; the market is still fragmented in 2026.
Vincent's Take: Enterprise providers are stronger in corporate pitches, mid-market solutions (which is where we count ourselves) stronger in pragmatic implementation. Which mid-market solutions will survive the next 12–24 months is open — a wave of consolidation is ahead here.
10. DPP & product counterfeiting
The OECD/EUIPO mapping "Global Trade in Fakes 2025" (Tier-1 source, data basis 2021) provides the order of magnitude:16
- Global counterfeit trade value: USD 467 billion (2.3 percent of all global imports)
- EU imports counterfeit value: USD 117 billion (4.7 percent of all EU imports)
- Share of clothing/footwear/leather in seizures: 62 percent
- Share of small parcels/mail in seizures: approx. 65 percent
Caveat: The data basis is 2021 (lag time for global trade statistics).
The DPP is primarily a compliance instrument, not a pure anti-counterfeiting tool. In combination with NFC (e.g., NTAG 424 DNA with cryptographic ECDSA signature), however, it becomes a strong proof of originality. Anyone who already has an anti-counterfeiting need can architect the DPP as a 2-in-1 solution.
11. Vincent's Take — the auditor's perspective
I am an IRCA-Certified ISO 9001 Lead Auditor (training via TÜV). When I look at the DPP, I don't see a new "compliance buzzword" but a shift in the burden of proof.
So far the rule was: the manufacturer claims properties, consumers and authorities trust — or sanction after the fact if something comes to light. From 2027 (batteries) and successively thereafter, this flips: the manufacturer must make the data structured and available before market entry, keep it for 10 years, and design it with multi-tier access. This is not a new form but a data-architecture project.
Three observations from audit practice
1. Data maturity is the actual bottleneck — not the software. In ISO 9001 audits I regularly see companies whose material, origin, and repair data are scattered across Excel, in people's heads, and in PDFs. A DPP platform can't conjure that away. Anyone who wants to be compliant in 2027 must identify, harmonize, and structure the data sources in 2026. In my experience this takes 6–12 months, not 6–12 weeks.
2. Audit trail becomes a core competency. ESPR Art. 10 requires 10 years of data availability. Every change to the DPP — material update, supplier change, recycled content — must be versioned and traceable. This is more than "database with backup": it is change-management discipline that many mid-sized companies do not have today for their master data.
3. The sales ban on batteries is harder than any fine. No one today knows exactly which fines the German market surveillance will impose (national penalty rules not yet final). But the Battery Regulation is unambiguous: no passport, no market entry from 18 Feb 2027. Anyone manufacturing EV batteries or industrial batteries > 2 kWh has a hard deadline.
What the DPP is not: a panacea or an end in itself. What it delivers: it makes supply and material flows structured and visible EU-wide for the first time. Whether companies turn this into a mere compliance obligation or a real marketing lever, they decide themselves — we see both paths working.
12. FAQ — Frequently asked questions about the DPP
What is a Digital Product Passport in short?
An electronic data record that stores the most important information about a product — material, origin, repairability, recycling, CO₂ — along its life cycle and makes it accessible via a data carrier such as a QR code or NFC tag for consumers, recyclers, and authorities.
From when is the DPP mandatory for my company?
It depends on the industry. Two hard-verified DPP deadlines are fixed: batteries (EV, Industrial > 2 kWh, LMT) from 18 February 2027 (Battery Regulation EU 2023/1542) and toys from 1 August 2030 (Toy Safety Regulation EU 2025/2509). For textiles, furniture, mattresses, tyres, and iron/steel and aluminium, obligations only arise with the respective Delegated Act; the ESPR working plan 2025–2030 gives only adoption dates for these (indicatively 2026–2029), not the start of the obligation — the application period follows afterwards.10 Not to be confused: 19 July 2026 is the deadline for the European Commission to set up the DPP Registry (ESPR Art. 13) — no obligation for manufacturers follows from it.
Do I absolutely need a QR code?
No. The ESPR is technology-neutral and permits various data carriers. The Toy Safety Regulation 2025/2509 explicitly names QR code "or other data carrier". QR is the cheapest and most widely used option; NFC is also permitted — and in cases with an anti-counterfeiting need often the better choice.
What does a DPP system cost?
There are currently no consolidated public estimates per product category. The costs depend heavily on: number of products, carrier technology (QR vs NFC), integration into existing ERP/PIM systems, internal data maintenance effort, and possibly compliance consulting. Flat-rate prices without a prior inventory assessment should raise suspicion.
What happens in case of non-compliance?
The EU regulations (ESPR Art. 74, Battery Reg Art. 93) require "effective, proportionate, and dissuasive" penalties, which each member state sets itself. Concrete fine amounts in Germany are, as of July 2026, not fixed in the national penalty rules under ESPR Art. 74. But: the Battery Regulation codifies that a battery without a passport may not enter the EU market from 18 Feb 2027 — a de facto sales ban.
Is the EU's DPP Registry already live?
Under ESPR Art. 13, the EU Commission had to set up the central DPP Registry by 19 July 2026 — that date has now been reached. No postponement of the deadline is known; we have not, however, verified proof of live operation, so we deliberately make no live claim here. For companies this changes little for now: the Registry is a directory that indexes product identifiers and points to where each passport is hosted — it does not store the DPP data itself. A duty to register only arises with the respective sectoral legal act; the first category to actually use the Registry is batteries from 18 February 2027. In parallel, the Commission is developing the service-provider rules (consultation ran from April to July 2025).18
Which products are explicitly exempt?
Food, animal feed, medical devices (human and veterinary), living plants/animals/microorganisms, products of human origin, products of animal/plant origin within the food chain, and vehicles (separate regulatory framework). Edge cases such as packaging mean a case-by-case assessment.
How long must DPP data remain available?
ESPR Art. 10 requires at least 10 years of data availability — even in the event of insolvency or range changes. This is a non-trivial technical requirement for hosting and backup. Anyone choosing a provider should contractually secure this 10-year availability.
What is CIRPASS-2 — and is it the EU standard?
No, CIRPASS-2 is not the EU standard. It is an EU-funded research and standardization-support project (Grant Agreement 101158775, ongoing as of July 2026) that develops proposals and recommendations for standardization bodies and regulators. Important deliverables: EU DPP Core Ontology Requirements (March 2025) and DPP Reference Architecture (May 2025). Correctly phrased: "We orient ourselves on the CIRPASS-2 architecture until EU-binding standards are adopted."13
What does GS1 have to do with the DPP?
GS1 (Global Trade Item Number, Digital Link, EPCIS 2.0, DataMatrix) is an industry standard, not EU-mandatory — but recommended by the industry and GS1 in Europe as the default for ESPR compliance. A GS1 membership costs approx. 300 EUR/year. No lock-in, optional.17
Do I need consulting — or can I do it myself?
It depends. Anyone with a clearly defined product portfolio (e.g., a toy brand with 20 SKUs) can set up the DPP themselves with a good SaaS solution and internal effort. Anyone with 5,000 SKUs across 8 industries or specific compliance risks benefits from an auditor-supported discovery workshop that clarifies the fundamental architecture decisions before tool selection.
What about wine and spirits?
Status unclear. Food is generally exempt from the ESPR (Art. 1(2)). Wine and spirits technically fall under Food Regulation 178/2002. Authentication against counterfeiting is, however, a large market in the industry, and some producers voluntarily deploy DPP-like systems. Whether a separate wine/spirits DPP regulation will come in the future is, as of July 2026, not conclusively clarified.