1. What exactly is a DPP? (Definition)

A Digital Product Passport (DPP) is an electronic data record that stores product information about material, origin, repairability, recycling, and CO₂ footprint and makes it accessible via a data carrier such as a QR code or NFC tag. The legal basis in the EU is Regulation (EU) 2024/1781 (ESPR), in force since 18 July 2024. Mandatory from 2026/2027 for batteries, from 2030 for toys, and progressively for textiles, construction products, and electronics.

The DPP makes the most important information about a product available in a structured form along its entire life cycle — for consumers, recyclers, repair businesses, and authorities. It is not a marketing label but a regulatory data infrastructure.1

Who is affected? In principle, almost all physical goods on the EU market. Exemptions include, among others, food, animal feed, medical devices, living organisms, and vehicles (separate regulatory framework).2

The most important deadlines at a glance:

2. What's inside the Digital Product Passport?

The specific data scope varies per product category — the respective Delegated Act of the EU Commission specifies the mandatory data fields. As a common framework, the ESPR base regulation prescribes these core building blocks:12

Identification

Compliance & Safety

Sustainability & Circular Economy

Supply chain information

Access layers (multi-tier access)

The DPP has different data levels. What the public sees, what recyclers see, and what authorities see is not the same. Using the example of the battery passport per EU Regulation 2023/1542 Annex XIII:3

Access tierWho?Which data?
PublicEnd consumersBasic info (model, manufacturer, safety notices)
Authorized actorsRecyclers, repair businessesExtended technical data
AuthoritiesMarket surveillance, EU CommissionFull access incl. compliance data
Notified BodiesCertification bodiesCompliance-relevant data

Important: The ESPR (Art. 10) requires that this data must remain available for at least 10 years — even if the manufacturer becomes insolvent or the product is dropped from the range.1 This is a demanding technical requirement profile for hosting and archiving.

3. Legal basis: ESPR (EU) 2024/1781

The Ecodesign for Sustainable Products Regulation (ESPR) is the umbrella framework. It replaces the old Ecodesign Directive 2009/125/EC and significantly expands its scope.1

FactValue
Regulation number(EU) 2024/1781
TitleRegulation establishing a framework for the setting of ecodesign requirements for sustainable products
Adopted13 June 2024 (Parliament + Council)
In force18 July 2024
First applicability19 July 2025 (disclosure for large companies, unsold goods)
ReplacesEcodesign Directive 2009/125/EC

Primary source: EUR-Lex — Regulation (EU) 2024/1781.1

Which products are covered?

In principle, almost all physical goods on the EU market — both finished products and components and intermediate products. Explicitly exempt (Art. 1(2)) are:12

For edge cases — such as packaging, which partly falls under the ESPR and partly under the Packaging Regulation — a specific assessment per product category is required.

The core articles on the DPP

ArticleContent
Art. 9DPP baseline requirements, data fields, multi-tier access
Art. 10Data management, hosting, decentralized data storage, 10-year availability
Art. 11Category-specific information requirements (repair, recycling, substances)
Art. 12Unique product identifier (ISO/IEC 15459)
Art. 13DPP Registry (EU-central; to be set up by the Commission by 19 July 2026)
Art. 25Destruction ban for unsold textiles/footwear
Art. 74Penalties (to be set by member states)

Working Plan 2025–2030

The EU Commission adopted the Working Plan on 16 April 2025 and published it on 11 July 2025. It names six priority product groups for which Delegated Acts with ecodesign and DPP requirements will be developed between 2025 and 2030:10

Product groupTypeDelegated Act — indicative adoption
Iron and steelIntermediate product2026
Textiles (apparel focus; footwear deferred for now)Final product2027
TyresFinal product2027
AluminiumIntermediate product2027
FurnitureFinal product2028
MattressesFinal product2029
Important — adoption ≠ start of the obligation: The years above are the indicative dates on which the Commission adopts the respective legal act. The point from which manufacturers must meet the requirements comes afterwards — usually after a transition period set out in the act itself. Reading these years as a compliance deadline means planning too early; assuming the transition period without tracking the adoption means planning too late.

In addition, the Working Plan continues work on 14 energy-related product groups carried over from the previous Ecodesign working plan, and announces horizontal measures — on the repairability of products generally and on the recyclability of electrical and electronic equipment. Electronics is therefore addressed, but through horizontal requirements rather than as a dedicated DPP product group.10

A mid-term review is planned for 2028.

4. Which industries, from when? — The timeline

As of July 2026. For moving targets (Delegated Acts not yet final), the status is explicitly indicated.

Hard-verified — the exact deadlines are set

IndustryRegulationMandatory fromDPP obligation
Batteries (EV, Industrial > 2 kWh, LMT)(EU) 2023/154218 February 2027Yes3
Toys(EU) 2025/25091 August 2030Yes6
Textiles/footwear — destruction ban(EU) 2024/1781 Art. 2519 July 2026 (large companies), 19 July 2030 (medium-sized). Micro and small enterprises are permanently exempt under Art. 25(1).No (separate disclosure)5
EU DPP Registry — Commission set-up deadline(EU) 2024/1781 Art. 1319 July 2026 — a deadline for the Commission, not for manufacturersn/a (infrastructure, no duty for companies to register)14

Expected (Delegated Act not yet final)

IndustryBasisExpected obligationStatus
Textiles DPPESPR + DAopen — DA adoption indicatively 2027, obligation afterwardsDA in preparation (JRC study underway)11
Electronics / ICTESPR + horizontal measuresopenNo dedicated DPP product group in the Working Plan; addressed via horizontal requirements on repairability and recyclability10
FurnitureESPR + DAopen — DA adoption indicatively 2028, obligation afterwardsPriority Working Plan10
MattressesESPR + DAopen — DA adoption indicatively 2029, obligation afterwardsPriority Working Plan10
Iron/steelESPR + DAopen — DA adoption indicatively 2026, obligation afterwardsPriority Working Plan, first group10
AluminiumESPR + DAopen — DA adoption indicatively 2027, obligation afterwardsPriority Working Plan10
TyresESPR + DAopen — DA adoption indicatively 2027, obligation afterwardsPriority Working Plan10
Construction products(EU) 2024/3110 (CPR)18 months after DA adoptionDA not yet adopted12

What is NOT covered

Food and medical devices are exempt under Art. 1(2) ESPR; vehicles fall under a separate regulatory framework.

Common misinformation about the timeline

Some inaccurate dates circulate in public discussion. Two examples that we checked against the primary sources:26

In case of diverging date claims, it's worth checking the primary source (EUR-Lex).

5. Example: The battery passport (Battery Passport)

The EU Battery Regulation (EU) 2023/1542 is the first DPP regulation with a hard-verified date (18 February 2027). Annex XIII lists the mandatory data fields:320

Which batteries are covered?3

CategoryBattery passport obligationThreshold
LMT (Light Means of Transport)Yes — from 18 Feb 2027All
EV (Electric Vehicle)Yes — from 18 Feb 2027All
Industrial batteriesYes — from 18 Feb 2027> 2 kWh
Portable (Consumer)No (labelling only)
SLI (Starting, Lighting, Ignition)No (labelling only)
"From 18 February 2027, a battery without a passport cannot legally be placed on the EU market or put into service." — EU Battery Regulation (EU) 2023/15423

In practice this means: anyone wanting to place EV batteries without a DPP on the EU market on 18 Feb 2027 will not get through market surveillance. There is no tolerance period.

6. Carrier technologies: QR, NFC, Blockchain

Important — carrier ≠ data: QR code, NFC, and blockchain are carrier technologies. The DPP itself is the data. A QR code or NFC tag points to the product data or makes it accessible — it "is" not the product passport. Carrier and data model are chosen independently of each other.

QR code

NFC (Near Field Communication)

Blockchain

In addition, research discusses decentralized identifiers and Verifiable Credentials (W3C) as architecture building blocks — however, these are not EU-mandatory.19

Vincent's Take: For pure ESPR compliance, a QR code is sufficient in many cases. For industries with an anti-counterfeiting need (luxury, pharma, high-priced branded goods), NFC is worthwhile as an additional layer. In 2026, blockchain is more than necessary in most cases — useful only when there is a concrete tamper-evidence need and the team knows what it's doing.

7. What does a DPP cost?

Honest answer: There are currently no consolidated public Tier-1 estimates for sector-specific DPP compliance costs per product category.14

What we know:

Key cost factors

FactorDriver
Platform/software costsNumber of products, API calls, multi-tenancy
Data maintenanceWho maintains it — internal employee, manufacturer partner, agency?
Carrier technologyQR (cheap) vs NFC (higher) vs hybrid
IntegrationERP/PIM/PLM connection — usually the biggest chunk
Hosting & 10-year availabilityGDPR-compliant, EU-hosted
Audit & compliance consultingAuditor support, legal review

Blanket "a DPP costs X EUR per product" answers are misleading: the costs depend so heavily on product portfolio, data maturity, and industry that model calculations without a concrete data basis are hardly reliable. Serious cost estimates therefore require an analysis of the specific product portfolio — flat-rate offers without a prior inventory assessment should be treated with caution.

8. Penalties for non-compliance

Verified (ESPR Art. 74):17

For the Battery Regulation (Art. 93), a similar scheme applies — here too, member states set the penalties.3

What is still open as of July 2026:7

From comparable EU regulations (e.g., GDPR with revenue-dependent fines), such a pattern is known — whether the ESPR implementation follows it is open and here expressly speculation, not an ESPR fact.

The hard deadline counts more than any fine: No one today knows the concrete fine amounts of the German market surveillance. But the Battery Regulation is unambiguous — no passport, no market entry from 18 Feb 2027. For EV batteries or industrial batteries > 2 kWh, this means: a fixed deadline, no leeway. Non-compliant products simply generate zero revenue from that date.

9. The DPP market 2026

According to MarketsandMarkets, the global DPP market is growing from USD 185.9 million (2024) to USD 1,780.5 million (2030) — CAGR 45.7 percent.8 An alternative estimate by Grand View Research is USD 213.9 million (2024) → USD 1,230.9 million (2030) with 34.9 percent CAGR.15 Both are commercial market research — not peer-reviewed, but industry standard.

Europe holds 36.29 percent of the market (2024), according to Grand View Research driven by ESPR and the Circular Economy Action Plan.9 Fashion & Textiles (dominant in 2024) is considered the driving sector, followed by pharma, electronics, automotive (EV batteries), and luxury goods.8

Market structure in the DACH/EU region

The market roughly splits into two camps: enterprise platforms focused on corporate supply chains (decentralized-identity approaches, ESG suites, battery/mining specialists) and pragmatic mid-market solutions focused on fast implementation. These segments are occupied by several DACH and EU providers; the market is still fragmented in 2026.

Vincent's Take: Enterprise providers are stronger in corporate pitches, mid-market solutions (which is where we count ourselves) stronger in pragmatic implementation. Which mid-market solutions will survive the next 12–24 months is open — a wave of consolidation is ahead here.

10. DPP & product counterfeiting

The OECD/EUIPO mapping "Global Trade in Fakes 2025" (Tier-1 source, data basis 2021) provides the order of magnitude:16

Caveat: The data basis is 2021 (lag time for global trade statistics).

The DPP is primarily a compliance instrument, not a pure anti-counterfeiting tool. In combination with NFC (e.g., NTAG 424 DNA with cryptographic ECDSA signature), however, it becomes a strong proof of originality. Anyone who already has an anti-counterfeiting need can architect the DPP as a 2-in-1 solution.

11. Vincent's Take — the auditor's perspective

I am an IRCA-Certified ISO 9001 Lead Auditor (training via TÜV). When I look at the DPP, I don't see a new "compliance buzzword" but a shift in the burden of proof.

So far the rule was: the manufacturer claims properties, consumers and authorities trust — or sanction after the fact if something comes to light. From 2027 (batteries) and successively thereafter, this flips: the manufacturer must make the data structured and available before market entry, keep it for 10 years, and design it with multi-tier access. This is not a new form but a data-architecture project.

Three observations from audit practice

1. Data maturity is the actual bottleneck — not the software. In ISO 9001 audits I regularly see companies whose material, origin, and repair data are scattered across Excel, in people's heads, and in PDFs. A DPP platform can't conjure that away. Anyone who wants to be compliant in 2027 must identify, harmonize, and structure the data sources in 2026. In my experience this takes 6–12 months, not 6–12 weeks.

2. Audit trail becomes a core competency. ESPR Art. 10 requires 10 years of data availability. Every change to the DPP — material update, supplier change, recycled content — must be versioned and traceable. This is more than "database with backup": it is change-management discipline that many mid-sized companies do not have today for their master data.

3. The sales ban on batteries is harder than any fine. No one today knows exactly which fines the German market surveillance will impose (national penalty rules not yet final). But the Battery Regulation is unambiguous: no passport, no market entry from 18 Feb 2027. Anyone manufacturing EV batteries or industrial batteries > 2 kWh has a hard deadline.

What the DPP is not: a panacea or an end in itself. What it delivers: it makes supply and material flows structured and visible EU-wide for the first time. Whether companies turn this into a mere compliance obligation or a real marketing lever, they decide themselves — we see both paths working.

12. FAQ — Frequently asked questions about the DPP

What is a Digital Product Passport in short?

An electronic data record that stores the most important information about a product — material, origin, repairability, recycling, CO₂ — along its life cycle and makes it accessible via a data carrier such as a QR code or NFC tag for consumers, recyclers, and authorities.

From when is the DPP mandatory for my company?

It depends on the industry. Two hard-verified DPP deadlines are fixed: batteries (EV, Industrial > 2 kWh, LMT) from 18 February 2027 (Battery Regulation EU 2023/1542) and toys from 1 August 2030 (Toy Safety Regulation EU 2025/2509). For textiles, furniture, mattresses, tyres, and iron/steel and aluminium, obligations only arise with the respective Delegated Act; the ESPR working plan 2025–2030 gives only adoption dates for these (indicatively 2026–2029), not the start of the obligation — the application period follows afterwards.10 Not to be confused: 19 July 2026 is the deadline for the European Commission to set up the DPP Registry (ESPR Art. 13) — no obligation for manufacturers follows from it.

Do I absolutely need a QR code?

No. The ESPR is technology-neutral and permits various data carriers. The Toy Safety Regulation 2025/2509 explicitly names QR code "or other data carrier". QR is the cheapest and most widely used option; NFC is also permitted — and in cases with an anti-counterfeiting need often the better choice.

What does a DPP system cost?

There are currently no consolidated public estimates per product category. The costs depend heavily on: number of products, carrier technology (QR vs NFC), integration into existing ERP/PIM systems, internal data maintenance effort, and possibly compliance consulting. Flat-rate prices without a prior inventory assessment should raise suspicion.

What happens in case of non-compliance?

The EU regulations (ESPR Art. 74, Battery Reg Art. 93) require "effective, proportionate, and dissuasive" penalties, which each member state sets itself. Concrete fine amounts in Germany are, as of July 2026, not fixed in the national penalty rules under ESPR Art. 74. But: the Battery Regulation codifies that a battery without a passport may not enter the EU market from 18 Feb 2027 — a de facto sales ban.

Is the EU's DPP Registry already live?

Under ESPR Art. 13, the EU Commission had to set up the central DPP Registry by 19 July 2026 — that date has now been reached. No postponement of the deadline is known; we have not, however, verified proof of live operation, so we deliberately make no live claim here. For companies this changes little for now: the Registry is a directory that indexes product identifiers and points to where each passport is hosted — it does not store the DPP data itself. A duty to register only arises with the respective sectoral legal act; the first category to actually use the Registry is batteries from 18 February 2027. In parallel, the Commission is developing the service-provider rules (consultation ran from April to July 2025).18

Which products are explicitly exempt?

Food, animal feed, medical devices (human and veterinary), living plants/animals/microorganisms, products of human origin, products of animal/plant origin within the food chain, and vehicles (separate regulatory framework). Edge cases such as packaging mean a case-by-case assessment.

How long must DPP data remain available?

ESPR Art. 10 requires at least 10 years of data availability — even in the event of insolvency or range changes. This is a non-trivial technical requirement for hosting and backup. Anyone choosing a provider should contractually secure this 10-year availability.

What is CIRPASS-2 — and is it the EU standard?

No, CIRPASS-2 is not the EU standard. It is an EU-funded research and standardization-support project (Grant Agreement 101158775, ongoing as of July 2026) that develops proposals and recommendations for standardization bodies and regulators. Important deliverables: EU DPP Core Ontology Requirements (March 2025) and DPP Reference Architecture (May 2025). Correctly phrased: "We orient ourselves on the CIRPASS-2 architecture until EU-binding standards are adopted."13

What does GS1 have to do with the DPP?

GS1 (Global Trade Item Number, Digital Link, EPCIS 2.0, DataMatrix) is an industry standard, not EU-mandatory — but recommended by the industry and GS1 in Europe as the default for ESPR compliance. A GS1 membership costs approx. 300 EUR/year. No lock-in, optional.17

Do I need consulting — or can I do it myself?

It depends. Anyone with a clearly defined product portfolio (e.g., a toy brand with 20 SKUs) can set up the DPP themselves with a good SaaS solution and internal effort. Anyone with 5,000 SKUs across 8 industries or specific compliance risks benefits from an auditor-supported discovery workshop that clarifies the fundamental architecture decisions before tool selection.

What about wine and spirits?

Status unclear. Food is generally exempt from the ESPR (Art. 1(2)). Wine and spirits technically fall under Food Regulation 178/2002. Authentication against counterfeiting is, however, a large market in the industry, and some producers voluntarily deploy DPP-like systems. Whether a separate wine/spirits DPP regulation will come in the future is, as of July 2026, not conclusively clarified.