Digital Product Passport Requirements — What You Need to Know
What are the Digital Product Passport requirements? Data fields, formats, QR codes, GS1 Digital Link, responsibilities for manufacturers, importers and distributors, and penalties for non-compliance.
Digital Product Passport Requirements — What You Need to Know
A Digital Product Passport (DPP) is not a single document you upload somewhere. It is a structured set of data, linked to a product identifier, accessible through a data carrier, and meeting specific technical and legal criteria. The requirements span what data must be included, in what format, how it must be accessible, and who bears responsibility.
This article breaks down the concrete requirements that companies must meet under EU DPP regulations.
For an overview of the regulations themselves, see: Digital Product Passport Regulation — Complete Guide 2026.
Key takeaways
- DPP requirements cover data content, data format, access mechanism, and organizational responsibility.
- The specific data points vary by product category (defined in delegated acts), but the structural requirements are consistent.
- Every DPP must be accessible via a data carrier (typically a QR code) linked to a unique product identifier.
- GS1 Digital Link is the recommended standard for linking identifiers to DPP data.
- Primary responsibility falls on whoever places the product on the EU market.
Data requirements: what must be included
DPP data requirements are defined at two levels:
- General requirements (from ESPR) — apply to all DPPs regardless of product category
- Category-specific requirements (from delegated acts) — define the exact data points for each product type
General data requirements
Every DPP must include:
| Data category | Required information |
|---|---|
| Product identification | Unique product identifier, product name, model, batch/serial number |
| Manufacturer information | Company name, registered address, contact details |
| Manufacturing data | Country of manufacture, production facility (where applicable) |
| Compliance data | EU Declaration of Conformity, applicable standards, CE marking info |
| Sustainability data | Environmental footprint (where calculated), recycled content, durability information |
| End-of-life information | Disassembly instructions, recycling guidance, hazardous substances |
| Supply chain data | Key materials and their origins (level of detail varies by category) |
Category-specific data examples
The exact data points depend on the product category. Here are examples from regulations and draft delegated acts already published:
Batteries (EU Battery Regulation):
- Battery chemistry and composition
- Carbon footprint per kWh (calculated per EU methodology)
- Recycled content percentages (cobalt, lithium, nickel, lead)
- State of health parameters
- Expected lifetime (in cycles and years)
- Collection and recycling information
Textiles (ESPR delegated act — in preparation):
- Fiber composition with percentages
- Country of manufacturing (each production stage)
- Chemical substances used (REACH-relevant)
- Durability test results
- Care instructions
- Recyclability assessment
Construction products (CPR):
- Declaration of Performance data
- Environmental Product Declaration (EPD) data
- Essential characteristics per harmonized standard
- AVCP (Assessment and Verification of Constancy of Performance) system
Data format requirements
DPP data must be:
- Machine-readable — structured in a way that software systems can parse automatically (not PDFs, not scanned documents)
- Interoperable — using standardized schemas so that data from different manufacturers can be compared and aggregated
- Verifiable — authorities must be able to confirm the data’s origin and integrity
- Updatable — certain data (e.g., state of health for batteries) must be updated during the product lifecycle
The European Commission and standardization bodies (CEN/CENELEC) are developing the technical standards for DPP data schemas. The current direction points toward:
- JSON-LD or similar linked data formats for data structure
- Standardized vocabularies aligned with existing EU databases (SCIP, EPREL)
- API-based access for machine-to-machine communication
- Human-readable views for consumers accessing via QR code scan
Access mechanism: data carriers and identifiers
Unique product identifier
Every product covered by a DPP obligation must carry a unique identifier. The regulations do not mandate a specific identification system, but strongly align with GS1 standards:
- GTIN (Global Trade Item Number) — for product model-level identification
- SGTIN (Serialized GTIN) — for individual item-level identification
- GIAI (Global Individual Asset Identifier) — for assets like batteries
The identifier must be globally unique and persistent throughout the product lifecycle.
Data carrier
The identifier must be physically present on the product (or its packaging) via a data carrier:
| Data carrier | Use case | DPP relevance |
|---|---|---|
| QR code | Most common, easily scanned by smartphones | Primary method for consumer access |
| Data Matrix | Smaller than QR, common in industrial settings | Used where space is limited |
| RFID/NFC | Embedded in products, no line-of-sight needed | Useful for textiles, electronics |
GS1 Digital Link
GS1 Digital Link is the recommended method for connecting the data carrier to the DPP data. It encodes the product identifier into a web-resolvable URL, enabling:
- One QR code that serves multiple purposes (compliance data, consumer information, logistics)
- Automatic routing to the correct data based on who scans it
- Compatibility with existing GS1 infrastructure used globally
For a detailed comparison of QR approaches, see: QR Code vs GS1 Digital Link — differences for DPP.
Who is responsible
DPP regulations assign responsibility along the supply chain. The obligations differ depending on your role.
Manufacturer
The manufacturer bears the primary obligation:
- Create the DPP before the product is placed on the EU market
- Provide all required data points accurately
- Ensure the data carrier is applied to the product or packaging
- Keep the DPP data accessible for the required retention period (minimum 10 years after the last unit is placed on the market, under ESPR)
- Update data when required (e.g., battery state of health)
Importer
If you import products into the EU:
- Verify that the manufacturer has created a valid DPP
- Ensure the data carrier is present and functional
- Ensure the DPP is accessible and complete
- You become the responsible economic operator if the manufacturer is outside the EU and has no authorized representative
Distributor
Distributors (wholesalers, retailers) must:
- Not remove or obscure data carriers
- Not alter DPP data
- Verify that products they sell carry a functional DPP (due diligence)
- Report any suspected non-compliance to market surveillance authorities
Authorized representative
Non-EU manufacturers can appoint an authorized representative within the EU. This representative assumes the manufacturer’s obligations regarding DPP compliance, including creating and maintaining the passport.
Data hosting and retention
DPP data must remain accessible for a defined period:
- ESPR: minimum 10 years after the last unit of the product model is placed on the market
- Battery Regulation: data must remain accessible throughout the battery lifecycle plus additional time for recycling verification
- CPR: aligned with the expected working life of the construction product
This means companies need a reliable hosting solution. If a DPP software provider goes out of business, the data must still be accessible. The EU is considering requirements for data portability and escrow arrangements to address this risk.
Penalties for non-compliance
The EU regulations require member states to establish penalty regimes that are “effective, proportionate and dissuasive.” While specific amounts are set nationally, the consequences include:
Financial penalties:
- Fines based on the severity of the infringement and company turnover
- Member states are defining fine ranges — expect figures comparable to other EU product compliance fines (up to several percent of annual turnover for serious violations)
Market access restrictions:
- Products without a valid DPP can be blocked from the EU market
- Customs authorities can hold shipments at the border
- Authorities can order product withdrawal or recall
Other consequences:
- Public naming of non-compliant companies
- Mandatory corrective actions with deadlines
- Repeated non-compliance can lead to escalated penalties
How to prepare: practical steps
Step 1: Assess your data readiness
Map your existing product data against the requirements for your product category. Most companies already have 60–80% of the required data in their ERP, PIM, or PLM systems — but it is often scattered, inconsistent, or in non-standard formats.
See: DPP and ERP Integration — a practical guide.
Step 2: Identify data gaps
Common gaps include:
- Carbon footprint calculations (requires Life Cycle Assessment methodology)
- Recycled content percentages (requires supply chain data collection)
- Detailed material composition (beyond what sales/marketing data provides)
- End-of-life and recycling instructions
Step 3: Establish data governance
Assign ownership for each data category. DPP data quality depends on clear responsibilities — who collects, validates, and updates each data point.
Step 4: Choose your DPP platform
Select a software solution that:
- Supports the data schemas for your product categories
- Integrates with your existing systems (ERP, PIM)
- Generates GS1 Digital Link-compliant QR codes
- Provides data validation and completeness checks
- Supports multi-language output (required for EU-wide sales)
Step 5: Pilot and scale
Start with a small product subset. Validate the entire chain — from data collection to QR code scanning to data display. Then scale across your catalog.
For a complete implementation checklist, see: How to implement DPP — complete checklist.