Regulations

EU Toy Safety Regulation (EU 2025/2509): the DPP becomes mandatory

The new EU Toy Safety Regulation (EU) 2025/2509 makes a Digital Product Passport mandatory for every toy and lets it replace the EU declaration of conformity. What the DPP must contain, the data carrier and chemical rules, and the road to 1 August 2030.

Author: myDPP Team

EU Toy Safety Regulation (EU 2025/2509): the DPP becomes mandatory

Until now, the Digital Product Passport was mostly an ecodesign story: the ESPR sets the framework, and delegated acts will fill it category by category. The Toy Safety Regulation changes the picture. It is the first piece of EU product legislation in which a Digital Product Passport is not an add-on but the primary proof of conformity — and it replaces the document that has anchored CE compliance for decades, the EU declaration of conformity.

Regulation (EU) 2025/2509 on the safety of toys was published in the Official Journal on 12 December 2025 and entered into force on 1 January 2026. Its substantive requirements — including the mandatory DPP — apply from 1 August 2030. This article explains what the regulation requires, what the toy DPP must contain, how it relates to the Digital Product Passport under the ESPR, and what toy companies should be doing during the transition.


Key takeaways

  • Regulation (EU) 2025/2509 (the Toy Safety Regulation, TSR) replaces the Toy Safety Directive 2009/48/EC. It entered into force on 1 January 2026 and applies from 1 August 2030, giving a 54-month transition.
  • A Digital Product Passport is mandatory for every toy placed on the EU market — and it replaces the EU declaration of conformity as the primary demonstration of conformity.
  • The DPP is a structured, machine-readable dataset linked to the toy through a persistent unique product identifier and reached via a data carrier (QR code or similar) on the toy or its label, accessible before purchase.
  • It must be available in the official language(s) of the Member States where the toy is sold and remain accessible for at least 10 years after the toy is placed on the market.
  • Before placing a toy on the market, the operator registers the unique product identifier and unique operator identifier in the central EU registry set up under the ESPR — the same registry infrastructure the horizontal DPP will use.
  • Chemical rules tighten substantially: a generic ban on CMR substances, endocrine disruptors, skin sensitisers and persistent substances, plus a ban on the intentional use of PFAS with narrow technical exceptions.
  • myDPP does not perform safety assessments, does not carry out chemical testing, is not a notified body and does not issue statements of conformity. myDPP stores, versions and serves the verified product data and the data carrier that opens it.

What the Toy Safety Regulation is

The TSR is the recast of EU toy safety law. The old regime, Directive 2009/48/EC, had to be transposed into 27 national laws; a regulation applies directly and uniformly across the Union. That change alone removes a long-standing source of divergent national interpretation for a product category sold almost entirely cross-border.

The substance changes too. The regulation was drafted around three problems the 2009 directive handled poorly: chemicals whose risks became clear only after 2009, toys sold directly to consumers from outside the EU through online marketplaces, and compliance documentation that existed only on paper, in a drawer, at the manufacturer. The DPP is the answer to the third problem — and, indirectly, to the second.

Timeline

DateMilestone
25 November 2025Regulation adopted
12 December 2025Published in the Official Journal of the EU
1 January 2026Entry into force; Articles 28–44 and 49–55 apply (notified bodies, administrative and empowerment provisions)
1 August 2030General application — all substantive requirements, including the mandatory DPP
1 August 2030Directive 2009/48/EC repealed; toys compliant with the directive may be placed on the market until this date
1 February 2031EU-type examination certificates issued under the old directive cease to be valid

The Commission is to adopt a delegated act laying down the technical specifications of the toy DPP before general application. Until then, the data elements are known from the regulation itself; the exact formats, protocols and interoperability requirements are not.

The Digital Product Passport for toys

It replaces the declaration of conformity

This is the most consequential shift. Under the classic New Legislative Framework, the manufacturer draws up an EU declaration of conformity — a signed document naming the product, the applicable legislation, the harmonised standards used and, where relevant, the notified body. Under the TSR, that document gives way to the DPP: the passport itself carries the statement of conformity and becomes what market surveillance authorities, customs, retailers and consumers consult.

The consequence for compliance work is not cosmetic. A declaration of conformity is authored once per product model and archived. A DPP is a live, addressable dataset that must stay correct, reachable and versioned for a decade — which makes it a data-management obligation rather than a documentation obligation.

What the DPP must contain

The regulation sets out the mandatory content. Confirmed elements include:

  • the unique product identifier and a clear colour image of the toy of sufficient quality for identification;
  • the name, registered trade name, address and contact details of the manufacturer, together with a unique operator identifier, and of the importer where applicable;
  • a statement of conformity with the regulation, plus references to the applicable EU legislation and to the harmonised standards or common specifications applied;
  • the CE marking and the commodity code;
  • details of the notified body, where a conformity assessment body was involved;
  • instructions for use, safety information and warnings, including the list of allergenic fragrances present;
  • a channel for contacting the responsible economic operator about safety concerns or complaints;
  • a reference to the DPP service provider hosting the backup copy.

Notably, the passport must not contain personal data about customers. It is a product record, not a customer record.

The data carrier

The DPP is reached through a data carrier — a QR code, barcode or comparable machine-readable element — linked to a persistent unique product identifier. The carrier must be physically present on the toy itself or on a label attached to it. Only where that is impossible because of the size or nature of the toy may it be placed on the packaging or on documentation accompanying the toy. In distance selling it must be accessible to the buyer before purchase.

If you already work with GS1 identifiers, this is familiar ground: the same identity layer that carries a GTIN can resolve to a passport. Our comparison of QR codes and GS1 Digital Link covers the trade-offs between a plain URL in a QR code and a standards-based resolver.

Languages, availability and the registry

Three operational requirements deserve attention because they shape system design rather than paperwork:

  • Language — the information must be presented in the official language or languages of every Member State in which the toy is placed on the market. For a toy sold across the EU, that is a translation and content-governance problem at product-data level.
  • Ten years — the DPP must remain available for at least ten years after the toy is placed on the market, regardless of whether the model is still sold, the supplier still exists or the internal system has since been replaced. Persistence, not just publication.
  • The registry — before placing a toy on the market, the economic operator submits the unique product identifier and its unique operator identifier to the central EU registry established under the ESPR. The toy DPP therefore plugs into the horizontal DPP infrastructure rather than creating a parallel one.

DPP service providers

The regulation recognises that most manufacturers will not host passports themselves. A DPP service provider is an independent third party authorised by the economic operator to process the passport data and keep a backup copy. The reference to that provider is itself part of the passport content.

One point is unambiguous: outsourcing the technology does not outsource the responsibility. The manufacturer remains fully accountable for the accuracy, completeness and legal conformity of everything in the DPP.

Stricter chemical requirements

The TSR moves further towards a generic (hazard-based) approach: substances are restricted because of their classification, not only after a toy-specific limit has been negotiated. In outline:

  • CMR substances — carcinogenic, mutagenic or toxic for reproduction, categories 1A, 1B and 2, are prohibited.
  • Endocrine disruptors (categories 1 and 2), substances with specific target organ toxicity, respiratory sensitisers, and skin sensitisers of category 1A are prohibited.
  • PFAS — the intentional use of per- and polyfluoroalkyl substances in toys, or in micro-structurally distinct parts of toys, is banned. Narrow technical exceptions exist, for example for certain stainless steel and conductive components and for neodymium magnets.
  • Bisphenol A — a stricter migration limit applies (0.005 mg/l).
  • Allergenic fragrances — the listed fragrances are banned unless technically unavoidable and below 10 mg/kg; the rules are strictest for toys intended for children under 36 months and toys intended to be placed in the mouth.
  • N-nitrosamines and nitrosatable substances — new limits differentiated by toy type and age group.
  • Biocidal products — not permitted, except in toys intended to remain outdoors.

For data purposes the important part is that these obligations generate evidence: supplier declarations, test reports, material and substance data per component. If that evidence already lives in a structured product-data model, the substance side of the DPP becomes a query rather than a project. Toys are also articles in the REACH sense, which brings the SCIP database and SVHC notification duties into the same data conversation.

Safety assessment, technical documentation and the supply chain

Before placing a toy on the market, the manufacturer must carry out a safety assessment covering the relevant hazards — mechanical, physical, flammability, chemical, electrical, hygiene and radioactivity — taking account of the particular vulnerabilities of children and of combined exposure to chemicals. The result goes into the technical documentation.

The regulation also allocates duties along the chain. Importers and distributors have verification and market-surveillance obligations. Fulfilment service providers must handle toys with due care in warehousing, packaging and dispatch, must not compromise compliance, and must cooperate in recalls and withdrawals. Online marketplaces must design their interfaces so that traders can display the CE marking, the mandatory warnings and a link to the DPP before purchase — which is how the passport reaches the buyer in a distance sale.

TSR, CE marking and the GPSR — how they fit together

Three regimes touch a toy, and they do different work:

  • The TSR is the sector-specific harmonised law. It sets the essential safety requirements, the chemical limits, the conformity assessment routes and, from 2030, the DPP.
  • The CE marking remains. CE is the manufacturer’s declaration that the product meets the applicable Union requirements; the TSR changes how that conformity is evidenced (DPP instead of declaration of conformity), not the marking itself. The CE marking is one of the mandatory DPP data elements.
  • The GPSR is the horizontal safety net. Because toys have sector-specific harmonised legislation, the GPSR applies only to safety aspects and risks the TSR does not cover — plus its distance-selling and marketplace machinery, and the Safety Gate.

A toy therefore carries CE marking, complies with the TSR, and falls back on the GPSR for anything the TSR leaves open.

The toy DPP and the DPP under ESPR

It is worth being precise about the relationship, because the two passports are not the same thing arriving twice.

The ESPR is the horizontal framework: it defines what a Digital Product Passport is, sets up the registry and the web portal, and delegates the category-specific data requirements to future delegated acts. Its focus is sustainability — durability, repairability, recycled content, carbon footprint, substances of concern.

The TSR uses that same infrastructure for a different purpose: conformity and safety. The toy passport is registered in the ESPR registry and reached through the same kind of data carrier, but its mandatory content is compliance evidence, warnings and traceability rather than ecodesign metrics. Sustainability information for toys is expected to arrive later, through an ESPR delegated act — at which point one passport per toy will serve both purposes.

The practical reading for a toy company: you will not be asked to build two passports. You will be asked to build one product-data foundation good enough to serve a safety-driven passport in 2030 and an ecodesign-driven extension afterwards. That is an argument for treating this as product data management, not as a compliance document exercise.

And to be clear about our own role: myDPP does not carry out safety assessments, does not perform chemical or mechanical testing, is not a notified body and does not issue statements of conformity. Those responsibilities sit with manufacturers, importers and conformity assessment bodies. What myDPP does is store, version and serve the verified product data — identifiers, operator details, conformity references, warnings, document links — and provide the resolvable data carrier through which that data reaches whoever scans the toy.

What toy companies should do now

1. Map the portfolio against the new chemical rules

The 54-month transition is mostly chemistry, not software. Identify toys and components affected by the PFAS ban, the generic CMR and endocrine-disruptor prohibitions, the bisphenol A limit and the fragrance rules. Reformulation and re-sourcing have the longest lead times of anything in this regulation.

2. Decide where the product identifier comes from

The DPP hangs on a persistent unique product identifier. Decide now whether that is a GS1 identifier, an internal scheme or a mix, and make sure it is stable across packaging changes, suppliers and system migrations. Retrofitting identity later is expensive.

3. Inventory the data you will have to publish

Take the mandatory content list and check, element by element, where each item lives today: manufacturer and importer details, harmonised standards applied, notified body reference, warnings, allergenic fragrance list, product image, commodity code. The gaps you find are the real project.

4. Plan for translations and for ten years

Warnings and instructions must be available in the languages of every market where the toy is sold, and the passport must survive a decade. Both requirements argue for one governed source of product content rather than per-market spreadsheets.

5. Bring in commercial and e-commerce teams early

Marketplace interfaces must show the CE marking, warnings and DPP link before purchase. That touches product feeds, packaging artwork and label design — teams that are usually invited to compliance projects far too late. Our DPP implementation checklist walks through the sequence.

Frequently asked questions

When does the toy DPP become mandatory?

From 1 August 2030. The regulation entered into force on 1 January 2026, but the substantive requirements — including the DPP — apply only from 1 August 2030. Toys compliant with Directive 2009/48/EC may be placed on the market until that date.

Does the DPP really replace the EU declaration of conformity for toys?

Yes. Under Regulation (EU) 2025/2509 the Digital Product Passport takes over the role of the EU declaration of conformity as the primary demonstration that a toy conforms. The CE marking itself remains, and is one of the mandatory data elements inside the passport.

Where does the QR code have to go?

On the toy itself, or on a label attached to it. Only where that is not possible because of the size or nature of the toy may it be placed on the packaging or on accompanying documentation. In online sales it must be accessible before purchase.

How long must a toy DPP stay online?

At least ten years after the toy is placed on the market — independently of whether the model is still being sold.

Is the toy DPP the same as the ESPR passport?

It uses the same infrastructure — the central EU registry and a data-carrier-based passport — but its mandatory content is conformity, safety and traceability data rather than ecodesign metrics. Sustainability data for toys is expected through a later ESPR delegated act.

Do we still need a notified body?

It depends on the conformity assessment route. Where harmonised standards fully cover the applicable requirements, the manufacturer can self-assess; otherwise EU-type examination by a notified body applies. Where a notified body is involved, its details go into the DPP.

Read more

Sources

  • Regulation (EU) 2025/2509 on the safety of toys — EUR-Lex
  • Directive 2009/48/EC on the safety of toys — EUR-Lex
  • Regulation (EU) 2024/1781 (ESPR) — EUR-Lex
  • European Commission — toy safety and product legislation