WHAT A DPP
actually has to do.

12 CORE REQUIREMENTS

The ESPR establishes the common architecture. Product-specific delegated acts decide the final data fields and implementation details. This guide separates the durable system requirements from product-specific rules that are still emerging.

01

Product-specific rules decide the final passport

The applicable delegated act determines which data must be included, which carrier is used, where it appears, whether the passport is model-, batch-, or item-level, who may access or update data, and how long the passport must remain available.

ESPR Article 9(2)PRIMARY SOURCE
02

Passport data must stay accurate, complete, and current

A DPP is not a one-time label. The regulation requires the passport data to be accurate, complete, and up to date for the applicable product.

ESPR Article 9(1)PRIMARY SOURCE
03

A persistent unique product identifier is required

The passport must be connected through a data carrier to a persistent unique product identifier.

ESPR Article 10(1)(a)PRIMARY SOURCE
04

The data carrier must exist in the physical product context

The applicable act will specify whether the carrier is physically present on the product, its packaging, or accompanying documentation.

ESPR Article 10(1)(b)PRIMARY SOURCE
05

Open standards and interoperable data are core requirements

DPP data must use open standards and an interoperable format and, where appropriate, be machine-readable, structured, searchable, and transferable without vendor lock-in.

ESPR Article 10(1)(d)PRIMARY SOURCE
06

Customer personal data needs explicit consent

Personal data relating to customers cannot be stored in the DPP without explicit consent under applicable data-protection law.

ESPR Article 10(1)(e)PRIMARY SOURCE
07

Access is role-based, not necessarily public

The applicable product rules specify which actors can access which data. The technical design must make access easy and free of charge for actors according to their respective rights.

ESPR Articles 10(1)(g) and 11(b)PRIMARY SOURCE
08

A backup copy must be made available through a DPP service provider

When placing a product on the market, the responsible economic operator must make a backup copy of the passport available through a Digital Product Passport service provider.

ESPR Article 10(4)PRIMARY SOURCE
09

DPPs must interoperate with other DPPs

The system must support technical, semantic, and organisational interoperability for end-to-end communication and data transfer.

ESPR Article 11(a)PRIMARY SOURCE
10

The passport must remain available beyond normal business continuity

DPP availability must survive for the period specified in the product rules, including after insolvency, liquidation, or cessation of activity by the economic operator responsible for its creation.

ESPR Article 11(e)PRIMARY SOURCE
11

Authentication, integrity, security, and privacy are explicit requirements

The technical design must ensure data authentication, reliability, integrity, a high level of security and privacy, and protection against fraud.

ESPR Article 11(g)–(h)PRIMARY SOURCE
12

Economic operators must plan for DPP Registry registration

The Commission states that in-scope DPPs must be registered in the EU DPP Registry in line with the relevant technical specifications and legal requirements before products are placed on the Single Market.

European Commission — Economic operatorsPRIMARY SOURCE

THE FRAMEWORK
is not the final schema.

The exact data fields, identifier level, carrier placement, access rights, and retention period depend on the legislation or delegated act applying to the product group. Use this page as an architecture checklist, then verify the applicable sector rule before making a compliance decision.

TRACK UPCOMING SECTOR RULES