Digital Product Passport

What Is the EU Digital Product Passport? Deadlines, Exemptions, and What Just Changed

The EU's central DPP registry went live this week. Here's what a Digital Product Passport actually is, why it exists, and the real deadlines manufacturers need to plan around now.

Tylko Advisors·23 July 2026·8 min read

In less than two years, the entire definition of what makes a physical product legal to sell in Europe is going to fundamentally change. A perfectly manufactured product with a missing or broken digital record will be treated the same as non-compliant goods: it won't clear customs.

Quick answer: A Digital Product Passport (DPP) is a digital identity record for a physical product, accessed via a QR code or NFC tag, that holds verifiable data about its materials, environmental impact, and how to repair or recycle it. The EU's central DPP registry went live on 20 July 2026. The first hard product deadline is 18 February 2027, for EV and industrial batteries above 2 kWh, under Regulation (EU) 2023/1542. The rules apply to any brand selling into the EU market, regardless of where the company is based.

What is a Digital Product Passport?

A Digital Product Passport (DPP) is a digital identity record for a physical product, accessible via a QR code or NFC tag, that holds a product's life story: where its raw materials came from, how it was made, and exactly how to repair or recycle it. Think of it as a CARFAX report combined with a detailed nutrition label, but for physical goods generally, not just cars.

The legal foundation is the Ecodesign for Sustainable Products Regulation (ESPR), Regulation (EU) 2024/1781, which works alongside the EU's Green Claims Directive to close a specific loophole: brands making sustainability claims with no way for anyone to verify them.

The DPP shifts the market from a "trust me" model to a "check it yourself" model. If a brand wants to make an explicit sustainability claim, it becomes prove it, or don't say it.

Why not just use existing fraud laws?

Because current enforcement cannot scale to the size of the modern global supply chain. Customs agents cannot physically inspect every garment arriving at European ports, send it to a lab, and chemically verify claims like "60% recycled ocean plastic." With millions of items arriving daily, the cost of making a false sustainability claim has been low, and the chance of getting caught has been close to zero. The DPP replaces spot-checking with structural, built-in verification.

What just changed in July 2026?

This is not a distant, future regulation. Two major milestones landed within days of each other this month:

19 JUL 2026
Destruction ban takes effectLarge companies in the EU are now prohibited from destroying unsold clothing, accessories, and footwear. They must resell, donate, repair, or recycle instead.
20 JUL 2026
EU Central DPP Registry goes liveThe European Commission launched the official registry and its testing environment, the digital infrastructure that will index every Digital Product Passport placed on the EU market.

Registering with the system is not yet mandatory for most product categories, but the infrastructure itself is now live and operational, not a whitepaper or a pilot.

What are the DPP deadlines through 2031?

The rollout is phased by product category. Only one deadline is currently locked into hard law; the rest follow a general working plan and are still subject to further rulemaking:

18 Feb 2027
EV & industrial batteries over 2 kWh (confirmed, Reg. 2023/1542)
~2028-2029
Textiles & apparel (anticipated, pending delegated act)
~2031
Consumer electronics, e.g. phones & tablets (anticipated)

Batteries are first because they involve critical raw materials (lithium, cobalt, nickel) that the EU wants to trace from sourcing through to recycling, making the sector a high-stakes proof of concept for the entire DPP system. Iron, steel, furniture, and tires are expected to follow a similar cascading rollout under the ESPR Working Plan.

One detail that matters regardless of location: these rules apply to any brand placing products on the EU market, regardless of where the company is headquartered or manufactures. A company based outside the EU still has to comply if it wants access to the European consumer base.

Which products are exempt?

Not everything will need a DPP. Categories generally understood to sit outside the ESPR's scope include:

  • Food and animal feed
  • Human medicines
  • Living plants and animals
  • Vehicles themselves (though a vehicle's battery is separately regulated)

The primary targets are manufactured physical goods with significant environmental footprints and high potential for circularity, such as textiles, electronics, furniture, and industrial products.

How does the DPP registry actually work?

The EU registry is deliberately decentralized. It does not store brands' actual product data, such as bills of materials, carbon footprint calculations, or safety certificates. Instead, it functions as a directory holding identifiers and metadata: the product ID, the facility ID, the economic operator ID, and a pointer to where the real data lives.

The heavy data itself stays hosted by the brand or a third-party provider. When someone scans a product's QR code, the registry acts like a switchboard, routing the request to the right server rather than storing the content centrally. This design is intended to avoid creating a single, centralized "honeypot" of sensitive supply chain data for hackers to target.

How is the DPP designed to protect trade secrets?

This is one of the more actively-discussed engineering challenges, since regulators, customers, and competitors all need very different levels of access to the same product record. The general model being discussed by DPP infrastructure providers uses tiered, field-level access:

PUBLIC
ConsumersBasic materials, recycling instructions, general carbon footprint - what's needed to buy and dispose of a product responsibly.
RESTRICTED
Customs & market surveillanceDetailed compliance documentation, lab safety test reports, supply chain traceability data.
CONFIDENTIAL
RegulatorsCost structures, proprietary manufacturing formulas, and sensitive supplier identities - protected from competitor access.

Techniques like cryptographic hashing (so tampering with data after the fact invalidates the passport) and, further out, zero-knowledge proofs (proving a condition is met, such as labor standards compliance, without revealing the underlying supplier data) are part of the broader toolkit being explored to balance transparency against legitimate business confidentiality. This remains an evolving area of implementation, not a single finalized standard.

How does the DPP interact with GDPR?

This is a genuine open engineering challenge. If a passport includes personal data, for example naming the individual artisans who made a product, and that person later exercises their GDPR "right to be forgotten," simply deleting their name could leave a broken, non-compliant record.

The approach being discussed to resolve this is pseudonymization: assigning a secure, anonymized ID that the passport references, while the brand separately holds the key linking that ID to a real identity in its own siloed system. If the individual asks to be forgotten, the brand deletes the link, not the ID, keeping the passport intact while honoring the privacy request.

What should manufacturers do now?

Even with the furthest-out deadlines still years away, the underlying shift is already forcing companies to restructure how they manage information. Preparing for a DPP means building genuine Life Cycle Assessment (LCA) data, tracking a product's environmental impact at every stage, not just emissions from a company's own factory.

That's a serious data problem for organizations where supplier information still lives in disconnected spreadsheets, or in the memory of a single procurement manager. You cannot retrofit this level of granular transparency onto a chaotic supply chain after the fact; it has to be designed in from the start.

DPP

This is exactly the kind of structured-data challenge Tylko Advisors works on. If your organization is trying to get ahead of DPP and BIM data readiness rather than scrambling once a deadline lands, get in touch to talk through where your data stands today.

Conclusion

The Digital Product Passport is no longer a distant policy concept. The registry is live, one hard product deadline is already locked into law, and the rules apply globally to anyone selling into the EU. The companies that treat this as a strategic opportunity to gain real visibility into their own supply chains, rather than a compliance box to check, will be the ones ready when their product category's deadline arrives.

If your product needed a Digital Product Passport tomorrow, would your supply chain data actually be ready to fill it in?

Frequently asked questions

What is a Digital Product Passport (DPP)?

A DPP is a digital record linked to a physical product, accessible via QR code or NFC tag, containing verifiable data about its materials, origin, environmental impact, and end-of-life handling, such as repair or recycling instructions.

When did the EU Digital Product Passport registry go live?

The European Commission's central DPP registry and testing environment went live on 20 July 2026, one day after a separate EU ban on destroying unsold clothing and footwear took effect for large companies on 19 July 2026.

What is the first product category required to have a DPP?

Batteries. Under Regulation (EU) 2023/1542, EV batteries and industrial batteries above 2 kWh must have a mandatory digital passport by 18 February 2027.

Does the Digital Product Passport apply to companies outside the EU?

Yes. The requirement applies to any brand placing products on the EU market, regardless of where the company is headquartered or where it manufactures.

Which products are exempt from the Digital Product Passport?

Categories generally outside the ESPR's scope include food, animal feed, human medicines, living plants and animals, and vehicles themselves (though a vehicle's battery is separately regulated).

Does the EU registry store a company's full product data?

No. The registry is decentralized: it stores identifiers and metadata pointing to where the real data is hosted, not the underlying bills of materials, carbon calculations, or safety certificates themselves.

Digital Product Passport ESPR EU Regulation Sustainability Supply Chain Data Governance
How to Get BuildingSMART Certified: Step-by-Step Guide to Passing the Exam - YouTube video thumbnail

Watch the full Deep Dive on the Digital Product Passport

All the details covered in this article, discussed in depth.

Watch the video →
What we offer

Ready to Get Certified?

1. Internationally recognized credential
Issued and validated by buildingSMART International — not a single-vendor certificate tied to one BIM platform.
2. Self-paced, flexible study
Learn online whenever suits you, with official exam sessions organised every month.
3. Two certificates + global registry
Earn certificates from both Tylko Academy and buildingSMART International, and get listed in bSI's Professional Registry.
4. Taught by practitioners
Built by Tylko Advisors, the team behind Smart Construction Insights — real project experience, not just exam prep.
Write your awesome label here.