Quifactum
Guide · Regulation

What is a Digital Product Passport?

A practical guide to the EU Digital Product Passport, how it works, what it means for companies — and why the digital identity behind it can become useful far beyond compliance.

By Quifactum

A Digital Product Passport is a structured set of digital information about a product, reachable electronically through a data carrier such as a QR code. In the European Union the central framework is the Ecodesign for Sustainable Products Regulation. Understanding what that actually requires — and what it deliberately leaves open — is the difference between a compliance exercise and useful product infrastructure.

A Digital Product Passport (DPP) is a structured set of digital information about a product that can be accessed electronically through a data carrier such as a QR code.

In the European Union, the most important framework for Digital Product Passports is the Ecodesign for Sustainable Products Regulation (ESPR), Regulation (EU) 2024/1781.

But understanding a DPP requires an important distinction. There are two related concepts:

  • The regulatory Digital Product Passport — the information and infrastructure required by applicable legislation.
  • The underlying persistent digital product identity — the connection between a physical product and its digital information that can remain useful throughout the product's lifecycle.

The first is driven by regulation. The second can turn the same underlying identity into infrastructure for transparency, customer services, repair, returns, take-back, resale and other lifecycle applications.

The regulatory DPP comes first. But it does not have to be where the value ends.

What does the EU mean by a Digital Product Passport?

The ESPR defines a Digital Product Passport as a set of data specific to a product that contains the information required by the applicable delegated act and is accessible electronically through a data carrier.

How a regulatory DPP works
  1. Physical product
  2. Data carrier — QR / NFC / other permitted carrier
  3. Persistent unique product identifier
  4. Digital Product Passport
  5. Product information & authorised access
The regulatory architecture: the carrier is the way in, the identifier is what makes the passport persistent.

The data carrier could, for example, be a QR code or another permitted automatic identification technology. The identifier connects the physical product, batch or model to its digital information.

Under the ESPR, a DPP must be connected through a data carrier to a persistent unique product identifier. The data must be based on open standards and, where appropriate, be machine-readable, structured, searchable and transferable through an interoperable data exchange network without vendor lock-in.

This is why a Digital Product Passport should not be thought of simply as a webpage behind a QR code.

The QR code is a way into the passport. It is not the passport itself.

Primary source: Regulation (EU) 2024/1781 — Ecodesign for Sustainable Products Regulation

What information does a Digital Product Passport contain?

There is no single universal dataset that every ESPR Digital Product Passport must contain.

The ESPR establishes the framework. Product-specific delegated acts define the actual requirements for the product groups they cover.

Depending on the product group, these rules can determine:

  • which data must be included;
  • which data carrier or carriers must be used;
  • where the data carrier must appear;
  • who can access which information;
  • who may create or update information;
  • how long the DPP must remain available;
  • and whether the DPP must exist at model, batch or individual item level.

Potential information identified in the ESPR framework includes product identifiers, information required by applicable EU legislation, manufacturer information, compliance documentation, technical information and information relevant to the product's environmental performance and circularity.

The exact dataset depends on the legislation applicable to that product.

There is no generic “ESPR-compliant DPP”

A passport can only be assessed against the legal requirements that actually apply to the relevant product. That distinction is important because many product-specific requirements are still being developed.

Which products will need a Digital Product Passport?

Not every product sold in Europe suddenly requires a DPP.

The ESPR is a framework regulation. Product-specific requirements are introduced progressively through delegated acts.

The European Commission's ESPR and Energy Labelling Working Plan 2025–2030 identifies priority product groups including:

  • textiles and apparel;
  • furniture;
  • tyres;
  • mattresses;
  • iron and steel;
  • aluminium;

alongside horizontal measures concerning areas such as repairability and recycled content in electrical and electronic equipment.

For textiles and apparel, for example, the European Commission currently indicates Q4 2027 as the planned adoption period for the relevant ESPR delegated act.

That is not the same as saying that “DPPs for textiles become mandatory in 2027”. The delegated act still has to define the product-specific requirements and implementation arrangements. Timelines can also evolve as the legislative and technical work progresses.

There is no single DPP deadline for every product.

The applicable requirements and timing depend on the product category and the legislation concerned.

Primary sources: European Commission — ESPR Working Plan 2025–2030 · European Commission — Textile apparel and the Digital Product Passport

DPP legislation goes beyond the ESPR

The ESPR is the central horizontal framework for Digital Product Passports in the EU, but it is not the only EU legislation introducing product-passport requirements. Examples include:

Batteries

Under the EU Batteries Regulation (EU) 2023/1542, certain batteries must have a battery passport from 18 February 2027. This applies to LMT batteries, industrial batteries with a capacity greater than 2 kWh and electric vehicle batteries placed on the market or put into service.

Construction products

The revised Construction Products Regulation (EU) 2024/3110 establishes a framework for a construction Digital Product Passport system designed to be compatible and interoperable, as far as possible, with the DPP architecture established under the ESPR.

Toys

The Toy Safety Regulation (EU) 2025/2509 also introduces Digital Product Passports as part of its product safety and compliance framework.

The important point is that “Digital Product Passport” does not mean that every product is governed by exactly the same legal requirements. Different legislation can determine different datasets, identifiers, access rights, responsibilities, granularity levels and implementation timelines.

For companies operating across sectors, the underlying architecture therefore needs to be flexible enough to support different regulatory requirements.

Primary sources: Regulation (EU) 2023/1542 — Batteries and waste batteries · Regulation (EU) 2024/3110 — Construction Products Regulation · Regulation (EU) 2025/2509 — Toy Safety Regulation

Model, batch or item: what gets the identity?

One common misunderstanding is that a Digital Product Passport automatically means giving every individual physical product its own unique passport. Under the ESPR, that is not necessarily the case.

The applicable delegated act can determine whether the DPP must be established at:

Model level

One identity for products of the same model that share the relevant characteristics.

Batch level

An identity associated with a particular production batch.

Item level

A unique identity for one individual physical product.

For regulatory compliance, the applicable legislation determines the required level. A company may nevertheless choose a more granular identity when there is a business reason to do so.

Compliance determines the minimum. The business case determines the useful level.

Explore model, batch and item identity →

The EU Digital Product Passport Registry

The European Commission launched the Digital Product Passport Registry on 20 July 2026.

The Registry is an important part of the European DPP architecture, but it should not be confused with the DPP itself. It does not function as one giant European database containing all detailed product information from every Digital Product Passport.

The architecture is decentralised. The Registry acts as a common EU-level indexing service. It stores unique identifiers, registration information and high-level metadata. Depending on applicable legislation, additional information may also have to be stored there.

The detailed product data remains under the responsibility of the relevant economic operator and may be hosted by that operator or through a Digital Product Passport service provider.

This allows authorities and other authorised actors to locate and verify relevant passports without requiring every piece of product information to be stored centrally by the European Commission.

Primary sources: European Commission — The DPP Registry · European Commission — The Digital Product Passport Registry is now live

A Digital Product Passport is not just a webpage behind a QR code

Imagine a QR code printed on a garment. Scanning that QR code might open a consumer-facing page showing fibre composition, care instructions, origin information or repair guidance.

That page is useful. But it is only the visible interface.

A regulatory DPP architecture contains several layers: the physical product; the data carrier, a QR code or another permitted carrier; the persistent unique product identifier; structured product information; access rights and interoperability; and the DPP ecosystem and Registry.

Different users may also need access to different information. A consumer, customs authority, market-surveillance authority, repairer or recycler does not necessarily need — or have the right — to see exactly the same data.

The consumer-facing webpage is therefore one interface to a broader product-data infrastructure.

From Digital Product Passport to persistent digital identity

This is where the DPP becomes interesting beyond regulatory compliance. The ESPR itself requires the passport to be connected to a persistent unique product identifier. That creates a foundation.

From compliance to lifecycle value
  1. Regulatory DPP — compliance · product information · transparency · regulatory access
  2. Built on: persistent digital product identity
  • Care
  • Authentication
  • Repair
  • Maintenance
  • Returns
  • Take-back
  • Resale
  • Reuse
  • Recycling
The lifecycle applications below are business applications built on the same identity. They are not legal requirements of the ESPR.

Instead of thinking only “we need a QR code to show the information required by regulation”, a company can ask: “we are giving this physical product a persistent digital identity — what else could that identity enable?”

The regulatory DPP

The regulatory DPP is governed by applicable legislation. It determines what information must be made available, at which level, to whom and under which conditions.

The broader digital product identity

A persistent digital product identity can connect the same physical product to additional information, events and services over time. These additional applications are not automatically part of the legal definition of the DPP. They are business applications that can be built around the same underlying product identity.

The DPP is the regulatory requirement. Persistent product identity can become the infrastructure for what happens next.

What can a persistent product identity enable?

Consider a physical product with a persistent digital identity. At the point of sale, that identity can provide access to the information required by its Digital Product Passport. But the physical product continues to exist after the first transaction. Its digital identity can continue to be useful too.

Before and at purchase

  • product transparency;
  • provenance and storytelling;
  • access to product documentation;
  • authentication;
  • customer engagement.

During ownership

  • care information;
  • manuals and instructions;
  • warranty or after-sales services;
  • maintenance;
  • repair;
  • product-specific service history.

At the next lifecycle event

  • returns;
  • take-back;
  • repair;
  • refurbishment;
  • resale;
  • reuse;
  • recycling.

Instead of creating a new disconnected record every time something happens to a product, relevant lifecycle events can remain associated with the same underlying identity.

Explore lifecycle applications →

Why granularity matters beyond compliance

This also explains why model, batch and item identities create different possibilities.

A model-level identity can be perfectly appropriate for information shared by every product of that model. A batch-level identity becomes useful when provenance, materials, production conditions or other relevant information differs between production runs. An item-level identity becomes useful when something happens to one individual physical object.

For example:

  • Which individual garment was returned?
  • Has this particular product already been resold?
  • Was this specific machine repaired?
  • Which individual product is being authenticated?
  • Which lifecycle events belong to this physical item?

Those events cannot reliably be associated with one individual object if the identity exists only at model level. That does not make item-level identity universally better. It makes different levels appropriate for different purposes.

The right granularity depends on both the regulatory requirement and the use case.

What about Digital Product Passports outside the EU?

Digital product information, traceability and product-identity initiatives are not limited to the European Union. Different jurisdictions and industries are developing digital labelling, traceability, product-information and product-passport approaches of their own.

These should not automatically be described as ESPR Digital Product Passports. Requirements can differ significantly between jurisdictions, including mandatory datasets, identifiers, data carriers, hosting, access rights, registries, retention periods and responsible economic operators.

For an international company, the more useful architectural question is therefore: can one underlying product identity support different regulatory and commercial requirements without rebuilding the product record for every market? That is a broader challenge than ESPR compliance alone.

Explore security, interoperability and portability →

Digital Product Passport vs persistent product identity

Regulatory Digital Product PassportPersistent digital product identity
Primary purposeMeet applicable product-information and compliance requirementsConnect a physical product to information and services over time
Driven byApplicable legislationRegulation + business use case
Required dataDefined by applicable legislationCan connect additional permitted business and service information
GranularityDefined by applicable rulesCan be more granular where useful
AccessDetermined by legislation and access rightsDetermined by the applications and services built around the identity
LifetimeAccording to applicable regulatory requirementsPotentially throughout the useful product lifecycle
Typical applicationsCompliance, transparency and regulatory traceabilityEngagement, authentication, maintenance, repair, returns, take-back, resale, reuse and other services
RelationshipThe legal information frameworkThe broader identity infrastructure on which regulatory and commercial applications can operate
A DPP can therefore be both a compliance requirement and the starting point for a much more useful digital relationship with a physical product.

What should companies do now?

For most companies, the first step is not buying QR codes. It is understanding the regulatory requirements that may apply to their products and understanding the product data they already have.

Start with these questions:

1. Which legislation applies to our products?

Do not assume that the ESPR is the only relevant framework.

2. Which requirements are already final?

Separate adopted legislation from delegated acts, technical specifications and requirements that are still being developed.

3. Where does our product information currently live?

  • ERP;
  • PLM;
  • PIM;
  • spreadsheets;
  • supplier files;
  • certificates;
  • PDFs and technical documentation.

4. Which required information do we already have?

Many companies discover that much of the necessary product information already exists — but is fragmented across systems and organisations.

5. What information is missing?

Identify the gaps before redesigning your technology stack.

6. What granularity is required?

Does the applicable legislation require a model, batch or item-level passport?

7. Is there a business reason to go further?

Could a more granular identity support repair, authentication, returns, take-back, resale or another valuable workflow?

8. Can the architecture remain interoperable and portable?

A product identity may need to remain useful for years. Avoid designing it around unnecessary vendor lock-in.

The technology required to publish a webpage is usually the easy part.

Structuring reliable product data and maintaining a useful product identity over time is the real implementation challenge.

Explore product data & integrations →

Where Quifactum fits

Quifactum turns existing product data into persistent digital product identities.

We help brands, manufacturers and technology partners structure existing product information, create Digital Product Passports at the appropriate model, batch or item level, and use the same underlying identity for applications beyond compliance.

Quifactum is designed to work with the product data and systems companies already use rather than requiring them to rebuild their entire product-data infrastructure.

Explore the Quifactum platform →  ·  Book a demo →

Frequently asked questions

Is a Digital Product Passport already mandatory?

There is no universal DPP obligation applying to every product today. Different requirements are being introduced under different pieces of EU legislation and on different timelines. For example, the EU Batteries Regulation requires battery passports for specified battery categories from 18 February 2027. ESPR requirements for other product groups will be introduced progressively through product-specific delegated acts.

Does every product need an individual QR code?

No. Under the ESPR, the applicable delegated act can determine whether the DPP must exist at model, batch or individual item level. The applicable rules also determine the permitted data carrier and where it must be placed.

Is a QR code a Digital Product Passport?

No. A QR code can act as the data carrier connecting the physical product to its digital identity and passport. The DPP consists of the associated data and the infrastructure that makes the required information accessible.

Does all DPP information go into the EU Registry?

No. The European DPP architecture is decentralised. The Registry provides a common EU-level index containing identifiers, registration information and metadata. The detailed DPP information remains under the responsibility of the relevant economic operator and can be hosted by that operator or through a DPP service provider.

Does DPP mean item-level identification?

Not necessarily. Depending on the applicable legislation, a DPP can be required at model, batch or item level. Item-level identification becomes particularly useful when applications need to interact with one specific physical product.

Is a DPP only about compliance?

The regulatory Digital Product Passport has a legal and regulatory purpose. However, the persistent product identity and data infrastructure used to implement it can also support lifecycle applications such as authentication, repair, maintenance, returns, take-back and resale. Those additional services should not be confused with the legal definition of the DPP itself.

Published by Quifactum. Last updated 21 September 2026. Regulatory content is reviewed against primary EU sources before publication.

Wondering what this means for your products?

Bring one real product and the data you already hold. Thirty minutes is usually enough to know where you stand.

Book a demo