What information must a DPP contain?
The exact data set is fixed by the delegated act for each product group, but the ESPR defines the categories of information a Digital Product Passport is expected to carry. In practice, a DPP brings together:
- Product identity: a unique product identifier, model, batch or item reference, and the identity of the responsible economic operator;
- Materials and composition: the materials used and their proportions;
- Origin and supply chain: provenance and, where required, traceability along the value chain;
- Durability and repairability: expected lifespan, spare-part availability and repair information;
- Substances of concern: the presence and location of hazardous substances above defined thresholds;
- Recyclability and end-of-life: recycled content, and instructions for reuse, recycling or safe disposal.
The data carrier: QR code, NFC and RFID
The passport data is not printed on the product. It is reached through a data carrier physically attached to the item, its packaging or its documentation. The ESPR allows carriers such as:
- QR codes and data-matrix codes;
- NFC tags;
- RFID tags.
The carrier holds a link to the passport rather than the full data set, so the information can be kept up to date without reprinting labels. Because the carrier is the entry point to every product, it is also the natural place to add anti-counterfeiting protection: this is where a secure NFC chip such as the NTAG 424 DNA used by SealTrust proves that each scan is genuine and not a copied code.
Access tiers: public, authorities and operators
Not every field is visible to everyone. The DPP is built around layered access rights:
- Public: information consumers need, such as care, repair and recycling guidance;
- Authorities: data reserved for market-surveillance and customs bodies;
- Economic operators: details shared with recyclers, repairers or other businesses along the chain.
The delegated act for each product group decides which field sits in which tier.
Who is responsible for the passport
Responsibility falls on the economic operator that places the product on the EU market:
- the manufacturer where it is established in the EU;
- the importer or authorised representative where the manufacturer is outside the EU.
That operator must ensure the passport exists, is accurate, stays available for the required period, and remains accessible even if the company itself ceases trading.
Interoperability and open standards
A DPP is only useful if any authorised party can read it. The ESPR therefore requires passports to be interoperable and built on open standards, with data that is machine-readable and structured. In practice this points to:
- GS1 standards, including GS1 Digital Link, to identify products and resolve the carrier to the passport;
- JSON-LD and linked-data models to express passport data in a shared, machine-readable vocabulary.
These choices let a single passport be read by retailers, customs, recyclers and consumers without bespoke integrations.
To see how these requirements come together in a working system, read our main guide to the Digital Product Passport.