Consulting Independent advice across RTLS, RFID and IoT — no platform to sell. Book a call →
INSIGHT · DIGITAL PRODUCT PASSPORT

Digital Product Passport: what is actually required, and when.

Almost everything published about DPP deadlines is wrong, usually in the same direction. This is what the regulation currently obliges, what it does not, and why the carrier decision is still open.

The legal position, stated plainly

The Digital Product Passport comes from Regulation (EU) 2024/1781, the Ecodesign for Sustainable Products Regulation, which entered into force on 18 July 2024.

ESPR is a framework. On its own it imposes no product obligations at all. The DPP requirement for any given product arrives through a product-specific delegated act, and until that act exists for your category, you have no DPP compliance date.

One provision matters more than any headline: a delegated act's date of application cannot be earlier than 18 months after it enters into force. That is your minimum lead time, and it is generous by regulatory standards.

The deadline everyone gets wrong

You will read that textiles must comply by 2027. That is not correct.

2027 is the indicative year in the first ESPR Working Plan for adopting the textiles delegated act. Adoption is not application. Add the eighteen-month minimum and realistic compliance lands appreciably later, and the date is not fixed because the act does not yet exist.

The first Working Plan, adopted April 2025 and covering 2025 to 2030, prioritises iron and steel, textiles and apparel, aluminium, tyres, furniture and mattresses, plus horizontal measures for electronics. The adoption years attached to those are indicative planning dates, not obligations.

If a supplier is selling you urgency based on a 2027 textile deadline, the deadline they are citing does not exist yet.

What is actually fixed

DateWhatStatus
18 July 2024ESPR enters into forceFixed
19 July 2026Registry deadline under Article 13Fixed
19 July 2026Ban on destroying unsold apparel and footwear (large enterprises; medium-sized from 19 July 2030; micro and small exempt)Fixed
20 July 2026EU DPP Registry live, in testingLive, no category yet required to register
18 February 2027Battery passport obligationFixed, and the first real one
2026–2029Sectoral delegated actsIndicative only

Note the battery row. The battery passport, under Regulation (EU) 2023/1542, is the first genuine DPP-type obligation — from 18 February 2027 for EV batteries, light means of transport batteries and rechargeable industrial batteries above 2 kWh. It arrives before any ESPR delegated act, under a separate regime. If you make or import batteries at that scale, that is your real deadline.

No technology is mandated, and this matters

ESPR Article 9(2) says the delegated act specifies one or more data carriers, their layout and positioning, and whether the passport applies at model, batch or item level. Article 10(1)(c) requires the carrier and identifier to comply with standards referenced in Annex III.

Nowhere does ESPR mandate QR, NFC or RAIN RFID. Carrier choice is made sector by sector, in acts that mostly do not exist yet.

So when a tag vendor tells you the DPP requires RFID, or a printing supplier tells you it requires QR, neither statement is currently true for any product category. The realistic expectation is that at least one carrier will need to be readable by an ordinary smartphone without an app, which points toward a 2D code as a baseline — but that is inference from draft standards work, not law.

The practical consequence for anyone buying tagging now: design for carrier flexibility rather than betting on one. An item-level identity strategy that can drive a QR, an NFC tag or a RAIN inlay is cheap insurance. Committing your packaging line to one carrier before the delegated act is a risk with no upside.

Identifiers and standards

CEN-CENELEC JTC 24 developed eight horizontal DPP standards. Six of them — EN 18216 (data exchange protocols), EN 18219 (unique identifiers), EN 18220 (data carriers), EN 18221 (storage and persistence), EN 18222 (APIs) and EN 18223 (interoperability) — were cited as harmonised standards by Commission Implementing Decision (EU) 2026/1736 of 14 July 2026. The two security standards, EN 18239 and EN 18246, were not part of that decision.

GS1 Digital Link is one permitted identifier syntax, not the mandated one. GS1 maintains its URI syntax as a separate, versioned standard (version 1.7.0, August 2026, at the time of writing).

Separately, GS1 Sunrise 2027 — retailers being able to read 2D barcodes at point of sale — is a voluntary industry ambition, not regulation. It is frequently cited alongside DPP as though it were a legal requirement. It is not.

Who carries the obligation

Article 27 places the duty on the manufacturer to ensure a passport is available, including a backup copy. Article 10(4) places the backup duty on the economic operator placing the product on the market, which means an importer inherits it for third-country goods. Distributors have verification duties rather than creation duties.

For most European businesses buying from outside the EU, that second point is the one with cost attached.

What remains genuinely unresolved

  • No adopted sectoral delegated act, so no fixed compliance date for any ESPR product group
  • Carrier choice per sector undecided
  • Access-rights tiers, public versus restricted data, untested in practice
  • The DPP service-provider market and backup obligations untested
  • How the battery passport regime and ESPR DPP interact

What we would do now

If you make batteries at scale: February 2027 is real. Treat it as a live programme.

Everyone else: do the identity work, not the carrier work. Establish one identifier per item that your systems agree on, make sure it can be expressed in more than one carrier, and capture the attribute data the passport will need. None of that is wasted whichever act lands.

What we would not do is buy a DPP platform against a deadline that has not been set. The lead time built into ESPR is eighteen months minimum, and it exists precisely so you do not have to.

Related: RFID explained, serialisation and chain of custody, DSCSA and GS1, standards.