Creating a DPP

For organisations that are or will be obligated to create a Digital Product Passport: timelines, responsibilities, data requirements, opportunities, and first steps.

With so much information available on Digital Product Passports (DPPs), finding the right information can be a challenge. CoE-DPP has brought together the key topics and linked them to content from official sources and trusted partners. Use the table of contents to quickly find the information you need.

If you can’t find what you’re looking for or you have other questions, please contact us at info@coe-dsc.nl. We’re happy to help you.

Table of Contents

Get started

Not every product needs a Digital Product Passport (DPP). A DPP is a digital record with key information about a product, such as what it is made of, where it comes from, and how it can be repaired, reused, or recycled. Under the ESPR, the company or person that places the product on the EU market is responsible for creating and sharing the DPP. This is called the economic operator. In most cases, this is the manufacturer or importer. If you make, import, or sell products under your own brand in the EU, you are likely to be the economic operator.

The specific product groups and timelines are defined in delegated acts. Not all products require a DPP yet — see the Regulatory Radar for current timelines.

An Economic Operator (EO) is defined in the ESPR as any natural or legal person who manufactures, imports, distributes, or makes products available on the EU market. The specific DPP responsibilities depend on your role:

  • Manufacturer in EU: Full responsibility for creating the DPP
  • Importer: Responsibility if the manufacturer is outside the EU
  • Authorised representative: Can act on behalf of a non-EU manufacturer
  • Distributor/Retailer: Must ensure DPP is accessible, but typically doesn’t create it

If you are a retailer with your own brand (private label), you are considered the manufacturer for DPP purposes — even if another company physically produces the goods. The entity whose brand appears on the product bears the DPP obligation.

The DPP timeline varies by product group and regulation:

RegulationProduct groupDPP obligation starts
Battery RegulationIndustrial + EV batteries (> 2 kWh)February 2027
Battery RegulationAll batteriesFebruary 2028
ESPRIron & steel, textiles (first delegated acts)Expected 2027–2028
CPRConstruction products (per delegated acts)TBD

The ESPR Work Programme 2025–2030 sets priorities for which product groups receive DPP requirements next.

A practical starting point:

  1. Determine if you’re an Economic Operator — Are you placing products on the EU market under your own name or brand?
  2. Identify your product group — Check the Regulatory Radar for your timeline
  3. Map your existing data — Most companies already have much of the required data in their PIM, ERP, or PLM systems
  4. Understand the data requirements — Review what data your specific DPP must contain (from the relevant delegated act or the JRC-TNO methodology)
  5. Choose your architecture — Select identifiers, data carriers, and hosting approach (see Technical section)
  6. Engage with the ecosystem — Connect with solution providers, industry peers, and standardisation bodies

The economic operator who places the product on the EU market is responsible for:

  • Creating the DPP before the product is placed on the market
  • Ensuring the data is accurate and up-to-date
  • Making the DPP accessible for at least 10 years after the last unit is placed on the market (or longer for product groups with longer lifetimes)

Responsibility can shift along the value chain — for example, when a product is substantially modified or refurbished.

The data requirements are product-group-specific and defined in delegated acts. However, the ESPR sets common requirements that every DPP must include:

  • Product identification (unique identifier)
  • Economic operator information
  • Product-specific performance and sustainability data
  • End-of-life information (repair, reuse, recycling)
  • Compliance and regulatory information

The JRC-TNO methodology provides guidance on how the EC establishes data requirements for each product group.

This depends on the product group and the delegated act. Options:

  • Model level: One DPP for all products of the same type (simplest, least data)
  • Batch level: One DPP per production batch (balances detail and effort)
  • Item level: One DPP per individual product (most detailed, highest effort)

The appropriate level depends on how much product variation exists and what information downstream users need. Batteries, for example, require item-level DPPs due to their individual performance characteristics.

Many organisations already have significant DPP-relevant data in their existing systems — but typically scattered across PIM, ERP, PLM, and supply chain tools. Key questions to assess readiness:

  • Can you export structured product data per SKU?
  • Do you have supply chain traceability data?
  • Is your product data machine-readable (not just PDFs)?
  • Can you link data to a unique product identifier?

Gaps are common in sustainability data, end-of-life instructions, and supply chain provenance — these typically require new data collection processes.

Delegated acts will define which data has to be part of the DPP for a product group. A DPP may be voluntarily extended by a sector or organisation, for example to reduce administrative burden or enable data sharing for a circular business model. The Semantic Treehouse provides a growing collection of vocabularies and ontologies for DPP data, organized by sector. CEN/CLC/JTC 24 is developing the official standards for data exchange formats.

For a specific product group, check the relevant delegated acts (once adopted) for mandatory data fields.

A DPP must be:

  1. Hosted by a DPP service provider (or self-hosted) — making the data accessible via the internet
  2. Registered in the EU DPP Registry — so authorities and the public can find it
  3. Backed up — the ESPR requires a backup mechanism by an independent DPPSP to ensure long-term access

The EU DPP Registry regulation is being finalized. It will define how registration works.

Not all DPP data is public. The ESPR distinguishes between:

  • Public data: Accessible to anyone (consumers, general public)
  • Data for authorities: Accessible only to market surveillance and customs
  • Data for specific actors: Accessible to repairers, recyclers, or other value chain partners

Access rights are defined per data field in the delegated acts. The technical mechanism for access control is part of the DPP system architecture.

Key principles to avoid lock-in:

  • Use open standards for data formats and identifiers
  • Ensure your data is exportable from any service provider
  • Choose providers that support interoperability with the broader DPP ecosystem
  • Consider open-source components where possible

Beyond compliance, a DPP creates value:

  • Brand trust: Demonstrate sustainability credentials with verifiable data
  • Circular business models: Enable repair, reuse, and recycling services based on product data
  • Supply chain efficiency: Reduce information requests and duplicate data collection
  • Administrative burden reduction: DPP data can support reporting for other (product) compliance obligations
  • Market differentiation: Early movers build competitive advantage

Costs depend heavily on your starting point, product complexity, and chosen approach. The CIRPASS SME study found that:

  • Companies with mature digital systems face lower incremental costs
  • DPP-as-a-Service providers can significantly reduce the burden for SMEs
  • Early investment can generate returns through operational efficiency and new business models

A growing ecosystem of solution providers offers DPP services — from full-service platforms to specialized tools for specific components (identifiers, hosting, data collection, etc.).

CoE-DPP supports an open ecosystem approach. We encourage working with providers who use open standards, support interoperability, and do not create lock-in. When evaluating providers, check whether their solutions align with the CIRPASS-2 Reference Architecture and CEN/CLC/JTC 24 standards.

DPP-like requirements are emerging globally. The CIRPASS-2 report on standardisation initiatives worldwide provides an overview of product passport and traceability requirements in other jurisdictions.

The UN Transparency Protocol (UNTP) provides an international framework complementary to the EU DPP, relevant for companies with global supply chains.

DPP compliance is enforced by national market surveillance authorities. In the Netherlands, this includes:

  • NVWA (food-related products)
  • ILT (environmental regulations)
  • ACM (consumer protection and market regulation)

Customs authorities can also check DPP compliance for products entering the EU.

Help us improve this page

The DPP landscape is evolving rapidly — regulations change, new standards emerge, and practical experience grows every day. If you notice something on this page that is incorrect, outdated, or incomplete, please let us know.

Your input helps us keep this knowledge hub accurate and useful for everyone in the DPP ecosystem.