Creating a DPP
For organisations that are or will be obligated to create a Digital Product Passport: timelines, responsibilities, data requirements, opportunities, and first steps.
With so much information available on Digital Product Passports (DPPs), finding the right information can be a challenge. CoE-DPP has brought together the key topics and linked them to content from official sources and trusted partners. Use the table of contents to quickly find the information you need.
If you can’t find what you’re looking for or you have other questions, please contact us at info@coe-dsc.nl. We’re happy to help you.
Get started
Who is obligated to create a DPP?
Not every product needs a Digital Product Passport (DPP). A DPP is a digital record with key information about a product, such as what it is made of, where it comes from, and how it can be repaired, reused, or recycled. Under the ESPR, the company or person that places the product on the EU market is responsible for creating and sharing the DPP. This is called the economic operator. In most cases, this is the manufacturer or importer. If you make, import, or sell products under your own brand in the EU, you are likely to be the economic operator.
The specific product groups and timelines are defined in delegated acts. Not all products require a DPP yet — see the Regulatory Radar for current timelines.
What is an Economic Operator?
An Economic Operator (EO) is defined in the ESPR as any natural or legal person who manufactures, imports, distributes, or makes products available on the EU market. The specific DPP responsibilities depend on your role:
- Manufacturer in EU: Full responsibility for creating the DPP
- Importer: Responsibility if the manufacturer is outside the EU
- Authorised representative: Can act on behalf of a non-EU manufacturer
- Distributor/Retailer: Must ensure DPP is accessible, but typically doesn’t create it
What about private label (own brand)?
If you are a retailer with your own brand (private label), you are considered the manufacturer for DPP purposes — even if another company physically produces the goods. The entity whose brand appears on the product bears the DPP obligation.
When does my product group need a DPP?
The DPP timeline varies by product group and regulation:
| Regulation | Product group | DPP obligation starts |
|---|---|---|
| Battery Regulation | Industrial + EV batteries (> 2 kWh) | February 2027 |
| Battery Regulation | All batteries | February 2028 |
| ESPR | Iron & steel, textiles (first delegated acts) | Expected 2027–2028 |
| CPR | Construction products (per delegated acts) | TBD |
The ESPR Work Programme 2025–2030 sets priorities for which product groups receive DPP requirements next.
How do I start with DPP implementation?
A practical starting point:
- Determine if you’re an Economic Operator — Are you placing products on the EU market under your own name or brand?
- Identify your product group — Check the Regulatory Radar for your timeline
- Map your existing data — Most companies already have much of the required data in their PIM, ERP, or PLM systems
- Understand the data requirements — Review what data your specific DPP must contain (from the relevant delegated act or the JRC-TNO methodology)
- Choose your architecture — Select identifiers, data carriers, and hosting approach (see Technical section)
- Engage with the ecosystem — Connect with solution providers, industry peers, and standardisation bodies
Who is responsible for creating and maintaining a DPP?
The economic operator who places the product on the EU market is responsible for:
- Creating the DPP before the product is placed on the market
- Ensuring the data is accurate and up-to-date
- Making the DPP accessible for at least 10 years after the last unit is placed on the market (or longer for product groups with longer lifetimes)
Responsibility can shift along the value chain — for example, when a product is substantially modified or refurbished.
What must a DPP contain?
The data requirements are product-group-specific and defined in delegated acts. However, the ESPR sets common requirements that every DPP must include:
- Product identification (unique identifier)
- Economic operator information
- Product-specific performance and sustainability data
- End-of-life information (repair, reuse, recycling)
- Compliance and regulatory information
The JRC-TNO methodology provides guidance on how the EC establishes data requirements for each product group.
At what level should a DPP be offered — product, model, batch, or item?
This depends on the product group and the delegated act. Options:
- Model level: One DPP for all products of the same type (simplest, least data)
- Batch level: One DPP per production batch (balances detail and effort)
- Item level: One DPP per individual product (most detailed, highest effort)
The appropriate level depends on how much product variation exists and what information downstream users need. Batteries, for example, require item-level DPPs due to their individual performance characteristics.
How suitable are my existing IT systems (PIM/ERP)?
Many organisations already have significant DPP-relevant data in their existing systems — but typically scattered across PIM, ERP, PLM, and supply chain tools. Key questions to assess readiness:
- Can you export structured product data per SKU?
- Do you have supply chain traceability data?
- Is your product data machine-readable (not just PDFs)?
- Can you link data to a unique product identifier?
Gaps are common in sustainability data, end-of-life instructions, and supply chain provenance — these typically require new data collection processes.
Which data models exist per product group?
Delegated acts will define which data has to be part of the DPP for a product group. A DPP may be voluntarily extended by a sector or organisation, for example to reduce administrative burden or enable data sharing for a circular business model. The Semantic Treehouse provides a growing collection of vocabularies and ontologies for DPP data, organized by sector. CEN/CLC/JTC 24 is developing the official standards for data exchange formats.
For a specific product group, check the relevant delegated acts (once adopted) for mandatory data fields.
Where do I store, host, or register my DPP?
A DPP must be:
- Hosted by a DPP service provider (or self-hosted) — making the data accessible via the internet
- Registered in the EU DPP Registry — so authorities and the public can find it
- Backed up — the ESPR requires a backup mechanism by an independent DPPSP to ensure long-term access
The EU DPP Registry regulation is being finalized. It will define how registration works.
Who can see my DPP data? (Access rights)
Not all DPP data is public. The ESPR distinguishes between:
- Public data: Accessible to anyone (consumers, general public)
- Data for authorities: Accessible only to market surveillance and customs
- Data for specific actors: Accessible to repairers, recyclers, or other value chain partners
Access rights are defined per data field in the delegated acts. The technical mechanism for access control is part of the DPP system architecture.
How do I prevent vendor lock-in?
Key principles to avoid lock-in:
- Use open standards for data formats and identifiers
- Ensure your data is exportable from any service provider
- Choose providers that support interoperability with the broader DPP ecosystem
- Consider open-source components where possible
What opportunities does a DPP offer?
Beyond compliance, a DPP creates value:
- Brand trust: Demonstrate sustainability credentials with verifiable data
- Circular business models: Enable repair, reuse, and recycling services based on product data
- Supply chain efficiency: Reduce information requests and duplicate data collection
- Administrative burden reduction: DPP data can support reporting for other (product) compliance obligations
- Market differentiation: Early movers build competitive advantage
How much will this cost?
Costs depend heavily on your starting point, product complexity, and chosen approach. The CIRPASS SME study found that:
- Companies with mature digital systems face lower incremental costs
- DPP-as-a-Service providers can significantly reduce the burden for SMEs
- Early investment can generate returns through operational efficiency and new business models
Who can help me? (Solution providers)
A growing ecosystem of solution providers offers DPP services — from full-service platforms to specialized tools for specific components (identifiers, hosting, data collection, etc.).
CoE-DPP supports an open ecosystem approach. We encourage working with providers who use open standards, support interoperability, and do not create lock-in. When evaluating providers, check whether their solutions align with the CIRPASS-2 Reference Architecture and CEN/CLC/JTC 24 standards.
Which countries outside the EU also require a DPP?
DPP-like requirements are emerging globally. The CIRPASS-2 report on standardisation initiatives worldwide provides an overview of product passport and traceability requirements in other jurisdictions.
The UN Transparency Protocol (UNTP) provides an international framework complementary to the EU DPP, relevant for companies with global supply chains.
Who enforces DPP compliance?
DPP compliance is enforced by national market surveillance authorities. In the Netherlands, this includes:
- NVWA (food-related products)
- ILT (environmental regulations)
- ACM (consumer protection and market regulation)
Customs authorities can also check DPP compliance for products entering the EU.
Help us improve this page
The DPP landscape is evolving rapidly — regulations change, new standards emerge, and practical experience grows every day. If you notice something on this page that is incorrect, outdated, or incomplete, please let us know.
Your input helps us keep this knowledge hub accurate and useful for everyone in the DPP ecosystem.