
The Digital Product Passport: Understanding Before Planning
Why "we still have time" isn't always the right conclusion
The Digital Product Passport, or DPP, is set to become mandatory for an increasing number of product categories over the coming years, regardless of company size. The legal basis is the EU Ecodesign for Sustainable Products Regulation, Regulation (EU) 2024/1781 (ESPR).
What the DPP actually is
The DPP is a structured digital record that accompanies a product throughout its entire lifecycle, bringing together information on materials, origin, repairability, and recyclability, accessible at any time to authorities, trading partners, and in some cases consumers as well.
Who is affected
In principle, any company placing a product from an affected category on the EU market is in scope, regardless of where that product is manufactured. Since the DPP is being phased in category by category, not every company will be affected at the same time, or at all, it depends entirely on whether a company's products fall within one of the covered product groups.
Affected industries at a glance
So far, only the battery passport has a legally fixed deadline: 18 February 2027. All other timelines will be set by the European Commission through product-specific delegated acts, most of which are still pending. That said, the range of affected industries is already fairly well defined: alongside batteries and accumulators, steel and iron, textiles and clothing, tyres, aluminium, and electrical and electronic equipment are among the first product groups to be covered. In subsequent years, furniture and mattresses are expected to follow, with machinery, packaging, construction products, and plastics likely joining later still.
Companies operating in any of these sectors would do well to engage with the topic now, regardless of the exact timing, since the gap between a delegated act taking effect and the actual compliance deadline tends to be relatively short.
What is at stake
Once a delegated act takes effect for a given product category, a simple but consequential rule is likely to apply: no valid product passport, no sale in the EU, including existing inventory already produced. For affected companies, the DPP is therefore not a compliance footnote but a potential precondition for market access.
The common misconception: "Our sustainability team already handles this"
This is precisely what many companies still underestimate. The DPP typically first lands with sustainability, sometimes with compliance or legal, and tends to stay there. A natural line of thinking in the boardroom then follows: we already have a sustainability team, so this is being taken care of. That falls short. Responsibility for the DPP generally rests with whoever places a product on the EU market, regardless of which department ends up coordinating the work. The actual data, material composition, supply chain information, technical specifications, is typically scattered across procurement, product development, and sales. A sustainability team can consolidate it, but it rarely owns the underlying data.
The challenge is rarely technical, it's organisational
Much of the required information already exists within companies, often spread across different systems and departments. The core task, therefore, tends to be less about building everything from scratch and more about bringing existing data together, supplementing it, documenting it in a traceable way, and maintaining it over time. That said, some degree of additional data collection is unlikely to be avoidable entirely, particularly where individual required criteria haven't been captured at all so far.
Individual departments typically work thoroughly within their own remit, but rarely see how their information connects to that of other departments. This cross-functional connectivity is exactly what the DPP demands, and it's exactly what many organisations lack at a central level.
There's also this: the DPP isn't a one-off project with a fixed end date. Changes to materials, new certifications, or updated spare-parts information all need to be tracked continuously, year after year. Companies that treat this as a single task to check off, rather than a recurring process, will find the requirement slipping out of reach again before long.
Starting points vary considerably between companies
Companies that already produce a sustainability report, or that have been tracking certain metrics for other regulatory reasons, aren't necessarily better positioned as a result, their starting point is simply different. Some of the required data may already be captured, but it rarely exists in the format the DPP requires. In larger organisations, often spread across multiple sites or legal entities, a different challenge tends to emerge: the data exists, but across disparate systems, formats, and areas of ownership, and turning that into a single, company-wide process can be demanding even when much of the groundwork is technically already there.
Companies that haven't grappled with comparable requirements before, on the other hand, more often face the task of building their data foundation from the ground up. There is no general exemption based on company size: any company selling an affected product in the EU is in scope, whether it's a mid-sized business or a large corporation. Some easing of implementation requirements for smaller companies is reportedly under discussion, though exactly what this will look like hasn't been finalised.
Who should actually own the project
In practice, an early question that many companies haven't yet answered is who manages the project internally. Depending on the company, natural candidates include procurement, sales, or a dedicated project function with real authority to act across departments. Where a sustainability team already exists, it makes sense to involve them, they often understand the regulatory landscape best. What matters, though, is that they aren't automatically made the sole owner of the data: the actual product and supply chain information generally sits elsewhere, and while sustainability can coordinate, accountability for the content itself remains distributed. Without a clearly assigned overall owner, the DPP risks becoming a topic everyone is somewhat responsible for and no one is fully responsible for.
This question also has a governance dimension. Boards and executive management are likely bound by a duty of care that extends to new regulatory market-access requirements such as the DPP. A topic that structurally spans multiple departments therefore belongs not only at the operational level, but firmly anchored at leadership level too.
The value of an external, audit-trained perspective
Even though the DPP won't ultimately be signed off by a statutory auditor, it remains, at its core, a matter subject to scrutiny: market surveillance authorities will check whether the data provided is complete, accurate, and properly documented. This is where an external perspective grounded in audit experience can help, regardless of who ultimately carries out the formal review. The aim is to identify early on whether processes are fundamentally set up to withstand scrutiny, and where the risk of findings can be reduced. This cannot and should not be framed as a guarantee of audit readiness, but it can be a well-founded outside perspective that complements the internal view with the kinds of questions a later review would typically raise.
What actually needs to be delivered
Some companies underestimate the scope because part of the work already seems done: product labelling is already in place, certificates exist somewhere in the system. But the DPP demands more than the existence of individual records, it requires that these records be brought together in a structured way, provided in a specific format, and kept continuously up to date. Broadly speaking, this spans five layers:
Identification – unique product identification, manufacturer, origin, batch or serial number
Material information – composition, raw materials used, substances of concern, recycled content
Environmental and circularity data – for example carbon footprint, energy efficiency, repairability, spare-parts availability, disposal guidance
Technical provisioning – a unique, machine-readable data carrier on the product, typically a QR code, in standardised formats, linked to an EU-wide registration system
Time dimension – multi-year retention requirements and the obligation to update the passport whenever something relevant changes, not once, but across the product's entire lifecycle
It's only when these layers come together that it becomes clear why the DPP isn't simply a labelling exercise.
What implementation additionally requires
Beyond the substantive and technical requirements, it's often the practical execution that determines whether a DPP project holds together or stalls. That starts with a clear answer to who is actually responsible for which data, not just formally, but substantively: who determines whether information is correct, and who keeps it updated on an ongoing basis? Without that clarity, data quality is left to chance, particularly where multiple departments are accessing the same datasets simultaneously.
Equally important is a realistic look at the existing IT landscape: rather than reaching straight for an entirely new system, it's worth first establishing what existing systems can already handle and where targeted additions are actually needed. And finally, this requires thoughtful communication, externally to customers, retailers, and partners, but just as much internally: anyone in sales or customer service who ends up fielding questions about the product passport needs to understand what's behind it themselves, otherwise the uncertainty simply shifts from the documentation to the conversation with the customer.
Whether all of this can be mapped onto existing systems or requires a separate solution isn't something that can be answered in general terms, it depends heavily on the IT landscape and the level of digitalisation across the departments involved. This is precisely why an early, structured look at one's own starting point is worthwhile before committing to an implementation path.
The first step: understanding before planning
Even where the obligation for a given product category won't take effect next year, it's worth looking into now. That's the essence of a first impact assessment: understanding how likely the company is to be affected, what is currently known about the requirements, even though details may still change through delegated acts, and where the relevant information already sits within the organisation.
Such an assessment typically addresses three questions:
Likely scope – does the product in question fall, or is it likely to fall, into one of the already foreseeable categories, and with what lead time?
Current position – how much of the required data already exists, where does it sit, and how complete is it?
Likely pain points – based on what's known today, where are the biggest gaps or the greatest coordination effort likely to emerge?
The outcome isn't a detailed analysis or a definitive assessment, but an initial sense of direction: where things are likely to get difficult, where a closer look is worthwhile, and where the effort appears manageable. This distinction often determines whether a company can approach the transition in a structured way, or ends up under time pressure once a deadline becomes concrete.
How much effort ultimately materialises depends heavily on the starting point. Where data is already largely digitised and suppliers are properly connected, implementation can move relatively quickly. Where key information is missing, or existing systems can't accommodate the requirements, potentially even requiring a separate solution, the timeline extends accordingly, sometimes well beyond a year. It's precisely this uncertainty that makes an early, structured look worthwhile, rather than confronting the actual scope only once a deadline is close.
Sources
European Commission: Regulation (EU) 2024/1781 establishing a framework for setting ecodesign requirements for sustainable products (ESPR).
Disclaimer
The content of this article is provided for general information purposes only and does not constitute legal, audit, or other professional advice. It makes no claim to completeness. In particular, the specific requirements and deadlines for individual product categories will only be established through delegated acts of the European Commission and may still change. Application to any specific company requires an assessment of the individual case.
Whether and to what extent your company is affected by the Digital Product Passport is best clarified in a direct conversation.
We're happy to discuss, where you currently stand and what a first impact assessment could show for you.
