Who Needs a Digital Product Passport?
Executive Summary
The Digital Product Passport is often described as a manufacturer obligation. That description is too narrow to plan against. The legal duty attaches to the economic operator that places a product on the European Union market, but the data that fills the passport originates across the entire value chain, and the passport is read by parties who never had a commercial relationship with the operator that created it.
This article answers the question most organisations ask first: does this affect us, and if so, what are we accountable for? It introduces the Digital Product Passport Responsibility Model, which divides the value chain into six groups and states what each one contributes. It then covers which products are expected to be in scope, which organisations should start work now, who is indirectly affected, what the position is for smaller businesses, and which misconceptions cause the most wasted effort.
It assumes you already know what a passport is. If you do not, read What is a Digital Product Passport? first, including the four layer framework introduced there, which this article builds on directly.
- Legal responsibility sits with the economic operator placing the product on the EU market. Operational responsibility is distributed across six groups. - The passport follows the product, not the company. Every party that touches the product may need to read from it or contribute to it. - Confirmed today: the ESPR framework (Regulation (EU) 2024/1781) and the battery passport (Regulation (EU) 2023/1542) from 18 February 2027. Everything else arrives per product group through delegated acts. - Suppliers are affected before their customers are, because the customer cannot publish data it has not been given. - Organisations outside the EU are in scope whenever their goods are placed on the EU market, usually through an importer that carries the legal duty.
- Small and medium sized enterprises are not exempt from the passport obligation itself, though ESPR requires the Commission to consider proportionate treatment and support measures. - The useful preparation now is identification, supplier data collection and governance. None of it depends on the final field list.
Maps the six economic operator groups in a supply chain to the passport duties each one actually carries.
Table of Contents
Who the Question Really Applies To
There are two different questions hiding inside “does this affect us”.
The first is legal: who carries the obligation, and who can be sanctioned if the passport is missing, inaccurate or unavailable. ESPR answers this narrowly. The duty falls on the economic operator that places the product on the EU market. For goods produced outside the EU, that is normally the importer rather than the non EU manufacturer.
The second is operational: whose product data ends up inside the passport, and whose work depends on it being right. This is a far wider set of organisations. A brand owner cannot declare recycled content it cannot evidence. An importer cannot verify a conformity declaration it has never received. A recycler cannot act on composition data that was never captured at design time.
Under EU product legislation, the manufacturer, the authorised representative, the importer, the distributor, the fulfilment service provider, or any other natural or legal person subject to obligations in relation to the manufacture of products, making them available on the market or putting them into service. The operator that places the product on the EU market carries the passport obligation.
Confusing the two questions is the most common planning error. Organisations with no direct legal duty conclude they are out of scope, then discover that their customer’s compliance deadline is now their delivery deadline.
The Digital Product Passport Responsibility Model
The Responsibility Model is an educational framework, not a legal classification. Its purpose is to let an organisation locate itself quickly, understand what it owes to the passport, and understand what it can expect from it. The six groups are arranged around the passport deliberately: the passport belongs to the product, and each group holds it for part of that product’s life.
Product information, compliance and lifecycle governance
Creating and maintaining technical product information
Ensuring compliant products enter and move through the market
Mapped against the four layer framework from the previous article, the model divides cleanly. Brand owners dominate the governance layer. Manufacturers and suppliers dominate the information layer. Importers, distributors and retailers operate mainly at the point where the regulatory and technology layers meet the market. Service, repair and recycling organisations are the primary consumers of the information layer and, over time, contributors to it.
1. Brand Owners
Responsible for product information, compliance and product lifecycle governance.
The brand owner is usually the organisation whose name appears on the product and, in many structures, the economic operator that places it on the EU market. That makes it the accountable party for passport accuracy, completeness, availability and retention, even where every input came from someone else.
Practical scope of responsibility:
- Deciding what the product claims and ensuring each claim is evidenced.
- Owning the governance layer: who may create, change, approve and publish each attribute.
- Contracting suppliers and manufacturers for the data required, in a structured form and on a schedule.
- Keeping the passport current after launch, including corrections and variant changes.
- Ensuring continued availability for the retention period set by the applicable delegated act, including the backup arrangement ESPR requires.
Passport data is not signed off once. Formulations change, suppliers change, standards are superseded and corrections are issued. Brand owners that fund a launch project but no stewardship role end up with a passport that was accurate on the day it was published and progressively wrong afterwards.
2. Manufacturers
Responsible for creating and maintaining technical product information.
Manufacturers hold the ground truth about how the product is actually made: bill of materials, process parameters, test results, part numbers, spare part availability and disassembly sequence. Where the manufacturer is also the operator placing the product on the EU market, it carries the legal duty as well.
Practical scope of responsibility:
-
Maintaining an accurate, versioned bill of materials with enough product traceability to tie it to physical output.
-
Producing and retaining conformity assessment evidence, test reports and applicable standards references.
-
Supplying repair, spare part and disassembly information in a structured form.
-
Binding passport data to the correct production unit, batch or serial, so that a scan resolves to the right record.
-
Contract manufacturers additionally need to deliver this data to the brand owner in an agreed format rather than as unstructured documents.
A brand owner specifies a product, a contract manufacturer builds it, and a third party laboratory tests it. The passport requires material composition traced to the batch. The manufacturer holds the batch records, the laboratory holds the test data, and neither has a contractual obligation to deliver either in a structured form. The gap is commercial, not technical, and it is resolved in the supply agreement rather than in the software.
3. Component and Material Suppliers
Responsible for supplying trusted upstream data.
Suppliers are the group most often surprised by the passport, and the group whose readiness most constrains everyone else. A passport attribute such as recycled content, substance of concern, or material origin is sustainability data that cannot be published by a brand owner unless a supplier has stated it, evidenced it, and accepted that it may be relied upon.
Practical scope of responsibility:
- Providing material declarations, substance data and, where applicable, recycled content evidence.
- Providing this data in a machine readable, reusable form rather than as a one off spreadsheet or scanned certificate.
- Notifying customers when a specification, source or formulation changes, because a silent change invalidates a published passport.
- Being able to answer the same question consistently for many customers, which is why a single internal source of truth is cheaper than per customer responses.
If a delegated act applies to a finished product from a given date, the supplier data behind it must exist well before that date. Suppliers that can answer structured data requests quickly become materially easier to buy from, which is a commercial advantage rather than a compliance cost.
4. Importers and Distributors
Responsible for ensuring compliant products enter and move through the market.
For goods manufactured outside the EU, the importer is normally the economic operator placing the product on the EU market, and therefore normally the party carrying the passport obligation. This is the single most under appreciated point in the entire topic. A non EU manufacturer may face no direct EU duty while its EU importer faces the full one.
Practical scope of responsibility:
- Verifying that a passport exists, is reachable and is complete before the product is placed on the market.
- Ensuring the product identifier in the passport can be checked by customs against the Commission operated registry.
- Holding the data, or a contractual right to it, sufficient to answer market surveillance requests.
- Distributors must ensure the passport remains associated with the product as it moves, including after repackaging or relabelling, and must not obscure or remove the data carrier.
Add passport existence, resolvability and data completeness to goods inward acceptance criteria, alongside conformity documentation. Discovering a missing passport at the border is expensive. Discovering it during supplier onboarding is not.
5. Retailers
Responsible for providing consumers with access to Digital Product Passport information where required.
Retailers are rarely the accountable operator, but they are the surface where consumers meet the passport. ESPR anticipates that passport information is accessible at the point of sale, including in distance selling, which places practical obligations on both physical and online retail.
Practical scope of responsibility:
- Ensuring the data carrier on the product or packaging remains present, legible and scannable in store.
- Presenting or linking to the required passport information in online listings, where the applicable rules require it for distance selling.
- Not overwriting or replacing manufacturer identifiers with retailer specific codes in a way that breaks resolution.
- Own brand and private label retailers are a special case: they are usually brand owners in the sense of group one, and carry the full accountability that comes with it.
A retailer selling a product under its own brand is generally the party placing it on the market and is therefore the accountable operator. Private label ranges frequently sit in a retailer’s buying function with no compliance ownership assigned to them.
6. Service, Repair and Recycling Organisations
Responsible for contributing lifecycle information where applicable.
This group is the reason the passport exists at all. ESPR is circular economy legislation, and its value is realised when a repairer can find a part reference, a refurbisher can verify provenance, and a recycler can identify materials and safe disassembly steps without contacting the manufacturer.
Practical scope of responsibility:
- Reading passport data to make repair, reuse, remanufacture and recovery decisions.
- Contributing lifecycle events where the applicable rules provide for it, such as repairs performed, parts replaced or refurbishment status.
- Feeding practical failure and disassembly experience back to manufacturers, which improves both the product and the passport.
Note the boundary carefully. The right of these organisations to access defined passport data is a framework principle in ESPR. A general obligation on independent repairers or recyclers to write into the passport is not established horizontally and would be set, if at all, per product group. Plan for read access as the near term reality and write access as the direction of travel.
Which Products Are Expected to Require a Passport
ESPR applies to almost all physical goods placed on the EU market, with limited exclusions including food, feed, medicinal products, veterinary medicinal products, living plants and animals, and products of human origin. Being within ESPR scope does not by itself create a passport obligation. The obligation attaches when a delegated act for the relevant product group is adopted and applies.
Two categories should be distinguished carefully, because conflating them produces both false alarm and false comfort.
Confirmed in law today. Batteries. Regulation (EU) 2023/1542 requires a battery passport for light means of transport batteries, industrial batteries above 2 kWh and electric vehicle batteries from 18 February 2027. This is a separate legal basis from ESPR and should be read from the battery regulation directly. Construction products are addressed separately again under Regulation (EU) 2024/3110, which establishes its own digital product passport system.
Expected through future delegated acts. The ESPR working plan for 2025 to 2030 identifies priority product groups for the first wave of ecodesign and information requirements, including textiles and apparel, furniture, iron and steel, aluminium, and tyres, alongside several energy related product groups carried over from the previous framework. Identification as a priority group signals intent and sequence. It does not fix the data model, the carrier or the compliance date until the delegated act is adopted.
“If we place physical goods on the EU market, we should assume a passport obligation will reach us eventually, and we should confirm timing only from an adopted delegated act or a directly applicable regulation.”
Which Organisations Should Prepare Now
Preparation is warranted where the timing is fixed, where the lead time is long, or where a customer will impose the requirement earlier than the law does.
- Anyone placing batteries in scope of Regulation (EU) 2023/1542 on the EU market. The date is fixed. Work should already be underway.
- Manufacturers and brand owners in announced priority groups, particularly textiles, furniture, steel, aluminium and tyres. Supplier data collection in these categories takes longer than the likely notice period.
- Importers of any regulated category. The legal duty lands on you rather than on the overseas manufacturer, and your remedy is contractual, which means it must be in place before the goods are ordered.
- Component and material suppliers to any of the above. You will be asked for structured data before your customer’s own deadline.
- Own brand and private label retailers. You are the accountable operator for those ranges.
- Organisations with long product development cycles. If a product designed today will still be sold when a delegated act applies, the passport data requirements belong in the current design process, not in a later retrofit.
Every plausible delegated act requires the same foundations: a persistent unique identifier per product, batch or item; structured supplier data with evidence; and governance that keeps both accurate. None of that is wasted if the final field list differs from your assumption. Field level mapping is the last step, not the first.
Organisations Likely to Be Indirectly Affected
Indirect exposure is real exposure when it lands on a customer’s timeline.
- Non EU manufacturers. No direct duty in most structures, but your EU importer has one and will pass the data requirements to you contractually. Suppliers who cannot answer will be replaced by those who can.
- Contract manufacturers and white label producers. You hold the technical data your customer must publish. Expect structured data delivery to become a clause in supply agreements.
- Logistics, fulfilment and packaging providers. Handling must not damage, obscure or remove the data carrier, and repackaging must preserve the link between product and passport.
- Marketplaces and online platforms. Distance selling rules generally require product information to be shown before purchase. Platforms will need to surface passport data supplied by sellers.
- Certification bodies, testing laboratories and auditors. Your outputs become passport inputs and will increasingly be requested in structured, machine readable form.
- Software, PLM, ERP and PIM vendors. Customers will require interoperability, open standards and export without lock in, which ESPR mandates for the passport itself.
- Consultancies and compliance advisers. Demand shifts from document preparation towards data governance and supply chain data collection.
SMEs and Digital Product Passports
There is no general small business exemption from the Digital Product Passport. If an SME places a product on the EU market that falls under an applicable delegated act, the obligation applies in the same way as it does to a large enterprise.
What ESPR does provide is proportionality and support. The regulation requires the Commission to take account of the impact on small and medium sized enterprises when setting requirements, to consider measures such as guidance, tools and financial support in the design of delegated acts, and to avoid disproportionate administrative burden. Member States are also expected to provide support through their own instruments. The practical effect is likely to be found in the transition periods, guidance and simplified routes within individual delegated acts, rather than in a blanket carve out.
Some smaller manufacturers plan on the assumption that they will be excluded. The ESPR framework does not exclude them. Assuming a proportionality measure that has not been adopted is a substantial planning risk, and the low cost preparation steps are worth taking regardless.
For a smaller organisation, the pragmatic reading is encouraging. The foundations are inexpensive. Unique identification, a clean product data record, a supplier data request template and a named owner cost far less than a large enterprise programme, and a business with fifty products can reach a defensible position faster than one with fifty thousand.
Common Misconceptions
The duty attaches to the operator placing the product on the EU market, which is frequently the importer or the private label retailer. The data comes from a much wider group again.
The trigger is placement on the EU market, not the location of the producer. Non EU producers selling into the EU are reached through their importers, and in practice through their supply contracts.
Consumer access is only one of several access tiers. Market surveillance authorities, customs, importers, repairers and recyclers all have defined interests, and business to business products sit squarely within ESPR scope.
Suppliers are responsible for supplying accurate data. The operator placing the product on the market remains accountable for what the passport states. Unverified supplier data does not transfer accountability.
A QR code is one part of the technology layer. Without a persistent unique identifier, structured data, access tiering and governance, it resolves to a marketing page rather than to a passport.
The battery obligation has a fixed date. The framework duties are already law. The preparation with the longest lead time, which is supplier data collection, is also the part that is completely independent of the pending detail.
Practical Preparation Checklist
Work through this in order. Each step is useful on its own and none depends on an unadopted delegated act.
-
Locate yourself in the Responsibility Model. Write down which of the six groups you occupy, for which product lines. Many organisations occupy more than one.
-
Establish whether you are the operator placing goods on the EU market. Confirm it per legal entity and per route to market, including private label and marketplace sales.
-
Assign a named owner. One accountable person for passport readiness, with authority across product, compliance, procurement and technology.
-
Inventory your products and variants. Determine what a passport would need to be issued against: model, batch or individual item.
-
Establish unique identification. A persistent identifier per product, and per batch or serial where it matters, that will not be reused or reissued. Most organisations use GS1 keys expressed as a GS1 Digital Link address.
-
Audit the data you already hold. Map existing attributes to the passport categories and mark each as present and structured, present but unstructured, or missing.
-
Identify your supplier data gaps. These are almost always the critical path. Rank suppliers by how much passport relevant data they hold.
-
Update contracts and onboarding. Add structured data delivery, change notification and evidence retention to supply agreements before the deadline, not after.
-
Define governance. For each attribute: source, owner, approver, update trigger, evidence and retention.
-
Run one product family end to end. Identifier, data collection, publication, resolution and access tiering, on a single family, before scaling.
-
Choose technology on interoperability grounds. ESPR requires open standards and no vendor lock in. Require data export as an acceptance criterion.
-
Monitor the delegated acts for your product groups. Assign this to a named person with a recurring review, and treat adoption as the trigger for field level mapping.
A mid sized textile component supplier built one internal record per material covering composition, recycled content, substances of concern and origin, with evidence attached. When brand customers began issuing passport data requests, it answered in days rather than months from a single source, and was added to two preferred supplier lists as a direct result. The work was data governance, not software.
Frequently Asked Questions
Does the Digital Product Passport apply to my organisation?
If you place physical goods on the EU market and a delegated act or a directly applicable regulation covers your product group, yes, and you are the accountable operator. If you supply, import, distribute, sell, repair or recycle those goods, you are affected operationally even where you carry no direct duty.
We are a non EU manufacturer. Are we in scope?
Usually not directly. Your EU importer normally carries the legal obligation. In practice the data requirements reach you through that importer’s supply contract, so the commercial effect is the same.
Who is legally responsible when several parties are involved?
The economic operator that places the product on the EU market. Contributions from manufacturers, suppliers and laboratories do not transfer that accountability, which is why contractual data obligations matter.
Are small businesses exempt?
No. There is no general SME exemption from the passport obligation. ESPR requires the Commission to consider SME impact and support measures when setting requirements, so proportionate treatment is likely to appear inside individual delegated acts rather than as a blanket exclusion.
Do retailers need their own passport system?
Not usually, unless they sell own brand or private label goods, in which case they are the accountable operator. Otherwise the retail responsibility is to keep the data carrier intact and to make the required information accessible at the point of sale, including online.
Do repairers and recyclers have to update the passport?
Access for these groups is a framework principle in ESPR. A horizontal obligation on independent operators to write into the passport is not established, and any such duty would be set per product group. Plan for read access now.
Which products are confirmed today?
Batteries under Regulation (EU) 2023/1542, applying from 18 February 2027, and a separate passport system for construction products under Regulation (EU) 2024/3110. Other product groups follow through ESPR delegated acts.
What should we do if our product group has no delegated act yet?
Establish unique identification, begin structured supplier data collection and put governance in place. These are prerequisites under every plausible field list, and they are the steps with the longest lead time.
Related Articles
- What is a Digital Product Passport?
- What Information Does a Digital Product Passport Contain?
- How Does a Digital Product Passport Work?
- Digital Product Passport
- What Are Delegated Acts?
- What is the Ecodesign for Sustainable Products Regulation (ESPR)?
- When Will Digital Product Passports Become Mandatory?
- What Are the Benefits of a Digital Product Passport?
Related Glossary Terms
Definitions of record for the terms used above live in the glossary.
- Economic Operator
- Digital Product Passport
- ESPR
- Delegated Act
- Market Surveillance
- Conformity Assessment
- Product Traceability
- Sustainability Data
References
- Regulation (EU) 2024/1781 establishing a framework for the setting of ecodesign requirements for sustainable products (ESPR), Official Journal of the European Union: https://eur-lex.europa.eu/eli/reg/2024/1781/oj
- Regulation (EU) 2023/1542 concerning batteries and waste batteries, Official Journal of the European Union: https://eur-lex.europa.eu/eli/reg/2023/1542/oj
- Regulation (EU) 2024/3110 laying down harmonised rules for the marketing of construction products, Official Journal of the European Union: https://eur-lex.europa.eu/eli/reg/2024/3110/oj
- Regulation (EU) 2019/1020 on market surveillance and compliance of products, Official Journal of the European Union: https://eur-lex.europa.eu/eli/reg/2019/1020/oj
- European Commission, ESPR working plan 2025 to 2030: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A52025DC0187
- European Commission, Ecodesign for Sustainable Products Regulation policy pages: https://commission.europa.eu/energy-climate-change-environment/standards-tools-and-labels/products-labelling-rules-and-requirements/ecodesign-sustainable-products-regulation_en
- CEN-CENELEC Joint Technical Committee 24 (JTC 24), Digital Product Passport standardisation work programme: https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/digital-product-passport/
About This Article
tieback Knowledge is a continuously maintained reference library covering Digital Product Passports, product traceability, product compliance and related regulations. Articles are reviewed regularly as legislation, standards and implementation guidance evolve.