What Are Delegated Acts?

Executive Summary

Most organisations first hear about the Digital Product Passport through the Ecodesign for Sustainable Products Regulation. They then look for the requirement in the regulation itself, do not find it, and conclude either that the obligation is vague or that it does not apply to them. Both conclusions are wrong. The detail is not missing. It lives somewhere else, in a second layer of European law called the delegated act.

A delegated act is a legally binding act adopted by the European Commission under a power granted to it by a framework regulation or directive. The framework decides what may be regulated and within what limits. The delegated act decides what is actually required, for which products, and from when. For Digital Product Passports this distinction is not academic. It is the difference between an organisation having a legal obligation and having none.

This article explains what delegated acts are, why the European Union uses them, who writes them and who can stop them, what they are permitted to change and what they are forbidden from changing. It separates them clearly from the other four things they are routinely confused with: framework regulations, implementing acts, guidance documents and industry best practice.

It introduces the EU Product Regulation Lifecycle, a nine stage model showing how a European policy ambition becomes an obligation on a named product in a named year, and where in that sequence an organisation can usefully act.

Where a requirement has not been adopted, this article says so. No product category is described as covered unless an act covering it has been adopted and published in the Official Journal.

Key Takeaways
  • A delegated act is binding EU law adopted by the European Commission under a power delegated to it by a framework act, on the basis of Article 290 of the Treaty on the Functioning of the European Union. - Framework regulations create powers and machinery. Delegated acts create the concrete, product specific obligations. - Delegated acts may only supplement or amend non essential elements of the framework. Essential elements are reserved to the Parliament and the Council. - The Commission drafts them, but the European Parliament and the Council can object during a scrutiny period, and either can veto. - Under ESPR, whether your product needs a Digital Product Passport, what it must contain and when it applies are all delegated act questions, not framework questions. - Until a delegated act covering your product group is adopted and applies, ESPR imposes no product specific passport requirement on that product. - Preparation is still rational, because the work with the longest lead time does not depend on the specification.

This is the second article in the Regulations section and the sixth in the learning path that begins with What is a Digital Product Passport?.

FrameworkTBF-006
The EU Product Regulation Lifecycle

Explains the stages by which a framework regulation becomes an enforceable product requirement through delegated acts.

Educational scope

This article provides general educational information about EU product regulation concepts. It does not determine the obligations of any particular organisation or product, and it is not legal advice. Whether and how a delegated act applies to a given product is a legal question that depends on specific facts.

Table of Contents

Definition

Definition
Delegated act

A non legislative act of general application, adopted by the European Commission under a power expressly delegated to it by a legislative act, which supplements or amends non essential elements of that legislative act. The legal basis is Article 290 of the Treaty on the Functioning of the European Union. A delegated act is binding law in every Member State once it enters into force, and it takes effect only if neither the European Parliament nor the Council objects within the scrutiny period set by the parent act.

Three features of that definition do the practical work.

It is real law, not guidance. A delegated act published in the Official Journal of the European Union is as binding on an economic operator as the framework regulation above it. It is enforced by the same national market surveillance authorities and carries the same consequences for non compliance.

Its power is borrowed and bounded. The Commission has no general authority to adopt delegated acts. It has authority only where a specific article of a specific legislative act grants it, only for the subject matter named in that grant, and only for the period the grant allows. A delegated act that exceeds its empowerment can be annulled by the Court of Justice.

It is where the specification lives. Framework acts are written to last for decades and are therefore deliberately general. The delegated act is the layer that names a product group, sets the numbers, lists the data fields and fixes the dates.

How to read the citation

A delegated act carries a citation of the form Commission Delegated Regulation (EU) 2025/NNNN supplementing Regulation (EU) 2024/1781. The word supplementing, and the reference to a parent regulation, are the tell. If a document you have been sent does not name a parent act and does not appear in the Official Journal, it is not a delegated act, whatever it is called.

Why Delegated Acts Exist

The European Union regulates a single market of roughly 450 million people and effectively every category of physical product sold within it. If every technical detail of every product rule had to pass through the full ordinary legislative procedure, involving the European Parliament and the Council in negotiation over each figure and each data field, the system would be unable to function. Delegated acts exist to resolve four specific problems.

Volume. ESPR alone is expected to cover most physical goods placed on the EU market. Writing product specific requirements for each family into one legislative text would produce an instrument too large to negotiate and too rigid to maintain.

Technical specificity. The right recycled content threshold for a textile is not a political question in the way that the decision to regulate recycled content is. It is a technical question that requires testing methods, industry data and standards work. Delegating it lets the political institutions decide the principle and specialists decide the number.

Speed of revision. Product technology, measurement methods and recycling infrastructure change faster than legislation can. A framework that can be updated only by full legislative procedure either freezes at the state of the art on the day it was signed or is repeatedly reopened. Delegation allows targeted revision without reopening the framework.

Sequencing. Not every product category is ready to be regulated at the same time. Delegation lets the Union start where the environmental gain is largest and the data is most mature, and address harder categories later, without holding the framework hostage to the least ready sector.

Example
Why the framework does not list the data fields

Regulation (EU) 2024/1781 sets out that a Digital Product Passport may be required, what it is for, how it must be accessible through a data carrier and who is responsible for it. It does not state that a garment must carry a fibre composition breakdown to a given percentage, because that answer differs for a garment, a tyre and a detergent. That is precisely the kind of decision the framework delegates.

There is a democratic trade off here, and the Treaty recognises it. Delegation moves rule making from elected co legislators to the executive. Article 290 answers that concern by fencing the power in three ways: the delegation must be explicit and limited in objective, content, scope and duration; only non essential elements may be delegated; and the Parliament and the Council retain both a veto during scrutiny and the power to revoke the delegation entirely.

The Difference Between Regulations and Delegated Acts

Five different kinds of document are routinely described as “the DPP rules” in supplier correspondence and vendor material. Only two of them are law. Distinguishing them is the single most useful compliance skill in this area.

InstrumentWho produces itLegally bindingWhat it doesTypical citation
Framework regulationEuropean Parliament and Council, ordinary procedureYes, directly applicableSets objectives, definitions, essential elements, and grants powersRegulation (EU) 2024/1781
Delegated actEuropean Commission, under a delegated powerYes, once in forceSupplements or amends non essential elements, sets product specific requirementsCommission Delegated Regulation (EU) YYYY/NNNN
Implementing actEuropean Commission, with Member State committee controlYes, once in forceSets uniform conditions for implementing rules that already existCommission Implementing Regulation (EU) YYYY/NNNN
Guidance documentEuropean Commission services, agencies, authoritiesNo, persuasive onlyExplains how the Commission interprets and expects to apply the lawFAQ, notice, guidance, blue guide
Industry best practiceTrade bodies, consortia, vendors, consultantsNoProposes a way of meeting a requirement, often ahead of the specificationWhite paper, sector playbook, vendor framework

Two boundaries in that table cause most of the confusion.

Delegated act versus implementing act. Both are Commission acts, and both appear in the Official Journal, so they look alike. The difference is constitutional. A delegated act, under Article 290, changes the content of the rules by supplementing or amending the parent act, and is controlled after the fact by Parliament and Council scrutiny. An implementing act, under Article 291, does not change what the rules require. It sets uniform conditions for applying rules that already exist, for example a common technical format or a standard template, and it is controlled in advance by committees of Member State representatives, a process known as comitology. In the Digital Product Passport context you should expect substance, meaning which products and which data, to arrive by delegated act, and mechanics, meaning common formats and procedures, to arrive by either route depending on the empowerment used.

Law versus guidance. Guidance is genuinely useful and often the fastest way to understand intent, but it cannot create an obligation and cannot remove one. An authority applying the law is bound by the act, not by the FAQ.

Common Mistake
Treating a vendor readiness framework as a legal requirement

A supplier is told that a “DPP standard” requires forty two data fields. The list turns out to originate from a consortium proposal or a software product’s data model rather than from any adopted act. The organisation then negotiates supplier contracts, and sometimes buys tooling, around a specification with no legal status. Ask one question of every requirement presented to you: which act, which article, which Official Journal reference? If there is no answer, it is input, not obligation.

Regulation Summary
Article 290, Treaty on the Functioning of the European Union
Jurisdiction
European Union
Status
In force
Applies from
1 December 2009

Establishes the delegated act. A legislative act may delegate to the Commission the power to adopt non legislative acts of general application to supplement or amend certain non essential elements of that act. The objectives, content, scope and duration of the delegation must be explicitly defined. Essential elements are reserved to the legislative act itself and cannot be delegated. The legislative act must set the conditions of delegation, which may include revocation by the Parliament or the Council, and entry into force only if no objection is expressed within a stated period.

What a delegated act can change

Within the boundaries of its empowerment, a delegated act can do a great deal:

  • Name the product group it applies to, and define its scope precisely enough to test membership.
  • Set performance requirements, for example on durability, reparability, recycled content or energy and resource efficiency.
  • Set information requirements, including whether a Digital Product Passport is required for the group.
  • Specify the data attributes the passport must carry, their format and their level of granularity.
  • Determine who may see which data, distinguishing public information from information available only to authorities or to specified professionals such as repairers and recyclers.
  • Set the applicable conformity assessment route.
  • Fix application dates and transitional arrangements, including different dates for different requirements within the same act.
  • Amend or repeal earlier delegated acts covering the same group.

What a delegated act cannot change

The limits matter just as much:

  • It cannot alter essential elements of the framework, such as its objectives, its core definitions or its scope of application. Those are reserved to the co legislators.
  • It cannot exceed the empowerment. It may only regulate what the parent article authorises, and only for the duration the parent act allows.
  • It cannot create obligations on subject matter the framework does not cover at all.
  • It cannot override other EU law. Where a product is already governed by a specific regime, the framework decides the relationship; a delegated act cannot unilaterally displace it.
  • It cannot take effect if the Parliament or the Council objects within the scrutiny period.
  • It cannot survive judicial challenge if it is adopted outside these limits. The Court of Justice can annul it.

The EU Product Regulation Lifecycle

The reason delegated acts feel opaque is that organisations encounter them at the end of a long process and see only the output. Seen as a whole, European product regulation follows a repeatable sequence. Understanding where a given product family sits in that sequence tells you, more reliably than any deadline list, whether you should be watching, preparing or delivering.

The EU Product Regulation Lifecycle has nine stages, grouped into four phases: the policy foundation that sets direction, the rule making phase where the specification is written, the effect phase where obligations become real, and renewal, where the cycle begins again for the same product group.

How to use the model

Locate each product family on the lifecycle and the right response follows from the stage:

  • Stages 1 to 3. No obligation exists and no specification exists. The correct posture is monitoring: watch the working plan, and note which of your categories appear in it.
  • Stage 4. A draft is being shaped. This is the moment to submit evidence through the public consultation, directly or through a trade association. Influence is cheap here and impossible later.
  • Stage 5. Adoption and scrutiny. The text is visible and close to final, but not yet certain. Begin gap analysis against the draft, and avoid irreversible commitments until it is published.
  • Stages 6 and 7. The specification is fixed and the clock is running. Delivery, not analysis.
  • Stages 8 and 9. Operate and maintain. Expect the requirement to change again, and build for data that can be corrected and republished rather than data that is entered once.

How a Delegated Act Is Developed

The path from an intention to a binding requirement is more structured, and more open, than most organisations assume. Six stages matter.

Public Consultation

Before the Commission adopts a delegated act, it publishes a call for evidence and a draft for public feedback on the Have Your Say portal. Anyone may respond: manufacturers, importers, retailers, trade bodies, standards organisations, non governmental organisations and individuals. Responses are published.

Two things are worth knowing. First, feedback periods are typically weeks, not months, so an organisation that is not watching will miss them. Second, the responses that change drafts are the ones carrying evidence, for example measured data on what a proposed threshold would cost, what a proposed data field is not currently possible to source, or where a definition would misclassify a real product.

Best Practice
Respond with evidence, not objection

A submission saying a requirement is burdensome carries almost no weight. A submission showing that a specific data attribute is not held by any actor in a named supply chain, with the reason, and proposing a workable alternative, is the kind of input that visibly changes drafts. Assign ownership of consultation monitoring to a named person for the product groups that matter to you.

Expert Groups

The Commission is required to consult expert groups when preparing delegated acts, including experts designated by each Member State. Under the ecodesign framework this work runs through the Ecodesign Forum, which brings together Member State representatives and stakeholders from industry, small and medium sized enterprises, environmental organisations, consumer groups and trade unions. Agendas, minutes and documents of formal Commission expert groups are published in the Register of Commission Expert Groups, which makes this the most reliable early view of where a draft is heading.

Preparatory studies commissioned at this stage assemble the technical evidence base: product definitions, market and stock data, environmental impact modelling and the feasibility of candidate requirements. Where they exist, they generally tell you what the eventual act will look like long before the act appears.

European Commission

The Commission drafts and formally adopts the act. Two points are commonly misunderstood.

The Commission is not free to write what it likes. Each delegated act must identify the article that empowers it, and must stay within that empowerment in objective, content, scope and duration. The enabling articles in ESPR are themselves quite prescriptive about what an ecodesign delegated act must contain and the assessment it must be based on.

Adoption is a formal college decision, and the act is adopted in all official EU languages simultaneously. The language versions are equally authentic, which occasionally matters when a term is ambiguous.

European Parliament & Council Scrutiny

Once adopted, the act is notified simultaneously to the European Parliament and the Council. Neither institution can amend it. Each has three options: say nothing and let the scrutiny period expire, declare early that it will not object, which accelerates entry into force, or object.

The scrutiny period is set by the parent act. Under ESPR it is two months, extendable by two further months at the request of either institution. If either the Parliament or the Council objects within that window, the act does not enter into force. Separately, either institution may revoke the delegation of power itself, which ends the Commission’s ability to adopt further acts under that empowerment without affecting acts already in force.

This is the answer to the frequent claim that delegated acts let the Commission legislate unchecked. The check is real, it is exercised by the elected co legislators, and it operates on every act.

Publication

If no objection is raised, the act is published in the Official Journal of the European Union and enters into force on the date it specifies, commonly the twentieth day after publication. Publication is the moment the requirement becomes certain and citable. Before publication there is a draft; after publication there is law.

Verify against the Official Journal, always

EUR-Lex is the authoritative source. Every act has an ELI reference of the form eur-lex.europa.eu/eli/reg_del/YYYY/NNNN/oj. Cite that, not a news article, a webinar slide or a vendor summary. If a claimed requirement cannot be traced to an ELI reference, treat it as unverified.

Application

Entry into force and date of application are different things, and the gap between them is the implementation window. An act can enter into force twenty days after publication while its requirements apply from a date eighteen months or more later. Acts frequently stagger dates: performance requirements from one date, information and passport requirements from another, particular data attributes later still, with transitional treatment for products already placed on the market.

Example
Reading the dates correctly

A hypothetical act enters into force in March, states that information requirements apply from July two years later, and exempts products placed on the market before that date. The planning date is not March, and it is not the July deadline either. It is the date by which data collection, supplier clauses, identifier assignment and carrier application must all be finished, which for a seasonal product with a long development cycle can be more than a year earlier.

Why Delegated Acts Matter for Digital Product Passports

ESPR creates the Digital Product Passport as an instrument. It establishes that a passport can be required, that it must be accessible through a data carrier linked to a product identifier, that the operator placing the product on the market is responsible for it, and that a registry and access rules exist. What it does not do is make any specific product need one.

Every question an organisation actually needs answered is a delegated act question:

QuestionAnswered by
Does my product need a passport at all?The delegated act for my product group
What data must the passport contain?The delegated act, attribute by attribute
How granular must it be, per model or per item?The delegated act
Who can see which data?The delegated act, which sets access rights per audience
Which carrier and where on the product?The delegated act, within the framework’s rules
From what date does it apply?The delegated act
What happens to existing stock?The delegated act’s transitional provisions

This has three practical consequences.

No delegated act means no product specific passport obligation. If no adopted act covers your product group, ESPR does not currently require a passport for it. That is a statement about today, not a prediction. The ESPR working plan for 2025 to 2030 sets out the product groups the Commission intends to address, but intention in a working plan is not law, and the content and timing of any future act remain undetermined until it is adopted. Any claim that a named category “will require a passport by” a particular year should be read as an expectation, not a requirement, unless it cites an adopted act.

Requirements will differ between your product families. Two categories in the same catalogue can be governed by different acts with different attributes, different granularity and different dates. Systems and processes built around one act’s field list tend to need rework for the second, which is an argument for modelling product data in a way that can be extended rather than hard coding one specification.

The specification will change after it arrives. Stage 9 of the lifecycle is not decoration. Delegated acts are amended and replaced. Treat the passport as a maintained data product with versioning and republication, not as a document produced once at launch. How that plays out operationally is covered in How Does a Digital Product Passport Work?.

Common Mistake
Waiting for certainty before doing anything

Because the specification is genuinely unknown until adoption, organisations often defer all work until the act appears. The specification then arrives with an application date shorter than the organisation’s own supplier data cycle. The mistake is treating all preparation as specification dependent. Most of the hardest work is not.

What Organisations Should Do While Waiting

Nothing in this section is legally required in the absence of an applicable delegated act. All of it is preparation that holds its value whatever the eventual specification says, because it addresses constraints that no act can remove: how long it takes to reach your suppliers, how long it takes to correct identifier data, and how long your product development cycle is.

  1. Establish which of your product groups appear in the working plan. Map your catalogue to the product groups named in the ESPR working plan for 2025 to 2030. This tells you which families to monitor closely and which are not on the horizon, and it is a one off exercise that most organisations have never done.

  2. Assign a named owner for regulatory monitoring. Watching the Have Your Say portal, the expert group register and EUR-Lex is a small ongoing task that is reliably forgotten when it belongs to nobody. The owner’s output is simple: which of our groups moved a stage this quarter.

  3. Fix identifiers first. Whatever the act requires, it will require the product to be uniquely and stably identifiable. Resolving duplicate, reused or inconsistent identifiers across ERP, PIM and commerce systems is slow, unglamorous and entirely specification independent. Standards work here, including GS1 identifiers and GS1 Digital Link, is mature and usable now.

  4. Audit what data you already hold, and where it came from. Most organisations hold more relevant sustainability data than they think, scattered across specification sheets, test reports and supplier declarations, and can evidence less of it than they think. Knowing the difference between held and evidenced is the real baseline.

  5. Put data clauses into supplier agreements at the next renewal. The longest lead time in any passport programme is obtaining verified data from tier two and beyond. Contractual language added at natural renewal points costs almost nothing; renegotiating a contract mid term under deadline pressure costs a great deal.

  6. Decide data ownership internally. Who owns composition data, who owns compliance evidence, who signs off on what is published. Ambiguity here surfaces late and stalls delivery.

  7. Participate in the consultation for your categories. See stage 4. It is the only point at which you can affect the requirement rather than absorb it.

Best Practice
Build for change, not for a specification

Design your product data model so that attributes, granularity and audiences can be added and revised without rebuilding, and so that a published passport can be corrected and reissued. Every delegated act will eventually be amended, and different acts will apply to different parts of the portfolio. Flexibility is the requirement that is certain.

Each of these steps has a fuller treatment elsewhere in the library. Sequencing them is covered in How to Build a Digital Product Passport Implementation Roadmap, supplier lead time in How to Prepare Suppliers for Digital Product Passports, and internal ownership of product data in What Is Product Data Governance?.

Common Misconceptions

“ESPR already tells us what data our passport needs.” It does not. It establishes the instrument and the machinery. The data is set by the delegated act for the product group.

“Delegated acts are just guidance.” They are binding law, published in the Official Journal and enforced by national market surveillance authorities.

“The Commission can impose anything it wants through a delegated act.” It can act only within an express empowerment, only on non essential elements, and only if neither the Parliament nor the Council objects during scrutiny. The delegation itself can be revoked.

“Delegated act and implementing act are two names for the same thing.” They rest on different Treaty articles, do different jobs and are controlled differently. Delegated acts supplement or amend the rules under Article 290 with after the fact scrutiny by the co legislators. Implementing acts set uniform conditions for applying existing rules under Article 291 with before the fact control by Member State committees.

“Our category is definitely covered, we saw it in a working plan.” A working plan states the Commission’s intended sequence. It is a strong signal and worth planning against, but it is not law, and both the content and the timing of any act remain open until adoption.

“Once the act applies we are compliant and done.” Enforcement is continuous and acts are revised. Compliance is a maintained state.

“There is nothing useful to do until the specification exists.” Identifiers, data ownership, data audit and supplier clauses are all specification independent, and all slower than the typical implementation window.

Frequently Asked Questions

Yes. Once it enters into force it is binding EU law in every Member State, directly applicable where it takes the form of a delegated regulation, and enforced by national market surveillance authorities.

The European Commission drafts and adopts it, supported by preparatory studies and required consultation of expert groups including Member State experts. The European Parliament and the Council cannot amend the text, but either may object during the scrutiny period, which prevents it entering into force.

Two months from notification, extendable by a further two months at the initiative of either the European Parliament or the Council. If neither objects, the act is published and enters into force.

Entry into force is when the act becomes part of EU law, commonly twenty days after publication. The date of application is when its requirements start to bite for products, which is often one to three years later and can differ between requirements within the same act.

Yes. Besides objection during scrutiny, an adopted act can be challenged before the Court of Justice of the European Union, typically on the ground that it exceeds the empowerment or regulates an essential element that could not lawfully be delegated.

Check EUR-Lex for acts supplementing Regulation (EU) 2024/1781 covering your group. If no adopted act covers it, ESPR imposes no product specific ecodesign or passport requirement on it today. The ESPR working plan for 2025 to 2030 indicates which groups the Commission intends to address, without determining the content or timing of any future act.

Regulation (EU) 2023/1542 is separate legislation with its own battery passport obligations and its own timetable, and it also uses delegated and implementing acts for detail. It does not derive from ESPR, so an ESPR delegated act is not needed for its obligations to apply.

The Commission’s Have Your Say portal publishes calls for evidence and draft acts for feedback, and the Register of Commission Expert Groups publishes agendas and documents from the groups consulted during preparation.

Key Takeaways

Key Takeaways
  • A delegated act is binding EU law adopted by the European Commission under an express power granted by a framework act, on the basis of Article 290 TFEU. - Framework regulations set objectives, definitions and powers. Delegated acts set the product specific requirements, the data and the dates. - The power is bounded: only non essential elements, only within the empowerment, and only if neither the Parliament nor the Council objects during scrutiny. The delegation can be revoked. - Delegated acts are not implementing acts. Article 290 supplements or amends the rules with after the fact scrutiny; Article 291 sets uniform conditions for applying existing rules with Member State committee control. - Guidance documents and industry frameworks are not law. Ask which act, which article, which Official Journal reference. - Under ESPR, whether a Digital Product Passport is required, what it contains, who can see it and when it applies are all delegated act questions. - No adopted delegated act for your product group means no product specific passport obligation today. Working plans signal intent, not obligation. - The EU Product Regulation Lifecycle runs from the Green Deal through framework regulation, prioritisation, consultation, delegated act, product specific requirements, implementation and market surveillance to future revision, and repeats per product group. - The consultation stage is the only point at which an organisation can shape the requirement rather than absorb it. - Identifier discipline, data ownership, a data audit and supplier data clauses are worth starting now because none of them depend on the specification.

Definitions of record for the terms used above live in the glossary.

References

About This Article

tieback Knowledge is a continuously maintained reference library covering Digital Product Passports, product traceability, product compliance and related regulations. Articles are reviewed regularly as legislation, standards and implementation guidance evolve.

Page Metadata

FieldValue
Published2026-08-07
Last Reviewed2026-08-07
Reading Time20 min
Difficultybeginner
Authortieback
CategoryRegulations
TagsDelegated Acts, ESPR, EU Law, Article 290 TFEU, Implementing Acts, Digital Product Passport