How to Prepare Your Company for the DPP - EADTrust

Blog

Inicio > Sin categoría > How to Prepare Your Company for the DPP

How to Prepare Your Company for the DPP

How to Prepare Your Company for the DPP

Suscríbete:

There is a way of interpreting the Digital Product Passport timeline that may seem reassuring: the first mandatory sector-specific DPPs, apart from the battery passport arriving in February 2027, will not become applicable until 2028-2029 for the most advanced sectors and until 2029-2031 for the others. A margin of two or three years. Enough time to adapt.

That interpretation is incorrect. Not because the dates are different, they are what they are, but because the DPP is not a document generated at the point of sale. It is a data system that requires information architecture, supplier contracts, IT design decisions, authentication infrastructure and integration with the European Commission’s Central Registry. CWA 18186:2025 (the CEN technical guidelines published in May 2025) identifies fifteen different design decisions that the person responsible for implementing the DPP in a company must make before the system becomes operational. Those decisions cannot be implemented in weeks. They take months or years.

This article is a guide to where you should begin: which decisions need to be made, in what order, what technical infrastructure you need and how everything fits within the actual deadlines established by the regulatory ecosystem.

Definitions on how to prepare your company for the DPP

CWA 18186:2025

CEN guidelines (CEN Workshop Agreement) published on 5 May 2025, providing practical guidance on designing and implementing Digital Product Passports. It is the first European standard on the DPP and the main technical reference for companies beginning the preparation process.

DPP management system

The IT system that hosts DPP data, manages differentiated access rights, provides the online information portal and connects to the European Commission’s Central Registry. It may be internal, outsourced or hybrid.

The role your company needs to create: the DPP designer

CWA 18186:2025 introduces a role that does not yet formally exist in most European companies: the DPP designer, or person responsible for the DPP. This is the person responsible for making decisions about the IT implementation of the DPP or preparing the requirements for an external provider to implement it.

The term may sound technical, but the function is strategic. The DPP designer is not necessarily a software engineer: this is the person who must determine what data the DPP needs to collect, how that data will be managed throughout the product life cycle, which supply chain actors must contribute to it and what IT architecture can support all of this.

The CWA states that although DPP designer is the term used in the document, each company may use whichever title it prefers: DPP manager, DPP executive or another title. What matters is not the title but the existence of a person or team with clear responsibility for designing and implementing the DPP.

In small companies, this role may fall to the quality manager or IT manager. In medium-sized and large companies, it may require a cross-functional team combining operations, IT, legal and sustainability professionals. What does not work is assuming that the DPP will only need to be addressed once the delegated act arrives.

The first decision your company needs to make about the DPP is who will design it. Without that person or team, the other decisions will not be made. And without those decisions, the system will not be ready when the deadline arrives.

The fifteen decisions the DPP designer must make

CWA 18186:2025 organises DPP design decisions into fifteen clearly defined contexts. They do not all have the same importance or time horizon, but all of them must be resolved before the system becomes operational. We have grouped them by type to make prioritisation easier.

Decisions about the passport type and identifiers

Decision 1Passport type: model, batch or item

This is probably the decision with the greatest impact on the entire technical architecture of the DPP. A model-level DPP is the closest to the current labelling system: all products in the same series share the same passport. It is the minimum requirement for many product groups. A batch-level DPP enables traceability between B2B actors. An item-level DPP is the most granular: each physical unit has its own unique identifier, allowing events to be recorded throughout its life cycle, including repairs, refurbishment and changes in status.

The required level is determined by the delegated act for each product group. However, deciding which level you want to implement, which may be more ambitious than the minimum requirement, is a strategic decision that affects the cost, complexity and value that the DPP can generate beyond regulatory compliance.

Decision 2 – Identifiers

The DPP must have four mandatory unique identifiers: the product identifier, operator identifier, identifier of the facility where the product is manufactured and DPP registration identifier in the Central Registry. The CWA identifies examples of commonly used identifiers: the Manufacturer Part Number (MPN), the manufacturer’s internal identifier, which is useful for internal use but has limited interoperability; the GS1 Global Trade Item Number (GTIN), used in retail, fashion, food and logistics; and Universally Unique Identifiers (UUIDs).

The identifier standard for the European DPP system is being developed by Working Group 2 of CEN/CENELEC JTC24, with delivery expected in March 2026. The DPP designer must ensure that the selected identifiers comply with that standard once it becomes available.

Decisions about the physical carrier and labelling

Decision 3 – Data carrier

The DPP must be accessible through a physical data carrier on the product: a QR code, two-dimensional barcode, RFID or another medium. The data carrier must appear on the product itself, its packaging or the accompanying documentation, depending on what is specified in the delegated act. The choice of carrier has direct implications for the production process, how it is physically incorporated into the product or packaging and the consumer experience.

Decision 4 – Product labelling

How the data carrier will be integrated into the existing physical labelling: whether it will be added to the current label, replace an existing element and how to ensure that it remains visible, legible and durable throughout the product’s expected useful life. In the textile sector, for example, this may involve redesigning the composition label to incorporate the DPP QR code.

Decisions about the information portal and IT architecture

Decision 5 – Access to the DPP information portal

The DPP is not just data: it is an online portal that displays this information to different users with different levels of authorisation. The DPP designer must define how consumers, distributors, repairers and authorities will access the information, which information will be public and which will require authentication.

Decision 6 – Language switching

The ESPR establishes that consumers must be able to access DPP information in all official EU languages. Managing the different language versions of the DPP, both the portal content and any documents it may contain, is an architectural decision with cost and management implications.

Decision 7 – IT architecture: internal or outsourced

This is the decision with the greatest budgetary impact. The ESPR establishes that the DPP data system is decentralised: the data is managed by the economic operator or an externally contracted DPP service provider. There are two options: developing and managing the infrastructure internally or contracting a DPP service provider to manage hosting, access and the mandatory backup. For most SMEs and many medium-sized companies, outsourcing to a certified provider is more efficient. For large manufacturers with complex products and extensive supply chains, an internal or hybrid solution may be appropriate.

Decisions about content and information management

Decision 8 – Calculation and acquisition of DPP information

This is the most complex decision in supply chain terms. The information that the DPP must include, such as material composition, carbon footprint, recycled content and durability parameters, is not usually available in a standard format within manufacturers’ current systems.

The carbon footprint must be calculated using recognised methodologies. Recycled content data must be obtained from material suppliers. Durability parameters require testing data. The CWA warns that, in many cases, information cannot simply be “retrieved” from existing systems: data collection processes must be designed before the DPP becomes mandatory.

Decision 9 – Searching for DPP information

How information is organised within the DPP so that it can be found and compared by different actors: consumers searching by sustainability parameter, authorities verifying compliance and repairers requiring technical specifications.

Decision 10 – Information exchange management

The DPP must be fully interoperable with other DPPs in technical, semantic and organisational terms. This means deciding which data exchange standards will be used and how the company’s DPP will integrate with the systems of other actors in the value chain that will also have DPPs, such as material suppliers and component manufacturers.

Decisions about traceability, longevity and security

Decision 11 – Traceability

Which events in the product life cycle will be recorded in the DPP: whether manufacturing, distribution, repair, refurbishment and end-of-life events will be recorded. This determines whether the DPP is a static document containing information from the time the product is placed on the market or a dynamic record that is updated throughout the product’s life.

Decision 12 – Longevity of data access

The ESPR requires the DPP to remain available for the period specified in the delegated act, even after the insolvency, liquidation or cessation of activity of the responsible economic operator. The DPP designer must decide how this long-term availability will be guaranteed, typically through the mandatory backup held by an independent third party.

Decision 13 – Backup availability

Article 10 of the ESPR establishes the obligation to make a backup copy of the DPP available through an independent third-party DPP service provider from the moment the product is placed on the market. Who manages that backup, how it is technically managed and under what conditions it would take over if the primary system fails are decisions that must be made before the product is first placed on the market.

Decision 14 – DPP security

Article 11 of the ESPR requires the technical design of the DPP to guarantee the authentication, reliability and integrity of the data, with a high level of security and privacy while preventing fraud. The CWA identifies five levels at which security must be addressed: the manufacturer’s DPP management system, the authenticity of the data carrier, access to restricted DPP information, the process for issuing access rights and the security of access to the information portal.

Decision 15 – Trust in DPP information

How to ensure that the information contained in the DPP is authentic, accurate and has not been manipulated. The CWA warns that the accuracy of the information may vary significantly depending on the quality of the manufacturer’s processes and that no mandatory independent verification is currently envisaged under the ESPR, although delegated acts may introduce it. The DPP designer must decide whether to incorporate voluntary third-party verification processes to improve the reliability of the information.

The supply chain: the most underestimated DPP challenge

There is a fundamental difference between the DPP and other product regulatory requirements that many companies have not yet understood: the DPP cannot be created using internal information alone. It requires supply chain data that currently does not flow to the manufacturer in a structured manner.

CWA 18186:2025 describes the case of a complex manufacturer that may receive DPP information from thousands of manufacturing suppliers. For a fashion brand that manufactures in several countries, data on fibre composition, percentages of recycled content, substances used in dyes and the carbon footprint of each production stage is held by suppliers, not the final manufacturer.

To collect this information in a structured manner, companies need to:

First, amend supplier contracts to include obligations to provide data in interoperable formats. Second, define which data formats and standards will be used so that information from different suppliers can be compared and consolidated. Third, build or contract systems that automatically integrate this information into the DPP.

This process, from contract negotiations to technical integration, cannot be completed in weeks. In sectors with complex global supply chains, such as textiles or furniture, building the data flows required by the DPP may take between one and three years. Waiting until the delegated act has been published before starting means assuming that eighteen months will be enough to complete all of this. In most cases, it will not.

Minimum technical infrastructure: what you need before the deadline

Regardless of the sector and the type of DPP required for your product group, there is a minimum technical infrastructure that every company subject to DPP requirements will need to have operational before the delegated act’s date of application:

Registration in the Central DPP Registry

The European Commission’s Central Registry will become operational on 19 July 2026. From that date, unique DPP identifiers can begin to be registered. The connection to the Central Registry and the identifier registration process must be integrated into the DPP system. For the customs clearance of regulated products, the unique registration identifier in this system will be mandatory.

DPP management system

The system that hosts DPP data, manages differentiated access rights, provides the information portal and connects to the Central Registry. It may be internal, outsourced to a DPP service provider or hybrid. Article 11 of the ESPR establishes that the system must be interoperable, open, machine-readable, structured and accessible through a data exchange network without vendor lock-in.

Mandatory backup

An independent third party that holds a copy of the DPP and guarantees its availability even after the insolvency or cessation of activity of the responsible operator. This third party may not use, sell or reuse the data beyond the contracted storage service.

Trust services for authentication

Article 11 of the ESPR requires the technical design of the DPP to guarantee the authentication, reliability and integrity of the data, with a high level of security and privacy. This requires authentication mechanisms for actors who enter or update data in the DPP: manufacturers, importers, repairers and refurbishers. Qualified trust services under the eIDAS framework, such as qualified electronic seals, qualified electronic signatures and qualified electronic time stamps, are the regulatory mechanism established to provide these guarantees of authenticity and integrity.

Data carrier on the product

The QR code or other data carrier must be integrated into the production or labelling process before the product goes on sale. If this requires changes to the production line, packaging design or labelling process, those changes will require implementation time.

Preparation timeline: what to do and when

Not all actions have the same time horizon. This indicative sequence can serve as a starting point for building your company’s DPP preparation plan.

Now (2026):

  • Identify the product group and the estimated date of its delegated act according to the ESPR Working Plan 2025-2030.
  • Appoint the DPP designer or responsible team.
  • Review the JRC preparatory studies that will inform the delegated act for your sector, which are public and provide guidance on the likely content of the DPP.
  • Assess which supply chain data will be required and whether current suppliers can provide it in a structured format.
  • Decide whether the DPP will be managed internally or by an external provider.

6-12 months before the delegated act:

  • Negotiate DPP data delivery requirements with material and component suppliers.
  • Select and integrate the DPP management system.
  • Design the physical data carrier and integrate it into the production or labelling process.
  • Contract the mandatory backup service with an independent third party.
  • Configure the authentication infrastructure for actors who will enter data into the DPP.

When the delegated act is published:

  • Review the mandatory DPP content under the specific delegated act and adapt the system.
  • Register the first identifiers in the Commission’s Central Registry, if it is already operational.
  • Complete the integration of the data carrier into products from the first regulated series.

18 months after the delegated act (date of application):

  • The DPP must be operational for all models in the product group placed on the market from that date.

The special case of companies already registered in EPREL

Manufacturers and importers that already have models registered in EPREL with active supplier verification have a more favourable starting point for the DPP. EPREL has already introduced them to the logic of European digital registries, the use of unique model identifiers, the management of structured technical documentation and authentication through qualified trust services.

When the ESPR delegated acts arrive for product groups subject to energy labelling, the Commission will most likely exempt those products from an additional DPP, as EPREL already acts as an equivalent system. However, that exemption is not automatic: the Commission must expressly declare it in the corresponding delegated act. Even if it does so, the ESPR’s additional ecodesign requirements, such as durability, recycled content and carbon footprint, may require information that EPREL does not currently collect.

In any case, companies already operating in EPREL with a qualified NTR seal have resolved the most critical link: the authentication and digital identity infrastructure required by the DPP is the same. The next step is to extend it across the product’s entire life cycle.

Frequently Asked Questions About How to Prepare Your Company for the DPP

Where should I start if I do not know when the DPP will apply to my sector?

Start with the ESPR Working Plan 2025-2030 and the article for the relevant sector in this content cluster. Once the estimated date of the delegated act has been identified, the subsequent eighteen-month period determines the DPP’s date of application. From there, work backwards to calculate how much time your company needs to implement the systems and negotiate data flows with suppliers.

Can an SME completely outsource the DPP to an external provider?

Yes. The ESPR allows the DPP to be managed by an external DPP service provider, including hosting, access management and the mandatory backup. For most SMEs, outsourcing is the most efficient option. What cannot be outsourced is responsibility for ensuring that the data is accurate, complete and up to date: that responsibility always remains with the economic operator placing the product on the market.

Can DPP data include consumers’ personal information?

Not without explicit consent. Article 10 of the ESPR establishes that personal data relating to customers may not be stored in the DPP without their explicit consent under the General Data Protection Regulation.

What happens if the DPP contains incorrect information?

Article 9 of the ESPR establishes that the data contained in the DPP must be accurate, complete and up to date. If market surveillance authorities detect incorrect information, they may take action against the responsible economic operator. Trust in the DPP system, and its usefulness for consumers and repairers, depends directly on the accuracy of the data.

Does the DPP replace the user manual or other product instructions?

Not necessarily, but it may include them. Annex III of the ESPR establishes that the DPP may include user manuals, instructions, warnings and safety information. Where necessary, the DPP must be supplemented by non-digital means of providing information, such as physical labels, to ensure that all users can access the information.

The DPP is not a future problem: it is a decision that must be made today

Companies that start working on the DPP now, before the delegated act for their sector is published, have an advantage in three areas: they can negotiate data flows with suppliers without deadline pressure, assess and select DPP service providers without urgency and design their IT architecture carefully without improvisation.

Those that wait until the delegated act is published before starting will have eighteen months to do all of this. In most sectors, that is not enough.

EADTrust is a qualified trust service provider included in the EU Trusted List. The same certificates currently used for verification in EPREL form the basis of the authentication infrastructure that the DPP will require: qualified electronic seals to authenticate who enters data, qualified electronic time stamps for event traceability and qualified electronic archiving services to ensure the long-term availability required by the Regulation.

Fecha de publicación:

Última actualización:

24 de August de 2026

26 de August de 2026