ESPR Article 11 explained: technical design and operation of the DPP
ESPR Article 11: Technical Design and Operation of the Digital Product Passport
Article 11 of the ESPR sets out the technical framework that makes Digital Product Passports work in practice. It’s not just about what information goes on a passport—it’s about how that information is stored, protected, shared, and kept available over time. For any company placing products on the EU market, this article translates compliance obligations into real technical and operational requirements.
What Article 11 Requires: The Core Framework
At its heart, Article 11 creates four interconnected requirements. First, your passport system must be technically interoperable—meaning it has to work with other product passport systems, regardless of what sector you’re in or what communication method you use. Second, the people who need access to passport data must get it free of charge, though what they can see depends on their role. Third, you must store and maintain that data securely for as long as the regulation specifies, even if your company closes down or becomes insolvent. Fourth, anyone handling the data—especially service providers—must follow strict rules about what they can and cannot do with it.
This isn’t a one-time setup. The passport must remain functional and accessible throughout the entire lifecycle of the product, from manufacturing through to end-of-life management and recycling. That’s a significant operational commitment.
Interoperability: Making Passports Talk to Each Other
Interoperability means your passport system should not be locked into a single technology, data format, or communication channel. Whether your industry uses GS1 standards, EPCIS 2.0, QR codes, or other identification methods, the underlying passport data must be retrievable and understandable by other systems. This matters because supply chain stakeholders—importers, distributors, recyclers, and authorities—need to access information across different manufacturer platforms without technical friction.
In practice, this means adopting common data standards and ensuring your system can exchange information with other passport platforms. It’s about creating a connected ecosystem rather than isolated silos.
Free Access for Authorized Users—Role-Based Permissions
Article 11 requires that customers, manufacturers, importers, distributors, recyclers, waste authorities, and enforcement agencies can access passport information at no charge. However, “access” doesn’t mean everyone sees everything. The regulation contemplates role-based access controls, meaning each user type has specific permissions tied to their function in the product lifecycle.
A customer might see sustainability claims and care instructions. A recycler needs to know material composition and hazardous substance information. An enforcement authority might need full visibility. A competitor should not have access to proprietary manufacturing data. Your system must implement these distinctions technically, granting or restricting view rights automatically based on who is requesting the information.
Secure Storage and Data Longevity
You (or a service provider acting on your behalf) must store passport data securely and maintain it for the duration specified in future delegated acts—which will set time periods by product category. This isn’t a short-term obligation. In many cases, data will need to remain accessible for years after a product is sold or even after it reaches end-of-life, to support recycling, warranty claims, or regulatory investigations.
A critical point: if your company goes out of business, ceases operations, or becomes insolvent, the data doesn’t disappear. The regulation requires that responsibility for maintaining the passport transfers—either to a service provider you’ve designated, to another party, or through some form of backup or archival mechanism. Planning for business continuity is therefore part of your compliance responsibility.
Service Providers and Data Restrictions
Many companies will outsource passport storage and management to third-party service providers. Article 11 imposes strict limits on what those providers can do with the data. They are permitted to store it, process it as necessary for technical operations, and support access management. They are not permitted to sell the data, reuse it for their own purposes, or process it for any reason beyond what’s needed for the storage and access service itself.
This means your contracts with service providers must be carefully drafted to enforce these restrictions. The service provider is not allowed to monetize passenger data or build competing products from it. You remain responsible for ensuring compliance, even when you delegate the technical operation.
Security, Privacy, and Fraud Prevention
Article 11 mandates “high standards” of security and privacy, though the specific technical measures will likely be detailed in implementing acts or standards. At minimum, your system must:
- Prevent unauthorized access and modification of passport data
- Detect and prevent fraud (such as counterfeit or altered passports)
- Ensure data authentication—so users can verify that information came from the manufacturer and hasn’t been tampered with
- Maintain data reliability and integrity throughout the product’s lifecycle
- Protect personal data in accordance with GDPR and other privacy rules
These are not optional refinements. They are baseline technical requirements. Depending on your product category and the sensitivity of the data, you may need encryption, digital signatures, tamper-evident mechanisms, or access logging.
What This Means for Your Business
Article 11 forces companies to think of the Digital Product Passport as a long-term infrastructure investment, not a compliance checkbox. You need to:
- Evaluate or build technical systems that meet interoperability standards before your products reach the EU market
- Plan for data retention and access throughout the product lifecycle, including after product discontinuation
- Implement role-based access controls that balance transparency with confidentiality
- Establish contracts with any service providers that enforce data use restrictions
- Design security and fraud prevention measures into your passport system from the start
- Plan for business continuity—what happens to passport data if your company changes hands or exits the market
Companies that treat Article 11 as a technical afterthought risk non-compliance. Those that integrate it into their product information management and supply chain systems early will find it becomes a competitive advantage: customers and recyclers trust that the data is authentic and accessible, and regulators can verify compliance with ease.
Frequently Asked Questions
Do I have to build my own passport system, or can I use a third-party platform?
You can use a third-party service provider to store and manage passport data, but you remain responsible for compliance with Article 11. The provider must meet all the security, interoperability, and data-protection requirements. You should have clear contracts that spell out data restrictions and define what happens if the provider goes out of business or you switch providers. The data belongs to you; the provider is merely a custodian.
What if I don’t know which specific data to keep or for how long?
The regulation will be accompanied by delegated acts that specify data retention periods by product category. For now, plan to retain passport data for the full useful life of the product, plus any period during which it might be repaired, refurbished, or recycled. When the delegated acts are published, you’ll need to align your storage policies to match. It’s safer to start with a longer retention period and adjust downward if the rules allow, rather than delete data prematurely.
Can my service provider use passport data to improve their own services or sell insights?
No. Article 11 explicitly restricts service providers to processing data only as necessary for storage, access, and technical operations. Any other use—including analytics, product improvement, or sales of insights—is prohibited. Your contract must enforce this, and you should have audit rights to verify compliance. If a provider violates this, you could face liability for non-compliance with the ESPR.
Official text (ESPR Article 11): “the digital product passport shall be fully interoperable with other digital product passports required by delegated acts” — Regulation (EU) 2024/1781, EUR-Lex
Get ESPR-ready on open standards
GovGDS issues, resolves and distributes DPPs that meet the ESPR requirements.
Related: ESPR explained · What is a Digital Product Passport?
