The EU Data Act and data portability: what it means for Digital Product Passports

A Digital Product Passport only delivers on its promise if its data can move — between owners, partners, platforms and borders. That is where the EU Data Act comes in. This guide explains what the Data Act is, how it reinforces data portability, and why it makes openness a design requirement for any DPP, not an afterthought.

What is the EU Data Act?

The Data Act (Regulation (EU) 2023/2854) entered into force in January 2024 and applies from 12 September 2025. It sets rules on who can access and use data generated by connected products and related services, strengthens the right to port data between providers, and constrains vendor lock-in — including easier switching between cloud and edge services and stronger interoperability requirements.

Why portability is the whole point of a DPP

A passport that can only be read inside the system that created it is not a passport — it is a silo with a QR code. The Data Act pushes in the opposite direction: data should follow the user and the product, in structured, commonly used, machine-readable formats. For a DPP this means the passport must be exportable and independently readable, not locked behind one vendor’s API.

What the research says about DPP data

The academic literature is converging on the same conclusion. In a widely cited study, Jensen and colleagues (2023) map the data needs for product life-cycle decision-making and show that the value of a DPP depends on which data are captured and how accessible they are across the chain. Jansen and colleagues (2023) go further, identifying concrete requirements for DPP systems — interoperability and data sovereignty chief among them. And King and colleagues (2023) argue that a DPP is best understood not as a file but as an ecosystem of stakeholders with distinct data rights and concerns. All three point the same way: portability and open standards are not optional features; they are the foundation.

How to build a Data-Act-ready passport

  1. Use open, standard formats — GS1 identifiers for identity and GS1 EPCIS 2.0 for lifecycle events.
  2. Make the full passport exportable as a self-describing file (data plus schema), not just viewable in a dashboard.
  3. Separate the data from the tool: any authorised actor should be able to read the passport without your platform in the loop.
  4. Design for switching — assume the customer may move providers, and make sure their data moves with them.

The Data Act and the ESPR work together

The ESPR mandates that products carry a DPP; the Data Act makes sure the data inside it stays open and portable. Read together, they close the loophole that would let “compliance” become a new form of lock-in. A distribution layer built on open standards satisfies both at once.

Frequently asked questions

Does the Data Act apply to my product data?

If your product is connected or generates data through a related service, the Data Act’s access and portability rules are likely relevant. It has applied since September 2025.

Is the Data Act the same as GDPR?

No. GDPR governs personal data; the Data Act governs access to and portability of data generated by connected products and services, much of which is non-personal. They can overlap but address different problems.

What does portability mean in practice for a DPP?

That the passport can be exported in a structured, standard format and read by another system or actor without your platform — the practical test of an open implementation.

Passports that move, not silos that trap

GovGDS distributes portable, standards-based passports designed for openness from day one.

Request a demo →

References

  • Jensen, S. F., Kristensen, J. H., Adamsen, S., Christensen, A., & Waehrens, B. V. (2023). Digital product passports for a circular economy: Data needs for product life cycle decision-making. Sustainable Production and Consumption, 37, 242–255. https://doi.org/10.1016/j.spc.2023.02.021
  • Jansen, M., Meisen, T., Plociennik, C., Berg, H., Pomp, A., & Windholz, W. (2023). Stop Guessing in the Dark: Identified Requirements for Digital Product Passport Systems. Systems, 11(3), 123. https://doi.org/10.3390/systems11030123
  • King, M. R. N., Timms, P. D., & Mountney, S. (2023). A proposed universal definition of a Digital Product Passport Ecosystem (DPPE). Journal of Cleaner Production, 384, 135538. https://doi.org/10.1016/j.jclepro.2022.135538

Related reading: What is a Digital Product Passport? · GS1 EPCIS 2.0 explained · ESPR explained

The Data Act article by article

Closer explainers of the Data Act articles most relevant to product data and the Digital Product Passport:

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *