ESPR Article 10 explained: essential requirements for the DPP
ESPR Article 10: Technical Requirements for Digital Product Passports
The ESPR establishes mandatory rules for how companies must create and manage Digital Product Passports. Article 10 is the core technical provision—it sets out the practical requirements for how these passports must be designed, built, and made accessible throughout the product’s lifecycle. Understanding these rules is essential for any manufacturer or distributor placing products on the EU market.
The Physical Data Carrier: Connecting the Real Product to Digital Information
At the heart of Article 10 is a simple but strict requirement: every Digital Product Passport must be connected to its physical product through a data carrier. This is not optional. The data carrier—typically a QR code, barcode, NFC tag, or similar machine-readable identifier—must be placed directly on the product itself, its packaging, or accompanying documentation such as an instruction manual or warranty card.
This physical connection serves a critical purpose. It allows consumers, retailers, regulators, and recyclers to instantly access the digital passport by scanning the product with a smartphone or scanner. Without this physical bridge, the Digital Product Passport would be disconnected from the actual goods, making it impossible for end-users to retrieve relevant information at the point of purchase or disposal.
The placement and format of the data carrier is not left entirely to chance. The regulation directs manufacturers to comply with specific standards listed in Annex III of the ESPR, or equivalent standards recognised under European or international frameworks. This ensures consistency and prevents fragmentation—retailers and consumers will know how to interact with the passport, regardless of which manufacturer created it or which product category it covers.
Open Standards: No Locked-In Data, No Vendor Dependencies
Article 10 prohibits companies from using proprietary, closed technical systems to store or encode their Digital Product Passport data. All information must be structured using open, interoperable standards that are machine-readable, searchable, and transferable between systems without vendor lock-in.
This principle protects the entire ecosystem. If a company were permitted to encode passport data in a format only their own software could read, that data would be trapped. Competitors could not access it. Regulators could not inspect it. Recyclers could not use it. Open standards—such as structured data formats aligned with frameworks like EPCIS 2.0 for supply chain data or standard JSON schemas—ensure that any authorised party can read, analyse, and act on the information without needing special software licenses or dependency on the original manufacturer.
This requirement also aligns with broader EU digital policy. The ESPR recognises that true interoperability benefits businesses and consumers alike. Manufacturers who adopt open standards can integrate their passport systems with third-party tools, retail networks, and compliance platforms more easily. Conversely, distributors and retailers can aggregate passport data from multiple suppliers into unified compliance or inventory systems.
Data Structure and Searchability Requirements
Beyond simply being “open,” the data within the Digital Product Passport must meet several structural criteria. It must be:
- Machine-readable: Computers and automated systems must be able to parse and understand the data without human intervention.
- Structured: Information must be organised in a consistent, logical format—not free-text or unformatted documents.
- Searchable: Users and systems must be able to find specific data points quickly, such as material composition, repairability scores, or carbon footprint data.
- Transferable: Data must be exportable and usable in other systems, platforms, and tools without degradation or loss of meaning.
These technical requirements ensure that the Digital Product Passport is not just a static webpage or PDF document. It is a structured, queryable dataset that can power compliance checks, supply chain transparency, circular economy initiatives, and consumer decision-making at scale.
Personal Data and GDPR Compliance: A Critical Boundary
Article 10 includes an important safeguard: personal customer data is prohibited from being stored in the Digital Product Passport unless the individual has given explicit, informed consent under GDPR rules.
This means that information such as purchase history, customer names, email addresses, or product usage logs must not be embedded in a passport that might be accessed by multiple parties. The passport is intended as a product-level information resource for transparency and compliance—not a customer profiling tool. If a company wishes to attach customer-specific data (for example, warranty registration details tied to a purchase), it must obtain clear consent and manage that data separately under strict GDPR safeguards.
Rapid Digital Access: Five Working Days for Dealers and Marketplaces
Retailers and online marketplaces are critical nodes in the distribution chain. Article 10 requires operators—typically manufacturers or authorised representatives—to provide digital copies of the Digital Product Passport to dealers and online marketplaces within five working days of a request. This ensures that retailers can fulfil their own obligations to display passport information and that customers can access it through online shopping platforms without delay.
Five working days is a tight timeline. Companies should establish automated or streamlined processes to fulfil these requests, perhaps through an API or a dedicated portal, rather than handling each request manually.
Backup and Redundancy Through Accredited Service Providers
Article 10 also mandates that operators maintain a backup copy of the Digital Product Passport through a digital product passport service provider. This backup requirement serves several purposes:
- It prevents loss of critical compliance and product information if the manufacturer’s systems fail.
- It creates a trusted, independent record that regulators can access for verification.
- It ensures continuity if a manufacturer exits the market or ceases operations.
The backup provider is typically an accredited third-party operator, certified to manage passport data securely and in compliance with the ESPR and other regulations.
Frequently Asked Questions
Does the QR code or physical data carrier have to be visible on the product itself, or can it be hidden on packaging?
The data carrier can be placed on the product, packaging, or accompanying documentation. However, it should be reasonably accessible so that consumers and recyclers can find and scan it. Hiding it where no one would look would defeat the purpose. Best practice is to place it in a visible, durable location on packaging or the product exterior.
What happens if we already use a proprietary system to store our product data?
You will need to migrate to, or integrate with, open standards that comply with Annex III or equivalent European/international standards. This does not mean abandoning your existing system entirely—many companies build an interoperability layer that translates proprietary data into open formats for the Digital Product Passport. Planning this transition early will reduce costs and compliance risk.
Are we liable if someone requests our digital passport data and we deliver it late?
The regulation sets a five working day deadline. Repeated or intentional breaches could expose you to regulatory action and potential penalties under the ESPR. It is prudent to establish automated fulfilment systems and monitor compliance closely.
Official text (ESPR Article 10): “all data included in the digital product passport shall be based on open standards, developed with an interoperable format” — Regulation (EU) 2024/1781, EUR-Lex
Get ESPR-ready on open standards
GovGDS issues, resolves and distributes DPPs that meet the ESPR requirements.
Related: ESPR explained · What is a Digital Product Passport?
