The Digital Product Passport is often discussed as if every product will soon carry the same QR code and disclose the same information. That is not how industrial procurement should plan for it.
The useful question is not “does the supplier have a DPP?” but which product-specific rule may apply, which data elements will be required, who owns them and can they be connected to the exact product placed on the EU market?
What is confirmed and what is still product-specific
The European Commission describes the Digital Product Passport as a digital identity card for products, components and materials that stores relevant information to support sustainability and circularity. It is established under the Ecodesign for Sustainable Products Regulation. European Commission — Digital Product Passport
The Commission's DPP FAQs stress that inclusion in an ESPR working plan does not itself mean a product already has a mandatory passport. Requirements are developed through product-specific delegated acts. European Commission — DPP FAQs
This distinction protects buyers from two errors: waiting until every detail is final before improving data, or purchasing a generic commercial “DPP solution” that may not match the eventual legal requirements for the product.
On 20 July 2026, the Commission announced that the central Digital Product Passport Registry had gone live and explained that it will store unique registration identifiers for product passports, operators and facilities. European Commission — DPP Registry now live Registry availability does not make every product passport mandatory; applicability still depends on the relevant legislation.
Build a product-data foundation first
Supplier information is often split across drawings, ERP descriptions, certificates, spreadsheets and email. DPP readiness begins by making core identities consistent:
- product model, part number and revision;
- manufacturer, operator and facility identities;
- country and location of manufacture where required;
- material and component identities;
- applicable EU legislation and conformity records;
- substances or composition data at the required level;
- sustainability, repair, durability or end-of-life information where applicable;
- evidence source, owner, date and validity;
- unique identifier and link to the marketed product; and
- change history and superseded data.
Not all these fields will apply to every product. They form a readiness inventory, not a claim about final mandatory content.
Separate master data from evidence
A spreadsheet value such as “recycled content: 30%” is not self-supporting. Buyers should record where the value came from, what period and product it covers, how it was calculated, and whether third-party verification is required. The same applies to material composition, carbon footprint, repair instructions and compliance status.
Create three layers:
- Identity: which product, operator, facility, batch or model the information describes.
- Claim: the value or statement intended for the passport.
- Evidence: source record, method, responsible party, validity and review status.
This structure allows the company to replace an expired certificate or corrected calculation without losing the identity of the product to which it applied.
Clarify roles across the supply chain
The EU economic operator responsible for placing a product on the market may need information from a manufacturer, component supplier, material producer or testing body. No single Chinese supplier necessarily owns the whole dataset.
For each proposed field, ask:
- Who creates the data?
- Who can verify it?
- Who is authorised to publish it?
- Is it product-, model-, batch- or facility-specific?
- How often can it change?
- What confidentiality or access restriction applies?
- Who corrects the record if an error is found?
Contracts may need data-delivery, update and retention clauses, but these should be aligned with the eventual delegated act and legal responsibility. Avoid asking suppliers to warrant unknown future rules.
Do not confuse a QR code with a passport system
A QR code is an access mechanism. It does not ensure that the underlying identifier is unique, the data is current, access rights work or records survive a platform change. Technology procurement should follow the information model and legal requirements, not lead them.
Buyers should also plan for different access levels. Some data may be public, some available to regulators or customs, and some restricted to authorised actors. Publishing sensitive supplier names or technical information without a legal basis can create confidentiality and security problems.
Interoperability matters. The Commission is developing standards and a registry architecture; companies should monitor official developments instead of designing an isolated format that cannot exchange data later.
Use current sourcing projects to improve readiness
Even before a product-specific passport becomes mandatory, buyers can improve data discipline by requiring:
- controlled product and facility identifiers;
- machine-readable document indexes;
- certificate-to-product traceability;
- explicit source and calculation fields for sustainability claims;
- expiry and review dates;
- supplier-change notification; and
- a secure record-retention location.
These controls also support ordinary quality, customs and compliance work. The investment is therefore not only for DPP.
Procurement readiness checklist
- Has legal/compliance identified which product groups may receive delegated acts?
- Are part, model and revision identifiers consistent across systems?
- Are manufacturer, facility and EU operator roles distinguished?
- Can material and component data connect to the marketed product?
- Does every important claim have a source, method, date and owner?
- Are certificate validity and supersession controlled?
- Can supplier and facility changes trigger data review?
- Are public and restricted data separated?
- Is the company avoiding unsupported DPP or sustainability claims?
- Are technology choices deferred until information and legal needs are understood?
- Is there a process to monitor Commission delegated acts and standards?
What this means for procurement
DPP readiness is primarily a data-governance and traceability task. Buyers should neither wait passively nor pretend the final template is already known. The sound approach is to strengthen the evidence chain now, then map it to product-specific requirements as they are adopted.
Morning Sunlight Asia can help organise China-side supplier, facility, product and certificate information requested by the client's DPP workstream. Discuss Your Requirement to build the operational data map; applicability and legal content should be confirmed by the responsible EU operator and advisers.
已確認與仍待產品規則決定的內容
歐盟委員會把 DPP 描述為產品、零組件和材料的數位身份卡,用於保存與永續及循環相關資訊,框架建立於 ESPR。European Commission — DPP
委員會 FAQ 強調,產品被列入 ESPR 工作計畫,不等於已經自動強制使用護照;具體要求透過產品專屬 delegated acts 制定。European Commission — DPP FAQs
2026 年 7 月 20 日,委員會宣布中央 DPP Registry 上線,將保存產品護照、營運者和設施的唯一登記識別碼。European Commission — DPP Registry 登記系統上線不代表所有產品立即強制適用。
先建立產品資料底座
可先整理產品型號、零件號與版本;製造商、營運者和設施身份;材料與零組件;適用法規和符合性文件;可能需要的成分、維修、耐用、回收及永續資料;每項證據的來源、責任人、日期和有效期;唯一識別碼及變更歷史。
這是準備清單,不代表所有字段對每種產品都會強制。
把身份、聲明和證據分開
試算表中的「30% 再生含量」不能自我證明。要說明它涵蓋哪個產品與期間、如何計算、來源是什麼,以及是否需要第三方驗證。
建議分三層管理:第一層是產品、設施、批次或型號身份;第二層是準備發布的數值或聲明;第三層是來源記錄、方法、責任人、有效期與審查狀態。這樣即使證書到期或計算更正,也不會失去與原產品的連接。
釐清供應鏈角色
負責將產品投放歐盟市場的營運者,可能需要從製造商、零件商、材料商或實驗室取得資料。單一中國供應商未必擁有完整資料。每個字段都應問:誰產生、誰驗證、誰有權發布、適用於產品還是批次、多久變更一次、誰負責修正,以及哪些資料需要限制存取。
QR code 只是入口,不保證識別唯一、資料最新、權限正確或平台更換後記錄仍可用。技術平台應在資訊模型和法律要求清楚後再選擇。
準備清單
- 法務是否識別可能受產品專屬規則影響的產品組?
- 零件、型號和版本身份是否一致?
- 製造商、設施和歐盟營運者角色是否區分?
- 材料與零組件資料能否連到市場產品?
- 每項重要聲明是否有來源、方法、日期與責任人?
- 證書有效期和替代是否受控?
- 供應商或設施變更是否觸發重審?
- 公開與受限資料是否分開?
- 是否避免無證據的 DPP 或永續聲明?
- 是否持續監測委員會 delegated acts 和標準?
先做字段盤點,不急於採購平台
企業可以先用受控表格盤點現有資料:字段名稱、產品粒度、來源系統、供應方、更新頻率、證據、保密等級和缺口。當產品專屬 delegated act 發布後,再把確定的強制字段映射進來。這比先購買一套宣稱「全套 DPP」的平台更容易避免返工。
盤點還應區分固定主資料與批次資料。製造商法人名稱可能相對穩定,材料來源、再生含量、碳數據或合規證書則可能按設施、批次或期間變化。若全部被存成一個產品層的永久值,後續護照容易顯示過期或錯配資訊。
對採購決策的意義
DPP 準備首先是資料治理和追溯工作。採購方既不應消極等待,也不能假裝最終模板已全部確定。合理做法是先加強證據鏈,再隨產品專屬要求落地進行映射。
晨陽亞洲可依客戶 DPP 工作需要,協助整理中國境內供應商、設施、產品和證書資訊。歡迎 Discuss Your Requirement 建立操作資料圖;適用性與法律內容應由歐盟責任營運者及顧問確認。