The Digital Product Passport is often discussed as if every product will soon carry the same QR code and disclose the same information. That is not how industrial procurement should plan for it.
The useful question is not “does the supplier have a DPP?” but which product-specific rule may apply, which data elements will be required, who owns them and can they be connected to the exact product placed on the EU market?
What is confirmed and what is still product-specific
The European Commission describes the Digital Product Passport as a digital identity card for products, components and materials that stores relevant information to support sustainability and circularity. It is established under the Ecodesign for Sustainable Products Regulation. European Commission — Digital Product Passport
The Commission's DPP FAQs stress that inclusion in an ESPR working plan does not itself mean a product already has a mandatory passport. Requirements are developed through product-specific delegated acts. European Commission — DPP FAQs
This distinction protects buyers from two errors: waiting until every detail is final before improving data, or purchasing a generic commercial “DPP solution” that may not match the eventual legal requirements for the product.
On 20 July 2026, the Commission announced that the central Digital Product Passport Registry had gone live and explained that it will store unique registration identifiers for product passports, operators and facilities. European Commission — DPP Registry now live Registry availability does not make every product passport mandatory; applicability still depends on the relevant legislation.
Build a product-data foundation first
Supplier information is often split across drawings, ERP descriptions, certificates, spreadsheets and email. DPP readiness begins by making core identities consistent:
- product model, part number and revision;
- manufacturer, operator and facility identities;
- country and location of manufacture where required;
- material and component identities;
- applicable EU legislation and conformity records;
- substances or composition data at the required level;
- sustainability, repair, durability or end-of-life information where applicable;
- evidence source, owner, date and validity;
- unique identifier and link to the marketed product; and
- change history and superseded data.
Not all these fields will apply to every product. They form a readiness inventory, not a claim about final mandatory content.
Separate master data from evidence
A spreadsheet value such as “recycled content: 30%” is not self-supporting. Buyers should record where the value came from, what period and product it covers, how it was calculated, and whether third-party verification is required. The same applies to material composition, carbon footprint, repair instructions and compliance status.
Create three layers:
- Identity: which product, operator, facility, batch or model the information describes.
- Claim: the value or statement intended for the passport.
- Evidence: source record, method, responsible party, validity and review status.
This structure allows the company to replace an expired certificate or corrected calculation without losing the identity of the product to which it applied.
Clarify roles across the supply chain
The EU economic operator responsible for placing a product on the market may need information from a manufacturer, component supplier, material producer or testing body. No single Chinese supplier necessarily owns the whole dataset.
For each proposed field, ask:
- Who creates the data?
- Who can verify it?
- Who is authorised to publish it?
- Is it product-, model-, batch- or facility-specific?
- How often can it change?
- What confidentiality or access restriction applies?
- Who corrects the record if an error is found?
Contracts may need data-delivery, update and retention clauses, but these should be aligned with the eventual delegated act and legal responsibility. Avoid asking suppliers to warrant unknown future rules.
Do not confuse a QR code with a passport system
A QR code is an access mechanism. It does not ensure that the underlying identifier is unique, the data is current, access rights work or records survive a platform change. Technology procurement should follow the information model and legal requirements, not lead them.
Buyers should also plan for different access levels. Some data may be public, some available to regulators or customs, and some restricted to authorised actors. Publishing sensitive supplier names or technical information without a legal basis can create confidentiality and security problems.
Interoperability matters. The Commission is developing standards and a registry architecture; companies should monitor official developments instead of designing an isolated format that cannot exchange data later.
Use current sourcing projects to improve readiness
Even before a product-specific passport becomes mandatory, buyers can improve data discipline by requiring:
- controlled product and facility identifiers;
- machine-readable document indexes;
- certificate-to-product traceability;
- explicit source and calculation fields for sustainability claims;
- expiry and review dates;
- supplier-change notification; and
- a secure record-retention location.
These controls also support ordinary quality, customs and compliance work. The investment is therefore not only for DPP.
Procurement readiness checklist
- Has legal/compliance identified which product groups may receive delegated acts?
- Are part, model and revision identifiers consistent across systems?
- Are manufacturer, facility and EU operator roles distinguished?
- Can material and component data connect to the marketed product?
- Does every important claim have a source, method, date and owner?
- Are certificate validity and supersession controlled?
- Can supplier and facility changes trigger data review?
- Are public and restricted data separated?
- Is the company avoiding unsupported DPP or sustainability claims?
- Are technology choices deferred until information and legal needs are understood?
- Is there a process to monitor Commission delegated acts and standards?
What this means for procurement
DPP readiness is primarily a data-governance and traceability task. Buyers should neither wait passively nor pretend the final template is already known. The sound approach is to strengthen the evidence chain now, then map it to product-specific requirements as they are adopted.
Morning Sunlight Asia can help organise China-side supplier, facility, product and certificate information requested by the client's DPP workstream. Submit Your Requirements to build the operational data map; applicability and legal content should be confirmed by the responsible EU operator and advisers.