SealTrustSealTrustSealTrust
Home
How it worksVerifyDemo
Sign inSign up
SealTrust
HomeHow it worksVerifyDemo

Product

Digital Product PassportFeaturesPricingSolutionsRegulation radarUse casesIntegrations

Company

AboutCareersPressContact

Resources

BlogDocumentationAPI DocsDevelopersSecurityTrust CenterAll resources
Sign inCreate an account

© 2026 SealTrust

SealTrust

Product authentication through NFC and blockchain. Protect your brand against counterfeiting.

Product

  • How it works
  • Features
  • Pricing
  • Solutions
  • Regulation radar
  • Use cases
  • Integrations
  • Documentation

Company

  • About
  • Contact
  • Careers
  • Press

Legal

  • Terms of Use
  • Terms of Sale
  • Privacy Policy
  • Legal notices
  • GDPR
  • Cookie Policy
  • Return & warranty

Resources

  • All resources
  • Technical documentation
  • Blog
  • Digital Product Passport
  • DPP 2027 Guide
  • Developers
  • Verification badge
  • Security
  • Trust Center
  • API Docs
  • Help
  • Support

EN 18219 · EN 18220 · ESPR-ready · GDPR

© 2026 SealTrust. All rights reserved.

Follow us on LinkedInMade with trust in France
← Digital Product Passport: full guide

EU Digital Product Passport Requirements: What a DPP Must Contain

What information must a DPP contain?

The exact data set is fixed by the delegated act for each product group, but the ESPR defines the categories of information a Digital Product Passport is expected to carry. In practice, a DPP brings together:

  • Product identity: a unique product identifier, model, batch or item reference, and the identity of the responsible economic operator;
  • Materials and composition: the materials used and their proportions;
  • Origin and supply chain: provenance and, where required, traceability along the value chain;
  • Durability and repairability: expected lifespan, spare-part availability and repair information;
  • Substances of concern: the presence and location of hazardous substances above defined thresholds;
  • Recyclability and end-of-life: recycled content, and instructions for reuse, recycling or safe disposal.

The data carrier: QR code, NFC and RFID

The passport data is not printed on the product. It is reached through a data carrier physically attached to the item, its packaging or its documentation. The ESPR allows carriers such as:

  • QR codes and data-matrix codes;
  • NFC tags;
  • RFID tags.

The carrier holds a link to the passport rather than the full data set, so the information can be kept up to date without reprinting labels. Because the carrier is the entry point to every product, it is also the natural place to add anti-counterfeiting protection: this is where a secure NFC chip such as the NTAG 424 DNA used by SealTrust proves that each scan is genuine and not a copied code.

Access: the actors the ESPR names

Not every field is meant for everyone, but the ESPR sets no access levels of its own. It names the actors who must be able to reach the passport, among them customers, professional repairers, refurbishers, recyclers, market-surveillance authorities and customs authorities (Article 11(b)), and that list stays open. It leaves it to each product group's delegated act to say which field goes to which audience.

No such delegated act is published yet, so the ESPR fixes no field-by-field split today. One split is already written elsewhere: Annex XIII of the Batteries Regulation (EU) 2023/1542 states which battery fields are public and which are reserved to holders of a legitimate interest, and it applies from 18 February 2027.

Until the delegated acts arrive, what a provider can offer is a split that stays reconfigurable field by field, within what the Batteries Regulation already reserves, rather than a compliance matrix that does not yet exist.

Who is responsible for the passport

Responsibility falls on the economic operator that places the product on the EU market:

  • the manufacturer where it is established in the EU;
  • the importer or authorised representative where the manufacturer is outside the EU.

That operator must ensure the passport exists, is accurate, stays available for the required period, and remains accessible even if the company itself ceases trading.

Interoperability and open standards

A DPP is only useful if any authorised party can read it. The ESPR therefore requires passports to be interoperable and built on open standards, with data that is machine-readable and structured. In practice this points to:

  • GS1 standards, including GS1 Digital Link, to identify products and resolve the carrier to the passport;
  • JSON-LD and linked-data models to express passport data in a shared, machine-readable vocabulary.

These choices let a single passport be read by retailers, customs, recyclers and consumers without bespoke integrations.

To see how these requirements come together in a working system, read our main guide to the Digital Product Passport.

See how SealTrust delivers the Digital Product Passport and anti-counterfeiting from a single verifiable identity.

Book a DPP demo→