Digital product passport: certified supply chain data under the ESPR

For years the sustainability data attached to your products lived in spreadsheets and supplier PDFs nobody outside the company ever opened. The Ecodesign for Sustainable Products Regulation moves it behind a code printed on the product, readable by a customer, a competitor or a market surveillance authority.

A digital product passport (DPP) is a structured set of product data, held by the economic operator placing the product on the EU market and reachable through a data carrier such as a QR code, covering identity, composition, environmental performance, repairability and end-of-life handling. Regulation (EU) 2024/1781, the Ecodesign for Sustainable Products Regulation, has been in force since 18 July 2024 and makes it the default instrument for regulated product groups, with the specific data points set group by group through delegated acts. The audience is deliberately wide: a consumer scanning the code sees one layer, a repairer or a recycler another, and market surveillance and customs authorities see the full record. Product information that used to travel between a manufacturer and its direct customer now sits in the open, attached to a named operator, for anyone entitled to look at it.

The awkward part is what feeds it. Most of the evidence behind those figures comes from outside your walls: a photo taken on a supplier’s phone, a test report exported from a laboratory system, a declaration signed two tiers upstream. None of it was built to be examined in public.

A digital product passport is only as good as the evidence feeding it. If that evidence cannot be verified, the passport does not create trust, it creates a larger surface for disputes. The answer sits earlier, at the moment the evidence is created.

What the ESPR requires and what data ends up in the passport

The ESPR sets a framework rather than a checklist. It introduces the digital product passport as a general instrument of the ecodesign regime, while the concrete requirements for each category arrive later, through delegated acts adopted product group by product group, along the calendar the Commission set out in its first working plan.

Scope, delegated acts and the European registry

The scope is broad. The regulation covers physical goods placed on the EU market, including components and intermediate products, which is why a supplier of steel coil or battery cells carries passport obligations of its own. What triggers the obligation is the market you sell into, not where your company is registered, so an exporter outside the EU faces the same product passport requirements as a manufacturer inside it.

The ESPR working plan for 2025 to 2030, adopted by the European Commission in April 2025, names the categories that go first and the order in which their delegated acts are expected:

Product group Delegated act expected
Iron and steel 2026
Textiles, starting with apparel 2027
Tyres 2027
Aluminium 2027
Furniture 2028
Mattresses 2029
Electronics and ICT 2029

Read those as planning dates rather than deadlines, because an obligation only bites once the delegated act for that group has been adopted and its transition period has run out. Batteries are the exception, since they fall under their own regulation and already carry a fixed date.

The infrastructure is already live. Commission Implementing Regulation (EU) 2026/1778, adopted on 16 July 2026, sets the operating rules for the European passport registry, which the Commission opened on 20 July 2026. Two details in it are worth pulling out. Every economic operator has to complete an identity verification before registering a passport, and customs authorities get direct access to the registered data. The passport is a filed declaration tied to a verified legal identity and checkable at the border.

What data the digital product passport contains

The passport carries the data that lets someone else assess the product without asking you. The Commission groups it into identity, composition, performance and end-of-life information, while each delegated act fixes the exact data points and decides which of them are public, which are reserved to authorities and which stay visible only to operators along the chain. Nothing on the list is final until the delegated act covering that product group has been adopted, which is why two passports in different categories rarely call for the same fields.

In practice the digital product passport contains:

  • unique product, batch and operator identifiers
  • the economic operator responsible for placing it on the market
  • materials, substances of concern and their origin
  • durability and environmental performance figures
  • repairability information and spare part availability
  • reuse, remanufacturing and recycling instructions
  • compliance documentation and certificates

Most of these fields describe events in a factory you do not own, and each stays an assertion until someone can show what it rests on.

The battery passport as the first real test

The battery passport is the first digital product passport with a binding date attached to it. Under Regulation (EU) 2023/1542, from 18 February 2027 electric vehicle batteries, light means of transport batteries and industrial batteries above 2 kWh placed on the EU market must carry a digital passport accessible through a QR code, and without a registered passport the product cannot legally be sold in the EU. That turns a reporting exercise into a condition for market access, and it lands on data that is hard to source: the share of recycled cobalt in a cell, the carbon footprint of its manufacturing, the plant where the active material was produced. Almost none of it originates with the company whose name goes on the passport. It comes from cell makers, refiners and mining operations several tiers upstream, and each of them keeps its own records and owes an explanation to nobody beyond its direct customer.

Why supply chain evidence does not hold up today

The ESPR requires you to publish data. It does not require anyone to prove it, and that gap is where the trouble accumulates. The problem is well measured: a 2020 European Commission study of 150 environmental claims found that 53.3% were vague, misleading or unfounded, and 40% were entirely unsubstantiated. Those claims were made by companies that mostly believed them. The data existed somewhere upstream, someone had seen it, a supplier had confirmed it by email. What was missing was the ability to demonstrate it to a third party with no reason to take anyone’s word for it. A passport does not fix that. It publishes the claim at scale, under a verified identity, next to a code anyone can scan, and keeps it available for years after the product has left the factory.

Production photos, test reports and supplier declarations

Consider what actually arrives from a supplier. A production photo comes as an image file sent by messaging app or email: its metadata is editable with free software, and nothing connects it to the plant it supposedly documents. A test report used in quality acceptance arrives as a PDF exported from a laboratory system, so the number in the report and the measurement in the instrument are separated by a step nobody witnessed. A plant logbook reconstructed after the fact looks identical to one kept in real time.

Supplier declarations are the weakest of the three, because they are pure assertion. A statement about recycled content is a promise on letterhead until the contract carries explicit data authenticity clauses and the supplier can produce something verifiable behind it.

The chain gets longer, the liability stays upstream

Every tier you add multiplies the hands a data point passes through, and none of them leaves a trace. The food sector has lived with this for years: origin claims travel through brokers and packers until the paperwork says one thing and the physical flow says another.

Liability does not follow the data down the chain. It stays with the economic operator who registers the passport, under the verified identity attached to it. A third tier supplier who overstated a recycled content figure is a contractual problem you may win two years later. The market surveillance authority, meanwhile, is talking to you.

What makes supply chain evidence verifiable

Supply chain evidence is verifiable when it satisfies three conditions at once: demonstrable origin, a trusted date and provable integrity. Miss one and the evidence becomes an opinion. A photo with perfect integrity and no verifiable origin proves only that a file has not changed since someone decided to protect it, which is a different statement from proving what it shows. These conditions are the substance of digital provenance and source certification, and they decide whether a file is treated as court-ready digital evidence when a dispute gets that far. They are not a private convention either. ISO/IEC 27037, the international standard for identifying, collecting, acquiring and preserving digital evidence, works from the same premise: what carries weight is not the file that lands on the reviewer’s desk but the documented process that produced it and kept it unaltered along the way.

Origin, trusted date and integrity

Origin answers where the evidence was created: which device, which location, which operator, recorded at capture and not reconstructed afterwards from a filename.

The date has to come from outside the file. A timestamp with legal value, recognised internationally, separates a record kept in real time from one assembled the week before an audit.

Integrity is the easiest of the three to get right and the one most often skipped. A digital seal applied at capture binds the content to a cryptographic fingerprint, so any later modification shows up to anyone who checks, including the party arguing against you.

Declared evidence versus evidence certified at the source

Criterion Declared evidence Evidence certified at the source
Origin Stated in an email or covering letter Recorded at capture, with device and context
Date Taken from editable file metadata Timestamp with legal value, applied at acquisition
Integrity Assumed, because the file looks untouched Digital seal, any alteration detectable
Who can verify it Only parties who already trust each other Any third party, independently
Effort during an audit Reconstruct the paper trail Produce the file
Outcome under challenge One opinion against another A technical check with a yes or no answer

Companies use TrueScreen to collect test evidence and supplier portal screenshots already in certified form, so the figure loaded into the passport rests on something dated and intact.

The cost of a challenge: audits, Green Claims and the CSRD

The cost of an unverifiable claim is no longer reputational alone. Directive (EU) 2024/825, which applies from 27 September 2026, bans generic environmental claims and carbon neutrality claims based on offsetting outside the value chain, and requires third-party verification for future environmental claims and sustainability labels. There is no transition period and no sell-through window for existing stock.

The CSRD pushes from the reporting side, because sustainability disclosures require external assurance. Once an assurance provider has to sign off, the question changes from whether you collected the data to whether you can demonstrate it.

One piece is still missing, and it is the piece that would have helped most. The Green Claims Directive, which would set a common EU method for substantiating an environmental claim, remains stalled: its legislative process has been suspended since June 2025. The duty to prove exists, the shared procedure for proving it does not, and the burden falls back on whatever evidence you hold. When a challenge concerns evidence gathered years earlier, files certified at the source with TrueScreen turn a documentary reconstruction into a technical check.

TrueScreen capture and certification platform

Feature

The TrueScreen capture and certification platform

With TrueScreen, test photos, supplier portal screens and supply chain documents are dated and tamper-evident from the moment they exist.

Discover more →

How to certify supply chain evidence before it enters the digital product passport

You certify supply chain evidence at the moment it is created, not at the moment it is uploaded. A production photo, a test report or a supplier declaration captured in certified mode carries its origin, a trusted date and a proof of integrity from the first second of its existence, so what flows into the passport can be checked by someone who has no reason to trust you. TrueScreen is the Data Authenticity Platform that captures, verifies, certifies with legal value and preserves digital data through an end-to-end forensic methodology, applying a digital seal and a timestamp with legal value, recognised internationally, at the moment of acquisition and keeping the chain of custody intact. TrueScreen is not a digital product passport platform and does not build passports: whoever builds the passport is someone else. It works one layer upstream, on the evidence that feeds it.

In practice that means capturing the evidence where it originates. Photos and video of production lines and incoming batches are captured in certified mode on the mobile app, so the image and its proof come into existence together. Supplier declarations published on portals are captured as certified web evidence, which fixes what the portal showed on the day you relied on it. Laboratory reports and material certificates are certified as files on receipt, and the same operation runs through the API inside the system that feeds the passport.

Take a producer of industrial battery cells that has to declare the share of recycled cobalt and the plant of origin before February 2027. The figure arrives from a second tier supplier as a PDF declaration plus photos of the incoming lot. In a market surveillance check, that PDF and those photos prove nothing: no trusted date, no demonstrable origin, freely modifiable. Certify the lot photos and the supplier portal screen on receipt, and the company holds dated, intact evidence for an inspection, a customer audit or a green claims challenge.

Frequently asked questions about the digital product passport

What is a digital product passport?

A digital product passport is a structured set of product data, accessible through a data carrier such as a QR code, covering identity, materials, environmental performance, repairability and end-of-life handling. It was introduced by Regulation (EU) 2024/1781, the Ecodesign for Sustainable Products Regulation, in force since 18 July 2024, with the data points fixed group by group by delegated acts.

When does the digital product passport come into force?

There is no single date: obligations arrive group by group through delegated acts under the ESPR, in force since 18 July 2024. The first hard deadline is the battery passport. From 18 February 2027, electric vehicle batteries, light means of transport batteries and industrial batteries above 2 kWh cannot be sold in the EU without a registered digital passport.

Who needs a digital product passport?

Any economic operator placing a covered physical product on the EU market, including components and intermediate products, and including manufacturers outside the EU who export into it. The 2025 to 2030 ESPR working plan lists iron and steel, aluminium, textiles, furniture, mattresses, tyres and electronics as the first categories. Since 20 July 2026, registration requires identity verification in the European registry.

What supply chain data does the digital product passport require?

Data that mostly originates upstream: material composition and origin, substances of concern, recycled content, manufacturing carbon footprint, durability and repairability figures, and end-of-life instructions. The exact fields come from the delegated act covering each product group, so a textile passport and a battery passport ask for different things while relying on the same kind of supplier evidence.

How do you prove that a supplier’s production photo or test report is authentic?

By certifying it when it is acquired, instead of examining it once it is contested. Certification at the source records the origin of the file, applies a timestamp with legal value, recognised internationally, and seals the content so that any subsequent alteration is detectable by an independent party. A photo received by email carries none of this, which is why its authenticity cannot be demonstrated after the fact.

Certify supply chain evidence before it enters the passport

With TrueScreen, production photos, test reports and supplier portal screens are created with a timestamp and a digital seal that carry legal value.

Start now
Request a demo

TrueScreen