The EU Digital Product Passport Moves from Policy to Practice: What Businesses Need to Know in 2026

By
Robert Brânzoi - Marketing Specialist
September 23, 2026

The EU Digital Product Passport Moves from Policy to Practice: What Businesses Need to Know in 2026

The Registry Is Live. The Obligations Are Getting Real.

For the past two years, the Digital Product Passport (DPP) concept has existed mainly as a policy commitment: a requirement formally written into law with the Ecodesign for Sustainable Products Regulation (ESPR), then given priority sectors and target dates in the 2025–2030 Ecodesign Working Plan. Useful for planning, but still one step removed from anything a company had to build against.

That changed in the summer of 2026. On 20 July, the European Commission opened the DPP Registry and its testing environment — the infrastructure that every Digital Product Passport must be registered against before a regulated product can be placed on the EU market. This came just days after the Commission adopted Implementing Regulation (EU) 2026/1778 on July 16, which sets out exactly how the registry works: who can use it, what must be submitted, how identity is verified, and what happens to the data.

Together, the registry and the implementing regulation provide the practical framework behind the Digital Product Passport, setting out how a company’s product data will interact with the EU infrastructure. In 2025, we published a blog on the Ecodesign Working Plan. At the time, it was easy to think of Digital Product Passports as something businesses would need to tackle further down the road. In 2026, that future is starting to arrive. With the registry live today, the rules governing it are now coming into force. And the first product category with a live deadline — certain battery types — is already inside its implementation window.

From Legal Commitment to Operating System: The ESPR Timeline

Here's a summary of the events leading up to September 2026: the full regulatory journey from the 2024 regulation through the 2025 Working Plan to this summer's implementing regulation. It's worth tracing the sequence in full, because each stage did a different job.

June–July 2024 — the framework regulation. Regulation (EU) 2024/1781— the ESPR — was published in the Official Journal on 28 June 2024 and entered into force on 18 July 2024. It replaced the earlier Ecodesign Directive and extended ecodesign requirements from energy-related products to, in principle, almost all physical goods placed on the EU market (with specific exclusions, including food, medicines and vehicles already covered by other rules). Critically, the ESPR didn't itself impose product-specific requirements — it created the mechanism: working plans, delegated acts, an Ecodesign Forum for stakeholder input, and the legal basis for the Digital Product Passport as an information tool. It also established, at a framework level, that the Commission would manage a central registry storing DPP identifiers.

April 2025 — the Working Plan sets priorities. The 2025–2030 Ecodesign Working Plan turned that mechanism toward specific sectors. It set iron, steel and aluminium as intermediate-product priorities, and textiles/apparel, furniture, tyres and mattresses as final-product priorities, each with a target year for adopting the relevant delegated act (steel in 2026, textiles and tyres in 2027, furniture in 2028, mattresses in 2029 — see the table below). It also carried forward 16 energy-related product groups from the previous 2022–2024 plan and confirmed the Commission's intent that, with limited exceptions such as products already covered by the EPREL energy-labelling database (European Product Registry for Energy Labelling), every product subject to ecodesign requirements under this plan needs a DPP. This is something that Finboot's 2025 article covered in detail.

July 2026 — the registry becomes operational. Implementing Regulation (EU) 2026/1778, adopted 16 July 2026 and in force from 6 August 2026, is the newest link in that chain. It doesn't set new ecodesign requirements or add product categories. Instead, it defines the operating rules for the registry established under the 2024 regulation. This includes how an economic operator registers a passport, how their identity is verified, what data the registry stores, and how long records are kept. The registry itself, together with a testing environment, went live for use on 20 July 2026.

Read together, the pattern is a regulation that has moved from legal commitment (2024) to sector prioritisation and timing (2025) to operating infrastructure (2026). Each stage narrowed the range of open questions.

Source: Regulation (EU) 2024/1781 (ESPR); 2025–2030 Ecodesign Working Plan; Implementing Regulation (EU) 2026/1778 — eur-lex.europa.eu, as of September 2026.

Let’s start with the basics: What is a Digital Product Passport?

A Digital Product Passport is a structured, machine-readable digital record attached to a product, its components, or its materials, accessible via a data carrier such as a QR code. Under the ESPR, its purpose is to make information that already exists somewhere in a value chain — origin, materials, environmental footprint, durability and repairability characteristics, end-of-life instructions — available in a consistent, checkable form to the people who need it: consumers, repairers, recyclers, market surveillance and customs authorities, and businesses further down the chain.

Two design choices matter for anyone planning around this:

•The system is decentralised, with a central index. The detailed product data in a DPP is not stored by the European Commission. It's held by the manufacturer or an appointed service provider. What the Commission-run registry stores is the index: a unique identifier per product, registration metadata, and enough structural information to verify a passport is real and complete — confirmed by both the ESPR text and the registry's own description. Manufacturers must also make their DPPs updatable by authorised third parties with a legitimate interest, such as repairers or recyclers.

Furthermore, a product can contain components and materials that have their own DPPs, managed by different organisations and linked through unique identifiers.

Think of a washing machine: the manufacturer manages the DPP for the appliance, while its steel, aluminium, electronics or plastic components may each have their own DPP linked to it.

That distinction — passport data decentralised, index centralised — is the architecture companies need to design their systems around.

Access is differentiated, not universal. The ESPR specifies that different stakeholder types get different levels of access to passport data, and that confidential business information and personal data are protected accordingly. A DPP is not a single public data dump; it's a structured record with access rules attached to different fields and audiences. Three main access levels exist: Public (mainly for consumers), Legitimate interest (for repairers or recyclers), Authorities (full access).

Within ESPR, the DPP is the delivery mechanism for whatever information requirements a given product-group delegated act sets.

The 2026 Implementing Regulation

Implementing Regulation (EU) 2026/1778 answers several practical questions that the 2024 regulation and 2025 Working Plan left open. What's now confirmed:

The registry's components. Article 3 defines what the registry consists of: a secure web interface and an API for registering passports, a verification service to check a passport's completeness against the applicable rules, a scheme for generating unique registration identifiers, storage for those identifiers and associated commodity codes, a public list of verified DPP service providers, a semantic repository of data models and definitions (available free of charge, per the Commission's registry announcement), and an automated log of registry activity.

Who can register, and how. Economic operators must verify their identity before they can register a passport. Identity verification uses a qualified electronic signature or a high-assurance eID recognised under the EU's eIDAS framework, valid for up to three years before re-verification is required. Verified operators can also authorise a verified third party to perform DPP Registry actions on their behalf, while retaining legal responsibility. This provides a practical route for manufacturers to appoint a DPP service provider to manage Registry interactions, avoiding the need to establish and maintain their own integrations with EU systems.

Data retention and access logging. Registered data is kept for ten years by default (unless other Union law specifies otherwise), authentication logs for six months, and administrative and data-exchange logs for five years — a concrete basis for internal data-governance planning around DPP records.

A confirmed governance and support timeline. Member States must appoint designated national administrators for the registry by 18 February 2027. The Commission commits to a helpdesk operating 08:00–20:00 Brussels time, with a 24-hour automated technical support tool due by February 2029, and a first formal evaluation of the regulation's implementation scheduled for the end of 2032.

Confirmed scope beyond ESPR itself. The registry isn't exclusively an ESPR instrument. Per the implementing regulation and the Commission's registry announcement, it also covers DPP obligations arising under the Batteries Regulation (large batteries), the Construction Products Regulation, the Toys Regulation, and detergents and surfactants. In practice, this positions the registry as the common backbone for Digital Product Passports across EU product legislation, rather than a system serving ESPR requirements alone.

What remains developing, not confirmed. The implementing regulation is about the registry's operating mechanics, not about which further product categories get DPP requirements or when. Those decisions still run through the separate delegated act process the 2025 Working Plan set out (see the table below). Companies should not read the registry's launch as confirmation that their specific product category now has a live DPP obligation — that depends on where their sector sits in the Working Plan's timeline.

How Economic Operators Should Prepare

The practical significance of this stage is that "DPP readiness" has stopped being a conceptual exercise and become an infrastructure question with defined technical parameters — and, because those parameters now touch identity verification, data structure and legal deadlines, no single function inside a company owns all of it.

Take a hypothetical example: a steel producer preparing for the Working Plan's 2026 delegated-act target, the earliest and highest-priority date on the current timeline. Three things are now true for a company in that position.

Registration is an operational process with real requirements, not a form to fill in later. Verified digital identity, structured data that passes an automated semantic-conformity check, and a registration granularity that matches the applicable legislation are all now specified. For the steel producer, this is a build task before it's a compliance task — IT/digital needs to establish who holds the qualified electronic signature or eID, and how product data gets structured to pass the registry's conformity check, while compliance/legal confirms which granularity (model, batch or item) the applicable delegated act will require.

The registry sits downstream of data quality the company controls today. The registry verifies structure and completeness; it does not create or validate the underlying facts about a product's origin, materials or footprint. For the steel producer, that means mill and supplier data, certification records and production-batch information — work that typically sits with supply chain/operations and sustainability/ESG, and that has to happen well before anything is submitted for registration, since it spans systems and organisational boundaries no single team controls alone.

Creating DPPs requires an operating model, not just a technical integration. Once access and data foundations are in place, companies still need a repeatable process to create, update and register DPPs at the required scale. For the steel producer, that operating model cuts across IT/digital, compliance/legal, supply chain/operations and sustainability/ESG: connecting source systems, collecting supplier data, applying the relevant regulatory rules, generating compliant passports and managing them through their lifecycle. The challenge is therefore not simply connecting to the registry, but establishing who and what will operate the DPP process across functions on an ongoing basis.

For companies approaching DPP obligations, the requirements now provide enough certainty to decide how that operating model should work. Building and maintaining it in-house places an additional coordination, technology and compliance burden on business units that are already managing significant regulatory change. Working with a service provider with a demonstrable DPP track record can ease that burden and derisk compliance — from data orchestration and passport generation through to registry integration and ongoing regulatory updates — while allowing internal teams to retain ownership of the data and compliance decisions that sit within their remit.

How Digital Traceability Turns Requirements Into Readiness

Everything the 2026 implementing regulation specifies — verified registration, structured and conformant data, defined granularity, retention discipline — depends on a company already having reliable, connected data about its products before that data ever reaches the registry. That is the layer digital traceability infrastructure operates at.

MARCO Track & Trace is built around this same logic: providing the operational infrastructure behind the DPP. It captures supplier, operational, certification and emissions data; connects it across batches, products and organisations; maintains an auditable record of the evidence behind each claim; transforms that information into structured, compliant Digital Product Passports; and manages the required interactions with the EU DPP Registry. The registry submission itself is now a defined and relatively mechanical final step. The real challenge is managing everything behind it — ensuring that product data is captured, connected, validated and evidenced throughout its lifecycle, and that compliant DPPs are created, maintained and registered at scale. This is the end-to-end process MARCO is designed to manage.

The real story behind the Implementing Regulation is not the registry itself. It is that the Digital Product Passport is becoming an operational system. What began with ESPR as a regulatory framework now has priority sectors, implementation timelines and defined rules for how passports will be registered and managed. The question for companies is increasingly shifting from what a DPP will require to how they will generate, operate and maintain them at scale.

How MARCO Track & Trace supports Digital Product Passport readiness.

Frequently Asked Questions

Is the Digital Product Passport mandatory for my product right now?

Only if your product falls under an already-adopted delegated act or sector-specific regulation — currently confirmed for LMT batteries, EV batteries, and industrial batteries with capacity greater than 2kWh, with obligations beginning 18 February 2027. Iron & Steel products are next in line with the delegated act expected in Q4 2026. For the Working Plan's other priority sectors (textiles, tyres, furniture, mattresses), the delegated acts are on a 2027–2029 adoption timeline; each will confirm when the DPP requirement kicks in. See the table above for the confirmed status by sector.

Does the DPP Registry going live mean my company has to register something now?

Not on its own. The registry provides the infrastructure for registration; it doesn't create a new obligation by existing. A company only has to register once its product falls under an adopted delegated act or other DPP-mandating legislation.

Download the full Q&A here.

Untitled UI logotextLogo
Join our newsletter to stay up to date on features and releases.
We care about your data in our privacy policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
© 2025 Finboot LTD. All rights reserved.