Skip to content
15 min read

Digital Product Passport (DPP) 2026: EU, China & US Requirements + Implementation Guide

Featured Image

A digital product passport is a structured, machine-readable record of a physical product: what it is made of, where it came from, what its environmental footprint is, and how it can be repaired, reused or recycled. It is reached through a data carrier on the product itself, usually a QR code, and in the EU it becomes a condition of market access rather than a marketing feature.

This page tracks the state of play across the three regimes that matter for an exporting manufacturer, the EU, China and the United States, and what each of them actually requires today. The EU is the only one of the three with a hard legal deadline in force.

What is in force in 2026, and what is still pending: EU, China and US at a glance

Last checked: 4 September 2026. Since the previous check in July 2026 the picture has not moved on the statutory side: the Digital Product Passport Registry under the Ecodesign for Sustainable Products Regulation (ESPR) opened on 20 July 2026, and batteries remain the only product group with a fixed date written into law. Every other date below tracks the Commission working plan, not adopted legislation, and will move if a delegated act slips.

I have covered this in more depth here: Ten Climate Tech Niches Under €1 Billion and the EU Rules Behind Them.

Jurisdiction and scopeDateStatus as of 4 September 2026
EU: Digital Product Passport Registry under ESPR (EU) 2024/1781Live since 20 July 2026ESPR itself has applied since 18 July 2024. The registry opened on 20 July 2026 (Implementing Regulation (EU) 2026/1778, applicable from 6 August 2026); no product obligation attaches to it on its own.
EU: EV, industrial and LMT batteries above 2 kWhFebruary 2027In law. Fixed by the Battery Regulation (EU) 2023/1542, not by an ESPR delegated act. The only hard deadline.
EU: textiles, footwear and apparelDelegated act expected 2027, application no earlier than 2028Pending. Not adopted. The minimum 18-month application window runs from adoption.
EU: iron and steel, ICT and electronics, tyres2028 to 2029 (indicative)Pending. Preparatory work under way; iron and steel and ICT are moving fastest.
EU: furniture, detergents, aluminium2029 to 2030 (indicative)Pending. Working plan only.
China: state-administered product passport systemTargeting 2027In development, coordinated through CAICT and national platforms. No EU-style market-access gate announced.
United States: federal DPP mandateNoneNo federal requirement. Sector traceability rules and voluntary industry standards only.

Two dates on the standards side are worth keeping in view because they decide what a passport will look like technically rather than when it is due. The Commission's battery due-diligence guidelines were due by 26 July 2026, with the due diligence obligations themselves postponed to 18 August 2027, and shape the responsible-sourcing layer of every battery passport. ISO/IEC Joint Technical Committee 5 on digital product passports was established in April 2026 as the global standards venue, with substantive deliverables expected from 2028, which means the international standard will arrive after the first EU obligations, not before them.

I have covered this in more depth here: China's Corporate Sustainability Disclosure Standards (CSDS): What Applies from 30 April 2026.

The practical reading of this table: there is no product obligation you can miss in the next twelve months unless you sell batteries. That is precisely why the window is worth using. No product-specific delegated act is in force, so the requirements are not yet legally pinned down, and building the underlying data layer now costs less than retrofitting it against a published schema under deadline pressure.

EU, China and US: how the three digital product passport regimes diverge

The three blocs will not converge into one clean global passport standard, and planning as if they will is the most expensive mistake I see. They differ not in detail but in what the passport is for: a market-access gate in the EU, an instrument of data sovereignty and export facilitation in China, a commercial requirement passed down the supply chain in the US.

 European UnionChinaUnited States
Legal basisESPR (EU) 2024/1781 plus product-specific delegated acts; Battery Regulation (EU) 2023/1542State programmes and national platforms, coordinated through CAICTNo federal mandate; sector rules such as food traceability and pharmaceutical serialisation
ScopeNearly all physical products, phased in by product groupPriority on electric mobility, then electronics and consumer goodsWhatever customers and EU export markets demand
Data carrierQR code, RFID or NFC, prescribed as durable and accessiblePlatform-defined, aligned with national carbon and traceability programmesIndustry choice, mostly GS1-based
Where the data sitsDecentralised: manufacturer's approved data host, resolved via the EU Central DPP RegistryCentralised on state-operated platformsWith the manufacturer or its platform vendor
EnforcementCE marking and market surveillance; penalties up to market exclusionAdministrative, via platform participation and export documentationContractual, through customer requirements

China's approach, led by the China Academy of Information and Communications Technology, is the part of this picture that gets least attention outside the country and matters most for anyone with Chinese suppliers. It pairs a product-level carbon credentialing initiative aimed at reducing trade friction for Chinese exports with a preference for state-operated infrastructure. The strategic logic is not compliance with Brussels but an alternative reference point to it, with cross-border data flows kept under Chinese protocols and the whole effort tied to the 2030 carbon peak and 2060 neutrality goals.

That creates a conflict a single global platform cannot design away. EU data protection rules push toward European storage, while China's Cybersecurity Law requires Chinese storage for certain data categories, and a passport carrying supplier identities and material origins sits squarely in that overlap. Verification reciprocity is equally unresolved: nobody has yet confirmed that EU authorities will accept Chinese third-party verifiers, or that Chinese customs will recognise EU-issued credentials.

The United States needs less explanation and is easy to underestimate. There is no federal mandate and none in prospect, but American manufacturers selling into Europe implement full EU compliance for those product lines anyway, and their tier-1 customers pass the same requirements down. This is the Brussels Effect working through purchase orders rather than statute, which is why "we do not sell into the EU" is a weak reason to wait, your customer's customer probably does.

The practical conclusion for a product line sold in all three markets: treat the EU schema as the baseline because it is the strictest and the only one legally hard-wired, then map deltas for China rather than building a parallel data model. Waiting for a harmonised global standard that has no political sponsor only burns the lead time you have now. Understanding broader EU Taxonomy simplification measures helps put the pace of European regulatory change in context.

Strategic Decision Framework: Global vs Regional Architecture

Multinational manufacturers face critical architectural choices shaping operational capabilities for 5-10 years. Wrong decisions create costly legacy digital systems, compliance gaps, or competitive disadvantages.

Option 1: Global Unified Digital Product Passport Platform

A single technology platform and data architecture serving all markets through regional configuration represents the most streamlined long-term approach.

When This Makes Sense:

Product portfolios remaining relatively homogeneous across markets justify unified infrastructure. Companies with resources for significant upfront technology investment and high confidence in eventual global convergence around EU-compatible standards benefit most.

Advantages:

Long-term cost efficiency emerges through economies of scale in platform licensing and maintenance. Data consistency ensures single source of truth across operations. Supplier simplicity allows vendors providing comprehensive information once in standardised format. Cross-market analytics enable portfolio-level sustainability performance insights.

Implementation Timeline:

Phase 1 (2025) focuses on platform selection and EU compliance, establishing foundation for entire value chain integration. Phase 2 (2026-2027) extends platform to China operations with localisation. Phase 3 (2028+) drives global supplier adoption through consolidated requirements.

Understanding product carbon footprint and lifecycle assessment methodologies proves essential for accurate DPP data generation across platforms.

Option 2: Regional Systems with Data Federation

Separate platforms or instances for major regions (EU, China, Americas, Asia-Pacific) with data exchange protocols enable cross-border information sharing where required.

When This Makes Sense:

Product portfolios differing significantly by region, substantial regional IT autonomy, or high uncertainty about global convergence timelines favour federated approaches. Existing regional technology infrastructure proves difficult to integrate centrally.

Advantages:

Flexibility allows each region optimising for local data requirements without compromise. Lower initial costs through phased investment matching actual regulatory timelines. Risk distribution contains platform failures or regulatory misalignments regionally.

Implementation Approach:

Phase 1 establishes EU priority system as reference architecture. Phase 2 evaluates China system selection based on regulatory clarity. Phase 3 deploys lighter-weight solutions for markets without strict mandates. Phase 4 assesses consolidation business case as global standards emerge.

Option 3: Hybrid Core-Plus Architecture

Core global data repository with lightweight access layer plus regional modules handling jurisdiction-specific requirements balances standardisation benefits with regional flexibility.

Implementation Structure:

Core global repository (2025-2026) maintains product master data, supplier information, base environmental data, and common metadata. Regional modules add EU-specific ESRS E1 detailed data, Chinese state system integration, US sector-specific requirements, and Asia-Pacific market attributes as needed.

Decision Matrix:

Product portfolio consistency, regulatory convergence confidence, IT governance capability, investment budget, and speed-to-compliance requirements determine optimal architectural choice. Most multinational manufacturers find hybrid approaches offering best risk-adjusted returns.

Supplier Engagement and Technology Integration: getting data and systems ready

The hard part of a digital product passport is never the QR code, it is the data supply chain behind it. The product, supplier and material data a passport demands usually sits in fragmented ERP, PLM and supplier spreadsheets that were never built to talk to each other, and buying a passport platform before that foundation is fixed just automates the gaps. Start with the data model, not the front end.

The single most useful exercise before any platform decision is a field-level inventory: sorting the data points a passport will need into what already exists somewhere in the company and what has to be collected for the first time. That split, not the software licence, is the real cost driver, and it is rarely as bad as feared on the left column or as easy as hoped on the right.

Already in CE documentation, BOM or LCA filesMust be newly collected
Product and article identifiers, typically GTIN-basedSupplier-specific carbon footprint broken down by lifecycle stage
Material composition and substances of concern, from REACH and RoHS workGeographic origin at material level, beyond the conflict-minerals scope
Manufacturing site and legal manufacturer dataRecycled-content shares evidenced at supplier level
Technical documentation, declarations of conformity and test recordsDurability and state-of-health data, item level, for batteries
Spare-part lists and repair instructionsEnd-of-life, take-back and recycling instructions per market
Cradle-to-gate LCA results, where an assessment already existsThird-party verification records tied to the individual batch or item

The right-hand column is also the column that propagates downstream. Those are the fields your customers will put into their own specifications, which is why tier-1 suppliers of automotive and electronics manufacturers are already being asked for them ahead of any legal deadline. Applying recognised lifecycle assessment methodologies and standards to those fields is what makes the numbers defensible rather than merely present.

Supplier readiness differs sharply by region. European suppliers generally know what is coming and already produce environmental data for REACH and RoHS. Large Chinese suppliers are moving quickly, pushed by both domestic programmes and EU export requirements, while Chinese SMEs lag. Southeast Asian suppliers outside export-dependent sectors often have neither awareness nor the digital infrastructure, and intermediaries sit between you and the actual producer. Segment accordingly: strategic suppliers get direct engagement and joint pilots, operational suppliers get templates and group training with contractual data obligations, and the long tail gets self-service resources plus industry-average data where nothing supplier-specific is available.

The carrier and registry decision is smaller than it looks. The ESPR allows QR codes, RFID and NFC. QR codes are cheap to print and readable with any phone, which makes them the default; RFID and NFC earn their cost only where contactless or automated scanning is already part of the process, as in logistics or high-value items. More consequential is where the data lives, and here the architecture is fixed by the regulation rather than by your vendor: the carrier holds only a static identifier, the EU Central DPP Registry resolves that identifier, and the passport content itself stays on the manufacturer's approved data host. You keep control of your data and you keep legal responsibility for it. There is no central EU database to upload into.

That also answers the question people ask most often about scanning in the field. Because the identifier resolves through the registry to a hosted record, retrieving the current passport needs connectivity at the point of reading, and the printed carrier alone will not display the data offline.

On the system side, four integration points carry most of the load: PLM for bills of materials and specifications, ERP for supplier master data, manufacturing execution systems for production data behind carbon footprints, and quality management for verification records. Whether the passport platform acts as master, as an aggregator pulling from source systems on demand, or as a cached hybrid, matters less than deciding it once and enforcing data ownership per field. A workable sequence is a three-month mapping and design phase, a pilot on one product line to prove the flows end to end, then extension to the wider portfolio, with automated data-quality checks added rather than bolted on afterwards. Well-structured ESG APIs and sustainability data management make the difference between a passport that updates itself and one that a person maintains by hand. Where a category deadline already exists, the EU Battery Passport is the most instructive template, because it is the only one whose data requirements are fully settled in law.

Frequently Asked Questions

Does a digital product passport require internet access?

Yes, at the moment of reading. The passport data does not sit on the product. The data carrier, whether QR code, RFID or NFC, holds only a static identifier, and the EU Central DPP Registry resolves that identifier to the manufacturer's approved data host where the live passport is stored. Scanning without connectivity gives you the identifier, not the passport content. Some implementations cache a subset of consumer-facing data in an app, but the authoritative record is always the hosted one.

Where is digital product passport data stored?

With the manufacturer, on its own approved data host, not in a single central EU database. The EU Central DPP Registry is a resolver and a supervisory backbone rather than a content repository: it maps identifiers to the right data source so that regulators, customs and authorised recyclers have one standardised way in. Each manufacturer therefore stores, controls and remains legally responsible for its own product data.

What data carrier does a digital product passport use?

The ESPR permits QR codes, RFID tags and NFC tags. Whichever is chosen, the carrier must be durable, easily accessible on the product or its packaging, and linked to the passport through the registry. QR codes dominate in practice because they cost almost nothing to apply and need no reader hardware.

Does China have a digital product passport?

China is building one, but not a copy of the EU model. Development is coordinated through the China Academy of Information and Communications Technology and national platforms, targeting 2027, and is tied to the country's carbon-footprint and traceability programmes rather than to a CE-style market-access gate. Large Chinese manufacturers already run battery passport infrastructure to serve EU export markets. The open question is interoperability in both directions, so manufacturers selling into both markets should plan for dual data governance instead of one passport for everything.

Are digital product passports mandatory, and do they apply to companies outside the EU?

They are mandatory in the EU for product groups covered by a delegated act, plus batteries above 2 kWh from February 2027 under the Battery Regulation. Enforcement runs through CE marking and market surveillance, so a non-compliant product can be kept off the market. Establishment outside the EU makes no difference: the obligation attaches to placing the product on the EU market, which is why an American or Asian manufacturer exporting into Europe carries the same requirements as a European one, usually via its importer or authorised representative.

What is the difference between a digital product passport and an EPD or LCA?

An LCA is a method for calculating environmental impacts, an EPD is a verified document that publishes those results for a product according to a product category rule, and a digital product passport is a regulated, machine-readable record attached to a specific product or item. The passport is broader than both, since it also carries material composition, origin, repair, spare-part and end-of-life information, and it is narrower in one respect: it is a legal obligation with a defined data set rather than a voluntary disclosure. In practice an existing LCA or EPD supplies part of the environmental content of a passport, but never the whole of it.

Johannes Fiegenbaum

Johannes Fiegenbaum

ESG and sustainability consultant based in Hamburg, specialised in VSME reporting and climate risk analysis. Has supported 300+ projects for companies and financial institutions, from mid-sized manufacturers to major banks and insurers.

More about