DIGITAL PRODUCT PASSPORT7 min read
What data goes in a Digital Product Passport?
ESPR sets what a passport holds and who sees it; GS1, ISO and W3C standards carry it. The battery passport's Annex XIII is the only fully worked example.
By Ilse Vermeulen
A Digital Product Passport holds structured data about a specific product — its identity, composition, compliance status, environmental performance and end-of-life handling — attached to a unique identifier that a data carrier makes scannable. Not all of that data is public: the framework splits it into tiers, and who sees which tier is one of the least settled parts of the law. This post is the "what", not the "why" or the "when" — for those, see the pillar post on the EU Digital Product Passport.
What ESPR says a passport must hold
The framework instrument is Regulation (EU) 2024/1781 (OJ L, 2024/1781, 28.6.2024; CELEX 32024R1781), the Ecodesign for Sustainable Products Regulation (ESPR), in force since 18 July 2024. Its digital product passport chapter — Articles 9 to 15 and Annex III — sets the architecture: what a passport must be capable of holding, how the identifier and registry work, and that access is differentiated by who is asking. It does not itself enumerate a field list. That is deliberate: ESPR is a framework regulation, and the actual data fields for any given product category are fixed by a product-specific delegated act adopted under Article 4.
That matters for how to read this post. Nearly everything written about "DPP data requirements" in the abstract is describing a shape, not a schedule — the shape gets filled in once, per product group, by delegated legislation. Batteries are the one product group where that has already happened in full, which is why the second half of this post leans on the battery passport.
The identifier and carrier layer
Before a passport can be tiered, it has to be findable. Two things sit underneath every DPP: a unique identifier for the specific item, and a data carrier that puts that identifier somewhere a scanner can read it.
In practice, the layer taking shape across CEN/CLC/JTC 24's standards work leans on existing supply-chain infrastructure rather than inventing new plumbing: GS1 Digital Link — a URL structure that turns a product identifier into a resolvable web address — built on ISO/IEC 15459, the international standard for unique item identification that GS1's own numbering schemes already comply with. The physical carrier is typically a QR code or a watermark placed on or with the product. We covered the standards that formalise this — EN 18219 for unique identifiers and EN 18220 for data carriers, both cited by Commission Implementing Decision (EU) 2026/1736 (CELEX 32026D1736) — in more depth in EN 18216 and the DPP standards stack, explained.
A second, structurally different approach is also in circulation: W3C decentralized identifiers (DIDs), standardised by the W3C, let a product's identifier be controlled by its owner rather than issued and resolved through a central registrar such as GS1. It is a live design conversation in the DPP community rather than something ESPR or the Batteries Regulation mandates — hedge accordingly if you see it presented as settled. The standard that would govern access-rights enforcement at the technical layer, prEN 18239, was still under formal vote as of mid-2026 and is not yet published, so how any of this gets locked down for enforcement is itself unresolved.
Public, legitimate interest, or authorities only
The access-tier idea is the part of the framework every DPP guide gestures at and few pin down with a source. Here is what is actually specified, using the battery passport as the worked example:
Who
Public: Anyone who scans the code — consumers, journalists, competitors
Legitimate interest: Repairers, remanufacturers, recyclers, researchers; some fields also go to the Commission
Battery passport example
Public: Cell chemistry, hazardous substances, round-trip efficiency
Legitimate interest: Detailed composition, dismantling instructions, spare-part sourcing, individual battery state of health
Legal status today
Public: Operative — these fields are public from day one
Legitimate interest: Defined in law, but who qualifies as a person with a legitimate interest is not yet specified
A third tier sits above both: information reserved for notified bodies, market surveillance authorities and the Commission — compliance test reports, in the battery passport's case. That tier is narrower and less discussed than the other two, precisely because it never touches the public web portal.
The one fully specified worked example
Annex XIII of Regulation (EU) 2023/1542 (OJ L 191, 28.7.2023; CELEX 32023R1542) is the only place today where "what data, at what tier" has been legislated field by field for an entire product category. It splits into four numbered points, and getting the numbering right matters more than it looks:
- Point 1 — public information about the battery model.
- Point 2 — model-level information open only to persons with a legitimate interest and the Commission: detailed composition, spare-part sourcing, dismantling information, safety measures.
- Point 3 — information open only to notified bodies, market surveillance authorities and the Commission: compliance test reports. This is the authorities tier, not point 2 — a transposition error common enough to be worth flagging explicitly.
- Point 4 — individual-battery information (as opposed to model-level) open only to persons with a legitimate interest: performance and durability values, state of health, status (original, repurposed, re-used, remanufactured, waste), and usage history.
Article 77(9) confirms this reading directly, referring to "persons with a legitimate interest as referred to in points 2 and 4 respectively of Annex XIII" — the two legitimate-interest points, by number.
Two fields are worth calling out because they read as restricted but are not: internal cell and pack resistance, and initial round-trip energy efficiency, are both enumerated in point 1 and are therefore public at the model level. It is the individual battery's measured values under point 4 — not the model-level spec — that sit behind the legitimate-interest tier. Confusing the two is an easy, and common, error.
4
Annex XIII points
public, model-level LI, authorities-only, individual-battery LI
18 Aug 2026
Legitimate-interest act deadline
Art. 77(9); no draft published as of July 2026
6
Published DPP standards
EN 18216–18223, minus 18217 and 18218, which don't exist
What's still undefined
The middle tier looks precise on paper and is not yet operable in practice, because the law that defines who counts as a "person with a legitimate interest" does not exist yet.
Implementing act on legitimate-interest access, Article 77(9)
Due 18 August 2026. As of July 2026 the Commission has not published a draft; its own roadmap targets Q4 2026, after the statutory deadline. Until it is adopted, Annex XIII points 2 and 4 have no defined audience — the tier exists in law but not yet in practice.
A second gap sits in the design requirements rather than the access rules. Article 78(e) requires that a battery passport "remain available after the economic operator … ceases to exist or ceases its activity in the Union" — but the Regulation names no custodian, no escrow mechanism and no duration for that continued availability. It is a real requirement with no specified way to meet it, and it applies equally to whatever ESPR-based passport regime eventually reaches other product categories.
What to build against now
The parts that are not in doubt are the parts worth starting on: pick an identifier scheme compatible with GS1 Digital Link and ISO/IEC 15459, map your data onto a public/legitimate-interest/authorities split even before the legitimate-interest act lands, and treat Annex XIII as the reference implementation rather than a battery-only curiosity — it is the closest thing the DPP ecosystem has to a finished spec.
Our Annex XIII explorer lets you filter every battery passport field by access tier and source provision, the data requirements page walks the same fields by category, and the compliance timeline tracks every date in this post against its Official Journal source.
Get the deadline off your risk register.
Book a walkthrough tailored to your battery lines and get a straight answer on your obligations.