Proovik
Back to blog
Sustainability

Digital Product Passport: the timeline and the data you will have to be able to prove

Equipo Proovik · Sep 14, 2026 · 9 min read

The Digital Product Passport (DPP) is an electronic record, accessible through a data carrier on the product (for example a QR code), that gathers the sustainability, composition, repair and traceability information required by Regulation (EU) 2024/1781 on ecodesign for sustainable products (ESPR). Which data each product carries is set by delegated acts per product group. Batteries have their own passport, mandatory from 18 February 2027 under Regulation (EU) 2023/1542.

This article belongs to Proovik's traceability cluster. It focuses on two questions: which dates are genuinely fixed, and what you will have to be able to prove, with dated evidence, when a customer or an authority reads your product's passport. For the event model that feeds that data, read EPCIS 2.0 and GS1 Digital Link for SMEs.

What the passport is and who issues it

The ESPR, in force since 18 July 2024, replaces the 2009 Ecodesign Directive and widens its scope from energy-related products to almost any physical product. Its Chapter III creates the digital product passport as the tool through which consumers, repairers, recyclers and authorities access reliable product information.

  • Who issues it: the manufacturer (or whoever places the product on the EU market), who is responsible for the data being accurate, complete and up to date.
  • How it is accessed: through a physical data carrier (QR, 2D code, NFC...) linked to a unique product identifier, with open, interoperable data.
  • Who hosts it: the manufacturer itself or a passport service provider; the Commission keeps a central registry of passport identifiers, not of their data.
  • When it is required: when the delegated act for the relevant product group applies. No delegated act, no obligation.

One nuance that avoids a misdirected project: the passport is a data and access architecture defined by the Commission and harmonised standards, not a specific technology. No blockchain "is" the passport or fulfils it on its own.

Timeline: what is fixed and what is not

Milestone Date Status
Entry into force of the ESPR (Regulation (EU) 2024/1781)18 July 2024Fixed in the regulation itself
First ecodesign working plan (priorities: textiles, furniture, tyres, mattresses, iron and steel, aluminium)Adopted by the Commission in April 2025Published; creates no obligations by itself
Commission's central passport registryOperational by 19 July 2026 at the latestFixed in Article 13 of the ESPR
Battery passport (electric vehicle, light means of transport, industrial above 2 kWh)18 February 2027Fixed in Article 77 of Regulation (EU) 2023/1542
Passport for textiles, furniture and the other working-plan groupsPending each delegated actCheck the Commission's official timeline

Estimates circulate for the missing dates (textiles are usually placed around 2027-2028). Do not treat them as deadlines: the obligation arises with the publication of the delegated act and the transition period it sets. The authoritative source is the Commission's ecodesign page (link in the sources).

The data you will have to be able to prove

Article 9 and Annex III of the ESPR list the categories of information a delegated act may require in the passport. Not all apply to every product, but the pattern repeats. What matters to a manufacturer is not only having the data, but being able to show it had the data when it published the passport and that the version the consumer sees is the one declared.

Passport data Usual evidence behind it What you must be able to show
Unique identifier of the product, lot or modelGS1 keys (GTIN, lot, serial) and product master dataThat the identifier existed and was assigned to that product on the date
Materials, substances of concern and recycled contentSupplier declarations, analyses, certificatesThat the supplier declaration existed before manufacturing and has not changed
Carbon footprint (mandatory for batteries)Calculation under the Commission's methodology, consumption and supplier dataThat the input data and the calculation are the ones used, with a date
Durability, repairability, spare partsManuals, tests, parts list and availabilityThat the manual or test corresponds to the version placed on the market
Supply chain due diligence (batteries)Policies, audits, supplier mapThat the policy and the audit existed on the declared date
Product history (repairs, change of owner, end of life)Events recorded by repairers, distributors and recyclersThat each event was recorded when claimed, in the order claimed

Everything in the right-hand column is proof of existence and prior date: a document or record existed on a date and has not changed. That is exactly what a time stamp over the file's hash gives you, and it requires publishing nothing.

The battery passport: the first real case

Regulation (EU) 2023/1542 is the only one with a firm date. From 18 February 2027, every electric vehicle battery, light means of transport battery (e-scooters, e-bikes) and industrial battery above 2 kWh placed on the market must have an electronic passport accessible through a unique identifier, with the information in Annex XIII: manufacturer, composition, carbon footprint, recycled content, state of health and repair and recycling data, with different access levels depending on who consults it. The economic operator placing the battery on the market is responsible for accuracy and must keep the information available for the battery's lifetime.

Battery manufacturers and importers therefore have about a year and a half for two tasks: building the passport (with a provider or in house) and building the chain of evidence behind every data point. The second task is the one that gets underestimated.

How to build dated evidence without waiting for the delegated act

  1. Identify the product with standard keys (GTIN, lot, serial) expressed as GS1 Digital Link, so the same identifier works in the QR code, in the passport and in your events.
  2. Record every passport data point as an event or a hashed document. A supplier declaration is a file: seal it. A change of owner is an event: record it.
  3. Version the passport. Every time you publish a version of the data, compute its hash and seal it. You will then be able to show what the passport said on the day a specific unit was sold.
  4. Do not put on chain what you do not want public. Only the hash leaves your system.
  5. Keep the proofs with the data. The seal is only worth something while you keep the file it corresponds to.

What the law says

Regulation (EU) 2024/1781 (ESPR), Article 9: information requirements may provide that products be placed on the market only if a digital product passport is available in accordance with the applicable delegated act. Article 10: the passport must be connected to a unique product identifier through a data carrier, be accessible through open, interoperable standards and respect the defined access rights. Article 13: the Commission shall set up and maintain a digital registry of passport identifiers by 19 July 2026.

Regulation (EU) 2023/1542 (batteries), Article 77: from 18 February 2027, each light means of transport battery, each industrial battery with a capacity greater than 2 kWh and each electric vehicle battery placed on the market or put into service shall have an electronic record (battery passport), accessible through the unique identifier, containing the information set out in Annex XIII.

Regulation (EU) 910/2014 (eIDAS), Article 41(1): an electronic time stamp cannot be denied legal effect or admissibility as evidence solely for being electronic or non-qualified. A seal over a passport version or a supplier declaration is a non-qualified stamp: admissible, without the presumption of accuracy of Article 41(2).

How to do it with Proovik

Proovik does not issue passports and does not replace a passport provider: it seals. From the certify page or through the API you can anchor on the Kaspa network the SHA-256 hash of every passport version, every supplier declaration and every test report; the file never leaves your device, and the seal is normally confirmed within seconds because Kaspa produces about ten blocks per second. With the traceability module you also record the product history as hash-chained EPCIS 2.0 events signed per actor, with a public verification QR code. Anyone can check the proof without Proovik using the specification on the verify page.

What it proves: that the file or event existed on the block date and has not changed. What it does not prove: that the content is accurate, that the passport complies with the delegated act, or that the carbon footprint was calculated correctly. Recording and anchoring is not the same as complying with the ESPR; it is the evidence that what you declare existed when you say it did.

Frequently asked questions

Is the digital product passport already mandatory?

Only for batteries, from 18 February 2027. For other products the delegated act for their group must be published and its transition period must expire. The ESPR is in force, but the concrete obligation arrives group by group.

Do I have to use blockchain for the passport?

No. The ESPR mentions no technology and the passport can be hosted on a conventional system. Blockchain serves a different purpose: showing that the data and its versions existed on a date and have not been retouched, without depending on whoever hosts them.

What about confidential passport data?

The ESPR provides for access levels: some information is public, some is reserved for authorities or specific operators. Sealing the hash publishes nothing; it lets you prove the integrity of a restricted data point without disclosing it.

What if my passport provider shuts down?

The data is yours and you must keep it. If you sealed every version, the proof of date and integrity remains verifiable even if you change provider, because it rests on a public network and not on the provider.

Sources

Proovik team. Published 16 September 2026; timeline last reviewed on 6 September 2026.

Share article

Link copied
Reference guides

From reading to proof

The three guides that explain where proof of existence and prior date comes from, and the two actions to check it yourself.

How to prove a document existed on a date

The methods that fix a document’s date, compared side by side, and how far each one goes.

Blockchain time stamping

What a non-qualified electronic time stamp is (Art. 3(16) EU Reg. 910/2014) and how anyone can check it without us.

Traceability with EPCIS 2.0

Supply-chain events stamped one by one, with GS1 Digital Link and public verification.