Who can access Digital Product Passport data?

QuestionsCategory: DPPWho can access Digital Product Passport data?
1 Answers
Best Answer
Team GreenSutra Staff answered 1 week ago
Faceless figure opening a DPP passport whose data fans into three tiered amber pools of access

DPP data access under the Ecodesign for Sustainable Products Regulation, Regulation (EU) 2024/1781, is tiered: a public subset open to anyone scanning the carrier, a restricted tier for repairers, remanufacturers and recyclers with a legitimate interest, and an authorities tier for market surveillance, customs and the Commission, keeping commercially sensitive data protected.

Access follows defined rights, not one open file

The Ecodesign for Sustainable Products Regulation, Regulation (EU) 2024/1781, builds differentiated access into every Digital Product Passport depending on the type of data and the type of stakeholder. The regulation lists the actors that must be able to read or update data according to their access rights: economic operators such as manufacturers, importers and distributors, alongside value-chain actors including customers, professional repairers, refurbishers, remanufacturers, recyclers, market surveillance and customs authorities, and the Commission. A GreenSutra DPP readiness engagement maps which fields sit in which tier before a delegated act fixes the split.

The three DPP data access tiers

In practice the framework reads as three tiers, with the exact fields for each product group set later by the relevant delegated act.

DPP data access tiers: public, restricted for repairers and recyclers, and authorities
One passport, three access tiers under the EU ESPR
Tier Who reads it Typical data
Public Anyone, including a consumer scanning the carrier Open public subset of passport data
Restricted (legitimate interest) Repairers, remanufacturers, second-life operators, recyclers Durability, repair and end-of-life information
Authorities Market surveillance, customs and the Commission Registration identifier and commodity code verified against the central EU registry

Economic operators retain write access to the fields they are responsible for, again according to their access rights.

Commercially sensitive data stays protected

Differentiated access exists precisely so that intellectual property and confidential business data are not exposed to the general public, and the exact public-versus-restricted split for each product group is fixed in that group’s delegated act. Two systems support the tiers: the Commission must set up a secure DPP registry by 19 July 2026, a future obligation and not yet a live service, and must also provide a publicly accessible web portal to search and compare passport data consistent with access rights. The EU Battery Passport applies the same three-tier logic from 18 February 2027. In GreenSutra engagements, exporters most often assume a passport is a single public file and are surprised by how much sits behind restricted, role-based tiers. A fuller walk-through of which field belongs in which tier sits in the DPP guide.

Sources: Regulation (EU) 2024/1781 (ESPR) · Regulation (EU) 2023/1542 (EU Battery Regulation)