Digital Product Passport: Who Hosts the Data Records?
For cloud teams the digital product passport is a data-architecture problem: one record per product, retrievable for years, with an EU registry from 19 July 2026.
The Digital Product Passport sounds like a sustainability mandate with a QR code. Anyone working in the cloud immediately sees the real challenge: a structured dataset for every physical product, accessible throughout its entire lifecycle and covering millions of items. From July 19, 2026, the EU central register goes live and turns the concept into an operational issue.
Key Points in Brief
- The approach remains decentralized. The actual product data stays with the respective economic operator. The EU central register does not store it; it only resolves identifiers and points to the distributed datasets.
- July 19, 2026, is the first hard deadline. From that date the register goes live. A few months later, the Battery Passport becomes the first mandatory use case.
- The burden falls on the operators. Resolver endpoints, role-based access, and retention periods of ten years or more then become part of your ongoing operations-not those of a central EU system.
Related:One Region Falls, Half the Supply Chain Stands / Trade Finance Without Document Backlogs
What the Product Passport Technically Requires
Every ecodesign-regulated product receives its own dataset containing structured information on its identity and properties. A data carrier is attached to the product, typically a QR code. It directs users via a resolver to the corresponding dataset. While this may sound trivial-and it is in one key respect-the real complexity lies in the boundary conditions.
The dataset must remain accessible throughout the product’s entire lifecycle. Access is role-based: manufacturers, importers, repair businesses, recyclers and end customers each see only the information their role permits. Multiple actors can be linked to the same passport via an Economic Operator ID (EOID). Under the ESPR, the GS1 Digital Link with GTIN is recognized as the identifier standard. The EU DPP Core Ontology from CIRPASS-2, published in March 2025, serves as the reference for interoperability. The decisive statement appears at the outset: The data remains with the respective actor; there is no shared central repository.
Why This Is a Data Architecture Problem
A single dataset is not the issue. The equation changes once the same dataset must be generated across millions of products, remain available for years, and be protected by role-based access controls. When hundreds of actors along a supply chain depend on one passport, access management itself becomes a system.
The decentralized approach brings tangible advantages. Data is updated where it originates, without routing through a central data lake. Access control stays with the operator. The cost appears on the other side of the ledger: every company must ensure availability, versioning, and authentication on its own. The central registry does not relieve this burden. It resolves identifiers and points to the actual sources, but shifts the operational load directly onto the systems of the economic actors involved. Resolver queries, API calls, and long-term storage become continuous operations from go-live onward, not a one-time project.
Two aspects are easily underestimated. The first is the identifier strategy. GS1 Digital Link with GTIN is an established route, yet cleanly mapping existing article numbers to it and maintaining EOID assignments over many years is painstaking work full of pitfalls. The second is retention. A product can remain in the field for ten or fifteen years. The dataset must stay consistently retrievable throughout that time. This affects backup strategies, migration paths, and the uncomfortable question of who remains responsible for the passport after a company sale or insolvency.
The Roadmap That Makes It Real
The ESPR (EU 2024/1781) has been in force since July 18, 2024, with the Digital Product Passport as its central instrument. The EU central registry will go live with the regulation’s full application on July 19, 2026. This establishes the foundation before the first product categories are activated.
The first mandatory application is the Battery Passport under the EU Battery Regulation (2023/1542). From February 18, 2027, EV batteries, industrial batteries above 2 kWh, and batteries for light means of transport must carry a passport, accessible via QR code and unique identifier. In the initial phase, only basic data is required: identity, type, model, and technical specifications. Details on lifespan and performance will be added through later delegated acts.
After that, the ESPR Working Plan 2025-2030, adopted in April 2025, comes into effect. It prioritizes iron and steel, aluminum, textiles, furniture, tires, and mattresses. Indicative timelines for the delegated acts are: steel around 2026, textiles, tires, and aluminum around 2027, furniture around 2028, and mattresses around 2029. Requirements will therefore be tightened gradually and by product group rather than in a single sweeping move.
What Teams Should Tackle Now
I would begin work in three areas early, no matter which product group reaches you first. The first is the identifier strategy. Whether and how GTINs and GS1 Digital Link are adopted will shape every integration that follows. This is not a decision you want to make once the first QR code is already printed on the product.
Second is the product data model. It should accommodate the DPP Core Ontology without being rigidly bound to it, since the required level of detail per product group has not yet been finalized. Third is technical ownership: where the data will actually reside, who will operate the resolver endpoint, and how role-based access will be implemented via EOID. Many existing systems are built for transactional data rather than the stable, decade-long delivery of product information.
To be frank, much remains undecided. How detailed the requirements will be for each product group, what real-world query loads will look like, and what versioning and migration will ultimately cost can only be estimated roughly today. Smaller companies face the additional challenge of financing long-term availability. This is not a reason to wait, but a reason to make the expensive foundational choices deliberately now.
- Decentralized data storage using resolver architecture rather than a central repository
- Established standards such as GS1 Digital Link for identifier resolution
- Clear timelines for registers, the battery passport, and the first ESPR product groups
- Specific data fields and schemas for most product categories
- Practical scaling of resolution and access control under high load
- Real costs of long-term availability and versioning across a product’s lifetime
Frequently Asked Questions
What is a digital product passport?
A digital product passport is a structured data record for a specific physical product. It contains information on identity and properties and can be accessed via a data carrier such as a QR code throughout the product’s entire lifecycle. In the EU, it serves as the central instrument of the Ecodesign Regulation ESPR.
How does the EU central register work?
The register does not store any product data. It resolves identifiers and points to the data records held by the respective economic operators. This keeps data sovereignty decentralized while the register ensures discoverability. It goes live on July 19, 2026.
When will the battery passport become mandatory?
From February 18, 2027, EV batteries, industrial batteries over 2 kWh, and batteries for light means of transport must carry a digital product passport. Access is provided via QR code and a unique identifier. Initially, only basic data such as identity, type, and technical specifications are required.
Which other product groups will follow?
The ESPR working plan 2025-2030 prioritizes iron and steel, aluminum, textiles, furniture, tires, and mattresses. Indicative timelines for the delegated acts are steel around 2026, textiles, tires, and aluminum around 2027, furniture around 2028, and mattresses around 2029.
What should cloud teams tackle first?
First, the identifier strategy and the underlying product data model. Equally important is clarifying early on where the data resides, who maintains it, and how long-term, role-based access will be managed via Economic Operator IDs.
Editor’s Picks
cloudmagazinC5 Attestations Force Mid-Sized Firms into Cloud ReversalcloudmagazinContainer Supply Chain Security: Securing IT Supply ChainscloudmagazinEdge Computing in Logistics: 5 Building Blocks for Real-Time PerformanceMore from the MBF Media Network
MyBusinessFutureInvestment Backlog: How AI Uncovers Hidden BudgetsDigital ChiefsIT Decides Whether the Spin-Off Pays OffSecurityTodayThe AI Act Is Actually a Security LawImage source: AI-generated (July 2026)

