
If your company sells physical products in the EU, you've probably heard that a Digital Product Passport (DPP) is coming for your category. And nearly everyone asks the same first question: "So we just need to put a QR code on the product, right?"
No. And treating it that way is the most expensive mistake you can make.
The short answer
A Digital Product Passport is not a QR code. It's a structured, verifiable, machine-readable data record about a product: its materials, origin, composition, certifications and end-of-life information, that stays attached to the product across its life cycle. The digital product passport QR code (or RFID/NFC tag) is only the data carrier: the doorway that resolves to that record. Building the doorway takes an afternoon. Assembling the data behind it, accurately, from your suppliers, in a format regulators and recyclers can trust, takes months. It's a supply chain problem before it's a software problem.
Why the QR code is the part nobody should worry about
Under the ESPR (Ecodesign for Sustainable Products Regulation), the carrier is already standardised. The recognised pattern is a GS1 Digital Link - a GTIN encoded as a URL that resolves through a resolver service to your live passport with the format set by the new CEN/CENELEC standards (EN 18219 for identifiers, EN 18220 for carriers). If your products already carry GTINs, you're structurally most of the way there on the carrier side.
That's exactly why the QR code is a distraction. Every digital product passport requirement that's actually hard sits behind the carrier:
- a persistent unique identifier that outlives a seasonal e-commerce URL
- a canonical product record for every SKU (for textiles, down to the production batch)
- structured, evidenced data — composition, country of manufacture, facility, substances of concern, certificates — not PDFs buried in an email thread
- access control separating public, restricted and authority-only fields
- immutable, timestamped records, so every update is auditable
None of that lives in the QR code. All of it lives in your supply chain.
What the ESPR timeline actually looks like
The other question we hear constantly is "when does this hit us?" Here's the digital product passport timeline as it stands, so you can plan rather than panic:
- 19 July 2026 - the ESPR reaches full application and the EU's central DPP Registry goes live. This is the framework switching on, not a product obligation.
- February 2027 - batteries above 2 kWh become the first category with a mandatory passport, under the Battery Regulation. This is the live proof-of-concept for everyone else.
- Late 2027 → 2028/2029 - the delegated act for digital product passport textiles and apparel is expected, followed by roughly an 18-month transition. The first affected collections land around 2028.
- 2028 onward - digital product passport furniture, plus iron and steel, tyres and aluminium, roll out across the 2028–2030 window.
Everything beyond batteries stays indicative until each delegated act is adopted, but the direction is fixed, and the data work has a multi-year lead time. That's the trap in the ESPR timeline: the deadline feels far away, and the preparation isn't.
Where companies actually get stuck
It's never the label. It's the data. Specifically:
You, as a manufacturer or importer, don't hold the data - your suppliers do. Material content, origin, factory-level information and substance declarations sit two or three tiers up your chain, often in spreadsheets and inboxes. The EU's own CIRPASS-2 pilots, the closest thing to an official DPP blueprint, spend most of their effort on exactly this: getting trustworthy data to flow across a chain that was never built to share it. Lighthouse Pilots is a project led by them where they involved real businesses to define the processes that will be recommended for the industries. They formed multiple expert working groups (EWG) for involved industries - textiles, construction, battery, apparel, etc.
Your data isn't structured for machines. A DPP has to be interoperable and queryable, with no vendor lock-in. "We have it somewhere" is not compliance.
You have no single source of truth. Most mid-market manufacturers store product data across an ERP, a PLM, supplier emails and someone's laptop. A passport needs one canonical record that stays correct as the product changes.
This is ordinary logistics and supply chain integration work, the complex work of getting the right data, clean and connected, from many systems into one trustworthy record. It's what decides whether your DPP is real or theatre.
How to start now, before your delegated act lands
- Fix your identifiers. Standardise on GTIN and a GS1 Digital Link resolution model. It's the cheapest thing you can do today.
- Map where your data lives. For each mandatory field, name the system or supplier that owns it. The gaps are your project plan.
- Start supplier data collection early. Tier-2 and tier-3 data is the long pole — set deadlines before the act is published, not after.
- Build one canonical product record, then attach the carrier last. Design the QR after the data model is stable, never before.
So what does the page behind the QR actually might look like?
When someone scans the code, the carrier resolves to a passport page and what appears there depends entirely on the product's category. Each category has its own set of fields, and not all of them are mandatory.
A textile passport, for example, surfaces things like fibre composition, country of manufacture and care and recyclability information. Here's how a textile DPP page can look:

The takeaway
A Digital Product Passport is only as good as the data underneath it. The carrier is trivial; the supply chain integration behind it - connecting ERPs, PLMs and supplier data into one clean, auditable, machine-readable record - is the real project, and it's the part worth starting early.
That integration work is what we do at Webamboos, building and integrating logistics and supply chain software for European mid-market companies. If it's useful to think through where your product data lives and what a DPP build would actually involve, we're happy to talk.







