A Digital Product Passport (DPP) is a structured, machine readable record of a product’s identity, materials and lifecycle data. It lives in a registry and connects to the physical item through a data carrier you scan to open it. Under the EU’s Ecodesign for Sustainable Products Regulation (ESPR, Regulation (EU) 2024/1781), most physical products sold in the EU will need one this decade. Batteries come first in February 2027, with textiles, iron and steel, electronics and furniture following. The carrier can be a QR code, a RAIN RFID tag or an NFC tag. QR works well for plenty of products, but once you need to read items in bulk, automate a warehouse or prove that something is genuine, RFID and NFC become the more practical choice. And that is where a regulation quietly turns into a very large tagging and encoding job.
For a long time the Digital Product Passport felt like a policy paper problem, something for sustainability teams and Brussels working groups to worry about. That has changed. The ESPR reached full application on 19 July 2026, the EU’s central DPP registry went live around the same time, and the first legally binding passport, the battery passport, becomes mandatory on 18 February 2027. From that point the passport stops being an idea and becomes a production requirement. Every affected product needs a unique identity, encoded onto a carrier, checked, and readable for the rest of the product’s life.
This article looks at what the passport actually is, which products need one and when, why it comes down to identification more than anything else, how QR, RFID and NFC compare as carriers, and what it really takes to encode and verify passport ready tags at production speed.
What is a Digital Product Passport?
A Digital Product Passport is a digital identity for a physical product. Instead of a printed label carrying a handful of facts, it is a data record, held in a registry and connected systems, that a person, a customs officer or a machine can pull up by reading a carrier attached to the item.
What sits inside a passport depends on the product. It might cover where the item came from, what it is made of, how repairable it is, how it performed environmentally, and how to reuse or recycle it. The exact fields are decided product group by product group through delegated acts under the ESPR, so a battery passport and a textile passport will look quite different even though the mechanism behind them is the same.
Three things have to work together for any of it to function:
- A unique identifier. Every product, or every batch where the rules allow it, gets its own ID, registered so authorities can confirm it exists before the item is sold.
- A data carrier. A QR code, RAIN RFID tag or NFC tag on the product that links to the passport.
- A data back end. The registry and structured data that the identifier points to, often expressed through standards like the GS1 Digital Link, so a single ID works for both databases and a shopper’s phone.
There is one shift here worth slowing down for. The passport is not printed information, it is linked information. The physical object only has to carry a reliable, unique, machine readable pointer. Getting that pointer onto billions of items correctly is where the theory meets the factory floor.ed.
Which products need a Digital Product Passport, and when?
The rollout happens in stages. The ESPR is a framework regulation, so it does not switch on for everything at once. Instead the European Commission adopts a delegated act for each priority product group, and each act sets that group’s data fields and deadlines. The ESPR Working Plan 2025 to 2030, adopted in April 2025, lays out the running order.
The indicative European Digital Product Passport timeline currently looks like this:
| Milestone | Timing | Status |
| ESPR full application and EU DPP registry live | 19 July 2026 | In force |
| Battery passport (EV, LMT, industrial over 2 kWh) | 18 February 2027 | First mandatory DPP |
| Iron and steel (delegated act) | around 2026 to 2027 | In preparation |
| Textiles and apparel (delegated act) | around late 2027 | Expected |
| Electronics and ICT, furniture, tyres, aluminium | around 2028 to 2029 | Later waves |
Dates for groups other than batteries are indicative and refer to when the delegated act is adopted. Enforcement usually follows 18 to 24 months later and can move.
Two things are worth keeping in mind when you plan. Batteries are the proof of concept. Because the battery passport is governed by its own regulation, (EU) 2023/1542, with a fixed date, it sets the practical benchmark for how carriers, unique IDs and structured data actually behave in the real world. The other thing is reach. The obligation is not limited to EU manufacturers. Any company placing a product on the EU market, importers included, is responsible for making sure a valid passport exists. For a global supply base that means the requirement travels upstream, all the way to the inlay producers, converters and packaging suppliers.
Why the passport really comes down to identification
Take away the sustainability framing and the passport is, underneath, a question of unique identity at scale. Every affected item needs an identifier that is unique, permanent, machine readable and verifiable. That happens to be the exact problem the RFID and identification industry has spent 25 years working on.
This is why the passport is such a strong pull for tagging. Turning the regulation into something real means writing a unique ID onto a carrier, confirming it was written correctly, and making sure it can still be read reliably later, whether that is on a customs line, a recycling sorter or a retail shelf. Multiply that across the volume of textiles, electronics and other goods entering the EU every year and you are quickly into billions of individual identifiers.
The Commission’s default carrier is the QR code, and for many products a printed QR code will do the job. QR has real limits, though. It has to stay visible, it fails if the surface is damaged, it is read one item at a time with line of sight, and it is easy to copy. Where those limits start to hurt, whether that is bulk reading, automation, durability or protection against counterfeiting, RFID and NFC take over as the stronger carrier.
QR code, RFID and NFC as a DPP carrier
The three carriers are less rivals than tools for different jobs. The table below sets them side by side on the points that tend to decide a passport implementation.
| Property | QR code | RAIN RFID (UHF) | NFC (HF) |
| Read method | Optical, line of sight | Radio, no line of sight | Radio, tap at close range |
| Range | Camera distance | Up to 10 m or more | About 0 to 4 cm |
| Bulk reading | One at a time | Hundreds at once | One at a time |
| Consumer access | Any smartphone camera | Reader or app needed | Any NFC smartphone |
| Durability | Fails if surface damaged | Works through packaging | Works through packaging |
| Counterfeit protection | Low, easy to copy | High, supports crypto and locking | High, supports crypto and locking |
| Typical passport fit | Low cost, visible goods | Supply chain automation, apparel at scale | Consumer engagement, brand protection |
In practice a lot of brands will end up using more than one. A printed QR code for shoppers, say, alongside an embedded RAIN RFID or NFC tag for warehouse automation, customs checks and authentication. That combined approach only works if the electronic carriers can be produced, encoded and quality checked at the same speed and cost as the labels they live inside. It helps to understand how RAIN RFID and NFC technologies differ and where each one earns its place.
What data actually sits on a DPP carrier?
A common assumption is that the passport data lives on the tag. Usually it does not. The carrier holds a small, unique identifier. The rich data, the materials, the footprint, the repair instructions, all of that lives in the registry and the systems the identifier resolves to.
That design is exactly what makes the whole thing workable at scale. The tag only needs to store a reliable pointer, most often:
- A unique product identifier, encoded as an EPC (Electronic Product Code) on RAIN tags and expressible as a GS1 Digital Link URL, so the same ID serves both a database and a phone.
- Optional secured data, for authentication or counterfeit protection. This might be a cryptographic element or locked memory that proves the tag, and therefore the product, is the real thing.
The consequence for manufacturing is sharp. Getting the identifier right is not negotiable. A duplicated, mis written or unverified ID does not simply fail a read. It breaks the link between a physical product and its legal passport. That is why encoding cannot be a write and hope step. It has to be written, read back, verified, and where security matters, locked.
From regulation to billions of tags
When a delegated act becomes a shipping requirement, the pressure lands squarely on the companies that make the carriers: inlay producers, converters and label manufacturers. They are pushed on three fronts at once.
Volume comes first. Identifying products at item level across whole categories means enormous tag counts, produced on fast converting lines that cannot afford to slow down for quality checks. Then comes correctness. Every unique ID has to be written and verified, and because passport identifiers are unique per item, you cannot simply spot check a batch the way you would a uniform print run. Each tag’s encode has to be confirmed. And finally security. For counterfeit protection and regulated goods, the identity has to be locked or cryptographically protected so nobody can alter it downstream.
This is the point where the passport stops being a data project and turns into a production quality problem. A tag that reads weakly, carries the wrong identifier or can be overwritten is not a small defect under a passport regime. It is a compliance failure, and it tends to surface at the worst possible moment, at a customs check or a retailer’s dock door.
How manufacturers verify and encode passport ready tags
Meeting that challenge means testing, encoding and securing each tag as it is produced, at line speed, with a record to prove it happened. On a modern inline system these steps run in a single pass rather than at separate stations:
- Performance test.
Confirm the tag reads reliably and clears its sensitivity threshold, so a weak inlay never leaves the line carrying a passport ID. - Encode.
Write the unique identifier, the EPC or its equivalent, and read it back to check the write actually worked. - Lock or secure.
Protect the memory so the identity cannot be corrupted or cloned, and add cryptographic security where the product group calls for it. - Record.
Produce a result for every tag, covering read, encoded value and lock state, which becomes the audit trail that regulators and brand owners increasingly ask for.
Handling all four in one production pass keeps the line fast while making sure that every tag leaving the factory is verified, correctly identified and secured. CISC’s production test equipment is built around this idea, with 100% testing, encoding and locking at production speed, so passport scale volumes never force a choice between throughput and correctness.
If you are trying to work out where you fit, the affected sectors, apparel and textiles, electronics, consumer and industrial goods, map closely onto the markets that already lean on RFID identification today. The passport does not invent the technology. It just turns reliable, verified, item level identification into a legal expectation rather than a competitive edge.
Frequently Asked Questions
It is a digital identity for a physical product, required under the ESPR (Regulation (EU) 2024/1781). It links the item to structured data about its origin, materials, repairability and recycling through a scannable carrier such as a QR code, RFID tag or NFC tag.
The EU’s default carrier is the QR code, but RFID and NFC are allowed and often preferable where bulk reading, automation, durability or counterfeit protection matter. Many brands combine a printed QR code for consumers with an embedded RAIN RFID or NFC tag for supply chain and authentication use.
The ESPR reached full application on 19 July 2026. The first mandatory passport is the battery passport, required from 18 February 2027. Textiles, iron and steel, electronics and furniture follow through delegated acts on an indicative 2027 to 2029 timeline.
Usually just a unique identifier, commonly an EPC on RAIN tags, expressible as a GS1 Digital Link, plus optional secured data for authentication. The detailed product data lives in a registry that the identifier resolves to, not on the tag itself.
Because passport identifiers are unique per item, every tag’s encode has to be verified rather than spot checked. A mis written, weak or unlocked tag breaks the legal link between the product and its passport, so testing, encoding, verifying and locking each tag at production speed is essential.
Key Takeaways
- The Digital Product Passport is a unique, machine readable product identity required under the EU’s ESPR, rolling out group by group from 2027 to 2030.
- Batteries lead the way on 18 February 2027, with textiles, iron and steel, electronics and furniture following through delegated acts.
- The carrier can be a QR code, RAIN RFID or NFC tag, and RFID and NFC win out where bulk reading, automation, durability or counterfeit protection matter.
- The tag itself holds a compact unique identifier, often an EPC or GS1 Digital Link, while the rich data sits in a registry.
- At passport scale, every tag has to be tested, encoded, verified and locked at production speed, which turns the passport from a data project into a production quality project.
Preparing for passport scale tagging and want to see 100% encoding and verification running at production speed? Explore the CISC Knowledge Hub or talk to a CISC engineer.