Digital Product Passport and RFID: Getting a Unique ID onto Billions of Products

DI Isabelle Urschitz
25. September 2026

A Digital Product Passport (DPP) is a structured, machine readable record of a product’s identity, materials and lifecycle data. It lives in a registry and connects to the physical item through a data carrier you scan to open it. Under the EU’s Ecodesign for Sustainable Products Regulation (ESPR, Regulation (EU) 2024/1781), most physical products sold in the EU will need one this decade. Batteries come first in February 2027, with textiles, iron and steel, electronics and furniture following. The carrier can be a QR code, a RAIN RFID tag or an NFC tag. QR works well for plenty of products, but once you need to read items in bulk, automate a warehouse or prove that something is genuine, RFID and NFC become the more practical choice. And that is where a regulation quietly turns into a very large tagging and encoding job.

For a long time the Digital Product Passport felt like a policy paper problem, something for sustainability teams and Brussels working groups to worry about. That has changed. The ESPR reached full application on 19 July 2026, the EU’s central DPP registry went live around the same time, and the first legally binding passport, the battery passport, becomes mandatory on 18 February 2027. From that point the passport stops being an idea and becomes a production requirement. Every affected product needs a unique identity, encoded onto a carrier, checked, and readable for the rest of the product’s life.

This article looks at what the passport actually is, which products need one and when, why it comes down to identification more than anything else, how QR, RFID and NFC compare as carriers, and what it really takes to encode and verify passport ready tags at production speed.

A Digital Product Passport is a digital identity for a physical product. Instead of a printed label carrying a handful of facts, it is a data record, held in a registry and connected systems, that a person, a customs officer or a machine can pull up by reading a carrier attached to the item.

What sits inside a passport depends on the product. It might cover where the item came from, what it is made of, how repairable it is, how it performed environmentally, and how to reuse or recycle it. The exact fields are decided product group by product group through delegated acts under the ESPR, so a battery passport and a textile passport will look quite different even though the mechanism behind them is the same.

Three things have to work together for any of it to function:

  • A unique identifier. Every product, or every batch where the rules allow it, gets its own ID, registered so authorities can confirm it exists before the item is sold.
  • A data carrier. A QR code, RAIN RFID tag or NFC tag on the product that links to the passport.
  • A data back end. The registry and structured data that the identifier points to, often expressed through standards like the GS1 Digital Link, so a single ID works for both databases and a shopper’s phone.

There is one shift here worth slowing down for. The passport is not printed information, it is linked information. The physical object only has to carry a reliable, unique, machine readable pointer. Getting that pointer onto billions of items correctly is where the theory meets the factory floor.ed.

The rollout happens in stages. The ESPR is a framework regulation, so it does not switch on for everything at once. Instead the European Commission adopts a delegated act for each priority product group, and each act sets that group’s data fields and deadlines. The ESPR Working Plan 2025 to 2030, adopted in April 2025, lays out the running order.

The indicative European Digital Product Passport timeline currently looks like this:

Dates for groups other than batteries are indicative and refer to when the delegated act is adopted. Enforcement usually follows 18 to 24 months later and can move.

Two things are worth keeping in mind when you plan. Batteries are the proof of concept. Because the battery passport is governed by its own regulation, (EU) 2023/1542, with a fixed date, it sets the practical benchmark for how carriers, unique IDs and structured data actually behave in the real world. The other thing is reach. The obligation is not limited to EU manufacturers. Any company placing a product on the EU market, importers included, is responsible for making sure a valid passport exists. For a global supply base that means the requirement travels upstream, all the way to the inlay producers, converters and packaging suppliers.

Take away the sustainability framing and the passport is, underneath, a question of unique identity at scale. Every affected item needs an identifier that is unique, permanent, machine readable and verifiable. That happens to be the exact problem the RFID and identification industry has spent 25 years working on.

This is why the passport is such a strong pull for tagging. Turning the regulation into something real means writing a unique ID onto a carrier, confirming it was written correctly, and making sure it can still be read reliably later, whether that is on a customs line, a recycling sorter or a retail shelf. Multiply that across the volume of textiles, electronics and other goods entering the EU every year and you are quickly into billions of individual identifiers.

The Commission’s default carrier is the QR code, and for many products a printed QR code will do the job. QR has real limits, though. It has to stay visible, it fails if the surface is damaged, it is read one item at a time with line of sight, and it is easy to copy. Where those limits start to hurt, whether that is bulk reading, automation, durability or protection against counterfeiting, RFID and NFC take over as the stronger carrier.

The three carriers are less rivals than tools for different jobs. The table below sets them side by side on the points that tend to decide a passport implementation.

A common assumption is that the passport data lives on the tag. Usually it does not. The carrier holds a small, unique identifier. The rich data, the materials, the footprint, the repair instructions, all of that lives in the registry and the systems the identifier resolves to.

That design is exactly what makes the whole thing workable at scale. The tag only needs to store a reliable pointer, most often:

  • A unique product identifier, encoded as an EPC (Electronic Product Code) on RAIN tags and expressible as a GS1 Digital Link URL, so the same ID serves both a database and a phone.
  • Optional secured data, for authentication or counterfeit protection. This might be a cryptographic element or locked memory that proves the tag, and therefore the product, is the real thing.

The consequence for manufacturing is sharp. Getting the identifier right is not negotiable. A duplicated, mis written or unverified ID does not simply fail a read. It breaks the link between a physical product and its legal passport. That is why encoding cannot be a write and hope step. It has to be written, read back, verified, and where security matters, locked.

When a delegated act becomes a shipping requirement, the pressure lands squarely on the companies that make the carriers: inlay producers, converters and label manufacturers. They are pushed on three fronts at once.

Volume comes first. Identifying products at item level across whole categories means enormous tag counts, produced on fast converting lines that cannot afford to slow down for quality checks. Then comes correctness. Every unique ID has to be written and verified, and because passport identifiers are unique per item, you cannot simply spot check a batch the way you would a uniform print run. Each tag’s encode has to be confirmed. And finally security. For counterfeit protection and regulated goods, the identity has to be locked or cryptographically protected so nobody can alter it downstream.

This is the point where the passport stops being a data project and turns into a production quality problem. A tag that reads weakly, carries the wrong identifier or can be overwritten is not a small defect under a passport regime. It is a compliance failure, and it tends to surface at the worst possible moment, at a customs check or a retailer’s dock door.

Meeting that challenge means testing, encoding and securing each tag as it is produced, at line speed, with a record to prove it happened. On a modern inline system these steps run in a single pass rather than at separate stations:

  1. Performance test.
    Confirm the tag reads reliably and clears its sensitivity threshold, so a weak inlay never leaves the line carrying a passport ID.
  2. Encode.
    Write the unique identifier, the EPC or its equivalent, and read it back to check the write actually worked.
  3. Lock or secure.
    Protect the memory so the identity cannot be corrupted or cloned, and add cryptographic security where the product group calls for it.
  4. Record.
    Produce a result for every tag, covering read, encoded value and lock state, which becomes the audit trail that regulators and brand owners increasingly ask for.
  • The Digital Product Passport is a unique, machine readable product identity required under the EU’s ESPR, rolling out group by group from 2027 to 2030.
  • Batteries lead the way on 18 February 2027, with textiles, iron and steel, electronics and furniture following through delegated acts.
  • The carrier can be a QR code, RAIN RFID or NFC tag, and RFID and NFC win out where bulk reading, automation, durability or counterfeit protection matter.
  • The tag itself holds a compact unique identifier, often an EPC or GS1 Digital Link, while the rich data sits in a registry.
  • At passport scale, every tag has to be tested, encoded, verified and locked at production speed, which turns the passport from a data project into a production quality project.

Related Articles

Contact

Any questions about this topic?

Content