Skip to content

Digital Product Passport

10 Common Myths About the Digital Product Passport

Widespread misconceptions about the DPP — "mandatory in 2026", "only for EU companies", "everything becomes public" — and what is actually true.

By IDPP · · Updated: · 3 min read

A great deal of what circulates about the Digital Product Passport is either out of date or was never right. Here are the ten misconceptions we meet most often in advisory conversations, and the reality in each case.

1. "The DPP became mandatory in 2026"

No. 2026 is the infrastructure year in which the EU DPP Registry went live and the standards were published. The first legal obligation at product level begins with batteries on 18 February 2027. For ESPR groups, the date arrives when a delegated act's transition period ends. See the timeline guide.

2. "It only applies to EU manufacturers"

Wrong. The trigger is placing a product on the EU market. If you manufacture outside the EU and sell into it, you are in scope — and even where the legal addressee is your importer, the data is requested from you. See economic operators.

3. "All our data becomes public"

No. The passport is tiered: a public tier sits alongside restricted tiers opened to authorised roles. Formulations, supplier lists and costs are not in the public tier. See restricted data tiers and protecting trade secrets.

4. "We already have a QR code, so we comply"

A marketing QR points at a web page. A DPP requires a standard identifier, machine-readable data, access tiers, versioning and registry registration. See DPP vs barcode and QR.

5. "SMEs are exempt"

There is no blanket exemption. Micro and small enterprises are exempt from specific provisions such as the unsold-goods destruction ban — but if you supply a brand, the request arrives by contract. See the SME guide.

6. "The Omnibus packages cancelled the DPP"

No. The 2025 sustainability Omnibus targeted CSRD and CSDDD; the Digital Omnibus targeted GDPR, the Data Act and the AI Act. Neither touched ESPR's DPP provisions. Delegated act dates slipped; nothing was cancelled.

7. "You need blockchain"

You do not. What is required is integrity and verifiability, which signed versions and verifiable credentials provide. See verifiable credentials.

8. "We create the passport once and we are done"

A passport is a living record: certificates are renewed, formulations change, repairs are logged. EN 18221 requires accessibility and versioning for the product's lifetime. See passport lifecycle management.

9. "Software is the biggest cost"

The opposite is what we see: the largest budget line is the labour of collecting supplier data. Software rarely exceeds a quarter of the total. See the cost guide.

10. "We will start when the delegated act lands"

The transition period after a delegated act is for putting a system live, not for collecting data from scratch. Data collection alone takes three to nine months. See a 12-month roadmap.

Frequently asked questions

Will these dates move again?

ESPR product-group dates are indicative and can change at the 2028 review. The battery passport date of 18 February 2027 is fixed in law.

If I am out of scope, should I ignore this entirely?

Voluntary passports for out-of-scope products are becoming common — to answer retailer requests and to differentiate. See brand differentiation with a DPP.

Can competitors copy my data?

Public-tier data is largely information obtainable from the label or by inspecting the product. Competitively sensitive fields stay in restricted tiers.

Get your products passport-ready

IDPP lets you build, publish and register ESPR- and EN 1821x-aligned digital product passports with the EU DPP Registry.

Start for free What is IDPP?