Security
DPP Access Rights: Who Sees What?
How to design role-based access for a Digital Product Passport — the public tier, legitimate interest holders, authorities and B2B partners.
"Does all our data become public?" is the most frequently asked and most misunderstood question about the DPP. The answer is no: a passport is tiered, and each role sees only its own tier.
The tier model
| Tier | Who reaches it | Example data |
|---|---|---|
| Public | Everyone | Product name, composition summary, care, recycling |
| Legitimate interest | Repairers, recyclers, second-life operators | Disassembly instructions, detailed composition, dynamic data |
| Authority | Market surveillance, customs, notified bodies | Test reports, conformity file |
| B2B partner | Customers, OEMs | Contractually agreed fields |
See restricted data tiers and protecting trade secrets.
How a role is proven
How do you know a repairer really is one? Three approaches:
- Registration and approval: application through the platform with manual review. Simple, does not scale.
- Sector identity: verification against a trade register or professional body.
- Verifiable credential: a role attestation presented as a VC. See verifiable credentials.
On the battery side, an implementing act clarifying "legitimate interest holder" is expected.
Design rules
- Mark the tier at field level. Filtering in the presentation layer invites leaks.
- Default to restricted. A newly added field must not become public automatically.
- Keep an audit trail: who reached which tier, and when.
- Grant time-bound access rather than permanent rights.
- Do not carry personal data. See GDPR and DPP data.
The public tier rule
EN 18220 requires at least one carrier to be free, app-free and smartphone-readable. Requiring a login, an app download or registration to reach the public tier is therefore non-compliance. See EN 18220.
Frequently asked questions
Can competitors see the public tier?
Yes, but public-tier information is largely obtainable from the label or by examining the product.
Can I open specific fields to one customer?
Yes — a B2B tier can be defined contractually, and it is the clean way to satisfy retailer requests. See what retailers ask suppliers for.
Do I have to log access?
It is necessary for auditability and is an expected practice alongside FprEN 18239.


