Digital Product Passport
The Passport Lifecycle: Create, Update, Archive
A DPP is not a one-off document. The stages of a passport lifecycle — draft, publish, update, suspend, archive — and the rules that govern each.
Treating a Digital Product Passport like a declaration of conformity is a common mistake. A declaration is signed once; a passport is a living record for as long as the product is on the market. EN 18222 governs that lifecycle and EN 18221 the storage and archiving.
Five stages
1. Draft
Data is collected and validated, and gaps are flagged. The passport is not public and no QR is printed yet.
2. Publish
The passport goes live, the identifier is registered and the data carrier enters production. Publication is the moment the content is signed. See eIDAS, e-seals and DPP signing.
3. Update
Certificates are renewed, formulations change, recycled content shares are corrected, repairs are logged. Each change creates a new version and the previous one stays reachable. See audit trails and versioning.
4. Suspend / withdraw
When a product is recalled or withdrawn, the passport is not deleted — its status changes, and that status is visible in the public tier. See product recalls and the DPP.
5. Archive
Even after production ends, the passport must stay reachable for the product's expected lifetime. See EN 18221 and data persistence and backup.
Update triggers
The events that require an update are predictable — tie them to processes:
| Event | Fields affected |
|---|---|
| Supplier change | Origin, facility identity, composition |
| Certificate renewal or withdrawal | Compliance fields |
| Formulation or material change | Composition, hazardous substances |
| Energy mix change | Carbon footprint |
| New repair manual | Circularity |
| Recall | Status |
Who updates it?
The weakest link in lifecycle management is usually unclear ownership. Quality, product development or sustainability? Write the roles down: who enters data, who approves, who publishes. See DPP project roles and RACI.
What happens at the API layer
EN 18222 defines create, read, update and search operations, item-level operations, bulk retrieval and version queries. The concrete question to ask a vendor: "can I retrieve the version as it stood on a given date, through the API?" See EN 18222 passport APIs.
Frequently asked questions
I published wrong data — can I correct it?
Yes, as a new version. The old version is not deleted, because when an error was corrected matters in an audit.
The product is discontinued. Can I close the passport?
No. As long as units remain in use, the passport must stay reachable. You can mark the status as discontinued.
What happens if the company ceases to exist?
Because of the persistence duty, the standards foresee backup service providers: passport data is mirrored and stays reachable independently of the operator.
Do I need a version for every small change?
Only for changes to passport content. Presentation changes such as layout or a translation fix can be handled separately.


