GDPR
GDPR/KVKK and DPP Data Management
How do the Digital Product Passport and GDPR/KVKK intersect? We address the balance between trade secrets, personal data and the public passport.
The Digital Product Passport is transparent by definition — but transparency does not mean opening every piece of data to everyone. When designing a passport, you must distinguish three kinds of data: public information, trade secrets and personal data.
Three kinds of data
- Public information: material content, recyclability, maintenance instructions — presenting these is the passport's very purpose.
- Trade secrets: full formulation, supplier prices, process details — competitive information. These must not appear in the public layer.
- Personal data: information relating to a natural person, covered by GDPR and KVKK.
Where does personal data show up in the passport?
A product passport mostly contains no personal data. But it can leak indirectly through:
- Repair or ownership records (who repaired it, and when).
- Real-person names in small workshop/supplier information.
- Scan analytics (who scanned, and from where).
IDPP's public passport surface handles scan events with bot filtering and aggregation, enabling counting without leaving a personal trace.
The layered-access solution
For trade secrets and sensitive data, the right tool is restricted data tiers: only an authorised party (market surveillance, recycler) can see it via verified access. This is the essence of the EN 18220 access model and strikes the balance between transparency and privacy.
The data-minimisation principle
GDPR's "data minimisation" principle applies here too: collect and store only the data necessary for the purpose. Avoid putting personal data in the passport's public layer; if you must, make its legal basis explicit.
For exporters
The DPP and GDPR/KVKK do not conflict; with the right design they complement each other. The key is to layer the data from the start. Make this design part of your supply-chain data-collection process and back it with verification mechanisms.
Frequently asked questions
Can ownership information live in the passport?
Not in the passport, but in a separate GDPR-compliant layer. See DPP in resale and second-hand.
Is collecting scan data a problem?
Aggregated measurement without personal data is possible. See fighting counterfeits with a DPP.
Is battery usage data personal data?
It can be if linkable to a vehicle and driver; use aggregation. See battery state of health.


