Standards
Restricted Data Tiers and Authorised Access (EN 18239)
How is public data separated from restricted data in the Digital Product Passport? Protecting trade secrets via EN 18239 and authorised access.
The Digital Product Passport champions transparency — but not blindly. Some data should open only to authorised parties: a full material formulation may be necessary for a market-surveillance authority yet must not reach a competitor. This is what restricted data tiers address.
Public vs restricted
The passport can offer two (or more) views of the same product:
- Public layer: the summary a consumer, repairer or curious buyer sees — free and app-free per EN 18220 principles.
- Restricted layer: detail reachable only with verified authorisation — full composition, detailed test data, sensitive supplier information.
This distinction is the practical application of the GDPR/KVKK and trade-secret balance.
How does authorised access work?
Access to restricted data typically rests on an authorisation token: a time-limited, revocable access right granted to a market-surveillance authority, an authorised recycler or a specific business partner. Access is protected by these principles:
- Role-based: each party sees only the data its role requires.
- Time-limited and revocable: access expires or can be cancelled.
- Traceable: who accessed which data, and when, is recorded.
In IDPP this mechanism is implemented with time-limited access links and role-based views; restricted content never falls into a public cache.
Why does EN 18239 matter?
If restricted access is not standardised, every manufacturer builds its own ad-hoc solution and authorities wrestle with hundreds of different systems. A framework like EN 18239 makes authorised access predictable and verifiable — essential for the system to scale.
For exporters
The restricted tier is the answer to the worry "must I open everything?": no. The right design meets your compliance obligation while protecting your competitive information. To layer data from the start, fill in your data-collection checklist with this distinction in mind.
Frequently asked questions
How do I verify a role?
Through registration and approval, sector identity, or a verifiable credential. See DPP access rights.
Can I require a login for the public tier?
No. Free, unobstructed access is required. See EN 18220.
Can I open a tier just for one customer?
Yes, a B2B tier can be defined contractually. See what retailers ask suppliers for.


