Cost & ROI
DPP: Build or Buy?
Writing the first version is easy. Keeping it alive as the regulation changes is the expensive part.
Blog
Security in DPP systems
Access rights, role-based authorisation, audit trails, data persistence and the cyber security of passport infrastructure.
All topicsDigital Product Passport40ESPR28Export28Standards27Integration22Verification20Circularity18Security17SME15Supply Chain15Retail & E-commerce14Textile11Life Cycle Assessment10Cost & ROI9GS1 Digital Link9Carbon Footprint8GDPR7Automotive6Data Carriers6EU DPP Registry6Electronics6Market Surveillance6Recycling & EPR6Battery5CBAM5Chemicals4Repairability4Türkiye4CSRD / ESRS3Furniture3Green Claims3Iron & Steel3Construction Products2Packaging2Aluminium1Toys1Tyre1
Articles in this topic 17 articles
Cost & ROI
DPP: Build or Buy?
Writing the first version is easy. Keeping it alive as the regulation changes is the expensive part.
Verification
Fighting Counterfeits With a Digital Product Passport
A QR can be copied. But a copied identity that cannot be verified is what makes counterfeiting visible.
Security
Protecting Trade Secrets While Being Transparent
Transparency is not showing everything. It is answering the right question at the right depth.
Security
Cyber Security for DPP Systems
A passport is a public surface by design. Shrinking the attack surface has to be part of that design.
Security
Audit Trails and Versioning in a DPP
A system that cannot answer "what did you declare last year?" is incomplete for audit purposes.
Security
Data Persistence and Backup Providers
Companies close, platforms change, domains lapse. The passport still has to be there.
Security
DPP Access Rights: Who Sees What?
The most misunderstood aspect of a passport. Tiered access is what makes transparency compatible with trade secrets.
Verification
eIDAS, E-Seals and Signing a DPP
Companies do not sign — they seal. In EU law, the right instrument for a passport is an electronic seal.
Verification
Verifiable Credentials for the Digital Product Passport
The technology that closes the gap between a declaration and proof. Signed supplier data makes audits far easier.
Standards
EN 18246: Data Authentication and Integrity
Who guarantees the data in a passport is genuine? This standard defines the signature and integrity layer.
Standards
EN 18221: Data Storage and Archiving
A passport can outlive your company. The persistence obligation is exactly about that.
Standards
EN 18216: Data Exchange Protocols
The standard that defines how passport data moves on the wire — the first text your integration team should read.
Battery
Battery State of Health and Dynamic Data
The battery passport is not static: usage data has to be updated for life. This is the hardest part of the architecture.
Chemicals
DPP for Chemicals: REACH, SVHC and SCIP
Hazardous substance declaration already exists. The passport makes the same data machine-readable and tiered.
Supply Chain
DPP Clauses for Supplier Contracts
Data left to goodwill does not arrive. Eight clauses to add to purchase contracts, and the reasoning behind each.
ESPR
What Is a DPP Service Provider?
Technical operation can be delegated; legal responsibility cannot. The limits of the service provider model and how to choose one.
Digital Product Passport
The Passport Lifecycle: Create, Update, Archive
Publishing the passport is not the end. Version management, update triggers and the archiving obligation.