Skip to content

Standards

The DPP Standards Guide (EN 1821x)

What the eight CEN/CENELEC JTC 24 system standards — EN 18216, 18219, 18220, 18221, 18222, 18223, 18239 and 18246 — actually require, and how to meet them.

Updated: · 5 min read

The technical rules for the Digital Product Passport were written by CEN/CENELEC technical committee JTC 24 under the Commission's M/604 standardisation request. The result is a family of eight system-level European standards: the first six were published on 27 May 2026, with the remaining two expected in autumn 2026.

These standards do not answer "what data goes in the passport" — that is the job of product-specific delegated acts. They define how the system works.

The eight standards at a glance

StandardWhat it definesStatus
EN 18219:2026Unique identifiers (product, operator, facility)Published
EN 18220:2026Data carriers and the physical–digital linkPublished
EN 18216:2026Data processing, exchange protocols, formatsPublished
EN 18221:2026Data storage, archiving, persistencePublished
EN 18222:2026Passport lifecycle and APIsPublished
EN 18223:2026Interoperability, terminology, core data modelPublished
FprEN 18239Access rights, security, commercial confidentiality~Autumn 2026
FprEN 18246Data authentication, trustworthiness, integrity~Autumn 2026

How the modules fit together

The family is modular, with a dependency chain:

  • EN 18223 is the base: terms, the core data model and semantics. Everything else sits on it.
  • EN 18219 is the "key reference": without an identifier, no API call, carrier or registry entry means anything.
  • EN 18220 binds that identity to the physical product. See EN 18220.
  • EN 18216 is the precondition for exchanging data over the internet; EN 18222 says which operations can be called on that channel.
  • EN 18239 adds access rights at the API layer; EN 18246 secures integrity at both data and carrier level.

Standard by standard

EN 18219 — identifiers

Permits five product identifier schemes: ISO/IEC 18975 web-enabled structured paths (in practice GS1 Digital Link), IEC 61406 identification links, W3C DIDs, ISO/IEC 15459 AIDC identifiers and DOIs. On the operator and facility side, GLEIF LEI and GS1 GLN are the common choices. See EN 18219.

EN 18220 — carriers

Permits QR, Data Matrix, NFC, HF RFID and RAIN RFID, and sets requirements for encoding, scannability, durability, print quality and placement. The critical rule: at least one carrier must be free, app-free and smartphone-readable.

EN 18216 — data exchange

RESTful APIs over HTTPS/TLS, structured machine-readable message formats and vendor independence, with room for voluntary extensions. See EN 18216.

EN 18221 — persistence

Storage, archiving and versioning rules that keep the passport reachable for the product's expected lifetime. This is where the backup service provider concept comes from. See EN 18221.

EN 18222 — APIs

Create, read, update and search operations; item-level operations, bulk retrieval, version queries and registry submission. See EN 18222.

EN 18223 — data model

Terminology, the core data model and semantic rules; this is the layer where JSON-LD serialisation acquires meaning. See EN 18223.

FprEN 18239 — access rights

Role-based separation between public and restricted data, authentication aligned with eIDAS assurance levels, and handover of responsibility between operators. See restricted data tiers.

FprEN 18246 — authentication

Electronic signatures via W3C Verifiable Credentials, eIDAS electronic attestations of attributes, ISO 22376 Visible Digital Seal or ISO/IEC 20248 — plus an audit record. See EN 18246.

The reference architecture

The architecture in the standards has three components: (1) EU central services — registry, portal, semantic repository; (2) decentralised passport data operated by economic operators or service providers; and (3) third-party backup services for persistence. Standard APIs connect them.

The economic operator's workflow is codified too: create an identifier → create and attach a carrier → store the data → place it in backup → register with the EU registry and link the data → manage access rights → maintain integrity.

Presumption of conformity

A European standard becomes "harmonised" when it is cited in the Official Journal against a piece of legislation, and applying it then confers a presumption of conformity: show you follow the standard and you are assumed to meet the legal requirement. That gives you one of the best questions to ask a vendor: "how does your product conform to EN 18219, 18220 and 18222?"

Frequently asked questions

Are the standards mandatory?

Legally, standards are voluntary; the regulation is what binds. But because a harmonised standard confers a presumption of conformity, following one is in practice the safest and cheapest route.

Do I have to buy the standards?

Access to the texts is paid, through national standards bodies. In practice most manufacturers rely on a platform that documents its own conformity rather than buying the texts.

What is happening at ISO level?

ISO/IEC JTC 5, operational from September 2026, aims to internationalise this work, so a comparable framework can be expected outside Europe.

Do these standards cover the battery passport?

The Battery Regulation legally references only ISO/IEC 15459, but the battery ecosystem — the Battery Pass data model, Catena-X, the IDTA AAS templates — is converging on the same EN family.

Get your products passport-ready

IDPP lets you build, publish and register ESPR- and EN 1821x-aligned digital product passports with the EU DPP Registry.

Start for free What is IDPP?