Regulation
The EU DPP Registry Guide
What the central EU DPP Registry created by ESPR Article 13 is, who must register, what data it holds and how it integrates with customs at import.
The EU DPP Registry is the central system created by ESPR Article 13 and brought online on 19 July 2026. Despite the name, it is not a passport database — it is an index: it records which identifier points to a passport hosted at which address.
That distinction is the key to the whole architecture. Passport content stays with the economic operator or its chosen DPP service provider; the Commission does not build a central product data lake.
What it holds — and what it does not
| Holds | Does not hold |
|---|---|
| Unique product identifiers (UPI) | Product names, material shares, carbon data |
| The address where the passport is hosted | The passport itself |
| Economic operator identity | Trade-secret fields |
| Customs commodity codes | Supplier lists |
| Verification and authorisation data | Price or cost information |
| Semantic definitions and data model references | Sales and stock data |
| Audit records |
Who registers, and when?
The duty sits with the responsible economic operator placing the product on the EU market — for a non-EU manufacturer, the importer or authorised representative. Registration must happen before the product is placed on the market.
A typical flow:
- Generate a unique identifier for the product (for example a GTIN-based GS1 Digital Link URI).
- Publish the passport data in your own system or at a service provider.
- Submit the identifier, product category and hosting URL to the registry over its RESTful API.
- The registry validates and indexes the entry.
- The data carrier on the product points at the address that resolves the identifier.
For the step-by-step technical walkthrough see registering a DPP step by step.
Customs integration
At import, customs authorities match the declared commodity code against the registered identifier before releasing goods for free circulation, with a secure query interface provided for customs and market surveillance authorities.
The practical consequence: a missing registration or an inconsistent commodity code can leave a shipment waiting at the border. This is what turns the DPP from a marketing project into a logistics risk. See DPP checks at customs.
Why decentralised?
ESPR Article 10 requires open standards, machine readability and no vendor lock-in. A central EU database would raise sovereignty and competition problems and would be hard to scale to billions of products. Instead:
- Data stays with the operator — trade secrets and data sovereignty are preserved.
- The registry acts as an index — authorities and customs query one place.
- Backup providers guarantee persistence — the passport survives even if the operator does not.
Registry versus resolver
The two are easy to confuse:
- A resolver is operated by the economic operator (or its provider) and redirects an identifier to the passport address currently in force. It is what a consumer's phone talks to after scanning a QR code.
- The registry is the EU index recording which operator owns an identifier and where the passport lives. It is what authorities and customs consult.
The CIRPASS-2 reference architecture additionally recommends an independent EU fallback resolution service for cases where an operator's resolver is unreachable.
Open questions
Industry has raised API registration costs, interoperability with existing EU systems such as EPREL and REACH-IT, cloud sovereignty and Member State implementation procedures. Details of the registration flow continue to be settled through the implementing act.
Frequently asked questions
When did the registry go live?
19 July 2026. ESPR Article 13 required the Commission to establish it by that date, and both the test and production environments became available.
Does every single product need its own entry?
Registration granularity follows passport granularity: a model-level passport registers per model, while item-level battery passports register per unit. See granularity.
Is registration paid?
Fees are being settled through the implementing act and Commission practice; API registration cost is one of the open items industry has raised.
Can I host the passport on my own servers?
Yes. The architecture is built for exactly that: the data stays with you or your provider and the registry only knows the address. The persistence obligation also means you need a backup arrangement.
Can I publish a passport without registering?
Technically yes, but it will not satisfy the registration duty for in-scope products. Publishing a voluntary passport for out-of-scope products — for brand value and customer demand — is common practice.


