2026 Is the Year DPP Moves From Framework to Implementation
For businesses following the digital product passport, 2026 is an important year. However, it is also important to understand what has and has not become mandatory.
There is not yet a blanket requirement for every product sold in the European Union to have a digital product passport. Under the Ecodesign for Sustainable Products Regulation, or ESPR, requirements are being introduced progressively through product-specific rules. Other EU legislation can also create DPP requirements for particular sectors.
What has changed significantly during 2026 is the infrastructure around the system.
The EU has published six harmonised DPP standards, introduced detailed rules for the Digital Product Passport Registry, brought the Registry into operation with a testing environment, and continued developing sector-specific requirements. At the same time, the first major mandatory passport deadline is approaching for certain batteries on 18 February 2027.
This means businesses should no longer think of the eu digital product passport as a distant compliance concept. The technical foundations are becoming much clearer.
For Australian manufacturers, suppliers and brands selling products into the EU, this is particularly relevant. The first question is not simply, “Do we need a QR code?” It is whether the business can collect, structure, maintain and provide the product information that future rules may require.
That requires looking at product identifiers, materials, suppliers, compliance documents, lifecycle information, data ownership and system responsibilities.
The practical shift in 2026 is therefore from understanding the legislation to preparing the systems and data needed to work with it.
New Industries Are Being Brought Into the DPP System
Toys and detergents show how DPP is spreading beyond ESPR priority products
The DPP system is not developing only through the ESPR priority-product programme. Separate EU legislation is also introducing digital product passport requirements.
The new Toy Safety Regulation is one example. It entered into force on 1 January 2026 and introduces a digital product passport for toys. However, businesses should note the timing carefully. The new rules generally apply from 1 August 2030, rather than making toy passports immediately mandatory during 2026.
Under the regulation, the passport will contain compliance and identification information and will be accessible through a data carrier. Manufacturers will be responsible for creating the passport before placing an affected toy on the market once the relevant rules apply.
Detergents and end-user surfactants are another important example.
Regulation (EU) 2026/405 introduces DPP requirements for these products and includes rules covering data carriers, product and operator identifiers, passport storage, access and registration. The regulation entered into force in March 2026, but most of its requirements apply from 23 September 2029.
This distinction matters when researching digital product passport regulation requirements. A regulation can already exist without every operational obligation applying immediately.
What this expansion means for businesses
The positive development is greater consistency in the way digital compliance information can be organised across different industries.
A company working across several regulated product categories may eventually be able to build more consistent processes for identifiers, product records, supporting evidence and digital access.
The challenge is that different pieces of EU legislation can still require different information.
A toy manufacturer, battery supplier and detergent producer should not assume that one generic passport template will satisfy every sector. Product-specific legislation determines what information is required, who can access it and when the requirement applies.
A useful preparation exercise is to create a regulatory scope map.
For every product family sold into the EU, record:
- the relevant EU product legislation
- the business entity responsible for placing the product on the market
- product and model identifiers already used
- manufacturer and supplier information
- material and component information already available
- compliance declarations, certificates and test evidence
- lifecycle information currently collected
- missing information that depends on suppliers or other value-chain participants
- the expected DPP or related digital-information deadline
This gives the business a clearer starting point without assuming that future data requirements have already been finalised.
Six Harmonised DPP Standards Give Businesses a Technical Foundation

Until recently, one of the difficulties facing manufacturers and technology teams was knowing what the underlying DPP architecture would look like.
That became clearer in July 2026.
Commission Implementing Decision (EU) 2026/1736 published references to six harmonised standards supporting the ESPR digital product passport requirements.
The six published standards cover:
- EN 18216:2026 for data exchange protocols
- EN 18219:2026 for unique identifiers
- EN 18220:2026 for data carriers
- EN 18221:2026 for data storage, archiving and persistence
- EN 18222:2026 for APIs used in passport lifecycle management and searchability
- EN 18223:2026 for system interoperability
The European Commission states that eight harmonised DPP standards have been developed, with six already published and referenced as of July 2026. Its current indicative timeline points to a later 2026 decision for the remaining standards.
For manufacturers and digital product passport platform providers, this is a significant improvement over designing systems around broad regulatory principles alone.
It provides a more concrete technical foundation for assessing whether identifiers, data carriers, storage systems and APIs are being designed in a way that can support the European architecture.
Why existing systems still need to be reviewed
Businesses should not assume that having a product database or QR code system automatically makes them DPP-ready.
A current product-information system may have been designed primarily for ecommerce, warehouse management, marketing or internal reporting. DPP implementation introduces additional questions.
For example:
- Can a product be identified consistently across systems?
- Can the responsible economic operator also be identified?
- Can the information behind a data carrier remain available over the required period?
- Can data be exchanged through appropriate interfaces?
- Can a passport be updated without losing control of earlier information?
- Can information originating from suppliers be linked to the correct product?
- Can public information be separated from restricted information where legislation requires different access rights?
- Can supporting evidence remain connected to the claim or data point it supports?
These are more important questions than simply deciding what the QR code should look like.
A business starting its technical review during 2026 should compare its existing architecture with the published standards and document where changes may eventually be required.
That review can also help avoid building a proprietary system that becomes difficult to adapt as product-specific rules mature.
The EU Digital Product Passport Registry Is Now Operational
July 2026 changed DPP from a concept into a system businesses can test
On 20 July 2026, the European Commission launched the Digital Product Passport Registry together with a testing environment.
This is one of the most practical developments in the DPP programme so far.
The Registry should not be understood as one giant central database containing every piece of information from every passport.
The EU system is designed around decentralised product-data storage. The Registry stores and manages required identifiers and associated registration information, while the broader product information can remain within the decentralised DPP system.
The Registry architecture includes a secure user interface, an API for registration, verification functions, identification and authorisation processes, unique registration identifiers, a semantic repository and logging capabilities.
Registration can be performed through the Registry interface or through an API, which is particularly important for organisations that may eventually need to handle passports at scale.
Businesses need clear responsibility for registration and data quality
The Registry rules also make identity and responsibility important parts of implementation.
Under the Registry arrangements, economic operators need to go through verification before obtaining the status needed to register new passports or modify existing registrations. The rules also place responsibility on verified operators and relevant value-chain actors to maintain accurate and up-to-date information in their Registry profiles.
For a business preparing now, this raises several operational questions:
- Who will be responsible for DPP registration?
- Which legal entity will act as the relevant economic operator?
- Who controls the product identifiers?
- Who approves changes to product information?
- Who verifies information received from suppliers?
- Who updates the passport when relevant lifecycle information changes?
- What happens to passport responsibilities if a product line or business unit is transferred?
- Will Registry interaction be manual, automated through an API, or a combination of both?
These responsibilities should be decided before the organisation has thousands of affected products to manage.
Businesses assessing a digital product passport platform should therefore look beyond the front-end passport page. They should ask how the system handles identifiers, Registry workflows, permissions, updates, versioning, supporting evidence and structured data exchange.
Battery Passport Deadline Is Now Less Than a Year Away

The battery sector is particularly important because it provides businesses with a real mandatory date rather than only an indicative future timetable.
From 18 February 2027, the EU Batteries Regulation requires a battery passport for each light means of transport, or LMT, battery, each electric vehicle battery and each industrial battery with a capacity greater than 2 kWh that is placed on the market or put into service.
The regulation requires the passport to include information relating to the battery model as well as information specific to the individual battery. Different information can also have different access rights, including information available to the public, authorities and parties with a legitimate interest.
This illustrates why supply chain traceability and data governance are becoming central implementation issues.
Battery information can involve multiple organisations and systems. A manufacturer may depend on data from material suppliers, component producers, laboratories, manufacturing systems and later lifecycle participants.
The practical challenge is connecting that information reliably to the correct battery.
Battery businesses should test complete workflows before February 2027
For an affected battery business, preparation should now move beyond general planning.
A useful readiness process includes:
- Confirm exactly which battery products fall within the scope of the February 2027 requirement.
- Map every required data source against the passport information defined by the Batteries Regulation.
- Identify the internal or external owner of each data field.
- Determine how unique battery and operator identification will be managed.
- Review data-carrier implementation.
- Define who can create, approve and update passport information.
- Test Registry registration and identity-verification processes.
- Check how restricted and public information will be separated.
- Test what happens when information changes during the battery lifecycle.
- Keep supporting evidence connected to the relevant battery or product record.
The goal should be repeatable operation, not simply producing one successful test passport.
For businesses outside the battery industry, the battery rollout is also useful because it provides a practical example of how DPP obligations can move from regulatory text into everyday product-data management.
Iron, Steel and Other ESPR Priority Products Are Next
Businesses outside the battery sector should not assume they can wait
The European Commission’s current indicative DPP timeline identifies iron and steel as the first ESPR priority product group expected to reach product-specific rules, with adoption of the relevant delegated act currently indicated for Q4 2026. The Commission also makes clear that implementation timelines may change as legislative and technical work progresses.
Other priority groups follow progressively.
The current Commission timetable indicates:
- textiles, tyres and aluminium in 2027
- furniture in 2028
- mattresses and ICT products in 2029
Energy-related product work is also scheduled across the 2026 to 2029 period.
These dates relate to the development and adoption of product-specific rules. They should not automatically be treated as the date on which every product in those groups must already carry a DPP.
The Commission explains that following adoption of ESPR delegated acts, economic operators generally have a transition period of at least 18 months.
That gives businesses preparation time, but it should not be mistaken for a reason to ignore the issue until the final months.
Supplier data is likely to be one of the biggest practical challenges
A brand may control basic information such as its product name, model number and market information. It may not directly hold detailed information about every material, component or earlier manufacturing stage.
That information may sit with suppliers.
For example, a company preparing a textile product could already begin mapping:
- fabric and material suppliers
- component suppliers
- product models and variants
- manufacturing locations
- existing certificates and supporting documents
- material composition records
- product identifiers
- supplier identifiers
- information currently held only in PDFs, spreadsheets or email
- data that can be exchanged in a structured format
The same principle applies to metals, tyres, furniture and other sectors.
The aim is not to invent future DPP fields before the delegated act defines them. It is to understand where reliable product information exists today and where the business depends on other organisations to provide it.
For companies exploring product passport circular economy use cases, this groundwork can also help with information needed later for activities such as repair, reuse or recycling where the applicable legislation makes that data available.
What Businesses Should Do During the Rest of 2026

For most businesses, the most useful DPP work during the remainder of 2026 will be preparation rather than rushing to create a finished passport for products whose detailed requirements have not yet been adopted.
A sensible starting point is to build a reliable product-data foundation.
Practical DPP readiness priorities
Businesses can work through the following priorities:
- Identify products likely to fall under current or forthcoming DPP legislation.
Start by mapping product families against the relevant EU legislation. Do not assume the ESPR is the only source of DPP requirements because batteries, toys, detergents and other sectors can be covered through separate legislation.
- Establish ownership of product information.
Decide which team owns product identity, supplier information, compliance evidence, lifecycle changes and final passport publication.
- Improve supplier-data collection.
Identify information that must come from suppliers and determine whether it is currently provided in a usable and consistent format.
- Establish stable identification processes.
Review how products, operators and other relevant entities are identified across ERP, PIM, ecommerce, compliance and manufacturing systems.
- Review the six published harmonised standards.
Technical teams and technology providers should compare current architecture with the standards covering identifiers, data carriers, data exchange, storage, APIs and interoperability.
- Test digital-access workflows.
A data carrier needs to connect the physical product with reliable digital information. Test scanning, resolution, product matching, accessibility and what happens if systems or URLs change.
- Assess EU Registry workflows.
Determine how the organisation could handle verification, registration, updates and API integration with the Registry. The European Commission now provides a testing environment and implementation resources that allow businesses to explore these processes before the first mandatory battery deadline.
- Prepare for versioning and lifecycle updates.
Product information is not always static. Build processes that can distinguish corrections from genuine lifecycle changes while maintaining clear responsibility for the information shown.
- Keep supporting evidence connected to product information.
If a sustainability, compliance, material or performance statement depends on a certificate, laboratory result or supplier document, retain the relationship between the statement, its evidence and the relevant product.
- Follow product-specific legislation rather than guessing future requirements.
The safest approach is to prepare systems and source data without presenting anticipated data fields as final regulatory requirements before the EU formally adopts them.
What to ask when comparing a digital product passport platform
Choosing technology too early can create unnecessary rework, while waiting until the final compliance deadline can make implementation difficult.
When comparing a provider, ask practical questions such as:
- How does the platform manage unique product and operator identifiers?
- How does it support the published DPP standards?
- Can information be exchanged through documented APIs?
- How are passport updates and versions handled?
- Can supporting documents or evidence stay linked to the relevant product record?
- How are different access rights managed?
- How does the platform approach EU Registry registration?
- Can existing ERP, PIM or product databases remain the source of information where appropriate?
- Can product data be exported in structured formats?
- What happens to the data if the business changes technology providers?
- How does the system distinguish required regulatory information from optional information?
These questions help a buyer evaluate the underlying data architecture rather than choosing a provider simply because it can generate an attractive QR-linked webpage.
Businesses assessing Aleverum for DPP preparation should use the same approach. Compare the platform against your products, existing data systems, supplier-data requirements and the applicable EU rules rather than assuming one standard configuration will suit every sector.
The most important preparation is better product data
Whether an organisation refers to the project internally as a digital product passport or product digital passport initiative, the practical work is increasingly the same: collect reliable information, structure it consistently, establish responsibility and keep it maintainable.
A QR code is only the access point.
The value of the system depends on what sits behind it.
Businesses need trusted digital information that can remain associated with the correct product, be updated under controlled processes and be made available to the appropriate people or systems when required.
For businesses selling into the EU, 2026 is therefore a useful preparation window.
The Registry is operational and testable. Six harmonised standards have been published. Product-specific legislation is expanding, and certain battery passports become mandatory on 18 February 2027. Meanwhile, the ESPR programme is progressively moving towards iron and steel, textiles, aluminium, tyres, furniture, mattresses and other product groups.
The strongest approach is not to guess requirements that have not yet been formally defined. It is to make product information more structured, reliable, traceable and maintainable now, so the organisation is better prepared when its sector’s final rules arrive.
That is the real shift taking place in 2026: digital product passport preparation is becoming an operational product-data challenge, not simply a future compliance exercise or a QR-code project.





