ManufacturingEUPeriod covered: 2024

Digital product passports start with ownership of the data

A passport is only as good as the data behind it. Before evaluating platforms, establish who owns each data element and how changes are versioned.

Hand scanning a product label with a barcode scanner
Byline
Gambit Reign analysis
Period covered
2024
Reviewed
6 October 2026
Topic
Evidence & traceability
Reading time
4 min read

Key takeaways

  • The ESPR is framework legislation. Product-specific requirements are developed through delegated acts, so obligations differ by product group and timing.
  • Passport readiness is a data governance question: identifiers, bill of materials, supplier evidence, version control and access rights.
  • Assign an accountable owner per data element before evaluating software. Platforms organise data; they do not create ownership of it.

What the ESPR is, and what it is not yet

The Ecodesign for Sustainable Products Regulation entered into force on 18 July 2024. The European Commission's explanatory material published in September 2024 describes it as a framework establishing requirements for sustainable products, with the digital product passport among the mechanisms. [I]

The word to hold on to is framework. The ESPR sets the structure within which product-specific requirements are established, largely through delegated acts. It does not, on its own, mean that every manufacturer of every product must already issue a passport. Which products are in scope, what data a passport must carry, and from when, are matters for the product-specific measures.

This distinction has a practical consequence for planning. A manufacturer should establish whether its product groups are in scope, and on what timetable, before investing in a passport platform. Reading the framework regulation as an immediate universal obligation leads to spending on capability that may be needed later, in a different form.

Identifiers: the foundation everything else attaches to

A passport identifies a product and connects to information about it. That requires unique, stable identifiers at more than one level — the product model or type, the individual item where item-level identification is required, and the batch or production lot that links a specific item to the conditions under which it was made.

Getting this wrong is expensive later. If a product identifier changes when a component supplier changes, or if the same identifier is reused across genuinely different specifications, the history attached to it becomes unreliable. The identifier structure needs to reflect how the business actually distinguishes products, and it needs to remain stable across design revisions.

Where item-level identification is required, the physical marking and the data record must be designed together. A marking that can be applied in production but not read at end of life serves only half the purpose.

Bill of materials and supplier evidence

The substance of a passport is the material and component information behind the product. That information arrives from suppliers, and supplier evidence is where most readiness gaps appear — not because suppliers are unwilling, but because the specific data required is often not part of what they currently provide.

The practical starting point is a bill of materials structured so that each significant component and material can carry the attributes that will be required of it. That means knowing which supplier provides which element, what evidence they hold, and what format it is in.

Where supplier data is not yet available, the useful step is a gap register: which elements lack evidence, which supplier holds it, and what the route to obtaining it is. This is more valuable than a platform selection, because it identifies the critical path — and the critical path usually runs through suppliers, not through software.

Data ownership and change triggers
Data elementAccountable ownerChange trigger
Product identifierProduct managementNew model or variant
Item-level identifierProductionMarking method or line change
Bill of materialsEngineeringDesign revision
Material compositionProcurement with suppliersSupplier or material change
Recycled content evidenceProcurementSupplier or batch change
Substance declarationsComplianceRegulatory or formulation change
Version recordData ownerAny change above
Access rightsComplianceRegulatory or contractual change

This ownership mapping is our own working model. It is not derived from the ESPR or from any delegated act, and the data elements a passport must carry will be determined by the product-specific requirements that apply.

Version control and access rights

Product data changes. A formulation is adjusted, a supplier is changed, a material specification is revised. Without version control, a passport describes a product that no longer exists, and there is no way to establish what was true when a particular unit was made.

Version control has two requirements. Each change must create a new version rather than overwriting, and each version must be linkable to the units produced while it was current. That second requirement is what makes it possible to answer, later, what a specific item contains.

Access rights are the second governance question. Different parties need different levels of access: authorities, supply chain partners, customers, repairers and recyclers. Designing access as a property of the data, rather than as an afterthought, avoids a common pattern in which access is granted broadly because restricting it is difficult.

Both version control and access rights are decisions about ownership. They cannot be delegated to a platform, because the platform implements whatever policy it is given. If no policy exists, the platform will implement an implicit one.

What to do before buying anything

The sequence that avoids wasted investment is: establish product scope, establish the data model, establish ownership and change triggers, close the evidentiary gaps with suppliers, and only then evaluate platforms against a defined requirement.

A manufacturer that reaches platform evaluation without a data model will find every vendor credible, because there is no requirement to evaluate against. A manufacturer that arrives with a defined data model, a gap register and a set of access rules can ask precise questions — and can tell which vendors understand the problem.

Limitations

  • This article describes data governance principles and does not state legal obligations. Which products are in scope of the ESPR, what a passport must contain and from what date are determined by product-specific measures and should be confirmed against current published requirements.
  • No specific platform, standard or provider is recommended or assessed.
  • The ownership and change-trigger table is our own working model for structuring readiness, not a regulatory requirement or an official data schema.

The next decision

Decide whether your product groups are in scope, and on what timetable — before committing budget to a passport platform.

Discuss your project

Taking this into your own project?

Our scoping guide and worksheet walk through the questions that make a brief usable — the decision, the evidence, the options including doing nothing, and what still has to be established. No email required.

Sources

External sources are referenced above by letter. Our own recommendations are identified as such in the text and are not attributed to these sources.

  1. [I]European Commission — New EU sustainability rules explained: Ecodesign Regulation FAQs (27 September 2024)https://environment.ec.europa.eu/news/new-eu-sustainability-rules-explained-ecodesign-regulation-faqs-2024-09-27_en