Reguly
All articles
Digital Product Passport

Digital Product Passport: run it yourself or outsource?

Oskar Cornelissen, Co-Founder & CLO, Reguly
Oskar Cornelissen
Co-Founder & CLO, Reguly
9 min read Updated July 2026
A digital product passport reached by QR code on the product, operated through an external service provider

Anyone looking at the digital product passport for the first time asks almost the same question: do we have to build and run this ourselves — our own database, our own URLs, our own server? The short answer is no. The longer one is more interesting: for the back-up copy of the product passport the Ecodesign Regulation expressly requires an independent third party. An external service provider is therefore not merely permitted but, on one point, legally envisaged. What you cannot hand over is responsibility for the data.

Legal basis
ESPR — Regulation (EU) 2024/1781
Storage
Economic operator or a third party (Art. 11(c))
Back-up copy
Mandatory via an independent third party (Art. 10(4))
Responsibility
stays with the economic operator (Art. 9(1))
EU registry
to be operated by the Commission from 19 July 2026 (Art. 13)
Application
per product group via delegated acts

May a third-party provider operate the digital product passport?

Yes, and the regulation says so in as many words. Article 11(c) ESPR provides: “the digital product passport shall be stored by the economic operator responsible for its creation or by digital product passport service providers.” The “or” is the decisive part. There is no obligation to run it in-house, no requirement for your own infrastructure and no preference for large companies with their own IT.

The legislator has therefore deliberately opened the market for operators. That is not a footnote but the precondition for the rules remaining implementable for small and medium-sized companies at all: a manufacturer with 300 articles would otherwise have to provide permanently available, standards-compliant web infrastructure maintained over years, on its own.

The back-up copy with an independent third party is mandatory

Here the regulation departs from what many articles on the subject say. Article 10(4) ESPR does not formulate an option but an obligation: the economic operator shall, when placing the product on the market, make available a back-up copy of the digital product passport through a digital product passport service provider.

This obligation reappears in two further places so that nobody overlooks it. Article 27(1)(c) takes it into the manufacturer obligations: before placing on the market there has to be a product passport “and a back-up copy of its current version” stored by an independent third-party service provider. Article 29(2)(c) requires the same of importers. And Annex III(l) prescribes that the reference to that very service provider is itself part of the product passport.

A common misunderstanding

Many overviews write that third-party providers are “permitted”. That understates the text of the regulation. Anyone hosting the product passport entirely themselves and lodging no back-up copy with an independent third party does not satisfy Article 10(4) — not even if their own solution runs flawlessly. “Independent” here means: not the economic operator itself.

Why does the ESPR require a second copy?

The reason sits in Article 11(e). The product passport has to remain available for the period laid down in the delegated acts — including “after an insolvency, a liquidation or a cessation of activity in the Union of the economic operator”. A product passport that disappears along with the manufacturer would be worthless to repairers, recyclers and market surveillance. How long that period is is set by the respective delegated act; under Article 9(2)(i) it has to correspond at least to the expected lifetime of the product.

What you hand to a service provider — and what you do not

Transferable to the service provider

  • Storage and permanent provision of the product passport (Art. 11(c))
  • Back-up copy of the current version (Art. 10(4))
  • Data carrier and QR code per the required standards (Art. 10(1))
  • Interoperable, machine-readable provision via open standards
  • Technically implementing access rights per group of actors (Art. 11(b) and (f))
  • Linking a new passport with the original one (Art. 11(d))

Stays with the economic operator

  • Accuracy, completeness and currency of the data (Art. 9(1))
  • That a product passport exists at all before the product goes on the market
  • Uploading the data to the EU registry (Art. 13(4))
  • The digital copy of the data carrier for retailers and marketplaces, within five working days (Art. 10(3))
  • Selecting a service provider that actually meets the requirements
  • The manufacturer or importer obligations as a whole (Art. 27, Art. 29)

The service provider may not use the data for itself

Outsourcing does not mean giving the data away. An independent third-party service provider may only store and process it to the extent agreed — reusing it for its own purposes is in principle barred. For your selection process that means: the scope belongs in the contract, not in a verbal assurance.

The dividing line therefore runs between technology and content. You may outsource operations entirely. Liability for the content you may not: Article 9(1) requires the data in the product passport to be “accurate, complete and up to date” — and it addresses the economic operator, not its service provider.

What the EU registry actually stores

Here too a simplification persists: that the registry is merely a directory pointing to the storage location. The wording is more cautious. Under Article 13(1) the Commission stores there “at least the unique product identifiers”; for goods released for free circulation additionally the commodity code. Paragraph 2 expressly empowers the Commission to specify in the delegated acts which further data is not only to be included in the digital product passport but also stored in the registry.

The scope is therefore not conclusively settled but grows with the acts for each product group. Two things are certain: the registry is not where your product passport lives — that sits with the economic operator or the service provider. And the upload of the registry data is owed under Article 13(4) by the economic operator placing the product on the market.

Cut-off date 19 July 2026

Article 13(1) obliges the Commission to set up the registry by 19 July 2026. No immediate obligation arises from that for companies — your own obligations only begin with the delegated act for your product group.

From when does this apply to my product at all?

The ESPR is a framework, not a directly applicable product rule. Whether and how a digital product passport is required for your products only follows from the delegated act for the relevant product group. Under Article 9(2) it determines, among other things, which data has to be included, which data carrier is to be used, whether the passport is created at model, batch or item level, who has access, who may create and update data and how long the passport has to remain available.

Under Article 9(4) the Commission can even exempt product groups — for instance where technical specifications are missing or other Union law already provides an equivalent system. Anyone planning today is therefore well advised to plan the data basis, not the cut-off date: you will need the information a product passport later demands in any case.

What to look for when choosing a provider

Because the regulation opens up operations, a market for DPP platforms is emerging. The selection criteria are mostly in the text of the regulation itself — knowing them means you do not have to rely on marketing promises.

  • No vendor lock-in: Article 10(1)(d) requires open standards and an interoperable format that can be transferred “without vendor lock-in”. Ask to be shown what a complete export looks like.
  • Standards-compliant identifiers: data carriers and unique product identifiers have to comply with the standards named in Annex III — in practice the ISO/IEC 15459 family and the GS1 standards built on it.
  • Data use limited by contract: under Article 11 third-party service providers may not “sell, reuse or process the data in whole or in part beyond what is necessary for the provision of the relevant storage or processing services”, unless you expressly agree otherwise. Check that the contract reflects this.
  • Demonstrable availability period: the passport has to stay reachable for the period laid down, even if your company no longer is. Ask what happens to the data when the contract ends.
  • Roles and rights: Article 11(f) requires that entry, modification and updating are restricted by access rights. A shared admin login for everyone does not satisfy this.
  • Traceability: Article 11(g) requires authenticity, reliability and integrity of the data. A change log is the practical evidence for that.

The real work comes before the hosting

Engaging a service provider solves operations — not the data. Material composition, recycled content, supplier evidence and identifiers have to come from your company and your supply chain. That is where product passport projects fail, not at the server.

In brief

  • A third-party provider may store and provide the digital product passport — Article 11(c) names it expressly as an alternative to running it yourself.
  • For the back-up copy an independent third-party service provider is even mandatory under Article 10(4), confirmed in Articles 27 and 29.
  • Responsibility for accurate, complete and up-to-date data stays with the economic operator under Article 9(1).
  • The EU registry stores at least the unique product identifiers; the Commission can add further data per product group.
  • When the product passport applies to you is decided by the delegated act for your product group — the data basis is worth building now regardless.

The digital product passport shall be stored by the economic operator responsible for its creation or by digital product passport service providers.

Article 11(c), Regulation (EU) 2024/1781 (ESPR)

Talk to us

A product passport without your own infrastructure

Reguly generates digital product passports from your product and packaging data, issues GS1-compliant QR codes and keeps every change traceable in the audit trail. Talk to us about your product group — we will tell you honestly what is possible today and what is waiting on the delegated act.

Arrange a call