What Information Does a Digital Product Passport Contain?
Executive Summary
Once an organisation accepts that a Digital Product Passport applies to it, the next question is always the same: what information actually goes inside one? The honest answer has two halves. The framework requirements are settled in law. The exact field lists are not, because they are set product group by product group through delegated acts, most of which are still being drafted.
That is not a reason to wait. Across every published passport regime, every draft delegated act and every standardisation workstream, the same six categories of information recur. This article sets them out as the Product Information Readiness Model, explains where each category typically already exists inside an organisation, which parts realistically have to come from suppliers, and how to judge whether your data is good enough to publish to a regulator, a recycler and a consumer at the same time.
It assumes you have read What is a Digital Product Passport?, which introduces the four layer framework, and Who Needs a Digital Product Passport?, which introduces the Digital Product Passport Responsibility Model. This article is the third step in that path: it fills in Layer 3, the information layer, and shows which of the six responsibility groups supplies each part of it.
- Passport content falls into six categories: identity, composition, compliance, sustainability, lifecycle and supply chain. - Only two things are fixed in law today: the ESPR framework requirements in Regulation (EU) 2024/1781, and the battery passport data set in Regulation (EU) 2023/1542. Everything else arrives per product group through delegated acts. - No product will require all six categories in full. Scope is set by the delegated act for that product group. - Identity, compliance and much of the lifecycle content usually already exists internally, spread across ERP, PIM, PLM and document stores. - Composition, sustainability and upstream supply chain content is where most organisations are genuinely short, and most of it sits with suppliers. - The blocking problem is rarely the absence of data. It is data that exists as a PDF, a spreadsheet or an email, with no owner, no version and no evidence trail. - Readiness can be assessed today, category by category, without knowing the final field list.
Grades each category of passport data by how ready an organisation is to publish it, from already held to not yet obtainable.
Table of Contents
- What the Law Actually Fixes Today
- The Product Information Readiness Model
- The Six Categories in Detail
- Does Every Product Require All of This Information?
- Which Information Comes From Suppliers?
- Which Information Already Exists in ERP, PIM and PLM?
- Common Data Quality Challenges
- How to Assess Your Current Data Readiness
- Common Misconceptions
- Practical Readiness Checklist
- Frequently Asked Questions
- Related Articles
- Related Glossary Terms
- References
- About This Article
- Page Metadata
- Related Docs
What the Law Actually Fixes Today
ESPR establishes the Digital Product Passport as a legal instrument and fixes its framework properties: it must be connected to a persistent product identifier, reachable through a data carrier, based on open standards, interoperable, machine readable, structured and searchable. The specific information a given product must carry, the access rights per user group and the applicable carrier are set in the delegated act for that product group.
Two consequences follow, and they are frequently confused.
First, the framework is binding now. The requirement to identify products persistently, to expose data through an open, non proprietary route, and to keep the record accurate for a defined period does not depend on any delegated act. It applies to whatever the passport eventually contains.
Second, the content is not yet universally defined. The only fully specified passport data set in force is the battery passport under Regulation (EU) 2023/1542, which applies from 18 February 2027 to industrial batteries above 2 kWh, electric vehicle batteries and light means of transport batteries. Construction products follow a separate track under Regulation (EU) 2024/3110. Textiles, iron and steel, aluminium, furniture, tyres and several other groups are named as priorities in the Commission’s 2025 to 2030 ESPR working plan, but their field lists are still in preparation.
The battery passport is the most complete worked example of what regulators consider a full passport data set. It is a reliable guide to the shape and depth of future requirements. It is not a statement of what your product group will be asked for.
The Product Information Readiness Model
A framework that groups Digital Product Passport content into six categories of information, so that an organisation can assess where each category originates, who owns it, and how ready it is to be published, without waiting for a final regulatory field list.
Every passport regime published or drafted so far draws on the same six categories. They differ in which fields they demand and how deeply, not in the kind of information they demand. Grouping the content this way makes the readiness question answerable today.
One record, six categories of information, many contributors and many readers
Product identifier, model, variant, serial number, manufacturer, brand, product category
Materials, components, chemicals, critical raw materials, bill of materials
CE marking, declarations, certifications, conformity assessment, regulatory documentation
Carbon footprint, recycled content, repairability, recyclability, environmental characteristics
Installation, maintenance, repair, software updates, refurbishment, end of life guidance
Country of origin, manufacturing site, supplier information, chain of custody, traceability data
The model maps directly onto the two frameworks introduced earlier in this learning path. All six categories sit inside Layer 3, the information layer, of the Four Layers of a Digital Product Passport. Each category is sourced from a different combination of the six groups in the Digital Product Passport Responsibility Model, which is why data readiness is rarely a single team’s problem.
The Six Categories in Detail
1. Product Identity
Identity is what the rest of the passport hangs from. Without a persistent, unique and resolvable identifier there is nothing for a scan to resolve to, and no way to distinguish one variant from another when a recall, a repair or a market check arrives years later.
Typical content: product identifier, model, variant, serial or batch number, manufacturer identity, brand, and product category or classification.
ESPR requires a unique product identifier, and requires unique operator and facility identifiers where the applicable delegated act says so. In practice this is where GS1 standards are most commonly applied, with a GS1 Digital Link URI encoded in a QR code so that one carrier serves both commercial and regulatory purposes.
Model level, batch level and item level identification produce very different data volumes, different supplier obligations and different system requirements. Changing granularity later means reissuing carriers on physical goods. Decide it first, and decide it per product family rather than for the whole catalogue.
2. Product Composition
Composition describes what the product is made of and what it is made from. It is the category most often missing, because it depends on information held one, two or three tiers upstream.
Typical content: material composition and mass fractions, component breakdown, substances of concern, critical raw materials, and the bill of materials at the level of detail the regulation requires.
The substances of concern element is already grounded in existing law rather than future delegated acts. ESPR requires information allowing the tracking of substances of concern throughout the lifecycle, and the SCIP database obligation under the Waste Framework Directive has required notification of articles containing candidate list substances above 0.1 percent since January 2021. Organisations that have complied with SCIP already hold part of this category.
A garment brand can state the fibre composition on the care label because it is a commercial requirement. It usually cannot state the recycled fraction of that fibre, the country the fibre was spun in, or the chemical finishes applied at the dye house, because none of that was ever requested in a purchase specification.
3. Compliance Information
Compliance information is the evidence that the product may lawfully be placed on the market.
Typical content: CE marking, EU declaration of conformity, test reports, product certifications, the applicable conformity assessment route, and supporting regulatory documentation.
This category is unusual because the data almost always exists. Every product placed on the EU market already has a technical file and a declaration of conformity behind it. The passport work is rarely about creating this information. It is about converting documents into structured, versioned, addressable records that can be exposed selectively to market surveillance authorities and customs.
Attaching a scanned declaration satisfies nobody. A passport is required to be machine readable and searchable. A document with no structured fields cannot be queried, cannot be validated, and cannot be checked automatically at a border.
4. Sustainability Information
Sustainability information is the category the regulation is ultimately aimed at, because it is what makes the circular economy argument actionable.
Typical content: carbon footprint, recycled content, durability and expected lifetime, repairability, recyclability, resource efficiency and other environmental characteristics.
It is also the category with the weakest existing foundations. Sustainability data is frequently held at company level for reporting purposes rather than at product level, calculated annually rather than maintained, and produced by consultants rather than owned by a system. A passport needs it per product, current, and defensible.
Corporate sustainability reporting answers “what did this organisation emit last year”. A passport answers “what is true of this specific product now”. The second cannot be derived from the first.
5. Lifecycle Information
Lifecycle information supports everything that happens to the product after sale, across its product lifecycle.
Typical content: installation guidance, maintenance schedules, repair instructions and spare part availability, software and firmware update information, refurbishment guidance, disassembly instructions and end of life handling.
This category is distinctive in two ways. It is the part most directly useful to consumers and repairers, and it is the only part where the record is expected to change after the product has been sold. That has a governance consequence: someone must own the passport after the launch project has been closed.
A repair technician scanning a unit needs the disassembly sequence and the correct spare part for that specific variant. A recycler at end of life needs to know which fasteners release the battery and which components contain substances requiring separate handling. Neither has any relationship with the brand that published the record.
6. Supply Chain Information
Supply chain information records where the product and its inputs came from, and how that claim can be trusted.
Typical content: country of origin, manufacturing site identity, supplier information, chain of custody records, and traceability data linking the finished product back to its inputs.
The depth required here varies more than in any other category. Some regimes ask only for country of origin. Others, notably where deforestation, forced labour or critical raw materials are in scope, require verifiable chain of custody. Where a delegated act requires facility level identification, this category also carries commercial sensitivity, which is why access rights are set per user group rather than published openly.
Does Every Product Require All of This Information?
No. This is the single most important qualification in this article.
The six categories describe the universe of passport content, not a mandatory checklist. What any given product must carry is determined by the delegated act, or the product specific regulation, covering that product group. A battery passport is deep in composition, sustainability and supply chain content. A textile passport is expected to emphasise composition, durability and recyclability. A construction product passport is anchored in declared performance and conformity.
Three statements can be made with confidence today:
- Every passport requires Product Identity. It is a framework requirement of ESPR, not a product specific one.
- Every passport requires the compliance content already implied by the product’s existing legislation, because that obligation predates the passport.
- Everything beyond that is scoped by the applicable delegated act, and should be treated as likely rather than certain until that act is adopted.
Teams that try to collect everything the six categories could contain generally deliver nothing. The categories are a readiness lens, not a specification. Prioritise by what is confirmed, then by what is difficult to obtain, not by what is easy to collect.
Which Information Comes From Suppliers?
Mapping the categories against the Digital Product Passport Responsibility Model produces a consistent pattern.
Three of the six categories depend materially on parties outside the organisation that carries the legal duty. That is why supplier engagement, not system selection, is the long pole in most passport programmes. Contracts, purchase specifications and onboarding templates take months to change, and the data cannot be requested retroactively for goods already produced.
Ask for composition, origin and recycled content in the format you will eventually need, on new product introductions only, starting now. This costs little, tests your supply base, and reveals which suppliers cannot answer long before a deadline makes it urgent.
Which Information Already Exists in ERP, PIM and PLM?
Most organisations underestimate how much passport relevant product data they already hold. It is rarely missing. It is scattered, and it is not in a publishable state.
A realistic first pass usually finds that identity and compliance are 70 to 90 percent available, lifecycle content exists but sits in manuals rather than fields, and composition, sustainability and upstream supply chain content is the genuine gap.
Which system becomes the source of record matters, but it is a decision you can only make sensibly after you know where each attribute currently lives and who owns it. Mapping first, architecture second.
Common Data Quality Challenges
Availability is not readiness. Six problems recur.
- No single owner. The same attribute exists in three systems with three values and no rule for which one is authoritative.
- Documents instead of data. A certificate exists as a scan. It cannot be validated, queried or partially disclosed.
- No evidence trail. A recycled content figure exists but nothing records who calculated it, when, on what basis, or what supporting document backs it.
- Wrong granularity. Data is held at model level when the obligation is at batch level, or the reverse, so the value cannot be attached to the physical item that was scanned.
- Stale values. Attributes captured once at product launch are never revalidated, while suppliers, materials and processes change underneath them.
- Unstructured units and vocabularies. Weights, materials and country codes recorded as free text cannot be made machine readable without a normalisation exercise nobody has budgeted for.
A passport is a live record with a legally defined retention period. Data that is corrected in a one off project and then left unmanaged will be inaccurate again within a product cycle. The governance layer, not the cleanse, is what keeps it correct.
How to Assess Your Current Data Readiness
A readiness assessment does not require the final regulatory field list. Run it category by category, on a representative product family rather than the whole catalogue.
Pick one representative product family
Choose something commercially significant with a typical supply chain. Whole catalogue assessments stall. One family produces an answer in weeks.
Score each of the six categories
For each category ask four questions: does the data exist, is it structured, is it owned by a named person or system, and is it evidenced. Score each category red, amber or green.
Record where each attribute physically lives
System, table or document location. This exposes duplication and the attributes that exist only in spreadsheets and email.
Separate internal gaps from supplier gaps
Internal gaps are a project. Supplier gaps are a procurement and contracting programme with a much longer lead time, so they must start first.
Common Misconceptions
- “The field list is unknown, so we cannot start.” The categories, the identity requirement and the supplier dependencies are all knowable now. The final field list mostly determines depth, not which categories apply.
- “This is a data problem, so it belongs to IT.” Five of the six categories are owned by compliance, engineering, procurement or sustainability. IT owns the plumbing, not the content.
- “We already publish this on our website.” Marketing attributes are unverified claims. Passport attributes must be evidenced, versioned and machine readable, and are read by regulators.
- “The passport is a document we generate at launch.” Lifecycle and sustainability content changes after sale, and the record must remain accurate for the retention period defined in the applicable act.
- “Suppliers will provide the data when we ask.” Many cannot, because they have never been asked and do not hold it themselves. Discovering that late is the most common cause of programme overrun.
- “More data is safer.” Publishing unverifiable or commercially sensitive content creates liability. Access rights per user group exist precisely because not everything belongs in public view.
Practical Readiness Checklist
- Confirm which product groups you sell into, and which regulation or expected delegated act covers each.
- Decide identification granularity per product family: model, batch or item.
- Confirm you can issue and maintain persistent unique product identifiers at that granularity.
- Score all six categories red, amber or green for one representative product family.
- Map each passport relevant attribute to the system that currently holds it.
- Name an accountable owner for each of the six categories.
- Identify which attributes are documents today and must become structured fields.
- List the attributes that can only come from suppliers, and rank suppliers by risk of being unable to answer.
- Add composition, origin and recycled content requirements to new supplier specifications now.
- Define an evidence rule: every published claim links to a source, a date and a responsible party.
- Define how the record will be updated after sale, and who is accountable once the project closes.
- Reconfirm the assessment against the delegated act for your product group when it is adopted.
Frequently Asked Questions
Is there a single official list of Digital Product Passport data fields?
No. ESPR sets framework requirements and delegates the content to product specific delegated acts. The only fully specified passport data set currently in force is the battery passport under Regulation (EU) 2023/1542. CEN and CENELEC JTC 24 is developing the supporting standards for data exchange and structure.
Will all passport information be publicly visible?
No. ESPR requires access rights to be differentiated by user group. Consumers, repairers, recyclers, notified bodies, customs and market surveillance authorities are expected to see different subsets. Commercially sensitive content, such as detailed composition or facility identity, is generally restricted.
How much of this can we prepare before our delegated act is adopted?
Identification, supplier data collection, evidence discipline and ownership can all be completed in advance, and none of them changes when the field list is published. These are also the items with the longest lead times.
Does existing SCIP or REACH work count towards the passport?
Partly. Substances of concern notified under the SCIP database obligation are directly relevant to the composition category, and organisations that maintain that data properly start from a stronger position. It does not cover the rest of the category.
Who is legally accountable for the accuracy of the information?
The economic operator that places the product on the EU market, even where the underlying data originated with a supplier. This is covered in detail in Who Needs a Digital Product Passport?
Related Articles
- What is a Digital Product Passport?
- Who Needs a Digital Product Passport?
- How Does a Digital Product Passport Work?
- Digital Product Passport
- What Are the Benefits of a Digital Product Passport?
- How Will Digital Product Passports Change Product Compliance?
- What Are Delegated Acts?
- What is the Ecodesign for Sustainable Products Regulation (ESPR)?
Related Glossary Terms
Definitions of record for the terms used above live in the glossary.
- Product Data
- Product Identifier
- Digital Product Passport
- ESPR
- Delegated Act
- Conformity Assessment
- Sustainability Data
- Product Traceability
- Product Lifecycle
- Circular Economy
References
- Regulation (EU) 2024/1781 establishing a framework for the setting of ecodesign requirements for sustainable products (ESPR), Official Journal of the European Union: https://eur-lex.europa.eu/eli/reg/2024/1781/oj
- Regulation (EU) 2023/1542 concerning batteries and waste batteries, Official Journal of the European Union: https://eur-lex.europa.eu/eli/reg/2023/1542/oj
- Regulation (EU) 2024/3110 laying down harmonised rules for the marketing of construction products, Official Journal of the European Union: https://eur-lex.europa.eu/eli/reg/2024/3110/oj
- Directive 2008/98/EC on waste (Waste Framework Directive), basis of the SCIP database obligation: https://eur-lex.europa.eu/eli/dir/2008/98/oj
- European Chemicals Agency, SCIP database: https://echa.europa.eu/scip
- European Commission, ESPR working plan 2025 to 2030: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A52025DC0187
- European Commission, Ecodesign for Sustainable Products Regulation policy pages: https://commission.europa.eu/energy-climate-change-environment/standards-tools-and-labels/products-labelling-rules-and-requirements/ecodesign-sustainable-products-regulation_en
- CEN-CENELEC Joint Technical Committee 24 (JTC 24), Digital Product Passport standardisation work programme: https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/digital-product-passport/
About This Article
tieback Knowledge is a continuously maintained reference library covering Digital Product Passports, product traceability, product compliance and related regulations. Articles are reviewed regularly as legislation, standards and implementation guidance evolve.