Who Is Legally Responsible for a Digital Product Passport?
Executive Summary
The question “who is legally responsible for a Digital Product Passport?” is asked far more often than it is answered precisely, and the imprecision is expensive. It is usually asked in a room where several organisations are already involved: a manufacturer, one or more suppliers, an importer, a distributor, a technology provider hosting the data, and increasingly an online marketplace listing the product. Each of those parties does something real. Only some of them may carry a legal obligation.
The central point of this article is a separation that enterprise teams routinely collapse. Who contributes data is not necessarily who is legally responsible. A supplier may provide a recycled content figure. A laboratory may produce a test result. A software provider may publish the passport and operate the resolver. An internal data steward may validate the value before it goes out. None of that activity, by itself, determines who the applicable legislation holds accountable. Legal responsibility normally follows the obligations that the applicable legal framework assigns to a defined economic operator in relation to a product placed or made available on the Union market.
The second separation matters just as much. “Who needs a Digital Product Passport?” is a question about participation in a regulated product ecosystem, and the article of that name answers it. “Who is legally responsible for the applicable obligation?” is a narrower question about statutory accountability. This article answers only the second one.
There is no single universal answer, and any source offering one should be treated with suspicion. Under the current EU framework, the allocation of responsibility depends on the applicable legal instrument, the product concerned, the relevant product-specific requirements, the organisation’s role in placing or making the product available on the market, and, critically, the specific obligation being considered. One organisation can be legally responsible for product conformity, operationally responsible for passport accuracy, contractually protected against supplier error, and dependent on a third party for technical delivery, all at the same time, for the same product.
This article introduces the DPP Legal Responsibility Model, a tieback educational model that places the applicable obligation at the centre and arranges the surrounding roles by the kind of responsibility they typically carry. It is a reasoning tool for mapping roles. It is not a statement of law, and it does not determine the position of any particular organisation.
- Legal responsibility is allocated by the applicable legislation to defined economic operators, not by who holds the data, who built the system, or who does the work. - “Who needs a DPP” and “who is legally responsible for the applicable obligation” are different questions with different answers. - Responsibility varies by obligation as well as by entity: conformity, information, availability, accuracy, identification, documentation, evidence, access, cooperation and corrective action can sit differently. - Manufacturers commonly carry the widest set of obligations under the current framework, but the actual set always depends on the instrument and the product-specific measure. - Importers and distributors carry their own distinct obligations rather than inheriting or replacing the manufacturer’s. - An authorised representative acts on a written mandate and covers only obligations capable of delegation under the applicable legislation. - Online marketplaces and fulfilment service providers may have specific responsibilities under relevant EU legislation, which is not the same as being the responsible economic operator for every passport obligation. - Suppliers and technology providers can carry substantial contractual and operational responsibility without becoming the statutorily responsible operator. - Contracts, internal RACI charts and data ownership models allocate responsibility inside and between organisations. They do not rewrite the external legal allocation.
This is the sixth article in the Regulations section, and the second in a three-part sequence on the back half of the regulatory journey. It follows How Digital Product Passports Will Be Enforced, which explains what authorities may do. This article explains who they may look to.
A role-based educational model of how legal responsibility for Digital Product Passport obligations is allocated. It places the applicable DPP obligation at the centre, defined by the applicable instrument, the product-specific measure, the product and the market, and arranges surrounding roles in three bands: an inner band of potential legal accountability containing manufacturer, importer, distributor and authorised representative where the applicable definition is met; a middle band of role-dependent responsibility containing online marketplaces and fulfilment service providers, whose duties arise under specific provisions of relevant EU legislation rather than automatically; and an outer band of contributing and supporting roles containing suppliers and upstream contributors, laboratories and evidence providers, and technology and service providers, which normally carry contractual, operational or service responsibility rather than statutory product responsibility. A separate authority interaction band records that market surveillance authorities engage with the operators the applicable legislation identifies. A responsibility lens separates five distinct kinds of responsibility: legal, created by applicable law and owed externally; contractual, created by agreement and owed to a counterparty; operational, assigned internally to perform the work; data, domain accountability inside the enterprise; and technical, responsibility for the systems that deliver and publish the passport. The model holds that outer bands move inward only where the applicable legislation defines the party as a responsible operator, and that contractual, operational, data and technical responsibility never rewrite the legal allocation. It further treats responsibility as a property of the pairing between an entity and a specific obligation rather than of the entity alone, using illustrative obligation categories including product conformity, required product information, DPP availability, DPP accuracy, product identification, technical documentation, evidence, information access, cooperation with authorities, corrective action and record retention. No EU instrument defines this model and it does not determine the position of any organisation, product or transaction. It narrows the ecosystem participation lens of the DPP Responsibility Model TBF-002 to statutory accountability, supplies the operator dimension that the DPP Enforcement Lifecycle TBF-038 assumes when authorities assess compliance, explains why supplier contribution under the Supplier DPP Readiness Model TBF-032 does not equal statutory responsibility, distinguishes the internal decision authority of the DPP Programme Governance Model TBF-037 from external legal accountability, and records that Product Data Governance TBF-023 and Product Data Stewardship TBF-026 determine internal ownership and control without redefining legal operator responsibilities.
Educational scope
This article provides general educational information about EU product regulation concepts. It does not determine the legal responsibilities of any particular organisation, product, contract or transaction, and it is not legal advice. Role classification under the applicable legislation is a legal question that depends on specific facts.
Table of Contents
- Definition
- Who Needs a DPP vs Who Is Legally Responsible?
- The DPP Legal Responsibility Model
- Why Responsibility Depends on the Applicable Law
- Manufacturer Responsibilities
- Importer Responsibilities
- Distributor Responsibilities
- Authorised Representatives
- Online Marketplaces
- Fulfilment Service Providers
- Suppliers and Upstream Contributors
- Technology and Service Providers
- The Role Responsibility Matrix
- Legal vs Contractual Responsibility
- Legal vs Operational Responsibility
- Legal Responsibility vs Data Ownership
- Responsibility by Obligation
- Building an Economic Operator Role Map
- When Supplier Data Is Wrong
- When a Technology Provider Makes an Error
- Changing Roles Across Markets and Distribution Models
- Interaction With Market Surveillance Authorities
- Practical Example
- Common Mistakes
- Frequently Asked Questions
- Key Takeaways
- Related Articles
- Related Glossary Terms
- References
- About This Article
Definition
The obligation, imposed by applicable EU or national law on a defined economic operator in relation to a product placed or made available on the market, to ensure that a specified requirement is met, including requirements relating to product information such as a Digital Product Passport. It attaches to the operator role recognised by the applicable legislation, not to the party that produced, held, hosted or published the underlying data.
Five kinds of responsibility appear in every DPP programme, and confusing them is the single most common cause of the wrong organisation believing it is safe.
Legal responsibility is created by applicable law. It is owed externally, to the legal order and to the authorities that supervise it. It cannot be created or removed by agreement between private parties, although the applicable legislation may itself permit certain obligations to be exercised through a mandated representative.
Contractual responsibility is created by agreement. It is owed to a counterparty. It can allocate cost, effort, warranties, remedies and indemnities between the parties who signed it. It binds only those parties.
Operational responsibility is assigned internally, to make the work happen. It says who collects, validates, approves and publishes. It is real, necessary, and invisible to the legal allocation.
Data ownership, in the enterprise governance sense described in What is Product Data Governance?, is accountability for a data domain inside an organisation. A data owner is accountable to their own organisation for the definition, quality and authoritative sourcing of a domain.
Service responsibility is what a provider owes under its service terms: availability, integrity, performance, security, correct processing of what it was given.
These five can point at five different parties for the same passport field. That is normal. The error is assuming that any one of them answers the others.
Who Needs a DPP vs Who Is Legally Responsible?
Who Needs a Digital Product Passport? answers a participation question. It explains which organisations will be drawn into passport programmes: those whose products fall within scope, and also the wide population of suppliers, distributors, service providers, recyclers and buyers who will be required to contribute to, consume, or operate around a passport even where no obligation attaches to them directly. That is the right lens for planning, for commercial strategy, and for understanding why a company with no direct obligation still ends up doing passport work.
This article uses a narrower lens. It asks which party the applicable legislation holds accountable when a specific obligation is not met. That population is smaller, more precisely defined, and determined by legal role rather than by involvement.
The two questions produce different answers on purpose. A tier-two component supplier may unambiguously need to participate in a passport programme, may hold contractual obligations to supply accurate composition data, and may still not be the economic operator legally responsible for the finished product’s passport obligation. Both statements are true at once. Programmes that treat participation and accountability as synonyms end up either over-assigning legal risk to suppliers who cannot carry it or under-assigning it to the operator who actually holds it.
The DPP Legal Responsibility Model
The DPP Legal Responsibility Model is a tieback educational model. It is role-based rather than sequential: there is no first stage and no last stage, because legal responsibility is not a process. It is an allocation.
The model places the applicable DPP obligation at the centre. Around it sit the parties that typically exist in a real product ecosystem, arranged by the kind of responsibility they usually carry in relation to that obligation. Alongside the map sits a second lens that separates the five kinds of responsibility defined above, so that a role can be read on more than one dimension at once.
No EU instrument defines this model. It does not assign legal responsibility, and the placement of a role in one band rather than another is an educational generalisation, not a determination. Under the applicable legislation, the same organisation may occupy more than one role, and a role that usually carries no statutory obligation may acquire one where the legal conditions for that role are met.
A role map, not a process. The obligation sits at the centre; roles are arranged by the kind of responsibility they typically carry. Placement is educational, not a legal determination.
Defined by the applicable instrument, the product-specific measure, the product and the market. Until this is established, no responsibility question can be answered.
Inner band, potential legal accountability where the definition is met
- Manufacturer
Commonly the widest set of obligations, subject to the applicable measure
- Importer
Distinct obligations on placing a third-country product on the Union market
- Distributor
Due care obligations when making a product available, not passport creation by default
- Authorised representative
Only obligations capable of delegation, only within a written mandate
Middle band, role dependent, only where legally relevant
- Online marketplace
Specific duties under relevant legislation, not automatic operator status
- Fulfilment service provider
Within the economic operator framework only where the legal definition is met
Outer band, contributing and supporting roles, normally not the responsible operator
- Supplier and upstream contributor
Contractual data responsibility, not finished-product accountability by default
- Laboratory and evidence provider
Responsible for the integrity of what it produced, within its own terms
- Technology and service provider
Service responsibility for hosting, publication and delivery
Created by applicable law. Owed externally. Not transferable by private agreement.
Created by agreement. Owed to a counterparty. Allocates cost, effort and remedies.
Assigned internally. Determines who collects, validates, approves and publishes.
Domain accountability inside the enterprise. Definition, quality, authoritative source.
Systems, integration, resolution and publication. Delivery of the passport, not the duty.
Outer bands move inward only where the applicable legislation defines the party as a responsible operator. Contractual, operational, data and technical responsibility never rewrite the legal allocation.
Read the model in two directions. Reading inward, it asks which of the surrounding parties the applicable legislation actually defines as carrying the obligation at the centre. Reading outward, it asks what every other party is doing, under what kind of responsibility, and what happens when that party fails. Most programme failures are visible in the second reading: a critical dependency sits in the outer band with no contractual teeth, no operational owner and no fallback, while the legal exposure remains firmly at the centre.
Why Responsibility Depends on the Applicable Law
There is no free-standing body of Digital Product Passport law that assigns responsibility once, for everyone. Passport obligations are created inside product legislation, and product legislation allocates responsibility using its own definitions.
Under the current EU framework, the Ecodesign for Sustainable Products Regulation establishes the framework under which Digital Product Passport requirements can be set for product groups, with the substantive requirements for a given product group set through delegated acts. Other instruments set their own passport-adjacent or passport-equivalent information duties: Regulation (EU) 2023/1542 on batteries provides for a battery passport, and Regulation (EU) 2024/3110 on construction products provides for a construction product digital product passport system. Regulation (EU) 2019/1020 on market surveillance and compliance of products supplies a cross-cutting economic operator framework for the Union harmonisation legislation it covers, and Decision No 768/2008/EC supplies the reference provisions from which many sectoral operator definitions descend.
Four consequences follow, and they are the reason a single answer does not exist.
Definitions are instrument-specific. Manufacturer, importer, distributor and authorised representative are defined terms. The definitions across instruments in the New Legislative Framework tradition are similar in structure, but they are not guaranteed to be identical in scope or in the obligations attached, and an organisation should read the instrument that actually applies to its product rather than a generic summary.
The obligation is set by the product-specific measure. Whether a passport is required at all, what it must contain, who must make it available, for how long, and to whom, are matters for the delegated act or sectoral regulation, not for the framework alone. Until that measure exists for a product group, responsibility can be planned but not finally determined.
The role is factual, not chosen. An organisation does not select its legal role. The role follows from what it actually does: who manufactures, who places on the Union market, who makes available, under whose name or trademark the product is marketed. A company can be a manufacturer for one product line, an importer for another and a distributor for a third, simultaneously.
The market matters. Roles are assessed per market. The same corporate group can hold different roles in different Member States, and roles under non-EU regimes do not map onto EU definitions.
Framework application is not product obligation
ESPR has applied since 18 July 2024. That establishes the framework. For most product groups the passport obligation itself arrives with the product-specific delegated act. Responsibility planning should begin now; final responsibility determination requires the applicable measure.
Manufacturer Responsibilities
In the New Legislative Framework tradition that shapes most EU product legislation, the manufacturer is the operator that manufactures a product, or has a product designed or manufactured, and markets it under its own name or trademark. Where that definition is met, the manufacturer commonly carries the widest and deepest set of obligations of any operator, because it is the only party positioned to know how the product was designed, what it contains and how it was assessed.
Where the applicable legislation and the relevant product-specific measure so provide, manufacturer obligations commonly include the following.
Product conformity. Ensuring the product is designed and manufactured in accordance with the applicable requirements. This is the substantive obligation from which most of the others follow.
Required information. Ensuring that the information the applicable measure requires is provided, in the required form, accessible to the categories of user the measure specifies.
Technical documentation. Drawing up and keeping the documentation the applicable legislation requires, for the period it requires. A passport is not that documentation, and does not replace it. Further treatment belongs with How to Manage Evidence for Digital Product Passports.
Conformity assessment where applicable. Carrying out or arranging the applicable conformity assessment procedure. Which procedure applies, and whether a third party is involved, depends entirely on the instrument and the product.
Declarations where applicable. Drawing up the declaration the applicable legislation requires and affixing required markings.
Product identification. Ensuring the product carries the identification the measure requires, which for passport regimes typically includes a product identifier and a data carrier linking to the passport.
Passport creation and availability where required. Ensuring the passport exists, is populated and is available in the manner and for the period the applicable measure requires.
Ongoing correctness. Ensuring that required information remains correct for as long as the obligation subsists. This is the obligation most likely to be underestimated. A passport is not a launch artefact. Values that were accurate at placing on the market can become inaccurate when a supplier changes, a specification is revised, a certificate lapses or a component is substituted.
Corrective action and cooperation. Taking the corrective measures the applicable legislation requires where a product is found not to conform, and cooperating with competent authorities.
None of this should be read as a universal list. Two manufacturers of different products under different instruments can hold materially different obligation sets, and a manufacturer outside the Union does not thereby escape the framework: the applicable legislation then typically brings an importer, and in some cases an authorised representative, into the picture.
A useful internal test for manufacturers: for each required passport value, can you name the authoritative source, the evidence behind it, the person who approved it, and the trigger that would make you revisit it? If not, the obligation is held but not operated.
Importer Responsibilities
Under the framework applicable to many product sectors, an importer is an operator established in the Union that places a product from a third country on the Union market. That act, placing on the market, is what creates the role. It is not a shipping function or a customs formality.
Where the applicable legislation so provides, importer obligations may include the following.
Verifying that the manufacturer has fulfilled its obligations. An importer commonly must check, before placing the product on the market, that the applicable conformity assessment has been carried out, that required documentation exists, and that required markings and information are present. This is a verification duty, not a re-performance duty: the importer is not usually required to redo the manufacturer’s assessment.
Checking required identification and information. Where a passport regime applies, this may extend to checking that the required identifier, carrier and passport information are present and accessible as the measure requires.
Not placing non-compliant products on the market. Where an importer considers or has reason to believe a product does not conform, the applicable legislation typically prohibits placing it on the market until it has been brought into conformity.
Its own identification duties. Many instruments require the importer to indicate its name and contact details on the product or its packaging or accompanying documents. Where the passport is the carrier of required information, the measure may extend related duties into the passport.
Record keeping and cooperation. Keeping specified documentation available to authorities for the required period, and cooperating with competent authorities on request.
Corrective action. Taking the corrective measures the applicable legislation requires where a product it has placed on the market is found not to conform, and informing authorities where the legislation requires it.
Two misconceptions need retiring. The first is that an importer inherits the manufacturer’s responsibility when the manufacturer is outside the Union. The importer has its own obligations, which are real and enforceable against it, but they are its own set. The second is that these obligations are procedural. Where a third-country manufacturer cannot or will not supply passport data, the importer’s verification duty becomes the binding constraint on whether the product can lawfully be placed on the market at all.
A separate trap
An importer that markets a product under its own name or trademark, or modifies a product already on the market in a way the applicable legislation treats as significant, may be considered a manufacturer for the purposes of that legislation and assume the corresponding obligations. This is a common and expensive surprise for private-label programmes.
Distributor Responsibilities
A distributor, in the framework tradition, is an operator in the supply chain, other than the manufacturer or importer, that makes a product available on the market. The distributor’s position is different in kind from the manufacturer’s, and the applicable legislation generally reflects that: it is not expected to know how the product was designed or assessed.
Where the applicable legislation so provides, distributor obligations may include the following.
Acting with due care. Distributors are typically required to act with due care in relation to the applicable requirements when making a product available.
Verifying that required markings, documents and information are present. This is usually a presence and completeness check rather than a substantive assessment. Under a passport regime, that may extend to checking that the required carrier and passport are present and accessible.
Ensuring products are accompanied by required information. Including, where applicable, instructions and safety information in the required language, as the applicable measure specifies.
Not making non-compliant products available. Where a distributor considers or has reason to believe a product does not conform, the legislation typically requires it not to make the product available until conformity is restored.
Storage and transport conditions. Where the distributor has the product under its responsibility, ensuring conditions do not jeopardise conformity.
Cooperation and corrective action. Cooperating with competent authorities and, where required, taking or supporting corrective measures for products it has made available.
What a distributor is not, by default, is the party responsible for creating the passport. It does not hold the design data, the conformity assessment or the technical documentation, and no general rule transfers passport creation to it. That default changes where the distributor’s own conduct changes its legal role, most obviously where it markets the product under its own name or trademark. Then it may be treated as a manufacturer under the applicable legislation, with the obligation set that follows.
Authorised Representatives
An authorised representative is a natural or legal person established in the Union who has received a written mandate from a manufacturer to act on the manufacturer’s behalf in relation to specified tasks. The concept is frequently misunderstood, and the misunderstanding is usually in the direction of assuming it does more than it does.
Three characteristics define it under the applicable legislation.
It exists only on the basis of a mandate. There is no implied or de facto authorised representative. The mandate is written, it is granted by the manufacturer, and it is accepted by the representative. Its content determines the scope of what the representative may do.
It covers only tasks capable of delegation. The applicable legislation determines which obligations a manufacturer may discharge through a representative. Typically these are administrative and cooperation tasks: keeping the declaration and technical documentation available to authorities, providing information and documentation on a reasoned request, cooperating with competent authorities on action taken in relation to products covered by the mandate. Obligations that go to the substance of the product, such as ensuring the product is designed and manufactured in accordance with applicable requirements, are generally not delegable and remain with the manufacturer.
Appointment does not transfer the manufacturer’s legal position. The manufacturer does not stop being the manufacturer. Where the applicable legislation permits, a representative may act, and may itself become subject to obligations and to enforcement in relation to the mandated tasks. That is an addition to the picture, not a substitution.
For passports specifically, whether an authorised representative may create, hold or maintain a passport depends entirely on the applicable legislation and the mandate. It should not be assumed. In practice, a mandate that covers cooperation with authorities but leaves the substance of passport population entirely unaddressed is a common and avoidable gap: the authority has a Union-based contact who cannot answer the substantive question.
Review authorised representative mandates specifically against passport obligations. A mandate written before passport requirements existed almost certainly does not address who maintains required information, who responds to substantive data questions, or what happens when the mandate ends while the passport obligation continues.
Online Marketplaces
Online marketplaces occupy a genuinely difficult position, and the honest summary is that their treatment is instrument-specific, evolving, and not reducible to a single rule.
What can be said with reasonable confidence under the current EU framework is this. Providers of online marketplaces are addressed by several instruments rather than by one. Regulation (EU) 2019/1020 on market surveillance and compliance of products contains provisions concerning information society service providers and cooperation with market surveillance authorities, including in relation to content offering products that do not comply. Regulation (EU) 2023/988 on general product safety places specific obligations on providers of online marketplaces for the products within its scope, including obligations concerning single points of contact, cooperation with authorities, treatment of notices and orders, and information to be displayed in offers. Regulation (EU) 2022/2065, the Digital Services Act, sets horizontal obligations for online platforms allowing consumers to conclude distance contracts with traders, including trader traceability duties.
Three points follow for passports.
Marketplaces may carry duties around information display and access. Where the applicable legislation requires specified information to appear in an offer, or requires certain product information to be accessible before purchase, a marketplace may carry duties in relation to how that appears on its surface. Whether a passport link or specified passport content falls within such a duty depends on the applicable measure.
Marketplaces have cooperation, notice and removal duties under relevant legislation. These are real, and they matter operationally: a passport defect that renders a listing non-compliant can result in the listing being removed or restricted, which is a commercial consequence arriving faster than any regulatory one.
None of that makes the marketplace the responsible economic operator by default. Hosting a listing is not placing the product on the market. Where a marketplace itself acts as manufacturer, importer or distributor for a given product, for instance by selling its own or private-label goods, it holds the corresponding role for those products, and that is a factual question determined per product.
The practical implication for brands is that marketplace channels create a second compliance surface with its own rules and its own enforcement mechanics, layered on top of the product obligation. It is usually a mistake to manage it from the same checklist.
Fulfilment Service Providers
Fulfilment service providers were brought into the economic operator framework by Regulation (EU) 2019/1020 for the Union harmonisation legislation it covers, and the reason was structural rather than punitive: the legislation aimed to ensure there is a responsible operator established in the Union for products sold into the Union, including through direct online channels.
The definition matters more than the label. Under that Regulation, a fulfilment service provider is a party offering, in the course of commercial activity, at least two of warehousing, packaging, addressing and dispatching of products it does not own, with specified exclusions such as postal and parcel delivery services and other freight transport services. A logistics company does not become an economic operator by moving boxes.
Where a fulfilment service provider does fall within the economic operator framework, it may carry specified obligations, which are typically narrower than a manufacturer’s or importer’s and centre on verifying that required documentation is available, cooperating with authorities and providing information on request. Whether such a party is treated as the operator for a specific passport obligation depends on the applicable legislation and the product-specific measure, and it should not be assumed either way.
The practically important consequence is that the framework is designed so that a product does not arrive on the Union market with no Union-established operator answerable for it. If an organisation’s route to market has no manufacturer, importer or authorised representative established in the Union, that is not a gap in the law. It is a signal that the model needs examining.
Suppliers and Upstream Contributors
This is where most enterprise confusion lives, and it deserves stating flatly.
A supplier that provides material composition, component specifications, sustainability data, evidence, declarations or technical records is contributing information that a passport obligation may depend on entirely. That contribution can be commercially critical, contractually enforceable and operationally decisive. It does not, by itself, make the supplier the economic operator legally responsible for the finished product’s passport obligation.
The reason is structural. The applicable legislation attaches obligations to roles defined by conduct in relation to the product placed or made available on the market. A component supplier that sells a component to a manufacturer has not placed the finished product on the Union market. It may of course hold its own obligations for its own products where those products are themselves regulated, and it may itself be a manufacturer of a regulated component. Those are separate obligations for separate products, not the finished product’s obligation.
So there are two distinct responsibility layers, and both are real.
Supplier data responsibility is contractual and operational. It covers accuracy, completeness, timeliness, evidence, notification of change, right to audit and remedies for failure. It is created by the agreement and by the programme, and it is exactly what How to Prepare Suppliers for Digital Product Passports is about: the Supplier DPP Readiness Model exists because supplier capability, not supplier liability, is what determines whether a passport can be populated.
Legal product responsibility is statutory. It sits with the operator the applicable legislation identifies, and it does not move because the data came from somewhere else.
The consequence that organisations dislike is that a manufacturer relying on a supplier remains exposed to the external obligation even where the supplier is entirely at fault. The correct response is not to attempt to push statutory responsibility upstream, which does not work. It is to make the dependency visible: contract for accuracy and evidence, validate what arrives as described in How to Validate Digital Product Passport Data, and record the authoritative source so that a defect can be traced, corrected and explained.
Technology and Service Providers
Technology providers can carry an enormous share of the work. They may host passport data, run publication pipelines, operate resolvers, provide the data platform, build the integrations, automate validation, manage evidence artefacts and deliver the consumer-facing experience described in How Does a Digital Product Passport Work?.
Providing that capability does not normally determine statutory product responsibility. A provider that publishes a value supplied to it has not thereby become the operator that placed the product on the market, and the applicable legislation does not generally allocate product obligations on the basis of who operates the infrastructure.
What a technology provider does carry is service responsibility, and it should be specified with the same seriousness as any other dependency: availability of the passport for the period the obligation requires, integrity of the data in transit and at rest, faithful publication of what was approved, auditability of what changed and when, the ability to correct and republish quickly, and continuity if the relationship ends. That last point is the one most often missed. A passport obligation can outlast a vendor contract by years. Where it does, exit and data portability are compliance controls, not procurement preferences.
A provider can be contractually responsible for publishing accurately what it was given, and for the systems that deliver it. Responsibility for whether the value is true about the product normally sits with the operator the applicable legislation identifies. Confusing publication fidelity with substantive accuracy leaves a real gap that no service agreement closes.
The Role Responsibility Matrix
The matrix below is an educational summary of typical positions under the current EU framework. It is deliberately written in conditional terms. It is not a legal allocation table, it does not apply uniformly across instruments, and it cannot substitute for reading the legislation that applies to a specific product in a specific market.
Read every cell with the qualifier attached. “May”, “where applicable” and “depending on the relevant legislation” are doing real work in this table, and removing them turns a reasoning aid into a false statement of law.
Legal vs Contractual Responsibility
Contracts are the main tool organisations reach for, and they are the right tool used for the wrong purpose more often than any other control in a DPP programme.
Consider a manufacturer that contracts a supplier to provide recycled content data for a component. The contract may require the supplier to provide accurate information, to supply supporting evidence, to update the information when the input material changes, to notify within a defined period, to submit to audit, and to indemnify the manufacturer for defined losses arising from inaccuracy. All of that is enforceable between them, and all of it is worth having.
What the contract does not do is change who the applicable legislation holds accountable for the passport obligation. If the passport carries an incorrect value, the external question remains one for the operator the legislation identifies. Contractual allocation operates alongside the statutory allocation, not on top of it.
Three practical consequences follow.
Indemnity is recovery, not compliance. An indemnity may make the manufacturer financially whole after the fact. It does not make the passport correct, does not answer an authority’s question, and does not discharge the obligation.
Contracts should be written to make compliance possible, not to relocate it. The valuable clauses are the ones that produce accurate data, evidence, change notification, audit rights and response times. Clauses that purport to transfer statutory responsibility are, in the external direction, largely decorative.
Flow-down needs to reach the actual source. A tier-one obligation to supply accurate data is worth little if the tier-one supplier has no equivalent right against tier two, which is where the value frequently originates.
A supplier warrants a recycled content figure and indemnifies the manufacturer for inaccuracy. The figure turns out to be wrong. Contractually, the manufacturer may have a claim, and the supplier may bear the cost of correction and consequential losses under the agreed terms. Under the applicable product legislation, the operator identified by that legislation remains the party answerable for the required information being correct. The two outcomes coexist and neither cancels the other.
Legal vs Operational Responsibility
Operational responsibility is how the work actually happens, and every functioning programme has it, usually in the form of a RACI chart, a set of process owners, or the operating capabilities described in How to Operate a Digital Product Passport Programme.
A data steward may own the validation process for a passport field. A compliance lead may approve exceptions and sign off publication. A supplier manager may chase missing evidence. A technology team may run the publication and correct a failed integration. A category manager may own the commercial relationship with the supplier whose data is late.
None of these assignments changes who the law holds accountable. They are internal allocations of effort and authority, and they are answerable inside the organisation. The distinction matters in two specific moments.
The first is when an internal owner leaves, changes role or is under-resourced. The operational responsibility becomes vacant. The legal responsibility does not, and the organisation is now carrying an unstaffed obligation. This is the most common failure mode in the second year of a programme.
The second is when an authority asks a question. The authority addresses the operator identified by the applicable legislation. That operator must be able to answer, which means the internal allocation has to be able to produce the answer on demand, through the decision routes set out in How to Govern a Digital Product Passport Programme. Internal governance determines who decides internally. It has no bearing on who is accountable externally.
Legal Responsibility vs Data Ownership
Enterprise data governance and statutory accountability use overlapping vocabulary for genuinely different things, and the overlap causes real errors.
In the governance sense described in What is Product Data Governance? and What is Product Data Stewardship?, a data owner is accountable inside the organisation for a data domain: its definition, its quality rules, its authoritative source and its system of record. A steward operates that domain day to day. These roles exist to make data trustworthy. They are indispensable, and a passport programme without them publishes whatever it happens to find.
But an internal data owner is not thereby the legally responsible economic operator, and appointing one does not move accountability anywhere. Two asymmetries make the point.
The legally responsible organisation may depend on data whose authoritative source sits outside it entirely, in a supplier’s system, in a laboratory report or in an upstream registry. Its accountability is unaffected by the fact that it does not own the source.
Conversely, an organisation may own a data domain with great rigour and hold no statutory responsibility for the product at all, which is the ordinary position of a component supplier with a mature data function.
The correct reading is that data governance is how the legally responsible operator becomes capable of meeting its obligation. It is a means, not a reallocation.
Responsibility by Obligation
Treating responsibility purely as a property of entities is the deeper modelling error. Responsibility is a property of the pairing between an entity and an obligation. Splitting it by obligation is what turns a vague sense of exposure into something a programme can actually manage.
The categories below are illustrative and educational. They are not a statutory list, and which of them exist for a given product depends on the applicable instrument and measure.
Product conformity. Whether the product meets the applicable substantive requirements. Typically the deepest manufacturer obligation, and the one least susceptible to distribution.
Required product information. Whether the specified information exists and is correct in substance.
DPP availability. Whether the passport is accessible in the required manner, to the required categories of user, for the required period. This has a strong technical delivery component and a strong legal component, and they belong to different parties.
DPP accuracy. Whether the published values are true of the product. Usually depends on data whose authoritative source is elsewhere.
Product identification. Whether the required identifier and carrier are present, correct and resolvable.
Technical documentation. Whether the required documentation was drawn up and is retained and available.
Evidence. Whether the substantiating artefacts exist, remain valid and can be produced.
Information access. Whether the specified parties, including authorities where the measure so provides, can obtain what they are entitled to.
Cooperation with authorities. Who must respond, in what language, within what period, and who is the Union-based contact.
Corrective action. Who must act when a defect is found, and who must inform whom.
Record retention. How long records must be kept and by whom, where the applicable legislation so requires.
The reason to split them is that they distribute differently. A single manufacturer might hold conformity, information, documentation and accuracy obligations while an importer independently holds verification, its own identification and cooperation obligations for the same product, while a distributor holds presence-checking obligations, while a technology provider holds no legal obligation but is the sole practical determinant of whether the availability obligation is met on any given day. An entity-level answer conceals all of that. An obligation-level answer exposes the point where the programme is actually fragile.
Building an Economic Operator Role Map
Because the role is factual, per product and per market, an organisation cannot answer the responsibility question once and file it. It has to be determined and maintained. The Role Mapping Record below is an implementation concept from tieback, not a regulatory artefact and not a required submission. No specific tool is implied; a maintained register is what matters, not its format.
Review triggers are the field most often omitted and the one that keeps the record alive. Typical triggers include a new delegated act or amendment for the product group, entry into a new market, a change of route to market, a change of importer or representative, a private-label arrangement, a product modification, a supplier change affecting an authoritative source, and the end or renewal of a mandate or platform contract.
A useful analytical sequence sits behind each row. It is a reading method rather than a second framework:
Each step constrains the next. Skipping any of them produces the confident, unsupportable answers that this article exists to prevent, and skipping the first two produces the most common one of all: a single group-wide statement of responsibility that is wrong in at least one market.
Determine the role before designing the process. Programmes that build passport tooling first and ask about legal role later frequently discover that the entity operating the system is not the entity carrying the obligation, and that the two sit in different countries with different reporting lines.
When Supplier Data Is Wrong
This is the scenario that tests whether the distinctions in this article have actually been absorbed.
A supplier provides a recycled content value for a component. The value is used to populate a passport field. It later emerges that the value was incorrect: the supplier changed input material and did not notify, or the original figure was calculated on a basis that does not match the required methodology.
Five things are true simultaneously, and they belong to different responsibility layers.
The supplier provided the information. That is a factual matter about the origin of the value, and it will be relevant to remediation, to contract and possibly to whether the operator acted reasonably in relying on it.
The relevant economic operator relied on it operationally. Reliance on supplier data is normal and unavoidable. What matters is whether the reliance was governed: was the source authoritative, was the value validated, was the evidence current, was there a change-notification mechanism.
The passport published the resulting claim. The public artefact is now incorrect and, depending on the applicable measure, that may itself be an information non-compliance regardless of cause.
Contractual and operational consequences may follow for the supplier. Remediation, re-submission, corrected evidence, audit, cost recovery under agreed terms, and in serious cases requalification or removal from the approved list.
Authorities may still look to the legally responsible economic operator. Under the applicable legislation, the external obligation attaches to the operator role. The origin of the error may be relevant to how a matter is handled and to proportionality, but it does not automatically relocate the obligation.
The correct sequence of response follows the article on How Digital Product Passports Will Be Enforced: establish the facts, determine whether this is an information defect or a signal of substantive non-compliance in the product, revalidate the evidence, correct the passport, address the source of the error, and record the decision. Correcting the published value first and investigating afterwards is the reflex to resist, because the correction can conceal the more serious question of whether the product actually has the property claimed.
No universal liability determination is possible here. Who ultimately bears what, as between supplier and operator, depends on the contract, the facts, the applicable law and the forum.
When a Technology Provider Makes an Error
A DPP platform publishes an outdated value because an integration failed silently and the passport continued to serve the previous version for six weeks.
Four questions are in play, and the discipline is to keep them separate because they can have four different answers.
Who caused the technical failure? The provider, or the enterprise integration, or a change on either side that was not coordinated. This is a factual and technical question, answerable from logs and change records.
Who owns operational remediation? Usually a shared answer: the provider restores the pipeline, the enterprise revalidates what was published during the affected window, and someone must decide whether any downstream consumer needs to be informed.
Who is contractually liable? Determined by the service agreement: service levels, data integrity warranties, remedies, limitations and exclusions. This may or may not reflect the operational effort each party expended.
Who holds the statutory product obligation? Normally unchanged. The operator identified by the applicable legislation remains the party accountable for the required information being available and correct.
The uncomfortable implication is that an organisation can do everything right internally, be failed by a provider, hold a strong contractual claim, and still be the party answerable externally. That is not a reason to distrust providers. It is a reason to treat detection as a first-class control: silent staleness is more dangerous than visible outage, because an unavailable passport is noticed and a wrong one is not. Assurance practice, covered in How to Test and Assure a Digital Product Passport, exists precisely to find this class of failure before an authority or a customer does.
Changing Roles Across Markets and Distribution Models
Role is a function of conduct, and conduct changes. The following situations change the analysis and should each be a review trigger in the role map.
Non-EU manufacturer with an EU importer. The manufacturer remains the manufacturer for the purposes of the applicable legislation, and the importer acquires its own distinct obligations on placing the product on the Union market. Where the manufacturer cannot supply required passport data, the importer’s verification duty becomes the practical gate.
Authorised representative appointed. Adds a Union-based mandated party for the tasks the applicable legislation allows to be delegated. It does not remove the manufacturer’s non-delegable obligations, and its scope is only what the mandate covers.
Direct-to-consumer sales into the Union. Selling directly, without a Union-established intermediary, does not remove the framework. It raises the question of which party established in the Union is answerable, which is precisely the gap the economic operator provisions of Regulation (EU) 2019/1020 were designed to address for the legislation it covers.
Online marketplace sales. Adds a distinct set of platform-level duties under relevant legislation, alongside the underlying product obligation rather than instead of it.
Distributor selling under its own name or trademark. Where the applicable legislation so provides, a distributor or importer that markets a product under its own name or trademark may be considered a manufacturer and assume the corresponding obligations. Private-label programmes should assume this is the position until confirmed otherwise for the applicable instrument.
Product modification. Where a party modifies a product already placed on the market in a way the applicable legislation treats as significant, it may take on manufacturer obligations for the modified product. Refurbishment, remanufacture and substantial repair models need specific analysis, and their passport implications are frequently unresolved rather than settled.
Group restructuring. Changing which legal entity contracts, imports or invoices can change which entity holds the role, without anyone in the compliance function being told.
Interaction With Market Surveillance Authorities
When an authority engages, it engages with the operator the applicable legislation identifies. Three practical points follow from the responsibility model.
The addressee is determined by role, not by convenience. An authority is not obliged to route its question to whichever party holds the data. It may address the manufacturer, the importer, the authorised representative or another operator as the applicable legislation provides. An organisation that has never determined its role will discover it under time pressure.
The response must be produced by parties in the outer bands. In practice, answering a substantive question about a passport value usually requires the supplier that produced it, the laboratory that tested it, the steward who validated it and the platform that published it. The responsible operator is the party that must assemble that, within the period the request allows. This is why supporting-party response obligations belong in contracts and why the role map records supporting parties explicitly.
Union-based contactability is a structural expectation, not a formality. Much of the economic operator architecture exists so that there is a party established in the Union who can be reached and who must cooperate. Where that party exists on paper but cannot obtain the substance from the wider group, the arrangement fails at exactly the moment it is needed.
Practical Example
A manufacturer established outside the Union produces a consumer product. An EU importer places it on the Union market. Two suppliers provide composition and sustainability data. A technology provider hosts and publishes the passport. A distributor sells to retail. An online marketplace lists the product for direct sale.
The analysis proceeds in order.
1. Product and market. A specific finished product, placed on the market in two Member States and sold in both physical retail and via a marketplace listing. The unit of analysis is the product, in each market.
2. Applicable legal framework. Whether a passport obligation applies depends on the instrument and the product-specific measure covering this product group. Under ESPR, that means the relevant delegated act. Until it exists and applies to this product, the programme is preparation rather than compliance. This step is not skippable, and it is skipped constantly.
3. Role identification. The non-EU producer is the manufacturer where it markets under its own name or trademark. The EU company placing the product on the Union market is the importer. The retail chain making it available is a distributor. If the importer or distributor were to rebrand the product under its own name, that party may be considered a manufacturer for the applicable legislation, which changes the whole analysis.
4. DPP and data responsibilities. Where the applicable measure requires a passport, the manufacturer typically holds creation, content and ongoing correctness obligations. The importer holds its own verification obligations before placing the product on the market, and may hold its own identification and cooperation duties.
5. Supplier contribution. The two suppliers are the authoritative sources for specific values. They hold contractual obligations to provide accurate data and evidence, and to notify change. They are not, on these facts, the operators responsible for the finished product’s passport obligation.
6. Service-provider contribution. The technology provider hosts, publishes and resolves. It holds service responsibility for availability, integrity and faithful publication. It holds no product obligation on these facts.
7. Importer and manufacturer obligations. Both exist, and they are different sets. The importer cannot lawfully place the product on the market if required information or documentation is absent, and that is its own duty rather than a favour to the manufacturer.
8. Distributor obligations. Due care, presence and accessibility checks, not making a non-compliant product available, cooperation, and support for corrective action.
9. Authority interaction. An authority in either Member State may address the importer, as the Union-established operator that placed the product on the market, or other operators as the applicable legislation provides. The importer must be able to obtain substantive answers from the manufacturer and, through it, the suppliers.
Now introduce the error. One supplier provided an incorrect sustainability value, which the passport has been publishing for four months.
Remediation runs: the supplier corrects the value and supplies revised evidence; the enterprise revalidates against the required methodology and determines whether this is an information defect or evidence that the product does not have the property claimed; the passport is corrected and the change recorded with its reason; contractual consequences are pursued under the supply agreement, which may include cost recovery, audit and requalification; and the decision, the basis for it and the parties involved are documented so that the position can be explained later.
Throughout, legal accountability remains determined by the applicable legislation and the operator role, not by the fact that the error originated upstream. Nothing in this example determines the position of any real organisation, and any actual case would require analysis of the applicable instrument, the measure, the contracts and the facts.
Common Mistakes
Hosting, publishing and resolving are service functions. The applicable legislation generally allocates product obligations to operators defined by their relationship to the product on the market, not to the party operating the infrastructure. The provider carries service responsibility; the operator carries the obligation.
A supplier can carry substantial contractual and operational responsibility, and may hold its own statutory obligations for its own products. That is not the same as holding the finished product’s passport obligation, which normally attaches to the operator that placed or made the finished product available on the market.
This is the reverse of the position the framework takes. Precisely because the manufacturer is outside the Union, the importer’s own obligations become the practical mechanism through which the requirement is enforced. Those obligations belong to the importer and are enforceable against it.
Distributors typically carry due care and verification duties rather than creation duties. They do not hold the design data, documentation or conformity assessment. This changes where the distributor’s own conduct, such as marketing under its own name or trademark, changes its legal role.
A representative acts within a written mandate, for tasks the applicable legislation permits to be delegated. The manufacturer remains the manufacturer, and non-delegable obligations stay with it. Appointment adds a mandated party; it does not perform a substitution.
Marketplaces may carry specific duties under relevant legislation concerning listings, information display, cooperation, notices and removal. Those duties are real and separate. They do not make the marketplace the operator responsible for every passport obligation, although a marketplace selling its own or private-label products holds the operator role for those products.
Data ownership is internal accountability for a data domain. Legal accountability is external and is allocated by the applicable legislation to an operator role. The legally responsible operator frequently depends on data it does not own, and organisations with mature data ownership frequently hold no product obligation at all.
Outsourcing collection, validation, hosting or publication moves effort and creates contractual rights. It does not move a statutory obligation, which is created by law rather than by agreement between private parties.
A RACI chart is an internal allocation of effort and decision authority. It is essential for making the work happen and it has no effect on who the law holds accountable. When the accountable person in the chart changes role, the legal obligation does not move with them.
The first is about participation in a passport ecosystem and covers a wide population including suppliers, distributors and service providers. The second is about statutory accountability for a specific obligation and covers a narrower set defined by legal role. Conflating them either over-assigns risk to parties who cannot carry it or leaves the real obligation unowned.
Role is determined per product and per market, based on conduct. A group can be manufacturer in one arrangement, importer in another and distributor in a third, with different entities holding different roles in different Member States, all at the same time.
The framework deliberately differentiates. Manufacturers, importers, distributors, authorised representatives and, where in scope, fulfilment service providers hold different obligation sets matched to their position and their knowledge of the product. Treating them as interchangeable produces both over-compliance and dangerous gaps.
Frequently Asked Questions
Who is legally responsible for a Digital Product Passport?
There is no single universal answer. Under the current EU framework, responsibility is allocated by the applicable legal instrument and the relevant product-specific measure to defined economic operators, based on their role in placing or making the product available on the Union market. In many arrangements the manufacturer carries the widest obligations, with importers and distributors carrying their own distinct duties, but the determination depends on the product, the market, the applicable legislation and the specific obligation in question.
Is the manufacturer always responsible?
Not universally, and not for everything. Where the definition of manufacturer is met, that operator commonly carries the widest set of obligations, including product conformity, required information, documentation and ongoing correctness where the applicable measure so provides. Other operators carry their own obligations independently, and some duties, such as an importer’s verification duty, do not sit with the manufacturer at all.
What responsibility does an importer have?
Where the applicable legislation so provides, an importer placing a third-country product on the Union market may need to verify that the manufacturer has fulfilled applicable obligations, check that required documentation, markings and information are present, refrain from placing non-compliant products on the market, indicate its own details where required, retain documentation, cooperate with authorities and take corrective action for products it placed on the market. These are the importer’s own obligations rather than inherited ones.
Does a distributor have to create the DPP?
Not by default. Distributor duties typically concern due care, verifying that required markings, documents and information are present, not making non-compliant products available, appropriate storage and transport, and cooperation. Creation duties can arise where the distributor’s own conduct changes its legal role, for example by marketing the product under its own name or trademark.
Can an authorised representative be responsible for a DPP?
Only to the extent the applicable legislation permits the relevant tasks to be delegated and the written mandate covers them. Mandates commonly cover keeping documentation available, providing information on a reasoned request and cooperating with authorities. Whether passport creation or maintenance can be mandated depends on the applicable legislation and should not be assumed.
Is a supplier legally responsible if its data is wrong?
A supplier is normally responsible under its contract for the accuracy of what it provided, and it may hold its own statutory obligations for its own products. That is different from holding the finished product’s passport obligation, which normally sits with the operator identified by the applicable legislation. Supplier error can produce significant contractual and commercial consequences without relocating the external obligation.
Is a DPP software provider legally responsible for incorrect information?
Normally not for the product obligation. A provider is typically responsible under its service terms for availability, integrity and publishing faithfully what it was given. Responsibility for whether the value is true of the product usually remains with the operator the applicable legislation identifies.
Can contractual agreements transfer legal responsibility?
Contracts allocate rights and obligations between the parties who sign them and are valuable for securing accuracy, evidence, notification and remedies. They do not rewrite the allocation made by applicable law, which operates externally. An indemnity may allow recovery after the event; it does not discharge a statutory obligation.
What role do online marketplaces have?
Providers of online marketplaces are addressed by several instruments, including provisions on cooperation with market surveillance authorities under Regulation (EU) 2019/1020, specific obligations under Regulation (EU) 2023/988 for products within its scope, and horizontal obligations under Regulation (EU) 2022/2065. These can include single points of contact, cooperation, handling of notices and orders, and information displayed in offers. They do not make the marketplace the responsible economic operator for every passport obligation, though a marketplace selling its own or private-label products holds the operator role for those products.
Who is responsible when the manufacturer is outside the EU?
The manufacturer remains the manufacturer under the applicable legislation, and the framework additionally looks for a party established in the Union that is answerable. Depending on the arrangement and the applicable legislation, that may be an importer, an authorised representative acting under a mandate, or, for the legislation covered by Regulation (EU) 2019/1020, a fulfilment service provider falling within the definition.
Can responsibilities differ by product category?
Yes. Passport requirements for ESPR product groups are set through delegated acts, and other sectors have their own instruments. What must be in a passport, who must make it available and for how long can therefore differ between product groups.
Can responsibilities differ by EU law?
Yes. Operator definitions in the New Legislative Framework tradition are similar in structure across instruments but are not guaranteed to be identical in scope or in the obligations attached. The instrument that applies to the product is the one that determines the allocation.
Who responds to market-surveillance authorities?
The operator the applicable legislation identifies, which in practice is frequently the Union-established party, such as an importer or an authorised representative acting within its mandate. Producing a substantive answer usually requires suppliers, laboratories and technology providers to contribute, which is why response obligations for those parties belong in contracts rather than in goodwill.
Key Takeaways
- Legal responsibility is allocated by the applicable legislation to defined economic operators based on their role in relation to a product on the market, and that role follows conduct rather than choice. - Who contributes data, who hosts it and who publishes it are separate questions from who is legally accountable for it. - Responsibility must be determined per product, per market and per obligation, because it distributes differently across all three. - Manufacturers commonly carry the widest obligations where the definition is met, but importers and distributors carry distinct obligations of their own rather than inherited ones. - An authorised representative acts within a written mandate for delegable tasks only and does not replace the manufacturer. - Online marketplaces and fulfilment service providers may hold specific duties under relevant legislation without being the responsible economic operator for every passport obligation. - Contracts, internal RACI charts and enterprise data ownership are essential for making compliance possible and are incapable of relocating a statutory obligation. - When supplier or provider error causes a passport defect, contractual and operational consequences follow for them while the external obligation normally remains with the operator the law identifies. - A maintained economic operator role map, with explicit review triggers, is the difference between knowing the answer and discovering it during an authority request.
Related Articles
- How Digital Product Passports Will Be Enforced
- How Conformity Assessment Works for Digital Product Passports
- What Are Delegated Acts?
- When Will Digital Product Passports Become Mandatory?
- Digital Product Passport
- Digital Product Passports for Electronics: What Companies Need to Know
- Digital Product Passports for Furniture: What Companies Need to Know
- Digital Product Passports for Steel and Aluminium: What Companies Need to Know
Related Glossary Terms
Definitions of record for the terms used above live in the glossary.
- Digital Product Passport
- Economic Operator
- ESPR
- Delegated Act
- Market Surveillance
- Conformity Assessment
- Product Identifier
- Data Carrier
- Authoritative Source
- System of Record
- Data Governance
- Data Stewardship
- Sustainability Data
- Product Data
- Product Traceability
References
- Regulation (EU) 2024/1781 establishing a framework for the setting of ecodesign requirements for sustainable products, Official Journal of the European Union: https://eur-lex.europa.eu/eli/reg/2024/1781/oj
- Regulation (EU) 2019/1020 on market surveillance and compliance of products, Official Journal of the European Union: https://eur-lex.europa.eu/eli/reg/2019/1020/oj
- Decision No 768/2008/EC on a common framework for the marketing of products, Official Journal of the European Union: https://eur-lex.europa.eu/eli/dec/2008/768/oj
- Regulation (EU) 2023/988 on general product safety, Official Journal of the European Union: https://eur-lex.europa.eu/eli/reg/2023/988/oj
- Regulation (EU) 2022/2065 on a Single Market For Digital Services, Official Journal of the European Union: https://eur-lex.europa.eu/eli/reg/2022/2065/oj
- Regulation (EU) 2023/1542 concerning batteries and waste batteries, Official Journal of the European Union: https://eur-lex.europa.eu/eli/reg/2023/1542/oj
- Regulation (EU) 2024/3110 laying down harmonised rules for the marketing of construction products, Official Journal of the European Union: https://eur-lex.europa.eu/eli/reg/2024/3110/oj
- Regulation (EC) No 765/2008 setting out the requirements for accreditation, Official Journal of the European Union: https://eur-lex.europa.eu/eli/reg/2008/765/oj
- European Commission, market surveillance and product compliance policy pages: https://single-market-economy.ec.europa.eu/single-market/goods/building-blocks/market-surveillance_en
- Treaty on the Functioning of the European Union, Article 290, delegated acts: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A12012E%2FTXT
About This Article
tieback Knowledge is a continuously maintained reference library covering Digital Product Passports, product traceability, product compliance and related regulations. Articles are reviewed regularly as legislation, standards and implementation guidance evolve.
Related Docs
- Regulations
- How Digital Product Passports Will Be Enforced
- What is the Ecodesign for Sustainable Products Regulation (ESPR)?
- What Are Delegated Acts?
- Which Products Will Require a Digital Product Passport?
- When Will Digital Product Passports Become Mandatory?
- Who Needs a Digital Product Passport?
- What Information Does a Digital Product Passport Contain?
- How to Prepare Suppliers for Digital Product Passports
- How to Govern a Digital Product Passport Programme