The Commission DPP FAQ: what it says, and the three things it leaves out
In December 2025 the Commission published Digital Product Passport: Frequently Asked Questions, thirty-two questions prepared by DG GROW. It is not a legal act, and it says so on page four: the answers do not extend rights or obligations and are not authoritative. Read that way, it is still the most useful non-binding document in this field, because it tells you how the institution writing the delegated acts thinks about the system. This is a reader guide: what each section commits to, and what it quietly leaves out.
The scope trap on page eight
The FAQ covers only the general DPP framework under the Ecodesign Regulation. It explicitly excludes the Batteries Regulation, the Toy Safety Regulation, the Construction Products Regulation and the rest of the sectoral acts.
That exclusion is the single most important sentence in the document, and it is easy to miss. The first passports to become mandatory - battery passports in early 2027 - fall outside the scope of this FAQ. Anything you read here about service providers, back-ups or access rules is written for the ecodesign framework. Apply it to batteries and you will be wrong in ways your customers will notice.
The sentence that legitimises an industry
Question 8, on day-to-day business impact, contains this:
To ease the technical burden on businesses, the DPP framework allows for specialist DPP service providers. These are independent companies that will offer the data hosting and management services needed to host a DPP. For many businesses this will be a straightforward way to ensure compliance, as these providers will handle all technical requirements, including the legally mandated data back-ups, for them.
Two things follow. First, using an external provider is a foreseen route to compliance rather than a workaround. Second, the phrase legally mandated data back-ups is the Commission reading Article 10(4) of the Ecodesign Regulation as an unconditional obligation, and the regulation backs that reading: on placing a product on the market, the economic operator makes available a back-up copy of the passport through a DPP service provider, who is by definition an independent third party. Your own second server does not satisfy it. Someone else’s does.
And, again: not for batteries. The Batteries Regulation contains no back-up obligation and does not know the role of DPP service provider at all.
The timeline, from the Commission rather than from a vendor deck
Question 5 restates the first ESPR working plan. Indicative dates for adopting the rules, not for compliance:
- 2026 - iron and steel
- 2026-2029 - energy-related products
- 2027 - textiles, tyres, aluminium
- 2028 - furniture
- 2029 - mattresses and ICT products
The FAQ is careful about something most summaries get wrong: appearing in the working plan does not make a DPP mandatory for that group. It means the group is queued for a study and an impact assessment, which then decide whether a passport is the right instrument at all and what the binding date is.
Question 4 adds the infrastructure milestones. The registry had a legal deadline of 19 July 2026. Its connection to the EU customs system must be operational within four years of the registry rules entering into force, which the FAQ itself estimates at around 2029. The web portal for consumers is promised for the coming years without a date. The eight JTC 24 standards were expected to be finalised by mid-2026.
The customs date is worth holding on to, because it is the honest answer to the most common scare in this market. Automated checks at the border are not a 2027 event.
What the FAQ tells consumers, and why it matters to you
Questions 12 to 17 are aimed at the public, but three of the answers are product requirements in disguise.
- Access must be free of charge and easy - by scanning the carrier, through the future EU web portal, and on marketplace product pages.
- Personal customer data must not be stored in the passport, general access is anonymous, and consent is the only exception. If your passport template has a field that could hold a customer identity, remove it.
- Some information must be available as a printed paper copy on request. That one appears in the answer about people without smartphones, and it is almost never mentioned in vendor materials.
The technical section is where the FAQ earns its keep
Questions 18 to 27 are the closest thing to an architecture statement the Commission has published.
- Hybrid architecture, deliberately. The registry holds identifiers and pointers. The data stays with the economic operator or its service provider. This is a design decision, not a transitional stage.
- Eight standards, eight areas: identifiers for products, operators and facilities; data carriers and the physical-to-digital link; access rights, security and data protection; interoperability; data processing and exchange; storage, archiving and persistence; authentication, reliability and integrity; and APIs for lifecycle management.
- Voluntary data points are allowed provided they do not compromise accuracy or interoperability and are clearly distinguished from mandatory ones. That is a user interface requirement, and most tools currently fail it.
- One identifier, one official passport. Each product at model, batch or item level links through the carrier to a single globally unique identifier, which connects to one official passport. Duplicates are what the registry exists to prevent.
- No universal third-party certification of passport data today, although delegated acts may require it for specific data points.
- The data carrier is decided per product group. QR and NFC are both under assessment by JTC 24. Nobody can promise you today that a QR code will always be enough.
Enforcement: who actually comes after you
Questions 30 to 32 divide the work. Market surveillance authorities in each Member State verify accuracy as part of ordinary enforcement. Customs check at the border, using the registry, once the connection exists. Penalties are set nationally and must be effective, proportionate and dissuasive, and they reach online platforms as well as manufacturers.
The part that gets least attention is private enforcement: consumers have a right to compensation for damage caused by non-compliant products, and manufacturers must provide a complaints channel. That is a second, slower pressure that does not depend on any authority deciding to inspect you.
Three things the FAQ does not say
Reading it against the registry rulebook, three gaps stand out, and all three are commercial rather than technical.
- Nothing about the list of verified service providers. Implementing Regulation (EU) 2026/1778 makes that list a component of the registry, but neither the FAQ nor the regulation states that it will be public or searchable. The Commission helpdesk confirmed to us on 17 August 2026 that no list and no recognition procedure exist yet, and that the criteria are expected in a delegated act around the second quarter of 2027.
- Nothing about registering on behalf of a client. That mechanism exists in Article 19(4) of the registry rulebook, requires the intermediary to be verified itself, and is absent from the registry interface today.
- Nothing about the API beyond listing it as one of the eight standardisation areas. The registry rulebook requires an API; the helpdesk told us it is scheduled for the fourth quarter of 2026.
How to use this document
Treat the FAQ as a statement of intent from the people drafting the rules, not as a source of obligations. When it agrees with the regulation, quote the regulation. When it goes further than the regulation - as it does on back-ups - check the article yourself before you build a product line on it. And when it is silent, as it is on the whole service-provider framework, assume the answer is not settled rather than that it is favourable.
The document is published by the European Commission under the CC BY 4.0 licence, which is why we can quote it at length here. The Polish version of this article translates the whole set of thirty-two answers.
FAQ
Is the Commission FAQ legally binding?
No. It states on page four that it is not the Commission official position and does not extend rights or obligations.
Does it cover battery passports?
No. It explicitly excludes the Batteries Regulation and other sectoral acts, even though battery passports come first.
Does it confirm that back-ups are mandatory?
It reads Article 10(4) of the Ecodesign Regulation that way, and the article text supports it - for passports required under that regulation.
When will customs check passports automatically?
The FAQ estimates around 2029, four years after the registry rules entered into force.
Can I republish or translate the FAQ?
Yes, under CC BY 4.0, with attribution and an indication of any changes.