Fourteen questions that tell you whether a DPP provider actually meets the standards

By Łukasz Głuch · 28 August 2026 · DPPera

DPPera - Due diligence: Check your provider

Full disclosure before anything else: we sell product passports. You should read what follows knowing that, and you should notice that every test below is one you can run against us too. That is the point. The harmonised standards turned a lot of vague marketing into checkable properties, and the checks do not require a lawyer.

The thirty second test

1. Scan a passport your prospective provider already hosts. Does it open in the browser, with no app and no login?

This is the one to do first, because you can do it yourself on a phone before any sales call. Two of the standards independently require that a consumer reaches the public part of a passport without registering, without downloading dedicated software and without credentials. Browsers, phone cameras and ordinary web protocols do not count as extra software. A dedicated app does.

If a provider hands you an app to read a passport, the conversation can end there.

Questions about leaving

2. If I leave, do my printed codes keep working?

Printed codes contain a domain. If that domain is your provider’s and they stop serving your paths, every label you printed goes dead - even though the identifier inside it is still yours. Ask specifically about redirects, not about data export.

A good answer names a period and puts it in the contract. A bad answer talks about how easy the export is, which is a different question.

3. Can I take the identifier with me?

The standards are explicit that the identifier must not create dependence on one supplier. Ask who owns the identifier scheme and whether it can be pointed elsewhere.

4. What happens to my passports if my company stops trading?

Persistence beyond the manufacturer is a requirement, not a courtesy. A provider should be able to describe what happens and who takes over serving the passport.

5. What happens to my passports if you stop trading?

Fewer providers have a good answer to this one. There is no shame in "we are working on it" - there is a problem with "that will not happen".

Questions about the data

6. Is there a machine readable version at the same address?

Storage has to allow both a human readable and a machine readable form to be produced. Ask for a JSON output and check it exists. Authorities and marketplaces will want it even if you do not.

7. Can I download the attached documents, or only view them?

Attached documentation has to be in a form that can be downloaded and saved on a device. A viewer that only renders in a browser does not satisfy it.

8. Can you show me the passport as it was on a given date?

Archived versions have to be retrievable for a point in time. If the provider only keeps the current state, they have no archive - they have a database.

9. How many independent copies of the archive exist, and where?

Archived versions are expected to sit with both the provider and a backup, on infrastructure that does not fail together. "We have backups" is not an answer to this; ask what fails independently of what.

Questions about the identifier

10. Which identification scheme does my passport use?

The recognised schemes are a closed list. A provider generating a random string of their own invention is outside it. The answer should name a scheme, not describe a format.

11. What happens if I need to move from batch level to item level?

The level is fixed once a product is on the market, and a change requires a new identifier linked to the old one. A provider who says "we can just change a setting" either has a decentralised identifier scheme, in which case ask them to explain it, or has not read the standard.

Two questions the registry itself just handed us

These two come from logging in to the Commission registry on 17 August 2026 and from the answer the DPP helpdesk sent the same day. Neither question existed in this form a month ago, which is exactly why the answers are informative.

13. What is the exact URL you will register for my product, and does it answer without a redirect?

The identifier a provider registers is a URL. The registry validates it, and validation rejects excessive redirects and any drop to a less secure protocol. The current build also caps it at fifty characters, a limit the Commission has told us will be raised in a future version because it does not fit every GS1 Digital Link form.

A good answer shows you the actual string, on the provider domain or yours, served directly over https. A red flag is a passport address that travels through a www host or a marketing domain before landing, or a provider who has never thought about the length at all. Redirect chains are not a style question here. They are a validation failure waiting to happen, on an identifier you cannot change afterwards without registering a new one.

14. Does the QR code on my product encode exactly the address you registered?

The data carrier is supposed to encode the unique product identifier. If the label points somewhere else, an inspector scanning the product gets an address that is not in the registry. Ask to see the two strings side by side. Providers who generate labels and registry entries in separate systems often cannot show you that, and that inability is the answer.

The question about honesty

12. Which specific requirements does your compliance claim cover?

This one separates the careful from the confident. Each harmonised standard carries an annex mapping its clauses to specific articles of the regulation - and a large share of the entries are marked as not applicable. No single standard delivers "ESPR compliance".

A provider claiming their product is "fully ESPR compliant" is either simplifying for marketing or has not looked. A good answer sounds like: compliance is built in layers, here is which standard covers which part, and here is what is not covered yet because the standards are not published.

The presumption also only holds while the standard stays cited in the Official Journal, which is a thing to monitor rather than assume.

Two more, if you have the patience

Accessibility. Data carriers must not limit accessibility, and the reference points at the European accessibility standard for ICT. In practice that means the passport page should meet ordinary web accessibility expectations. Open one with a screen reader for two minutes. Very few vendors have done this.

Print quality. Ask what quiet zone their generated codes use and what module size they recommend for your label. If the answer is a shrug, their codes will scan in a demo and fail on a real garment tag.

How to use this

You will not get fourteen good answers from anyone, including us. That is not the bar. The bar is whether the provider knows which ones they fail and says so without being cornered.

A supplier who answers "we do not do that yet, here is when" is telling you the truth about the rest of their answers too. A supplier who answers everything perfectly and instantly has probably not read the standards, because anybody who has read them knows how much is still open.

FAQ

Do I have to buy the standards to check this?

No. Every question above can be asked and evaluated without owning a single standard. That is deliberate.

Is a provider who fails some of these breaking the law?

Not necessarily. The obligation sits with you as the economic operator, not with your supplier. That is exactly why the checks matter: their gaps become your problem.

What if my provider says the standards are voluntary?

They are, formally. Departing from them means proving equivalence yourself, at your own cost, to a market surveillance authority. Ask whether they will do that proving for you.

Which question matters most?

The first one. It takes thirty seconds and it is not negotiable.

Get DPPera Brief - a short monthly monitor of EU DPP regulations. After confirming you get the DPP Readiness Guide plus our reader's guide to the Commission DPP FAQ (PDF). Subscribe here.