Free tier, no card requiredDynamic QR codes that update after printGDPR-compliant scan analyticsBuilt for agencies, freelancers & in-house teamsFree tier, no card requiredDynamic QR codes that update after printGDPR-compliant scan analyticsBuilt for agencies, freelancers & in-house teamsFree tier, no card requiredDynamic QR codes that update after printGDPR-compliant scan analyticsBuilt for agencies, freelancers & in-house teamsFree tier, no card requiredDynamic QR codes that update after printGDPR-compliant scan analyticsBuilt for agencies, freelancers & in-house teams
All posts
A QR code linking to a passport-style document card with a certified checkmark seal.
Explainer

The EU Digital Product Passport: what it means for your agency's QR codes

Does your QR platform make a client DPP-compliant? Almost never. Here's what the EU Digital Product Passport actually requires, which deadlines are confirmed (batteries, February 2027) versus still indicative, and where agencies genuinely add value.

ScanKit

ScanKit · Organization

· 17 min read

Somewhere in the next twelve months, a client in retail, apparel, furniture or electronics is going to ask their agency a version of the same question: does our QR code platform make us compliant with the EU's new Digital Product Passport rules? The honest answer is almost always no, and agencies that answer yes without checking are making a promise on a subject that is not theirs to promise on. This post explains what the Digital Product Passport actually is, which deadlines are real right now versus still provisional, and where an agency's dynamic QR expertise genuinely helps a client, as distinct from where it doesn't.

This is regulatory territory, not marketing territory, so we have been careful to separate confirmed rules from industry rules of thumb throughout. Where a date or requirement is still provisional, we say so.

What the Digital Product Passport actually is

The Digital Product Passport is not, on its own, a law you can be "compliant" or "non-compliant" with. It is a mechanism defined inside the Ecodesign for Sustainable Products Regulation (ESPR), which entered into force on 18 July 2024. ESPR itself does not require any product to carry a passport yet. Instead, it sets up the framework, and each product category only gets a real, enforceable DPP requirement once the European Commission adopts a category-specific delegated act that says so.

That distinction matters because it means "the DPP" is really a growing family of separate, category-by-category rules, not one single deadline. As of mid-2026, exactly one category has a finalised, dated, legally binding requirement: batteries, under a different regulation entirely. Everything else is still in preparation.

A DPP, once it applies to a product, is a structured, registered data record about that product, accessible by scanning or tapping a data carrier attached to it. It typically covers material composition, carbon footprint, repairability, recycled content, and end-of-life instructions, though the exact required fields are set separately for each product category and are not yet finalised for most of them.

The one category with a live deadline: batteries

The EU Battery Regulation ((EU) 2023/1542) is a separate piece of legislation from ESPR, and it is currently the only place agencies will meet a real, dated Digital Product Passport requirement. It entered into force on 17 August 2023, with most provisions applying from 18 February 2024.

Two dates matter for anyone advising a client who sells batteries, or products built around them, into the EU:

  • 18 August 2026: a physical, human-readable label becomes mandatory on batteries (capacity, chemistry, hazardous substances and so on). This is a printed label requirement, not a digital one.
  • 18 February 2027: a QR code becomes mandatory on all batteries covered by the regulation. Separately, and on the same date, a full digital battery passport becomes mandatory, but only for a narrower set of categories: light means of transport (LMT) batteries, industrial batteries over 2 kWh, and electric-vehicle batteries.

That second point is the one agencies most often get wrong when they skim a headline. Every battery in scope gets a QR code from February 2027. Only the larger, higher-value battery categories get a full structured passport behind that code. A consumer AA battery and an EV battery pack both need a QR code, but only the EV pack needs the full passport data behind it.

Five numbered milestones on a timeline, the first four solid and connected, the fifth hollow and dashed to indicate it is not yet binding.
1) ESPR enters into force, 18 July 2024. 2) The DPP Registry goes live, 20 July 2026. 3) Physical battery labelling becomes mandatory, 18 August 2026. 4) QR codes and the full passport become mandatory for batteries, 18 February 2027. 5) Indicative dates for textiles, furniture, tyres and more, not yet binding.

The image above lays out the confirmed and provisional dates in order: ESPR's entry into force, the Digital Product Passport Registry going live, the battery physical-label deadline, the battery QR and passport deadline, and the indicative (not yet binding) dates for the next wave of product categories.

  1. 18 July 2024: ESPR enters into force, establishing the DPP framework (no product requirement yet)
  2. 20 July 2026: the EU's central Digital Product Passport Registry goes live
  3. 18 August 2026: physical battery labelling becomes mandatory
  4. 18 February 2027: QR codes mandatory on all batteries in scope; full digital passport mandatory for LMT, industrial (over 2 kWh) and EV batteries specifically
  5. Indicative, not yet binding: delegated acts for iron and steel expected around 2026, textiles and tyres around 2027, furniture around 2028, mattresses around 2029

What's coming for everything else

In April 2025, the European Commission adopted its first ESPR Working Plan, covering 2025 to 2030. It names the priority product groups for the next round of delegated acts: textiles and apparel, furniture, mattresses, tyres, iron and steel, and aluminium, with electronics and ICT products referenced for later phases.

Treat the dates attached to that plan as indicative, not enforceable. The working plan itself already slipped once, from an original 2024 target to April 2025, and delegated act adoption dates are not the same thing as the date a product must actually carry a passport on shelf; there is normally a transition period after a delegated act is adopted before it applies. If a client asks "when do we need this for our clothing line," the honest answer in mid-2026 is: there is no finalised legal deadline yet, only an indicative Commission timeline that has already moved once.

This is a useful thing for an agency to be able to say plainly to a client. It positions the agency as informed without overstating certainty the regulation itself doesn't have yet.

The passport registry is already live

The clearest, freshest piece of primary evidence agencies can point clients to is that the infrastructure is no longer theoretical. On 20 July 2026, the European Commission announced that the central Digital Product Passport Registry had gone live, along with six published technical standards covering unique identifiers, interoperability, data carriers, APIs, data exchange and storage. The registry already supports textiles, steel and aluminium, tyres, furniture, ICT, energy-related products, large batteries, construction products, toys, and detergents and surfactants, even though most of those categories don't have a binding product requirement yet.

That is a meaningful signal for how agencies should talk to clients: the "when" is still partly open, but the "how" is being built now, and it is being built around structured, registered identifiers, not around whatever QR generator a brand happens to already use for its marketing campaigns.

Why a QR code is not a passport

This is the point worth being blunt about with a client, because it is the one most vendor marketing glosses over. A QR code is a container. The Digital Product Passport is what's supposed to be behind it: a structured, registered data record, tied to a unique product identifier, hosted by an accountable party, and checkable by a regulator. Printing a QR code that opens a nice product page does not create any of that.

For the categories that already have a finalised requirement, generating a compliant passport means the identifier is registered against the DPP Registry, the data itself meets the fields the relevant delegated act specifies, and the hosting party can be traced back to the economic operator legally responsible for the product, meaning the manufacturer, or the importer or authorised representative if the manufacturer sits outside the EU. None of that comes from a QR-generation platform on its own, dynamic or otherwise. It comes from a data-governance and product-documentation project that a QR code merely provides the front door to.

Whoever places the product on the EU market carries the legal responsibility for the accuracy of that data, not any third party they hire to help build the infrastructure. An agency can be part of that project, as a vendor or implementation partner, but it cannot absorb that legal responsibility on a client's behalf, and it shouldn't imply that a redirect service does.

We'd also flag one figure worth avoiding: you may see specific penalty numbers quoted for DPP non-compliance, such as a fixed percentage of turnover. ESPR requires member states to set penalties that are "effective, proportionate and dissuasive," but it leaves the actual figures to national implementation rather than harmonising a single EU-wide number. Any specific euro or percentage figure attributed to ESPR generally, rather than to a specific member state's implementing law, should be treated as unverified.

Agencies that have already read our piece on GS1 Digital Link and Sunrise 2027 will recognise some of this territory, and it's worth being precise about where the two overlap and where they don't, because vendors routinely blur the line.

GS1 Sunrise 2027 is an industry-led initiative aimed at getting retail point-of-sale scanners worldwide able to read 2D barcodes, including QR codes, by the end of 2027. It is not an EU regulation, and it exists independently of the Digital Product Passport.

GS1 Digital Link is a technical standard for encoding a product's identifiers into a resolvable web link. GS1 itself describes its Digital Product Passport work as a provisional standard, meaning it is a strong, widely backed candidate for the technical layer under DPP implementations, not something the EU has formally mandated as the only acceptable format. Most delegated acts haven't finalised their data-carrier requirements yet, so no single carrier technology is locked in across categories.

The practical distinction for a client conversation: Sunrise 2027 is about whether a checkout scanner can read a 2D code at all. The Digital Product Passport is about whether a specific product has a legally required, structured, registered data record behind whatever code sits on it. A product can be fully Sunrise-2027-ready and still not be anywhere close to DPP-compliant, and the reverse is possible too, at least in principle.

Can you reuse a client's existing marketing QR code?

Not as it stands, in almost every real case. A generic dynamic QR code pointing at a campaign landing page is built for a completely different job: changing a destination without reprinting, tracking scans, running A/B tests, feeding UTM parameters into analytics. None of that overlaps with what a DPP data carrier needs to do, which is resolve to a registered, structured, accountable data source recognised by the DPP Registry.

There is a version of this that could technically converge: a QR code built on GS1 Digital Link syntax can, in principle, encode multiple link types, one of which could resolve to compliance data and another to a marketing experience, all from a single physical code. But getting there requires building the compliance-grade data infrastructure first. Restructuring the code is the easy 5% of that project; registering the identifier, populating the required fields correctly, and taking on the hosting obligations is the other 95%. An agency that leads with "we can just repoint your existing QR code" is offering the easy part and implying the hard part is already solved.

Where agencies genuinely add value

None of this means agencies should stay out of DPP work. There is real, legitimate value an agency can offer, it just isn't "our platform makes you compliant."

  • Client education. Being the one who can explain the difference between a battery QR mandate, an ESPR working-plan date, and Sunrise 2027 is worth more to a client relationship than most agencies realise, precisely because so much vendor content conflates the three.
  • The consumer-facing layer. Once a client's compliance team (or a specialist DPP vendor) has built the registered data record, an agency is well placed to design the human-facing experience around it: what a shopper actually sees and does when they scan, how the compliance data sits alongside brand storytelling, care instructions or a warranty flow.
  • Campaign attribution that sits next to, not inside, the passport. A client's DPP carrier and their marketing QR strategy can coexist on the same packaging without being the same code; the agency's job is the second one, done well, and clearly scoped apart from the first.
  • Timeline literacy. Being able to tell a client honestly which deadlines are locked (batteries, February 2027) and which are indicative and have already slipped once (the wider ESPR categories) is a service in itself, and it's worth pricing as part of the engagement rather than giving away as a free add-on to a QR contract.

What not to promise a client

A short list worth keeping visible internally before any client conversation about this:

  • Don't describe any QR or dynamic-link product as "DPP-compliant" on its own. Compliance is a data-governance outcome, not a feature of a code generator.
  • Don't quote specific penalty figures for ESPR non-compliance as though they were EU-wide and finalised; they are set by member states.
  • Don't tell a client a category deadline is fixed when it's still an indicative Commission working-plan date, particularly for anything outside batteries.
  • Don't take on, or imply you're taking on, the legal responsibility for the accuracy of passport data. That sits with the economic operator who places the product on the EU market, not with a marketing vendor.
  • Do point clients who are actually in scope now, principally battery-adjacent categories, toward a specialist DPP compliance provider or their own legal counsel for the data-governance side, while the agency handles what it's actually good at.

Frequently asked questions

What is the EU Digital Product Passport?

It's a structured, registered digital record about a specific product, accessible via a data carrier such as a QR code, that discloses information like material composition, carbon footprint and repairability. It exists as a mechanism inside the Ecodesign for Sustainable Products Regulation (ESPR) and only becomes a binding requirement for a given product category once the European Commission adopts a delegated act for that category.

When does the Digital Product Passport become mandatory?

It depends entirely on the product category, because each one needs its own delegated act. The only category with a confirmed, binding date so far is batteries, under a separate regulation: 18 February 2027 for the QR code requirement (all batteries in scope) and the full passport (LMT, industrial over 2 kWh, and EV batteries specifically). Other categories, such as textiles and furniture, only have indicative Commission working-plan dates, not finalised legal deadlines.

Is a QR code legally required for a Digital Product Passport?

Not universally. ESPR requires a "data carrier" without mandating one specific technology at the framework level; the carrier requirements are set per product category by delegated act. QR codes, GS1 DataMatrix codes, RFID and NFC are all in use or under consideration depending on the category. The Battery Regulation is the exception with a confirmed QR code mandate specifically, from February 2027.

No. GS1 describes its own Digital Product Passport work as a provisional standard, meaning it's a leading technical candidate, not a confirmed universal mandate. Even where GS1 Digital Link is used as the carrier format, compliance also requires the identifier to be registered, the data fields to meet the relevant category's requirements, and an accountable economic operator behind the record.

Can an agency reuse a client's existing marketing QR code as their DPP carrier?

In practice, no, not without rebuilding the underlying data infrastructure. A standard marketing QR code resolves to a campaign landing page and is optimised for tracking and redirect flexibility. A DPP carrier needs to resolve to a registered, structured, accountable data record recognised by the DPP Registry. The two can theoretically converge on GS1 Digital Link syntax, but only once the compliance-grade data project behind it exists.

Who is legally responsible if a product's passport data is wrong?

The economic operator who places the product on the EU market, meaning the manufacturer, or an EU-based importer or authorised representative if the manufacturer is outside the EU. That responsibility isn't transferred to a third-party platform, vendor or agency that helps build or host the technical solution.

Does the Digital Product Passport apply to companies outside the EU?

Yes, if their products are placed on the EU market. Scope is determined by where the product is sold, not where the manufacturer is headquartered, which is the same logic used across other EU product regulation such as CE marking.

Is GS1 Sunrise 2027 the same thing as the Digital Product Passport deadline?

No, and it's worth being precise with clients about this. Sunrise 2027 is an industry initiative aimed at getting retail checkout scanners able to read 2D barcodes by the end of 2027. It's not an EU regulation and exists independently of the Digital Product Passport, even though both push toward 2D codes and both can use GS1 identifiers.

What penalties apply for not complying with the Digital Product Passport?

ESPR requires member states to set penalties that are effective, proportionate and dissuasive, including at minimum fines and possible exclusion from public procurement, but it leaves the specific amounts to national implementing law rather than fixing one EU-wide figure. Treat any specific percentage or euro amount you see quoted for ESPR generally as unverified unless it's tied to a named member state's own legislation.

The short version

The Digital Product Passport is real, it has one confirmed deadline right now (batteries, 18 February 2027, with a narrower full-passport scope inside that), and the infrastructure behind it, the DPP Registry, went live in July 2026. Everything else, textiles, furniture, tyres and the rest, is still running on indicative Commission dates that have already slipped once. A marketing QR code is not a passport, and an agency's existing dynamic QR platform doesn't become DPP-compliant by association. What agencies can genuinely offer is client education, the consumer-facing experience layered next to a compliant carrier, and honest timeline literacy, scoped and priced as its own service rather than bundled into a QR contract as an unearned promise. If a client raises this in the next planning cycle, start the conversation by pulling up the current ESPR working plan together, not by promising a feature your platform doesn't have.

Share

Keep reading

The EU Digital Product Passport: what it means for your agency's QR codes | ScanKit