Skip to content
InfoDPP Logo
InfoDPP
ESPR knowledge hub
getting-started

How to Create a DPP: Step-by-Step Guide for Manufacturers

Step-by-step Digital Product Passport guide: identifiers, data carriers and ESPR readiness for manufacturers and importers.

· 18 min read · InfoDPP

Editorial update, 16 July 2026: read earlier passages about identifier and data-carrier specifications still being developed in light of Decision (EU) 2026/1736. The references to six horizontal DPP standards are now in the Official Journal; sector-specific requirements and remaining standards are still open, but the status of those six standards is not. What changed →

Editorial update, 20 July 2026: the production DPP Registry, separate testing environment and Economic Operators User Guide are now available. Organisations can begin enrolment, but the guide says successful DPP registration is not yet possible because the battery semantic catalogue has not been defined. Testing requires a separate EU Login, valid organisation data and the same qualified-signature or qualified-seal verification used in production. The published guide covers the interface and JSON/XML file submission, not the Registry API contract.

From Zero to Implementation-Ready: Your DPP Roadmap

You know what a Digital Product Passport (DPP) is. You understand the penalties for non-compliance. Now it’s time for the practical part: how do you actually create one?

This step-by-step guide walks through the reusable parts of a DPP implementation, from selecting a product-identifier scheme to configuring the data carrier that links the physical product to the digital record. It is a readiness workflow, not a substitute for the applicable sector rule: only that rule can determine the mandatory content, granularity, carrier placement and application date for a particular product.

Before You Start: What You Need

Before creating your first DPP, make sure you have:

  • Your product catalogue: a list of all SKUs (stock keeping units) you sell on the EU market
  • Existing product data: catalogue, technical, compliance, supplier and sustainability records relevant to your sector
  • Company data: legal-entity and contact information required by the applicable product law
  • An identifier decision: including ownership, granularity and persistence; GS1/GTIN is one option, not a universal prerequisite
  • Access to product, packaging or label design files: you may need to add a QR code or another data carrier where the applicable rule requires it

Don’t worry if your product data isn’t perfect yet, the guide shows you how to gather and organise it step by step.

Step 1: Choose an Identifier Scheme (GS1/GTIN Is One Option)

The Global Trade Item Number (GTIN) is a widely used product identifier and a practical route for many retail products. It can be used as the anchor linking a physical product to its digital passport, but neither ESPR nor Regulation 2026/1778 makes GS1 membership the universal prerequisite for every DPP.

⚠️ Regulatory note: ESPR uses the ISO/IEC 15459 standard series and permits an “or equivalent” approach. Regulation 2026/1778 requires the Registry to use the product identifier and registration level set by the relevant Union rule; it does not mandate GTIN or GS1. Registering with GS1 is a practical, low-risk option where it suits your products and supply chain, not a universal legal requirement.

What is a GTIN?

A GTIN is a globally unique numeric code that identifies your product. It comes in several formats:

FormatDigitsUse case
GTIN-13 (EAN)13Most common in Europe: consumer products
GTIN-1414Outer cases, shipping cartons
GTIN-12 (UPC)12Common in North America
GTIN-88Small products with limited label space

For retail trade items, GTIN-13 is a common practical choice. The correct identifier and granularity still depend on the product, packaging hierarchy and applicable sector rule.

How to get GTINs

  1. Find your national GS1 office: visit gs1.org/contact and select your country
  2. Apply for a GS1 Company Prefix: this is your unique company code (typically 7–10 digits)
  3. Assign GTINs to your products: you combine your prefix with product-specific numbers
  4. Verify your GTINs: use Verified by GS1 to check validity

How many GTINs do you need?

The applicable product rule determines the required DPP granularity; Regulation 2026/1778 then requires the Registry to use that model, batch or item level:

LevelExample if using a GTIN-based schemeWhen to useExample
Model1 GTIN per product modelWhen the applicable rule uses model-level registration”Blue cotton t-shirt, size M”
Batch1 GTIN + batch/lot numberWhen required by delegated act”Production batch March 2026”
Item1 GTIN + serial numberWhen the rule requires an individual record; Article 77 does so for covered batteries, but does not make GTIN universal”Battery unit SN-2026-04817”

Key ESPR reference: Article 9(1) states that the DPP shall be linked to a “unique product identifier”. Annex III names the ISO/IEC 15459-6 standard, not GTIN or GS1 as a universal legal requirement. A GTIN can be one practical implementation within a compatible identifier scheme. The product-specific rule determines whether registration is at model, batch or item level. Battery Regulation Article 77 requires each covered battery to have a passport linked to its own unique identifier; that passport combines model-level and individual-battery information.

💡 Tip: If you already sell through retailers or on Amazon, you likely already have GTINs (EAN codes). Check your existing barcodes; you may be closer to DPP readiness than you think.

Step 2: Gather Your Product Data

The DPP is only as good as the data behind it. The ESPR framework (Articles 9–12) and product-specific delegated acts define what information must be included.

Common DPP data themes (illustrative: actual fields follow the applicable law)

ESPR Annex III sets a framework list of information that delegated acts may require; it is not a single mandatory dataset for every product. Standalone product frameworks, batteries, detergents, toys and construction products under the CPR, use their own legal bases and datasets or delegated measures. The table below is therefore a planning map of data themes that typically appear once an act is in force, actual required fields depend on the applicable product law.

ThemeTypical contentWhere it usually lives
Product identityProduct name, model, unique product identifier (e.g. GTIN), manufacturer name and addressYour product catalogue
Legal compliance referenceReference to applicable Union law and, where required, the EU Declaration of Conformity or a reference to it: some regimes (e.g. toys Annex VI Part I (h)) only require a mention that the DPP replaces a separate DoC where allowedYour compliance department
Manufacturer infoLegal name, registered address, electronic address; unique operator identifier where the regulation requires it (e.g. detergents Annex VI Part A (b))Company registration
Place of manufactureCountry and, where required, facility: this is part of technical documentation in some regimes but not always part of the DPP minimum (e.g. not mandated by toys Annex VI Part I)Production records
Product compositionMaterials and substances, where required by the applicable actBill of Materials (BOM)
SustainabilityCarbon footprint, recycled content, environmental certifications where mandatedLCA data, supplier certificates
CircularityRecyclability information, disassembly/end-of-life guidance where requiredProduct engineering team
DurabilityExpected lifespan, warranty information where in scopeProduct specifications

⚠️ Always check the applicable regulation. Toys (Reg. (EU) 2025/2509), detergents (Reg. (EU) 2026/405), batteries (Reg. (EU) 2023/1542), construction products under the CPR (Reg. (EU) 2024/3110) and future ESPR delegated acts follow their own sector rules. Do not treat the table above as a single mandatory DPP specification; the CPR delegated implementation layer is still pending.

Category-specific planning themes

Confirmed sectors already have requirements in standalone product laws; future ESPR groups do not yet have final datasets. The lists below deliberately distinguish binding baselines from planning topics.

🔋 Batteries (mandatory from Feb 2027):

  • Item-level passport for each covered battery under Article 77
  • Annex XIII data layers, public, authority, and legitimate-interest access
  • State of health (SoH), capacity, and other durability/performance data
  • Carbon footprint, recycled cobalt/lithium/nickel/lead content, and due-diligence evidence
  • Collection, recycling, and safe-handling information linked to the responsible operator

🧵 Textiles (delegated act indicatively Q3–Q4 2027; DPP application signalled for 2029):

  • No final mandatory DPP dataset is adopted yet
  • Fibre composition, manufacturing traceability, durability, care/repair and environmental information are credible preparation themes from the policy and study work
  • Do not treat a study field or consultation proposal as a legal requirement until the delegated act is adopted

🪑 Furniture (delegated act indicatively 2028; application date not fixed):

  • No final mandatory DPP dataset is adopted yet
  • Materials, substances of concern, durability, repair and disassembly are sensible preparation themes, not confirmed fields

🏗️ Iron, steel and aluminium (DPP application indicatively 2028–2029):

  • No final ESPR DPP dataset is adopted yet
  • Product identity/grade, environmental performance, recycled content and relevant supply-chain evidence are reasonable preparation themes
  • CBAM data may overlap operationally for covered imports, but CBAM and DPP remain separate legal regimes

🧴 Detergents and end-user surfactants (mandatory from 23 September 2029):

  • Model-level DPP for detergents and end-user surfactants under Regulation (EU) 2026/405
  • The content and access layers follow Article 21 and Annex VI; labelling, ingredient and responsible-operator information must be mapped against those provisions
  • Technical-file or emergency-response information should not automatically be presented as public DPP content; access and document duties differ

🧸 Toys (mandatory from 1 Aug 2030):

  • Annex VI Part I passport data under Regulation (EU) 2025/2509
  • References to all Union law the toy complies with (Annex VI Part I (g)) and, where applicable under Article 19(5), a mention that the DPP replaces the EU Declaration of Conformity: the full DoC text lives in the technical documentation under Annex V
  • Chemical and safety information only to the extent required by Annex VI Part I; detailed assessments and test evidence generally remain in the technical documentation unless a provision requires them in the passport
  • Traceability and responsible economic operator data for market surveillance and recalls
  • Safety warnings, instructions, and test evidence aligned with the data carrier on the toy, packaging, or documentation

🏗️ Construction products (separate CPR path; delegated act pending):

  • Article 75 of Regulation (EU) 2024/3110 empowers the Commission to establish the construction DPP system; Article 76 defines the passport information and conditions, while operational implementation depends on delegated measures
  • Article 22(7) requires manufacturers to make the DPP available by 18 months after the Article 75 system act enters into force; the Commission’s current Q2 2027 target is indicative until that act is adopted
  • Performance and conformity information, environmental evidence and technical documentation already used under the CPR are the main preparation layer
  • Regulation 2026/1778 expressly brings CPR passports into the horizontal Registry framework, but it does not set a universal construction-product application date

How to organise your data

Most manufacturers already have 60–80% of the required data scattered across different departments. The challenge is consolidation:

  1. Create a DPP data template: one spreadsheet per product category with all required fields
  2. Assign data owners: who in your organisation is responsible for each data point?
  3. Identify gaps: which fields are empty? What data needs to be collected from suppliers?
  4. Set a data collection timeline: start with your earliest-deadline products
  5. Establish a supplier data workflow: send standardised data requests to your material suppliers

💡 Tip: Organising supplier data now not only prepares you for the DPP, but also builds the foundation for supply chain mapping required by the upcoming Corporate Sustainability Due Diligence Directive (CSDDD), which begins phasing in from 2029.

💡 Tip: An internal pilot can begin with incomplete data because its purpose is to expose gaps. A live passport subject to a legal obligation is different: all mandatory fields must be complete and accurate before the product is placed on the market or put into service.

Step 3: Choose a DPP Platform

You need software to create, host, and manage your Digital Product Passports. The ESPR doesn’t mandate a specific platform, but the technical requirements (Articles 10–12) effectively require a system that can:

  • ✅ Store structured product data in a machine-readable format
  • ✅ Preserve persistent identifiers and resolvable links without assuming that GS1 Digital Link is the only permitted syntax
  • ✅ Make the DPP accessible through the data-carrier mechanism required by the applicable rule
  • ✅ Produce and test the required machine-readable data carrier; QR Code is one implementation, not the universal ESPR format
  • ✅ Support the language or languages required by the applicable product rule and market
  • ✅ Provide role-based access (different data for consumers, authorities, recyclers)
  • ✅ Maintain availability, updates and backup/continuity for the periods and events required by the applicable law

Platform options

OptionProsConsBest for
Self-service SaaS platform (e.g., OriginPass)Fast setup, low cost, automatic compliance updatesLess customisationSMEs, brands with fewer than 10,000 SKUs
Enterprise DPP solutionFull customisation, ERP integration, API accessHigh cost, long implementationLarge manufacturers, 10,000+ SKUs
Custom developmentComplete controlExtremely expensive, regulatory riskOnly if you have a dedicated compliance IT team
Industry consortiumShared costs, sector-specific featuresSlower rollout, less flexibilityTrade associations

What to look for in a DPP platform

  • Identifier flexibility: the platform should support the scheme required for your product; GS1 Digital Link support matters if you choose GTIN/GS1
  • Delegated act coverage: does it support your product category’s specific data requirements?
  • Multi-language support: the platform should support the languages required in the markets where you sell
  • Data export/portability: you must be able to export your data (avoid vendor lock-in)
  • Uptime guarantee: if the DPP endpoint goes down, your products are technically non-compliant
  • GDPR compliance: the platform processes product data that may include supply chain information

Step 4: Create Your First Digital Product Passport

With the identifier scheme selected, data gathered, and platform chosen, it is time to create a pilot DPP.

The process (using a self-service platform)

  1. Log in to your DPP platform and create a new product
  2. Enter or import your product identifier: if you selected GTIN, the platform may express it in a GS1 Digital Link URL
  3. Fill in product data: use the category-specific template
  4. Upload supporting documents: certificates, test reports, Declaration of Conformity
  5. Set access levels: define what consumers, authorities, and recyclers can see
  6. Preview the DPP: verify all data is displayed correctly
  7. Publish: the DPP goes live at its unique URL

Many web-based implementations use a persistent URL. Where the selected scheme is GS1, GS1 Digital Link defines how identifiers such as GTIN can be expressed within that URL. The example below is an implementation pattern, not a universal ESPR payload requirement:

https://dpp.example.com/01/05901234123457

Breaking this down:

  • https://dpp.example.com, the resolver domain (your DPP platform)
  • /01/, GS1 Application Identifier for GTIN
  • 05901234123457, your product’s GTIN (zero-padded to 14 digits in the URL)

For batch-level DPPs, the URL includes the lot number:

https://dpp.example.com/01/05901234123457/10/BATCH2026-03

For item-level DPPs (batteries), it includes the serial number:

https://dpp.example.com/01/05901234123457/21/SN-2026-04817

How it can work: A resolver can keep the identifier link stable while routing users or systems to appropriate resources. Human-readable and machine-readable representations may be exposed through links or HTTP content negotiation. The applicable sector rule and cited DPP standards, not this example, determine the required data and access behaviour.

⚠️ Note: The ESPR does not mandate GS1 Digital Link by name. Six harmonised DPP standards are now cited in the Official Journal, including EN 18219 on unique identifiers and EN 18220 on data carriers. They remain technology-neutral at this level and do not make GS1 mandatory. GS1 Digital Link is a practical web-identifier option where it fits the chosen scheme, not a legal guarantee of conformity by itself.

Step 5: Generate and Apply the Data Carrier

A QR code is one possible physical bridge between your product and its digital passport. ESPR Article 10 defines requirements for the “data carrier”, the scannable element that links the physical item, packaging or documentation to the passport record, as specified by the applicable rule.

Data-carrier decisions to validate

DecisionSafe implementation ruleSource of the binding detail
SymbologyUse the carrier type specified for the product; QR Code and Data Matrix are possible implementationsApplicable sector law and EN 18220
Encoded valueLink the carrier to the unique product identifier and DPP using the prescribed syntaxApplicable sector law and identifier/carrier standards
Size and error correctionSelect these from the chosen symbology, print process, material and scanning distance; ESPR does not set a universal 10 mm minimum or QR error-correction levelTechnical standard, print specification and verified scan tests
DurabilityDesign for the availability and legibility period required for the productApplicable sector law and EN 18220
PlacementConfirm whether the carrier belongs on the product, label, packaging or documentationApplicable sector law; do not infer one universal position from ESPR
Human-readable textFollow the selected identifier and sector labelling rules; a human-readable GTIN is not mandatory where GTIN is not the chosen schemeApplicable sector and identifier rules

Design best practices

  1. Contrast: dark modules on light background; avoid colour QR codes for reliability
  2. Quiet zone: leave at least 4 modules of white space around the QR code
  3. Testing: scan the QR code with at least 3 different smartphone models before printing
  4. Material: for textiles, consider woven labels with QR; for batteries, laser-etched or high-durability print
  5. Placement: visible without opening packaging; adjacent to existing barcodes where possible

Integrating the carrier into your product workflow

Most DPP platforms provide QR codes in multiple formats:

  • SVG: scalable vector for print design software (Adobe Illustrator, Figma)
  • PNG: raster format for web and digital use (300+ DPI for print)
  • PDF: ready-to-print templates for label printers
  • ZPL: Zebra Programming Language for industrial thermal printers
  • API: automated QR generation for integration with your ERP/PLM system

💡 Tip: Don’t wait until your packaging is redesigned. Many manufacturers start with a sticker phase, testing QR-code or data-carrier stickers on existing packaging while a full redesign is planned. Treat this as a readiness approach and confirm the final placement against the sector rule.

Step 6: Test the End-to-End Flow

Before going live with your DPP, conduct thorough testing:

Testing checklist

TestWhat to verifyTool
QR scan testQR code resolves to correct DPP URL3+ smartphone models
Data completenessAll required fields are populatedPlatform validation or ESPR checklist
Language testDPP displays correctly in all relevant EU languagesManual check
Machine readabilityThe required structured representation is accessible to each authorised roleValidator matching the applicable schema
Performance testDPP endpoint remains usable at the expected load; use a project target unless law sets oneBrowser and load-testing tools
Offline carrierQR code or other carrier scans correctly in its intended physical location, not just on screenPrinted or marked sample
Resolver testIf a resolver is used, identifier links remain stable and each declared resource is reachableResolver test tools for the selected scheme

Common pitfalls to avoid

  • Untested carrier size: minimum dimensions depend on symbol density, print quality, surface and scanning distance; test production samples
  • Ephemeral URLs: do not encode session-specific links; use a persistent identifier URL where the chosen architecture relies on a URL
  • Identifier mismatch: ensure the machine-readable value and any required human-readable identifier refer to the same product/granularity
  • Stale data: verify the live DPP reflects your latest product data, not a cached version
  • Missing required language coverage: map language obligations under the applicable sector rule and each market instead of assuming one universal ESPR rule

Step 7: Prepare for the EU DPP Registry

ESPR Article 13 establishes an EU-level DPP Registry, and Regulation 2026/1778 provides its operating framework. The Registry is not a central warehouse for the complete DPP: it records registration data and high-level metadata while the detailed passport stays decentralized with the operator or provider. The production Registry and separate test environment have been accessible since 20 July 2026, but their current scope must be described precisely: organisation enrolment is available, while successful DPP registration is not. The regulation itself enters into force on 6 August.

What the registry will require

Where the product-specific rule makes registration applicable, manufacturers should expect at least:

  • Registration at the required level: model, batch or item; where multiple Union rules apply, the most granular level prevails
  • Verified registrant identity: the economic operator or eligible value-chain actor must use the eIDAS-based verification route in the Regulation and repeat verification before the credential expires or, in any event, before three years have elapsed
  • Registration data and technical checks: the product identifier and other required data are checked for semantic conformity, consistency and granularity; the commodity code is checked where relevant, especially for products intended for release for free circulation. Technical acceptance is not substantive product compliance
  • A versioned audit trail: registration changes are logged and registry data is versioned and time-stamped
  • Interface or API connection: the law requires both channels, but public endpoints, payloads and onboarding instructions must be confirmed in the Commission materials

What to do now

  1. Assign the registrant role: decide which legal entity or eligible actor will register and maintain the verification credential
  2. Map granularity and versions: connect item records to batch/model identifiers where necessary, and preserve an auditable change history
  3. Ask your platform precise questions: can it handle semantic data models, versioning, structured exports, verified registration and API integration when the official contract is available?
  4. Maintain clean, structured data: regardless of the final integration process, your data should be machine-readable from day one
  5. Follow the Commission’s Registry updates: use the DPP Registry page and the relevant product-specific act, not generic claims of “registry readiness”

Step 8: Train Your Team and Establish Processes

DPP is not a one-off project; it is an ongoing compliance obligation. Set up the right processes now:

Who needs training?

RoleWhat they need to know
Product managersHow to fill in DPP data, what each field means, where to source data
Quality/ComplianceESPR requirements, delegated act specifics, audit preparation
ProcurementHow to request DPP-relevant data from suppliers (materials, certifications)
Product/label/packaging designData-carrier placement, sizing, print or marking specifications
IT/ERPPlatform integration, data sync, API connections
Customer serviceHow to explain DPP to customers and B2B partners

Ongoing processes to establish

  1. New product launch → where a DPP obligation applies, complete the required passport and Registry step before placing the product on the market or putting it into service
  2. Relevant product change → assess whether the applicable law requires an update, new version or new identifier
  3. Accuracy review → set a risk-based review cadence and any frequency required by the applicable product law; ESPR does not impose one universal annual review rule
  4. Supplier onboarding → include DPP data requirements in supplier contracts and onboarding checklists
  5. Regulatory monitoring → assign someone to track delegated act updates and Commission publications

Step 9: Scale to Your Full Catalogue

Once your first DPP is live and tested, scale systematically:

Prioritisation strategy

  1. Start with your highest-risk products: closest deadline, highest volume, or products sold in the most EU markets
  2. Then your highest-value products: flagship products where DPP also adds marketing value
  3. Then long-tail SKUs: use bulk import/template features in your platform for efficiency
  4. Finally, custom/made-to-order products: these may need batch-level or item-level DPPs

Scaling tips

  • Bulk CSV/Excel import: most platforms support importing hundreds of products at once
  • ERP integration: connect your enterprise system to auto-populate DPP fields
  • Template products: create one DPP per product family, then clone and adjust per variant
  • Supplier portal: invite suppliers to input their data directly into your DPP platform

Timeline: When to Do What

The dates below separate binding application dates from editorial preparation targets. Preparation dates are project guidance, not legal deadlines.

If your application date is…Suggested project startIdentifier scheme readyPilot target
18 Feb 2027 (battery categories covered by battery passport rules, confirmed)⚠️ NOWAlready doneQ3 2026
2029 (textiles: Commission timeline, indicative)20262027Before the delegated act’s transition period ends
~2028–2029 (iron/steel: Working Plan indicative)Q1 2027Q3 2027Q1 2028
23 September 2029 (detergents, confirmed)Q1 2027Q3 2027Q1 2028
Not yet fixed (furniture; delegated act indicatively 2028)20272028After the draft dataset is available
1 Aug 2030 (toys, confirmed)Q2 2028Q4 2028Q2 2029

The “indicative” rows reflect Commission planning and will become binding only through the relevant adopted act. The “confirmed” rows are application dates already set in sector legislation.

🔴 Critical: If your products fall within Battery Regulation Article 77, the 18 February 2027 application date is close. Identifier onboarding, supplier-data collection, Registry testing and the Article 13 QR-code/marking workflow should be scheduled against your actual vendors and product design; no single lead time applies to every company.

Cost Overview

Illustrative budgeting ranges vary sharply by catalogue size, data maturity, identifier scheme, integration depth and whether environmental studies are needed. They are not regulatory fees or market quotations:

Cost itemRangeNotes
Identifier licensing or issuance€0–500+/yearDepends on the selected scheme, country and portfolio; GS1 is optional unless chosen or otherwise required
DPP platform (SaaS)€0–200/monthFree plans available for small catalogues
Label redesign/printing€200–5,000One-time; depends on number of SKUs
Data collection/LCA€500–10,000If you need external sustainability assessments
Staff training€0–2,000In-house or workshop-based
Total (typical SME)€1,000–15,000One-time setup + ongoing platform fee

These figures are planning examples, not promises. Penalties for non-compliance are set and enforced through Member-State and sector rules; ESPR does not establish a universal EU-wide fine starting at €10,000.

Official Sources

Quick Reference: The 9-Step DPP Checklist

StepActionStatus
1️⃣Choose an interoperable identifier scheme; use GS1/GTIN where appropriate
2️⃣Gather product data (composition, sustainability, lifecycle)
3️⃣Choose a DPP platform
4️⃣Create your first DPP
5️⃣Generate and apply the data carrier in the location required for the sector
6️⃣Test end-to-end (scan → view → verify)
7️⃣Prepare for EU DPP Registry
8️⃣Train your team and establish processes
9️⃣Scale to full product catalogue

Ready to create your first Digital Product Passport? Start free on OriginPass.eu, generate compliant DPPs with QR codes in minutes. No credit card required.

Continue Reading

OriginPass

Prepare Your Product Data for ESPR

Start building your Digital Product Passport — structure product data, map identifiers, and get ready before delegated acts arrive. Free plan available.

No credit card required · Free plan available · Start at your own pace