Operational notes Regulation

Digital product passport: what you will have to make public (and how not to publish your secrets)

7 min read

A wall of twenty-four identical metal lockers, all closed with their locks in view, shot frontally in black and white
All identical from the outside. What is inside is known only to whoever opens it.

Whoever writes a product’s technical data sheet today mixes, almost always without a written rule, two kinds of data: the kind a customer has always been able to see, and the kind that stays in the internal systems out of habit, not because anyone decided it should. For manufacturers of textiles, tyres, furniture, steel or aluminium, that distinction will have to become a formal list, item by item, on every product — and whoever has not already built it risks having to redo it against a deadline, reclassifying an entire catalogue in a few weeks.

What the regulation actually requires

Regulation (EU) 2024/1781, which establishes a framework for the ecodesign of sustainable products (ESPR), in force since 18 July 2024, defines in Article 3(28) the digital product passport as “a set of data specific to a product that includes the information specified in the applicable delegated act adopted pursuant to Article 4 and that is accessible via electronic means through a data carrier”. Article 9 turns it into a condition of market access: once the delegated act for a product category applies, that product can only be placed on the market or put into service if a passport is available. It is not an extra label: it is a compliance requirement, on a par with the CE mark.

Annex III lists what may or must go into the passport: the product’s unique identifier, declaration of conformity and technical documentation, manuals and safety information, manufacturer and importer identifiers, GTIN code. It is, in substance, the technical file that already exists inside most companies today — scattered across the bill of materials, the product sheet, supplier declarations and the quality archive — turned into a digital record that outsiders can query.

Who sees what: the Commission decides it, category by category

Here is the point this piece’s headline is getting at: the regulation does not draw the line between public and confidential data itself. It delegates that, category by category, to the delegated acts the Commission adopts under Article 4. Article 9(2)(f) requires every delegated act to specify “the actors that are to have access to data in the digital product passport and to what data they are to have access”: customers, manufacturers, importers, distributors, repairers, market surveillance authorities, customs authorities, civil society organisations and trade unions all appear in the list in Article 11(b) — but each actor’s access stays conditional on the specific access rights set out in the applicable delegated act. Not one wholly public passport: a different one for every category of actor consulting it.

When setting those requirements, Article 4(10)(d) requires the Commission to take into consideration the protection of confidential business information — but that is a balancing criterion the Commission applies when drafting the delegated act, not a list of exclusions a company can consult today. For every category, the line between what ends up in the public passport and what stays internal is drawn the moment the delegated act for that category is published — not before, and not for every category at once.

The calendar by category, checked line by line

The first ESPR working plan, Communication COM(2025) 187 of 16 April 2025, sets six priority categories with an indicative adoption timeline for the delegated acts: textiles and apparel (priority 1, 2027, a market worth €78 billion), iron and steel (priority 1 among intermediate products, 2026), tyres (2027), aluminium (2027), furniture (2028), mattresses (2029). One clarification worth making, because it is often muddled: footwear is not among these six categories. The working plan treats it as a category separate from textiles — different materials, function and supply chain, lower environmental impact — and provides only for a study, to be completed by the end of 2027, to decide whether to bring it into ESPR ecodesign. Footwear manufacturers have, today, no entry date into the digital passport.

The registry under Article 13 — the infrastructure that stores at least the unique identifiers of every passport, which the Commission had to open by 19 July 2026 — is already a reality: it went live in testing on 20 July 2026, a day after the statutory deadline. The first real operational deadline, though, is 18 February 2027, and it concerns industrial and electric-vehicle batteries under Regulation (EU) 2023/1542, not yet the ESPR working-plan categories: the system is switched on, but for textiles, steel, tyres, furniture, aluminium and mattresses the first passport obligations will only arrive with delegated acts still to be adopted.

The front already open: unsold textiles and footwear

On one point, though, textiles and footwear are already inside a deadline that has passed, not one still to come. Article 25(1) is unambiguous: “From 19 July 2026, the destruction of unsold consumer products as listed in Annex VII shall be prohibited” — which covers precisely apparel and clothing accessories (CN codes 4203, 61, 62, 6504, 6505) and footwear (CN 6401-6405). The same paragraph excludes micro and small enterprises and defers medium-sized ones to 19 July 2030: for large enterprises in the sector, the ban has already been in force since this summer. Article 24 adds a linked duty — publishing, every year, on the company’s own website, the quantity and destination of unsold products it has disposed of, including any derogations applied.

It is proof that, on textiles and footwear, ESPR already has concrete effects independent of the digital passport — and that the two obligations run on different tracks and calendars, with the same sector exposed to both at different times.

The real work: classify before the delegated act arrives

Waiting for your own category’s delegated act to find out what will be public is the most expensive choice available: it means reclassifying the whole catalogue against a date already fixed, with the technical office working under pressure while sales carry on regardless. The work worth doing now is building the passport dataset from the sources that already exist — bills of materials, technical data sheets, supplier declarations, conformity files — and classifying every entry as public under a foreseeable obligation, confidential as a trade secret, or to be decided once the delegated act arrives, with the reasoning for each choice written down. It is the same principle behind the trade-secret mapping the Data Act imposes on connected products — a different rule, the same mistake to avoid: declaring a piece of data confidential only once a request to show it arrives, rather than having decided beforehand. And for anyone in manufacturing already debating which process parameters to send outside the company’s perimeter to an external service, the same warning applies that we documented for whoever uploads a bill of materials and a dimensioned drawing to a public AI tool: data that has already been shown does not become confidential again by decree.

This is the control we put into operation: a system that reads bills of materials, product sheets and conformity files, flags every entry with its intended disclosure status and the reasoning behind it, and produces the trail — date, entry, decision — to show an inspector once the delegated act for your category becomes applicable. The same system brings together the rest of the company’s scattered data — PLM, ERP, quality, suppliers — into a single operating model, on which AI agents can already keep tomorrow’s passport record up to date today, with a human operator in command: on-premise on self-contained machines, or on a dedicated cloud with a data centre in Italy that we run ourselves.

Could you say today, product by product, which data will end up in the public passport and which stays a trade secret? Half an hour with one of our engineers is enough for the first map.

Sources

What we do not know

We do not know which specific data the delegated acts for textiles or steel will make public, nor the access rights differentiated by category of actor: those acts do not appear to have been published yet, and the working plan fixes only the adoption timeline, not the application date of the passport itself — which in any case cannot come earlier than 18 months after the act’s entry into force, barring duly justified exceptions (Art. 4(4)). Nor do we know whether footwear will join the ESPR categories: that depends on the study due by the end of 2027. We will update this piece once the delegated acts, or that study, are published.