TECHNICAL GUIDE
What Goes on the QR Code? DPP Data Carriers & the EU Registry
The most common assumption about the Digital Product Passport is also wrong: that the QR code on the garment holds the data. It doesn't. It holds a link. What's actually stored where — on the product, with your brand, or with the European Commission — is defined precisely in the ESPR's own text, and it's less centralised than most people expect.
This guide walks through the data carrier, the EU Registry that went live this summer, and the CEN-CENELEC standards behind both — sourced directly from EUR-Lex and CEN-CENELEC, checked live.
1. What's actually on the carrier
The ESPR defines a "data carrier" broadly: "a linear barcode symbol, a two-dimensional symbol or other automatic identification data capture medium that can be read by a device" (Article 2, point 29). A QR code is the obvious example, but the definition also covers NFC chips, RFID tags and other formats — the law is carrier-agnostic.
What the carrier connects to is narrow and specific: a "persistent unique product identifier" (Article 10(1)(a)) — a string of characters that "enables a web link to the digital product passport" (Article 2, point 30). That's it. The carrier is a pointer, not a payload. Article 10(1)(b) requires it to be physically present on the product, its packaging, or documentation accompanying it.
One practical duty worth knowing: if a product is sold online and a dealer or marketplace can't physically scan it, Article 10(3) requires the brand placing the product on the market to supply them with a digital copy of the carrier or identifier — free of charge, within five working days of a request.
2. Where the real data actually lives
Not with the EU. Article 11(c) of the ESPR is explicit: the digital product passport "shall be stored by the economic operator responsible for its creation or by digital product passport service providers." CEN-CENELEC — the standards body building the technical framework — describes the result as a "hybrid structure": not a centralised government database, and not fully decentralised either, but a split of responsibilities between the Commission and third-party service providers, who are typically private companies.
The brand (or its service provider) also carries a resilience duty: Article 10(4) requires a back-up copy of the passport to be made available through a digital product passport service provider, and Article 11(e) requires the passport to stay available even if the original economic operator becomes insolvent or ceases trading.
3. What the EU Registry actually stores
The Commission-run "registry" is real, and it's live — but it stores far less than the word suggests. Article 13(1) required the Commission to set it up by 19 July 2026, storing "in a secure manner at least the unique identifiers" for the product, its manufacturer and its production facility, plus commodity codes for goods entering the EU through customs. That deadline was met: Commission Implementing Regulation (EU) 2026/1778, adopted 16 July 2026, lays down how the registry actually operates.
The Commission can require additional data per product group (Article 13(2)) — but only where it helps verify a passport's authenticity, supports market surveillance or customs checks, or doesn't create a disproportionate burden. The full DPP dataset is not the default.
Not the same thing
Registry vs. web portal vs. the passport itself
- The registry (Article 13): Commission-run, identifiers and enforcement data only. Brands upload their own data (Article 13(4)); the registry auto-issues a "unique registration identifier" in return — which the law explicitly says is not proof of compliance.
- The web portal (Article 14): a separate, publicly searchable Commission tool for comparing passport data, linking out to each brand's own decentralised passport rather than hosting the data itself.
- The passport itself: stays with the economic operator or their service provider, per Article 11(c) — never centralised.
The registry isn't textile-specific, either — Implementing Regulation (EU) 2026/1778 covers the same infrastructure for batteries, construction products, toys and detergents, each under their own product law. It's shared plumbing, not a fashion-only system.
4. The standards that make it work
The technical detail sits with CEN-CENELEC Joint Technical Committee 24, "Digital Product Passport – Framework and System" (secretariat held by Germany's DIN), working under EU Standardization Request M/604. It has produced eight EN standards, including EN 18220:2026 "Digital product passport – Data carriers" — the one that governs exactly this topic.
Six of the eight, including EN 18220, were cited as harmonised standards in the Official Journal on 15 July 2026 (Commission Implementing Decision (EU) 2026/1736). That citation matters legally: compliance with a cited harmonised standard gives a "presumption of conformity" with the ESPR's essential requirements — meaning a brand using EN 18220 correctly doesn't have to separately prove its carrier meets Article 10. Two standards — covering access-rights security and data authentication — haven't been cited yet.
What none of this fixes yet: exactly which carrier technology fashion products must use. That detail is set per product group in each delegated act, and no textile delegated act has been adopted so far — so today, EN 18220 tells you how a compliant carrier must behave, not which one your garments will be required to carry.
DPP AUDIT
How ready is your collection for the DPP?
Benchmark one complete collection against the LGFL DPP Data Framework. 10 domains, four ESPR categories. Under NDA.
Start Your DPP Audit