Layered DPP data access: who sees what
A common worry about the Digital Product Passport (DPP) is exposing sensitive data to competitors. That is a misunderstanding: access to the passport is layered. This article explains who sees what and why the model protects trade secrets.
Not all data is public
ESPR (the Ecodesign for Sustainable Products Regulation, 2024/1781) provides that some passport data is public and some is reserved for specific audiences. A passport therefore does not mean full transparency toward everyone.
This is a deliberate design. It is meant to reconcile two goals: transparency toward consumers and authorities, and protection of information that represents a manufacturer's competitive value.
The public layer
Public data is seen by anyone who scans the data carrier — most often a QR code. This is information relevant to the user: product identity, basic characteristics, and guidance on use, repair or end-of-life handling.
This layer builds trust and supports informed purchasing decisions. It is also the foundation of the passport's marketing value, because it is the layer the consumer meets.
The B2B layer: partners with a legitimate interest
The second layer is available to parties with a legitimate interest — for example distributors, repairers, recyclers or auditors. They see data the consumer does not need but which is essential to their role.
Examples include detailed composition information a recycler needs, or service data useful for repair. Access is limited to what the party's role justifies.
The layer for authorities and notified bodies
The third layer is reserved for market-surveillance authorities and, where relevant, notified bodies. They have access to the widest range of data, needed to verify compliance.
It is this layer that lets rules be enforced without making everything public. An authority can check details that neither competitors nor the average consumer can see.
Why this model protects the company
Layered access answers a real worry: "will the passport force me to reveal my formulation or commercial terms?" The answer is no — sensitive data can be placed in a restricted-access layer.
This lets a company meet its transparency duty without losing competitive advantage. That matters especially in sectors where composition or the production process is key know-how.
Access versus data classification
It is worth distinguishing two things. Field classification (essential, recommended, voluntary) says whether data must appear in the passport. Layered access says who may see it.
These are two independent dimensions: an essential field need not be public, and a public field need not be essential. We cover classification in Essential, recommended, voluntary data, and the data types in What data does a DPP need.
What it means in practice
When designing a passport, it is worth assigning each field the right access layer from the start. This is an architectural decision that affects both compliance and the protection of trade secrets.
- Decide which data is relevant to the consumer and can be public.
- Identify data needed by B2B partners and restrict access to it.
- Reserve the most sensitive information for surveillance authorities.
- Make sure the technical solution actually enforces these levels. We recap the passport basics in What is a DPP.
Who decides what goes into which layer
The scope of public and restricted data is not arbitrary — it follows from the sectoral rules. It is the delegated act for a given product group that determines which information must be public and which may be restricted.
A company therefore operates within legally set bounds, but inside those bounds it makes its own design decisions. It is best to treat the assignment of layers as a deliberate choice, not the result of chance.
How layered access connects to the DPP architecture
Layered access does not work in a vacuum — it rests on the same architecture as the rest of the passport. The data carrier, for example a QR code, leads to the record, and the system recognises who is asking for data and to what extent they may see it.
The EU registry acts here as an index and a verification layer, not a store of full data. The information itself stays decentralised, with the company or its service provider, which also matters for access control.
Access, privacy and analytics
Layered access is also tied to privacy. In some sectors the rules limit analytics on how the passport is used, so that it does not become a tool for tracking consumers.
For a company that is a signal to design access and measurement with restraint. The public layer can build trust and marketing value, but without collecting data whose use is limited or unnecessary.
Key takeaways
- DPP data access is layered — not everything is public.
- The public layer serves consumers; the B2B layer serves partners with a legitimate interest.
- Surveillance authorities and notified bodies have the widest access.
- The model protects trade secrets, reconciling transparency with the protection of know-how.
- Access ("who sees it") is a different dimension from field classification ("whether it is required").
See how CyfroPass lets you assign data to the right access layers and publish a Digital Product Passport without writing code. Visit cyfropass.pl and design access in layers from your first product.