Category: Enforcement & customs

DPP Compliance Audit: How to Get Your Company Ready

Published on

DPP Compliance Audit: How to Get Your Company Ready

A DPP compliance audit is not a distant formality — market-surveillance authorities and customs services are already building tools to check Digital Product Passports. This practical guide helps your company get ready before an inspector scans your data carrier or asks for access to the record. We focus on what you can do today, not on speculation about future enforcement.

What triggers penalties

Non-compliance is not limited to a missing passport. A DPP compliance audit looks at several common failures that authorities take seriously:

  • a missing, incomplete or inaccurate product passport,
  • a broken or unreadable data carrier that does not resolve to the record,
  • obstructing the work of market-surveillance authorities.

Each of these can trigger serious consequences: fines, withdrawal of the product from the market, import bans, and public disclosure of the breach. That last measure is often the most damaging to a brand's reputation, because it is visible to customers and partners alike.

Who bears responsibility

Liability does not rest on the manufacturer alone. It stretches across the whole chain of placing a product on the market — it covers manufacturers, importers, distributors and online platforms. If you sell goods in the EU that were made outside the Union, the importer usually carries responsibility for the passport.

Settle this inside your organisation before an inspector does. A clear assignment of roles reduces the risk that, at the moment of an audit, no one can produce the right data or explain who owns it.

What the penalties look like

The ESPR, Regulation (EU) 2024/1781, does not set a single EU-wide tariff of fines. Penalties are defined by member states at national level, and the regulation only requires that they be "effective, proportionate and dissuasive" (Article 74).

In practice this means the size of penalties varies widely between countries and can be significant for a business. The backbone of the enforcement system is Regulation (EU) 2019/1020, which gives authorities their inspection powers. There is little point budgeting around a specific figure — budget around readiness instead, because that is what you actually control.

Border checks work differently

Many importers picture a customs officer scanning every QR code. That is not how it works. Enforcement at the border is risk-based and system-driven, running through the EU Single Window for customs rather than through universal scanning of data carriers.

The DPP registry connects to this infrastructure, so checks can be targeted at higher-risk operators and shipments. For your company the takeaway is simple: the data in the registry and in the passport must be consistent, because that consistency is what decides whether a shipment is held or cleared.

The readiness checklist

Treat preparation for an audit as a project with clear steps. Here are seven items worth verifying well before an obligation reaches your sector:

  1. The data carrier works and resolves — test the scan on several devices and confirm the link opens the correct record.
  2. The record is complete and accurate — reconcile the passport data against your technical file and declarations of conformity.
  3. Layered access is configured — public data, B2B partner data and authority-only data each have the right visibility level.
  4. Roles and responsibilities are assigned — you know who owns the passport content and who keeps it current.
  5. Registration in the EU registry is done — identifiers and metadata are filed as the sector requires.
  6. Documentation and an audit trail exist — changes to the passport are logged and the history can be reconstructed.
  7. Backup and continuity are in place — the data survives an outage and the passport stays reachable.

Working through this list early turns a future obligation into a routine. If you are building a passport from scratch, our guide on how to create a DPP walks through the full path.

Documentation is your evidence

In an audit, what counts is what you can demonstrate. An audit trail — a record of who changed what and when — lets you prove due diligence. Keep the change history and the evidence that links the passport to your compliance documentation.

Well-kept documentation shortens an inspection and lowers the risk of a dispute over data completeness. It is also the simplest way for a new employee to understand your compliance status quickly, without reverse-engineering it from scattered files.

Who is really accountable for the data

One misconception is worth clearing up: using a DPP platform does not transfer legal responsibility to that platform. The economic operator — the manufacturer or importer — always remains responsible for the accuracy of the passport.

The platform provider does the technical work: it stores data, generates carriers, delivers layered access and ensures continuity. It does not, however, assume your responsibility toward the authorities. That is why you should judge a provider by how well it helps you demonstrate compliance. For the full timeline of obligations, see the ESPR timeline, and for the basics of the concept, see what a DPP is.

Key takeaways

  • Non-compliance is more than a missing passport — it also covers an unreadable carrier and inaccurate data.
  • Liability spans manufacturers, importers, distributors and online platforms.
  • Penalties are set nationally, vary widely between states, and can be significant.
  • Border enforcement is risk-driven through the Single Window, not universal scanning.
  • The manufacturer or importer always owns the data; the platform does the technical work.

See how CyfroPass helps keep your passports audit-ready — with a working carrier, layered access and a full audit trail. Visit cyfropass.pl and check the readiness of your first product.

← Back to all articles