Category: Registry & standards

DPP Data Versioning and Retention

Published on

DPP Data Versioning and Retention

A Digital Product Passport (DPP) is not a document you create once and forget. Product data changes over time, and the passport has to keep up. That makes versioning and data retention one of the quiet but important DPP obligations.

Product data changes over time

A lot happens over a product's life cycle: you update documentation, change a component supplier, correct reparability information. The passport should reflect the current state, not a snapshot from launch day, because it is the source of truth about the product for authorities and partners.

The advantage of a digital passport is that you can update it without changing the code printed on the product. The carrier stays the same, while the content it points to can be refreshed. As a result, a single label, applied once, serves an entire record that changes over time.

Why versioning matters

Since the data changes, you need a history of those changes. Versioning means that each significant modification creates a new, reproducible version of the record, and earlier states do not vanish without trace.

This serves two purposes. First, transparency: a surveillance authority or a partner can see what changed and when. Second, accountability: it is easier to show what the passport looked like at a given moment — for example, when a specific unit was sold. That matters when a dispute arises over the compliance of a product placed on the market earlier.

Logging changes

Change logging goes hand in hand with versioning. The DPP framework provides for recording modifications to the record so that an audit trail is created. It is the equivalent of a journal showing successive states of the data and letting you trace who changed what and when.

For a company this means it is worth choosing a platform that keeps such a log automatically. Manually tracking version history quickly becomes unworkable with a larger catalogue, and mistakes in this area are hard to fix later.

How long to keep the data

The passport must remain available not only at the point of sale but for a period relevant to the product's life cycle. A discussed reference point is a default retention on the order of about ten years, though the exact period depends on the sector act and the type of product.

The simple conclusion follows: the passport and its history must outlast a single marketing campaign or a single IT system. Data continuity has to be planned in advance, not discovered as a problem during a migration or a change of provider.

Backups and continuity

The ESPR (Regulation (EU) 2024/1781) imposes obligations on data continuity. A DPP service provider must ensure backups and the availability of the passport even in the event of technical problems, so that a scanned code always leads to a working record.

This is why choosing a provider is no trivial matter. Look for solutions that offer:

  • automatic versioning and a change log,
  • backups and a business-continuity plan,
  • data export in a structured form, without lock-in to a single provider.

We cover the split of roles between the company and the provider in Supply-chain responsibility for the DPP, and the registry itself in DPP registry vs EPREL.

Migration and changing providers

Retention and continuity have one more practical dimension: changing providers. Since the passport is meant to live for years, you will probably change your system or provider at least once in that time. Without the ability to export the complete data together with the version history, such a migration becomes risky.

That is why data portability is not a luxury but a safeguard of continuity. Choose solutions that let you export passports in a structured, open format and move them without losing the change log. It is a practical test of whether you really control your own data.

Key takeaways

  • A passport is a living record — data changes across the product life cycle.
  • Versioning creates a reproducible change history; logging provides an audit trail.
  • The default retention period is sometimes cited as around ten years, but it depends on the sector.
  • ESPR requires backups and continuity on the service provider's side.
  • Choose a platform with versioning, backups and data portability.

See how CyfroPass versions and archives your passports automatically without writing code. Visit cyfropass.pl and start with your first product.

← Back to all articles