Category: DPP implementation

DPP Service Provider Requirements: What to Check

Published on

DPP Service Provider Requirements: What to Check

If you do not want to build your own passport infrastructure, you will use a DPP service provider. But not every provider meets what the law requires and what your business needs. This article organises the requirements worth watching when you assess a provider.

Who a DPP service provider is

A DPP service provider is an entity that technically creates, hosts and maintains Digital Product Passports (DPPs) on behalf of a manufacturer or importer. It handles data carriers, record storage and the connection to the EU registry.

A key distinction: the provider does the technical work, but the economic operator is legally responsible for the accuracy and completeness of the data. Choosing a provider does not transfer that responsibility — which is why the terms of the arrangement must be well understood.

Where the requirements come from

Provider obligations stem from the ESPR (Regulation 2024/1781) and its rules on the Digital Product Passport. The full delegated act detailing these requirements is only expected (around 2027) and has no final text yet.

That means some details are still taking shape. A good provider should be ready for this and flexible toward future changes, rather than locking you into a rigid solution.

Data portability and no lock-in

Data portability comes first: the ability to export passports in a structured form to avoid dependence on a single provider. It is a safeguard in case you change providers or something goes wrong on their side.

When assessing a provider, make sure it:

  • offers a full data export in an open, machine-readable format,
  • does not lock down passport identifiers or URLs,
  • documents the data structure so migration is feasible,
  • treats your data as your property, not its own asset.

We expand on this in choosing a DPP platform.

Backups and continuity

Because passport data stays decentralised, the provider carries the duty to make backups and ensure continuous access. The passport must be available across the product's whole life cycle, so outages are a real problem.

It is worth asking about retention too: data and change history should be kept for a suitably long time — in practice, a change log is expected to be retained for many years. Establish how long the provider guarantees data can be recovered.

Role-based access

ESPR introduces layered access: some data is public, some for B2B partners, and some reserved for surveillance authorities and notified bodies. The provider must let you assign these roles and enforce the restrictions.

A well-designed system shows consumers what concerns them while protecting trade secrets and sensitive data. We cover access layers in more depth in layered access to DPP data.

Interoperability and the registry

A provider should ensure interoperability — working with your systems (ERP, PIM) and with the EU registry. The registry acts as an index and identifier-verification layer, not a warehouse of full passports, so the provider must report data to that index correctly.

Mind the terminology: "verification" in the registry means checking identity and access credentials, not certifying the provider. A certification scheme for service providers is still being prepared, so no provider can today claim an official DPP certificate.

What to ask before signing

A short checklist of control questions:

  1. What does a full export look like, and in what format?
  2. What are the backup, continuity and retention policies?
  3. Does the system support role-based access?
  4. How does integration with the EU registry and my systems work?
  5. How does the provider respond to regulatory change?

Security and data protection

Since the provider stores your product data, its security practices become your concern. Ask about how data is stored, access control on the provider's side, and how restricted information and trade secrets are protected.

Layered access only makes sense if technical safeguards actually enforce it. It is worth checking whether the provider can clearly describe who sees each data layer, and on what basis.

Support and provider maturity

The rules around the DPP are still taking shape, so what counts is not only today's functionality but also the provider's ability to keep pace with change. A good partner communicates updates, explains what they mean and does not leave you alone with the interpretation.

Pay attention to the quality of support and documentation: how quickly the team responds, whether help materials exist and whether it is easy to get an answer to a technical question. This shapes how smoothly you get through the rollout and daily work.

Key takeaways

  • A DPP service provider does the technical work, but legal responsibility stays with the manufacturer or importer.
  • The most important requirements are data portability, backups, continuity and role-based access.
  • Interoperability with the EU registry and your systems is essential.
  • "Verification" in the registry is an identity check, not a certificate — a certification scheme is still being developed.
  • The full delegated act for service providers is only expected (around 2027).

See how CyfroPass meets these requirements — from data export to layered access. Visit cyfropass.pl and try the platform on your own product.

← Back to all articles