Category: Registry & standards

The Four Layers of a DPP System

Published on

The Four Layers of a DPP System

The Digital Product Passport (DPP) system is easier to understand when you break it into functional layers. Each does something different, and together they form a working whole. This article describes the four layers of the system and shows which one your company is responsible for.

Why think in layers

Splitting into layers helps separate things that are easy to confuse — for example the QR code from the data itself. It becomes clear that a failure or change in one layer need not touch the others.

It is also a practical decision-making tool. When you know which layer is on your side, it is easier to plan responsibility, costs and provider choice.

Layer 1: the data carrier

The first layer is the data carrier placed on the product, packaging or a label — most often a QR code. Its job is to lead to the right passport.

The carrier is only an access mechanism, not the passport itself. We expand on this distinction in DPP vs QR code. Importantly, the carrier can stay unchanged even as the data behind it is updated.

Layer 2: passport data

The second layer is the actual content — structured, machine-readable data about the product. This is where information on identity, composition, environment and traceability lives.

This data is decentralised and stays with the economic operator or its DPP service provider. It is the most valuable layer, because it is what actually constitutes the passport.

Layer 3: the registry

The third layer is the EU DPP registry. It acts as an index and verification layer: it holds identifiers and metadata but not passport content. It lets you confirm that a passport exists and who it belongs to.

The registry also connects to surveillance systems and the customs Single Window. We describe it further in The EU DPP registry.

Layer 4: the public portal

The fourth layer is a public search portal that lets people reach publicly available product information. It is the entry point for those who do not scan the carrier but search for data directly.

Not all data is visible there — access remains layered, so some information is reserved for authorised audiences.

How the layers work together

The layers form a chain: the carrier leads to the data, the registry confirms its identity, and the portal exposes the public part. The key observation is that data and registry are two different things — the data does not live in the registry.

That is why data continuity depends on your layer, not on the registry. We cover the backup and continuity duty in Backups and continuity of DPP data.

Which layer you own

In practice the economic operator is responsible above all for the data layer and the carrier on the product. The registry and portal are public infrastructure. This boundary helps you plan what you must provide yourself or with a provider.

Example flow: from scan to data

Let us follow one scan. A customer scans the QR code on a product — that is the carrier layer. The code leads to the right passport, the data layer, where the product information sits.

If someone wants to confirm that a passport is authentic and who it belongs to, they turn to the registry. And when they look for a product without scanning, they use the public portal. So the same system serves different paths to the data.

One layer failing does not break the others

The strength of splitting into layers is resilience. Changing the data content does not require changing the carrier on the product. A temporary portal outage does not delete the data itself. And a registry that holds only identifiers is not a bottleneck for content.

This independence of the layers is deliberate. It makes the system easier to maintain and less exposed to a single point of failure.

Common confusions about the layers

The most frequent misunderstandings are:

  • equating the QR code with the passport, i.e. confusing layer 1 with layer 2,
  • assuming the data "is in the registry" — the registry holds identifiers, not content,
  • treating the public portal as the place with all the data,
  • overlooking that data continuity depends on the layer on the company's side.

Being aware of the boundaries between layers makes it easier to plan responsibility and costs.

Key takeaways

  • The DPP system can be broken into four layers: carrier, data, registry and public portal.
  • The carrier is only an access mechanism; the data layer is the actual passport.
  • The data is decentralised; the registry holds identifiers and metadata, not content.
  • The public portal exposes public data, but access remains layered.
  • Your company owns the data layer and the carrier; the registry and portal are public infrastructure.

See how CyfroPass ties all the layers of the DPP system together in one place. Visit cyfropass.pl and build a passport from carrier to data.

← Back to all articles