Traceability and Evidence in a Product Passport
Traceability and evidence make up the layer of a Digital Product Passport (DPP) that is most often underestimated. It is the layer that links the passport to real compliance documentation and to the product's history. This article explains what the layer covers and why it decides the credibility of the whole passport.
What traceability means in a DPP
Traceability is the ability to link a product to its origin, its documentation and its life-cycle stages. In a passport this means being able to trace where the key data comes from and what it rests on.
Without this layer a passport would be just a set of declarations. Only linking the data to evidence makes the information verifiable, rather than something to be taken on trust.
What evidence means in a passport
Evidence is a set of references to documentation that supports the data held in the passport. Instead of copying whole documents, the passport usually points to them in a machine-readable way.
Typical kinds of evidence include:
- declarations of conformity and related markings,
- test reports and certificates,
- supplier documentation on materials,
- provenance records for components or batches.
Not all evidence has to be public — some is reserved for market-surveillance authorities or notified bodies.
Linking to existing documentation
The evidence layer does not create new bureaucracy. In most companies compliance documentation already exists — the problem is that it is scattered. The passport organises these links and makes them available when they are needed.
A good practice is to maintain stable references to documents, so that an update or a new version does not break the link. That keeps the passport consistent despite changes in the underlying documentation.
Traceability and the level of detail
The scope of traceability depends on the level of the passport. At model level we trace data common to the whole line, at batch level the origin of a specific run, and at item level the history of a single unit.
The higher the granularity, the greater the value of traceability — but also the greater the effort to maintain the data. We cover this trade-off in How to set your data granularity.
Versioning and credibility
Data in a passport changes over time — new batches appear, documentation is updated, corrections are made. Credible traceability therefore requires versioning: the ability to check how the data looked at a given moment.
This matters especially in a compliance check, where what counts is the state of the data when the product was placed on the market. That is why a change history is part of a sound passport, not an add-on.
Who is responsible for evidence
Responsibility for the accuracy of the data and its linked evidence sits with the economic operator — the manufacturer or importer. A platform provider supplies the technical mechanisms but does not take on responsibility for the content. We explain this distinction further in What is a DPP.
Internal and external traceability
It helps to distinguish two levels of traceability. Internal traceability concerns what happens inside your company — from receiving materials to the finished product. External traceability reaches up and down the chain, to suppliers and further links.
A passport usually draws on both levels. Internal traceability is normally easier to master, because the data is under your control. External traceability requires partners' cooperation and an agreed format for the information they pass on.
Traceability across the supply chain
Much of the data that ends up in a passport comes from suppliers. They hold the information about the origin of materials and components. Without their cooperation, traceability stays incomplete.
A good practice is to agree upfront what data suppliers should provide and in what format. The sooner you settle this, the less manual work when assembling the passport and the easier it is to keep consistency between runs.
Common mistakes in traceability
A few traps recur with this layer:
- copying whole documents instead of stable references to them,
- breaking links every time a document is updated,
- keeping no change history, so a past state cannot be reconstructed,
- confusing traceability with disclosure — not everything has to be public.
Consciously avoiding these keeps traceability something that can actually be verified.
Key takeaways
- Traceability links a product to its origin, documentation and life-cycle stages.
- Evidence is a set of references to declarations, reports and certificates — not copies of them.
- The layer organises existing documentation rather than creating new bureaucracy.
- Credible traceability needs stable references and versioned data.
- The manufacturer or importer is responsible for the data and evidence, not the platform provider.
See how CyfroPass links product data to compliance documentation in a single passport. Visit cyfropass.pl and build traceability that can actually be verified.