Category: DPP implementation

How to Create a DPP: Step-by-Step Guide

Published on

How to Create a DPP: Step-by-Step Guide

Rolling out a Digital Product Passport (DPP) sounds like a large IT project, but in practice it is mostly about tidying up data your company already holds. Below is a practical, step-by-step path — from choosing an identifier to scaling across your whole catalogue. Treat it as a map you adapt to your sector and timeline.

Step 1: Choose an identifier scheme

Every passport begins with a unique product identifier. A common and practical choice is the GS1/GTIN system, but ESPR is technology-neutral — this is not the only lawful option.

What matters is that the identifier is unique and durable and fits the level of detail you plan to use. A deliberate choice of scheme at the start saves costly migrations later. It also helps to settle early how the identifier maps to the model, batch and item levels, because that shapes the data structure that follows.

Step 2: Collect and structure your product data

This is usually the most labour-intensive stage, yet it rarely means creating data from scratch. Draw on what you already have: your ERP system, spec sheets, declarations of conformity and supplier documentation.

The goal is one consistent, complete and up-to-date record per product. At this stage it is worth flagging the gaps: data that is missing or out of date, and the sources you will use to fill it. To a large extent this is a data-tidying project, not a data-invention one — the earlier you find the gaps, the fewer surprises at publication.

Step 3: Decide the level of granularity

Decide whether the passport describes a model, a batch or a single item. The choice depends on the sector and the regulatory objective.

  • Model — the whole product line or variant.
  • Batch — a specific production run.
  • Item — a single, individually identifiable unit.

Batteries require the item level, which neatly shows that granularity follows from the specific requirements of a sector. The choice affects how many records you generate and how, so make it deliberately before moving on.

Step 4: Pick a DPP platform or service provider

Your choice of provider shapes how conveniently and safely you can maintain passports over time. Weigh a few criteria:

  • Data portability and structured export — no lock-in to a single vendor.
  • Backup and continuity of operation.
  • Role-based access — public, B2B and authority layers.
  • Interoperability with your existing systems.

These criteria protect you from trapped data and make future growth easier. Check as well whether the provider supports content updates and versioning, because you will maintain the passport for years rather than publish it once.

Step 5: Create the passport

At this stage you map the collected data onto the passport fields. The exact set of fields comes from the delegated act for your sector, so it is worth checking the requirements specific to your product group.

Remember layered access: some data is public, while some is reserved for authorities or parties with a legitimate interest. A well-designed passport distinguishes these layers from the outset. Plan for multiple languages too if you sell in several markets — content can be served in different versions without changing the identifier.

Step 6: Generate and apply the data carrier

Once the data is ready, you create the carrier — most often a QR code — and place it on the product, its packaging or a label. The carrier leads to the passport but is not the passport itself.

This distinction matters in practice: you can update the passport content without changing the code printed on the product. The data lives independently of the physical carrier. Choose where to place it so the code stays legible across the product's life cycle and survives normal conditions of use.

Step 7: Test the whole flow end to end

Before going wide, check the flow from end to end. Scan the carrier and trace where it leads.

  • Does the scan resolve correctly to the right passport?
  • Are the content, version and language correct?
  • Do the access layers behave as intended?

Testing on a few representative products catches errors before they reach the entire catalogue. It is worth checking the scan on different devices and browsers, so both a customer and an inspector see what they should.

Step 8: Register in the EU Registry

Passports are registered in the EU Registry, which acts as an index and verification layer rather than a warehouse of full data. The data itself stays decentralised, with you or your service provider.

The registry will be available from mid-2026. What goes into the registry are identifiers and registration metadata, not the full passport content — a distinction worth grasping as you design your data architecture. This design is deliberate: it limits the risk of a single point of failure. We give the wider context in the ESPR timeline.

Step 9: Train the team and assign responsibility

Responsibility for the accuracy of passport data lies with the economic operator — the manufacturer or importer. The platform provider does the technical work but does not take on that legal responsibility.

So assign clearly who in the company keeps the data current and complete, and who approves changes to it. Set out how often the data will be reviewed, so responsibility does not blur between departments. A trained team is the condition for maintaining passport quality over time. We cover verification in DPP compliance audit.

Step 10: Scale across the catalogue and keep data current

Once the process works on a few products, you extend it to the whole catalogue. Versioning and regular updates are key here, because the passport must reflect the real state of the product.

It pays to work in phases, in line with the ESPR rollout waves. Batteries are covered earliest — from 18 February 2027 — so if they are part of your range, start there. Prioritising by the timeline lets you spread the work out and avoid a pile-up of tasks. Further product groups will join in later years as delegated acts arrive, so build a process you can easily repeat for new sectors.

Key takeaways

  • Rolling out a DPP is mainly a data-tidying project, not building a system from scratch.
  • Start with a unique identifier; GS1/GTIN is a practical but not the only lawful option.
  • Choose a provider for data portability, continuity and layered access.
  • The EU Registry (from mid-2026) is an index, and the data stays decentralised.
  • The manufacturer or importer owns the data; roll out in phases — batteries from 18 February 2027.

See how CyfroPass guides you through all these steps and lets you publish a Digital Product Passport without writing code. Visit cyfropass.pl and start with your first product.

← Back to all articles