Category: Registry & standards

Backups and Continuity of DPP Data

Published on

Backups and Continuity of DPP Data

In the Digital Product Passport (DPP) system, data must stay available throughout a product's life cycle — often for many years. Because the data is decentralised, its continuity rests on your side. This article explains why backups and continuity are an obligation, not just good practice.

Why continuity is critical

A passport is not a one-off document. It is meant to be available whenever someone scans the carrier — a consumer, a repairer, a market-surveillance authority or a recycling plant. If the data disappears, the product effectively loses its passport.

Because the EU registry holds only identifiers and metadata, it will not reconstruct your data. The continuity of the passport therefore depends on how you store and safeguard the data layer.

An obligation on the service provider

ESPR places continuity and backup obligations on DPP service providers. The point is that the data survives technical failures and stays available for the required period.

This is an important criterion when choosing a provider. It is worth checking how they handle backups, how often they run them, and what the recovery procedure looks like after a failure.

What happens when a provider fails

The biggest risk is not a single server outage but dependence on one provider with no way to recover the data. That is why portability of the data matters as much as backups.

Good practice covers several safeguards:

  • regular backups of the data layer,
  • the ability to export data in a structured format,
  • no lock-in to a single provider,
  • a clear procedure for migrating to another solution.

This way a failure or a change of provider does not mean losing your passports.

Versioning and change history

Continuity is not only about the availability of current data but of its history. Passport data changes over time, and in a compliance check what counts is the state at a specific moment.

That is why a sound system records changes and keeps their history for a suitably long period — usually measured in years. This makes it possible to reconstruct how the passport looked when the product was placed on the market.

Continuity and responsibility

Even if a provider supplies the technical mechanisms, responsibility for the availability and accuracy of the passport stays with the economic operator — the manufacturer or importer. We discuss this distinction in Central registry versus decentralised data.

That is why data continuity is worth treating as part of your own risk strategy, not solely a provider matter.

A practical approach

Start with the questions you will ask a provider: where the data is hosted, how often backups are made, and what export and migration look like. Also check how long the change history is retained. We describe the layered architecture in which this continuity operates in The four layers of a DPP system.

Retention: how long to keep the data

Passport data and its change history must be kept for a suitably long time — usually measured in years, often on the order of a decade. The point is that the passport stays available and verifiable long after the product is placed on the market.

The exact period depends on the sector and the type of data. That is why, when designing a passport, it is worth setting a retention policy upfront: what you keep, for how long and in what form, and how you manage the data after the product's life cycle ends.

A continuity checklist

Before you consider continuity assured, check a few points:

  • whether there are regular, tested backups of the data layer,
  • whether the data can be exported in a structured, open format,
  • whether the change history is kept for the required period,
  • whether there is a clear procedure for migrating to another provider,
  • whether responsibilities are assigned on the company's side, not only the provider's.

This list helps tell real continuity from marketing claims.

Continuity as part of a risk strategy

Data continuity is best treated like any other area of operational risk. It is worth naming a responsible person, deciding how you test data recovery, and periodically checking that the assumptions still hold.

This approach makes backups more than a feature in a system — a safeguard that actually works. We describe the architecture in which this operates in The EU DPP registry.

Key takeaways

  • Passport data must stay available throughout the product's life cycle, often for many years.
  • The EU registry will not reconstruct your data — it holds only identifiers and metadata.
  • ESPR places backup and continuity obligations on DPP service providers.
  • Portability and no lock-in protect against data loss when changing provider.
  • Responsibility for the passport's availability stays with the manufacturer or importer.

See how CyfroPass provides backups, versioning and export of passport data. Visit cyfropass.pl and secure your data continuity from the first product.

← Back to all articles