Category: Enforcement & customs

Market Surveillance and the DPP: How Enforcement Works

Published on

Market Surveillance and the DPP: How Enforcement Works

A Digital Product Passport (DPP) will be only as credible as its enforcement. Behind that enforcement stands market surveillance — the system that checks whether products on the EU market meet requirements. It is worth understanding how it works before it knocks on your company's door.

What market surveillance is

Market surveillance is the organised inspection of products already available on the market. It is carried out by designated national authorities operating under common rules set in Regulation (EU) 2019/1020.

That regulation is the backbone of enforcement in the EU. It gives authorities the power to inspect, demand documentation and take measures against products that do not comply — including against a missing or invalid DPP. Thanks to it, enforcement runs on similar rules across all member states.

What authorities can check

In the context of the passport, surveillance authorities can in particular:

  • check whether the product has the required data carrier and a working record,
  • verify the completeness and accuracy of the passport data,
  • access data from the layer reserved for authorities,
  • demand additional documentation from the responsible operator.

The passport does not replace these powers but makes them easier. Instead of asking for paper files, an authority can read structured data directly and immediately compare it with the requirements.

How the DPP helps inspectors

The strength of the passport is that it is machine-readable. The data is organised according to common rules, so it is easier to compare and verify than inconsistent documents from different manufacturers.

Added to this is the DPP registry, which serves as an index and a verification layer for identifiers. An authority can confirm a product's identity and reach the right passport, even when the data itself is stored in a decentralised way. That shortens the inspection and narrows the room for manipulation.

Risk-based inspections

Market surveillance does not mean checking every single unit. Authorities work on a risk-based model: they concentrate resources where the likelihood or the impact of non-compliance is greatest.

Risk signals can include complaints, prior breaches, market data or analysis of specific product categories. For a company this means an inspection can come at any time, and good data is the best preparation — you cannot predict when your product will be the one under the microscope.

Cross-border cooperation

The internal market is shared, so authorities in different countries cooperate and exchange information. A product challenged in one country may be stopped in others too, because surveillance operates across the whole Union.

This coordination also connects to controls at the EU border, where market surveillance meets customs authorities. We expand on this in The DPP and EU customs.

How to prepare

Preparing for market surveillance comes down to keeping data in order. It is worth:

  • maintaining a complete, up-to-date passport for every product in scope,
  • ensuring the data carrier is durable and leads to the right version of the record,
  • keeping supporting documentation ready in case an authority requests it.

We cover the consequences of non-compliance in more detail in Consequences of a missing DPP.

What a typical inspection looks like

Although the course depends on the authority and the product, an inspection usually follows a repeatable pattern. First the authority establishes the product's identity, then reads the data carrier and checks that it leads to a working record. Next it verifies the completeness and consistency of the data and, if needed, demands supporting documentation.

Finally comes assessment and a decision on any measures. The sooner the authority reaches reliable data, the smoother the inspection runs — and a well-maintained passport shortens it and reduces the risk of misunderstandings.

The role of the registry and the authority layer

Market surveillance uses two elements that an ordinary consumer does not see. The first is the DPP registry, which lets an authority confirm a product's identity and reach the right passport. The second is the data layer reserved for authorities, containing information not available publicly.

Thanks to them, an inspection is not limited to what a customer sees after scanning the code. The authority can look deeper, compare data with documentation and catch inconsistencies that are not visible at first glance.

Cooperating with the authority pays off

The way a company responds to an inspection matters. Promptly providing data, clear contact and ready documentation shorten the procedure and build credibility. Obstructing surveillance, by contrast, is often treated as a breach in its own right.

In practice this means it is worth knowing in advance who in the company handles contact with the authority and where the needed data lives. A prepared organisation passes an inspection calmly, without a last-minute scramble for documents.

Key takeaways

  • Market surveillance (Regulation (EU) 2019/1020) is the basis of DPP enforcement in the EU.
  • Authorities can check the carrier, data completeness and access the reserved layer.
  • Machine readability and the index-registry make inspection easier.
  • Inspections are risk-based, and authorities cooperate across borders.
  • The best preparation is complete, up-to-date passport data.

See how CyfroPass keeps passports ready for market-surveillance inspection. Visit cyfropass.pl and start with your first product.

← Back to all articles