Choosing a DPP Platform: Portability, No Lock-in
Choosing a platform for the Digital Product Passport (DPP) is a decision for years, not a single season. The passport has to follow the product across its whole life cycle, so the data must stay available and portable no matter who you work with today. This guide shows what to look for so you do not become locked into a single vendor.
Why data portability is critical
A Digital Product Passport (DPP) is not a marketing campaign but a multi-year regulatory obligation under the ESPR (Regulation 2024/1781). A product may be on the market for years, and the passport must keep working the whole time — including after you switch service providers.
That is why the first selection criterion is not how the interface looks, but whether you can retrieve your data in a usable form at any moment. A platform that makes export hard becomes an operational risk rather than a tool.
Portability and data export
The rules for DPP service providers stress data portability and structured export — precisely to avoid dependence on a single supplier (vendor lock-in). In practice this means the right to take your passports and move them elsewhere.
When assessing a platform, check specifically whether it:
- offers a full export of all passports, not just an on-screen view,
- delivers data in an open, structured, machine-readable format,
- includes change history and versions in the export, not only the current state,
- makes export self-service, without depending on the provider's goodwill.
No vendor lock-in in practice
Lock-in rarely comes from a single clause in a contract. It usually builds up gradually: data in a closed format, identifiers tied to the platform, no documentation of the structure. After a few years, migration costs more than staying put.
To avoid this, ask outright who owns the passport identifiers and URLs. If the data carrier on the product points to the provider's domain, changing providers may mean re-labelling your goods. That is a real cost worth anticipating at the start.
Continuity and backups
Because passport data stays decentralised with the company or its service provider, business continuity is an obligation, not an add-on. The provider's tasks include making backups and ensuring continuous access to the data.
Control questions for a provider:
- where and how often passport data is backed up,
- what happens to the passports if you end the relationship,
- how long the data stays available and recoverable,
- whether there is a contingency plan for a service outage.
Layered access and interoperability
ESPR assumes layered access: some data is public, some reserved for B2B partners, and some for surveillance authorities and notified bodies. A platform should support this role differentiation without workarounds.
Interoperability matters too — the platform's ability to work with the EU registry and with your systems (ERP, PIM). We cover how the DPP system layers connect in the EU DPP registry, and we discuss detailed provider requirements in what to expect from DPP service providers.
Who bears responsibility
Whatever platform you pick, legal responsibility for data accuracy rests with the economic operator — the manufacturer or importer. The provider does the technical work but does not take on that responsibility.
This is worth remembering, because it means your company needs control over the data. Separately: the full delegated act for DPP service providers is only expected (around 2027) and has no final text yet, so look for a partner that is flexible toward change.
A platform selection checklist
Before you sign, run through a few questions:
- Can I retrieve all my data in an open format at any time?
- Who owns the passport identifiers and URLs?
- What do continuity and backup policies look like?
- Does the platform support layered access and integration with my systems?
- Does the provider keep pace with changing rules?
Total cost, not just the price
The figure on a price list is not the same as the total cost of using a platform. It is worth accounting for the cost of onboarding, data migration, integration with your systems and a possible exit in the future.
Ask exactly what the subscription covers and what is charged on top: the number of products, language versions, users or integrations. A transparent pricing model makes planning easier once passports cover a larger share of the catalogue.
Scaling and upkeep over time
You will make the first passport by hand, but with hundreds or thousands of products, automation is what counts. Check whether the platform lets you create passports in bulk, import data from an ERP or PIM and update many items at once.
Upkeep matters just as much: a passport lives across the product's whole life cycle, so you need a convenient way to update, version and handle changes. A platform that eases day-to-day work pays off every day.
Test before you commit
Claims from a sales demo are worth checking in practice before you move your whole catalogue onto a platform. Ask to build a few passports on real data and walk the full path — from creating a record to exporting it.
Such a short pilot shows more than a feature list. You will see what daily work looks like, how export behaves and whether the platform actually answers your team's needs, not just the requirements on a leaflet.
Key takeaways
- Data portability and no vendor lock-in are the most important criteria when choosing a DPP platform.
- Demand a full, self-service export in an open, machine-readable format.
- Check who owns the identifiers and URLs — it drives your migration cost.
- Continuity, backups and layered access should be standard, not optional.
- Legal responsibility stays with the manufacturer or importer, so keep control of your data.
See how CyfroPass lets you build product passports with full data export and no dependence on a single vendor. Visit cyfropass.pl and try the platform on your first product.