Junction®

standard

The passport does not store customer data

Product information in a DPP is anonymous by law and personal customer data is explicitly excluded. Teams reviewing it as a marketing tool stall for no reason.

One objection comes up in almost every internal review of a digital product passport (DPP) project, usually from legal or from a data protection officer, and it is based on a misunderstanding that is worth clearing quickly because it stalls projects for no reason.

The passport is not a customer database.

What the regulation says

The Ecodesign Regulation embeds several safeguards, in line with the GDPR.

Data protection by design and by default is a core principle: general access to product information is anonymous, with no identification required of the person accessing it. Someone scanning a code in a shop does not identify themselves to see the passport.

No personal data by default. The regulation explicitly states that personal customer data is not to be stored in the passport.

Consent as the only exception. Personal data could be linked to a passport only where an individual gives explicit, informed consent for a specific, clearly stated purpose, in full compliance with the GDPR.

The passport describes the product, not the person holding it.

Why the confusion happens

The confusion is understandable, and it comes from two places.

The first is the QR code. Scannable codes on products are strongly associated with marketing campaigns, where the entire point is to identify and track the person scanning. A compliance mechanism that uses the same interface reads, at first glance, like the same thing.

The second is that some vendors do build consumer engagement features on top of passport infrastructure, and those features may involve personal data with consent. That is a separate product decision layered above the compliance record, and it should be reviewed as such, separately and on its own merits.

What legal should actually review

Redirecting the review rather than ending it, because there are real questions here.

Access rights. The passport presents different data to different parties. Who sees the restricted layer, on what basis, and how is that enforced? This is a genuine design question with data protection implications, even when no personal data is involved.

Scan analytics. If scan events are logged, what is logged, for how long, and is any of it capable of identifying a person? Aggregate geography is not personal data; a device fingerprint tied to a location and a timestamp deserves a look.

Any consumer-facing layer. Accounts, ownership registration, warranty registration and second hand transfer all involve people. If you offer them, they need their own basis and their own notice, distinct from the passport.

Commercially sensitive product data. The more interesting confidentiality question is usually not personal data at all. It is supplier identity and cost-revealing composition data, and who can see it.

The practical point

If a DPP project is being held up because someone believes it puts customer data at risk, the answer is one paragraph of regulation, and the project can move. Then have the harder conversation, which is about access rights and commercial confidentiality.

Sources

  • European Commission, *Digital Product Passport: Frequently Asked Questions*, January 2026 update,
  • question 16 on privacy considerations.
  • Regulation (EU) 2016/679 (GDPR), Regulation (EU) 2024/1781 (ESPR).

Get DPP-ready before your category

The DPP and customer data privacy | Junction®