Junction®

standard

A QR code is not a digital product passport

The QR code is the carrier. The passport is the verifiable record behind it. Vendors selling the first as the second are selling you a rebuild.

There is a version of digital product passport (DPP) compliance being sold right now that consists of a QR code and a web page. It is fast, it is cheap, and it is not a passport.

Worth being precise about why, because the difference is not cosmetic and it decides whether you build once or twice.

What the code is for

The European Commission describes the passport as accessible by scanning a data carrier, a QR code or similar technology, placed on the product, its packaging, or the documents accompanying it.

The carrier is how you reach the record. It is not the record. Any print shop can produce a QR code this afternoon, and the code itself proves nothing about what sits behind it.

What the record has to be

Three properties separate a passport from a link, and a marketing page has none of them.

Structured. The passport carries defined fields, in the form the delegated act for your product group specifies, so that a machine can read it. Customs run automated checks. Market surveillance authorities search across products. A page of prose that a human can read is not a queryable record.

Verifiable. The claims in it have to be traceable to evidence. Recycled content, substances of concern, origin. A page that asserts these is a claim; a passport is a claim you can stand behind when someone checks.

Current. The economic operator has to maintain data accuracy throughout the product's lifecycle. A record frozen at launch is wrong the first time a supplier or a material changes, and wrong is worse than absent because it was published.

There is a fourth property that the regulation does not require but the market increasingly does: a code that anyone can photograph and reprint proves nothing about the item it is stuck to. Good sustainability data attached to a product anyone can copy is data about a category, not about the thing in the buyer's hand.

The cost of doing it the fast way

The QR-and-page version fails in a specific and predictable order.

It passes internal review, because it looks finished. It survives the first year, because nobody checks. Then a buyer asks for the structured record for a tender, or a market surveillance authority scans it and asks for the evidence behind a claim, and the answer is a web page.

At that point you rebuild, under a deadline, with the same supplier data problem you had at the start plus the sunk cost of the first attempt and a set of carriers already printed on physical products. That last part is the expensive one: changing what a code resolves to is a software change, but changing the code itself means relabelling goods that have already shipped.

How to tell the difference in a vendor conversation

Ask what a scan returns to a machine, not to a person. If the answer is a web page, ask what the API returns. Ask which identification link standard the code follows. Ask how the record is updated when a material changes, and who is responsible for making that happen. Ask what happens to the passport if the vendor stops trading, which is covered in data continuity.

The answers take five minutes and they separate a passport from a sticker.

Sources

  • European Commission, *Digital Product Passport: Frequently Asked Questions*, January 2026 update,
  • questions 1 and 3, including the economic operator's lifecycle data accuracy duty.
  • Regulation (EU) 2024/1781 (ESPR).

Get DPP-ready before your category

A QR code is not a DPP | Junction®