Junction®

how-to

What a passport service provider owes you under the regulation

The ESPR defines the DPP service provider role and constrains it: no reuse of your data, a mandated back-up copy, and a possible future certification scheme.

If you are buying digital product passport (DPP) infrastructure rather than building it, you are buying from a category the regulation defines and constrains. Knowing what the text says is a useful thing to bring to a vendor conversation, including ours.

The role exists in law

The Ecodesign Regulation defines a digital product passport service provider as an independent third party, authorised by the economic operator placing the product on the market, that processes passport data in order to make it available to those with access rights.

The Commission's own guidance is that using such a provider will be a straightforward route to compliance for many businesses, since the provider handles the technical requirements including legally mandated back-ups.

That produces two obligations you can hold a vendor to.

What the provider must do

Hold the back-up copy. The operator must make available a back-up copy of the passport through a service provider, and the passport itself must carry a reference to the provider hosting it. That reference travels inside your compliance record, which means your continuity arrangement is visible in the passport rather than buried in a contract. More on why this matters in data continuity.

Stay within the service. Service providers may not sell, reuse or process passport data beyond what the service requires, unless the operator specifically agrees.

That second one is worth reading twice if you have ever signed a SaaS agreement with broad data usage terms. In this category, the default is constrained by regulation rather than by whatever the contract says, and a provider seeking broad rights over your product data is asking you to opt out of a protection the law gives you.

What may come later

The Commission is empowered to set requirements for service providers and, where appropriate, a certification scheme to verify compliance.

Nothing exists yet. But it is worth tracking for a commercial reason: when a certification scheme arrives, it becomes a barrier that favours providers already aligned with the requirements, and it becomes a question your auditors ask about your vendor.

Five questions for any provider

Are you the back-up provider under Article 10(4), and how is that reference carried in the passport? A name, not a reassurance.

What are your data usage terms, and how do they sit against the Article 11 restriction? The answer should be narrower than a standard SaaS agreement, not broader.

Can we export the full record, today, without re-issuing identifiers? Portability is a property of the data, not of the contract.

What happens if you cease trading? Something written down.

Which identifier schemes do you carry, and do you require your own? Covered in identifiers explained.

We answer all five in writing, and we think a buyer who asks them of every vendor gets a better outcome regardless of who they choose. The requirement outlives the vendor relationship, which is the whole reason the regulation created the category in the first place.

Sources

  • Regulation (EU) 2024/1781 (ESPR): Article 2(32) defining the service provider, Article 10(4) on
  • the back-up copy, Article 11 on service provider obligations and the possible certification
  • scheme, Annex III point (l).
  • European Commission, *Digital Product Passport: FAQ*, January 2026 update, question 8.

Get DPP-ready before your category

What a DPP service provider owes you | Junction®