standard
Where the passport actually lives
The DPP architecture is hybrid: a central EU registry of identifiers, and decentralised data held by operators. That split decides your obligations.
"Is the digital product passport (DPP) centralised or decentralised" sounds like an architecture question for engineers. It is actually the question that decides how much of the work is yours, so it belongs in a management conversation.
The answer is both, split in a specific way.
The split
Central: a registry at EU level. It does not store detailed product data. It links each product's unique identifier to the location of that product's passport. Delegated acts may require additional information to be stored in the registry for specific product groups.
Decentralised: the detailed product data, hosted by the individual economic operators or by service providers acting on their behalf.
The stated purpose of the hybrid structure is that data stays managed and controlled by individual operators while remaining consistently accessible, through a single regulated entry point, to consumers, other operators down the value chain, market surveillance authorities and other authorised parties.
What each half implies for you
The central half is an obligation to register, and it is a process problem: every product in scope, registered, correctly, before it is placed on the market. It is bounded work with a clear definition of done.
The decentralised half is an obligation to run something, and it is unbounded. The passport has to resolve, be accurate and stay available for the product's life. That means hosting, availability, updates when the product changes, and a continuity arrangement for when the arrangement itself changes. This is the half that never finishes.
Companies that read "the EU is building a registry" as "the EU is building the system" are planning for the first half only.
The advantage of the design, if you use it
The decentralised model means your data is not deposited into a system you do not control, which protects commercially sensitive information: supplier identity, composition detail, facility locations. Access rules are yours to enforce within the framework the standards set.
That is a real benefit, but it only materialises if the record is under your control rather than inside a vendor's proprietary store. Decentralised does not automatically mean yours. It means somebody other than the EU holds it, and which somebody is a procurement decision with a long horizon, discussed in data continuity.
The three questions this leaves
Who hosts, and can you leave? Export in full, without re-issuing identifiers.
How does the registry entry stay correct? If the location of the passport changes, the pointer has to change with it.
What resolves the identifier in ten years? The product may outlive the vendor, the contract and the person who signed it.
None of these need answering by an engineer. They need answering before you sign.
Sources
- European Commission, *Digital Product Passport: Frequently Asked Questions*, January 2026 update,
- questions 18 and 19.