How to implement a DPP: a step-by-step guide
Knowing what a Digital Product Passport is is the first step; the second is implementing it without drowning in regulation or building a system that will not scale. This guide lays out a practical, phased path to launching a DPP, aimed at organisations that export to the European market or want to get ahead of the ESPR obligation.
Before you start: three foundational decisions
Most DPP projects fail not because of technology but because of three decisions made badly at the outset:
- Open standards, not a silo. If the passport can only be read inside the system that created it, it does not do its job. Bet on GS1 identifiers and EPCIS 2.0 events from day one.
- Phased scope, not everything at once. Start with one product line and a few mandatory attributes; expand later.
- Governed data, not a marketing sheet. Define who owns each data point, who updates it and who may read it.
Step 1 · Define the product’s identity
Every DPP starts with a unique, resolvable identifier. In practice that means assigning a GS1 GTIN (plus a serial number when you need to trace the individual item) and expressing it as a GS1 Digital Link, so a single QR code resolves to the right passport. Without solid identity, nothing else holds up.
Step 2 · Model the mandatory data for your category
The exact attributes are set by the ESPR category by category through delegated acts. For textiles —likely among the first— this includes composition, recycled content, durability and care/repair information. Map what your category requires and where each data point will come from (ERP, suppliers, lab).
Step 3 · Record lifecycle events with EPCIS 2.0
Here the passport stops being a static label and becomes a living history. With GS1 EPCIS 2.0 you record the what, where, when and why of each step: manufacture, shipment, sale, repair, resale and recycling. Start with manufacture and sale events; add the rest as the process matures.
Step 4 · Guarantee portability
Before scaling, apply the decisive test: can you export the passport as a self-describing file —identifiers, events and schema together— and have another actor read it without your platform? The Data Act (Regulation (EU) 2023/2854) reinforces exactly that portability right. If the answer is no, fix it before you grow.
Step 5 · Connect the physical carrier and publish
Print the QR (or place NFC) on the product or its label, verify that it resolves to the passport, and define what the consumer sees and what the machines read. From here, every new item is born with its passport.
Costly common mistakes
- Building on a proprietary database that is impossible to export.
- Trying to cover every attribute and category from the start.
- Treating the DPP as a marketing project rather than a data-governance one.
- Ignoring interoperability until a partner or customs demands it.
How much does it cost and how long does it take?
It depends on scope, but the pattern is clear: starting with one product line on open standards costs a fraction of rebuilding everything under regulatory pressure in 2027. An initial diagnostic lets you size the effort, the missing data and the roadmap realistically, before committing budget.
Frequently asked questions
Do I need to change my ERP to implement a DPP?
Not necessarily. In many cases the ERP is the source of several data points, but the passport is built on an identity-and-events layer that integrates with what you already have, without replacing it.
Can I start before I know my category’s delegated acts?
Yes. Identity (GS1) and events (EPCIS 2.0) are foundations common to every category; advancing them now is not wasted work when the specific requirements are published.
Who should lead the project internally?
It works best with a product/operations owner supported by systems, not as a purely IT project. It is a data-governance decision with business impact.
Ready to size your DPP?
Book an initial diagnostic and leave with a clear, realistic roadmap.
Related reading: What is a Digital Product Passport? · The research behind our approach
