How it works
Content negotiation, one passport address with two answers
One web address can answer a person with a page and a machine with structured data. The caller states which answer it wants.
Content negotiation is how one web address serves both a person and a machine. The caller states the form of answer it can use, and the server sends that form from the same address.
It is an ordinary feature of the web. Nobody invented it for digital product passports.
A supplier demonstrates a code that opens a page, because the page is the part that demonstrates well. Your European customer then asks for the machine answer, finds a web page, and you pay for the work a second time.
The caller states the form it wants, and the server sends that form
A request for a web address carries a field named Accept. That field states what the caller can read.
A browser asks for a page. A computer system asks for structured data. The server reads the field and sends the matching answer. The web address stays the same. No European Union text that this site has read names the format of that structured data. See why no EU law names a data format.
Take the label on an e-bike battery. A person scans the code with a phone and reads a page in words. The importer's compliance system calls the same address, asks for structured data, and takes the fields into its own records.
The same mechanism also picks a language. A caller can send a field named Accept-Language, and a German reader then gets German. That field is the reason one printed code can serve two markets.
A passport has one address and more than one type of reader
Two European Union (EU) laws decide who reads a passport. Neither one requires a passport for your product today.
| Law | Status | Passport duty |
|---|---|---|
| Ecodesign for Sustainable Products Regulation (ESPR), Regulation (EU) 2024/1781 | In force since 18 July 2024 | None yet for any product group |
| The battery regulation, Regulation (EU) 2023/1542 | In force | Starts 18 February 2027 |
ESPR creates no passport duty for a product group until the European Commission adopts a delegated act for that group. It has adopted none, as at 14 August 2026.
The battery duty covers three categories:
- each light means of transport (LMT) battery, such as an e-bike battery
- each industrial battery with a capacity greater than 2 kilowatt hours
- each electric vehicle battery
See batteries for the scope of that duty.
Three verified rules describe a reader that is a computer system.
| Verified rule | What it requires |
|---|---|
| ESPR Article 14 | A public web portal where stakeholders search and compare passport data |
| ESPR Article 15 | Customs receive the registration identifier for the product |
| Battery regulation Article 78(a) | Full interoperability for the battery passport |
Warning: Article 78 governs the battery passport alone. It sets no rule for the passport of any other product.
Read the three rows together. A portal that compares two entries needs data that a computer can read. A customs system reads an identifier. Full interoperability means that another organisation's system reads the record correctly. See the EU portal.
A person still scans the code on the pack and wants words. So one address has to answer two kinds of caller, and content negotiation is the ordinary way to do that. That last sentence is a conclusion from the rules above, and not a quotation from any of them.
The battery passport also splits its readers three ways, under Article 77(2) of the battery regulation. Warning: none of those three groups contains another, and the answer for each one is different. See who can see what.
No law that this site has read names content negotiation
Read this part carefully, because a supplier may tell you otherwise. Content negotiation is how the work is usually done. It is not a requirement that this site can cite.
ESPR names no web address form either. A search of the full regulation returns no hit for GS1, for Digital Link, for IEC 61406 or for the digital object identifier (DOI). The search covered the recitals, the 79 articles and every annex.
What ESPR names instead is the ISO/IEC 15459 series, in Annex III. The rule names parts 1 to 6. It covers the data carrier and the unique product identifier, where relevant for the products concerned. Article 10(1)(c) makes it an interim rule, until the Commission publishes the references of harmonised standards. See GS1 Digital Link.
One industry standard does describe the mechanism. GS1 is the standards body behind the barcode on a retail product. GS1 ratified Release 1.2.0 of its GS1-Conformant Resolver Standard in January 2026.
Warning: GS1 is a standards body and not a regulator. Read that standard for what a resolver does, and never for what the law requires.
Under that standard a client can ask for the set of links with the Accept field. A resolver should also support Accept-Language.
This site has not read EN 18216, the standard for data exchange protocols
The Commission cited six European standards for the passport in Implementing Decision (EU) 2026/1736. That Decision is in force. One of the six titles names data exchange. That standard is EN 18216:2026, and its official title is "Digital product passport - Data exchange protocols".
Name the six one by one, because two numbers are missing:
- EN 18216
- EN 18219
- EN 18220
- EN 18221
- EN 18222
- EN 18223
There is no EN 18217 and no EN 18218. A supplier who writes the set as a range names two documents that do not exist.
Warning: the distributor listings put each text between 190 and 370 EUR. This site has bought none of them. So this site states no protocol, no format and no rule from EN 18216. A title is a name, and it is not a scope. See EN 18216 and why the texts are paywalled.
Citation does not make a standard mandatory in any case. It gives a product built to the standard a presumption of conformity. That presumption comes from ESPR Article 41(2). It reaches the requirements in Articles 10 and 11.
Ask a supplier to show you the machine answer, not the page
Warning: do not accept a demonstration of the page as proof of the machine answer. The page is the part that a seller shows you.
- Ask the seller to call one address twice, as a browser and as a system.
- Ask what label the machine answer carries. An answer written as linked data has its own label,
application/ld+json. - Ask which of the six cited standards the service implements, by number.
- Ask for a saved copy of the machine answer for one of your own products.
- Send that copy to your European customer. Ask if their system reads it.
Step 5 settles most of these conversations. Your customer's system is the test that matters, and no law today gives you a better one. See why your website cannot be the passport.
You will probably not host the passport, but your data must be current
You will probably not host the passport. The operator that places the product on the EU market carries that duty. If you have no EU establishment, that operator is usually your importer. See what a resolver is.
Your data still has to be structured and current. The importer cannot supply what you do not send, and an email attachment is not a machine answer.
This site searched for New Zealand material on 16 August 2026, in fifteen separate searches, and read 104 separate pages. The Ministry of Foreign Affairs and Trade wrote the substantial government account, in a market report of October 2025. See what New Zealand agencies have said.
No page in that search explains how to build, host or resolve a passport. The MFAT advice stops at the integration of data tracking and reporting systems.
If you sell food or drink, none of this reaches that product. ESPR Article 1(2) excludes food, and ESPR counts drink as food. The exclusion covers the product and not the company. Your packaging is a separate product under a separate law. See food and feed are excluded and what this means for New Zealand exporters.