Data, access and durability
Personal data in a digital product passport: open questions
The product law limits personal data in a passport. No article read here requires a passport to be immutable, and the EU registry holds data about people.
No verified field in a digital product passport describes a person. The product law goes further than that, because it limits what a passport may hold about a customer. It permits that data only if the customer gives explicit consent.
One claim on this subject can cost you money. A supplier may tell you that a passport must be permanently unchangeable, and that nobody can then erase a record in it. If you believe that claim, you pay for a system built to a requirement that no article read here sets. Ask that supplier to name the instrument and the article.
The ecodesign regulation bars customer personal data without consent
The Ecodesign for Sustainable Products Regulation (ESPR) is Regulation (EU) 2024/1781. It has been in force since 18 July 2024. Article 10(1), point (e), reads:
personal data relating to customers shall not be stored in the digital product passport without their explicit consent in compliance with Article 6 of Regulation (EU) 2016/679;
Recital 43 of the same regulation puts the idea in one sentence:
Personal data of customers should not be stored in the digital product passport.
So the ecodesign regulation does not ask a passport to carry personal data. It permits customer personal data on explicit consent, and it names the consent rule that applies.
Recital 43 also splits the work between two instruments. A national authority works under Regulation (EU) 2016/679, the General Data Protection Regulation. The European Commission works under Regulation (EU) 2018/1725, which covers the Union institutions. Article 13(3) of the ecodesign regulation makes that split binding for the registry:
In relation to its responsibility to set up and manage the registry and the processing of any personal data that might result from that activity, the Commission shall be regarded as controller as defined in Article 3, point (8), of Regulation (EU) 2018/1725.
Article 11, point (h), adds a design duty for every passport:
digital product passports shall be designed and operated so that a high level of security and privacy is ensured and fraud is avoided.
One study for the European Parliament says the same thing. Jeremy Legardeur and Pantxika Ospital wrote "Digital product passport for the textile sector", PE 757.808, in June 2024. Its recommendations state:
For DPP implementations involving usage, we do not recommend integrating customers' personal data (e.g., user registrations, product ownership history), because adherence to General Data Protection Regulation (GDPR) principles will be mandatory.
That is a study, and it is a recommendation. It is not law. This site names it because it is independent of any passport vendor.
No article read here requires a passport to be immutable
A supplier may tell you that a passport must be permanently unchangeable. That claim decides how you build the system, so test it before you pay for it.
This site searched three legal texts for the words that would carry such a rule. The battery regulation was searched twice, as published and as consolidated, and both gave the same counts.
| Word searched | ESPR | Battery regulation | Registry regulation |
|---|---|---|---|
| immutab | 0 | 0 | 1 |
| unalter | 0 | 0 | 0 |
| tamper | 0 | 0 | 0 |
| unchang | 0 | 0 | 0 |
| irrevers | 0 | 0 | 0 |
| append-only | 0 | 0 | 0 |
| write-once | 0 | 0 | 0 |
| blockchain | 0 | 0 | 0 |
| distributed ledger | 0 | 0 | 0 |
| permanent | 0 | 7 | 0 |
| indelib | 1 | 3 | 0 |
Two of those words return hits, and every hit describes a physical thing. The word indelible describes the CE marking and the printed battery label. The word permanent describes a cable connection, an end of trade, and instructions kept online. No hit sets a rule about passport data.
The single hit for immutability sits in the registry implementing regulation, Regulation (EU) 2026/1778. It is in Article 14, which governs the log system of the Commission registry. Article 14(5) reads:
The Commission shall implement appropriate technical and organisational measures to guarantee the security of all logs and protect their integrity, in particular against unauthorised or unlawful processing, accidental loss, destruction or damage. Such measures shall, at least, ensure the immutability and confidentiality of the logs.
So the one immutability duty found here covers the audit trail of the Commission's own registry, not a passport.
One more word deserves a note, because a supplier can point at it. Article 10(1), point (a), of the ecodesign regulation requires a persistent unique product identifier. The word persistent covers the identifier. It does not cover the data behind the identifier.
Three provisions require the record to change
| Provision | What it says |
|---|---|
| ESPR Article 9(1) | "The data in the digital product passport shall be accurate, complete and up to date." |
| Battery regulation Article 77(8) | "A battery passport shall cease to exist after the battery has been recycled." |
| Registry regulation Article 19(2) | The operator keeps the registered information accurate, complete and up to date at all times |
Article 10 of the registry regulation is titled "Registration data management", and it names deletion three times. Paragraph 1 reads:
Any change to the digital product passport registration data, including its creation, modification and deletion, shall be logged in the log system of the registry in accordance with Article 14 and reflected in the status of the registration.
Paragraph 2 requires versioning and a timestamp for each update. Paragraph 3 deletes registration data automatically 10 years after registration, where Union law sets no other period. Paragraph 4 gives a registry user the right to ask for the deletion of their own account.
The ecodesign regulation assumes the same thing. Article 11, point (f), restricts "the rights to introduce, modify or update data in the digital product passport". Point (g) requires that "data authentication, reliability and integrity shall be ensured". A rule about who may change data assumes that somebody changes it.
Warning: this site reads the texts above as a set of duties to keep the record current. It does not state that no immutability rule exists anywhere in Union law. Ask the supplier for the instrument and the article, then read the article.
One paper shows where the idea comes from. Illan Garcia and others wrote "Digital Product Passport Management with Decentralised Identifiers and Verifiable Credentials", arXiv 2410.15758, in October 2024. It takes the integrity requirement in Article 11, point (g), and adds a design step: passport data "should become immutable to ensure its integrity". The paper presents that step as its own choice, and not as a rule of law.
The EU registry stores personal data about people, not about products
This part reaches your own company. Article 18 of the registry regulation is titled "Personal data". Paragraph 1 requires the Commission to store these items for each registry user:
- the first and last name of the user, or of the legal representative
- the authentication credentials that the user needs for secure access
- the postal address of the economic operator or the value chain actor
- the email address of the user
- metadata in an uploaded document, where it helps to identify the user
Paragraph 2 goes further, and it names an identity number:
In the case of natural persons, it shall also be required to store personal identifiers, such as a passport number, national identity card number or national eID number, civil registry number, tax identification number issued by the relevant national authority of the respective Member State, or any third-country identifier that is assigned to a person or any documentation that identifies that person.
Read that list with care. The word passport in it means a travel document.
Paragraph 3 names the rule that governs those data:
Personal data collected shall be processed in accordance with Regulation (EU) 2018/1725.
So the person in your company who enrols in the registry gives a name and an identity number to the Commission. That is personal data about a company representative. It is not data in a passport. See the EU registry.
Article 19(5) puts the submitted data back on the company:
Each verified economic operator shall be responsible for the data it submits to the Commission as manager of the registry and shall be considered as the controller of the data it submits.
The battery regulation gives no data protection rule of its own
The first binding passport duty in EU law is Article 77 of Regulation (EU) 2023/1542, the battery regulation. That regulation does not use the words below. The counts come from a search of two texts of the same act.
Warning: this is the result of a search of two documents. It is not a statement about the world. Other Union law still reaches the company that processes personal data.
| Words searched | Text as published | Consolidated text |
|---|---|---|
| personal data | 0 | 0 |
| data protection | 0 | 0 |
| 2016/679 | 0 | 0 |
| privacy | 2 | 1 |
The two hits for privacy are recital 126 and Article 78, point (h). Neither one names a data protection instrument. The consolidated text carries no recitals, which is why it holds one hit and not two.
Article 17 of the General Data Protection Regulation carries its own exception
Warning: this site does not state that the exception settles any particular case. It states the exception, cites it, and stops there. Take your own case to a legal adviser who reads EU law.
A supplier may tell you that a passport stops the right to erasure. Article 17 sets that right, and paragraph 3 limits it. The paragraph opens with the words "Paragraphs 1 and 2 shall not apply to the extent that processing is necessary". Point (b) then reads:
for compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
Regulation (EU) 2018/1725 carries the matching exception for a Union institution, in Article 19(3), point (b). Its words are shorter, because its controller is always a Union institution. Do not quote one act and cite the other.
The General Data Protection Regulation can reach a company in New Zealand
Article 3(2) sets out two cases that reach a company outside the Union:
This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to: (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or (b) the monitoring of their behaviour as far as their behaviour takes place within the Union.
So the reach does not depend on an office in Europe. It depends on what your company does with data about people who are in the Union. This site cannot tell you if your own processing meets either case.
The first binding passport duty in EU law records product facts
| Item | Detail |
|---|---|
| Instrument | Regulation (EU) 2023/1542, the battery regulation, in force |
| Passport duty | Article 77 |
| Date the duty starts | 18 February 2027 |
The duty covers three categories of battery:
- each light means of transport (LMT) battery, such as an e-bike battery
- each industrial battery with a capacity greater than 2 kilowatt hours
- each electric vehicle battery
Every battery carries a QR code under Article 13(6). For a battery outside the three categories, that code gives other information, and not a passport. See batteries for the scope and the date.
The table gives examples of the recorded fields. Each one states a fact about a battery.
| What the passport records | Where the rule sits |
|---|---|
| The detailed composition, including the cathode, anode and electrolyte materials | Annex XIII point 2 |
| The recycled shares of cobalt, lithium, nickel and lead | Annex XIII points 1(e) and 1(f) |
| The responsible sourcing information from the due diligence policy report | Annex XIII point 1(d) |
| The state of health and the other item-level performance values | Annex XIII point 4 |
Take an e-bike battery sold through an importer in Amsterdam. The chemistry, the recycled cobalt share and the responsible sourcing information are facts about the battery. They stay the same facts whoever rides the bike.
The ecodesign regulation sets no field list for any product group. The European Commission has adopted no delegated act for any group, as at August 2026. So no other verified field list exists. See what a passport holds.
The access tiers control readers, and they answer no privacy question
Article 77(2) of the battery regulation sets three tiers of reader. The general public reads one part of the data. Notified bodies, market surveillance authorities and the Commission read a second part. A person with a legitimate interest reads a third part.
The tiers are not nested. Each tier reads data that another tier cannot read. See who can see what.
The tiers answer one question: who may read a field about a product. They are a disclosure rule inside product law. This site does not present them as data protection compliance.
Article 78(d) bars resale of the data, and that is data governance
Article 78 sets the technical requirements for the battery passport. Point (d) bars resale and re-use of the passport data by authorised third-party hosts.
That rule protects the operator whose data sits on somebody else's server. It states what a hosting company may not do with your product data. It governs commercial data, and it answers no privacy question.
The difference matters when you read a contract. A supplier who quotes Article 78(d) has answered a commercial question about data re-use. See commercially sensitive data and what a service provider does.
Three questions this site cannot answer
Each question below needs a source that this site does not have. Do not treat any of the three as settled.
Can an item-level record identify the person who owns the item?
A battery passport belongs to one physical battery. It does not belong to a model or to a batch.
Annex XIII point 4 records values that change after the sale. Point 4(d) requires:
information and data resulting from its use, including the number of charging and discharging cycles and negative events, such as accidents, as well as periodically recorded information on the operating environmental conditions, including temperature, and on the state of charge.
An e-bike battery usually has one owner, and that record sits against one unique identifier. The record could become information about an identifiable person. That result depends on who holds the record and what else they hold. No text read here answers that question. See lifecycle events.
Is a person with a legitimate interest identified when they ask for access?
The third tier gives access to any person with a legitimate interest. The Commission must adopt implementing acts that say who counts as such a person.
Article 77(9) sets the deadline at 18 August 2026. This site searched for the acts on 15 August 2026 and found none.
An access check needs to know something about the person who asks. This site cannot say what that requirement means in law. See public data versus legitimate interest.
What happens when a duty to keep meets a duty to erase?
Article 78(e) requires the battery passport to stay available after the responsible operator ceases to exist or ceases its activity in the Union.
If any record in a passport is ever treated as data about a person, a duty to erase that record could meet that requirement. Article 17(3), point (b), of the General Data Protection Regulation is the provision that addresses such a case. This site does not say how it applies to a passport. See how long a passport lasts and what happens if the company closes.
This site made nine searches, and no document from a European data protection body came back
This site never presents an absence as a fact. The table records the searches, so that you can judge them yourself.
| Search | Result |
|---|---|
| "data protection supervisor" in the ecodesign regulation | 0 hits |
| "data protection supervisor" in the battery regulation | 0 hits |
| "data protection supervisor" in the registry regulation | 0 hits |
| European Data Protection Board site search, "digital product passport" | Results returned, and none was about a product passport |
| European Data Protection Board site search, "ecodesign" | Results returned, and none was about ecodesign |
| European Data Protection Supervisor website | Unreachable. It answered every request with an error |
| CIRPASS deliverable D2.1, the legal mapping | 0 hits for "GDPR" and for "personal data" |
| CIRPASS recommendations report | 2 hits for "GDPR", both about its own survey ethics |
| General web search engines | Unreachable. Three engines blocked the request |
So this site has read no European Data Protection Board document and no European Data Protection Supervisor document on the digital product passport. That does not mean that none exists. See what this site does not know.
Your EU importer usually carries the duty, so name who answers a data protection request
A New Zealand company usually has no office in the EU. The operator that places the product on the EU market carries the passport duty, and that operator is usually your importer. See what this means for New Zealand exporters.
Warning: a supplier who cannot name the instrument and the article has given you an opinion. Treat it as an opinion, and put the question to your legal adviser. See agreeing data duties.
- Write down every passport field that changes after you sell the product.
- Ask your legal adviser if any of those fields can point to a person.
- Ask your EU importer who answers a data protection request, and name that person in the supply agreement.
- Ask each passport supplier to name the instrument and the article behind every privacy claim they make.
- Put the same question to any supplier who says a passport must be immutable.