Published on 8/6/2026
The Digital Product Passport and the Code That Carries It
The EU's ecodesign rules introduce a Digital Product Passport: a set of information about a product — materials, repairability, compliance, end-of-life — reachable from the product itself through a data carrier. In practice, for most goods, that carrier is a QR code.
Timelines arrive per product group, in separate delegated acts, and the first working programme puts textiles and steel near the front; batteries are covered by their own, earlier regulation. So the date that matters to you is your product group's, not a general one — and that is the first thing to look up rather than take from an article.
What we can be useful about is the part every manufacturer will hit regardless of the date: the code itself.
The requirement nobody costs correctly
A passport must stay reachable for as long as the product is in use. A sofa is bought for fifteen years. Structural steel outlives the building's owner. A tyre is scanned by a recycler at the end of a life nobody planned.
Now compare that with the average life of a corporate website — a rebuild every three to five years, a CMS migration, a rebrand, an acquisition that moves the domain. The code is stamped once and permanently; the thing it points at will move several times.
Which produces the single most important design decision, and it costs nothing to make now: the code must carry an address you control and can repoint, not a deep link into whatever system currently holds the data. Marking a URL that dies with your next CMS migration means marking every unit again — except you cannot, because they are already in the world.
Why GS1 Digital Link comes up
Products already carry an identifier for trade. GS1 Digital Link expresses that identifier as a web address, so a single code can serve the till, the warehouse and the consumer — the same square resolves to whatever each caller needs, instead of the product wearing one barcode for retail and a second code for the passport.
That matters here for a practical reason: packaging real estate is finite, and a second code competes with the first for space and attention. We support GS1 Digital Link on the Business plan for exactly this case.
What we do and, more usefully, what we do not
Being clear about the boundary is worth more to you than a sales pitch, because the gap is where projects fail.
What this service does: generates the code, keeps the destination editable for the life of the product, exports print-quality SVG for labels and marking, counts scans, and checks the design's readability before you commit to a marking run.
What it does not do: store or serve passport data, model the data structure a delegated act requires, validate your content, or certify anyone's compliance. The passport itself lives in your PLM, your ERP or a specialist platform. We are the durable pointer to it — a real and separable job, and not the whole one.
Anyone selling you a QR generator as a DPP solution is either confused or hoping you are.
Practicalities that are settled already
- One code per item or per batch, not per product line. A passport is about a specific thing. A single code for the whole catalogue forces a consumer to search, and a recycler will not.
- Mark it to survive the product, not the sale. The label that carries the passport has to be readable at end-of-life, after years of sun, washing, abrasion or workshop grime. A paper label on a sofa is legible in the showroom and gone by the time it matters.
- Assume a cheap phone in bad light. The scanner at end-of-life is a recycler in a yard, not a marketing team with a demo device.
- Print the address as text too. A code damaged beyond reading still has a typeable line beside it, and that line costs nothing at design time.
- Size for the surface and the process. Laser marking, moulding and woven labels each have a smallest mark they can hold cleanly — the module has to be bigger than that, which is a different question from what looks fine on screen.
- Consumers will scan it out of curiosity. A passport code is a consumer touchpoint whether you intended it or not, so the page behind it should be readable by a person, not only parseable by a machine.
What we record, since consumers will be scanning
Time, which code, device type, operating system and browser as the request reports them, the referrer if the browser sends one, and a salted hash of the IP address for counting unique visitors. No identity, no account, and no location at all — not even a country.
Whether a mandatory carrier may be measured at all, and on what basis, is a question for the act that governs your product group. We are telling you exactly what exists so you can put that question precisely.
What to do this year
- Find your product group's delegated act and its date. Everything else follows from it.
- Decide where the passport data will live, and treat that as separate from the code.
- Reserve a stable address space you control, and point the codes at it — so a future migration is a redirect, not a recall.
- Test the marking on the real material now: a laser sample, a woven label, a moulded panel. Materials, not renders, decide what survives.
- Only then generate at scale.
Quick answers
- Is a QR code required? The rules require a data carrier; for most goods a QR code is the practical choice.
- When does this apply to me? Per product group, via delegated acts. Textiles and steel are in the first working programme; batteries fall under their own earlier regulation.
- Static or dynamic? Dynamic, unambiguously. The product outlives the website behind it.
- Do I need GS1? Not always — but if the product already carries a GS1 identifier, Digital Link lets one code serve retail and the passport.
- Are you a DPP platform? No. We generate and maintain the carrier; the passport data lives in your systems.
- How long must the code work? For the product's life, which for furniture or steel is decades — plan the address accordingly.