4 Digital Product Passport myths that are slowing down your compliance strategy
- Sep 1
- 9 min read
Updated: 2 days ago

If you work in supply chain, ESG, quality, procurement, or legal, you have heard the term “Digital Product Passport” more times in the last year than in the previous five combined. You have probably also heard four claims about it that are, at best, incomplete - and at worst, actively steering your organization’s DPP strategy in the wrong direction.
The Digital Product Passport (DPP) is becoming a condition for market access across Europe, with regulations like the Ecodesign for Sustainable Products Regulation (ESPR), the EU Battery Regulation, and the Critical Raw Materials Act converging on the same principle: products need verifiable, structured data attached to them throughout their lifecycle. Up to six million companies in Europe could ultimately be required to provide one (Source: EU CEN-CENELEC JTC5).
Yet as adoption accelerates, so does the noise. Below, we unpack the four misconceptions we hear most often from supply chain and compliance leaders, and what the shift from understanding the DPP to executing it actually requires.
Myth #1: “The Digital Product Passport is just a sticker with a QR code”
This is the most common misconception about DPPs, and it's an understandable one. A QR code is the only part of a DPP most people will ever see, so it's easy to assume the QR code is the passport.
It isn’t. The QR code - or any equivalent data carrier - is only the access point. The Digital Product Passport itself is the data infrastructure behind that access point: the systems that collect information from suppliers, validate and enrich it, structure it against regulatory requirements, govern who can see what, and keep it continuously updated across a product’s lifecycle.
Scanning a QR code takes seconds. Building the capability behind it - mapping supply chains beyond Tier 1, standardizing data formats across suppliers with wildly different levels of digital maturity, and keeping that data accurate as products, suppliers, and regulations change - takes considerably longer. A Digital Product Passport is, at its core, a structured, interoperable digital record that compiles all relevant product data (materials, provenance, certifications, manufacturing details, traceability logs, technical specifications, and end-of-life instructions) into a single, accessible framework, continuously updated to link product identity, lifecycle events, and traceability over time.
Treating the DPP as a label to print is how organizations end up with a QR code that links to incomplete, unverifiable, or outdated data, which defeats the purpose the moment a regulator, retailer, or customer actually checks it.
Myth #2: “The DPP is just another marketing tool”
At the opposite end of the spectrum from “it's just a sticker” sits “it's just a brochure with a QR code.” Some organizations approach their DPP as a storytelling opportunity first and a compliance system second. That framing gets the priority backwards.
A Digital Product Passport is not based on static, marketing-authored declarations. It structures dynamic, verifiable data shared across the value chain, and it is defined by regulatory and operational requirements: an auditable data system, not just a communication channel. Yes, a well-executed DPP can strengthen customer trust: Longchamp, for instance, has embedded its DPP into a consumer-facing CSR and product-transparency experience, giving shoppers access to sourcing, certifications, and care instructions by scanning a QR code on the bag itself. But that consumer-facing layer sits on top of a structured, auditable data foundation - it doesn't replace it.
Confusing the two is a real operational risk. A DPP built primarily as a marketing asset will typically lack the granularity, chain-of-custody, and audit trail that regulators, auditors, and B2B partners require. Compliance and traceability come first; trust-building is the dividend, not the design brief.
Myth #3: “A Digital Product Passport will expose all our sensitive data”
This is the objection we hear most from legal and procurement teams, and it's a reasonable instinct: transparency at this scale sounds, on its face, like an IP and confidentiality risk.
But transparency doesn't mean every stakeholder sees everything. A properly designed DPP does not expose the same information to all stakeholders. Data access is governed by structured authorization rules based on roles, responsibilities, and regulatory rights: some information is meant to be public (think care instructions or country of origin for consumers) while other data, such as supplier identities, sensitive material formulations, or compliance documentation, stays restricted to regulators or authorized business partners.
In practice, this means a functioning DPP architecture needs multiple layers of visibility combined with controlled access mechanisms: role-based access controls, encryption, and granular permissioning built into the system from the start, not bolted on afterward. Governance isn't an external policy layered over the data; it's a structural component of the architecture itself, defining who owns each data domain, who can update it, and who can see it. Get that right, and a DPP protects sensitive information while meeting disclosure obligations. Get it wrong - or skip the design work - and you end up with either an unusable black box or an uncomfortable amount of exposure. Understanding this balance is essential to any DPP initiative that will actually survive contact with legal review.
Myth #4: “The DPP is just another cost for ESPR compliance”
The fourth myth is the most consequential, because it shapes budget conversations and long-term architecture decisions, not just messaging.
Looking at DPPs only through the lens of ESPR means missing the bigger picture. Yes, ESPR - in force since July 2024, with the first sector-specific requirements expected from 2027 starting with textiles, and coverage extending to nearly all product categories by 2030 - is currently the primary driver of DPP adoption in the EU. But it is one driver among several. The EU Battery Regulation introduces its own mandatory DPPs from 2027. The Critical Raw Materials Act adds a DPP requirement for permanent magnets from 2027. Construction products, toys, and packaging each have their own regulatory tracks converging on the same underlying logic. And outside Europe, countries including the United States, China, Turkey, and Vietnam are exploring frameworks aligned with the same core principles: product-level data, traceability, interoperability, and verifiable supply chain information.
Treating the DPP as a single-regulation, single-market cost center leads organizations to build narrow, disposable solutions - systems designed to satisfy one delegated act that will need to be rebuilt the moment the next regulation, market, or product category comes into scope. The alternative is to treat the DPP as what it is becoming: a strategic, reusable product data infrastructure that can support traceability, due diligence, market access, and future regulatory requirements simultaneously, not just one line item on a compliance budget. Companies that build this capability once, designed to absorb change, will spend the 2027–2030 wave of regulatory deadlines extending an existing system. Companies that don't will be rebuilding from scratch every time a new delegated act lands.
Why this matters now: from theory to operational execution
Understanding what a DPP is - and isn't - is only step one. The organizations furthest ahead have already moved from defining the DPP to operating one.
That shift showed up clearly in Gartner’s first-ever Emerging Market Quadrant for Digital Product Passport, published July 6, 2026, which named Tilkal a Market Shaper - the quadrant position representing the strongest combined potential to execute and to disrupt the market. Gartner’s evaluation weighted exactly the operational factors that separate a working DPP from a compliance slide deck: a track record of large-scale production deployments, the use of open data standards such as GS1 EPCIS 2.0 and the UN Transparency Protocol (UNTP), the application of AI for data integration, and active participation in standards-setting bodies.
"A Digital Product Passport is only as credible as the traceability data behind it." — Matthieu Hug, CEO and co-founder, Tilkal
That's the crux of moving from theory to execution. A DPP strategy built on assumptions and partial interpretations of “what the regulation will require” is not an operational DPP - it's a readiness gap waiting to surface during an audit or a market-access check. Real execution means:
Mapping data beyond Tier 1 - most organizations have visibility into direct suppliers; DPP-grade traceability requires structured access to Tier 2, 3, and beyond.
Verifying data before it's shared - supply chain data cannot be inherently trusted. It has to be checked for consistency, completeness, and provenance before it becomes part of an auditable record.
Building on open standards, not custom formats - alignment with GS1 EPCIS, GS1 Digital Link, and UNTP is what allows DPP data to move between systems, suppliers, and regulatory infrastructure like the EU DPP Registry without manual reconciliation.
Designing for continuous change - a DPP built for time T will not survive time T+1 unless the underlying architecture can absorb new suppliers, new markets, and new regulatory data points without a full rebuild.

This isn't theoretical for the companies already doing it. Eramet, a global mining and
metallurgical group, deployed a Digital Product Passport for manganese alloys with Tilkal that has already traced over 1.2 million tons of material and generated Scope 3 carbon calculations from real operational data, rolled out site by site over 12 months. Longchamp has pushed supplier onboarding to Tier 4 across its textile, footwear, and leather goods lines. CHO Group, an olive oil producer, deployed a DPP across more than 70 product references in under five months, structuring farm-to-consumer traceability in a historically fragmented agricultural supply chain.
None of these were built by printing QR codes on packaging. They were built by treating the DPP as what it actually is: a living, governed data infrastructure - the same conclusion the four myths above all point back to.
Occupying the DPP conversation, not just complying with it
The pattern across all four myths is the same: each one shrinks the Digital Product Passport down to something smaller, simpler, and less strategic than it actually is - a sticker, a brochure, a liability, a line item. Each shrunken version is easier to dismiss, easier to underfund, and easier to get wrong.
The organizations earning recognition as market leaders - and the ones that will be ready when ESPR's first textile requirements land in 2027 and the wave of sector-specific delegated acts follows - are the ones treating the DPP as what analysts (Gartner), the standards bodies, and the early operational deployments all confirm it to be: durable, cross-regulatory infrastructure for trusted product data, not a one-off compliance artifact.
Want the full picture: how DPPs are structured, governed, architected, and deployed at scale, with real case studies?
FAQ: Digital Product Passport, explained
What is a Digital Product Passport (DPP)?
A Digital Product Passport is a structured, interoperable digital record that compiles a product's data - materials, provenance, certifications, manufacturing details, traceability events, environmental performance, and compliance status - into a single, continuously updated record linked to that product throughout its lifecycle. The QR code or data carrier consumers scan is only the entry point; the DPP itself is the underlying data infrastructure.
Is the Digital Product Passport only about ESPR compliance?
No. ESPR (the EU Ecodesign for Sustainable Products Regulation) is currently the main driver of DPP adoption in Europe, with first requirements expected from 2027 starting with textiles, but the DPP logic extends across the EU Battery Regulation, the Critical Raw Materials Act, construction products, toys, and packaging regulations, and similar frameworks are emerging outside the EU in markets including the US, China, Turkey, and Vietnam. Organizations that build DPP infrastructure as a reusable capability, rather than a single-regulation project, are better positioned for this broader convergence.
Does a Digital Product Passport expose confidential business data?
Not when it's designed correctly. DPPs rely on role-based access controls, data granularity, and governance rules so that different stakeholders (consumers, regulators, business partners) see different levels of information. Public-facing data (like country of origin or care instructions) can coexist with restricted data (like supplier identities or proprietary formulations) within the same system.
Which companies are required to have a Digital Product Passport?
In Europe, requirements are being phased in by product category under ESPR delegated acts, starting with textiles from 2027 and expanding to cover most regulated categories by 2030, alongside sector-specific rules like the EU Battery Regulation (2027) and the Critical Raw Materials Act (2027, for permanent magnets). Estimates suggest up to six million companies in Europe could ultimately be affected, spanning manufacturers, importers, distributors, and marketplaces.
What does it take to move from DPP theory to operational execution?
Execution requires four things a compliance checklist alone won't give you: multi-tier supply chain visibility (beyond Tier 1 suppliers), the ability to verify data before it's used, alignment with open interoperability standards like GS1 EPCIS and UNTP, and an architecture that can absorb new regulations, markets, and suppliers without a full rebuild. A readiness assessment across data, governance, systems, and supplier maturity is typically the first step.
Why was Tilkal named a Market Shaper by Gartner?
In its inaugural Emerging Market Quadrant for Digital Product Passport (published July 6, 2026), Gartner named Tilkal a Market Shaper - the quadrant position reflecting the strongest combined ability to execute and to disrupt the market - citing Tilkal's track record of large-scale production deployments, its use of open standards (GS1 EPCIS 2.0, UNTP), its application of AI for data integration, and its active role in DPP standards-setting.




Comments