eSign.AIeSign.AI

Industry Insights

EU Digital Product Passport: Data Integrity and Signing Controls

What ESPR requires for Digital Product Passport data integrity, and when electronic signatures, seals, timestamps, or other controls may support implementation.

eSign.AI Regulatory & Industry Research Team8 min read

What ESPR requires for Digital Product Passport data

The EU's Digital Product Passport Regulation, adopted under the Ecodesign for Sustainable Products Regulation (ESPR), requires manufacturers, importers, and supply chain partners to create and maintain a digital record for each product placed on the EU market. These records must be authentic, tamper-evident, and traceable — which places new demands on the digital signing infrastructure that organisations use to issue and verify product data.

ESPR

Regulation (EU) 2024/1781

2026

DPP first delegating acts in force

All EU products

Scope: physical goods on the EU market

Tamper-evident

Digital signatures required for data integrity

What the Digital Product Passport requires

A DPP is a structured digital record that carries product information across its entire lifecycle — from manufacturing to repair, reuse, and disposal. The regulation specifies that this data must be authentic, secure, and verifiable.

01

Each product (or batch) receives a unique identifier. Data is linked to this ID through a standardised data carrier — typically a QR code, RFID tag, or NFC chip.

02

Product data must be signed by an authorised representative of the manufacturer or importer. The signature must ensure data origin authenticity and detect post-issuance tampering.

03

Different actors in the supply chain (manufacturers, importers, distributors, repairers, recyclers) have different read and write permissions. Data access must be controlled and auditable.

04

The DPP persists across the product's entire lifecycle. Updates, transfers, and retirements must be signed and logged, creating a continuous chain of custody.

Digital signature requirements for DPP data

The DPP regulation does not prescribe a single signature format, but it requires signatures that meet the evidentiary standards of eIDAS for data integrity and authenticity. Here's how the requirements map to eIDAS signature levels.

DPP requirementeIDAS mapping
Data authenticityManufacturer must prove data originAdvanced Electronic Signature (AES): uniquely linked to signer, capable of identifying signer
Data integrityTamper must be detectableTechnical and organisational controls that make unauthorised changes detectable; a digital signature or seal may be one implementation option
Non-repudiationSigner cannot deny having signedEvidence appropriate to the actor and use case; where a regulated workflow requires strong attribution, a qualified signature or seal may be considered
TimestampSigning moment must be provableQualified electronic timestamp per eIDAS Article 41
Long-term validationDPP persists for product lifecycle (years/decades)PAdES/XAdES Long-Term Validation (LTV) format recommended
Machine-verifiableRegulators and supply chain partners must verify automaticallyStandardised signature formats (PAdES, XAdES, JAdES) enable automated verification

How DPP signing connects to enterprise PLM and ERP systems

Manufacturers placing products on the EU market

The primary obligation falls on the manufacturer (or the importer for non-EU manufacturers). They must create the DPP, sign the data, and ensure it remains accessible throughout the product lifecycle.

Supply chain partners

Importers, distributors, and authorised representatives have obligations to verify DPP presence and relay data. Repairers and recyclers may have write access to update specific DPP fields — these updates must also be signed.

Non-EU exporters to the EU

Companies outside the EU may need to coordinate DPP responsibilities with an EU importer or authorised representative. The relevant delegated act and product-specific rules determine who creates, updates, and can access the passport; eIDAS tools may support evidence, but ESPR does not impose a universal QES requirement.

IT and signing infrastructure owners

Teams responsible for identity, access control, data provenance, signing APIs, and records must ensure that DPP data remains authentic, reliable, available, and protected against unauthorised change. The control set should follow the applicable delegated act and system architecture.

How signing teams should prepare

DPP readiness is a data-governance and systems exercise. Signing or sealing may be useful controls, but teams should begin with the applicable product rules, data responsibilities, access rights, and evidence requirements.

01

Inventory affected product lines

Identify which products your organisation places on the EU market and map them to the relevant DPP delegating acts. Priority sectors include batteries, textiles, electronics, construction products, and furniture.

02

Assess current signing capabilities

Map how the system authenticates data contributors, controls updates, detects changes, records provenance, and preserves evidence. Where digital signatures or seals are selected, confirm the required format, certificate status, timestamping, and validation period.

03

Engage a QTSP

If the risk assessment or a product-specific rule calls for qualified trust services, verify the exact service on the EU Trusted Lists and test certificate issuance, automation, throughput, revocation checking, and long-term validation.

04

Design the DPP signing workflow

Map the full lifecycle: creation (manufacturer signs), updates (supply chain partners sign amendments), transfers (ownership changes require new attestations), and retirement (final decommissioning signature).

05

Plan for long-term archival

DPPs must persist for the product's entire lifecycle — potentially decades. Ensure your signature format supports Long-Term Validation, and plan for cryptographic algorithm migration as old algorithms weaken over time.

Manufacturer action plan for DPP compliance

Manufacturers placing products on the EU market must prepare for DPP requirements under the ESPR.

Audit product scope

Determine which of your products fall under the ESPR DPP requirements. The first product categories with mandatory DPP are batteries (from 2027), followed by textiles, electronics, and construction materials. Check the EU Commission delegated acts for your product category.

Map data sources

Identify where the required DPP data lives in your organisation: ERP for materials and bill of materials, PLM for specifications, LCA tools for environmental impact, supply chain management for supplier data. Plan how to aggregate this data into the DPP format.

Provision signing capability

Choose controls proportionate to the use case. If an organisational seal is selected, obtain the appropriate certificate from a verified provider, configure secure key use, and test sealing and validation with representative product data.

Register with the EU DPP system

Prepare the passport and data carrier according to the applicable delegated act and the technical interfaces available for the product group. ESPR provides for a DPP registry and unique identifiers, but implementation teams should not assume a universal submission workflow before the relevant specifications are final.

Common questions from compliance teams

The DPP regulation requires data authenticity and integrity but does not explicitly mandate QES for every record. However, eIDAS-aligned QES provides the strongest legal presumption of authenticity and non-repudiation, which is valuable when product data is challenged in disputes or regulatory inspections. Many organisations are adopting QES as a risk-management choice rather than a strict legal minimum.

How eSign.AI can support DPP evidence workflows

eSign.AI can support electronic-signature and digital-seal steps within a broader DPP evidence workflow. The customer remains responsible for confirming the applicable product rules, registry interfaces, trust-service configuration, and system integrations.

Qualified electronic seal via API

Where a deployment includes an organisational seal, an enterprise system can invoke a configured signing service through an API. Before production use, verify the certificate holder, trust-service provider, key custody, throughput, revocation handling, and audit evidence.

ERP and PLM integration

ERP, PLM, MES, and supplier systems can provide source data to an integration layer, while eSign.AI handles the configured signing or sealing step. Connector availability, field mapping, delegated-act schemas, and registry submission must be validated for the customer's actual environment.

Multi-party supply chain signing

DPP data often comes from multiple parties. A workflow can capture who supplied or approved each contribution and preserve associated evidence. Whether every contributor should sign or seal its data is an architecture and legal decision, not a general ESPR requirement.

Audit-ready evidence

Every DPP submission generates a complete evidence package: sealed data payload, QSeal certificate chain, timestamp token, and EU registry submission receipt. This evidence is stored for the product retention period and can be exported for market surveillance audits.

Team discussing the right eSignature approach for a business

Explore the right eSignature approach for your business

Talk to our team about eSignature requirements, compliance considerations, and document workflows across your target markets.