Regulation (EU) 2024/1781
The EU Digital Product Passport requires qualified electronic signatures
The EU's Digital Product Passport Regulation, adopted under the Ecodesign for Sustainable Products Regulation (ESPR), requires manufacturers, importers, and supply chain partners to create and maintain a digital record for each product placed on the EU market. These records must be authentic, tamper-evident, and traceable — which places new demands on the digital signing infrastructure that organisations use to issue and verify product data.
DPP first delegating acts in force
Scope: physical goods on the EU market
Digital signatures required for data integrity
What the Digital Product Passport requires
A DPP is a structured digital record that carries product information across its entire lifecycle — from manufacturing to repair, reuse, and disposal. The regulation specifies that this data must be authentic, secure, and verifiable.
Each product (or batch) receives a unique identifier. Data is linked to this ID through a standardised data carrier — typically a QR code, RFID tag, or NFC chip.
Product data must be signed by an authorised representative of the manufacturer or importer. The signature must ensure data origin authenticity and detect post-issuance tampering.
Different actors in the supply chain (manufacturers, importers, distributors, repairers, recyclers) have different read and write permissions. Data access must be controlled and auditable.
The DPP persists across the product's entire lifecycle. Updates, transfers, and retirements must be signed and logged, creating a continuous chain of custody.
Digital signature requirements for DPP data
กฎระเบียบ DPP ไม่กำหนดรูปแบบลายมือชื่อเดียวเดียว แต่ต้องการให้ลายมือชื่อที่ปฏิบัติตามมาตรฐานของ eIDAS สำหรับความเป็นสมบูรณ์และความเป็นจริงของข้อมูล นี่คือวิธีที่ความต้องการนี้ตรงกับระดับลายมือชื่อของ eIDAS
| ความต้องการของ DPP | การแมพติ้ง eIDAS | |
|---|---|---|
| ความเป็นจริงของข้อมูล | ผู้ผลิตต้องพิสูจน์ต้นกำเนิดข้อมูล | ลายมือชื่ออิเล็กทรอนิกส์ขั้นสูง (AES): มีความเชื่อมโยงเดี่ยวกับผู้ลงลายมือชื่อ สามารถระบุผู้ลงลายมือชื่อได้ |
| ความเป็นสมบูรณ์ของข้อมูล | การเปลี่ยนแปลงต้องสามารถตรวจสอบได้ | AES หรือ ลายมือชื่ออิเล็กทรอนิกส์ที่มีคุณภาพ (QES): การเปลี่ยนแปลงใดๆ ของข้อมูลต้องสามารถตรวจสอบได้ |
| ความไม่สามารถปฏิเสธ | ผู้ลงลายมือชื่อไม่สามารถปฏิเสธการลงลายมือชื่อได้ | QES: มีการสนับสนุนจากหนังสือรับรองที่มีคุณภาพจาก QTSP — ความมีความไม่สามารถปฏิเสธได้สูงสุด |
| หมายเวลา | จุดเวลาที่ลงลายมือชื่อต้องสามารถพิสูจน์ได้ | หมายเวลาอิเล็กทรอนิกส์ที่มีคุณภาพตามบทบัญญัติของ eIDAS มาตรา 41 |
| การพิสูจน์ระยะยาว | DPP ยังคงมีผลตลอดชีวิตของสินค้า (ปี/ศตวรรษ) | รูปแบบ PAdES/XAdES Long-Term Validation (LTV) แนะนำ |
| สามารถตรวจสอบโดยเครื่อง | ผู้ควบคุมและผู้ร่วมมือในโซ่อุปทานต้องตรวจสอบโดยอัตโนมัติ | รูปแบบลายมือชื่อมาตรฐาน (PAdES, XAdES, JAdES) ทำให้การตรวจสอบโดยเครื่องที่สามารถทำได้ |
วิธีที่การลงลายมือชื่อ DPP ต่อข้อเสนอของระบบ PLM และ ERP ของกิจการ
ผู้ผลิตที่นำสินค้าขึ้นตลาด EU
ความเป็นหน้าที่หลักตกที่ผู้ผลิต (หรือผู้นำเข้าสินค้าสำหรับผู้ผลิตที่ไม่ใช่สมาชิก EU) พวกเขาต้องสร้าง DPP ลงลายมือชื่อข้อมูล และให้ความมั่นใจว่ามันยังคงสามารถเข้าถึงได้ตลอดชีวิตของสินค้า
Supply chain partners
ผู้นำเข้าสินค้า ผู้แจกจำหน่าย และตัวแทนที่ได้รับอนุญาตมีหน้าที่ต้องตรวจสอบความมี DPP และส่งข้อมูล ผู้ซ่อมแซมและผู้รีไซเคิลอาจมีสิทธิ์เขียนเพื่อปรับปรุงช่องข้อมูล DPP โดยเฉพาะ — การปรับปรุงนี้ต้องลงลายมือชื่อด้วยเช่นกัน
Non-EU exporters to the EU
Companies outside the EU that sell products into the EU market must comply through their EU-based importer or authorised representative. This creates cross-border signing requirements that intersect with eIDAS, especially for QES-qualified signatures.
IT and signing infrastructure owners
Teams responsible for PKI, digital certificates, and signing APIs must ensure the infrastructure supports qualified signatures, timestamps, and long-term validation formats — not just basic e-signatures.
How signing teams should prepare
DPP compliance is not just a regulatory exercise — it requires signing infrastructure that can produce, verify, and archive qualified signatures at scale. Start with these five steps.
Inventory affected product lines
Identify which products your organisation places on the EU market and map them to the relevant DPP delegating acts. Priority sectors include batteries, textiles, electronics, construction products, and furniture.
Assess current signing capabilities
Check whether your PKI and signing infrastructure supports AES/QES, qualified timestamps, and PAdES/XAdES Long-Term Validation. Many organisations discover their infrastructure only supports basic (SES) signatures.
Engage a QTSP
If you need qualified signatures, engage a Qualified Trust Service Provider. Verify that their certificate issuance process and service level meet DPP volume requirements — some product categories will require millions of signed DPP records.
Design the DPP signing workflow
Map the full lifecycle: creation (manufacturer signs), updates (supply chain partners sign amendments), transfers (ownership changes require new attestations), and retirement (final decommissioning signature).
Plan for long-term archival
DPPs must persist for the product's entire lifecycle — potentially decades. Ensure your signature format supports Long-Term Validation, and plan for cryptographic algorithm migration as old algorithms weaken over time.
Manufacturer action plan for DPP compliance
Manufacturers placing products on the EU market must prepare for DPP requirements under the ESPR.
Audit product scope
Determine which of your products fall under the ESPR DPP requirements. The first product categories with mandatory DPP are batteries (from 2027), followed by textiles, electronics, and construction materials. Check the EU Commission delegated acts for your product category.
Map data sources
Identify where the required DPP data lives in your organisation: ERP for materials and bill of materials, PLM for specifications, LCA tools for environmental impact, supply chain management for supplier data. Plan how to aggregate this data into the DPP format.
Provision signing capability
Obtain a qualified electronic seal certificate from an EU QTSP. Configure your signing platform for batch sealing via API. Test the sealing workflow with sample product data before the compliance deadline.
Register with the EU DPP system
Once data is prepared and sealed, submit it to the EU DPP registry. The registry assigns a unique identifier that must be physically affixed to the product (QR code or digital link). Consumers and authorities scan this link to access the full product passport.
Common questions from compliance teams
The DPP regulation requires data authenticity and integrity but does not explicitly mandate QES for every record. However, eIDAS-aligned QES provides the strongest legal presumption of authenticity and non-repudiation, which is valuable when product data is challenged in disputes or regulatory inspections. Many organisations are adopting QES as a risk-management choice rather than a strict legal minimum.
How eSign.AI supports DPP data signing and submission
eSign.AI provides the QSeal infrastructure for manufacturers to sign and submit Digital Product Passport data to the EU registry.
Qualified electronic seal via API
eSign.AI holds qualified seal certificates from EU QTSPs and exposes them via a REST API. Manufacturing execution systems (MES) can seal product data programmatically — no manual signing step. Typical API latency is under 2 seconds per seal, supporting high-volume production lines.
ERP and PLM integration
eSign.AI integrates with SAP, Oracle, and major PLM systems to pull product data automatically. The integration extracts DPP-required fields (materials, origin, carbon footprint), formats them per the ESPR delegated act schema, applies the QSeal, and submits to the EU DPP registry.
Multi-party supply chain signing
DPP data often comes from multiple parties: material suppliers, manufacturers, and distributors. eSign.AI supports sequential multi-party signing workflows where each party seals their contribution. The final DPP record carries a chain of seals proving the origin of each data element.
Audit-ready evidence
Every DPP submission generates a complete evidence package: sealed data payload, QSeal certificate chain, timestamp token, and EU registry submission receipt. This evidence is stored for the product retention period and can be exported for market surveillance audits.







