CirculeID

regulation

ESPR Penalties: What Non-Compliance Costs

Penalties are set nationally, but the real cost is market withdrawal. Which ESPR failures trigger which sanction, and why the fine is rarely the problem.

CirculeID Research8 min read1,851 words

ESPR leaves penalties to member states, requiring only that they be effective, proportionate and dissuasive. In practice the significant sanction is not the fine but the power of market surveillance authorities to require withdrawal or recall, which turns a data gap into a stock problem.

What this gives you

What non-compliance costs under the ESPR, how member states set penalties, and the enforcement route a market surveillance authority will take before it reaches a fine.

Key takeaways

  • Regulation (EU) 2024/1781 sets no penalty schedule of its own — each member state legislates its own, so exposure differs by market.
  • Market withdrawal is the sanction that hurts: product sitting in a warehouse it cannot legally leave costs more than most fines.
  • Public procurement exclusion is an underrated consequence, because ESPR explicitly contemplates ecodesign criteria in tendering.
  • A passport that exists but contains wrong data is treated as non-compliance, not as partial compliance.

The first question a board asks about any regulation is what happens if we miss it. For the Ecodesign for Sustainable Products Regulation the honest answer is uncomfortable, because the number everyone wants does not exist at EU level.

Regulation (EU) 2024/1781 requires member states to lay down rules on penalties and to make them effective, proportionate and dissuasive. It does not set the amounts. That means your exposure in Germany is not your exposure in Ireland, and a group placing product across the single market has as many penalty regimes as it has markets.

Why the fine is the least of it

Focusing on fines misreads how product regulation is enforced. Market surveillance authorities operating under Regulation (EU) 2019/1020 have powers that bite long before a penalty is assessed: they can require corrective action, prohibit making a product available, and order withdrawal or recall.

For a physical goods business those powers are the sanction. Stock that cannot legally be sold in a market still carries its full working capital cost, still occupies warehouse space, and still ages. A seasonal product prohibited during its season is written off regardless of whether the underlying issue is fixed in eight weeks.

Enforcement responses to ESPR non-compliance and their commercial consequences
Authority responseWhat triggers itCommercial consequence
Request for corrective actionIncomplete or inaccurate passport dataEngineering and data cost, deadline pressure
Prohibition on making availablePersistent failure to correctStock frozen in market, revenue stops
Withdrawal from marketSerious or repeated non-complianceReverse logistics cost, retailer relationship damage
Recall from end usersSafety-adjacent or systemic failureDirect cost plus reputational exposure
Financial penaltySet by national law, varies by member stateQuantifiable, and usually the smallest line
Enforcement responses to ESPR non-compliance and their commercial consequences

Which failures count as non-compliance?

It helps to separate three failure modes, because they carry different risk and are found by different means.

  • No passport at all for a product in a group where a delegated act applies. The most visible failure and the easiest for an authority to detect, because absence is checkable from the carrier alone.
  • A passport that exists but is incomplete — required attributes missing or blank. Detected on inspection, and treated as non-compliance rather than as partial credit.
  • A passport that is complete but wrong. The hardest to detect and the most dangerous, because it survives inspection until someone checks the underlying evidence and then looks deliberate.

The consequences that do not look like penalties

Three further exposures rarely appear in a compliance risk register and are usually larger than the fine.

The first is public procurement. ESPR anticipates ecodesign criteria being used in public tendering, which means a product that cannot evidence its parameters is not merely at risk of sanction — it is unable to bid. For manufacturers with meaningful public sector revenue this arrives before any enforcement action does.

The second is customer-imposed. Large buyers pass regulatory requirements up their supply chain contractually, and they do it earlier than regulators enforce. Most suppliers experience ESPR first as a purchase order condition, with the commercial consequence of losing the account rather than paying a fine.

The third is the retailer. Distributors have their own obligations not to make non-compliant product available, so a retailer with any compliance function will delist rather than carry the risk. That decision is made commercially, quickly, and without an appeal process.

How enforcement actually finds you

Market surveillance is sample-based and complaint-driven rather than comprehensive. The realistic triggers are worth knowing because they determine where to spend first.

How ESPR non-compliance typically comes to an authority’s attention
TriggerTypical sourceWhat it usually finds
Routine market samplingNational authority programmeMissing or unreadable data carrier
Competitor complaintA rival with a compliant productUnsupported comparative claims
Customs checks at importBorder control on entryAbsent passport for an in-scope group
Consumer or NGO complaintA scan that returned nothing usefulBroken resolver, stale content
Downstream due diligenceA customer’s own compliance reviewAttributes that cannot be evidenced
How ESPR non-compliance typically comes to an authority’s attention

Note how many of these are found by scanning the product rather than by auditing the company. A carrier that resolves to nothing is the single most detectable failure in the whole framework, and it is also the cheapest to prevent.

How penalties differ across member states

Because each member state legislates its own penalties, the same failure carries different consequences depending on where the product is placed. Some states express maxima as fixed amounts, others as a percentage of turnover, and a few attach personal liability to company officers for repeated breaches.

That variation matters for sequencing. A group with concentrated revenue in two or three markets should read those national implementing measures specifically rather than planning against an EU average that does not exist. It also matters for where you pilot: launching a passport programme first in a market with turnover-linked penalties is a choice worth making deliberately rather than by accident of sales volume.

Evidence is the thing that gets tested

When an authority engages, the conversation moves quickly from what the passport says to where the figures came from. That is the point at which most programmes discover whether they built a compliance capability or a publishing pipeline.

The distinction is concrete. A recycled content figure with the supplier who asserted it, the date, the chain-of-custody model and the test method behind it survives scrutiny. The same number with no provenance is indistinguishable from an estimate, and an authority is not obliged to give it the benefit of the doubt.

  • Who asserted it — a named supplier or laboratory, not a department.
  • When — because a screening against a candidate list that has since been updated is stale rather than wrong.
  • By what method — the test standard, or the calculation rule, named rather than implied.
  • Under which custody model — segregated and mass balance mean different things and are not interchangeable in a declaration.

What proportionate preparation looks like

Because exposure is national and enforcement is sampled, the rational response is not to gold-plate every market. It is to make the visible failures impossible and to keep evidence for the rest.

  1. Ensure every in-scope product has a carrier that resolves, in every market you supply. This removes the most detectable failure entirely.
  2. Keep a gap register naming missing attributes and their owners, so an inspection meets a documented programme rather than a shrug.
  3. Record provenance for every attribute. An authority asking where a figure came from is a routine question that should have a routine answer.
  4. Check your largest markets’ national penalty legislation specifically, because the range between member states is wide.
  5. Treat a customer’s data request as an earlier deadline than the regulator’s, since commercially it usually is.

None of that requires knowing the fine. It requires knowing that the sanction which matters most is being told you cannot sell, and that the failure most likely to produce it is a code on a product that leads nowhere.

It is also worth being clear about what preparation does not need to include. Perfect data across every attribute is not the standard, and waiting for it delays the things that actually reduce risk. An authority encountering a working carrier, a documented gap register and named provenance is looking at a controlled programme, which changes the tone of the conversation considerably compared with a product that scans to a dead link.

Frequently asked questions

How much is the fine for ESPR non-compliance?

There is no EU-wide figure. Regulation (EU) 2024/1781 requires member states to set penalties that are effective, proportionate and dissuasive, and leaves the amounts to national law. Exposure therefore varies by market, and a group selling across the single market faces several different regimes simultaneously.

Can a product be withdrawn from sale over a passport failure?

Yes. Market surveillance authorities can require corrective action and, where non-compliance persists or is serious, prohibit making the product available or require withdrawal. For most manufacturers this power is a larger financial exposure than any penalty, because frozen stock costs money every day it cannot move.

Is an incomplete passport better than no passport?

Marginally, in that it shows a programme underway, but it is still non-compliance rather than partial compliance. The one case where incomplete is clearly worse is when the missing field is filled with an unsupported estimate, because that converts a data gap into a claim.

Who is liable — the manufacturer or the importer?

The economic operator placing the product on the EU market. For goods made outside the EU that is normally the importer, who inherits the obligation and will pass the data requirement back to the manufacturer contractually. Distributors have separate duties not to make non-compliant product available.

Do penalties apply before a delegated act is in force?

No. Obligations attach when the delegated act for a product group applies, which is typically around eighteen months after adoption. Until then there is nothing to enforce for that group, which is precisely the window in which supplier data collection has to happen.

Can we be penalised in one member state and not another?

Yes, and it is common. Penalties are national, enforcement is national, and sampling programmes differ by authority. The same product with the same passport can pass unremarked in one market and attract a corrective action request in another, which is why concentrated-revenue markets deserve specific attention rather than an averaged approach.

Does having a passport protect us from greenwashing claims?

Only if what it contains is supportable. A passport makes claims machine-readable and therefore easier to challenge, so it increases exposure where figures are weak and reduces it where each attribute names its method and issuer. The discipline of publishing the basis is the protection, not the passport itself.

Sources

  1. Regulation (EU) 2024/1781 establishing a framework for ecodesign requirementsEUR-Lex, European Union, 2024-06
  2. Regulation (EU) 2019/1020 on market surveillance and compliance of productsEUR-Lex, European Union, 2019-06

Continue reading

Next step

Voir un passeport bâti là-dessus

CirculeID transforme les exigences décrites ci-dessus en un passeport numérique de produit opérationnel pour vos produits.

Index