CirculeID

concept

Can a DPP Stop Counterfeiting?

A passport does not prevent copying an identifier. What it genuinely changes about counterfeit detection, and which techniques close the remaining gap.

CirculeID Research6 min read1,277 words

A passport cannot prevent a counterfeiter printing a valid identifier, so it does not stop counterfeiting on its own. What it changes is that verification becomes available to anybody with a phone, and that duplicate or inconsistent use of an identifier becomes detectable at scale.

What this gives you

An honest answer on where a passport stops a counterfeit and where it does not, plus the three authentication layers that actually raise the cost of faking a product.

Key takeaways

  • An identifier can always be copied; treating a scan as proof of authenticity is a mistake.
  • The real gain is detection at scale, not prevention at the individual item.
  • Duplicate detection turns a copied code into a signal rather than a success.
  • Physical security features and a digital record are complementary, not alternatives.

Anti-counterfeiting is frequently offered as a benefit of product passports, and the claim is usually overstated in a way that sets up disappointment.

Being precise about what a passport does and does not achieve here matters, because the gap between the two is where counterfeiters operate.

The limitation to state plainly

A QR code is a printed pattern. Anybody who can photograph one can reproduce it perfectly, and the copy resolves to the same record as the original.

This is not a flaw in any particular implementation. It follows from the identifier being readable, which is the property that makes it useful. Any scheme where a consumer can read a code is a scheme where a counterfeiter can read the same code.

What genuinely changes

The gain is real and it operates at a different level than individual item verification.

  • Absence becomes informative — a product with no resolvable record at all is immediately suspect in a way it previously was not.
  • Inconsistency becomes visible — a code resolving to a different product, size or market than the item in hand is a detectable mismatch.
  • Duplicates become detectable — the same serial scanned in twenty countries in one week is a pattern no counterfeiter can avoid producing.
  • Verification is distributed — customs officers, retailers and consumers can all check, rather than only trained experts.

The third point is where most of the value sits. Counterfeiting is a volume business, and volume is exactly what duplicate detection catches. A single copied code is invisible; a code copied ten thousand times generates a scan pattern that is statistically obvious.

Serialisation is what makes detection work

Duplicate detection requires that each item carries a distinct identifier. A code identifying only the product model tells you nothing when the same code legitimately appears on a million items.

What each identifier level enables for counterfeit detection
LevelDuplicate detectionCost
Product class onlyImpossible — duplicates are expectedLowest
Batch or lotWeak — flags gross anomalies onlyLow
Serialised per itemStrong — every duplicate is anomalousMarking and data cost per unit
Serialised plus scan telemetryStrongest — patterns over time and geographyAdds analytics and privacy obligations
What each identifier level enables for counterfeit detection

The fourth row carries a genuine trade-off that deserves stating. Scan telemetry is what makes duplicate detection powerful, and it means recording where and when products are scanned, which is a data protection question requiring a lawful basis and a retention policy.

Where physical features still matter

The gap a digital record cannot close is the link between the code and the physical object. Closing it requires something that cannot be copied by photographing it.

Each layer answers a question the other cannot.

The third and fourth layers are where the sectors with the most acute counterfeiting problems concentrate their spending, and the passport does not replace them. It makes the first two layers available to everybody, which was previously the expensive part.

What to tell consumers

The messaging question is genuinely difficult, and getting it wrong creates liability as well as false confidence.

Telling consumers that scanning proves authenticity is inaccurate and, under Directive (EU) 2024/825, potentially an unfair commercial practice if the claim materially misleads. Telling them nothing wastes the detection capability entirely.

The defensible position is to describe what the scan actually establishes: that a record exists, that it matches the item in hand, and that anomalies can be reported. Framing it as one check among several is both accurate and more useful than framing it as proof.

Where it helps most

The strongest application is not consumer-facing at all. It is customs, market surveillance and retail intake, where trained parties check at volume and where an inconsistent or duplicated record triggers an inspection that would not otherwise happen.

Regulation (EU) 2019/1020 gives market surveillance authorities the powers to act on that signal, and a resolvable record turns a laborious physical assessment into a query. That is a considerably larger effect on counterfeit volume than any number of individual consumer scans.

Retail intake deserves particular attention because it is the point where counterfeit goods most often enter a legitimate distribution channel. A retailer checking codes at goods-in catches the parallel and counterfeit stock that reaches shelves through grey market suppliers, which no consumer-facing scan can address.

None of this requires the consumer to do anything at all, which is the point worth ending on. The detection value of a passport is realised largely by parties handling volume, and it accrues whether or not a single buyer ever scans the code on their purchase.

Frequently asked questions

Does a passport stop counterfeiting?

No. A QR code is a printed pattern that anybody can photograph and reproduce, and the copy resolves to the same record as the original. A consumer told that scanning proves authenticity has been given a test that the counterfeit passes successfully.

So what does it actually achieve?

Detection at scale rather than prevention per item. Absence of a record becomes suspect, inconsistency between record and item becomes visible, and duplicate use of a serial becomes detectable. Verification also moves from trained experts to anybody with a phone.

Why is duplicate detection the important part?

Because counterfeiting is a volume business and volume is what duplicate detection catches. A single copied code is invisible, while a code copied ten thousand times produces a scan pattern across countries and dates that is statistically obvious and impossible for a counterfeiter to avoid.

Do we need serialisation for this?

Yes. Duplicate detection requires each item to carry a distinct identifier. A code identifying only the product model tells you nothing, because the same code legitimately appears on every unit, so there is no anomaly for any analysis to detect.

What is the trade-off with scan telemetry?

It is what makes duplicate detection powerful, and it means recording where and when products are scanned. That is a data protection question requiring a lawful basis and a retention policy, which should be settled before the capability is built rather than afterwards.

Do physical security features still matter?

Yes. The gap a digital record cannot close is the link between the code and the physical object, and closing it requires something that cannot be copied by photographing it. Covert features and material signatures remain necessary where counterfeiting pressure is acute.

What should we tell consumers?

What the scan actually establishes: that a record exists, that it matches the item in hand, and that anomalies can be reported. Claiming a scan proves authenticity is inaccurate and, under Directive (EU) 2024/825, potentially an unfair commercial practice if it materially misleads.

Sources

  1. Regulation (EU) 2019/1020 on market surveillance and compliance of productsEUR-Lex, European Union, 2019-06
  2. Directive (EU) 2024/825 on empowering consumers for the green transitionEUR-Lex, European Union, 2024-02

Continue reading

Next step

Bekijk een paspoort dat hierop is gebouwd

CirculeID maakt van de hierboven beschreven vereisten een werkend digitaal productpaspoort voor uw producten.

Index