CirculeID

industry

Data Centre and Server Product Passports

Servers already carry ecodesign duties under Regulation (EU) 2019/424. What a passport adds, and why data centre buyers ask for most of it already.

CirculeID Research9 min read2,037 words

Servers and data storage products are covered by ecodesign requirements under Regulation (EU) 2019/424, including material efficiency, firmware availability and secure data deletion. A passport extends this into resolvable per-unit data covering composition, critical raw materials, refurbishment history and end-of-life handling.

What this gives you

Which server obligations already exist, what a passport adds beyond them, and why enterprise tender questionnaires already ask for most of the fields you would have to publish.

Key takeaways

  • Regulation (EU) 2019/424 already sets material efficiency and firmware duties for servers.
  • Secure data deletion is a regulated function, not only a customer expectation.
  • Servers have unusually high refurbishment rates, which makes unit history commercially valuable.
  • Critical raw materials are concentrated in identifiable components rather than dispersed.
  • Enterprise buyers already demand most passport fields through procurement questionnaires.

Servers are an unusual case in the passport conversation. The category already carries specific ecodesign obligations, the buyers already ask sustainability questions in tenders, and secondary markets for used hardware are mature rather than aspirational.

That combination means the passport lands on a category that is closer to ready than most, and where the commercial return is easier to identify than the compliance one.

What does Regulation (EU) 2019/424 already require?

Existing ecodesign obligations for servers and data storage products
RequirementWhat it covers
Idle state powerMaximum consumption at idle by configuration
Power supply efficiencyMinimum efficiency and power factor
Material efficiencyDisassembly of key components, joining techniques
Firmware availabilityLatest security firmware available for a defined period
Secure data deletionA function to delete data on all storage
Information requirementsComposition of certain materials, published
Existing ecodesign obligations for servers and data storage products

The last three rows already read like passport content. Firmware availability, secure deletion and material composition are exactly the kind of durable, per-model information a passport is designed to carry, and they are currently published as documents.

Why secure deletion is a passport field

Secure data deletion is the precondition for reuse in this category. A server that cannot be certified clean does not enter the secondary market, because the risk of residual data is unacceptable to the party disposing of it.

Recording that deletion occurred, by whom and to what standard, converts a private assurance into a retrievable record. That is what allows the next buyer to accept the asset without repeating the process, and it is one of the clearest cases where an event record has direct monetary value.

What makes servers different from consumer electronics?

  • They are bought by organisations that keep asset registers, so identity already exists internally.
  • They are refurbished and resold at high rates rather than discarded.
  • Their components are modular and individually valuable, which rewards dismantling.
  • They are decommissioned in batches, which makes structured data economic to use.
  • Their buyers ask sustainability questions contractually rather than reading a label.

Each of those makes the passport easier to justify. The economics of dismantling that fail for a cheap consumer device succeed for a server, because the components are worth recovering and the volumes arrive together.

What the secondary market needs

A refurbisher pricing a decommissioned server needs configuration, service history, firmware state and confirmation that data has been removed. Today most of that is reconstructed by inspection and by trusting the seller.

Reconstruction is expensive and imperfect, and the discount applied for uncertainty is real. A unit with a retrievable history sells for more than an identical unit without one, which is the same mechanism that governs second-life batteries.

Critical raw materials in servers

Servers concentrate materials that matter. Gold and palladium in connectors and boards, tantalum in capacitors, neodymium in drive motors and fans, and cobalt in some storage components.

Concentration is what makes recovery viable, and identification is what makes concentration usable. Knowing that a specific board carries recoverable palladium turns a general assay into a targeted removal, which is the same argument set out in e-waste: what happens without material data.

How procurement already asks for this

Large data centre operators and public sector buyers issue sustainability questionnaires with tenders. These routinely ask for embodied carbon, recycled content, disassembly information, take-back terms and expected support duration.

Those are passport fields under different names, answered today by a bid team assembling evidence per tender. Holding them once in a product record turns a recurring bid cost into a lookup, which is a benefit that arrives before any regulatory deadline.

Embodied carbon is the contested field

Operational energy has dominated data centre sustainability for a decade because it is measurable and large. As grids decarbonise, embodied carbon in the hardware becomes a larger share of total impact, and buyers have started asking for it.

Server embodied carbon figures vary widely between manufacturers, largely because boundary and allocation choices differ rather than because the hardware differs. A figure without its method attached is not comparable, which is why the passport should carry both.

What about the software side?

Firmware support duration determines how long a server can remain in secure service, which makes it a durability parameter in substance even where it is not labelled as one. A machine that is mechanically sound but no longer receiving security firmware is functionally retired.

Recording the support commitment and its expiry in the passport gives a secondary buyer the single most important fact about the asset’s remaining useful life, and it is information the manufacturer holds and rarely publishes in a retrievable form.

Who holds the record across the asset life?

The record changes hands more often than the hardware does.

No single party holds the whole record, which is the structural argument for a resolvable identity rather than a vendor database. Each custodian appends what they know, and the identifier is what makes the additions belong to the same asset.

What about confidentiality?

Data centre operators treat configuration and location as sensitive, sometimes acutely so. A passport that published deployment detail would be unacceptable to exactly the customers it is meant to serve.

This is a role-scoped access problem rather than a reason to avoid the record. Composition and support duration can be public; service history and deletion certificates belong to the asset owner and their chosen counterparties, resolved from credentials rather than published.

How does the ESPR change this?

Regulation (EU) 2019/424 was made under the earlier ecodesign framework. Regulation (EU) 2024/1781 now governs new measures, and servers are a plausible candidate for early treatment given that requirements already exist and only need extending into passport form.

The likely shape is that existing information requirements become resolvable rather than published, with additions covering recycled content and critical raw materials. A manufacturer already complying with 2019/424 is closer to ready than most categories.

How component-level identity changes the picture

A server is not a single product in any meaningful sense. Drives, memory, processors and power supplies are replaced independently across its life, and the machine decommissioned rarely contains the components it shipped with.

That makes chassis-level identity insufficient on its own. A passport recording composition at shipment describes a configuration that no longer exists, and a refurbisher assessing the unit has to inventory it physically anyway.

The workable model gives the chassis an identity and lets components carry their own, with the record describing the current assembly rather than the original one. Replacement then updates the record instead of invalidating it, which is the same pattern that keeps a battery passport honest across module swaps.

What does this cost to run?

The manufacturer cost is largely one-off: structuring information that already exists under Regulation (EU) 2019/424 and assigning resolvable identity to units that already carry serial numbers.

The recurring cost sits with operators, who must record service events and deletion certificates against the identity rather than in their own asset system alone. That is a small marginal effort attached to work already being done, and it is the part most likely to be skipped, because the benefit accrues at decommissioning to whoever holds the asset then.

Where an operator leases rather than owns, the incentive aligns better: the lessor holds the asset at end of term and captures the residual value directly, which is why leased fleets are the most likely place for this practice to establish itself first.

Where the record should actually live

A manufacturer portal is the obvious answer and the wrong one. Data centre estates are multi-vendor by policy, and an operator decommissioning three hundred machines from four manufacturers will not consult four portals to assemble a disposal record.

The same objection applies to a passport delivered as a per-vendor API. What an operator needs is one scanning workflow that resolves any machine on the floor, returning a predictable shape regardless of who built it, which is precisely what a standards-based identifier provides and a vendor integration does not.

A resolvable identifier that any conforming service can serve is the property that makes this work at estate scale, and it is also what protects the record when a manufacturer exits the market or is acquired. Hardware bought today will outlive at least one such event.

What should a server manufacturer do?

  1. Assign per-unit identity if you do not already; serial numbers exist but rarely resolve.
  2. Publish firmware support duration as a commitment with an expiry, not a general statement.
  3. Structure the material composition you already publish under 2019/424 as data rather than a document.
  4. Record secure deletion as an event, so a refurbisher can rely on it without repeating it.
  5. Answer the recurring tender questionnaire from a record rather than per bid.

The last item is the one that pays for the programme. Bid teams in this category spend real effort reassembling the same evidence per tender, and that cost is already being incurred without producing a durable asset.

Frequently asked questions

Are servers already covered by ecodesign requirements?

Yes. Regulation (EU) 2019/424 sets requirements for servers and data storage products covering idle power, power supply efficiency, material efficiency, firmware availability, secure data deletion and published material composition. Several of those obligations already read like passport content delivered as documents.

Why does secure data deletion belong in a passport?

Because it is the precondition for reuse. A server that cannot be certified clean does not enter the secondary market. Recording that deletion happened, by whom and to what standard, lets the next buyer accept the asset without repeating the process, which has direct monetary value.

What makes servers easier than consumer electronics?

Identity already exists in asset registers, refurbishment rates are high, components are modular and individually valuable, and decommissioning happens in batches. Each factor improves the economics of dismantling and of maintaining a record, where a cheap consumer device fails all four tests.

Is embodied carbon comparable between manufacturers?

Not reliably. Published figures vary widely, mostly because boundary and allocation choices differ rather than because the hardware does. A figure without its methodology attached is not comparable, which is why a passport should carry the method alongside the number rather than the number alone.

How do you handle customer confidentiality?

With role-scoped access rather than by avoiding the record. Composition and firmware support duration can be public. Deployment detail, configuration and deletion certificates belong to the asset owner and are resolved from credentials, not published, which is what the access model exists to do.

Does firmware support duration count as durability?

In substance yes, whatever it is labelled. A server that is mechanically sound but no longer receiving security firmware is functionally retired, because no operator will run it on a production network. The support expiry is therefore the most important single fact about remaining useful life, and the one a secondary buyer most needs before pricing the asset.

What is the commercial case if compliance is not urgent?

Tender response cost and residual value. Enterprise buyers already ask for embodied carbon, recycled content, disassembly data and take-back terms in every bid, which a bid team currently reassembles from scratch each time. Better-documented assets also clear faster and at higher prices when decommissioned. Both benefits arrive well before any passport deadline does, which is unusual in this field.

Sources

  1. Regulation (EU) 2019/424 on ecodesign requirements for servers and data storage productsEUR-Lex, European Union, 2019-03
  2. Regulation (EU) 2024/1781 establishing a framework for ecodesign requirementsEUR-Lex, European Union, 2024-06
  3. Regulation (EU) 2024/1252 establishing a framework for critical raw materialsEUR-Lex, European Union, 2024-04

Continue reading

Next step

Bekijk een paspoort dat hierop is gebouwd

CirculeID maakt van de hierboven beschreven vereisten een werkend digitaal productpaspoort voor uw producten.

Index