CirculeID

Respostas

Trinta respostas diretas sobre passaportes de produto

As perguntas que as pessoas realmente fazem antes de arrancar um programa de passaporte — respondidas num parágrafo cada, com o regulamento identificado. Sem preâmbulo, sem posicionamento e sem pedir primeiro o seu endereço de e-mail.

Respostas
100
Temas
9
Com acesso condicionado
Nenhum

Definition

O que as empresas mais vezes entendem mal sobre o passaporte digital de produto

Três coisas: presumir que existe um único prazo da ESPR quando as obrigações chegam por grupo de produtos, presumir que uma empresa pequena está isenta quando não existe qualquer exclusão geral, e tratar o assunto como um projeto de software quando o calendário é na verdade ditado pelo tempo que os dados dos fornecedores demoram a chegar.

Each answer below is written to stand on its own, so it can be pasted into a briefing note without the surrounding page. Where an answer rests on a regulation, the instrument is named — the ESPR and the Battery Regulation do most of the work.

5 answers

Âmbito

Does the Digital Product Passport apply to my company?

If you place a physical product on the EU market, almost certainly — eventually. ESPR works product group by product group, so the question is not whether but when your group’s delegated act lands. Batteries above 2 kWh are already fixed for February 2027. Everything else follows a delegated act with roughly eighteen months from adoption to enforcement.

Scope

Who is legally responsible for the passport?

The economic operator placing the product on the EU market — usually the manufacturer, or the importer where the manufacturer is outside the EU. Responsibility cannot be delegated to a software vendor. A service provider can host and serve the passport, but the operator remains accountable for whether its contents are correct.

Scope

We manufacture outside the EU. Does this reach us?

Through your importer, yes. The obligation attaches to whoever places the product on the EU market, so an EU importer inherits it — and will pass the data requirement straight back up the contract to you. In practice non-EU manufacturers feel this as a customer requirement before they feel it as a law.

Scope

Are small companies exempt?

Not by default. ESPR allows delegated acts to take proportionality into account, and micro-enterprises may get lighter treatment in specific product groups, but there is no blanket small-company carve-out. Assuming one is a common and expensive mistake, because supply chain customers impose the requirement regardless of statutory relief.

Scope

What happens if we do not comply?

Penalties are set nationally, and market surveillance authorities can require withdrawal from the market. That commercial consequence usually outweighs the fine: a product that cannot be sold in the EU while its passport is corrected is a stock and revenue problem, not a legal line item.

Scope

1 answer

Timing

What is the ESPR deadline?

There is not one, and any tool showing a single ESPR date has invented it. Obligations arrive per product group through delegated acts, each allowing roughly eighteen months before enforcement. Iron and steel is expected first, with textiles following. The only fixed passport date in EU law today is 18 February 2027, for batteries.

Timing

10 answers

Data

What data must a Digital Product Passport contain?

Material composition and sourcing, durability and repairability, carbon footprint, substances of concern, and end-of-life handling. The precise fields are fixed per product group in its delegated act, which is why mapping data to a standards-based model beats building to a form that has not been published yet.

Data

Does a passport contain personal data?

It should not, and designing so it cannot is the safer position. Passport content is product data. Where a repair or resale record could identify an individual, the identifying part belongs in your own systems under normal GDPR controls, not in a record designed to be publicly resolvable for fifteen years.

Data

What if we do not have the data yet?

That is the normal starting position, and it is a supplier problem before it is a software problem. Most missing attributes sit with tier-2 and tier-3 suppliers who have never been asked. Start by listing the named gaps against your product group’s data set, then run one collection campaign per attribute set rather than per product.

Data

How accurate does the data have to be?

Accurate enough to defend to a market surveillance authority, and attributable to whoever asserted it. That is why signed credentials matter more than precision theatre: a figure with a named issuer and a method behind it survives scrutiny, and a confident number with no provenance does not.

Data

How often must a passport be updated?

Whenever the underlying facts change — a new supplier, a reformulation, a corrected footprint, a withdrawn certificate. Passports are versioned records rather than one-time publications, which is why the ability to correct them matters and why immutable storage is the wrong architecture for the content.

Data

Why can we not just publish our existing PDFs?

Because a passport attribute asks for a typed value against a product identifier, and a document containing that number is not addressable by anything. The information exists in the organisation without being reachable, which is the gap most programmes underestimate at the outset.

Data

How do we prove a published claim if challenged?

Through provenance recorded with the value: who asserted it, when, by what method and on what evidence. A figure without its method is not interpretable, and a self-declared number and an audited one are both legitimate while being very different evidence.

Data

What is the most dangerous kind of bad passport data?

Stale values, because they look complete. A gap is visible and everyone treats it as a gap, while a value that was correct three years ago and is no longer true gets acted on. Recording when each value was established is the defence.

Data

Will schema validation catch our data errors?

Only format errors, which is the smallest category. Unit confusion, granularity mismatch, silent defaults and stale values all produce structurally valid data that is simply wrong. Distribution analysis across similar products catches what validation cannot, by flagging values orders of magnitude away from their peers.

Data

What should we measure instead of data completeness?

Proportion of attributes with recorded provenance, proportion resting on primary rather than estimated data, and median value age. None of the three can be improved by filling a field with a guess, which is exactly what a completeness percentage rewards.

Data

1 answer

Acesso

Will a passport expose our commercial data?

Only if it is modelled that way. A passport has one identity and role-scoped views: consumers see care and take-back, recyclers see disassembly and hazardous substances, regulators see the full compliance set. Supplier pricing and margins are not passport data at all, and should never be in the record to be exposed.

Access

1 answer

Carriers

Should we use a QR code or an NFC tag?

QR unless the product argues otherwise. It costs nothing to print, needs no chip and any phone reads it. NFC earns its unit cost where authentication matters or the surface cannot carry a readable code. Steel, tyres and anything handled in bulk usually need RFID instead, because nobody stops to aim a camera.

Carriers

5 answers

Technology

Do we need a blockchain for a Digital Product Passport?

No. Identity resolves through GS1 Digital Link, claims are signed Verifiable Credentials, events are EPCIS. A ledger is useful for two narrow jobs — proving a record existed in a given state at a given time, and holding a revocation registry — but putting passport content on one prevents the corrections regulation requires.

Technology

As Verifiable Credentials exigem uma blockchain?

No, and this is the most common misconception in the category. A credential is a signed document; verifying it needs the issuer’s public key, resolved through a Decentralized Identifier method. Some DID methods use a ledger, others use DNS and HTTPS, and the credential data model does not care which.

Technology

Does a passport platform replace our ERP or PLM?

No, and one that claims to should worry you. The passport sits above the systems of record: data flows in from ERP, PLM and carbon accounting through APIs and connectors, and the passport becomes a governed view over them rather than another place to key the same figures in twice.

Technology

Does a passport work without an internet connection?

The resolver needs connectivity, but the evidence does not. A Verifiable Credential can be checked offline by anyone holding the issuer’s key, and an anchored digest can be verified against a ledger later. Design so the critical safety information — battery handling, hazardous substances — is also carried on the product itself.

Technology

How long must a passport remain available?

Beyond the life of the product, and beyond the life of your vendor contract. ESPR expects the data to remain available even if the economic operator ceases trading, which is the practical argument for open standards and portable formats over any proprietary store you cannot export from.

Technology

8 answers

Normas

Why use GS1 identifiers rather than our own SKUs?

Because your SKU means nothing to a recycler in another country. A GTIN is globally unique and already understood by retail, customs and waste operators, and expressed as a Digital Link it becomes the address of the passport as well as the identifier on the barcode.

Standards

What is EPCIS actually for?

Recording what happened to a physical object in a form another company can ingest. A business step of `urn:epcglobal:cbv:bizstep:commissioning` means the same thing in every EPCIS repository, whereas the word "made" in a column called "stage" means whatever your database designer intended.

Standards

Do open standards actually prevent vendor lock-in?

They make leaving possible, which is not the same as easy. If your identifiers are GTINs, your events EPCIS and your claims Verifiable Credentials, the data is portable by construction and your credentials verify without the vendor. Test it: ask for a full export in those formats during evaluation, not after signature.

Standards

Why use GS1 identifiers rather than our own?

Because retailers, customs systems and scanners already understand them, and a passport is read by parties you have never met. A proprietary scheme requires every one of those parties to learn it, which is exactly the bilateral cost passports exist to remove.

Standards

Should we build an AAS or a Digital Product Passport?

They answer different questions and industrial manufacturers frequently need both. Treat them as views over shared data rather than separate stores — nameplate, technical specification and footprint are the same facts whether an engineering system or a regulator reads them.

Standards

Why sign passport claims with verifiable credentials?

Because a claim needs to survive leaving your website. A signed credential can be checked against the issuer’s public key wherever it is copied to, which means a supplier declaration keeps its evidentiary value when a customer stores it in their own system.

Standards

What is hash anchoring and why use it?

It publishes a cryptographic fingerprint of a record to a ledger without publishing the record itself, proving the data existed unchanged at a point in time. Records are salted before hashing so predictable values cannot be brute-forced, and thousands combine into one published root.

Standards

What identifier granularity should EPCIS events use?

Follow the questions the business needs answered, with a bias toward the finer level when costs are close. Serial data aggregates to batch whenever you want it to, while batch data can never be refined to serial for units already in the field.

Standards

5 answers

Programa

How long does a passport programme take?

The software is weeks; the data is quarters. Issuing a passport against data you already hold is quick. Getting process-stage origin from a tier-3 mill, or a verified carbon figure from a supplier who has never calculated one, is what sets the timeline — which is why collection should start before vendor selection finishes.

Programme

What does a Digital Product Passport cost?

Platform licensing is the smaller line. The real costs are supplier data collection, third-party verification where claims need it, and carrier application on the production line. Budget by product group rather than by SKU count, because the data set — not the catalogue size — is what drives the work.

Programme

Where should we start?

With one product group, not the whole catalogue. Pick the group with the nearest obligation, list the attributes its data set requires, mark which you already hold, and name an owner for each gap. That list is a plan; a platform selected before it exists is a tool looking for a problem.

Programme

Which department should own the passport programme?

Compliance owns the obligation, but the data sits in sourcing, product development and sustainability. Programmes that stall are usually ones where compliance was made accountable without authority over the teams holding the attributes. Name the owner per attribute, not per project.

Programme

Is there any return beyond compliance?

Three that are measurable: eco-modulated producer responsibility fees fall when recyclability data is good, resale and repair channels need the product history a passport already holds, and the same data set answers CSRD disclosure. The consumer engagement argument is real but harder to bank.

Programme

4 answers

Declarações

Can a passport protect us from greenwashing accusations?

Only if the claims in it are attributable. An unsourced "eco-friendly" is a liability wherever it appears. A figure with a named issuer, a stated method and a verifiable signature is defensible — and the discipline of having to publish the method is what stops the weak claims being made at all.

Claims

Do our claims need third-party verification?

It depends on the claim and the instrument. Some, like the battery carbon footprint declaration, require verification outright. Others accept self-declaration. Either way the passport should record which it is, because a reader treating a self-declared figure as audited is a misunderstanding you created.

Claims

How do we prove recycled content?

With a chain-of-custody model stated explicitly. Identity-preserved and segregated claims mean the physical material is there; mass balance means an equivalent quantity entered the system somewhere. All three are legitimate, but publishing a mass-balance figure as though it were segregated is the claim that gets challenged.

Claims

Do consumers actually scan product passports?

Some do, and the ones who do are the ones deciding between you and an alternative. Treat scan volume as a signal of intent rather than reach: a scan asking for repair instructions is somebody keeping your product in use, which is worth more than a hundred passive impressions.

Claims

Respostas

Perguntas frequentes

Does the Digital Product Passport apply to my company?

If you place a physical product on the EU market, almost certainly — eventually. ESPR works product group by product group, so the question is not whether but when your group’s delegated act lands. Batteries above 2 kWh are already fixed for February 2027. Everything else follows a delegated act with roughly eighteen months from adoption to enforcement.

What is the ESPR deadline?

There is not one, and any tool showing a single ESPR date has invented it. Obligations arrive per product group through delegated acts, each allowing roughly eighteen months before enforcement. Iron and steel is expected first, with textiles following. The only fixed passport date in EU law today is 18 February 2027, for batteries.

Who is legally responsible for the passport?

The economic operator placing the product on the EU market — usually the manufacturer, or the importer where the manufacturer is outside the EU. Responsibility cannot be delegated to a software vendor. A service provider can host and serve the passport, but the operator remains accountable for whether its contents are correct.

We manufacture outside the EU. Does this reach us?

Through your importer, yes. The obligation attaches to whoever places the product on the EU market, so an EU importer inherits it — and will pass the data requirement straight back up the contract to you. In practice non-EU manufacturers feel this as a customer requirement before they feel it as a law.

Are small companies exempt?

Not by default. ESPR allows delegated acts to take proportionality into account, and micro-enterprises may get lighter treatment in specific product groups, but there is no blanket small-company carve-out. Assuming one is a common and expensive mistake, because supply chain customers impose the requirement regardless of statutory relief.

What happens if we do not comply?

Penalties are set nationally, and market surveillance authorities can require withdrawal from the market. That commercial consequence usually outweighs the fine: a product that cannot be sold in the EU while its passport is corrected is a stock and revenue problem, not a legal line item.

Next step

Faça-nos aquela que aqui não está

Se a sua pergunta for específica do seu grupo de produtos ou da sua cadeia, provavelmente pede uma conversa em vez de um parágrafo. De qualquer forma, responderemos.

Respondemos a questões de âmbito, esteja ou não a avaliar-nos.

Index