By role
One passport. Five people who need different things from it.
A consumer wants to know how to wash it. A recycler wants to know how to take it apart. A regulator wants the evidence chain. Publishing one document for all three is how passport programmes stall.
- Public tier
- No login
- Restricted tier
- Credential-gated
- Evaluated
- At resolution
Definition
How does role-based access work in a Digital Product Passport?
A Digital Product Passport has one identity and several role-scoped views. Consumers scanning a data carrier receive the public tier with no login. Recyclers, repairers and regulators present verifiable credentials and receive the restricted tiers those credentials entitle them to. Commercial data stays with the brand and its suppliers.
The tiering is not a product convenience; it is written into the ESPR, which distinguishes information available to the public from information restricted to specified parties. A platform without it either over-publishes or under-serves the recycler the regulation is trying to help.
One passport, five views
Transparency does not mean publishing your supplier list
| Data category | Consumer | Retailer | Recycler | Regulator | Brand |
|---|---|---|---|---|---|
| Identity and originGTIN, model, manufacture date, country of assembly | Open | Open | Open | Open | Open |
| Care, repair and take-backInstructions, spare parts, return routes | Open | Open | Open | Open | Open |
| Material compositionDeclared composition and recycled content | On request | On request | Open | Open | Open |
| Substances of concernREACH-SCIP declarations and safe handling | On request | On request | Open | Open | Open |
| Disassembly instructionsSequence, fasteners, hazardous component locations | Restricted | Restricted | Open | On request | Open |
| Supplier identitiesTier-n facility names and site identifiers | Restricted | Restricted | Restricted | On request | Open |
| Cost and commercial termsNever part of the passport record | Restricted | Restricted | Restricted | Restricted | Open |
Illustrative default policy. Access is configured per product group and per regulation; where a delegated act requires a field to be public, the policy cannot be set to restrict it.
The five views
What each role resolves
For brands
Own the record, decide what it says publicly, and prove where every claim in it came from.
For manufacturers
Supply evidence once, signed by you, and satisfy every customer asking the same question.
For recyclers
Disassembly sequences, hazardous substance locations and material composition at the point of intake.
For consumers
Scan and read what a product is made of, how to care for it, and where it goes at end of life.
For regulators
The full compliance dataset with its evidence chain, and the ability to verify claims independently.
For retailers
Product-level sustainability data that can be surfaced on a listing without becoming an unsupported claim.
Resolution
What happens when someone scans
- 01
Resolve the identifier
The data carrier holds a GS1 Digital Link URL. Scanning it reaches the resolver with the product identity and nothing else.
- 02
Establish the caller
A consumer presents nothing. A recycler, repairer or authority presents a verifiable credential issued by a party the policy trusts.
- 03
Apply the policy
The access policy for that product group and regulation decides which fields the caller receives. Policy is evaluated now, not at issuance.
- 04
Return the view
The caller receives their tier — as a page for a person, as JSON for a system — with the credential evidence for every claim in it.
Answers
Frequently asked questions
Does a Digital Product Passport mean publishing our supplier list?
No. The ESPR (EU) 2024/1781 distinguishes between information available to the general public and information restricted to specified parties such as market surveillance authorities, repairers and recyclers. Supplier identities and commercial terms are not in the public tier, and CirculeID’s default policy keeps them restricted to the brand.
How does the platform know who is asking?
By what they present, not by who they say they are. A consumer scanning a QR code presents nothing and receives the public view. A recycler or a repairer presents a credential issued by an accreditation body or by you, and the resolver returns the tier that credential entitles them to.
Can a regulator see everything?
A market surveillance authority sees the full compliance dataset and its evidence chain, which is what an inspection requires. It does not automatically include commercial information that no regulation asks for. Access is defined per product group and per regulation, and where an act requires a field to be public the policy cannot restrict it.
What stops someone claiming to be a recycler?
The credential has to be issued by a party you or the accreditation regime trust, and it is cryptographically verifiable. A claim without a valid credential resolves to the public view. Credentials can also be revoked, which matters when a facility loses its permit.
Can access policies change after passports are issued?
Yes, and they need to. A delegated act may move a field from restricted to public, or a supplier agreement may change what you are permitted to share. Policy is evaluated at resolution time rather than baked into the issued document, so a change applies to every passport already in the field.
Next step
See the policy against your own data
Bring a product group and the fields you would never publish. We will show you the four views it produces and what each party sees.