
When a company picks a Digital Product Passport platform, it usually asks about price, integrations and timelines. It rarely asks the question that will matter most in five years: if you cease to exist, what happens to my products’ passports?
The question is not hypothetical. A passport has to stay available for years after the product left the factory — and the DPP platform market is currently full of companies founded less than three years ago.
Regulation (EU) 2024/1781 deals with this in two places, and they are not the same thing.
Article 10(4) is short and unambiguous: the economic operator, when placing the product on the market, shall make available a back-up copy of the passport through a digital product passport service provider. That is an obligation, not a good practice.
Article 2(32) defines who may be such a provider: an independent third party, authorised by the operator, that processes the passport data in order to make it available to those with access rights.
So the back-up cannot sit with you, and it cannot sit with the same provider. It sits with an independent third party. That is the mechanism meant to protect you.
Article 11(e) says the passport shall remain available for the period specified in the delegated acts — including after an insolvency, a liquidation or a cessation of activity in the Union of the economic operator responsible for creating the passport.
Read those last words carefully. The protection is written against the failure of the manufacturer — the party that creates the passport. Not against the failure of the platform hosting it.
If your software provider disappears, the regulation does not describe that scenario explicitly. It is covered only indirectly: through the Article 10(4) duty to place the back-up with an independent third party, and through the European standard EN 18221, which governs storage, archiving and data persistence, including replication between economic operators and back-up operators. It is one of the six standards cited in the Official Journal on 15 July 2026.
The distinction has practical consequences. It means the answer to "what if you disappear" should not be a promise in an email. It should be the name of a third party and the standard that party works to.
This is the part almost nobody writes about. Article 11 empowers the Commission to adopt delegated acts setting out the requirements that digital product passport service providers must meet in order to become such providers — and, where appropriate, a certification scheme to verify compliance.
The empowerment exists. The act does not. Which means that, as of today, anyone can call themselves a DPP service provider. There is no register, no accreditation, no exam.
The practical consequence: choosing a provider today is entirely your responsibility, not something a regulator has already checked on your behalf.
The honest answer is that nobody knows yet. Article 11 refers to "the period specified in delegated acts" — and the delegated act for your product group probably does not exist yet.
If a provider gives you a specific number for your category today, ask where it comes from. The regulation does not contain one.
1. Who is your back-up provider, and in what way are they independent of you? The answer is a name, not the word "yes".
2. Where does the primary copy live? Article 11(c) allows it to sit either with the economic operator or with the service provider — establish which applies to you.
3. Do you implement EN 18221, and specifically the replication to a back-up operator and the data-lifetime rules?
4. If I terminate the contract, in what format do I take my data? Article 10(1)(d) requires data to be based on open standards and transferable through an open interoperable exchange network — explicitly without vendor lock-in.
5. What do you do with my data besides storing it? Article 11 forbids providers from selling, reusing or processing the data beyond what the service requires, unless specifically agreed with the operator.
6. How is data authenticity demonstrated? Article 11(g) requires authentication, reliability and integrity. Note that the two security standards — on access rights and on data authentication — have not yet been cited in the Official Journal.
We publish these questions because they apply to us as well. If you ask them and get an answer containing names, articles and standards, you are talking to a serious provider. If you get reassurance, you know what is missing.
The passport has to outlive the product. The product often outlives its manufacturer. And in this market — sometimes the platform too.
Get Started
Schedule a meetingDPP for Textiles
DPP for Steel and Iron
DPP for Batteries
DPP for Construction Materials
DPP for Furniture
DPP for Manufacturers
ESPR - Core Framework
DPP - Digital Product Passport
Work Plan 2025-2030
DPP - First Affected Industries
Partner Program
Technical standards
FAQ
Deadlines
CPR - Construction Products
Regulations
Battery Regulation & battery passport
PPWR – Packaging Regulation
CRMA – Critical Raw Materials Act
CBAM – carbon border adjustment
Toy Safety Regulation (EU) 2025/2509
Detergents Regulation (EU) 2026/405
Right to Repair – Directive 2024/1799
Green claims & greenwashing – ECD 2024/825
Textile EPR – Waste Framework Directive
CEA – Circular Economy Act
EPA – European Product Act
© 2026 WIARA DAAS Ltd.
All rights reserved.