If your DPP provider goes under tomorrow — what happens to your passports?

Kiril ShivachevKiril ShivachevAugust 21, 20265 min read
3D illustration of a checklist — the questions to ask any Digital Product Passport service provider.

When a company picks a Digital Product Passport platform, it usually asks about price, integrations and timelines. It rarely asks the question that will matter most in five years: if you cease to exist, what happens to my products’ passports?

The question is not hypothetical. A passport has to stay available for years after the product left the factory — and the DPP platform market is currently full of companies founded less than three years ago.

What the regulation actually requires

Regulation (EU) 2024/1781 deals with this in two places, and they are not the same thing.

Article 10(4) is short and unambiguous: the economic operator, when placing the product on the market, shall make available a back-up copy of the passport through a digital product passport service provider. That is an obligation, not a good practice.

Article 2(32) defines who may be such a provider: an independent third party, authorised by the operator, that processes the passport data in order to make it available to those with access rights.

So the back-up cannot sit with you, and it cannot sit with the same provider. It sits with an independent third party. That is the mechanism meant to protect you.

⚠ The precision most explanations miss

Article 11(e) says the passport shall remain available for the period specified in the delegated acts — including after an insolvency, a liquidation or a cessation of activity in the Union of the economic operator responsible for creating the passport.

Read those last words carefully. The protection is written against the failure of the manufacturer — the party that creates the passport. Not against the failure of the platform hosting it.

If your software provider disappears, the regulation does not describe that scenario explicitly. It is covered only indirectly: through the Article 10(4) duty to place the back-up with an independent third party, and through the European standard EN 18221, which governs storage, archiving and data persistence, including replication between economic operators and back-up operators. It is one of the six standards cited in the Official Journal on 15 July 2026.

The distinction has practical consequences. It means the answer to "what if you disappear" should not be a promise in an email. It should be the name of a third party and the standard that party works to.

There is still no accreditation for DPP providers

This is the part almost nobody writes about. Article 11 empowers the Commission to adopt delegated acts setting out the requirements that digital product passport service providers must meet in order to become such providers — and, where appropriate, a certification scheme to verify compliance.

The empowerment exists. The act does not. Which means that, as of today, anyone can call themselves a DPP service provider. There is no register, no accreditation, no exam.

The practical consequence: choosing a provider today is entirely your responsibility, not something a regulator has already checked on your behalf.

How long must the passport stay available?

The honest answer is that nobody knows yet. Article 11 refers to "the period specified in delegated acts" — and the delegated act for your product group probably does not exist yet.

If a provider gives you a specific number for your category today, ask where it comes from. The regulation does not contain one.

Six questions before you sign

1. Who is your back-up provider, and in what way are they independent of you? The answer is a name, not the word "yes".

2. Where does the primary copy live? Article 11(c) allows it to sit either with the economic operator or with the service provider — establish which applies to you.

3. Do you implement EN 18221, and specifically the replication to a back-up operator and the data-lifetime rules?

4. If I terminate the contract, in what format do I take my data? Article 10(1)(d) requires data to be based on open standards and transferable through an open interoperable exchange network — explicitly without vendor lock-in.

5. What do you do with my data besides storing it? Article 11 forbids providers from selling, reusing or processing the data beyond what the service requires, unless specifically agreed with the operator.

6. How is data authenticity demonstrated? Article 11(g) requires authentication, reliability and integrity. Note that the two security standards — on access rights and on data authentication — have not yet been cited in the Official Journal.

Why this is a test for us too

We publish these questions because they apply to us as well. If you ask them and get an answer containing names, articles and standards, you are talking to a serious provider. If you get reassurance, you know what is missing.

The passport has to outlive the product. The product often outlives its manufacturer. And in this market — sometimes the platform too.