How to choose a DPP solution

A buyer's guide — the criteria that are verifiable regardless of the vendor

One thing before we start

We are a DPP vendor too — so this guide is not neutral in origin. That is why it is built so you do not have to trust us: every criterion below is publicly verifiable or answerable with a direct question to any vendor, including us. We name no companies — compare on criteria, not on names.

Before comparing anyone, answer three questions: which product category your products fall into and which act governs it; at what level you will need passports — model, batch or individual item; and which of the required data you actually hold today. Without those three answers, every demo looks convincing.

The eight criteria that matter

Category and delegated act

Does the platform support your exact category?

Not “we support ESPR” in general, but the specific fields of your act — and who updates the templates when the act changes.

Standards and identifiers

GS1 Digital Link, JSON-LD, a permanent address

The passport must resolve through a standard carrier and live at a permanent address that does not die with your contract. Ask to scan a live passport, not to watch a mock-up.

Passport levels

Model, batch, item

Different acts require different levels. The Commission's registry for batteries works at individual item level — check the platform can do all three.

Data provenance

Who entered each value, and when

Look for an audit log with the regulatory retention period — who, when, and the before and after states. Without it, every inspection by a market authority becomes archaeology.

Integration

An API and a route to your systems

If the data lives in an ERP or PIM, manual re-entry is a permanent source of errors. Ask for the public API documentation — its very existence is a signal.

Exit and portability

Can you leave with everything?

Full export in open formats, at any time. It is also a regulatory obligation — a vendor who makes it hard is telling you something important about themselves.

Responsibility

Who answers for accuracy

Under the regulation — you, as the operator. A platform can validate structure and completeness, but not truth. Run from anyone promising otherwise.

The real cost

The cost of the process, not the subscription

Add up: subscription + data entry + integration + support when the act changes. A public price list is a good sign; “contact us” at every price point is not.

Red flags

“EU-certified” or “approved provider”. No such regime exists — no authority currently certifies or approves DPP vendors. The Commission is preparing a separate act on service providers, but as of today there is no accreditation. Anyone claiming otherwise is overstating.

Compliance guarantees. Compliance is a property of your data and processes, not of software. A platform can make compliance achievable and verifiable — it cannot guarantee it on your behalf.

Export only in a proprietary format, or no export at all. That is lock-in dressed up as a product.

Demos only on sample data. A convincing demo on someone else's data proves nothing about yours. Ask for a pilot with one of your real products before signing anything.

How to check any vendor in five minutes

Look up the legal entity and its registration number — a serious vendor prints them on its site. Check whether the technical documentation is public or “available on request”. If ISO certification is claimed — ask for the number and the scope, and verify them with the certification body. Then put the same criteria questions above to everyone on your list: the differences in the answers say more than any presentation.

Our answers to these questions are public — on our “DPP provider or software” page, in our technical documentation and in our price list. Hold us to the same standard you hold everyone else.

For completeness, here are our own answers to the same questions — row by row, with a date: Technical standards & interoperability. Put them to every provider you are considering, including us.

Using this guide

Questions buyers ask us

No. There is no such regime today: no authority certifies or approves Digital Product Passport vendors. The Commission is preparing a separate act on DPP service providers, but as of now nothing is accredited and nobody is on an approved list. A vendor claiming otherwise is overstating, and that is worth knowing before the second meeting.

No, and be careful with anyone who says it can. Compliance is a property of your data and your processes. Under the regulation the economic operator answers for the accuracy of what is declared. A platform can validate structure and completeness, keep the format to the harmonised standards and prove who changed what and when. It cannot make a wrong number true.

Six things that separate answers quickly: does the platform support the specific fields of my delegated act, and who updates the template when the act changes; can I scan a live passport right now rather than watch a mock-up; can I export everything in an open format today; is the API documentation public; is there an audit log covering the regulatory retention period; and what does the whole process cost, not just the subscription.

You should not have to. That is why the guide names no companies and why every criterion in it is either publicly verifiable or answerable with a direct question to any vendor, including us. Our own answers to the same questions are published — the price list, the technical documentation, the subprocessor list and the certificate number are all on this site. Hold us to the standard you hold everyone else.

Last verified