Security and Compliance

Your data In safe hands

The Digital Product Passport holds sensitive product and supply-chain data. Here is how we protect it and which standards we work to.

Data security

  • ISO/IEC 27001:2022 certification for information security management (reg. no. BG2026030401).
  • Infrastructure on AWS with role-based access and encryption.
  • Three access tiers — public (consumer), professional (technical data), and authority (full certificates via eIDAS).

Compliance and standards

  • eIDAS authentication for authority-tier access.
  • Built to the European CEN-CENELEC standards for the DPP (the EN 18216–18223 series, cited in the Official Journal on 15 July 2026) for identification, security, and long-term data storage.
  • Member of the CIRPASS-2 Stakeholder Community — the EU initiative preparing the DPP.

Retention and audit

  • An immutable audit trail and long-term data retention in line with requirements.
  • Full data portability in open standards (JSON-LD, Schema.org) — no vendor lock-in.

Have a question about the security or compliance of a specific process? Book a free consultation and we’ll answer it concretely.

ISO/IEC 27001:2022 certification

Our information security management system is certified by an independently accredited body. The details below are what the certificate can be verified against.

  • Standard: ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection. Information security management systems. Requirements.
  • Certificate holder: WIARA – DAAS EOOD
  • Registration number: BG2026030401
  • Certification body: INCERT EOOD
  • Scope of certification: Development, maintenance and subsequent monitoring of software.
  • Certified site: Plovdiv, Bulgaria
  • Initial approval: 4 March 2026
  • Valid until: 3 March 2029
  • Statement of Applicability: Version 01 / 23 January 2026
  • Accreditation: Bulgarian Accreditation Service (ИА БСА), Reg. No. 16 ОСС; IAF MLA signatory
  • Verification: incert.bg

Independent verification in the IAF global database of accredited certifications: IAF CertSearch — WIARA – DAAS LTD.

Your data: where it is, whose it is, how you get it back

Where. Data and passports are stored on AWS in the Frankfurt region (eu-central-1), inside the European Union. Published passports are served as static pages through a CDN, with a permanent address per product.

Whose. The data belongs to the manufacturer. WIARA processes it only to provide the service and uses it for nothing else.

Export. All data and passports can be exported at any time in open, machine-readable formats (JSON-LD, Schema.org). This also covers the portability and backup obligations under the ESPR (Article 10(4) and Article 27).

On termination. You receive a full export. Passports already published remain available for the product's lifecycle plus 10 years as our own commitment, and the audit trail is kept for 7 years — as stated on the pricing page.

Responsibility. The manufacturer is responsible for the accuracy of the declared data — that is how the ESPR and the CPR work. WIARA is responsible for the platform: availability, data integrity, format to EN 18216–18223, the audit trail and ISO/IEC 27001 security.

Security

Certification questions

Certificate No. BG2026030401 was issued by INCERT, valid from 4 March 2026 to 3 March 2029, with the scope “Development, maintenance and ongoing monitoring of software”. It certifies our information security management system, within which the DPP platform is developed and operated. ISO 27001 is not a certificate of the product’s regulatory compliance with ESPR — those are two different things, and we keep them distinct.

We provide a copy of the certificate and its scope on request. Its validity can be verified independently with the certification body INCERT and in the international IAF CertSearch database. For corporate due diligence we provide further documentation under a confidentiality agreement.

The platform runs entirely on Amazon Web Services in the Frankfurt (EU) region — effectively the only subprocessor with access to passport data. The full list, including website tools, is published on the “Subprocessors and infrastructure” page and updated on every change.

Last verified

DigitalProductPassport in other countries: Bulgaria · Czechia · Greece · Hungary · Poland · Romania · Slovakia