What actually launched
Four things landed between 15 and 20 July.
- The registry went live on 20 July 2026. It opened with a public testing environment, secure UI and API access, a semantic repository with machine-readable data models, implementation guidelines and a helpdesk. Not a press release. A system you can request access to.
- Its rulebook was published two days earlier. Commission Implementing Regulation (EU) 2026/1778 of 16 July 2026, published in the Official Journal on 17 July, governs the registry: access management, identity verification, data registration, storage, the API and a 10-year retention period. It enters into force on 6 August 2026.
- The first six harmonised standards were cited on 15 July. Commission Implementing Decision (EU) 2026/1736, adopted 14 July, put six CEN/CENELEC DPP standards into the Official Journal, granting presumption of conformity with Articles 10 and 11 of the Ecodesign Regulation. More on these below, because they answer the format question.
- ESPR reached full application on 19 July. The Ecodesign Regulation, Regulation (EU) 2024/1781, has been in force since 18 July 2024 and is now fully applicable. Its first live obligation already bites: large companies may no longer destroy unsold textiles and footwear.
None of this changes who must comply or when. It changes something quieter: the infrastructure everyone said was coming actually shipped, on schedule, with a helpdesk.
What the registry is, and what it is not
The registry is a decentralised, federated index. It stores the passport identifier and the lookup metadata needed to find a passport. The passport data itself stays on the operator's side, hosted at a URL the identifier resolves to. The operator is the economic actor responsible for the product, usually the brand or manufacturer.
So the registry is a phone book, not the conversation. When someone scans a product's data carrier, the identifier resolves to a record the brand controls and hosts. The Commission never holds your product data. It holds the pointer.
Two things the registry is not. It is not a data vault: nobody uploads their bill of materials to a server in Brussels. And it is not a blockchain: the EU looked hard at distributed ledgers for this job and chose a federated web architecture instead, for reasons we unpacked in why the EU rejected blockchain for the DPP.
If you already host product records at stable URLs, this architecture should feel familiar. The registry does not replace your hosting. It points at it.
Who must care, and when
First production use is batteries. From 18 February 2027, EV batteries, industrial batteries over 2 kWh and Light Means of Transport batteries need a DPP under Article 77 of Regulation (EU) 2023/1542. That deadline is unchanged.
One point of frequent confusion: battery due-diligence obligations were separately postponed to 18 August 2027 by Regulation (EU) 2025/1561. The postponement covers due diligence only. The passport date did not move.
After batteries, the ladder comes from the first ESPR working plan, adopted 16 April 2025 and unchanged since. Compliance typically lands around 18 months after each delegated act, so a textiles act in early 2027 would put textile passports on shelves around late 2028, if the current plan holds.
| Date | What | Status |
|---|---|---|
| 15 July 2026 | Six harmonised DPP standards cited in the Official Journal | Done |
| 17 July 2026 | Registry regulation (EU) 2026/1778 published | Done |
| 19 July 2026 | ESPR full application; unsold textiles destruction ban for large companies | Done |
| 20 July 2026 | DPP Registry goes live | Done |
| 6 August 2026 | Registry regulation enters into force | Set |
| ~September 2026 | Two pending security standards (prEN 18239, prEN 18246) expected | Expected |
| Late 2026 | Iron and steel delegated act target | Target |
| 18 February 2027 | Battery passports mandatory (EV, industrial over 2 kWh, LMT) | Set |
| ~Early 2027 | Textiles and apparel delegated act expected | Expected |
| 2027 | Tyres and aluminium delegated acts expected | Expected |
| 18 August 2027 | Battery due-diligence obligations apply | Set |
| 2028 | Furniture delegated act expected; ESPR mid-term review, the earliest realistic window for new categories | Expected |
| 2029 | Mattresses delegated act expected | Expected |
For the sector-by-sector picture, see the EU DPP timeline 2026-2030. If batteries touch your catalog, the battery passport guide covers the February 2027 scope in detail.
What the standards mean for QR codes and data
Standards sound dry until you notice they answer the question every merchant actually asks: what format? The six cited on 15 July are:
- EN 18216:2026, data exchange protocols
- EN 18219:2026, unique identifiers
- EN 18220:2026, data carriers
- EN 18221:2026, data storage, archiving and persistence
- EN 18222:2026, APIs
- EN 18223:2026, system interoperability
Citation in the Official Journal grants presumption of conformity with ESPR Articles 10 and 11: build to these and you are presumed to meet those requirements.
The one to read first is EN 18220. It defines what may carry the passport link on a physical product: QR codes, Data Matrix, NFC and RFID all qualify. Its encoding examples reference ISO/IEC 18975 and GS1 Digital Link URI syntax. In plain terms, a product identifier packed into a normal QR code, resolving over HTTPS to a URL you control. No mandatory chip, no proprietary format. If you have read our QR certificate and GS1 Digital Link guide, you already know this pattern. The record behind the URL should be machine-readable, and our JSON-LD field walkthrough covers that shape.
Two security standards, prEN 18239 and prEN 18246, are still pending and expected around September 2026. Until they land, the security layer is the one part of the stack still in draft, so treat security-specific tooling claims with some caution for now.
Provenance that matches the pattern
Editioned runs numbered editions, hosted certificates at stable URLs, QR data carriers and DPP-shaped JSON-LD export on Shopify. Install free, 30-day Pro trial, no card.
Install free on ShopifySelling jewelry, art or craft? Read this part
Read the coverage lists twice and one absence stands out. Jewelry, watches, art, ceramics and craft goods appear in none of them. Not in the working plan, not in the registry coverage list, not in any delegated act. The earliest realistic entry point is the 2028 mid-term review, or a later working plan after that. If you sell in these categories, nothing is required of you, and that will likely stay true for years.
So why care? Three reasons.
- The pattern is now settled. Identifier, data carrier, resolvable URL, machine-readable record. That is the shape the EU built, the shape the standards describe, and the shape any future category rules would most likely reuse. Voluntary provenance built this way should age well.
- Expectations travel. A buyer who scans a passport on a pair of running shoes in 2028 may wonder why the piece that cost ten times more scans to nothing. Retail partners handling passports for obligated lines may start preferring passport-shaped data across the board.
- Voluntary is cheap. Building provenance on your own schedule, with no deadline and no auditor, costs a fraction of retrofitting it under one.
This is the argument we made in does the EU DPP apply to jewelry, and last week strengthened it: the target is no longer hypothetical. A numbered edition with a hosted certificate at a stable URL, a QR carrier and a JSON-LD export is, structurally, a voluntary passport. If the framework ever reaches your category, you would be adjusting fields, not building a system.
What to do this month
If your products, or your suppliers' products, sit in an obligated category:
- Read Implementing Regulation (EU) 2026/1778. It is short as these things go, and it defines how access, identity verification and registration will work.
- Get into the public testing environment while the stakes are zero. The guidelines and helpdesk exist for exactly this phase.
- Name an internal owner for product data. Registry work is mostly data plumbing, and it goes badly when nobody owns it.
If you are not obligated:
- Give every product, ideally every unit or edition, an identifier that resolves to a stable URL.
- Put a QR carrier on the piece, its tag or its card.
- Keep the record machine-readable, not only pretty.
- Start collecting material, origin and care facts per product now, while gathering them is cheap.
- Put the 2028 mid-term review in your calendar, then get back to selling.
FAQ
What is the EU DPP Registry that went live on 20 July 2026?
It is the central index the European Commission runs for Digital Product Passports. It launched with a public testing environment, secure UI and API access, a semantic repository with machine-readable data models, implementation guidelines and a helpdesk. It stores passport identifiers and lookup metadata, not the passport content itself.
Does the registry store my product data?
No. The registry is a decentralised, federated index. It holds the passport identifier and the metadata needed to find a passport. The passport data itself stays on the operator's side, hosted at a URL the identifier resolves to. The economic operator, usually the brand or manufacturer, keeps control of the record.
Who needs a Digital Product Passport first, and by when?
Batteries. From 18 February 2027, EV batteries, industrial batteries over 2 kWh and Light Means of Transport batteries need a DPP under Regulation (EU) 2023/1542. Other categories follow after their delegated acts under the Ecodesign framework, typically with around 18 months of lead time once an act is adopted.
Did the battery due-diligence postponement move the passport deadline?
No. Regulation (EU) 2025/1561 postponed battery due-diligence obligations to 18 August 2027. The passport requirement is separate and its date did not move: 18 February 2027.
Do jewelry, art or craft goods need a DPP now?
No. Jewelry, watches, art, ceramics and craft goods are not named in any working plan, registry coverage list or delegated act. The earliest realistic entry point is the 2028 mid-term review or a later working plan. Provenance records in these categories remain voluntary, which is exactly why now is a low-pressure time to build them.
What do the new harmonised standards mean for QR codes?
EN 18220:2026 covers data carriers and accepts QR, Data Matrix, NFC and RFID. Its encoding examples reference ISO/IEC 18975 and GS1 Digital Link URI syntax, which means an identifier carried in a normal QR code that resolves to a stable URL sits squarely inside the standard. No special chip or proprietary format is required.
Ready before it is required
Certificates at stable URLs, QR data carriers and structured data on every numbered edition. The voluntary version of the thing the EU just switched on. 30-day Pro trial on every install, no card required.
Install on Shopify