For much of the past few years, the Digital Product Passport conversation has focused on the product itself.
What data will the passport contain? Where will the QR code sit? Which system will host the information? Which provider should a manufacturer use?
Those questions matter.
But for companies selling products online, another question is becoming increasingly difficult to ignore:
What happens to the Digital Product Passport before somebody buys the product?
On 24 September 2026, CIRPASS-2 published new recommendations on the integration of European Digital Product Passports into e-commerce environments.
The document focuses specifically on the pre-sale environment, where product manufacturers, retailers and online marketplaces already have to present multiple layers of product and consumer information.
The Digital Product Passport adds another one.
That may sound like a user-interface problem.
It is bigger than that.
The law already anticipates an online passport
The Ecodesign for Sustainable Products Regulation, or ESPR, does not treat the Digital Product Passport as something customers should only discover after receiving a physical product.
Article 9 says that, for product groups covered by future delegated acts, those acts must specify how the Digital Product Passport is made accessible to customers before they are bound by a contract, including in distance selling.
That distinction matters.
A QR code printed on a physical product cannot solve that requirement when the customer is sitting at home looking at a product page.
ESPR goes further.
Article 10 requires the economic operator placing the product on the market to provide dealers and online marketplaces with a digital copy of the relevant data carrier or unique product identifier when potential customers cannot physically access the product.
Article 31 then requires dealers to ensure that the Digital Product Passport is easily accessible to customers and potential customers, including in distance selling, according to the requirements eventually specified for the relevant product group.
Put those provisions together and the direction becomes fairly clear.
For covered products sold online, the Digital Product Passport becomes part of the digital sales environment.
This is not a rule saying where the button goes
There is an important distinction.
ESPR establishes the framework. It does not currently prescribe one universal product-page design for every Digital Product Passport.
The detailed requirements will depend on the delegated acts adopted for individual product groups.
Those acts can determine things such as the required passport data, the data carrier, whether the passport operates at model, batch or item level, access rights and the way customers must be able to access it before purchase.
The new CIRPASS-2 publication should therefore not be confused with legislation.
CIRPASS-2 is an EU-funded implementation and research initiative. Its new e-commerce document contains recommendations. It does not create new legal obligations.
That difference is essential.
But the recommendations are still useful because they take a requirement that can appear abstract in legislation and move the discussion closer to the real customer journey.
The product page is becoming part of DPP implementation
Imagine a customer considering a pair of shoes, a piece of furniture, an electrical product or another product group eventually covered by Digital Product Passport requirements.
Today the product page might contain price, photographs, dimensions, materials, delivery information, reviews and sustainability claims.
Tomorrow it may also need to provide access to regulated product information through a Digital Product Passport.
That raises a different set of implementation questions.
Where should passport access appear?
How visible does it need to be?
Should a customer enter the full passport immediately, or first see a structured consumer-facing layer?
How do you prevent mandatory information from disappearing beneath marketing content?
How does the experience work on a mobile screen?
What happens if the same product appears on the manufacturer's website, a retailer's website and several marketplaces?
And what happens when the passport information changes while those sales channels continue to display the product?
These are no longer questions for the compliance team alone.
They touch product management, e-commerce, UX, IT architecture, master data, legal, marketing and supply-chain operations.
The Digital Product Passport is not another sustainability badge
This is also where businesses need to be careful about how the passport is presented.
The Digital Product Passport should not become another decorative sustainability icon sitting beside a collection of environmental claims.
Its purpose is fundamentally different.
The DPP is intended to provide structured product information to different actors across the value chain, with access determined by their role and the applicable product requirements.
Some information may be relevant to consumers.
Other information may matter to repairers, recyclers, customs authorities, market surveillance authorities or other professional actors.
Some data may be public. Other data may be subject to access controls.
That means the customer-facing Digital Product Passport experience may ultimately need to do something quite sophisticated:
make the regulated information easy to discover without pretending that every user should see every piece of passport data.
One passport, many sales channels
The e-commerce challenge becomes even more interesting when the manufacturer is not the seller.
A product may be manufactured by one company, imported by another, sold by a distributor and ultimately displayed to a customer through a large online marketplace.
The passport still has to refer to the correct product.
The identifier has to travel through that commercial chain.
The online seller has to know which passport belongs to which product offer.
And the information needs to remain available and current.
That means Digital Product Passport readiness cannot stop at generating a passport.
Companies will need to think about how identifiers and passport access move through their existing product-information systems, commerce platforms, distributors and marketplace feeds.
For companies with thousands of SKUs and multiple sales channels, this could become a substantial data-governance challenge.
For marketplaces, the DPP becomes infrastructure
Online marketplaces should pay particular attention.
ESPR explicitly anticipates their role. Economic operators must be able to provide marketplace providers with the relevant digital identifier or data carrier where customers cannot physically access the product.
This creates a practical integration question.
If millions of products eventually require Digital Product Passports, marketplaces cannot reasonably treat passport access as an occasional manual link added by sellers.
It becomes part of the product-data infrastructure.
Marketplace product schemas, seller onboarding, validation processes and product-page components may all need to accommodate it.
And that creates another issue: bad data does not become good data merely because it has been passed to a marketplace.
The same problem we repeatedly see elsewhere in Digital Product Passport preparation remains.
The passport is only as reliable as the evidence and data feeding it.
Non-EU companies should pay particular attention
This matters beyond Europe.
The ESPR framework applies to covered products placed on the EU market, not simply to products manufactured inside the European Union.
A company in the United States, United Kingdom, China, India or elsewhere selling covered products into Europe therefore cannot assume that the Digital Product Passport is somebody else's problem.
For distance selling, the digital customer journey can become part of compliance.
This is especially relevant to brands selling directly to European consumers from their own websites, and to companies using European or global online marketplaces.
They will need to understand not only whether their products fall within future product-specific Digital Product Passport requirements, but also how their product data reaches the online sales channel through which an EU customer sees the offer.
The first DPP question should not be "Which platform?"
There is a tendency for Digital Product Passport projects to become technology projects very quickly.
Which platform should we buy?
Which QR technology should we use?
Which passport provider has the best interface?
The emerging e-commerce requirements reinforce why that is the wrong place to start.
Before selecting technology, a business needs to understand the product, the applicable regulatory position, the information it holds, where that information lives, who controls it, what can be evidenced and where that product is sold.
If the product appears across ten different commerce channels, the implementation problem is different from that of a manufacturer selling through one controlled channel.
If critical product information sits with upstream suppliers, the problem is different again.
If the business cannot reliably connect the correct product identifier to the correct passport, an attractive DPP interface will not solve it.
The product page is becoming a compliance surface
That may be the broader lesson from the latest CIRPASS-2 work.
For years, e-commerce teams have treated the product page primarily as a conversion surface.
It exists to help the customer understand the product and decide whether to buy it.
European product regulation is increasingly adding another function.
The product page is becoming a compliance surface.
Digital Product Passport information will sit alongside other regulated product information, responsible economic operator details, warnings, labels and information requirements that may apply to the product being offered.
The companies that handle this well will not simply bolt another compliance link onto an already crowded page.
They will have to design the regulatory information layer into the product experience.
What businesses should do now
There is no reason to redesign every e-commerce site tomorrow.
For most ESPR product groups, the detailed Digital Product Passport obligations still depend on product-specific delegated acts.
But businesses can start mapping the problem now.
Take one representative product and trace it from the internal product record to every place where a European customer can buy it.
Ask:
- Which entity places this product on the EU market?
- Which company controls the product data?
- Which identifiers are used internally and externally?
- Which retailers and marketplaces receive that information?
- Can the same product be reliably recognised across those systems?
- Which product claims can actually be evidenced?
- Who would be responsible for keeping passport information current?
- How would a customer find the Digital Product Passport before buying?
If those questions are difficult to answer today, that is useful information.
It means the Digital Product Passport problem exists before a passport platform enters the conversation.
From QR code to customer journey
The Digital Product Passport began as an idea that could easily be visualised as a QR code attached to a physical product.
That picture is becoming too simple.
The emerging system connects regulation, identifiers, product data, supply chains, marketplaces, physical products and digital commerce.
CIRPASS-2's latest e-commerce work makes one part of that transition particularly visible.
The Digital Product Passport does not start when somebody scans the product.
For online commerce, it can start while somebody is still deciding whether to buy it.
That changes the implementation question from "How do we create a passport?" to "How does the passport become part of the way this product is sold?"
That is a much bigger question.
Sources and status
Regulation (EU) 2024/1781, Ecodesign for Sustainable Products Regulation. In particular Articles 9, 10, 11, 31 and 36. This is binding EU legislation. Product-specific Digital Product Passport requirements are established through applicable delegated acts.
CIRPASS-2, “Recommendations on the integration of European Digital Product Passports (DPP) into eCommerce environments”, 24 September 2026. DOI: 10.5281/zenodo.22871175. This is CIRPASS-2 guidance and does not itself create legal obligations.
CIRPASS-2, “E-commerce & DPP – Definitions & Obligations”, 24 September 2026. This provides a representative overview of DPP-relevant roles, definitions and obligations across relevant EU legislation. It should be treated as secondary guidance rather than binding EU law.
