yellow3 / Digital Product Passport
Buyer resource
How to choose a Digital Product Passport provider
There is no best provider in general; there is the provider that can show, not just state, what your products and your obligations need.
- What this helps you do
- Run a provider decision as a procurement framework: ten questions in three stages, and the evidence that answers each.
- Evidence basis
- yellow3 Buyer Platform provider questions, the European Digital Product Passport standards, Implementing Regulation (EU) 2026/1778.
- Updated
- Regulatory status checked 28 September 2026
yellow3 does not publish a verdict naming a best provider. The right one depends on your products, the rule that applies to them and the requirements you set. What can be made objective is the evidence. To see who states what today, use the software comparison or the Supplier Register.
Whichever provider you choose, the economic operator that places the product on the EU market remains responsible for the passport: its accuracy, its registration and its availability (Implementing Regulation (EU) 2026/1778, Article 19(4)). The battery passport applies from 18 February 2027; for most other product groups no ESPR rule has been adopted yet, so "full compliance" today is a promise against requirements that do not exist. See evidence requirements.
01
Establish fit
Who stays responsible, and whether the basics a passport cannot work without are there.
-
01
Who is the economic operator of record Contract
Contract clause the buyer chooses to require
Ask The contract states that you remain the economic operator responsible for registration and for the accuracy of passport data, and describes what the provider does on your behalf.
Evidence that answers it A contract clause. Under Implementing Regulation (EU) 2026/1778, Article 19(4), the economic operator placing the product on the market stays responsible even where a service provider performs the work, so a provider who implies otherwise is describing something that is not available to sell.
-
02
Unique identifiers EN 18219
European standard, cited in the Official Journal (Implementing Decision (EU) 2026/1736)
Ask The provider supports at least one of the five identifier schemes permitted by EN 18219, and can state which, including the operator identifier.
Evidence that answers it A written statement naming the scheme or schemes supported (GS1 Digital Link URI, IEC 61406 identification links, W3C decentralised identifiers, RFID or 2D product identifiers, or DOIs) and how the economic operator is identified. A demonstration against a real product is stronger than a datasheet.
-
03
Data carriers EN 18220
European standard, cited in the Official Journal (Implementing Decision (EU) 2026/1736)
Ask At least one data carrier offered is free to use and readable by an ordinary smartphone with no application installed, as EN 18220 requires.
Evidence that answers it A working link or code you can scan on an unmodified phone. A carrier that needs the provider's own app does not satisfy this, and anybody can run the test in a meeting.
02
Test the evidence
Whether the passport data can be exchanged, operated, read elsewhere and protected, shown rather than stated.
-
04
Data exchange protocols EN 18216
European standard, cited in the Official Journal (Implementing Decision (EU) 2026/1736)
Ask Passport data is exchanged over the REST, HTTPS and TLS transport described by EN 18216.
Evidence that answers it API documentation showing the transport and TLS configuration, or a written statement of conformity naming the standard.
-
05
Lifecycle APIs EN 18222
European standard, cited in the Official Journal (Implementing Decision (EU) 2026/1736)
Ask The provider offers create, read, update and search operations, batch retrieval, versioning and registry submission, per EN 18222.
Evidence that answers it API documentation covering each operation by name. Batch retrieval and registry submission are the two most often missing, so ask for them specifically rather than accepting a general conformance claim.
-
06
System interoperability EN 18223
European standard, cited in the Official Journal (Implementing Decision (EU) 2026/1736)
Ask Passport data uses the shared data model and semantics of EN 18223, so it remains machine-interpretable outside the provider's own platform.
Evidence that answers it A sample passport export you can read without the provider's tooling. This is the requirement that decides whether leaving the provider is possible, so test it rather than accept it on paper.
-
07
Access rights, security and confidentiality EN 18239
European standard, published 16 September 2026, not yet cited in the Official Journal
Ask The provider can describe how role-based access separates public from restricted passport data, and states whether it conforms to EN 18239.
Evidence that answers it A written description of the access model and the roles it distinguishes, and a statement of conformity where the provider claims one. Conformity does not yet carry a legal presumption of conformity.
-
08
Data authentication and integrity EN 18246
European standard, published 16 September 2026, not yet cited in the Official Journal
Ask The provider can describe how passport data is made tamper-evident, and states whether it conforms to EN 18246.
Evidence that answers it A written description of the mechanism used (W3C verifiable credentials, an eIDAS electronic attestation of attributes, an ISO 22376 visible digital seal or ISO/IEC 20248) and a statement of conformity where the provider claims one. Conformity does not yet carry a legal presumption of conformity.
03
Test delivery and continuity
Whether the passport survives time, the provider and rules not yet written.
-
09
Storage, archiving and persistence EN 18221
European standard, cited in the Official Journal (Implementing Decision (EU) 2026/1736)
Ask The provider supports the lifetime availability, versioned history and independent backup arrangements described by EN 18221.
Evidence that answers it Written terms covering retention period, version history, and the backup copy held by an independent service provider under ESPR Article 10(4). The economic operator remains responsible for availability, so a backup held only by the same provider does not answer this.
-
10
The pending service-provider rules Contract
Contract clause the buyer chooses to require
Ask The provider commits to meeting the requirements for Digital Product Passport service providers under ESPR Article 11(3) once that delegated act is adopted, and the contract lets you exit if it does not.
Evidence that answers it A contract clause naming the act and an exit right. The delegated act is not yet adopted (status checked 28 September 2026; the Commission plans it for 2027). Nobody knows what certification it will require, which is a reason to keep the first term short rather than a reason to wait.
Two tests to run in the first meeting
Scan it on an ordinary phone. Ask for a live data carrier and scan it with an unmodified smartphone. If it needs the provider's app, it fails EN 18220's requirement for a carrier readable without an application.
Read the export without their tools. Ask for a sample passport export and open it without the provider's software. If you cannot read it, you cannot leave, whatever the contract says about portability (EN 18223).
Keep statements and evidence apart
A provider's statement that it supports a standard is a statement; a demonstration you can inspect is evidence. The yellow3 Supplier Register records every capability finding as stated or shown, with its source page and date, and suppliers cannot pay to change a finding. Keep the two in separate columns when you compare responses, because a table that mixes them makes the best-written brochure look like the best product. The yellow3 Buyer Platform runs this comparison against your own programme.
Sources and status
Legal statements cite the article that imposes them, and every date carries its legal status, as in the Digital Product Passport 2026 executive report. Regulatory status checked 28 September 2026; yellow3 re-checks the Official Journal and CEN-CENELEC's published standards every week. This page separates what the law requires from what a buyer may choose to require, and neither is legal advice.