DPP Compliance: Clarifying Liability and Responsibility
Reading time:
minutes
When it comes to the Digital Product Passport, simply providing a QR code is not enough. As soon as a Digital Product Passport becomes mandatory for a product group, the responsible economic operator must also ensure that the required information is provided accurately, completely, up-to-date, and in compliance with regulations.
This raises a key question for company management:
Who is responsible if information is missing, outdated, or incorrect?
The answer depends on the product group, the applicable legal framework, and the respective role in the supply chain. DPP compliance must therefore be understood as an interplay of regulation, product data management, and clear governance.
It is important to note that the Ecodesign for Sustainable Products Regulation (ESPR) does not automatically impose a DPP obligation on every product. For many product groups, specific requirements are established only through product-specific delegated acts. In addition, specific sectors, such as batteries or construction products, are subject to their own sector-specific regulations.
Who is responsible for the Digital Product Passport?
The ESPR distinguishes between various economic operators. The specific obligations applicable to a product are determined by the ESPR in conjunction with the relevant product-specific legal act.
In general, the manufacturer bears primary responsibility for ensuring that a product covered by the applicable requirements meets the applicable ecodesign and information requirements. This may include, among other things, conducting the conformity assessment, preparing technical documentation, and—where required—providing a Digital Product Passport.
The availability of the required information must also be ensured. There is no blanket rule for an unlimited retention period. The requirements and timeframes specified for the respective product group are decisive.
Importers may only place affected products on the market if the relevant requirements are met. This includes, among other things, verifying whether the manufacturer has conducted the required conformity assessment, prepared the technical documentation, and—where required—provided a Digital Product Passport.
Distributors also have their own verification obligations. Among other things, they must ensure that the required markings, Distributors also have their own obligations to verify compliance. Among other things, they must ensure that the required labeling, documentation, and—where applicable—a digital product passport are in place. If there are indications that a product does not comply with requirements, they may not simply make it available on the market.
Retailers, in turn, must ensure, in particular, that customers have access to the required product information and the Digital Product Passport.
Special caution is also required with private-label products and product modifications: Anyone who places a product on the market under their own name or brand, or modifies a product in a way that affects its compliance with the relevant requirements, may assume the manufacturer’s obligations themselves.
Separate regulatory frameworks also apply to batteries, construction products, and other goods regulated by sector-specific rules. A blanket allocation of DPP roles across the entire product range is therefore risky.
DPP Compliance Is Not the Same as Product Liability
When it comes to liability issues related to the Digital Product Passport, a distinction should be made between at least four levels.
Regulatory Responsibility
Regulatory responsibility pertains to compliance with the ESPR or the applicable sector-specific regulation and product-specific requirements.
If the requirements are not met, market surveillance authorities may require corrective actions. Depending on the specific nonconformity, measures such as sales restrictions, product withdrawals, or recalls may be required.
In addition, Member States must provide for effective sanctions for violations.
Compensation for Damages Under Consumer Law Pursuant to the ESPR
In addition to regulatory measures, the ESPR also contains specific provisions regarding consumer protection.
If a consumer suffers damage because a product does not comply with the ecodesign requirements set forth in a delegated act, claims for damages may arise against the responsible economic operator under certain conditions.
Which specific person or company is liable depends, among other things, ontheir role in the supply chain and the specific circumstances of the case.Thus, DPP and ecodesign compliance is not solely a matter of regulatory oversight but can also have civil law consequences.
Contractual Liability and Recourse
Another area is contractual liability within the supply chain.
For example, if a supplier provides incorrect data on materials, origin, emissions, or substances, contractual claims for rectification, indemnification, or damages may arise.
Therefore, supplier contracts should clearly stipulate:
- what product data must be provided,
- what quality requirements apply,
- how often information must be updated,
- what documentation is required,
- who is responsible for incorrect or delayed information,
- and what the consequences of data errors are.
Such contracts can help distribute risks within the supply chain. However, they do not automatically alter the regulatory responsibility of the economic operator obligated under the relevant legal act.
Product Liability and Product Safety
Classic product liability must be distinguished from regulatory DPP responsibility.
A defective or incomplete Digital Product Passport does not automatically give rise to product liability. Under product liability law, however, incorrect or missing information may become relevant if it affects the safety of the product and contributes to the product’s defectiveness or to any resulting damage.
This can be relevant, for example, in the case of safety-related instructions for use, maintenance instructions, substance information, or other details relevant to safe use.
For products placed on the market or put into service after December 8, 2026, the new European Product Liability Directive will also become increasingly important.
However, the specific assessment of liability always depends on the individual case and is no substitute for legal advice.
Why Data Quality Is Becoming a Compliance and Liability Issue
The greatest risks often arise not from the QR code itself, but from the underlying source systems.
In many companies, product information is scattered across various systems, such as:
- ERP,
- PIM,
- PLM,
- MDM,
- DAM,
- document management systems,
- supplier portals,
- sustainability platforms,
- Excel files, or other specialized systems.
For each mandatory data field, the following should therefore be clearly defined:
- Which system is the authoritative source?
- Who provides the information?
- Who verifies the information?
- Who authorizes the release of the information?
- What evidence supports its accuracy?
- When must it be updated?
- How are changes documented?
- How can one trace which information was published at what time?
The more product information is consolidated from different systems, countries, and suppliers, the more important traceable processes and data responsibilities become.
A digital product passport is therefore not just a technology project.
DPP compliance is not solely an IT task
It is not enough for this to be solely the responsibility of IT.
Compliance and legal departments must ensure that regulatory requirements are met.
Business units and product management must ensure the accuracy of product information.
Purchasing and supplier management must require suppliers to provide the necessary data.
Sustainability managers can play a central role, particularly with regard to environmental, material, and circular economy data.
IT and data management must ensure controlled data flows, interfaces, access rights, and technical availability.
DPP compliance thus arises only through the interaction of multiple business units.
How Management Establishes Clear Lines of Responsibility
A robust governance model should include at least four key decisions.
1. Assign Products and Corporate Roles to Each Legal Act
Companies should first systematically examine:
- Which product groups are affected?
- Which legal act applies?
- What role does the company play?
- Manufacturer?
- Importer?
- Distributor?
- Retailer?
- Authorized representative?
- Private-label owner?
Companies operating internationally, in particular, may assume different roles for different products.
2. Appoint a DPP Owner with Technical Responsibility
A clearly defined role should be established for overall management.
The DPP Owner does not have to create all content themselves.
However, they should ensure that requirements, responsibilities, systems, and processes are aligned.
3. Define Data Responsibility and Approval Processes
For each relevant data field, the following should be specified:
- Who is responsible for the information?
- Who provides it?
- Who verifies it?
- Who approves it?
- Who is notified?
A RACI matrix can help map out responsibilities in a transparent and auditable manner.
While such a matrix is not explicitly required by the GDPR, it can be an effective governance tool.
4. Expand Supplier Contracts
Much of the information relevant to DPP originates outside the company.
Therefore, contracts with suppliers should include provisions addressing the following points, among others:
- Data quality,
- Timeliness,
- Notifications of changes,
- Obligations to provide evidence,
- Data formats,
- Inspection and audit rights,
- Responsibilities,
- Possible liability and indemnification provisions.
The sooner such requirements are integrated into procurement and supplier management, the lower the risk of subsequent
Don’t Forget Controls and Documentation
In addition to clear responsibilities, DPP compliance requires documented control processes.
These may include, for example:
- Completeness checks,
- Plausibility checks,
- Automatic data validation,
- Random sampling,
- Approval processes,
- version histories,
- change logs,
- escalation processes for incorrect data.
It is crucial that a company not only be able to state what information is contained in the product passport, but also be able to trace where it came from, who reviewed it, and when it was modified.
This transforms a technical DPP solution into a robust and auditable compliance process.
DPP Compliance for Batteries and Construction Products
Existing sector-specific regulations already demonstrate how varied these responsibilities can be.
For certain batteries, the battery passport will become mandatory as of February 18, 2027. The economic operator placing the battery on the market must ensure that the required information is accurate, complete, and up-to-date.
The new European Construction Products Regulation also includes its own system for digital product passports. The specific implementation will be outlined in further legal acts.
Both examples show that companies should not rely solely on the ESPR but should always check which sector-specific regulations apply to their own product portfolio.
DPP Compliance as a Management Task
The Digital Product Passport is not merely a data or IT project.
Legal responsibility cannot be fully outsourced to a software provider, platform operator, or supplier.
Companies should therefore clarify the following at an early stage:
- What legal role do we play for each product?
- Which DPP requirements are already in effect or are foreseeable?
- What information must be provided?
- From which systems does this information originate?
- Who bears technical responsibility?
- Who is authorized to release data?
- How are records and changes documented?
- How are suppliers integrated into the process?
It is not merely crucial that a Digital Product Passport exists technically. What is crucial is that the information it contains can be reliably managed, tracked, and updated.
asioso can help companies integrate regulatory requirements with product data, PIM, DAM, and MDM structures, as well as the necessary interfaces, to create a workable DPP architecture.
FAQ
1. Who is liable for incorrect information in the Digital Product Passport?
First and foremost, it depends on which economic operator is responsible for compliance with the requirements under the relevant legal act. Depending on the circumstances, regulatory measures, claims for damages, or contractual recourse claims may apply.
For example, if a supplier has provided incorrect data, additional contractual claims may exist against that supplier.
Specific liability always depends on the individual case.
2. Is the manufacturer always responsible for the DPP?
The manufacturer typically bears primary responsibility. However, importers, distributors, dealers, authorized representatives, or private-label owners may also have their own obligations.
Anyone who markets a product under their own brand or modifies it in a way that affects its conformity may also assume the manufacturer’s obligations themselves.
3. Can DPP responsibility be outsourced to a service provider?
Operational tasks can generally be delegated to service providers, such as the technical operation of a platform or the processing of certain data.
However, this does not generally relieve the economic operator responsible under the relevant legal act of its regulatory obligations.
4. Which department should oversee DPP compliance?
There is no uniformly prescribed organizational structure.
In practice, central management—for example, by the compliance department, product management, or a cross-functional DPP team—is a viable option.
It is important to ensure the mandatory involvement of procurement, IT, sustainability, product data management, and the relevant business units.
Bibliography
- Europäisches Parlament und Rat: Verordnung (EU) 2024/1781 zur Schaffung eines Rahmens für Ökodesign-Anforderungen für nachhaltige Produkte (ESPR), 13.06.2024, EUR-Lex.
- Europäische Kommission: Ecodesign for Sustainable Products Regulation, fortlaufend aktualisierte Themenseite.
- Europäisches Parlament und Rat: Verordnung (EU) 2023/1542 über Batterien und Altbatterien, insbesondere zu Wirtschaftsakteuren und Batteriepass, EUR-Lex.
- Europäisches Parlament und Rat: Verordnung (EU) 2024/3110 zur Festlegung harmonisierter Vorschriften für die Vermarktung von Bauprodukten, insbesondere zum digitalen Produktpasssystem für Bauprodukte, EUR-Lex.
- Europäisches Parlament und Rat: Richtlinie (EU) 2024/2853 über die Haftung für fehlerhafte Produkte, EUR-Lex.
- Europäisches Parlament und Rat: Verordnung (EU) 2023/988 über die allgemeine Produktsicherheit, EUR-Lex.
- Bundesanstalt für Materialforschung und -prüfung (BAM): ESPR und Digitaler Produktpass.
- asioso-Arbeitsgrundlage: Digitaler Produktpass einfach erklärt: Definition, Ziel, Rechtsgrundlage.
Note: This article is intended for general informational purposes only and does not constitute legal advice. The specific requirements and liability consequences that apply in a given case depend, in particular, on the product category in question, the relevant legislation, and the company’s role in the supply chain.
