Skip to main content

Digital Product Passport for Importers — EU Obligations for Non-EU Manufacturers

The Importer Problem Nobody Tells You About

If you import physical goods into the EU, you probably already know that product regulations apply to you. CE marking, chemical restrictions under REACH, waste handling obligations — none of this is new. What is different about the Digital Product Passport is how aggressively it shifts liability toward importers when the manufacturer falls short.

Under the Ecodesign for Sustainable Products Regulation, the default obligation to create, register and keep the passport accurate sits with the manufacturer (Article 27). Importers have a separate, independent obligation of their own: before placing a product on the EU market, Article 29 requires them to ensure that the manufacturer has carried out the conformity assessment and that a compliant digital product passport is available. Importers do not become the manufacturer merely because the manufacturer is outside the EU — that only happens in the specific situations set out in Article 34 (see below).

Being a verification duty rather than a creation duty does not make this a lesser obligation. You cannot point to a contract with your supplier that says they are responsible for the DPP and use that to defend a market surveillance action. The regulation does not care about your supplier contract. It cares whether the product entering the EU market has a compliant DPP when you place it there. Placing a product with a missing or non-compliant passport on the market is itself a breach you are directly responsible for, independent of what your contract with the supplier says.

The DPP requirements checklist is the place to start mapping what this means for your specific product categories. But this article focuses on what importers specifically must understand and act on.

When Importer Obligations Are Triggered

Two distinct sets of obligations exist, and it matters which one applies to you.

The verification duty applies to every importer, always. Under Article 29 of the ESPR, before placing a covered product on the EU market you must ensure that the manufacturer has carried out the conformity assessment and that a compliant digital product passport is available. If you have reason to believe the product is not in conformity, you must not place it on the market until it has been brought into conformity.

Full manufacturer-equivalent obligations apply only in the two situations set out in Article 34: when you place the product on the market under your own name or trademark, or when you modify a product already on the market in a way that affects its compliance. Outside those two situations, the manufacturer remains responsible for creating and maintaining the passport, even where that manufacturer is established outside the EU.

In practice, this means the compliance risk for most importers is not that they must build a passport the manufacturer failed to produce. It is that a shipment with a missing or non-compliant passport cannot legally be placed on the EU market at all. The importer must verify that the DPP is actually compliant — correct data fields, correct access levels, registry registration once that obligation applies, and a valid and scannable data carrier on the product. If you import a product with a QR code that links to a broken URL, you have a non-compliant DPP even if the underlying data is technically correct somewhere on a server, and the product should not be placed on the market.

The full DPP explainer describes what a compliant passport looks like structurally. For importers, the verification duty is not optional — it is part of your due diligence obligation before placing products on the EU market.

Verification Duties in Practice: What You Must Actually Check

Verification is not a legal formality. It requires substantive technical and commercial due diligence. Here is what that looks like in practice.

Before committing to a supplier: Establish whether the supplier can produce a DPP that meets the applicable delegated regulation for your product category. Not a general DPP — the specific one required for textiles, or electronics, or batteries, or whichever category applies. Ask for a sample passport for an existing product line. Query it. Check that the data carrier resolves to a live, structured data endpoint. Verify the registration in the EU registry once it is operational.

Before customs clearance: Each shipment arriving at an EU border should be verifiable against the DPP registry. Once the registry is live and your product category has a compliance deadline, customs authorities will be doing this check themselves. You want to catch non-compliant shipments before they do. This means having a process — not just a contract clause, but an actual operational process — for verifying DPP compliance on incoming goods.

On an ongoing basis: Passports must be kept up to date. A textile product's DPP that was accurate at the time of import may need updating if the recycled content percentage changes in subsequent production runs, or if a substance previously absent from the SVHC list gets listed. Your supplier contract should specify who is responsible for updates, but your operational process should include periodic verification that the passport data remains current and accurate.

This is not trivial to operationalise. The guide to creating a digital product passport covers the technical infrastructure needed. For importers managing large, diverse product portfolios, the answer is almost certainly a platform rather than a manual process — see the platform features if you are assessing options.

Authorised Representative Requirements

A non-EU manufacturer can appoint an authorised representative (AR) established in the EU by written mandate. The AR takes on a defined scope of tasks and becomes a point of contact for market surveillance authorities within the EU.

But the AR arrangement has limits that importers need to understand. An AR takes responsibility for the specific tasks set out in the mandate — holding documentation, being the contact point for authorities, cooperating on corrective action. Under the ESPR, the manufacturer's core obligation to ensure a digital product passport is available cannot form part of the AR's mandate (Article 28(1) excludes it explicitly) — passport creation itself stays with the manufacturer even where an AR is appointed. The AR cannot be held responsible for physical product defects or for data that the manufacturer controls and has not shared.

This creates a potential gap: if the manufacturer's underlying data is inaccurate, any digital product passport built on that data is inaccurate too — regardless of whether an AR is in place, since the AR's mandate does not extend to correcting or validating the manufacturer's data. Under the ESPR framework's economic operator chain, each actor who places a non-compliant product on the market can be held accountable. Including you, if you place that product on the market without having verified its passport.

The practical upshot: even when a non-EU manufacturer has an authorised representative, importers retain a verification duty. You cannot contract your way out of market surveillance liability.

Product Categories Most Affecting Importers Right Now

Not every product category has a DPP compliance deadline yet. The ESPR works through delegated regulations, and the rollout is phased. For importers, the priority categories are:

Batteries. The EU Battery Regulation is already in force and contains the most advanced DPP requirements. Industrial batteries above 2 kWh, EV batteries and LMT batteries all face passport requirements from 18 February 2027 under the Battery Regulation. If you import batteries into the EU in any form — finished products, components, replacement units — this is your most immediate DPP obligation. The battery passport guide goes deep on this specific category.

Textiles and apparel. The Commission's work plan pencils in 2027 as the indicative year for adopting the textile delegated act — not a compliance deadline. Once adopted, Article 4(4) of the ESPR sets a floor of at least 18 months before the act can apply, except in duly justified cases; no fixed compliance year exists yet. Given the EU's heavy dependence on textile imports from Asia and the complexity of proving fibre-level material composition through a DPP, this is where importer obligations will eventually create the most operational disruption once the act is adopted. Start preparing now.

Electronics and ICT products. The Commission's ESPR work plan does not include a dedicated electronics delegated act with a DPP line of its own. ICT products are covered only through two horizontal measures — reparability (indicative adoption 2027) and recyclability of electrical and electronic equipment (indicative adoption 2029) — plus a separate mobile phones and tablets measure under the existing energy-labelling framework (indicative adoption end 2030). Many of these products are manufactured entirely outside the EU, so once requirements do apply the importer verification duty will affect a large share of this category — but there is no confirmed DPP obligation or deadline for electronics as a whole yet.

Furniture. Less discussed, but significant. EU furniture imports are substantial, and the DPP requirements for furniture will include material sourcing documentation that many current supply chains are not equipped to provide.

For each of these categories, the ESPR regulation overview tracks the current status of delegated acts and expected compliance timelines.

What Market Surveillance Looks Like for Importers

Market surveillance is the enforcement mechanism. Understanding how it works for DPP non-compliance is not a theoretical concern — it is a risk management input.

Customs authorities at EU external borders will, once DPP requirements are in force for a product category, verify DPP compliance as part of the import procedure. This verification involves scanning the product's data carrier, resolving the registry lookup, and checking that the public-tier data fields required by the applicable delegated regulation are present and correctly formatted. Products that fail this check can be detained at the border pending further investigation.

Inland market surveillance — meaning inspections by national market surveillance authorities after a product is already in circulation — will use the same DPP registry lookup, plus they can exercise Tier Three access rights to inspect the full passport including restricted data. If they find discrepancies between the public-tier data and the Tier Three data, or between the passport data and physical product testing results, that is prima facie evidence of non-compliance.

Under the ESPR framework, national market surveillance actions are recorded in the EU's ICSMS market surveillance system, where other Member States can see them. A non-compliance finding in one Member State can therefore trigger inspections in others and feed into the Commission's monitoring of sectoral compliance rates.

The financial exposure from a detention, withdrawal order or penalty under Member State implementing legislation can far exceed the cost of proper DPP compliance implementation. Work through the DPP compliance checklist and the implementation options with that risk in mind.

Building Supplier Contracts for DPP Compliance

Even though contracts do not protect you from market surveillance liability, they are still essential for risk allocation and for ensuring your suppliers actually deliver what you need.

A DPP-ready supplier contract should include:

  • A warranty that the product will have a compliant DPP when shipped to the EU
  • Specifications defining what "compliant" means by reference to the applicable delegated regulation
  • An obligation on the supplier to maintain and update the passport data for the product's commercial lifetime
  • Access rights for you (the importer) to audit the passport data before and after shipment
  • Indemnification provisions allocating costs of market surveillance actions where the non-compliance arose from the supplier's data
  • Termination rights if the supplier repeatedly fails to provide compliant DPPs

Some importers are building DPP data collection clauses into their RFQ (Request for Quotation) processes, so that supplier qualification now includes DPP capability assessment. This is particularly important for batteries, whose passport deadline is 18 February 2027 — you do not have time to discover non-compliant suppliers after the compliance date.

Frequently Asked Questions

Dpp For Importers
If my non-EU supplier creates a DPP, do I still have obligations as an importer?
Yes. Even if your supplier creates a DPP, you retain a verification duty as the importer. You must check that the passport is genuinely compliant — correct data fields, valid registration, working data carrier — before placing the product on the EU market. You cannot rely solely on your supplier's assurance without verification.
What is an authorised representative and does having one remove my DPP obligations?
An authorised representative (AR) is an EU-established entity a non-EU manufacturer can appoint by written mandate to handle specific compliance tasks — holding documentation, acting as the contact point for authorities. Under the ESPR, the AR's mandate cannot include the manufacturer's core obligation to ensure a digital product passport is available; that stays with the manufacturer. Importers must still verify, before placing the product on the market, that a compliant passport exists, regardless of whether an AR has been appointed.
Which product categories have the most urgent DPP obligations for importers?
Batteries are the most urgent, with Battery Regulation passport requirements applying from 18 February 2027. Textiles and electronics will follow only after their delegated acts are adopted and their transition periods expire. Importers in these categories should begin supplier engagement and internal systems preparation immediately.
Can customs authorities reject a shipment because of a non-compliant DPP?
Yes. Once DPP requirements are in force for a product category, customs authorities at EU external borders are empowered to verify DPP compliance as part of the import procedure. Products without a compliant DPP — including products with a DPP that links to a broken URL — can be detained at the border.
How long must a DPP remain accessible after a product is placed on the market?
Under the ESPR framework, the DPP must remain accessible for the entire expected lifetime of the product plus a period specified in the applicable delegated regulation — for a period that each delegated regulation will define after the last unit of a product model is placed on the market. Importers responsible for the DPP must ensure this long-term availability.

Ready to Get Started?

Create your first Digital Product Passport today.

Try DPP-Tool Free