[{"data":1,"prerenderedAt":1165},["ShallowReactive",2],{"content-dpp-when-the-server-goes-down":3,"related-dpp-when-the-server-goes-down":207},{"id":4,"title":5,"author":6,"body":7,"category":189,"date":190,"description":191,"draft":192,"extension":193,"locale":194,"meta":195,"navigation":196,"path":197,"readingTime":198,"seo":199,"stem":200,"tags":201,"thumbnail":182,"__hash__":206},"articles\u002Farticles\u002Fdpp-when-the-server-goes-down.md","DPP When the Server Goes Down: Hosting Obligations Under ESPR","PassportLab Team",{"type":8,"value":9,"toc":181},"minimark",[10,19,22,27,30,46,49,53,56,59,86,90,93,116,119,123,126,158,161,164],[11,12,13,14,18],"p",{},"There is a clause buried in ESPR Article 9(2)(i) that most importers and brands have not fully processed yet: the obligation to guarantee DPP data availability for ",[15,16,17],"strong",{},"10 years"," after a product model is discontinued.",[11,20,21],{},"This is not a soft requirement. It is a hard legal obligation on the economic operator who places the product on the EU market. If the DPP endpoint returns a 404 five years from now — because your SaaS provider was acquired, pivoted, or went bankrupt — you are in breach. Not your provider. You.",[23,24,26],"h2",{"id":25},"what-availability-actually-means","What \"Availability\" Actually Means",[11,28,29],{},"The ESPR delegated acts are explicit about what availability means in practice. It means:",[31,32,33,37,40,43],"ul",{},[34,35,36],"li",{},"The DPP URL must resolve and return the required data fields",[34,38,39],{},"The GS1 Digital Link resolver must point to a live endpoint",[34,41,42],{},"The EU Common Information Repository record must be active and current",[34,44,45],{},"The cryptographic credential (W3C VC 2.0) must be verifiable against the issuer's DID document",[11,47,48],{},"All four of these require active infrastructure. QR codes printed on physical products five years ago must still work. This is a fundamentally different obligation than keeping a PDF in a file drawer.",[23,50,52],{"id":51},"the-saas-vendor-risk-nobody-talks-about","The SaaS Vendor Risk Nobody Talks About",[11,54,55],{},"When you choose a DPP platform, you are not just choosing software. You are delegating a 10-year hosting obligation to a third party. That third party has its own venture capital timeline, its own acquisition risk, and its own infrastructure decisions.",[11,57,58],{},"The risk questions to ask any DPP vendor:",[60,61,62,68,74,80],"ol",{},[34,63,64,67],{},[15,65,66],{},"Where is the data hosted?"," EU-based servers are required for many product categories under GDPR and emerging ESPR data residency guidance. \"EU region\" on a US cloud provider is different from EU-controlled infrastructure.",[34,69,70,73],{},[15,71,72],{},"What is the data export policy?"," Can you export your full DPP dataset in machine-readable form at any time, without losing the cryptographic signatures? Or does export break the chain of custody?",[34,75,76,79],{},[15,77,78],{},"What happens to your DPPs if you cancel the contract?"," A 30-day notice period is not compatible with a 10-year hosting obligation. You need contractual continuity provisions.",[34,81,82,85],{},[15,83,84],{},"Is there a backup URL?"," CIRPASS-2 interoperability guidance recommends registering a backup resolution URL for every DPP. If your primary provider is unreachable, the backup must serve the same data.",[23,87,89],{"id":88},"the-espr-data-retention-model-in-practice","The ESPR Data Retention Model in Practice",[11,91,92],{},"PassportLab implements the 10-year retention model by:",[31,94,95,103,110,113],{},[34,96,97,98,102],{},"Recording the ",[99,100,101],"code",{},"discontinuation_date"," at the product model level",[34,104,105,106,109],{},"Auto-computing ",[99,107,108],{},"retention_expires_at"," as discontinuation date + 10 years",[34,111,112],{},"Flagging products for archival review when they approach expiry, rather than silently removing them",[34,114,115],{},"Supporting backup URL registration in the CIRPASS-2 registry format so a secondary endpoint can serve data if the primary is unavailable",[11,117,118],{},"The backup URL field is not optional infrastructure — it is the difference between a compliant DPP lifecycle and an undiscoverable compliance gap five years from now.",[23,120,122],{"id":121},"what-you-should-require-in-your-dpp-contract","What You Should Require in Your DPP Contract",[11,124,125],{},"Minimum contractual protections for a 10-year hosting obligation:",[31,127,128,134,140,146,152],{},[34,129,130,133],{},[15,131,132],{},"Data portability clause:"," full export within 30 days of request, in ESPR-compliant JSON format with verifiable credentials intact",[34,135,136,139],{},[15,137,138],{},"EU data residency clause:"," explicit commitment to EU-based infrastructure for the full retention period",[34,141,142,145],{},[15,143,144],{},"Continuity clause:"," obligation to give 180 days notice before service termination, with a defined migration path",[34,147,148,151],{},[15,149,150],{},"Backup endpoint clause:"," platform provides a CIRPASS-2-compatible backup URL for each DPP",[34,153,154,157],{},[15,155,156],{},"SLA with teeth:"," uptime guarantee of at least 99.9% with financial remedy for breaches",[11,159,160],{},"If your current DPP provider cannot meet these terms, that is useful information to have before the 2027 deadline, not after.",[162,163],"hr",{},[11,165,166],{},[167,168,169,170,175,176,180],"em",{},"PassportLab is EU-hosted (Elsdorf, Germany) with contractual data portability and CIRPASS-2 backup URL support built in. ",[171,172,174],"a",{"href":173},"\u002Fhow-it-works","See how it works"," or ",[171,177,179],{"href":178},"\u002Fdemo","book a call"," to discuss your specific hosting requirements.",{"title":182,"searchDepth":183,"depth":183,"links":184},"",2,[185,186,187,188],{"id":25,"depth":183,"text":26},{"id":51,"depth":183,"text":52},{"id":88,"depth":183,"text":89},{"id":121,"depth":183,"text":122},"Technical","2025-10-02","ESPR Article 9(2)(i) requires DPP data to remain accessible for 10 years after a product model is discontinued. What happens when your DPP provider shuts down or gets acquired?",false,"md","en",{},true,"\u002Farticles\u002Fdpp-when-the-server-goes-down",8,{"title":5,"description":191},"articles\u002Fdpp-when-the-server-goes-down",[202,203,204,205],"ESPR","Data Hosting","Reliability","EU Compliance","1swcEviH5AErJ3KlCIvakAkk3oct0oscwCUk6rel_tU",[208,384,584],{"id":209,"title":210,"author":6,"body":211,"category":189,"date":372,"description":373,"draft":192,"extension":193,"locale":194,"meta":374,"navigation":196,"path":375,"readingTime":376,"seo":377,"stem":378,"tags":379,"thumbnail":182,"__hash__":383},"articles\u002Farticles\u002Fdeath-of-the-static-pdf.md","Death of the Static PDF: Why DPPs Cannot Be Documents",{"type":8,"value":212,"toc":365},[213,216,219,223,226,237,240,244,247,250,254,257,281,284,288,291,301,307,313,319,325,329,332,346,349,351],[11,214,215],{},"A significant fraction of the \"DPP solutions\" being marketed to brands in 2025 are, at their core, PDF generators with a QR code on top. The QR code links to a hosted PDF. The PDF contains the product data. Someone, somewhere, reads the PDF and decides whether the product is compliant.",[11,217,218],{},"This approach fails at every layer of the ESPR technical specification. Here is why, and what a DPP actually needs to be.",[23,220,222],{"id":221},"the-pdf-cannot-be-verified","The PDF Cannot Be Verified",[11,224,225],{},"ESPR requires that DPP data be cryptographically verifiable. Specifically, the data must carry a verifiable credential (W3C Verifiable Credentials 2.0) signed by the economic operator using a key registered under their legal entity identity. A customs officer or market surveillance authority must be able to verify that:",[60,227,228,231,234],{},[34,229,230],{},"The data was issued by the organisation claiming to issue it",[34,232,233],{},"The data has not been modified since issuance",[34,235,236],{},"The issuing organisation is the legitimate economic operator for this product",[11,238,239],{},"A PDF cannot carry a W3C VC. A PDF cannot be verified by an automated system. A PDF requires a human to read it, which does not scale to the volume of products crossing EU borders.",[23,241,243],{"id":242},"the-pdf-cannot-be-queried","The PDF Cannot Be Queried",[11,245,246],{},"EU customs pre-filing systems, market surveillance tools, and retail compliance platforms all query DPP data programmatically. They call a REST endpoint, receive JSON, and check specific fields against required values. A PDF has no queryable API. It cannot be integrated into import declaration systems. It cannot be cross-referenced with the EU Common Information Repository.",[11,248,249],{},"The ESPR technical specification requires that the DPP endpoint return machine-readable JSON. The GS1 Digital Link standard specifies how the URL should be structured. The CIRPASS-2 interoperability format specifies what the JSON must contain. None of these requirements can be satisfied by a PDF.",[23,251,253],{"id":252},"the-pdf-is-static-dpps-must-be-dynamic","The PDF Is Static — DPPs Must Be Dynamic",[11,255,256],{},"A DPP is not a point-in-time document. It is a living record. Under ESPR, the DPP must be updated when:",[31,258,259,266,272,275,278],{},[34,260,261,262,265],{},"The product is repaired or remanufactured (status changes to ",[99,263,264],{},"remanufactured",")",[34,267,268,269,265],{},"The product is destroyed (status changes to ",[99,270,271],{},"destroyed",[34,273,274],{},"The product model is discontinued (triggers 10-year retention clock)",[34,276,277],{},"Recycled content percentages change due to supply chain adjustments",[34,279,280],{},"A conformity certificate is renewed or revoked",[11,282,283],{},"None of these updates can be reflected in a static PDF without reissuing the entire document and invalidating all the existing QR codes in the field. A DPP must be a live data record with a stable URL that always returns current data — not a document frozen at issuance time.",[23,285,287],{"id":286},"what-a-compliant-dpp-actually-needs","What a Compliant DPP Actually Needs",[11,289,290],{},"A compliant DPP requires:",[11,292,293,296,297,300],{},[15,294,295],{},"A stable, resolvable URL"," — the GS1 Digital Link format ",[99,298,299],{},"\u002F01\u002F{gtin}\u002F21\u002F{serial}"," is the preferred form. The URL must resolve for the lifetime of the product plus 10 years after discontinuation.",[11,302,303,306],{},[15,304,305],{},"Machine-readable JSON at that URL"," — conforming to the ESPR delegated act schema for the product category. For batteries, this means Annex XIII fields. For textiles, the relevant delegated act fields.",[11,308,309,312],{},[15,310,311],{},"A W3C Verifiable Credential"," — signed by the economic operator's DID (Decentralised Identifier), using Ed25519 or similar algorithm. The credential must be verifiable against the issuer's published DID document.",[11,314,315,318],{},[15,316,317],{},"EU CIR registration"," — the product's unique identifier must be registered in the EU Common Information Repository so discovery tools can find the authoritative data endpoint.",[11,320,321,324],{},[15,322,323],{},"Selective Disclosure capability"," — some fields in the DPP are public (basic product data), others are restricted (B2B supply chain data visible only to authorised parties). SD-JWT format allows field-level access control without invalidating the credential.",[23,326,328],{"id":327},"the-time-to-switch-is-before-enforcement","The Time to Switch Is Before Enforcement",[11,330,331],{},"If your current DPP solution produces PDFs, the time to replace it is before the 2027 battery DPP deadline, not after. Migration from a PDF-based approach requires:",[60,333,334,337,340,343],{},[34,335,336],{},"Re-creating all DPP records in a compliant JSON format",[34,338,339],{},"Re-issuing cryptographic credentials for all products",[34,341,342],{},"Re-registering all products with the EU CIR",[34,344,345],{},"Re-distributing QR codes that resolve to the new endpoints (or setting up redirect infrastructure from old QR codes)",[11,347,348],{},"This is significant operational work. It is much less significant if done proactively than if triggered by a customs rejection at the border.",[162,350],{},[11,352,353],{},[167,354,355,356,175,360,364],{},"PassportLab generates cryptographically signed, W3C VC 2.0 compliant DPPs with GS1 Digital Link resolution and EU CIR registration. ",[171,357,359],{"href":358},"\u002Fdevelopers","See the technical details",[171,361,363],{"href":362},"\u002Ffree-dpp-generator","generate a compliant DPP now",".",{"title":182,"searchDepth":183,"depth":183,"links":366},[367,368,369,370,371],{"id":221,"depth":183,"text":222},{"id":242,"depth":183,"text":243},{"id":252,"depth":183,"text":253},{"id":286,"depth":183,"text":287},{"id":327,"depth":183,"text":328},"2025-12-01","Many brands are treating their Digital Product Passport as a sophisticated PDF. This approach is not just incomplete — it is fundamentally incompatible with how DPP verification actually works.",{},"\u002Farticles\u002Fdeath-of-the-static-pdf",6,{"title":210,"description":373},"articles\u002Fdeath-of-the-static-pdf",[380,189,381,382],"DPP","W3C VC","Cryptographic Signing","iy0aTTLKkEyWlIyKnz2pbRxlAg7Er7kVwwXadmw2TKw",{"id":385,"title":386,"author":6,"body":387,"category":572,"date":573,"description":574,"draft":192,"extension":193,"locale":194,"meta":575,"navigation":196,"path":576,"readingTime":577,"seo":578,"stem":579,"tags":580,"thumbnail":182,"__hash__":583},"articles\u002Farticles\u002Fdigital-product-passport-decoded-2026.md","Digital Product Passport Decoded: The 2026 Practical Guide for Importers",{"type":8,"value":388,"toc":565},[389,392,396,399,402,405,409,412,421,427,433,439,445,449,455,461,467,473,477,480,506,509,513,516,548,551,553],[11,390,391],{},"The phrase \"Digital Product Passport\" appears in enough regulatory communications that most importers and brand managers have heard of it. Fewer have a concrete understanding of what it actually is, what it must contain, and what happens when an authority checks it at the border. This guide is the practical version.",[23,393,395],{"id":394},"what-a-dpp-is-and-is-not","What a DPP Is (and Is Not)",[11,397,398],{},"A Digital Product Passport is a structured data record attached to a physical product, accessible via a URL encoded in a QR code, barcode, or RFID tag on the product. It is not a document. It is not a certificate. It is not a PDF. It is a live API endpoint that returns machine-readable JSON.",[11,400,401],{},"When a customs officer, market surveillance authority, retailer, or consumer scans the QR code on your product, their device makes an HTTP request to a URL. That URL returns JSON data. The data is verified cryptographically. The result is either a valid, compliant DPP — or it is not.",[11,403,404],{},"The EU Ecodesign for Sustainable Products Regulation (ESPR) mandates DPPs for all product categories covered by ESPR delegated acts. The first mandates affect batteries (February 2027) and will extend to textiles, electronics, iron and steel, and other categories on a rolling schedule through 2030 and beyond.",[23,406,408],{"id":407},"the-anatomy-of-a-compliant-dpp","The Anatomy of a Compliant DPP",[11,410,411],{},"A compliant DPP has five layers:",[11,413,414,417,418,420],{},[15,415,416],{},"Layer 1: The unique identifier."," Every DPP has a unique identifier — either a GS1 GTIN\u002Fserial combination formatted as a Digital Link URL (",[99,419,299],{},") or a UUID-based identifier. The identifier is encoded in the physical label (QR code, RFID tag) and registered in the EU Common Information Repository.",[11,422,423,426],{},[15,424,425],{},"Layer 2: The data record."," The product's required fields as specified in the ESPR delegated act for its category. For batteries: carbon footprint per kWh of energy stored, recycled content by battery material, state of health, responsible sourcing documentation. For textiles: fibre composition, country of origin per manufacturing stage, care and repair instructions, recycled content. The delegated act for each category specifies exactly which fields are mandatory.",[11,428,429,432],{},[15,430,431],{},"Layer 3: The verifiable credential."," The data record is wrapped in a W3C Verifiable Credential (VC 2.0), signed by the economic operator's cryptographic key. The key is associated with the operator's legal entity identity via a DID (Decentralised Identifier). Any party can verify the credential without contacting the issuer, by resolving the DID and checking the signature.",[11,434,435,438],{},[15,436,437],{},"Layer 4: The selective disclosure layer."," Some DPP fields are public (accessible to anyone who scans the QR code). Others are restricted — visible to customs authorities but not consumers, or visible to recycling operators but not retailers. Selective Disclosure JWT (SD-JWT) format allows field-level access control without invalidating the credential.",[11,440,441,444],{},[15,442,443],{},"Layer 5: The registry registration."," The DPP identifier and the URL of the data endpoint are registered in the EU Common Information Repository. When an authority scans a product, they can look up the CIR to find the authoritative endpoint, even if the QR code resolves to a different URL.",[23,446,448],{"id":447},"who-checks-your-dpp-and-how","Who Checks Your DPP and How",[11,450,451,454],{},[15,452,453],{},"EU Customs:"," Import declarations for products covered by ESPR mandates will soon include a DPP identifier field. Customs systems will resolve the DPP at the time of import and check required fields against the declared product category. A DPP that is missing required fields, returns an error, or fails cryptographic verification will trigger a hold.",[11,456,457,460],{},[15,458,459],{},"Market Surveillance Authorities (MSAs):"," MSAs in each EU member state conduct post-market checks on products in circulation. They scan QR codes, resolve DPPs, and check compliance with the delegated act for the product category. MSA findings are shared via the ICSMS (Information and Communication System for Market Surveillance) and can result in product recalls, import bans, and financial penalties.",[11,462,463,466],{},[15,464,465],{},"Retailers:"," Large EU retailers are increasingly requiring DPP compliance as a condition of listing. This is a commercial requirement, not a regulatory one, but it has the same practical effect. Retailers running their own compliance checks resolve DPPs programmatically and reject listings where required fields are missing.",[11,468,469,472],{},[15,470,471],{},"Consumers:"," The public-facing layer of the DPP — product composition, care instructions, repairability information, end-of-life guidance — must be accessible to consumers. EU citizens have the right to request DPP data under ESPR. The QR code must resolve to a human-readable display, not just a machine-readable JSON endpoint.",[23,474,476],{"id":475},"what-happens-when-your-dpp-is-wrong","What Happens When Your DPP Is Wrong",[11,478,479],{},"Non-compliance with ESPR DPP requirements can result in:",[31,481,482,488,494,500],{},[34,483,484,487],{},[15,485,486],{},"Import rejection at customs"," — shipments held pending compliance remediation",[34,489,490,493],{},[15,491,492],{},"Market surveillance enforcement action"," — withdrawal from sale, recall obligation, financial penalties",[34,495,496,499],{},[15,497,498],{},"Retailer delisting"," — commercial consequence from buyers requiring DPP compliance",[34,501,502,505],{},[15,503,504],{},"Registry flagging"," — an invalid DPP in the EU CIR creates a permanent compliance record",[11,507,508],{},"The penalties under ESPR are set by member states but must be \"effective, proportionate, and dissuasive.\" France, Germany, and the Netherlands have indicated penalty frameworks of €10,000–€50,000 per non-compliant product category, per enforcement action.",[23,510,512],{"id":511},"getting-your-first-compliant-dpp","Getting Your First Compliant DPP",[11,514,515],{},"The fastest path to a compliant DPP for most importers:",[60,517,518,524,530,536,542],{},[34,519,520,523],{},[15,521,522],{},"Identify your first product category"," — which of your products will be subject to the earliest ESPR mandate? Batteries first, then textiles.",[34,525,526,529],{},[15,527,528],{},"Collect the required fields"," — use the relevant delegated act field list (or PassportLab's category templates) to identify what supplier data you need.",[34,531,532,535],{},[15,533,534],{},"Generate and sign the DPP"," — a compliant DPP platform creates the W3C VC, registers with the EU CIR, and generates the QR code automatically.",[34,537,538,541],{},[15,539,540],{},"Test the QR code"," — scan it with a DPP verification tool to confirm the endpoint resolves, the data is complete, and the credential verifies.",[34,543,544,547],{},[15,545,546],{},"Distribute to your supply chain"," — update your product labels with the QR code or RFID tag encoding the DPP URL.",[11,549,550],{},"The process does not require a technical team. It requires supplier data and a platform that handles the technical compliance layers.",[162,552],{},[11,554,555],{},[167,556,557,560,561,564],{},[171,558,559],{"href":362},"Generate a compliant DPP for your product now"," — no technical knowledge required. Or ",[171,562,563],{"href":178},"book a compliance walkthrough"," with the PassportLab team.",{"title":182,"searchDepth":183,"depth":183,"links":566},[567,568,569,570,571],{"id":394,"depth":183,"text":395},{"id":407,"depth":183,"text":408},{"id":447,"depth":183,"text":448},{"id":475,"depth":183,"text":476},{"id":511,"depth":183,"text":512},"Guide","2026-03-01","What a Digital Product Passport actually is, what data it must contain, who checks it, how it gets verified, and what happens if yours is wrong. Written for importers and private-label brands.",{},"\u002Farticles\u002Fdigital-product-passport-decoded-2026",12,{"title":386,"description":574},"articles\u002Fdigital-product-passport-decoded-2026",[380,202,572,581,582],"Importers","2026","3eHIAXwnmYeZbgKO-H5s-IbyDiDasit8rP4srupvFms",{"id":585,"title":586,"author":6,"body":587,"category":572,"date":1154,"description":1155,"draft":192,"extension":193,"locale":194,"meta":1156,"navigation":196,"path":1157,"readingTime":1158,"seo":1159,"stem":1160,"tags":1161,"thumbnail":182,"__hash__":1164},"articles\u002Farticles\u002Fdpp-software-comparison.md","DPP Software Comparison 2026: PassportLab vs. Enterprise Platforms",{"type":8,"value":588,"toc":1142},[589,592,598,604,607,611,616,622,628,634,640,653,657,662,667,673,678,688,692,697,702,707,712,722,726,731,736,742,747,757,761,766,770,799,805,810,814,1092,1096,1102,1108,1114,1120,1126,1129,1131],[11,590,591],{},"The Digital Product Passport software market has fragmented into two tiers that serve fundamentally different buyers. Understanding which tier you belong to saves months of evaluation time and significant budget.",[11,593,594,597],{},[15,595,596],{},"Tier 1:"," Enterprise platforms built for Fortune 500 manufacturers with large technical teams, multi-year implementation timelines, and integration budgets in six figures. Built around supply chain data platforms, digital twin frameworks, or identity infrastructure.",[11,599,600,603],{},[15,601,602],{},"Tier 2:"," Platforms built for importers, private-label brands, and SMEs that need to be compliant without a dedicated compliance engineering team. Built around fast setup, self-service data entry, and practical regulatory output.",[11,605,606],{},"PassportLab is explicitly in Tier 2. This comparison is written to help buyers in Tier 2 understand the landscape honestly.",[23,608,610],{"id":609},"the-platforms","The Platforms",[612,613,615],"h3",{"id":614},"spherity","Spherity",[11,617,618,621],{},[15,619,620],{},"What it is:"," Spherity is a German decentralised identity and verifiable credentials infrastructure company. Their DPP product is built on top of their existing identity stack, with a focus on cryptographic credential management and W3C VC issuance at scale.",[11,623,624,627],{},[15,625,626],{},"Strengths:"," Deep technical standards compliance. W3C VC 2.0 implementation is robust. Strong in battery supply chain use cases where buyers require cryptographic proof of origin. Direct relationships with major German automotive OEMs.",[11,629,630,633],{},[15,631,632],{},"Limitations for SMEs:"," Implementation is primarily professional-services-led. There is no self-service onboarding path for a brand with 50 SKUs. Pricing is enterprise-contracted. Setup timelines are measured in months, not days. If you do not have a development team and an existing identity infrastructure, Spherity is not the right tool.",[11,635,636,639],{},[15,637,638],{},"Standards:"," W3C VC 2.0, DID:Web, eIDAS 2.0. Not currently GS1 Digital Link native.",[11,641,642,645,646,652],{},[15,643,644],{},"Sources:"," ",[171,647,651],{"href":648,"rel":649},"https:\u002F\u002Fspherity.com",[650],"nofollow","spherity.com",", EU Blockchain Observatory reports on digital identity for supply chains.",[612,654,656],{"id":655},"qliktag","Qliktag",[11,658,659,661],{},[15,660,620],{}," Qliktag is a product experience and DPP platform based in Canada, with significant EU market presence through retail partnerships. Their strength is consumer-facing product experience content — the \"digital twin\" of a product from a brand storytelling perspective as well as compliance.",[11,663,664,666],{},[15,665,626],{}," Strong content management capabilities. Good for brands that want to use the DPP as a consumer engagement tool as well as a compliance tool. Retail partnership network for distribution.",[11,668,669,672],{},[15,670,671],{},"Limitations for compliance-first use cases:"," Qliktag's primary positioning is consumer experience rather than regulatory compliance. W3C VC cryptographic signing and EU CIR registration are not core features. For brands that need to pass a market surveillance audit in 2027, the compliance layer is less mature than purpose-built compliance platforms.",[11,674,675,677],{},[15,676,638],{}," GS1 Digital Link supported. W3C VC integration limited. EU CIR registration not confirmed.",[11,679,680,645,682,687],{},[15,681,644],{},[171,683,686],{"href":684,"rel":685},"https:\u002F\u002Fqliktag.com",[650],"qliktag.com",", GS1 DPP Pilot documentation.",[612,689,691],{"id":690},"psqr","PSQR",[11,693,694,696],{},[15,695,620],{}," PSQR is a Netherlands-based platform focused on supply chain transparency and GS1-compatible product data. They have deep GS1 relationships and are active in EU DPP standardisation bodies.",[11,698,699,701],{},[15,700,626],{}," GS1 compliance is very strong. Good for brands already operating in GS1-centric supply chains (major EU retailers). Active in policy and standards — PSQR's work shows up in ESPR technical specifications.",[11,703,704,706],{},[15,705,632],{}," Similar to Spherity, PSQR is primarily enterprise-oriented. The platform is built for supply chain data integration at scale, not self-service DPP creation. SMEs without EDI or GS1 DataKEEP integration will find onboarding complex.",[11,708,709,711],{},[15,710,638],{}," GS1 Digital Link native. W3C VC in development. EU CIR registration supported.",[11,713,714,645,716,721],{},[15,715,644],{},[171,717,720],{"href":718,"rel":719},"https:\u002F\u002Fpsqr.eu",[650],"psqr.eu",", GS1 AISBL Digital Link standard documentation.",[612,723,725],{"id":724},"avery-dennison-atmaio","Avery Dennison atma.io",[11,727,728,730],{},[15,729,620],{}," atma.io is the digital identity platform from Avery Dennison, the label and RFID tag manufacturer. Their DPP offering is built on top of their existing RFID infrastructure and cloud-based product identity platform.",[11,732,733,735],{},[15,734,626],{}," For brands already using Avery Dennison RFID tags (common in fashion and luxury goods), the integration path to a unit-level DPP is relatively straightforward. Physical-to-digital connection is a core strength. Strong in textile and luxury goods sectors.",[11,737,738,741],{},[15,739,740],{},"Limitations for non-Avery Dennison supply chains:"," The platform is most valuable when you are already buying physical labels and tags from Avery Dennison. If you are not, the value proposition weakens. DPP compliance features (W3C VC, EU CIR) are available but not as mature as pure-play compliance platforms. Pricing is tied to label volume, which can make it expensive for low-volume high-value products.",[11,743,744,746],{},[15,745,638],{}," RAIN RFID native. GS1 Digital Link supported. W3C VC available. EU CIR integration in progress.",[11,748,749,645,751,756],{},[15,750,644],{},[171,752,755],{"href":753,"rel":754},"https:\u002F\u002Fwww.averydennison.com\u002Fen\u002Fhome\u002Fproducts-and-solutions\u002Fatma.io.html",[650],"atma.io",", Avery Dennison sustainability reports.",[612,758,760],{"id":759},"passportlab","PassportLab",[11,762,763,765],{},[15,764,620],{}," PassportLab is a purpose-built EU DPP compliance platform for importers and private-label brands. Self-service, EU-hosted (Germany), GS1 Germany partner.",[11,767,768],{},[15,769,626],{},[31,771,772,775,778,781,784,787,790,793,796],{},[34,773,774],{},"Self-service setup in under 30 minutes for first DPP",[34,776,777],{},"Full W3C VC 2.0 + Ed25519 cryptographic signing",[34,779,780],{},"GS1 Digital Link resolution (GS1 Germany partnership)",[34,782,783],{},"EU CIR registration via CIRPASS-2 format",[34,785,786],{},"SD-JWT selective disclosure for stakeholder access control",[34,788,789],{},"Shopify and WooCommerce sync",[34,791,792],{},"Battery Regulation 2023\u002F1542 Annex XIII schema enforcement",[34,794,795],{},"EU-hosted infrastructure with contractual data portability",[34,797,798],{},"Pricing from €149\u002Fmonth (Starter: 100 DPPs)",[11,800,801,804],{},[15,802,803],{},"Limitations:"," Not designed for Fortune 500 supply chain complexity. No EDI integration. Not a general-purpose supply chain platform. Best fit is importers and brand owners with up to a few thousand SKUs.",[11,806,807,809],{},[15,808,638],{}," W3C VC 2.0, DID:Web, GS1 Digital Link, CIRPASS-2, IDTA AAS submodels, SD-JWT.",[23,811,813],{"id":812},"comparison-table","Comparison Table",[815,816,817,836],"table",{},[818,819,820],"thead",{},[821,822,823,826,828,830,832,834],"tr",{},[824,825],"th",{},[824,827,760],{},[824,829,615],{},[824,831,656],{},[824,833,691],{},[824,835,755],{},[837,838,839,862,883,903,925,945,963,981,999,1019,1036,1054,1072],"tbody",{},[821,840,841,847,850,853,856,859],{},[842,843,844],"td",{},[15,845,846],{},"Target buyer",[842,848,849],{},"SME importers, private label",[842,851,852],{},"Enterprise OEM\u002Fsupply chain",[842,854,855],{},"Brand experience + compliance",[842,857,858],{},"Enterprise, GS1-centric",[842,860,861],{},"Avery Dennison customers",[821,863,864,869,872,875,878,880],{},[842,865,866],{},[15,867,868],{},"Self-service setup",[842,870,871],{},"Yes, \u003C 30 min",[842,873,874],{},"No — PS-led",[842,876,877],{},"Limited self-service",[842,879,874],{},[842,881,882],{},"Limited",[821,884,885,890,893,896,898,900],{},[842,886,887],{},[15,888,889],{},"Pricing model",[842,891,892],{},"Monthly SaaS (€149–€499\u002Fmo)",[842,894,895],{},"Enterprise contract",[842,897,895],{},[842,899,895],{},[842,901,902],{},"Per-label volume",[821,904,905,910,913,916,919,922],{},[842,906,907],{},[15,908,909],{},"W3C VC 2.0",[842,911,912],{},"Full (Ed25519)",[842,914,915],{},"Full",[842,917,918],{},"Partial",[842,920,921],{},"In progress",[842,923,924],{},"Available",[821,926,927,932,935,937,940,943],{},[842,928,929],{},[15,930,931],{},"GS1 Digital Link",[842,933,934],{},"Yes (GS1 DE partner)",[842,936,921],{},[842,938,939],{},"Yes",[842,941,942],{},"Yes (core)",[842,944,939],{},[821,946,947,951,954,956,959,961],{},[842,948,949],{},[15,950,317],{},[842,952,953],{},"Yes (CIRPASS-2)",[842,955,921],{},[842,957,958],{},"Not confirmed",[842,960,939],{},[842,962,921],{},[821,964,965,970,972,974,977,979],{},[842,966,967],{},[15,968,969],{},"SD-JWT",[842,971,939],{},[842,973,939],{},[842,975,976],{},"No",[842,978,976],{},[842,980,976],{},[821,982,983,988,991,993,995,997],{},[842,984,985],{},[15,986,987],{},"Battery Annex XIII",[842,989,990],{},"Yes (schema enforcement)",[842,992,939],{},[842,994,976],{},[842,996,918],{},[842,998,976],{},[821,1000,1001,1006,1009,1011,1014,1017],{},[842,1002,1003],{},[15,1004,1005],{},"EU hosting",[842,1007,1008],{},"Yes (Germany)",[842,1010,1008],{},[842,1012,1013],{},"No (Canada)",[842,1015,1016],{},"Yes (Netherlands)",[842,1018,918],{},[821,1020,1021,1026,1028,1030,1032,1034],{},[842,1022,1023],{},[15,1024,1025],{},"Shopify\u002FWooCommerce sync",[842,1027,939],{},[842,1029,976],{},[842,1031,939],{},[842,1033,976],{},[842,1035,976],{},[821,1037,1038,1043,1046,1048,1050,1052],{},[842,1039,1040],{},[15,1041,1042],{},"IDTA AAS submodels",[842,1044,1045],{},"Yes (5 submodels)",[842,1047,918],{},[842,1049,976],{},[842,1051,976],{},[842,1053,976],{},[821,1055,1056,1061,1064,1066,1068,1070],{},[842,1057,1058],{},[15,1059,1060],{},"RAIN RFID support",[842,1062,1063],{},"Yes (EN 18219\u002F18220)",[842,1065,976],{},[842,1067,976],{},[842,1069,976],{},[842,1071,942],{},[821,1073,1074,1079,1082,1085,1088,1090],{},[842,1075,1076],{},[15,1077,1078],{},"Setup timeline",[842,1080,1081],{},"Hours to days",[842,1083,1084],{},"Months",[842,1086,1087],{},"Weeks to months",[842,1089,1084],{},[842,1091,1087],{},[23,1093,1095],{"id":1094},"which-platform-is-right-for-you","Which Platform Is Right for You",[11,1097,1098,1101],{},[15,1099,1100],{},"Choose PassportLab"," if you are an importer or private-label brand with fewer than 10,000 SKUs, need to be compliant before 2027, do not have a dedicated compliance engineering team, and want self-service setup at a predictable monthly cost.",[11,1103,1104,1107],{},[15,1105,1106],{},"Choose Spherity"," if you are a Tier 1 automotive or industrial supplier, have a development team, and require enterprise-grade cryptographic identity infrastructure with professional services support.",[11,1109,1110,1113],{},[15,1111,1112],{},"Choose Qliktag"," if consumer-facing product experience content is equally important to you as regulatory compliance, and you want a single platform for both.",[11,1115,1116,1119],{},[15,1117,1118],{},"Choose PSQR"," if you are deeply embedded in GS1 DataKEEP infrastructure and your buyers require EDI-level supply chain data integration alongside DPP compliance.",[11,1121,1122,1125],{},[15,1123,1124],{},"Choose atma.io"," if you are already an Avery Dennison customer with RFID-tagged products in fashion or luxury goods, and the unit-level physical-to-digital connection is your primary requirement.",[11,1127,1128],{},"The honest summary: enterprise platforms exist for enterprise problems. If your problem is \"I need to be ESPR-compliant before the enforcement date, I don't have a compliance engineering team, and I need it to cost less than a mid-level developer salary per year,\" PassportLab is the practical answer.",[162,1130],{},[11,1132,1133],{},[167,1134,1135,175,1138,1141],{},[171,1136,1137],{"href":362},"Try PassportLab free for your first DPP",[171,1139,1140],{"href":178},"book a comparison call"," to walk through your specific requirements.",{"title":182,"searchDepth":183,"depth":183,"links":1143},[1144,1152,1153],{"id":609,"depth":183,"text":610,"children":1145},[1146,1148,1149,1150,1151],{"id":614,"depth":1147,"text":615},3,{"id":655,"depth":1147,"text":656},{"id":690,"depth":1147,"text":691},{"id":724,"depth":1147,"text":725},{"id":759,"depth":1147,"text":760},{"id":812,"depth":183,"text":813},{"id":1094,"depth":183,"text":1095},"2026-03-15","An honest comparison of Digital Product Passport platforms: PassportLab, Spherity, Qliktag, PSQR, and Avery Dennison atma.io. Pricing models, setup time, standards support, and who each tool is actually built for.",{},"\u002Farticles\u002Fdpp-software-comparison",10,{"title":586,"description":1155},"articles\u002Fdpp-software-comparison",[1162,1163,615,656,691],"DPP Software","Comparison","WlvolFWYyrX4pleIsOSPeG3mwCvPOa8MyLqZVl5d400",1781291545062]