Kommisjonens gjennomføringsforordning (EU) 2026/1778 av 16. juli 2026 om fastsettelse av gjennomføringsordninger for det digitale produktpassregistret etablert under europaparlaments- og rådsforordning (EU) 2024/1781
Økodesignforordningen 2024: gjennomføringsbestemmelser om det digitale produktpassregistret
Kommisjonsforordning publisert i EU-tidende 17.7.2026
Tidligere
- Utkast til forordning lagt fram av Kommisjonen 29.4.2026 med tilbakemeldingsfrist 27.5.2026
Bakgrunn
(fra kommisjonsforordningen)
(1) Article 13(1) of Regulation (EU) 2024/1781 requires the Commission to establish a digital registry for the digital product passport (‘the registry’) to store in a secure manner at least the unique identifiers. It is necessary to set out the main components of the registry and lay down the technical and operational roles and obligations of economic operators placing a product on the market or putting it into service within the framework of the digital product passport registry, competent national authorities and customs authorities, and the Commission. Furthermore, it is necessary to establish a log system in order to record and monitor the operations and interactions carried out in the registry in order to ensure accountability for all users, and delineate the responsibility for the maintenance, operation and security of the registry. These implementation arrangements also include rules applicable to value chain actors, competent national authorities and customs authorities, and the Commission regarding the use of the registry. Where appropriate, competent national authorities should be able to update or change the status of the digital product passport based on the checks carried out in accordance with their tasks under relevant Union law and national law that complies with Union law.
(2) The registry should provide information about products covered by delegated acts adopted under Regulation (EU) 2024/1781, to the extent that the use of a digital product passport is provided for, and, about batteries, under Regulation (EU) 2023/1542 of the European Parliament and of the Council (2). Further Union legislation may require that information on products be stored in the registry. That is already the case for construction products falling within the scope of Regulation (EU) 2024/3110 of the European Parliament and of the Council (3), toys falling within the scope of Regulation (EU) 2025/2509 of the European Parliament and of the Council (4) and detergents and end-user surfactants falling within the scope of Regulation (EU) 2026/405 of the European Parliament and of the Council (5). Where further Union legislation refers to the registry established by Regulation (EU) 2024/1781, the implementation arrangements laid down in this Regulation should apply. This should be without prejudice to specific Union rules concerning the digital product passport registry, including rules adopted through empowerments to supplement or adapt its requirements, such as the case of construction products in Article 79(2) of Regulation (EU) 2024/3110 of the European Parliament and of the Council (6). Where the registry is interconnected with other information systems, such interconnection should not compromise the interoperability of those systems.
(3) To ensure the effectiveness, security and interoperability of the registry, it should consist of the following elements: a website providing a secure user interface; an Application Programming Interface (API) for registering digital product passports; a verification platform to verify and confirm the existence and completeness of the digital product passports; an identification and authorisation scheme for users; a schema for generating unique registration identifiers; a storage component for unique identifiers and commodity codes of products intended to be placed under the customs procedure ‘release for free circulation’; a semantic repository which serves as the authoritative reference for the semantic meaning, structure, versioning and interoperability requirements of digital product passport data; a log system recording relevant operations. Considering that the digital product passport system is built on a decentralised model, the registry should also include a reference list of verified digital product passport service providers registered in the registry.
(4) To ensure accountability, each economic operator and value chain actor (such as digital product passport service provider, repairer, refurbisher, remanufacturer, recycler) should be identified through a verification process.
(5) In the case of a natural person acting as a sole trader which is required to be established in the Union, its identity should be proved through a qualified electronic signature supported by a qualified certificate for electronic signatures in accordance with Regulation (EU) No 910/2014 of the European Parliament and of the Council (7), or through an electronic identification means which meets the requirements of that Regulation with regard to the assurance level ‘high’, or through an electronic attestation of attributes issued under Union law that enables the identification of the economic operator. In the case of a natural person acting as a sole trader which is not required to be established in the Union, his/her identity should be proved through a qualified electronic signature supported by a qualified certificate for electronic signatures in accordance with Regulation (EU) No 910/2014, or through an electronic attestation of attributes issued under Union law that enables the identification of the economic operator.
(6) In the case of a legal person required to be established in the Union, proof of its identity and its establishment should be verified by a qualified trust service provider through a qualified electronic seal supported by a qualified certificate for electronic seals in accordance with Regulation (EU) No 910/2014, or through a qualified electronic attestation of attributes issued under Union law that enables the identification and of establishment of the economic operator. In the case of a legal person not required to be established in the Union, proof of its identity and, where applicable, of its establishment should be verified by means of a qualified electronic seal supported by a qualified certificate for electronic seals, issued by a qualified trust service provider pursuant to Regulation (EU) No 910/2014, or by means of an electronic attestation of attributes issued under Union law that enables the identification of the economic operator.
(7) This Regulation should be without prejudice to requirements laid down in other pieces of Union law concerning the place of establishment of economic operators or, where applicable, value chain actors that place products on the market or put them into service. Therefore, where such requirements apply, the use of the registry should not circumvent or undermine their application, and the registry should be operated in a manner fully consistent with them.
(8) Upon completion of the verification process, the economic operator should be considered to be a ‘verified economic operator’, authorised to create a user profile and manage access rights for additional users acting on behalf of the same operator, to register new digital product passports in the registry and modify existing registrations. Only an economic operator with a ‘verified’ status should be able to register digital product passports in the registry and make corrections to the existing registrations, to the benefit of the integrity and accuracy of the data. The registry should indicate whether the registration of the verified economic operator is valid. A single verification process should provide the economic operator with the ‘verified’ status up until their means for electronic identification expire, and, in any event for no longer than for 3 years. Where an economic operator does not repeat that process upon expiry of the three-year period or where its identification means have expired, it should no longer be considered a ‘verified economic operator’. Therefore, it will lose the capacity to register new digital product passports or modify any data in the registry.
(9) For value chain actors (repairers, refurbishers, remanufacturers or other) to get access to the registry, those actors will need to go through the verification process detailed in Article 5. Therefore, only actors which have obtained the ‘verified’ status are to have access to the digital product passport registry. Their role (such as repairer, recycler, remanufacturer or other) and any actions which they perform in the registry should be specified in the delegated acts adopted under Regulation (EU) 2024/1781 or under other pieces of Union law.
(10) Economic operators or value chain actors that did not pass the identity verification before the deadline foreseen in this Regulation should be able to transfer their registered digital product passports to a verified economic operator or, where applicable, to a verified value chain actor which is to take over the responsibilities related to those digital product passports. That transfer may be also possible for any verified economic operator or verified value chain actor in case of organisational changes such as merging, splitting or sale of all or parts of the actor, cessation of activities or other circumstances.
(11) To ensure proper functioning of the registry and accountability for users, rules should be laid down for managing the user profile data of verified economic operators and verified value chain actors. For that purpose, each verified economic operator and verified value chain actor should always have at least one person linked to the registry account who handles the profile data. This includes but is not limited to: granting access rights to additional users where practicable, modifying and reading existing registrations, and registering new digital product passports. That person may also be the person who registers the verified economic operator or the verified value chain actor in the registry. The verified economic operator and the verified value chain actor should maintain in the registry accurate, complete and up-to-date records and ensure all the information provided is correct, including any changes to its legal representative. The economic operator and value chain actors should also be responsible for managing the electronic identity verification process in the registry. The registry should not prevent any lawful transfer of ownership of digital product passport registrations to any other verified economic operator or verified value chain actor irrespective of their own identity verification status. Where the digital product passport registry is integrated with already established EU systems (such as the European Product Registry for Energy Labelling (‘EPREL’)) that use the same level of verification for economic operators or, where relevant, for verified value chain actors, double verification should be avoided.
(12) Competent national authorities, such as market surveillance authorities, and customs authorities should have access to the registry for the purpose of carrying out their duties based on their access rights specified in relevant Union and national laws in compliance with Union law. In order to streamline access management and ensure accountability, each Member State should designate a single national administrator as the main contact point with the Commission to manage and oversee access rights for that Member State. The designated national administrator should act as the central authority responsible for managing access rights for all relevant national authorities within that Member State, to ensure that only relevant authorities are assigned access rights to the registry. The role of the designated national administrators does not include the fulfilment of the obligations laid down in Article 22 for the Member State. Member States should inform the Commission of the name and contact details of their appointed national administrator and notify the Commission of any changes to this information. In order to ensure the security, integrity and confidentiality of the data, the delegation of access rights should be carried out under the full responsibility of the Member State taking into account the specific needs of its authorities.
(13) The Commission, in managing the registry in accordance with Article 13(1) of Regulation (EU) 2024/1781, should ensure that personal data is processed in accordance with the highest data protection standards in accordance with Regulation (EU) 2018/1725 of the European Parliament and of the Council (8). The Commission should therefore be considered the registry’s ‘controller’ as defined in Article 3, point (8), of that Regulation. Personal data should be processed only for the purpose of the management and operation of the registry. That information should be protected from unauthorised access, use, or sharing. Those data should only be kept as long as necessary and should be deleted when user accounts are removed or access is revoked. However, if a user’s actions in the registry require data retention for auditing or traceability under Union law, those data should be kept accordingly.
(14) Registration of the digital product passport in the registry should be carried out by the economic operator at the level of granularity set out in the applicable Union law, namely at model, batch or item level. In order to ensure full functionality of the registry, in particular for competent national authorities and customs authorities, where a digital product passport is created at item level, the corresponding batch and model identifiers should also be registered together with that digital product passport in the registry, provided that batch and model design exist for the product concerned. For products that are unique by nature, including handmade goods, no batch and model identifiers are required. The same rule applies for digital product passports issued at batch level, where a model identifier is required upon registration. In that context, the batch identifier and the model identifier should represent the higher-level grouping of the product concerned. Those identifiers should be issued by the economic operator in order to enable the competent national authorities to trace products belonging to a specific batch or model registered in the digital product passport registry. Where the same product is subject to several Union rules requiring registration of its digital product passport at different levels of granularity (model, batch or item), the digital product passport should be registered at the most granular of those levels.
(15) Registration should be carried out by using the secure user interface of the registry provided by the Commission or through the API set up for that purpose. Once the registration of a digital product passport is successfully validated, a unique registration identifier is generated and stored in the registry and communicated according to Article 8 automatically to the actor registering the digital product passport using the same service which was used by the actor to upload the digital product passport data.
(16) To ensure that only complete and valid digital product passports are registered, the Commission should, as the owner and manager of the registry in accordance with Article 13(1) of Regulation (EU) 2024/1781, perform an automatic verification of the submitted data. It should verify at least the data structure and the level of granularity (model, batch or item) of the digital product passport for that relevant product in accordance with the applicable Union rules. Where relevant, the product commodity codes and the link to the back-up hosted by a digital product passport service provider should also be subject to verification. The verification of the substantive correctness of the data registered remains a task for the market surveillance authorities under the applicable Union rules. Accordingly, the automated verifications should not be deemed to constitute proof of compliance with the requirements of the Union rules applicable to the product, including with market surveillance rules.
(17) Where a digital product passport is registered in the registry, the economic operator or, where relevant, a third party acting on behalf of the economic operator is entitled to request proof of registration from the registry. That request can cover one or more digital product passports for which the economic operator is responsible. The proof of registration should serve as evidence for third parties that a particular digital product passport has been properly registered. It should be created as a secure electronic document, which can be downloaded from the registry. That proof should remain available for 90 calendar days from the date of its generation, with the possibility of regeneration, if necessary.
(18) To ensure the correctness and accuracy of registry data, the registry should support versioning of registered data. Each new version of the digital product passport should be linked to the original registration identifier, and each update should be time-stamped. For the purpose of secure handling of data, all operations performed should also be logged in the registry. In cases where Union law does not specify how long a digital product passport must remain available, the registry will automatically delete the digital product passport registration data 10 years after registration in accordance with the rules laid down in Commission notice The ‘Blue Guide’ on the implementation of EU product rules 2022 (9). Where Union law does set a specific duration, the data will be kept in the registry for that specific period.
(19) To ensure semantic interoperability of the digital product passports and technical functioning of the registry, a semantic repository should be set up. The semantic repository will be an evolving collection of data models and semantic definitions, expanding progressively as additional product groups are incorporated. All data contained in a digital product passport needs to be structured in accordance with common data models and semantic definitions published in the semantic repository of the registry. That framework should remain flexible and extensible to accommodate any future changes to data requirements regarding the inclusion of a product in the digital product passport. The Commission strives to ensure that the semantic repository is technically capable of publishing semantic specifications and exchanging them with other Union level repositories, including those maintained by Union institutions and bodies.
(20) To allow reading, searching and comparing of semantic definitions and data structures, the semantic repository should include a search service. The Commission should ensure that the content of the semantic repository is always accessible through publicly documented APIs except during periods of necessary maintenance or temporary suspension of the service in accordance with Article 15. The APIs should support common data formats to facilitate automated use by external systems. Access to and use of the semantic repository and its APIs should be free of charge.
(21) To ensure adequate support to users, the Commission should establish a helpdesk service to provide technical support to all users of the registry where needed. The helpdesk service should operate throughout the year during standard business hours. Further details, including operational procedures, should be made available on the Commission’s website.
(22) To ensure the integrity, security and transparency of the registry, the Commission should maintain a robust and automated log system recording all activities within the registry. As part of the log system, comprehensive audit trails should be created. To that end, and to track all actions performed on the registry in order to ensure accountability for all users, logs should be kept of access attempts, both successful and unsuccessful, as well as modifications and administrative actions.
(23) The retention periods for logs should be proportionate to their purposes. While logs related to data modifications should be retained for the duration of the registration to support long-term verification, incident investigations and compliance with legal obligations, logs of authentication attempts require a shorter retention period to balance security needs with data minimisation principles. Logs of administrative operations and data exchange are retained for an average period of five years.
(24) Access to logs by competent national authorities and customs authorities for the purpose of conducting investigations or security audits, or in the event of incidents, is essential for effective cooperation and enforcement. Such access should be granted in a manner that respects the confidentiality and integrity of the logs, while allowing for timely and thorough investigations or audits.
(25) Given the sensitive nature of the logged data, which may include personal or confidential information, the Commission should implement appropriate technical and organisational measures to protect logs against unauthorised access or unlawful processing, accidental loss, destruction or damage. Such measures should guarantee the continuity and confidentiality of logs as well as ensure their integrity and reliability as evidence. The use of encryption, access controls, and regular integrity checks should be considered best practices to fulfil these obligations.
(26) To facilitate the effective and efficient use of the registry, the Commission should provide clear, accessible and up-to-date guidelines as well as instructions on registration procedures and data management. Making those resources available through the Commission website will ensure that all users, regardless of their technical expertise, are able to comply with their obligations. Such guidance is essential to minimise errors, reduce administrative burdens, and promote uniform application of the requirements to register across the Union.
(27) The continual availability of the registry is a fundamental requirement for its proper functioning, as interruptions could disrupt compliance activities, market surveillance, customs controls and the free movement of goods and services within the internal market. However, planned maintenance, such as software updates, security patches, or system upgrades, may occasionally necessitate temporary inaccessibility. To mitigate disruptions, the Commission should provide advance notice of such periods on a publicly accessible website, allowing users to plan accordingly. Additionally, in exceptional circumstances, such as system malfunctions, cyber-attacks, or urgent security threats, the Commission may suspend access to the registry without prior notice to prevent data breaches, unauthorised access, or further damage. Such measures are justified by the overriding need to protect the integrity and security of the registry and the data it contains. In the event of such suspension, the Commission should act swiftly to restore normal operations and, where feasible, inform users, as soon as practicable, of the suspension and its expected duration. To ensure accountability and enable access by market surveillance authorities and customs authorities, the Commission should document the duration and timing of any outages and retain such records for at least five years.
(28) The registry should operate in compliance with high-level security standards to protect the integrity, confidentiality and availability of its data. Therefore, the Commission should prepare an IT Security Plan which will cover cybersecurity and other IT related risk assessments, conduct technical audits and random checks to verify compliance and identify vulnerabilities, in order to ensure that the system remains resilient against cyber threats. The Commission should ensure that all security events, which include but are not limited to unauthorised access, unauthorised processing, data breaches, failures in implementation logic, are logged in accordance with the information technology security standards applied by the Commission. In addition, the registry should comply, as soon as the relevant services become available on the Union market, with an adequate level of sovereignty, based on the Cloud Sovereignty Framework (10).
(29) The Commission should be able to take the necessary action if it suspects fraudulent activity in the registry, which may include inappropriate downloading of information. Users have the responsibility to notify the Commission and, where relevant, the affected national authorities immediately in case of suspected malicious behaviour.
(30) The processing of personal data in the registry is necessary under Regulation (EU) 2024/1781, including the verification of digital product passports, market surveillance, and customs controls. To ensure the authenticity and integrity of the data and to protect the rights of data subjects, the registry should process personal data stored in it, such as names, contact information, and login credentials, in accordance with Regulation (EU) 2018/1725.
(31) The economic operator should be responsible for providing accurate and complete information to the registry. Given the potential risks associated with unauthorised access to the registry, such as data modification, the economic operator should be obliged to implement adequate technical and organisational security measures to protect its IT systems, in particular the credentials used to access the registry. The economic operator should remain liable even if a third party is authorised to register a digital product passport on behalf of the economic operator.
(32) The Commission, which is to be the owner and manager of the registry, should be responsible for the overall lifecycle management of the registry, including its development, availability, monitoring, updating, maintenance, and hosting. That entails inter alia the fact that the Commission has access to the registry. The Commission should also be able to access the registry in order to obtain information that is necessary for carrying out measures required under other EU legislative acts, including for the purposes of market surveillance, consumer protection and customs compliance.
(33) It should also remain responsible for ensuring that the data stored in it is processed securely and in compliance with Union law, including with the data protection rules.
(34) Member States need to be able to interact with the registry to effectively carry out their market surveillance, customs controls, and other tasks laid down at national level or under Union law. Member States should remain responsible for ensuring the development, maintenance and security of national components which they use to access the system, such as national registries or information systems. To ensure appropriate protection of personal data, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (11), Member States should be regarded as controllers within the meaning of Article 4, point (7), of that Regulation, when they process personal data for the purposes laid down in Union law. Member States are entitled to process data obtained from the registry in accordance with Union law.
(35) The measures provided for in this Regulation are in accordance with the opinion of the Committee established by Article 73 of Regulation (EU) 2024/1781,