Public vs Restricted DPP Data: ESPR Access Tiers Explained
ESPR Digital Product Passports are not one public dump of every field. Some data is consumer-facing; some is restricted to regulators and recyclers.
A DPP is not a public PDF of everything you know
The Digital Product Passport (DPP) under the European Sustainability Product Regulation (ESPR), Regulation (EU) 2024/1781, is fundamentally a machine-readable record. It is linked to a physical product via QR codes, RFID, or data matrix codes. Unlike a static document, the DPP is a dynamic data structure that supports granular access control. This distinction is critical for compliance and product-data teams: the DPP is not a public PDF containing every detail you know about a product. Instead, it is a secure gateway that serves different data sets to different stakeholders based on their authorization level. This architecture ensures that while consumers receive the information they need for informed purchasing, sensitive operational and regulatory data remains protected.
What consumer-facing fields typically cover
For the end-user, the DPP provides transparency on aspects that directly impact usage, care, and environmental impact. According to the core fields outlined in Articles 9-11 of the ESPR, consumer-facing data typically includes the unique product identifier, material composition, and basic technical and safety information. Crucially, this tier includes environmental performance data such as durability, repairability, recyclability, and carbon footprint. Consumers also receive manufacturer and importer details, along with clear instructions for use, care, and end-of-life disposal. These fields are designed to empower shoppers to make sustainable choices and maintain their products effectively, without exposing proprietary supply chain mechanics or internal compliance metrics.
What stays restricted: regulators and recyclers
While the consumer view is broad, the DPP architecture allows for restricted access tiers. Certain data points are not intended for the general public. Regulators and authorized recyclers may require access to more detailed or sensitive information to verify compliance or facilitate circular economy processes. For instance, while a consumer sees the carbon footprint, a regulator might need the underlying calculation methodology or specific supply chain verification data. It is important to note that supply chain information for textiles is not yet fully specified in the current framework; a delegated act is expected in late 2027 to clarify these specifics. Until then, the distinction between public and restricted data remains a strategic lever for brands to manage information disclosure while preparing for future regulatory requirements.
Why certificates cannot do tiered access
Traditional PDF certificates or static compliance documents lack the technical capability to enforce tiered access. A PDF is a flat file; once generated, it contains all the data embedded within it. There is no mechanism to hide specific fields from a consumer while revealing them to a regulator. If you include sensitive supply chain details in a PDF for a regulator, that same document is accessible to anyone who possesses it. Conversely, if you redact sensitive data for public consumption, you create a separate document for regulators, leading to version control issues and data fragmentation. The DPP’s machine-readable nature solves this by linking to a central database where access rights are dynamically applied based on the user’s credentials, ensuring data integrity and security across all stakeholder groups.
Interoperability: authorized readers, not a proprietary silo
The DPP ecosystem is built on interoperability standards rather than proprietary silos. CEN/CENELEC EN 18xxx standards define the technical interoperability required for authorized parties to access DPP data. This means that an authorized reader—whether it is a regulatory body, a recycler, or a brand’s own compliance team—can access the DPP using standard-compliant tools. This open architecture prevents vendor lock-in and ensures that data remains accessible and usable across the product’s lifecycle. For brands, this means you are not trapped in a single platform’s ecosystem; your DPP data is structured to be readable by any compliant system, facilitating smoother audits and broader industry collaboration.
How KadmilOS fits in
KadmilOS is designed to manage this complexity for fashion and product-brand suppliers. We help you structure your product data according to ESPR requirements, ensuring that the right information is available to the right audience at the right time. By leveraging the machine-readable nature of the DPP, KadmilOS enables you to maintain a single source of truth while enforcing the necessary access controls. As mandatory textile and footwear DPP compliance approaches in the 2027-2028 window, having a robust system in place to manage these access tiers is essential. KadmilOS provides the infrastructure to handle the technical interoperability standards, allowing your team to focus on data accuracy and strategic compliance rather than technical implementation details.
Prepare your product data for the upcoming ESPR requirements with a platform built for tiered access and regulatory compliance. See KadmilOS pricing and Check ESPR scope.
Ready to handle compliance via API?
KadmilOS covers DPP data, eco scoring, CSRD documentation, and ECGT 2024/825 claim-support.