On July 19, 2026, the EU’s Central Digital Product Passport Registry went live, marking full application of the Ecodesign for Sustainable Products Regulation (ESPR). It’s a genuine milestone, the framework that will eventually govern product transparency for nearly everything sold in the EU officially switched on. Batteries follow next, with mandatory passports required from February 18, 2027, and delegated acts for iron and steel already scheduled for adoption this year.
Most of the commentary around this launch has focused on what it means for data: which fields go in a passport, which formats regulators expect, which delegated act applies to which product category. That’s the visible problem, and it’s a real one. But underneath it sits a harder, less-discussed problem that a registry by itself doesn’t solve: proving who is allowed to write to a given product’s passport in the first place.
A registry is a lookup. It isn’t proof of authorization.
A central registry answers “does a passport exist for this product, and where do I find it.” It doesn’t answer “was the entity that created or updated this entry actually entitled to do so.” Those are different questions, and the second one turns out to be where most of the real complexity lives.
Take the battery passport, the first category with a hard deadline. Under the Battery Regulation, responsibility for a battery’s passport sits with the “economic operator” who places it on the EU market ( typically the manufacturer, or the importer if the manufacturer is outside the EU). That sounds like a single, clean party. In practice, a single battery’s passport can legitimately need input from several different organizations over its life: the original manufacturer at creation, a repairer or second-life operator if the battery is repurposed, and a recycler at end-of-life. The regulation explicitly allows the responsible operator to authorize another party to act on its behalf, and separately, responsibility for the passport can transfer entirely to a new economic operator if the battery is repurposed or remanufactured.
That means a compliant passport system needs to answer, reliably and automatically: is this specific organization currently the authorized economic operator for this specific battery, at this specific point in its life? Not “is this a real company”, plenty of registries can confirm that. Specifically: does this company, right now, hold the authorization to write to this passport, given that the answer may have legitimately changed hands since the battery was made.
Why this doesn’t get simpler outside batteries
It would be tempting to treat this as a batteries-specific quirk. It isn’t. The ESPR’s working plan already schedules delegated acts for iron and steel this year, with aluminium, textiles, furniture, and a growing list of other categories phased in through 2030. Each of those brings its own supply chain shape, but the same underlying structure repeats: a product moves through multiple organizations over its life, more than one of them may legitimately need to update the same passport, and the authorization to do so needs to be provable, not assumed.
At EU-wide scale across dozens of product categories, “who’s allowed to write here” isn’t a footnote to the compliance problem. It’s the foundation the rest of the compliance problem sits on top of.
The layer most DPP conversations skip
This is where the discussion usually jumps straight to data schemas and QR codes, and skips the organizational identity layer entirely, as if verifying an organization’s authorization to act is a solved problem that doesn’t need architecture of its own. It isn’t solved by default. Proving that a specific legal entity currently holds a specific authorization, in a way another party (a customs authority, a recycler, a competitor’s system) can verify without a phone call or a PDF letter, is the same category of problem that verifiable credentials and decentralized identifiers were built to solve for people, just applied to organizations and, increasingly, to the systems and processes acting on their behalf.
Put differently: a digital product passport is only as trustworthy as the identity infrastructure standing behind every entity permitted to touch it. A registry tells you where to look. It’s the credentialing layer underneath (proving who’s allowed to write, and letting that authorization transfer cleanly when responsibility legitimately changes hands) that determines whether what you find there can actually be trusted.
The pattern to watch
The July registry launch is a genuine milestone, but it’s the visible part of a much bigger buildout. As more product categories come online through 2027 and beyond, the organizations best positioned won’t just be the ones with clean product data, they’ll be the ones that solved organizational identity and authorization as infrastructure, once, rather than re-solving it ad hoc for every new delegated act. That’s a less visible problem than a registry going live, and a considerably harder one to retrofit later.