How do I document the delivery of passport data in my purchasing contract?
Establish supply obligations and dataset contractually
The purchase contract specifies which product passport data the supplier delivers, in what form, at what point in the process, and what happens if data is missing or incorrect. This is the core of the agreement: not merely 'you provide the required data', but a concrete list of data categories (material composition, repair information, conformity data, and whatever else applies to the relevant product group), a delivery moment that fits the production process (before shipment, before placing on the market), and an agreement on updates whenever something changes. Without that concrete specification, the general obligation to exchange data between parties in the supply chain remains an abstract commitment that is difficult to enforce in a dispute. The contract is the instrument that makes that obligation practical and enforceable between the parties themselves.
For manufacturers, importers and their suppliers — not for the end user
These agreements are relevant between parties who both play a role in the supply chain of electronic or ICT equipment: a manufacturer purchasing components, an importer bringing equipment from outside the EU, or a distributor between manufacturer and market. In particular, the importer with a supplier outside the EU has an interest in a solid contractual agreement, because the importer itself bears responsibilities towards the market and supervisory authorities, even if the data must actually come from the manufacturer. This is not about the sales agreement with the consumer — the consumer receives the passport via the QR carrier on the product, not via a separate contract. Nor is it about whether a product is subject to the passport requirement; that follows from the delegated act per product category, not from the purchase contract. The purchase contract regulates only the relationship between the purchasing and supplying party regarding the delivery of data.
Date not yet fixed; the obligation to exchange data is already in place
There is no fixed date yet for when this will apply to electronic and ICT equipment — the delegated acts per sub-category are expected at a later time and have not yet been published. What is already established is the general line from the ESPR itself: actors in the supply chain are required to provide, upon request, the information needed to draw up or complete the product passport, and importers have their own obligations to verify that these requirements are met before a product is placed on the market. These basic obligations are therefore already in place, regardless of the exact specification per product category. A purchase contract can therefore be drawn up or adapted now on the basis of this general line, with the intention to refine it later once the delegated act for the specific product group is published and it becomes clear what data is precisely required.
What this means for the reader: step by step
If you are now drawing up or revising a supply contract, you typically approach this in the following order. First: inventory which data are expected to be needed for the product group in question, based on what is already known about it, without waiting until every detail is finalised. Next: establish a delivery moment that aligns with your own procurement process — for example before shipment or before invoicing — so that no gap emerges between placing the product on the market and the availability of the data. Then: include an updating obligation for the situation where data change after delivery, with an agreement on how and within what timeframe the supplier communicates this. An indemnification or liability exclusion clause also belongs here, in case the supplier provides incorrect or incomplete data as a result of which the procuring party itself runs into problems with supervisory authorities. Finally, an audit right or documentation obligation is practical: the right to request evidence showing that the supplied data are correct, rather than relying solely on the supplier's statement. An explicit reference to the relevant ESPR articles in the contract moreover makes clear that these agreements do not come out of nowhere, but are an implementation of a legal obligation that rests on both parties.
The legal basis: article 38 and 29 of the ESPR
Article 38 of Regulation (EU) 2024/1781 (ESPR) obliges actors in the supply chain to provide, on request, the information needed to draw up or complete the product passport — both to other economic actors in the chain and to competent authorities. That article is the basis for why a procuring party has an interest in making this obligation concrete in the contract with its own supplier: the law regulates that information must be supplied, the contract regulates how. Article 29 of the same regulation describes the obligations of importers, including checking whether the applicable requirements have been met before a product is placed on the market and keeping documentation on this. For an importer obtaining equipment from a manufacturer outside the EU, this article is the reason why contractual agreements on data supply are not optional: the importer bears its own responsibility, regardless of what has been agreed contractually with the manufacturer.
Those who wish to go further can now place the existing supply contract alongside these two articles and check whether delivery moment, data set, updating obligation and liability are already described concretely enough — and supplement the text as soon as the delegated act for their own product category is published.
What this is based on
- Regulation (EU) 2024/1781 (ESPR), Article 38 (requirements for actors in the supply chain)
- Regulation (EU) 2024/1781 (ESPR), article 29 (obligations of importers)
The regulation itself is on EUR-Lex. We provide references per statement; you do not have to take our word for it.
What you must concretely do
What is expected of you
The ESPR places the obligation to compile a digital product passport with the manufacturer, and also with the importer when goods are imported from outside the EU. However, the data that must be included in that passport often does not originate with that party — it sits with the supply chain: with the manufacturer of a component, the assembly location, or a supplier further down the chain. Article 38 of the ESPR (Regulation (EU) 2024/1781) therefore sets requirements for actors in that chain: whoever has information that is needed for the passport is expected to make it available to the party compiling the passport. For a purchasing company, this means in particular that the obligation does not automatically translate into a contractual agreement — you must arrange the latter yourself.
Obtaining data on time and in full
A manufacturer that must compile the passport is dependent on the information that a supplier provides: materials, origin, repair data, conformity information. For a company with 10 to 100 employees, this means in practice that procurement not only agrees on price and delivery time, but also on a data obligation: which data, in which format, and at which point before delivery. Without that agreement, the problem only arises when the passport needs to be compiled — too late to still change the procurement terms.
Traceability throughout the chain
Article 29 (obligations of importers) of the ESPR (Regulation (EU) 2024/1781) makes the importer jointly responsible for the accuracy of what is in the passport, even if the data comes from a manufacturer outside the EU. For an importing company, this means that its own position in the chain matters: it is not only asked to pass on data, but also to exercise some degree of control over what has been supplied. That is different from simply "forwarding what the supplier sends".
Continuity when changing suppliers
A product passport is hosted and continues to exist as long as the product is on the market or in use. When a supplier changes — for example because a component is henceforth purchased from a different party — the original data source does not automatically disappear from the passport, but something must be done about the currency of the data. For a company, this means that contractual agreements belong not only at the start of a supply relationship, but also at its end: who keeps the data up to date, and what happens to historical data.
Where things go wrong in practice
A number of situations recur more often than others. First: the supplier provides data only after delivery of the goods, while the passport must already be present when the product is placed on the market — the timing is not in the contract, so no one feels bound by it. Second: data is provided in a format that does not match what the passport requires, so manual work is still needed to convert the data. Third: multiple suppliers are purchasing for the same component without having documented which data belongs to which delivery — that makes it difficult to trace which batch corresponds with which passport data. Fourth: a subcontractor who does part of the production is not named in the procurement contract as a data source, creating a gap in the chain that no one had anticipated. Fifth: existing procurement terms are not adapted because the supplier does not want to cooperate on a change, and the purchasing party accepts that without seeking an alternative.
These situations are rarely the result of unwillingness by one party — more often they are the result of contracts that were drawn up before the passport obligation came into play, and that simply have not been updated.
What you can document
A number of elements recur when it comes to documenting passport data in a procurement contract:
- A data annex to the procurement contract, which sets out what data the supplier provides, in what format, and before which point in the delivery process. This is more precise than a general reference to "legal obligations".
- A description of what is being requested exactly — for electronics, it often concerns different data than for household appliances or ICT equipment. What you can concretely ask your supplier, is described on the page about what data you must request from your electronics supplier.
- A verification provisionwhich sets out how and by whom the supplied data is checked before it enters the passport. An approach for that verification is described on the page about verifying a supplier's data for accuracy.
- A provision on what happens if data is not supplied, including a timeline and possibly an escalation route. What to do if a supplier does not supply the data is explained on the page about a supplier that does not supply the data.
- A provision on subcontractors, so that data not directly originating from the main supplier also reaches the passport compilation — relevant when a subcontractor is involved, as described on the page about product passport data that must come from a subcontractor.
- A provision for situations with multiple suppliers for the same part, so that it is clear which data belongs to which batch or delivery.
- An approach for when a supplier is unwilling to cooperate in contract amendment, including alternatives such as a separate agreement alongside the existing contract or finding another supplier.
A purchase contract containing these elements does not need to be completely rewritten — often a supplementary annex or addendum is sufficient to place the data obligation alongside the existing delivery terms.
This is not legal advice. This page provides general information about the regulations that this platform covers. We are not familiar with your situation. If you are in doubt about your own case, consult a lawyer or the competent supervisory authority.
Written with AI based on the sources above, checked by a human on 2026-08-22. Is something incorrect? Let us know — corrections take priority.