elektropas.com

Do I have to make business-sensitive data about my electronics public?

Not everything is made public: the passport has different access levels

No, not all data in the digital product passport is automatically visible to everyone. The ESPR is based on a passport with layered access: some information is available to the general public, other information only to supervisory authorities, customs or specific market participants such as repairers or recyclers. This approach exists precisely because the legislator recognises that not all product information is equally relevant or desirable for everyone to share. Business-sensitive data, such as precise formulation, supplier relationships or production details, do not therefore need to be disclosed as soon as a passport goes live.

Which data this applies to, and which it does not

This protection applies to data that represents a genuine commercial interest and whose disclosure could harm competitive position — think of specific supplier information, internal production processes or technical details that go beyond what is necessary for repair, recycling or market supervision. It does not apply to the core information that the passport is actually intended to contain: data on sustainability, origin of materials, repair and recycling information and compliance with product requirements. That information is the whole raison d'être of the passport and is not subject to a confidentiality claim, even if a manufacturer would prefer not to have shared that information. The distinction is therefore not "do I want to share this" but what the regulation deems necessary for the passport versus what goes beyond that.

Also important: layered access does not mean that sensitive data does not need to be shared at all. Actors in the supply chain may be required to provide certain information to other parties in that chain or to supervisory authorities, even if that information is not intended for the general public. Confidentiality towards the consumer is therefore something different from confidentiality towards the entire chain or towards a supervisory authority.

No fixed date yet, but an established principle

For electronics and ICT equipment, the date when the product passport becomes mandatory is not yet fixed: this follows per subcategory from delegated acts expected from 2027 onwards within the ESPR work plan 2025-2030. As long as that act for a specific product category does not exist, there is no obligation to maintain a passport, and therefore no concrete question about which data may remain confidential. What is established, however, is the principle from the ESPR itself: layered access to passport data is part of the basic regulation and will therefore also apply as soon as a delegated act for electronics comes into force. The concrete implementation — which data fields are precisely public and which are restricted access — will be further developed per product category in those delegated acts. Until then, there is nothing to fill in; this page will be updated as soon as the act for electronics is published.

How this works in practice

Anyone thinking ahead about the product passport would be well advised to first map out which data should be included in the passport based on the core information requirements, regardless of whether that is sensitive. Next, it makes sense to consider which additional data a supplier, manufacturer or importer would want to add themselves or must provide, and whether that information goes beyond the mandatory minimum. For that additional layer, it is relevant to know who exactly gets access: the general public via the QR code, or a more limited group such as supervisory authorities or supply chain partners. Because the exact allocation of data fields per product category has yet to be determined, it is not yet possible to determine for each field whether something becomes public or remains restricted. What can be done now: put existing internal data inventories in order, so that it will quickly become clear which data falls under which category once the delegated act is in place. Those who have a passport compiled via Elektropas will have that allocation processed according to the rules in force at that time; the data provided does not need to go beyond what the regulations require for the relevant category.

Where this follows from: Article 10 and Article 38 of the ESPR

The basis for the tiered access to passport data is laid down in Article 10 of Regulation (EU) 2024/1781 (ESPR), which sets out the requirements for the digital product passport, including the manner in which information is made accessible to different types of users. Article 38 of the same regulation sets out the requirements for actors in the supply chain, and is relevant to the question of which information must be shared between parties in the chain, even if it is not intended for the public. The precise delimitation between public and restricted-access data for electronics follows from the delegated act that still needs to be adopted for this product category.

What to do now

Map your own product data and already separate what is likely to be part of the mandatory core information from what counts as additional or sensitive information; consult the ESPR work programme of the European Commission for the current status of the delegated acts, and return to this page once the act for electronics has been published — it will be processed here immediately.

What this is based on

The regulation itself is on EUR-Lex. We provide references per statement; you do not have to take our word for it.

What you must concretely do

What is expected of you

The digital product passport requests product information: composition, origin of materials, repair data, energy consumption. For a company, part of that information quickly feels sensitive — supplier relationships, recipe, procurement structures. The ESPR does not stipulate that all company information becomes public, but it does require that product information be available, with distinction in who may see what.

The passport contains product data, not free business data

Article 10 of the ESPR (Regulation (EU) 2024/1781) describes what type of data belongs in the passport: properties of the product itself, not an open collection of everything a company has in information. What exactly is requested differs per product group and is set out in the delegated act for that group. In practical terms, for a company of 10 to 100 employees, the first step is to check what data the applicable act actually requests, rather than assume in advance that competition-sensitive information will become public. What level of detail exactly is requested also differs per product type — see which data must I fill in exactly for my type of device.

Access is layered, not equal for everyone

Not every party that consults the passport sees the same data. The ESPR makes a distinction between what a consumer sees via the QR code, what a supervisory authority can request, and what is only accessible to recyclers or market players in the chain. For a company, this means the question "will this become public" is actually two questions: is it in the passport, and who can see it there. That distinction is precisely worked out on who is allowed to access which data from the digital product passport, and is relevant before a company decides to omit something or generalize it.

Actors in the supply chain pass on data, not everything is public

Article 38 of the ESPR (Regulation (EU) 2024/1781) describes obligations for actors in the supply chain: they provide product information to the party compiling the passport. That is a different flow from public publication. For a company of 10 to 100 employees that supplies to a manufacturer, this means data does pass into the chain — to the party drawing up the passport — without that establishing that such data will also be visible to the public or to competitors.

The obligation rests on the product, not on the enterprise as a whole

The passport is about a product model or batch, not about business operations. A company therefore does not need to explain how it procures, who it negotiates with, or what the margins are. What is requested, in turn, relates to properties relevant to repair, recycling and lifespan — think of software support or raw material use. These two topics are often confused with trade secrets, whereas essentially it is about product characteristics; see must I record how long a device receives software updates and which critical raw materials must I report in the passport.

Where things go wrong in practice

A supplier refuses data transfer for fear of disclosure. A component supplier suspects that all transmitted specifications automatically become public, and therefore withholds data that is needed for the end manufacturer's passport. This causes delay in the chain without it being established that the concern is justified.

Material composition is confused with recipe. A home appliance manufacturer prefers not to report exact material percentages, for fear that competitors can reconstruct the product formula. Often it is information at a different aggregation level than what the concern is actually about.

Internal quality data is incorrectly included. A company adds test reports and internal process documentation to the passport file "to be safe", while only final values are requested. This increases the risk that sensitive internal documents are included in something that is more widely accessible than intended.

Unclear about who sees the importer data. An ICT equipment importer is uncertain whether their own company name and purchasing relationship will be visible to end-users, and consequently postpones data submission.

Assumptions about transparency without consulting the delegated act. Because the delegated act per product category has not yet been published for every group, some companies fill in the uncertainty themselves — often more cautiously than necessary, causing them to incorrectly withhold data that will be requested later.

What you can document

  • An overview of which data the applicable delegated act for the company's own product group requests, as soon as it is published, with a separate note on what constitutes product information and what would be company information in that act.
  • An internal agreement on which employee or department supplies data to the party that compiles the passport, including what is and is not passed on — the breakdown from who is allowed to access which data from the digital product passport can serve as a basis.
  • A supplier agreement or addendum stating which data a supplier provides under Article 38 of the ESPR, and for what purpose — so that a supplier does not have to guess what happens with the data.
  • A documented assignment of data to the correct aggregation level: per product model rather than per internal recipe or process, aligned with which data goes into the digital product passport for electronics.
  • A procedure for the event that data proves to have been supplied incorrectly in too much detail or too broad a scope, so that this can be reviewed — see also I found an error in the product passport what now.

This is not legal advice. This page provides general information about the regulations that this platform covers. We are not familiar with your situation. If you are in doubt about your own case, consult a lawyer or the competent supervisory authority.

Written with AI based on the sources above, checked by a human on 2026-08-22. Is something incorrect? Let us know — corrections take priority.