must my subcontractor also provide product passport data
Yes, in most cases a subcontractor also supplies data
Whoever engages a subcontractor to produce, process or assemble components is not off the hook: the ESPR places the obligations for the digital product passport with the manufacturer, but that manufacturer can only supply that information if the parties in its supply chain — including a subcontractor — make the underlying data available. Article 38 of the ESPR (Regulation (EU) 2024/1781) describes this as a requirement for actors in the supply chain: whoever has relevant information about a product or component becomes part of the chain that must feed the passport. This does not mean that the subcontractor itself draws up or publishes a passport — that responsibility remains with the manufacturer — but it does mean that the data the subcontractor possesses must reach the chain somewhere.
Who this applies to, and who it does not
This applies especially to manufacturers who have parts produced or processed by a third party, and to importers who place an assembled product on the market without themselves having insight into every production step. The obligation under Article 38 is directed at actors who actually have relevant information — think of material composition, origin of raw materials or technical properties of a component. A subcontractor who carries out purely executive work without its own data about the product (for example only packaging or transporting) generally has little or nothing to supply. Also, this does not automatically apply to every electronics category: the precise content of the passport — and therefore also which data must be retrieved in the chain — is laid down per product group in a delegated act, as described on the page about what a delegated act is and why it determines what must be done. Without that act, there is as yet no passport obligation for a specific product category, and therefore no concrete delivery obligation for the subcontractor within that category.
When this takes effect is not yet fixed
There is no fixed date yet for when this obligation applies to electronics and ICT equipment. The ESPR itself is established, but the delegated acts that determine per product category which data are mandatory and from when are phased in from 2027 onwards, according to the European Commission's work plan for the period 2025-2030. Until a delegated act for a specific electronics category is published, there is no legal obligation to supply passport data — not even for subcontractors. What is already established is the principle from Article 38: once the passport becomes mandatory for a category, the chain of data supply — including subcontractors — is included in it. More about the planning is on the page about when the product passport becomes mandatory for electronics.
What this means for your approach
The first step is to check whether the product itself will fall under a delegated act; the page about or the digital product passport applies to the company's own electronics provides a starting point for this. If so, the next step is to map out which subcontractors and suppliers have data that is relevant to the passport — material composition, origin, repair data, or other elements that Articles 9 and 10 of the ESPR name as content of the digital product passport. After that, it is practical to document who supplies which data, in which format and at what time; this is best done through a contractual agreement, as described on the page about recording the supply of passport data in the procurement contract. For subcontractors, essentially the same applies as for suppliers in general: without clear agreements, there is a risk that data will be supplied late, incomplete or not at all. Those already facing this issue will find on the page about what to do if a supplier does not provide the data a description of possible next steps.
The legal basis: Article 38, 27, 9 and 10 of the ESPR
The obligation for actors in the supply chain to provide relevant information is laid down in Article 38 of the ESPR (Regulation (EU) 2024/1781). Article 27 additionally describes the obligations of manufacturers themselves, including the responsibility to compile and make available the digital product passport — a task that in practice is not feasible without data from the chain. What must be included in the passport follows from Article 9 and Article 10 of the ESPR, which set out the general requirements for the digital product passport and its contents. Together, these articles form the basis for the understanding that a subcontractor who holds relevant product information is in most cases involved in providing it, without the ultimate responsibility for the passport falling on them.
What to do now
If you are already working with subcontractors, it is best to start by inventorying which data those subcontractors record about materials, composition and origin, and to start this conversation now — even though the exact obligation is still to be set out in a delegated act that has yet to be published. This creates time to make arrangements before the obligation actually comes into force, rather than only responding once the date is known.
What this is based on
- Regulation (EU) 2024/1781 (ESPR), Article 38 (requirements for actors in the supply chain)
- Regulation (EU) 2024/1781 (ESPR), Article 10 (requirements for the digital product passport)
- Regulation (EU) 2024/1781 (ESPR), Article 27 (obligations of manufacturers)
- Regulation (EU) 2024/1781 (ESPR), article 9 (digital product passport)
The regulation itself is on EUR-Lex. We provide references per statement; you do not have to take our word for it.
What you must concretely do
What is expected of you
A product passport does not come from a single source. The manufacturing data, the origin of components, the repair and recycling information — that is distributed throughout the chain, including at parties that are not themselves designated as a "manufacturer". The ESPR recognizes this and therefore lays down requirements in Article 38 (Regulation (EU) 2024/1781) for actors in the supply chain, in addition to the obligations that Article 27 places on the manufacturer itself.
Make information available to whoever compiles the passport
If you supply a component or module for an electronic product, you may be asked to provide information that is relevant to the passport of the final product. Article 38 of the ESPR identifies this as a requirement for actors in the supply chain. For a company with 10 to 100 employees that operates as a subcontractor, this means in practice: the data needed to comply with Article 10 of the ESPR (the content of the digital product passport) must come from somewhere, and if the subcontractor does not provide it, the manufacturer or importer must reconstruct or request it themselves. The latter takes time and is error-prone.
The manufacturer remains ultimately responsible
Article 27 of the ESPR places the obligations for the passport with the manufacturer. This does not change because part of the product is made by a subcontractor. The manufacturer who provides or has the passport compiled remains the point of contact for the data contained in it — even if that data actually comes from a supplier. For companies working with subcontractors, this means that responsibility does not automatically shift to whoever makes the component. What can shift is the practical task of requesting, checking and passing on the correct data.
Subcontractor is not automatically a "manufacturer"
Whether a subcontractor themselves falls under the obligations of Article 27 depends on the role that this party plays in the chain — does the party make its own product that is placed on the market, or does the party supply a component to another party that places the final product on the market. This distinction is not predetermined for every cooperation arrangement. For those unsure whether their own product falls under the digital product passport at all, it is useful to first check whether the product falls under the digital product passport for electronics, before the question about subcontractors is explored.
Where things go wrong in practice
The subcontractor supplies only physical components, not data. A production contract often covers specifications, delivery times and quality requirements, but not who documents the origin or material data needed for the product passport. If this has not been agreed, the data requirement only arises when the product passport actually has to be compiled — often too late.
The subcontractor in turn works with suppliers. A component produced by the subcontractor is itself made up of raw materials or sub-components from third parties. The question "where does this come from" can then be several layers deep in the chain, and by definition no one in the supply chain has visibility of the whole picture.
There is no contractual agreement on delivery, only a verbal expectation. Without a documented agreement, there is little leverage if the subcontractor does not deliver the data, delivers it late, or delivers it incompletely. This problem is substantively similar to the situation in which a supplier does not provide the data, and the approach — documenting what is needed and when — is also the starting point here.
Multiple subcontractors supply the same component, with slightly different compositions. When procuring the same component from different suppliers, the material composition may differ slightly, while the product passport expects one set of data per product. This applies in a similar way as with multiple suppliers for the same component.
The supplied data is not checked. A subcontractor supplies a list of materials or a certificate, and that data goes into the product passport unseen. If a component turns out to be incorrect, the inaccuracy is attributed to whoever compiled the product passport — not automatically to the subcontractor who supplied the data.
What you can document
- An overview of which data per component is required, derived from what article 10 of the ESPR expects from a digital product passport. That overview can serve as a permanent annex to every new contract with a subcontractor or supplier, similar to the question what data is requested from an electronics supplier.
- A contractual provision on delivery, form and timing. When, in what format, and upon which change in the component again. For the precise wording of this, there is a worked example in agreements on passport data in the purchase contract.
- A documented verification step before supplied data is incorporated into the product passport — who reviews the data and on the basis of which underlying documents. See also how supplied data is checked for accuracy.
- A list of subcontractors and suppliers per component, including who supplied which information and when. This makes it traceable where a data point comes from if a question arises about it later.
- A procedure for batch changes or composition switches, so that an adjustment at the subcontractor does not leave an outdated product passport unnoticed — relevant for products that vary per batch.
- A note of the agreement made if a subcontractor does not want to cooperate with the requested data supply, including the alternative that was chosen. This aligns with the approach described under what to do if a supplier does not want to adjust the purchasing terms.
This is not legal advice. This page provides general information about the regulations that this platform covers. We are not familiar with your situation. If you are in doubt about your own case, consult a lawyer or the competent supervisory authority.
Written with AI based on the sources above, checked by a human on 2026-09-05. Is something not correct? Let us know — corrections take priority.