elektropas.com

What data must I request from my electronics supplier?

Your supplier provides the building blocks for the passport

The data that ends up in the digital product passport are essentially the same data that already exist somewhere in the supply chain: material composition, substances of concern, information on repair and durability, and data for uniquely identifying the product. Whoever as an importer, assembler or brand owner places a product on the EU market is responsible for the passport, but usually does not have that information in-house — it sits with the manufacturer of components or the final product further down the chain. Article 38 of the ESPR (Regulation (EU) 2024/1781) places an obligation on actors in the supply chain to pass on the information needed for compliance to those entitled to it. In practice, this means that a supplier can be asked for precisely the data that Article 10 of the ESPR names for the passport, as soon as it has been established for the product category what that data specifically are.

For whom this applies, and for whom not yet

This obligation affects actors within the EU supply chain of products that fall under a delegated act of the ESPR: manufacturers, importers, distributors, authorised representatives and fulfilment service providers. For electronics and ICT equipment, this is not currently the case — there is no delegated act published that specifies which data for this category must exactly be in the passport. This means that the obligation under Article 38 is not yet enforceable for this sector, and that a supplier cannot be required to provide a data set that does not yet exist. It also does not mean that there is nothing to do: the structure of the obligation is already established, only the content per category is not yet. For product categories for which a delegated act has already been adopted, the obligation now applies in full.

The date is not yet fixed

There is no fixed date on which the request for supplier data for electronics becomes mandatory. The ESPR Work Plan 2025-2030 mentions electronics and ICT equipment as a category, per subcategory, with delegated acts expected from 2027 onwards. This is an expectation from the work plan, not a commitment to a specific date for a specific product. Until a delegated act for your own subcategory is published, the general provisions of the ESPR do apply as a framework, but the detailed list of mandatory data on which a concrete request to a supplier could be based is missing. As soon as that act appears, the date and content will be updated here.

What this means for your approach

The order in which this is usually tackled begins by reviewing your own position: which sub-category of electronics or ICT equipment the product falls under, and whether a delegated act has already been published for it. As long as that is not the case, a detailed data request from a supplier is not yet necessary, but an inventory of what is already available is worthwhile. A second step is to check what information the supplier already maintains as standard: material lists, safety data sheets, test reports, certificates on substances of concern, and documentation on repair or disassembly. A third step is to check whether the product or its components already have a unique identification — a serial number, batch code or similar identifier — because the passport must be linked to it. A fourth step is to establish this contractually: who supplies which part of the data, in what format, and how is it recorded that this data remains current over the period during which the passport must be available. Because a passport must generally remain accessible for a longer period after the delegated act is published, it is practical to make agreements with suppliers such that data can still be requested after the initial delivery, for example in the event of a change in composition or an additional test.

Where this follows from: Article 38 and Article 10 of the ESPR

The obligation to pass on information through the supply chain is set out in Article 38 of the ESPR (Regulation (EU) 2024/1781). That article is addressed to actors in the supply chain and obliges them to provide relevant information to the person responsible for ensuring compliance with product requirements. What information that is in substance follows from Article 10 of the ESPR, which sets out the requirements for the digital product passport itself: the type of data a passport must contain, and the way in which that data must be made accessible. Both articles only apply concretely to a product once the delegated act for the relevant product category has been adopted; that act specifies what is specifically required for electronics or a sub-category thereof.

What to do now

Those who already work with suppliers can, without waiting for the delegated act, map out which data on materials, substances and repair are already available and where the gaps are. This saves time once the act for their own sub-category is published and the obligation becomes concrete. This page will be updated once the relevant delegated act has been published.

What this is based on

The regulation itself is on EUR-Lex. We provide references per statement; you do not have to take our word for it.

What you must concretely do

What is expected of you

When purchasing electronics or ICT equipment from a supplier, you as a buyer ultimately bear responsibility for the digital product passport that comes with the product. Article 38 of the ESPR (Regulation (EU) 2024/1781) establishes that actors in the supply chain must provide each other with the data needed to comply with the regulation. In practice, this works through what is requested from a supplier and why.

The data that substantively fill the passport

Article 10 of the ESPR describes what type of information a product passport must be able to contain: including data on composition, origin of materials, repair and recycling options, and technical characteristics that are specified per product group through a delegated act. For a company with 10 to 100 employees, this means the supplier is asked to provide precisely those data that are relevant for your own product category — not a general product description, but the specific data points that future regulations for that category will establish. Which data points these are exactly differs per product group and is determined in a delegated act; until one is available, it is wise to start by inventorying which data the supplier already records anyway.

Data that are accurate at the time of delivery

It is not enough that a supplier provided data at some point; the data must correspond to the product as it is actually delivered. For a mid-sized company, this means there must be a fixed way to check whether what the supplier states aligns with practice — especially when a product consists of multiple parts from different sub-suppliers. How this check is practically arranged is described in how do I check whether my supplier's data is correct.

Data that remain accessible further down the chain

Article 38 focuses not only on the data themselves, but also on the fact that other actors in the supply chain must be able to rely on the information remaining available. For a company that itself supplies to another party — a wholesaler, an assembly company — this means your own supplier is asked to not only provide data, but also to indicate how long and in what way that data remain current and retrievable.

Data on parts that do not come directly from the supplier

A supplier often sources parts from third parties itself. For an importer or manufacturer, it is practically relevant to know whether your own supplier manages this sub-supply itself or not, and whether data on sub-contractors are included in what is requested. This is one of the points where the overview per product category becomes unclear most quickly, especially if it has not been established in advance who supplies which data; see must my subcontractor also provide product passport data.

Where things go wrong in practice

A number of situations come up repeatedly in practice among companies requesting data from their supplier for the first time.

The supplier provides incomplete data. Often only what already exists is provided — a technical datasheet, a declaration of conformity — without this matching what the passport specifically requires.

Data are provided once and then not updated thereafter. A product change at the supplier, for example a different sub-supplier for a component, is not automatically communicated to the party that compiles the passport.

There is no contractual agreement on who supplies which data. In case of a dispute — or simply in case of ambiguity — it turns out that it was never established who is responsible for which part of the information.

Composition varies per batch or delivery, without having agreed in advance how this is handled in the data. This applies in particular to raw materials or components that do not come from a single source; see my product varies per batch how do I fill in the passport then.

Multiple suppliers provide the same component, with different data or different levels of detail, without it being agreed how this data together forms one passport; see multiple suppliers for a product.

What you can document

To prevent the request for data from the supplier requiring improvisation each time, it is practical to lay down a number of points — as a separate document or as part of existing purchasing agreements.

  • A list of the data points requested per product category, based on what Article 10 of the ESPR describes for that category, so that the supplier knows what is concretely expected.
  • An agreement on the updating of data, including the moment at which the supplier must report a change in the product.
  • A contractual provision on the delivery of passport data, included in the purchasing contract itself rather than in separate correspondence; see how do I record the delivery of passport data in my purchasing contract.
  • A fixed procedure for checking the supplied data, so that discrepancies between what has been stated and what is actually delivered are noticed in time.
  • Agreements on subcontractors and sub-suppliers, in particular who supplies which part of the data when a supplier does not itself produce all components.
  • A procedure in case the supplier does not or incompletely deliver, including an escalation step; see my supplier does not deliver the data — what can I do.

For companies importing electronics from outside the EU, an extra layer comes into play here: the role of importer within the supply chain brings its own obligations that go beyond merely passing on data from a non-European manufacturer; this is described separately in what does the product passport mean if I import electronics from outside the European Union.

What is consistently lacking here is not so much the willingness to deliver data, but a fixed structure in which it has been determined in advance which data, in what form, and at what moment are expected. That structure is precisely what a purchasing contract or a fixed template for data requests can provide, and prevents the question "what must I request from my supplier" being reinvented with each new product.

This is not legal advice. This page provides general information about the regulations that this platform covers. We are not familiar with your situation. If you are in doubt about your own case, consult a lawyer or the competent supervisory authority.

Written with AI based on the sources above, checked by a human on 2026-08-22. Is something incorrect? Let us know — corrections take priority.