elektropas.com

Who may view which data from the product passport?

Access differs by user type, not everyone sees everything

The digital product passport is not a single document that is the same for everyone: the ESPR is based on layered access, where the type of data determines who is allowed to view it. A consumer who scans the QR code sees different information than a market actor, a repairer, a recycler or a supervisory authority. The regulation establishes this principle in Article 11 (technical design and functioning of the digital product passport), but which data is exactly visible to which group will be further specified per product category. For electronics and ICT equipment, this has not yet been established; this will happen in the delegated act expected for this sector.

Who this applies to, and who it does not

This topic concerns access rights to the product passport itself: who is allowed to see which fields once the passport is active. It is not about which data must be included in the passport — that is regulated by Article 10 (requirements for the digital product passport), and that is a separate matter. It is also not about data portability between companies or about general GDPR obligations for personal data; those frameworks remain separate and are not replaced by the ESPR.

The layered access from Article 11 is a general principle that applies to all product categories within the ESPR, not just electronics. For each category individually — household appliances, mobile phones, batteries, textiles, and so on — a separate delegated act will specify which concrete data belongs to which category of access. As long as that act does not exist for electronics, there is no established list of who exactly may see what within this sector.

When this becomes concrete, and what applies until then

There is currently no fixed date for the delegated act that will specify this for electronics and ICT. The ESPR work plan for the 2025-2030 period mentions electronics as a category for which delegated acts are expected from 2027 onwards, but this is an expectation for the start of that process, not a commitment regarding a publication date. Until that act is published, Article 11 is established as a general framework — the principle of layered access applies — but the specific application for electronics (which field is visible to whom) is still pending. As soon as the delegated act for this sector is published, the date and content will be shown here.

How this will work in practice for electronics

For an importer or manufacturer already thinking about the passport, it is useful to establish a clear distinction between two types of data. On the one hand, information that is expected to become broadly accessible: basic product data, repair and maintenance information, environmental information that a buyer needs to make a purchasing decision. On the other hand, data that is likely to remain more restricted: technical specifications relevant to recyclers or dismantling companies, commercial information relevant only to supervisory authorities or customs, and possibly commercially sensitive data.

In practice, this means that setting up the data sources behind the passport would do well to take this distinction into account, even though the exact breakdown for electronics has not yet been established. Data that is demonstrably traceable to a specific target group (repairer, recycler, supervisory authority) can be labelled separately, so that when the delegated act appears, access levels can be applied without major restructuring. Anyone who thinks about this now will prevent the passport from having to be completely rebuilt later.

In addition, it is worth monitoring whether data included in the passport contains personal data or affects trade secrets. The ESPR regulates access to product information, but does so alongside existing rules on data protection and confidentiality — these remain fully in force and are not overridden by the passport.

Article 11 as basis, further specified per category

The principle of layered access is set out in Article 11 of the ESPR (Regulation (EU) 2024/1781), which concerns the technical design and functioning of the digital product passport. Article 10 of the same regulation describes the requirements the passport must meet in terms of content, including which data belong in it — this is the basis on which the access layers from Article 11 are subsequently applied. The precise implementation per product category, including electronics, follows from the delegated acts adopted by the European Commission for each sector.

What you can do now

For now, it is useful to organise your own product data in advance according to the type of user for whom they are relevant — consumer, repairer, recycler, supervisor — without anticipating a classification that has not yet been established. Keep an eye on the publication of the delegated act for electronics; as soon as it appears, the concrete access classification will be added to this page.

What this is based on

The regulation itself is on EUR-Lex. We provide references per statement; you do not have to take our word for it.

What you must concretely do

What is expected of you

The digital product passport is not a single block of information that is the same for everyone. The ESPR is based on layered access: some of the information is visible to everyone, some only to specific parties such as supervisory authorities, market actors or repairers. Article 10 of the ESPR (Regulation (EU) 2024/1781) names this distinction between publicly accessible information and information limited to specific target groups. Article 11 of the ESPR addresses how this is technically implemented: via access rights that are set per role in the data model.

Distinguishing between public and restricted data

For a company, this means that not all data that is supplied is automatically made public. Some data is intended for the consumer who scans the QR code, other data is intended for the supervisory authority carrying out a conformity check, and still other data is intended for the recycler who wants to know which materials have been processed at the end of the product's life. A company with 10 to 100 employees that has the passport compiled is well advised to determine in advance which data belongs in which layer — and not to leave this to an assumption afterwards. This overlaps with the question of which information must be in the passport anyway: see which data goes into the digital product passport for electronics.

Technically align access rights with the role of the user

Article 11 of the ESPR describes that the product passport is structured so that access to data is linked to the role of the person requesting the data: consumer, market actor, supervisory authority, or another party in the chain. In practice, a company notices this mainly with the supplier of the passport platform: that party must be able to demonstrate that the division into access levels actually works, and does not merely exist on paper. For a company itself, this means that it is important to know exactly who can ask for which data, before data is supplied — not after.

Shielding business-sensitive information without missing mandatory data

Some of the data that a manufacturer or importer supplies can be commercially sensitive: composition, suppliers, or technical specifications not intended for the open market. The ESPR provides scope to distinguish between what must be public and what can remain restricted to supervisory authorities, but that distinction must be substantiated and filled in. This directly relates to the question must I disclose commercially sensitive information about my electronics — a question that is dealt with separately and more extensively, but which plays a role immediately in the allocation of access rights.

Keep data current for every target group, not just for the consumer

Because different parties see different data, it is conceivable that an update to the passport is not immediately visible to everyone in the same way. A change in a technical data point that is only intended for supervisory authorities does not need to immediately affect the consumer view, and vice versa. This makes keeping data up to date something that involves multiple layers. More information on the update obligation itself can be found in how often must I update the data in the product passport.

Where things go wrong in practice

Everything is made public by default. A company supplies the full dataset without distinguishing between what is for the consumer and what is for the supervisory authority. The platform or software supplier then sets everything to 'publicly visible' because there was no clear instruction on which fields should remain restricted.

Business-sensitive data accidentally ends up in the public layer. Especially with composition data on components, or information about suppliers, this happens more often than one might think — because nobody established in advance that this specific field should be restricted.

There is no overview of who has which role. A company no longer knows precisely which party — supervisory authority, recycler, repairer — should have access via the product passport to which data, making it difficult to quickly demonstrate to a supervisory authority that the correct categorization has been made.

Access is not taken into account when the product range is modified. A new product model is added with the same data structure as an older model, without checking whether the access categorization still applies — resulting in sensitive information from the new model ending up in the wrong layer.

Confusion between language versions and access levels. At companies that sell in multiple language regions, it is sometimes assumed that a translated version of the product passport also requires a different access categorization, while the distinction between public and restricted is independent of language. See separately for the language aspect must I offer the product passport in multiple languages.

What you can document

  • An overview per product group of which data are publicly visible and which remain restricted to specific parties, including the justification for why a data point has been restricted.
  • A role categorization: which party (consumer, supervisory authority, recycler, repairer, economic operator) may see which data point, to be coordinated with the provider of the product passport platform.
  • A note with each data point marked as commercially sensitive, stating the reason — useful if a supervisory authority later asks about it.
  • A fixed contact point or process for when an access categorization needs to be adjusted, for example with a new product model or a modification to the data structure.
  • A reference to the underlying technical data, such as energy consumption or repair information, so that it is known in which layer these belong. See for example how do I record the energy consumption of a device and how is the repairability score of a device determined for the content of that data itself.
  • A procedure in case an incorrect categorization is discovered, aligned with the approach that also applies to other errors in the product passport: see I found an error in the product passport what now.

This is not legal advice. This page provides general information about the regulations that this platform covers. We are not familiar with your situation. If you are in doubt about your own case, consult a lawyer or the competent supervisory authority.

Written with AI based on the sources above, checked by a human on 2026-08-22. Is something incorrect? Let us know — corrections take priority.