Toy Digital Product Passport Requirements
What the EU Toy Digital Product Passport contains, when it applies, how model-level identity works and why factory technical-documentation data is not automatically passport data.
Navigate this page
- Direct answer
- Which products are covered?
- When does it apply?
- What information does the Toy DPP contain?
- Identifiers and data carrier
- Is the Toy DPP model, batch or item-level?
- Who can see what?
- Registry, storage and persistence
- Factory and storage addresses: required in technical documen
- Other toy-safety obligations are not automatically DPP conte
- What businesses can prepare now
- What the Toy DPP shows about DPPs
- Open questions and implementation pending
- Direct questions
- How we know
- Primary and official sources
- In this section
Direct answer
Regulation (EU) 2025/2509 creates an adopted Digital Product Passport for toys. The Regulation applies from 1 August 2030, while a group of implementation and governance provisions, including the Commission's DPP technical powers, apply from 1 January 2026.1
Before placing a toy on the market, the manufacturer must create a DPP. The passport corresponds to a specific toy model by default and contains mandatory information from Annex VI Part I, including the toy's unique product identifier, manufacturer and responsible economic-operator information, traceability identity, legal/compliance references, relevant standards and certificates, CE marking and specified allergenic-fragrance information.1
This is a safety and conformity-oriented model-level passport. It is not a Battery Passport with toy fields substituted into it.
For the wider category landscape, see Digital Product Passport Requirements by Product Category.
Which products are covered?
The Toy Safety Regulation applies to products designed or intended, whether or not exclusively, for use in play by children under 14 years of age, subject to the exclusions and specific boundaries set out in the Regulation and Annex I.1
The category boundary matters because not every product used by a child is legally a toy, and Annex I excludes specified products from the Regulation's toy scope.
The DPP obligation follows the product's status under the Toy Safety Regulation. The first implementation step is therefore to establish that the product is a toy within the Regulation before treating Annex VI as its mandatory passport schema.
When does it apply?
| Milestone | Date | What it means |
|---|---|---|
| Regulation adopted | 26 November 2025 | Regulation (EU) 2025/2509 adopted. |
| Published in Official Journal | 12 December 2025 | Official publication. |
| DPP technical/governance powers start applying | 1 January 2026 | Articles 49-55, among others, apply early, enabling implementation work before the main application date.1 |
| Main Regulation applies | 1 August 2030 | The Toy Safety Regulation, including the DPP obligation, applies generally from this date.1 |
| Old Directive repealed | 1 August 2030 | Directive 2009/48/EC is repealed as the new Regulation applies.1 |
| Certain existing EC type-examination certificates | Up to 1 February 2031 | Transitional validity may continue subject to the Regulation's conditions.1 |
This is another example of why adoption date, implementation date and application date should not be collapsed into one "deadline".
What information does the Toy DPP contain?
Article 19 requires at least the information in Annex VI Part I. Part II allows additional optional information.1
| Information territory | Mandatory position | Level | Legal basis | Practical explanation |
|---|---|---|---|---|
| Unique product identity | Unique product identifier of the toy | Model | Annex VI Part I(a) | Persistent identity for the model represented by the DPP. |
| Manufacturer | Manufacturer name/address and authorised representative where applicable, with UOI | Model | Annex VI Part I(b) | Legal operator identity. |
| Responsible economic operator | Name/address of the operator responsible under Regulation (EU) 2019/1020, with UOI | Model | Annex VI Part I(c) | Separates product identity from market-responsibility identity. |
| Responsibility statement | Passport issued under manufacturer's sole responsibility | Model | Annex VI Part I(d) | Makes responsibility explicit. |
| Toy traceability | Identification allowing traceability, including a clear colour image | Model | Annex VI Part I(e) | Helps identify the toy represented. |
| Commodity code | Commodity code where applicable | Model | Annex VI Part I(f) | Supports customs/Registry use. |
| Applicable Union law | References to all Union law with which the toy complies | Model | Annex VI Part I(g) | Conformity/legal reference layer. |
| DPP replacing other declarations | Where applicable, statement that DPP replaces the EU Declaration of Conformity under specified Union acts | Model | Annex VI Part I(h) | Avoids duplicate declaration architecture where the law allows replacement. |
| Standards / common specifications | References to relevant harmonised standards or common specifications used | Model | Annex VI Part I(i) | Evidence pathway for conformity. |
| Notified body / certificate | Where applicable, notified-body name/number and certificate reference | Model | Annex VI Part I(j) | Only where a notified body intervened. |
| CE marking | CE marking | Model | Annex VI Part I(k) | Safety/conformity signal is explicitly in the DPP dataset. |
| Allergenic fragrances | List of allergenic fragrances present and subject to the specified labelling rules | Model | Annex VI Part I(l) | Selected safety information, not a universal chemical inventory. |
| Communication channel | Communication channel required by Article 7(12) | Model | Annex VI Part I(m) | Consumer/operator communication route. |
| Backup service provider | Reference to DPP service provider hosting the backup copy | Model | Annex VI Part I(n) | Supports continuity and persistence. |
| Safety information and instructions | May be included | Model | Annex VI Part II | Optional DPP content rather than minimum Part I data. |
What the allergenic-fragrance field does not mean
Annex VI does not say the Toy DPP must contain an unlimited inventory of every chemical substance in every toy.
It specifically requires a list of allergenic fragrances that are present in the toy and subject to the particular labelling requirements identified by the Regulation.1
The wider Toy Safety Regulation contains extensive chemical and safety requirements. Those should not all be relabelled as DPP fields.
Identifiers and data carrier
Article 19 requires the passport to be connected through a data carrier to a persistent unique product identifier.1
Before placing a toy on the market, Article 22 requires the economic operator to upload the toy's UPI and UOI to the DPP Registry. For toys intended for release for free circulation, the Registry also stores the commodity code and communicates a unique registration identifier associated with the registered identifiers.1
The unique registration identifier is a Registry/customs mechanism. The Regulation expressly says communication of that identifier is not proof of compliance.1
The carrier itself is physically located on the toy or affixed label. Where the size or nature of the toy prevents that, the Regulation allows the carrier to be placed on packaging or accompanying documentation in accordance with the technical rules to be adopted.1
The DPP carrier must also be made visible to potential customers in distance sales through the relevant digital copy or identifier mechanism.
Three points should remain separate:
- UPI identifies the product under the DPP architecture
- UOI identifies the relevant operator
- data carrier connects the physical/digital sales context to the passport.
None of those statements means a GTIN is automatically mandatory for every toy DPP.
Is the Toy DPP model, batch or item-level?
The default is model-level.
Article 19 says the DPP corresponds to a specific toy model.1
There is a controlled exception. Where other Union law requires a DPP for the toy at batch level, the Toy DPP can correspond to that batch level. The Regulation also provides for a single DPP where other Union law creates overlapping DPP requirements.1
The safe public description is therefore:
model-level by default, with alignment to batch-level obligations where another applicable Union law requires it.
Do not call the Toy DPP item-level simply because an individual physical toy carries or is associated with a data carrier.
For the wider comparison, see Model, Batch or Item Level for a Textile Passport, the current page to expand into the cross-category reference.
Who can see what?
Article 19 identifies the broad actor groups that may access the Toy DPP:
- consumers or other end users
- market surveillance authorities
- customs authorities
- notified bodies
- the Commission
- other economic operators.1
But it does so according to access rights to be set under Article 49(1)(d).
Article 49 gives the Commission power to adopt the detailed technical DPP rules, including:
- one or more data carriers
- carrier layout and position
- applicable technical standards
- the actors that have access to data and which data they can access
- actors that may create or update information
- detailed updating arrangements.1
As at 1 September 2026, those category-specific detailed access arrangements remain an implementation dependency.
So the adopted law tells businesses which kinds of actors the system must support, but it is not safe to invent a complete field-by-field public/restricted access matrix before the relevant delegated rules are adopted.
Registry, storage and persistence
The Toy DPP uses the common ESPR Registry architecture without turning the Registry into the full central passport database.
Article 22 requires the UPI and UOI to be uploaded to the Registry and, for relevant imports, connects the Registry to customs verification through the unique registration identifier.1
Article 20 requires the passport to operate as an interoperable system and carries forward the DPP technical principles on data storage, persistence and service providers.12
The EU DPP Registry became operational on 20 July 2026.3
The useful separation is:
- passport: the fuller toy information and evidence-facing data layer
- Registry: registered identifiers and the information needed for regulatory/customs use.
Factory and storage addresses: required in technical documentation, not automatically a DPP field
This is one of the most important boundaries in the Toy Regulation.
Annex V, which governs technical documentation, requires the addresses of the places of manufacture and storage.1
Annex VI Part I, which lists the mandatory Toy DPP information, does not simply reproduce that factory/storage-address requirement.1
Therefore:
Factory or storage addresses required in the technical documentation are not automatically mandatory Toy DPP fields.
This is a strong example of why businesses should not take information required elsewhere in product law and silently move it into the passport schema.
A manufacturer address is a mandatory Annex VI DPP field. The separate addresses of the places of manufacture and storage are a technical-documentation requirement.
For the cross-category factory/origin question, use the future Factory / Origin reference rather than turning this article into a universal factory-data guide.
Other toy-safety obligations are not automatically DPP content
The Regulation contains extensive requirements on:
- essential safety
- chemical restrictions
- warnings
- conformity assessment
- technical documentation
- CE marking
- traceability
- market surveillance.
Some of these connect directly to mandatory Annex VI fields, such as CE marking, standards and notified-body certificates.
Others remain obligations elsewhere in the law.
The passport must therefore be built from Annex VI plus the specific cross-references in Article 19, not from a blanket copy of the entire technical file.
What businesses can prepare now
PREPARE
Confirm toy scope. Use the Regulation's legal definition and exclusions rather than a commercial product category alone.
Build model identity. The default DPP is for a specific toy model.
Structure UPI and operator identity. Keep UPI, UOI and Registry registration identity separate.
Map Annex VI Part I. Prepare governed sources for operator identity, traceability image, legal references, standards, certificates, CE marking and applicable allergenic-fragrance data.
Separate technical documentation from DPP content. Keep factory/storage addresses and other Annex V records available for compliance without automatically publishing them as passport fields.
Prepare backup/service-provider continuity. Annex VI includes the backup DPP service-provider reference.
Design evidence links. Standards, certificates and conformity statements need stable provenance and scope.
WATCH
- Article 49 DPP delegated acts
- detailed access-right allocation
- final data-carrier specification and positioning rules
- technical standards and service-provider requirements
- Registry/customs implementation
- amendments to Annex VI or other DPP information before application.
IMPLEMENTATION DETAIL STILL PENDING
The Regulation has already adopted the model-level DPP, the minimum Annex VI dataset and the 1 August 2030 application date.
The main open layer is technical implementation under Article 49, especially access rights, carrier details and updating roles.
What the Toy DPP shows about DPPs
The Toy DPP demonstrates a model-level safety and conformity-oriented passport.
That is materially different from:
- the Battery Passport's hybrid model + individual lifecycle architecture
- the detergent DPP's model-level ingredient/substance and compliance architecture.
The shared idea is a governed digital passport system. The product information remains category-specific.
Open questions and implementation pending
As at 1 September 2026:
- Detailed category-specific access rules under Article 49 remain to be adopted.
- Final carrier choice/layout/positioning details are subject to the Article 49 technical rules.
- Detailed create/update roles may be supplemented by delegated action.
- The Registry/customs technical workflow will need to be implemented operationally before the 2030 application date.
- Annex VI can be amended under the Regulation's delegated powers, so the adopted dataset should be monitored rather than treated as permanently frozen.
Direct questions
When does the Toy DPP apply?
The Toy Safety Regulation applies from 1 August 2030, including its model-level DPP obligation.1
Is the Toy DPP item-level?
No. The default passport corresponds to a specific toy model. It can align to batch level where another applicable Union law requires a batch-level DPP.1
Is factory information part of the Toy DPP?
The manufacturer's name and address are mandatory DPP data. The addresses of places of manufacture and storage are required in Annex V technical documentation, but are not automatically part of the mandatory Annex VI DPP field set.1
What conformity information is included?
Annex VI includes references to applicable Union law, relevant harmonised standards or common specifications, notified-body and certificate information where applicable, and CE marking.1
Does the Toy DPP contain chemical information?
It includes specified allergenic-fragrance information where those fragrances are present and subject to the Regulation's labelling requirements. That should not be expanded into a claim that the DPP contains every chemical in the toy.1
Does the Registry prove that a toy complies?
No. Article 22 explicitly says the Registry's communication of a unique registration identifier is not proof of compliance.1
How we know
Material claims were checked against Regulation (EU) 2025/2509 and current official DPP infrastructure material on 1 September 2026.
In this section
The approved Passport resources that sit under this page.
Keep exploring
The questions this page usually raises next.
- Go deeperSpecific questionWhich allergen information is actually in the Toy DPP?Toy Digital Product Passport Requirements naturally raises this next question.
- Related questionCross-category referenceIs this passport model, batch, product-type or item level?Toy Digital Product Passport Requirements naturally raises this next question.
- Related questionCross-category referenceWho can see the data?Toy Digital Product Passport Requirements naturally raises this next question.
Does this reach your products?
Give ActivateDigital one product and it works out which obligations apply from the product's own character, and says which it cannot decide.
Help someone else make sense of product passports.
Primary and official sources
https://single-market-economy.ec.europa.eu/single-market/digital-product-passport_en