Skip to content
Knowledge / Evidence & Trust

Who Checks Digital Product Passport Information? Registration, Evidence, Conformity Assessment and Market Surveillance

Understand who checks Digital Product Passport information and the difference between Registry validation, evidence, conformity assessment and market surveillance.

Last verified
Share
LinkedIn X Email
Navigate this page

There is no single universal “DPP verifier”. Different checks answer different questions. The EU Registry performs defined registration checks. Proof of registration shows that the registration obligation for that passport has been fulfilled. Evidence supports the facts you publish. Product-specific law can require a conformity-assessment procedure. Market-surveillance authorities check compliance under the applicable law. A successful Registry submission is not certification of every product claim in the passport.

The four checks people keep calling “verification”

LayerQuestion it answersWhat it does not prove
Registry checksCan this DPP registration be accepted against the Registry’s defined checks?That every product fact is substantively true or that the product is compliant in every respect
Evidence / substantiationWhat supports this product fact and does the evidence cover this product and scope?That a formal conformity procedure has been completed unless that evidence is part of one
Conformity assessmentHas the product’s compliance with applicable ecodesign requirements been assessed using the procedure specified for that product rule?That every future DPP regime uses the same procedure or a third party
Market surveillanceDoes the product/economic operator comply with applicable Union rules, and is corrective action needed?That a vendor, Registry or QR code has taken over the authority’s role

The clean implementation rule is to keep these four states separate in your system.

1. The Registry checks the registration, not the whole product

Commission Implementing Regulation (EU) 2026/1778 sets out the DPP Registry’s operational rules. Article 8 describes automated checks around matters including semantic conformity, coherence of mandatory Registry data where relevant, the required model/batch/item granularity, commodity-code validity where relevant and the backup-provider link where relevant.

Those are meaningful checks. They are not the same thing as proving that a recycled-content percentage, carbon value, test result or repairability claim is substantively correct.

The Regulation itself draws that boundary. Its Registry framework says successful automated checks should not be treated as proof of compliance with the requirements applicable to the product.

If your internal system has a status called verified, split it. Useful states are more specific:

  • registry_accepted
  • evidence_supported
  • conformity_assessed
  • market_surveillance_checked

Those states are not interchangeable.

For the operational registration workflow, use the Registry pages in the Knowledge estate. This article stays at the verification boundary rather than re-owning Agent 3’s Registry territory.

2. Proof of registration proves registration

Article 9 of the Registry Implementing Regulation gives proof of registration a narrow purpose: it serves as evidence that the registration obligation for that DPP has been fulfilled.

That is useful commercial evidence. It can show a buyer, internal audit team or other third party that the required registration event happened.

It should not be renamed “DPP compliance certificate”. It is not a certificate that every field is correct and it is not a substitute for product evidence or a required conformity-assessment procedure.

The proof of registration page owns the proof document itself. This page explains where that proof sits in the wider checking stack.

3. The economic operator still owns the accuracy of what it submits

Registry checks do not transfer responsibility to the Commission. Article 19 of the Registry Implementing Regulation makes the verified economic operator responsible for the accuracy and completeness of information submitted at registration and for keeping Registry information accurate, complete and up to date.

That is a useful control for supplier and vendor arrangements. A third party may perform registration actions where the law allows it, but moving the keystrokes does not automatically move the operator’s responsibility.

The same principle should shape product evidence. If a supplier document supports a field, keep the supplier document. If a lab report is the source, keep the lab report and its scope. Do not keep only the final number.

For that layer, see certificates, declarations and test reports and what a passport field can and cannot prove.

4. Conformity assessment is product-specific

ESPR requires product delegated acts to specify the applicable conformity-assessment procedure for the ecodesign requirements concerned. The framework can use internal production control or other conformity-assessment modules depending on the product rule.

The Commission’s DPP FAQ therefore says there is no universal requirement for third-party certification or conformity assessment of all DPP information. Future product rules may require third-party involvement for particular product groups or data points where the underlying rule justifies it.

That gives businesses two rules:

  1. do not promise “independently certified DPP data” unless you can say what was certified, by whom, against which requirement and for which scope; and
  2. do not assume every future DPP field will need a notified body or accredited third party.

5. Harmonised standards can support conformity, but only within their coverage

ESPR Article 41 gives harmonised standards a defined legal effect. DPPs that conform to harmonised standards whose references are published in the Official Journal can benefit from a presumption of conformity with Articles 10 and 11 to the extent those requirements are covered by the standards.

That is important and narrow.

A harmonised standard can help establish conformity with covered technical requirements. It does not by itself decide which product group needs a DPP, what the product’s mandatory field set is or when a future delegated act applies.

The detailed standards position belongs on the existing standards pages, not here.

6. Market surveillance is a different control again

Market-surveillance authorities enforce applicable product rules. ESPR gives authorities powers and provides for corrective action where products or economic operators do not meet applicable requirements. The DPP can make information and documentation easier for authorities to reach, but it does not replace market surveillance with an automated “pass/fail” service.

That distinction matters when building customer-facing status labels. Avoid a single green badge called EU verified unless the exact basis is displayed beside it.

A more honest design says what happened:

  • Registered in the EU DPP Registry
  • Source evidence recorded
  • Conformity assessment completed under [instrument/procedure]
  • Market-surveillance outcome [if one exists and can lawfully be stated]

Each is useful. None should impersonate the others.

A worked example: one recycled-content field

Imagine a future product rule requires a recycled-content value.

Evidence layer: supplier declarations, chain-of-custody records, calculation method or test evidence support the value. Conformity layer: the applicable product act determines the assessment procedure for the requirement. Registry layer: the Registry checks the data that the registration rules require and returns a registration identifier after successful verification. Proof layer: the operator can generate proof that the DPP registration obligation was fulfilled. Surveillance layer: an authority may later test the product, ask for documentation or otherwise assess compliance.

Calling all five “verification” hides the decision a business actually needs to make.

What is settled

  • Registry registration now has defined operational checks under Implementing Regulation 2026/1778.
  • Proof of registration has a defined, narrow evidential purpose.
  • The verified economic operator remains responsible for accuracy and completeness of submitted registration information.
  • ESPR product delegated acts specify the conformity-assessment procedure for the requirements they create.
  • There is no universal current rule requiring third-party certification of all DPP information.

What remains product-specific

  • which conformity-assessment module a future product act will require;
  • whether a third party is required for a particular requirement or data point;
  • what technical standards create presumption of conformity once references are published and for what coverage; and
  • what evidence is sufficient for a specific factual claim in a specific regime.

What a business can prepare now

Build separate controls for:

  • source evidence;
  • data approval;
  • Registry submission;
  • proof of registration;
  • conformity-assessment records; and
  • authority requests or surveillance outcomes.

Keep provenance: who supplied a value, what document supported it, its scope, effective date and review status.

Avoid:

  • “EU verified” as a generic product badge;
  • “registration = compliance” logic;
  • deleting source evidence after the value is copied into a passport; and
  • assuming every field needs third-party certification.

What would change this page

Re-verify when:

  • the Registry verification rules are amended;
  • a product delegated act specifies a new conformity-assessment approach;
  • Commission FAQ question 25 changes;
  • new market-surveillance implementation materially changes the DPP checking model; or
  • new harmonised-standard references change the scope of presumption of conformity.

Keep exploring

The questions this page usually raises next.

Does this reach your products?

Give ActivateDigital one product and it works out which obligations apply from the product's own character, and says which it cannot decide.

Worth sharing?

Help someone else make sense of product passports.

LinkedInXEmail

Sources and legal basis

  • Commission Implementing Regulation (EU) 2026/1778, especially Articles 8, 9 and 19.

https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32026R1778

  • Regulation (EU) 2024/1781 (ESPR), especially Articles 4, 9, 41 and the conformity/enforcement provisions.

https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1781

  • European Commission DPP FAQ, especially question 25.

https://single-market-economy.ec.europa.eu/single-market/digital-product-passport/explore-our-faqs_en