A Product Has Been Recalled. What Happens to Its Digital Product Passport?
A DPP update does not replace a product recall. See how consumer notification, Safety Business Gateway, passport corrections and EU Registry updates stay separate.
Navigate this page
- Overview
- Direct answer
- The recall system has its own mandatory channels
- Consumers have to be notified directly where they can be ide
- A recall notice has prescribed content
- What does ESPR add when the product also has a DPP?
- The EU Registry is another record to check
- The first job is to identify exactly which products are affe
- Do not overwrite the evidence that explains what happened
- A recall and a withdrawal are not the same thing
- The passport can make the recall easier without becoming the
- A safe operational sequence
- What ActivateDigital should and should not do
- Direct questions
- What would change this page
- Try it on one product
- Primary and official sources
- Keep exploring
A product recall and a Digital Product Passport are different legal systems. A DPP can help identify the affected product and keep product information current, but it does not replace the recall notice, consumer notification or Safety Business Gateway duties that apply to a dangerous product.
Direct answer
A recall does not turn the Digital Product Passport into the recall system.
For products within the General Product Safety Regulation, GPSR, or to the extent GPSR applies alongside sector-specific product law, a dangerous product can trigger duties to:
- take corrective action, including withdrawal or recall where appropriate
- inform affected consumers
- report the dangerous product and corrective action to market-surveillance authorities through the Safety Business Gateway
- use the prescribed recall-notice framework
- offer the remedies required by the applicable recall rules.
Those duties exist independently of the DPP.
At the same time, a DPP that is legally required under ESPR has to contain data that are accurate, complete and up to date. The EU Registry regulation separately requires Registry registration information to be kept accurate, complete and up to date and supports versioning and logging of changes.
So a recall creates two parallel jobs:
product-safety response
and
passport / registration accuracy.
They can interact. They should not be collapsed into one workflow.
The practical rule is:
Do the recall through the legal recall channels. Then assess whether the DPP or Registry data also need to change. Never assume updating the passport is enough to notify consumers or authorities.
The recall system has its own mandatory channels
GPSR Article 9 gives manufacturers a clear duty when they consider or have reason to believe a product they placed on the market is dangerous.
The manufacturer must immediately:
- take the corrective measures necessary to bring the product into conformity, including withdrawal or recall as appropriate
- inform consumers in accordance with the GPSR recall and safety-warning provisions
- inform the market-surveillance authorities of the Member States where the product has been made available through the Safety Business Gateway.
Importers and distributors have corresponding duties in the situations set out in the Regulation.
The Safety Business Gateway is therefore not optional workflow software. The Commission's 2025 practical guidelines describe it as the portal businesses must use for the reporting obligations covered by the GPSR.
A DPP link on the product does not replace that authority notification.
A field in the DPP saying RECALLED does not replace the consumer notification.
A QR code that leads to a warning does not, by itself, satisfy the direct-contact duty where affected consumers can be identified.
Consumers have to be notified directly where they can be identified
GPSR Article 35 says that in the case of a product safety recall, affected consumers who can be identified must be notified directly and without undue delay.
Where not all affected consumers can be contacted directly, the responsible actors must disseminate a clear and visible recall notice or safety warning through other appropriate channels with the widest possible reach.
The Regulation names examples including:
- the company's website
- social media
- newsletters
- retail outlets
- other communication channels where appropriate.
That is a much broader communication obligation than “make the DPP correct”.
The DPP may be one useful route for somebody who still has the physical product, but the recall duty is designed to reach people rather than wait for them to scan.
This is consistent with the evidence already covered in What a scan actually tells you: a resolver log is not a substitute for a known customer-contact route.
A recall notice has prescribed content
GPSR Article 36 sets out what a written product-safety recall notice must contain.
Among other things, the notice needs to identify the recalled product, explain the hazard, tell consumers what action to take and describe the available remedy. It also has language requirements tied to the Member States where the product was made available.
That matters for DPP design because a generic “product status: recalled” field is not the same thing as the legally required recall notice.
A business might choose to make the recall notice reachable from the DPP as an additional service to the product holder.
That can be useful.
It should be labelled as additional distribution of the recall information, not as the sole legal recall mechanism unless the applicable law expressly allows that outcome.
What does ESPR add when the product also has a DPP?
ESPR contains its own corrective-action duties for products covered by delegated acts adopted under it.
A manufacturer that considers or has reason to believe that such a product is not in conformity with the applicable ecodesign requirements must, without undue delay, take the necessary corrective action to bring it into conformity, or withdraw or recall it if appropriate, and inform the relevant market-surveillance authorities.
Importers have corresponding duties.
Separately, Article 9 says the data in the DPP must be accurate, complete and up to date.
Those rules mean a business cannot treat the passport as frozen merely because the physical product has already been sold.
But the legal consequence of a recall is not automatically:
delete the DPP
or
replace the existing DPP with a recall webpage.
The applicable product law still controls DPP availability, access and lifecycle.
ESPR expects product-specific delegated acts to specify how long the DPP remains available, with the period corresponding at least to the expected lifetime of the product.
There is no general horizontal recall exception in that rule saying a recalled product's passport should disappear.
That points towards a sensible operational principle:
Keep the product identity and passport history intact unless the applicable law tells you otherwise. Correct or add the information that needs to change rather than making the record vanish.
That sentence is an implementation principle based on the legal architecture, not a substitute for product-specific recall law.
The EU Registry is another record to check
The Registry does not hold the full DPP, but it does hold registration data around it.
Commission Implementing Regulation (EU) 2026/1778 says the verified economic operator must keep Registry information accurate, complete and up to date.
Article 10 says changes to registration data are logged, reflected in registration status and versioned with Commission timestamps.
So after a recall, ask a second question:
Did anything in the Registry registration data change?
Examples could include a correction to:
- the registered product identifier
- granularity-linked information
- commodity code where relevant
- service-provider reference where relevant
- other registration data required by the applicable law.
A recall does not necessarily change any of those things.
If the product identity and registration data remain correct, do not change them merely to create activity in the Registry.
If registration data are wrong or have changed, the responsible verified actor needs to manage that correction through the proper Registry workflow.
For the registration mechanics, use How to Register a DPP in the EU Registry, and What Happens After Submission.
The first job is to identify exactly which products are affected
A recall is where product granularity stops being an abstract data-model question.
If the safety problem affects:
- one serialised item
- one manufacturing batch
- one colour variant
- one date range
- every unit of a model
then the business needs to identify that affected population precisely.
A model-level DPP that says “recalled” when only one batch is affected can overstate the recall.
A model-level DPP that remains unchanged when an entire model is recalled can understate it.
The recall scope and passport granularity therefore need to be reconciled.
This is why How many passports a range needs and Model vs Variant vs SKU: Where Product Data Belongs are not just architecture pages. They determine whether the business can isolate the affected products when something goes wrong.
Do not overwrite the evidence that explains what happened
When a product is recalled because a published product fact was wrong, the temptation is to fix the value everywhere and move on.
That destroys the evidence trail.
A better pattern is:
old published value → reason it was superseded → effective correction → supporting evidence → actor and timestamp
The user-facing DPP can show the current safe and accurate information while the governed system retains the history needed for audit and investigation.
The decision between correction, versioning, new batch or new product identity is covered by When a Product Changes, Do You Overwrite the Fact, Version the Record or Create a New Product?.
The internal sign-off question is covered by Who has to own this, and what happens when a field turns out to be wrong.
A recall and a withdrawal are not the same thing
Both GPSR and ESPR use corrective-action language that can include withdrawal or recall.
Operationally, they point at different parts of the chain.
A withdrawal generally stops a product moving through the supply chain or being made available.
A recall addresses products that have reached consumers or users and seeks their return or other corrective action.
The DPP does not remove the need to classify the safety action correctly.
That classification can also affect what happens online. A dangerous product offer may need to be removed or disabled, marketplaces have specific product-safety duties and consumers may need direct notification.
For the online-offer baseline, see What Product Information Must an EU Online Listing Show Under the GPSR? and What an Online Listing Has to Carry by Law.
The passport can make the recall easier without becoming the recall system
A well-governed DPP architecture can improve recall execution in several ways.
Product identity
A persistent identifier can help match the consumer's physical product to the affected model, batch or item.
Traceable version history
The business can see what information was published at the time the affected unit was placed on the market.
Lifecycle information
Where the applicable product rule permits it, the DPP can expose updated safety or service information to somebody who still holds the product.
Better downstream handoff
Retailers, repairers and other actors can work from the same product identity instead of reconciling a recall against marketing names.
Customer self-check
A consumer can scan or open the passport and determine whether the identifier in their possession is part of the affected population, if the system has been designed to expose that state correctly.
Those are valuable capabilities.
None of them replaces the formal recall duties.
The product-safety system is push-oriented where affected consumers can be identified. The DPP is largely pull-oriented when a person scans or follows the product link. Good recall design uses both, not one instead of the other.
A safe operational sequence
When a product with a DPP is recalled, a business can use this sequence as an implementation checklist while following the applicable legal advice and sector rules.
1. Establish the legal safety action
Identify the product-safety rule, the responsible economic operator and whether the action is correction, withdrawal, recall or another measure.
2. Establish the affected identity scope
Map the safety issue to the correct model, variant, batch or item population.
3. Use the mandatory recall channels
Notify consumers, authorities and marketplaces through the routes the applicable law requires. Under GPSR, that can include direct consumer notification, the Safety Business Gateway and the formal recall notice.
4. Preserve the pre-correction record
Retain the product-data and DPP state that existed when the product was placed on the market.
5. Correct the DPP where needed
If a passport fact is inaccurate, incomplete or no longer up to date, apply the appropriate governed correction or lifecycle update. Do not invent a generic recalled=true requirement where the product-specific law has not created one.
6. Check Registry data separately
Only change Registry registration data if the registration information itself needs correction or update.
7. Keep the passport route usable
Where the applicable law continues to require passport availability, keep the persistent product route working so a holder of the affected product can still reach the relevant information.
8. Test the customer journey
A customer with an affected product should be able to understand what happened and what they should do, while the formal recall notice remains the authoritative safety communication where required.
What ActivateDigital should and should not do
A DPP platform can help maintain product identity, evidence, version history and publication state.
It should not tell a business that publishing a passport update has completed a legal product recall.
A safe product boundary is:
ActivateDigital can help keep the product record current and traceable. The economic operator still carries the applicable recall, authority-notification and consumer-remedy duties.
That boundary is consistent with the wider principle in You have done the safety compliance work. How much of it counts towards a passport?: product safety and the DPP can reuse some of the same governed data without becoming the same regulatory system.
Direct questions
Do I have to delete the DPP when a product is recalled?
There is no horizontal ESPR rule saying a recalled product's DPP must automatically be deleted. Product-specific availability rules still apply, and ESPR expects DPPs to remain available for the period specified by the applicable act. Correct or update the record where necessary rather than assuming recall means deletion.
Can I use the DPP as the recall notice?
Do not rely on it as the sole recall notice. GPSR has specific consumer-notification and recall-notice requirements, including direct notification where consumers can be identified.
Should the DPP say the product is recalled?
The horizontal DPP framework does not create a universal recalled field. Whether safety status or recall information belongs in the DPP depends on the applicable product rule and the information the DPP is required or permitted to contain. It can still be sensible to link a customer to authoritative recall information as an additional service.
Does a recall require a new product identifier?
Not automatically. A recall identifies an affected population. A new identifier depends on the product-identity rules and whether a corrected or replacement product is legally a new product, variant, batch or item.
Does updating the EU Registry notify consumers?
No. Registry data management and consumer recall notification are different systems.
Does Safety Gate replace the DPP?
No. Safety Gate and the Safety Business Gateway are product-safety infrastructure. The DPP is product-information infrastructure. They may refer to the same product identity but perform different jobs.
What would change this page
Recheck this page when:
- a product-specific DPP law introduces an explicit safety-status or recall field
- the Commission creates a formal DPP to Safety Gate or Safety Business Gateway interconnection
- Registry status values gain a legally defined recall meaning
- GPSR or sector-specific recall rules change
- a product-specific delegated act defines how recalled products' DPPs are maintained or retired.
Until then, keep the safety workflow and passport workflow connected but distinct.
Try it on one product
A recall is much easier to scope when product identity, variant structure and evidence are already governed. Start with one product and see which facts are established, missing or dependent on upstream evidence.
Where this connects
Related resources this page depends on.
Keep exploring
The questions this page usually raises next.
- Another angleNext questionWhat GPSR work carries into a passport?→ GPSR and product passports
- Evidence behind thisNext questionWho owns a wrong published field?→ Owning a published field
- Another angleNext questionDo I overwrite or version a correction?→ Product data changes
- Another angleNext questionWhat must an online offer show?→ GPSR Article 19
- Another angleNext questionHow is a DPP registered and updated?→ How to register a DPP in the EU Registry
Does this reach your products?
Give ActivateDigital one product and it works out which obligations apply from the product's own character, and says which it cannot decide.
Help someone else make sense of product passports.
Primary and official sources
https://commission.europa.eu/topics/business-and-industry/product-safety_en Supporting Commission entry point for Safety Gate, GPSR and business obligations.
Last verified: 3 September 2026. This page is practical guidance, not personalised legal advice.