The code proves the record. It does not prove the product.
A passport establishes that a record exists, that it is reachable and that somebody registered it. It does not establish that the object in your hand is the one the record is about, and it does not say who owns that object. Identity, authentication and ownership are three different problems with three different mechanisms behind them, and a passport supplies the first one only.
Navigate this page
The short answer
A data carrier connected to a persistent identifier makes a record findable from an object. Nothing in that arrangement binds the record to a specific physical thing.
Photograph a legitimate code, reprint it on a thousand counterfeits, and every one of them resolves to a genuine, correctly registered passport. The record is authentic. The garment is not. The attack needs no technical skill and nothing in the framework provisions we read patches it.
Ownership is a separate absence. The framework provides for information to be available to different actors at different levels. Actor is a category, not a person, and the mechanism is access by stakeholder type rather than a record of who currently holds the item.
Six words that are not synonyms
Most of the confusion in this territory is one word doing six jobs. Separating them is the whole of the argument, and each one has a different thing on the other end of it.
| The word | What it establishes | What it does not establish |
|---|---|---|
| Identification | Which product this is, as a number. | That the number is on the right object. |
| Data retrieval | That a record exists at the end of an address, and that it came back. | Anything at all about the object that carried the address. |
| Authentication | That this physical item is the item it presents itself as. | Anything about the record. An authentic object can carry a wrong one. |
| Verification | That a value was checked against something, by somebody, on a date. | That the check covered your goods, or that it is still current. |
| Traceability | That a documented chain connects an input to an output. | That any claim about materials or products follows from it. The chain of custody standard says so on its own face. |
| Provenance | An account of where something came from, of whatever evidential quality it happens to have. | That the account is true, or that it attaches to this unit rather than to a batch. |
A scan performs the first two. It performs neither of the middle two, and it carries the last two only as far as whoever wrote the record carried them.
Where each of the three questions actually lives
The three that a business usually cares about sort like this.
| The question | What answers it | What a passport contributes |
|---|---|---|
| What is this object? | An identifier, a carrier and a resolver. | This is the whole of what the passport supplies, and it supplies it well. |
| Is this object genuine? | A physical security feature bound to the object itself, or a person who inspects it. | Nothing. The carrier is copyable and copying it is the attack. |
| Who owns this object now? | A register of holders, maintained by somebody, with a rule for transfer. | Nothing. Differentiated access is by stakeholder type, and no provision we read records a holder. |
The three get collapsed because a scan looks like a check. Somebody points a phone at a garment, a branded page appears, and the page carries the brand's name and a set of correct values. Every part of that experience is consistent with the item being genuine and every part of it is equally consistent with the item being a good copy of a genuine one.
The sentence to hold on to is short. This code resolves to this record is a different statement from this item has been proven genuine, and no amount of care taken over the record converts the first into the second. The mechanics of the retrieval half are set out in what actually happens when somebody scans the code.
Why the counterfeit case is worse than an absence
Two things follow from the reprint attack and the second one is the uncomfortable half.
The first is ordinary. Signing passport data proves the record has not been altered. It says nothing about the object holding the carrier, because the signature is over the data and the carrier is a printed square that anybody with a camera can reproduce. That signing is now the subject of a European standard at formal vote, and what the standards work does and does not change about this argument is on signing the record.
The second is that a clone which resolves to a genuine passport is more persuasive than a clone that resolves to nothing. Discoverability has been solved. Trust has not. A registry that makes identifiers findable is doing exactly what a counterfeiter needs, and the better the register works the more convincing the copy becomes to somebody who treats resolution as verification.
A targeted retrieval of the framework's passport provisions and recitals returned no counterfeiting or authentication provisions at all. That is an absence in our reading rather than a proof that no provision exists anywhere in the instrument, and it is recorded as such. What it does mean is that anybody describing anti-counterfeiting as a passport capability should be asked which provision they are relying on.
The industry's own products settle the argument
The clearest evidence that a code does not authenticate is what the anti-counterfeiting industry sells alongside one.
Scantrust sells copy detection patterns and explains why in its own material: a secure code can be detected as faked or copied because of the information lost when a code is scanned and reprinted. That is a vendor stating, in order to sell the remedy, that a plain code cannot do this job.
Digimarc pairs a visible code with a covert watermark and describes the pair as two factor authentication. The Aura Blockchain Consortium lists authenticity as a module sitting alongside traceability, resale and warranty, rather than as something the passport produces on its own.
Every serious operator in this space sells something in addition to the identifier. The product architecture is the argument, and it is more reliable than any efficacy claim any of them make, because it is what they build rather than what they say.
What happens at the moment authentication actually matters
The commercial case usually offered for identity in authentication is that it replaces physical inspection with a data lookup. Whether it lifts resale prices or lowers authentication costs is a separate commercial question and it is taken apart, with what came back when the estate went looking, on the garment that will never have a passport. Nothing here repeats it.
What belongs on this page is narrower and is about mechanism rather than price. The party with the strongest available incentive to make that substitution, a marketplace that bought an apparel digital identity business outright, still pays people to hold the goods and look at them, including goods that already carry brand issued identity. That is revealed behaviour rather than an argument, and it is the only evidence in this territory that comes from somebody with money on the outcome.
The ownership question, which is quietly the harder one
Luxury programmes have migrated, over about three years, from describing themselves as traceability and transparency instruments to describing themselves as ownership certificates with warranty, after sales and resale transfer attached. Read the Aura and Arianee case entries in date order and the stated purpose shifts under you. The commercial logic is not obscure. A digital identity claimed by a buyer is a route to a customer the brand met through a wholesale channel and otherwise never meets.
That is a real and working business use. It is also not a passport capability, and treating it as one creates three problems nobody has answered in public.
No instrument we read records a holder. The rules being circulated, that a passport must not be deleted on resale, that access permissions update to the new owner, that a previous owner's personal data is protected, come from vendor and consultant guidance rather than from binding text. They may be sensible. They are not requirements, and a business relying on them is relying on somebody's recommendation.
Access by stakeholder type is not access by person. The framework provides for different actors to see different things. It does not provide for one individual owner to see something the previous owner cannot. Per owner isolation is a product design decision made by whoever builds the thing.
Nobody has said who controls an ownership chain that outlives the brand. A record of successive holders is personal data about a series of people. Which party is the controller of it once the company that started it has been sold, wound up or has simply stopped maintaining the service is an open question, and it interacts badly with any design that anchors entries immutably. We found nobody answering it in public, and we are not answering it here. Resale raises the same question from the other end, where goods already on the market will not acquire a passport.
The physical question underneath all of it
One unresolved matter sits below identity, authentication and ownership alike. Every argument on this page assumes the carrier is still on the garment and still readable at the moment somebody wants to check something, and for authentication or an ownership transfer that moment is years after manufacture. Whether any carrier survives a garment's ordinary life is not established, and what does and does not exist by way of evidence is set out on choosing a carrier that still works.
What this page does not say
It does not say that product identity is useless against counterfeiting. It says a passport as the framework describes it is not an authentication mechanism, and that authentication requires something bound to the object rather than printed on it.
It does not evaluate any vendor's security product. Whether a copy detection pattern or a covert watermark performs as claimed is a question about that product, and the efficacy claims in this space are vendor claims that we have not tested.
It does not publish comparative scale figures for the operators in this territory. Two of the largest publish item counts two orders of magnitude apart, and either the counting bases differ materially or one figure is inflated. Which of those it is has not been established, so no count from any of them appears here.
It carries no cost for an authenticating carrier. Passive tag inlay prices circulate freely and describe the chip. The all in unit cost of a cryptographically authenticating tag at apparel volumes, which is the number a brand would actually need, is not published by anybody we found.
What would change this page
An authentication provision located in the framework or in a delegated act, which would move the absence recorded above from our reading into the instrument itself.
Independent test data on whether any carrier type survives normal domestic laundering and alteration in apparel. That single study would settle the load bearing question underneath this whole territory.
A binding rule, rather than guidance, on what happens to an ownership record at transfer and on who controls it afterwards.
What to do with this
Separate the three questions in every conversation where they arrive together, and make whoever is selling you something say which one they are answering. A proposal that answers the first and is priced against the second is the ordinary shape of the problem.
If the requirement is authentication, the passport is context and not the mechanism, and the mechanism is a separate purchase with a separate cost that nobody publishes.
If the requirement is an owner relationship, that is a working commercial use with real deployments behind it, and it is a customer relationship product rather than a compliance one. Build it knowing that no instrument requires it, no instrument protects it and the rules it would follow have not been written.
Sources
-
CELEX 02024R1781-20240628In forceIn force
Read for the passport, carrier and identifier provisions and for the provision on availability of information to different actors. Used here for two propositions and no others: that the framework connects a carrier to an identifier without binding the record to a physical object, and that access is provided for by actor category rather than by holder. A targeted retrieval for a counterfeiting or authentication provision returned nothing, and that is recorded as an absence in our reading rather than as a finding about the whole instrument.
-
Vendor product documentation from three anti-counterfeiting operators, checked 27 August 2026Vendor material
Cited for product architecture only, that each sells a physical or covert security feature in addition to an identifier, and for one vendor's own stated reason for doing so. No efficacy claim from any of them is carried here.
-
A case library of luxury digital identity programmes with dated entries, compiled 27 August 2026Field research
Used for the migration in stated purpose across the 2022 to 2026 entries. Individual operators' published item counts are not carried, because two of them differ by two orders of magnitude on bases that have not been established.
-
Carrier durability material for consumer apparelNot established
Searched and not found. The absence is stated in the body rather than filled.
Sources as at 30 August 2026.
Keep going
The question this one usually raises next.
Also worth reading
- Rules & scopeThe garment that will never have a passportWhy existing resale stock will not acquire one, and what came back when the estate went looking for evidence on resale price and authentication cost.
- Passport technologyWho sees whatHow differentiated access is meant to work, and why nobody has been told what it means for textiles.
Build one from a product you already sell.
One governed record becomes the passport, the Digital Link behind the code, the retailer pack and the consumer page.
Help someone else make sense of product passports.