Can One 2D Barcode Handle Checkout, Packaging Information and a Digital Product Passport?
One 2D barcode can sometimes support checkout, packaging information and a Digital Product Passport. See the legal, identity, scanner and routing conditions that have to line up.
Navigate this page
- Overview
- The short answer
- First separate the three jobs
- What PPWR actually says about one data carrier
- Detergents go further
- Toys use the same architectural idea
- Why one code is harder at checkout than on the web
- The identity has to line up before the carrier can consolida
- The strongest web pattern is one identity, several resources
- One carrier does not mean one access level
- A decision test for one-code architecture
- Four architectures, from weakest to strongest
- What not to combine
- What is established, and what is not
- What would change this answer
- Sources and legal basis
- Keep exploring
One physical 2D barcode can support several jobs, but only when the legal requirements, product identity, encoded syntax, scanner estate and web architecture are compatible. The direction of EU law and retail standards increasingly favours avoiding unnecessary duplicate carriers. The Packaging and Packaging Waste Regulation, the Toy Safety Regulation and the 2026 Detergents Regulation each contain forms of single-data-carrier logic where information duties under different Union rules meet on the same product or package. That does not mean every product can delete every other barcode today. Retail POS is still in transition, product-specific DPP acts can set their own carrier details and one physical carrier can only do several jobs if each receiving system can use what is inside it.
The short answer
A one-code architecture is strongest when:
- the same persistent product identity can anchor all required uses;
- the applicable product law allows the chosen carrier;
- packaging information can be reached through the same carrier while remaining clearly distinguishable where required;
- the 2D symbol and syntax work at retail POS if checkout is one of the jobs;
- the web identity can route to several resources without changing the printed mark;
- the business controls the long-term domain and routing model;
- the transition plan still supports legacy linear barcode needs until retailers are ready.
If any of those fail, “one code” becomes a visual simplification that creates a system problem somewhere else.
First separate the three jobs
A single square on-pack can be asked to do three very different things.
| Job | What the scanner/user needs | Typical system behind it |
|---|---|---|
| Checkout | Reliable product identity, usually GTIN, at retail speed | POS scanner, host and item master |
| Packaging information | Access to packaging composition, reuse, sorting or other legally selected information | Web resource or digital information service |
| Digital Product Passport | Persistent product identity connected to the legally required passport data and access model | DPP data service, resource or resolver architecture |
The same physical carrier can point into all three. That does not make the data itself one undifferentiated page.
The law can require information to remain separately identifiable even when it is reached through one carrier.
What PPWR actually says about one data carrier
Regulation (EU) 2025/40 on packaging and packaging waste is unusually helpful because it addresses the collision directly.
Where Union law requires information on the packaged product to be provided via a data carrier, PPWR says a single data carrier shall be used for the information required for the packaged product and for the packaging, and the two sets of information must be easily distinguishable.
That is a legal design signal, not just a UX preference.
It tells you that the regulatory direction is not “print a fresh QR code for every legal instrument”. In the circumstances covered by that provision, the architecture is supposed to consolidate the physical access point while preserving the distinction between the information sets.
It does not tell you the carrier must be QR Code, GS1 DataMatrix or GS1 Digital Link.
Detergents go further
Regulation (EU) 2026/405 on detergents and surfactants contains an even more explicit cross-regime rule.
Article 21 provides that where other Union law requires information on a detergent or end-user surfactant to be available via a data carrier, a single data carrier shall be used to provide the information required under the Detergents Regulation and the other Union law.
It also says that where other Union law requires a DPP, a single digital product passport shall be created containing the data required under the Detergents Regulation and the other DPP law. Additional information can be accessible through the same carrier but must be clearly separated from legally required information.
That is a strong adopted example of one-code and one-passport architecture.
It is still product-specific. Do not generalise the detergents rule to every category that has not adopted the same wording.
For the detergent regime itself, use Detergent Digital Product Passport Requirements.
Toys use the same architectural idea
Regulation (EU) 2025/2509 on toy safety also says that where other Union law requires toy information to be available via a data carrier, a single data carrier shall be used to provide the information required by the Toy Safety Regulation and that other law.
Where another Union rule also requires a DPP, a single DPP can contain the required data under both regimes, subject to the regulation's conditions.
Again, the lesson is architectural: the EU is creating mechanisms to avoid multiple digital carriers and passports colliding on the same physical product.
The carrier implementation still has to satisfy the applicable technical rules.
Why one code is harder at checkout than on the web
A phone can scan a web-enabled QR Code and open a browser. Retail checkout is more demanding.
The POS journey has to work at line speed across scanner hardware, scanner software, host software, item master and exception handling. During the current GS1 2D transition, many products still need a linear barcode alongside a 2D barcode.
GS1's retail guideline says the future-state POS 2D options include:
- QR Code with GS1 Digital Link URI syntax;
- Data Matrix with GS1 Digital Link URI syntax;
- GS1 DataMatrix.
It also says products using retail 2D barcodes need an accompanying linear barcode until 90% of POS scanning solutions are capable of using GS1-compliant POS 2D barcodes and at minimum capturing the GTIN.
So a one-code end state can be sensible while a two-code transition is still operationally necessary.
See Ambition 2027: What Retail's 2D Barcode Transition Means for Digital Product Passports.
The identity has to line up before the carrier can consolidate
One physical carrier only simplifies the estate if the identity model underneath it is coherent.
Suppose retail identifies a sellable variant with a GTIN, while a product-specific DPP act requires an item-level passport. The one-code design now needs to carry or derive both the trade-item identity and the individual item identity in a standards-compliant way.
That can be possible. It is not automatic.
Likewise, a packaging information service may be about the packaging configuration while the DPP is about the product model. One carrier can route to both, but the architecture must know which identity belongs to which resource.
This is why GS1 Application Identifiers for Digital Product Passports matters before artwork is frozen.
The strongest web pattern is one identity, several resources
A web-enabled identifier can keep the printed mark stable while routing changes behind it.
A simple architecture looks like this:
2D carrier -> persistent product identity in URI -> routing layer -> resource
The resources might include:
- product passport;
- packaging information;
- recycling instructions;
- repair information;
- consumer product information;
- business-to-business data.
If GS1 is the identity scheme, GS1 Digital Link provides a standards-defined URI structure and an optional resolver model for connecting one GS1 identity to different resources.
The word optional matters. Digital Link URI syntax does not force every implementation to use a GS1-Conformant Resolver.
One carrier does not mean one access level
A DPP can contain public and restricted information. Packaging information can have its own visibility requirements. A market-surveillance authority and a consumer can scan the same physical carrier and still be entitled to different data.
The access decision belongs behind the carrier.
Do not print separate symbols merely because different users see different resources unless the applicable law or operational design genuinely requires separate carriers.
Equally, do not expose restricted information because “there is only one QR code”. A carrier is an entry point, not an access-control policy.
A decision test for one-code architecture
Work through these eight questions in order.
1. Is there a legal single-carrier rule for this product or package?
Check the applicable product and packaging law. If a single carrier is expressly required, the architecture must honour it.
2. Does the product law specify the carrier?
A category-specific rule can select QR Code or another carrier. That decision outranks a generic preference.
3. What is the legally relevant product identity?
Model, batch and item are not interchangeable. Establish granularity before choosing the encoded structure.
4. What does retail POS need?
If checkout is a job, test the actual retailer environment and GS1 implementation path. Do not assume any 2D symbol is automatically POS-ready.
5. Can one encoded structure express what each use needs?
You may need a GTIN plus batch, serial or other qualifiers. The carrier can be the same while downstream systems use different parts of the encoded identity.
6. Can the information sets remain distinguishable?
Where law requires product and packaging information to be distinguishable, the resource design must preserve that separation even when the physical carrier is shared.
7. Who controls routing after print?
If the code contains a URI, decide who controls the domain, resolver or redirects and what happens if providers change.
8. What is the transition state?
The final architecture may be one 2D carrier. The current retail reality may still require the linear barcode alongside it.
Four architectures, from weakest to strongest
Architecture A: one marketing QR plus separate legal and retail codes
Easy to start, hard to govern. It creates multiple identities and physical marks with no shared architecture.
Architecture B: retail barcode plus separate DPP QR
Common and workable during transition. The risk is creating two product identities that later drift apart.
Architecture C: one persistent identity across retail and DPP, two physical carriers during transition
Often the strongest near-term retail pattern. The linear barcode and 2D carrier coexist, but they resolve to the same governed trade-item identity.
Architecture D: one 2D carrier serving retail, DPP and other digital information
Potential end state where product law, GS1 standards, retailer capability and web architecture all support it. This is the cleanest physical design but requires the most disciplined systems design underneath.
What not to combine
One-code architecture should not be used as an excuse to merge facts that have different legal meanings.
Keep separate:
- product identity and packaging identity;
- model identity and serial identity;
- public resources and restricted resources;
- DPP compliance data and marketing content;
- legal source and implementation standard;
- carrier conformance and product-law scope.
The square can be shared while the data stays governed.
What is established, and what is not
| Proposition | Status at 3 September 2026 |
|---|---|
| PPWR contains a single-data-carrier rule where packaged-product information is also required via a carrier | Required by adopted EU law in the stated circumstances |
| Detergents Regulation contains single-carrier and single-DPP rules across overlapping Union law | Required by adopted EU law in the stated circumstances |
| Toy Safety Regulation contains a single-carrier rule across overlapping Union law | Required by adopted EU law in the stated circumstances |
| One physical 2D carrier can technically support several resources | Supported implementation pattern |
| Every retail product can remove its linear barcode now | False |
| One-code architecture universally requires GS1 Digital Link | Not established |
| One carrier means all information should be shown to every scanner | False |
What would change this answer
Recheck if:
- product-specific delegated acts add new single-carrier or carrier-selection rules;
- PPWR implementing acts materially change the digital labelling architecture;
- GS1 changes its retail transition conditions;
- a product regime fixes an incompatible granularity or carrier rule;
- EN 18219 or EN 18220 is amended in a way that changes the implementation route.
Last verified 3 September 2026.
Keep exploring
The questions this page usually raises next.
- CompareNext questionAmbition 2027: What Retail's 2D Barcode Transition Means for Digital Product PassportsUnderstand why one-code may be the end state while dual marking remains the transition state.
- Related questionNext questionGS1 Digital Link for Digital Product PassportsSee how one persistent GS1 identity can route to several resources without turning the resolver into the passport.
- CompareNext questionWhen the Link DiesDesign the one-code architecture for provider changes and long product life.
Does this reach your products?
Give ActivateDigital one product and it works out which obligations apply from the product's own character, and says which it cannot decide.
Help someone else make sense of product passports.