What you can take with you when you leave a provider
Nobody sells a guide to leaving. Across the educational material surveyed for this research, eight resources touched what happens to your product data when you move away from the platform holding it, and not one of them was published by a vendor. That silence is structural rather than accidental, and it means the questions below have to be asked before you sign, because they cannot be researched afterwards.
Navigate this page
The short answer
Four things can leave with you, and they leave under different conditions.
The values are yours, and the framework behind passports makes the operator that submitted them the controller of them. Whether you can get them out in a usable state is a contractual question, not a legal one.
The evidence behind the values is the part most likely to be stranded, because most systems export what a field says and not what supports it.
The identifier stays with whoever the numbering scheme allocated it to, which is normally you. It is one of the few things in this chain a provider cannot hold hostage.
The address the code points at stays with whoever owns the domain. If that is your provider, every code you have already printed points at somebody else's property.
The last two are the ones printed onto goods, and they are the two nobody asks about.
Why the market is quiet about this
Two reasons, and neither is sinister.
A vendor publishing a guide to leaving is publishing a document that only ever gets used against it. The absence is predictable and it will persist.
More importantly, the questions here are boring at the moment they matter least. You ask them when you are buying, which is when everybody involved is optimistic, and you need the answers when you are leaving, which is usually when something has already gone wrong.
There is also a live signal worth noting. This category's own suppliers are not uniformly stable. The research observed one vendor whose blog has been dormant since April 2025 and another whose flagship regulatory page still describes the framework as awaiting adoption in a year that has passed. A passport obligation is expected to outlive the product by years, and that is exactly the horizon over which a supplier gets acquired, changes direction or stops.
The four layers, and who holds each one
| What | Who holds it | What happens if you leave |
|---|---|---|
| The values in your product records | You, as the party that submitted them. The framework makes the submitting operator the controller of the data it submits. | Recoverable in principle. Whether the export is usable is a contract question. |
| The evidence behind each value | Usually the provider's system, if it is modelled at all | This is where the loss happens. Most systems export values, not provenance. |
| The product identifier | Whoever the numbering scheme allocated the prefix to, which is normally your company | Stays with you. Not a lock-in point. |
| The address printed on goods, and the service that answers it | Whoever owns the domain and operates the resolver | Cannot be changed on goods already in circulation. |
Two constraints sit on top of that table and both work in your favour.
The framework restricts what a passport service provider may do with your data, barring it from reselling or reusing the data beyond providing the service without your explicit consent. And where a third party registers on your behalf, the operator remains fully responsible, which is a burden rather than a benefit but does confirm whose data it is. What the framework requires of the company holding your data is on who is allowed to hold your passport data.
The identity layer is not a moat, and that is worth knowing before you negotiate
The GS1-Conformant Resolver standard read for this research does not restrict operation of a conformant resolver to GS1 or to its member organisations. Conformance consists of a set of technical criteria plus a self-asserted description file published at a well known location on the service itself. Nothing in the text read states a fee, a licence or a mandatory approval step.
What follows is commercially useful. Running the service that answers your codes is not a privileged capability that a vendor holds and you cannot. It is a small, well specified service with a published conformance description, and the standard leaves continuity, retirement and handover entirely to whoever operates it.
That last point is the one to carry into a contract. The standard specifies no procedure for handing a resolver over, winding one down or retiring the addresses it used to answer. What the standard leaves open about continuity is set out on when the link dies, and the practical consequence is that anything about handover has to be in a contract or it does not exist.
The five questions to ask before signing
Each of these has a checkable answer and each of them gets harder to ask later.
Who owns the domain the printed codes resolve to? If the answer is the provider, understand that you are printing their address onto your goods for the life of those goods. If it is yours, the resolver becomes a supplier you can replace rather than a dependency you cannot.
What does an export actually contain? Ask for a sample export of a real record, not a description of one. You are looking for whether each value carries the document it came from, who declared it, when, and what state it was in. An export of values alone hands you a spreadsheet you cannot defend.
Is there a difference between an audit log and a provenance record? Several systems in this category log edits. An edit log tells you who changed a field. A provenance record tells you what the value rests on. They are not the same object and only one of them survives a question from a regulator or a buyer.
What happens to registrations made on your behalf? If the provider registered anything for you, establish what transfers and what has to be redone. The operator remains responsible either way, which means the exposure is yours whoever does the keystrokes.
What is the notice period, and what happens during it? Specifically whether the resolver keeps answering while you migrate. Codes on goods do not stop existing because a contract ended.
What a usable export looks like
Three properties, and a file that has all three is portable whatever format it is in.
Every value carries its source. Not a footnote. A per-value link to the document, the declaration or the party the value came from, with a date.
Every absence is typed. A blank cell tells you nothing. A field recorded as not applicable, not established, or not yet asked for tells you what to do next, and the difference between those states is most of what an export is worth.
Identifiers are intact and unmangled. Product numbers survive a spreadsheet only if nobody let the spreadsheet decide they were numbers.
If an export has those three, you can rebuild elsewhere. If it has none, you are not migrating, you are starting again with a head start on the typing. The failure this is insurance against is described on when the link dies.
What this page does not do
It does not compare providers, name any of them, or score anything. It is a list of questions and a description of where the layers sit. Any version of this that ranked suppliers would be a different and much less useful document, and it would be the sort of thing a supplier writes about its competitors.
It does not claim any provider behaves badly. The silence described at the top is a structural feature of the category, not an accusation about anybody in it.
It does not tell you a resolver is easy to run. It says the standard reserves it to nobody and specifies what conformance consists of. Whether you should run one is a separate decision about what you want to be responsible for in five years.
What would change this page
A conformance or licensing condition appearing in a later release of the resolver standard that reserved operation to a class of operator. That would change the negotiating position described above.
Any provider in this category publishing an exit and export specification. It would be the first, and it would be a genuine signal about that provider.
Sources
-
CELEX 02024R1781-20240628In forceIn force
Used for two propositions: that a passport service provider is restricted from reselling or reusing the data beyond providing the service without explicit consent, and that a backup copy is provided for against cessation of activity.
-
Implementing Regulation (EU) 2026/1778, the passport registryIn force
Used for two provisions, described by function rather than by number because the internal numbering has not been checked against the Official Journal in this estate: that the operator remains fully responsible where a third party registers on its behalf, and that the operator is the controller of the data it submits.
-
The GS1-Conformant Resolver standard, read at the GS1 reference siteStandard
Read for what conformance consists of and, as an absence, for the fact that the text read states no fee, licence or approval requirement and reserves operation to no class of operator. Registered here with its read depth, following the estate's practice for this publisher.
-
Exit and portability material across sixteen organisations' educational estates, surveyed 27 August 2026Field research
Cited for one measurement: eight resources across six organisations touched the subject and none was published by a vendor. The survey read a sample rather than the whole corpus, and the figure is a count of resources observed rather than a claim about everything published.
Sources as at 30 August 2026.
Keep going
The question this one usually raises next.
Also worth reading
Build one from a product you already sell.
One governed record becomes the passport, the Digital Link behind the code, the retailer pack and the consumer page.
Help someone else make sense of product passports.