When the link dies
The framework already assumes the company holding a passport stops. It requires the record to stay available for at least the expected lifetime of the product, and that requirement is written to survive insolvency, liquidation or cessation of activity. It names one mechanism for that, a backup copy held by an independent third party, and it does not say for how many years.
On this page
The short answer
The law already assumes this happens. The framework requires a passport to stay available for at least the expected lifetime of the product, and the requirement is written to hold after insolvency, liquidation or cessation of activity. Somebody drafting that sentence expected passports to outlive the businesses that made them.
It supplies exactly one mechanism to achieve it: a backup copy made available through an independent third-party service provider. That is the whole of the continuity machinery in the framework. Whether it is adequate has not been assessed by anybody whose assessment we have found, and how the estate treats a gap of that kind is set out in how we know.
What the framework does not say is how long. The availability period is delegated to product-specific acts, and no such act exists for textiles, so the number of years a passport must remain reachable is today undetermined by law for every product group rather than for textiles alone.
Underneath all of that sits a layer the framework says nothing about at all: the address printed on the garment, the domain in it and the service that answers when somebody scans. That layer is governed by a standard with no continuity protocol in it. If you have not read what actually answers the code, that is the mechanism this page is describing the failure of.
What the framework requires, and the one mechanism it names
Three provisions do the work here and they are worth separating, because they are usually quoted as one.
The availability requirement. The passport has to remain available for at least a period tied to the expected lifetime of the product. That is a duty about the record staying reachable, not about a company staying solvent, and those are different things that a supplier contract will often treat as the same thing.
The clause that survives the business. The requirement is expressed to continue after insolvency, liquidation or cessation of activity in the Union. This is the provision most worth reading twice. It means the obligation is written as a property of the product rather than as a property of the operator, which is why an exit clause that ends when the contract ends does not discharge it.
The delegation. The actual period is set by the product-specific act, not by the framework. For textiles no such act exists, so the number is not merely unpublished, it has not been decided. Anyone quoting you a figure in years for how long a textile passport must persist is quoting something that does not yet exist, and the honest answer is that it is undetermined.
Against those three, the framework offers a backup copy made available through an independent third-party service provider. Note what that phrasing does and does not commit anybody to. It names a mechanism and a category of party. It does not name a standard for what the copy contains, a trigger that moves custody, a duty on the third party to accept the role or a way for a reader holding the garment to find out whether one exists. Those are the questions the last section of this page turns into contract language.
One note on citation. No article number appears anywhere on this page, deliberately. Two independent reads of this instrument attributed the passport-establishing provision to two different articles, and until the articles are read verbatim in a single sitting the estate treats the numbering as contested. The provisions above were read. It is the numbering that is unresolved, and an article citation is the first thing a lawyer checks.
What the resolver standard does not contain
The address on a garment is answered by a resolver, and the behaviour of a conformant one is set out in a ratified standard we read at its reference site. Most of what matters here is what the standard leaves out. Read as an absence, it is the clearest evidence on this page.
- No continuity or retirement protocol. Nothing specifies what happens to an address when the party answering it stops. There is no defined way to hand an address over, no defined way to retire one and no defined signal that either has happened.
- No fallback. Where a requested link type is absent the specified behaviour is a dead end rather than a redirection to something else. That is the right behaviour, and it also means there is no second place to look when the first place stops answering.
- No caching guidance at all. The standard says nothing about how long an answer may be held, by whom or on what terms, so there is no specified layer between the reader and a service that has gone quiet.
- No trust model. Nothing verifies that the party operating a resolver is the legitimate holder of the identifier being resolved.
Each resolver and each internet domain is sovereign over its own address space. That is a design decision rather than an oversight, and it is the same decision that makes the web work. The consequence for a passport is direct: the party that controls the domain in the printed address controls whether anything answers, and no standard obliges them to keep answering or to tell anybody when they stop.
It is worth saying plainly what the standard is, because it is often described as something wider. It is a resolver standard. Conformance to it is a claim about resolver behaviour, which is real, narrow and a good thing to be able to claim. It is not a claim about the passport, the record behind it or how long either will last.
We also looked for the thing a reader will reasonably ask for at this point, which is a documented case of a passport resolver going dark and taking records with it. We did not find one, in the standards material, in the trade press or in the competitive corpus the estate assembled. That is a statement about our search rather than a finding that it has not happened, and no example is invented here to fill the space.
Identity is licensed rather than owned
The second layer is the identifier itself, and the ownership question there is settled in the issuer's published terms rather than in law. Identifiers of the kind most textile catalogues use are allocated by a national member organisation of GS1 under terms that prohibit transferring or reselling an allocated identifier. What a business acquires is a licence to use a range, and that licence is renewable.
One national member organisation states the continuity position directly in its own fee material, and the sentence is worth reading with its condition attached rather than without it.
The published condition, kept with the guarantee
Product data remains linked, in the issuer's own words, "as long as membership is renewed annually". The guarantee and its condition are one sentence, and separating them changes what is being promised. Renewed annually means the persistence of the link is contingent on an annual payment continuing, by somebody, indefinitely, for as long as the garment exists.
That is the one persistence commitment on this page anybody has actually published, and it is conditional. It is not a criticism of the issuer, which has stated its terms openly, and it is a great deal more than the resolver standard offers. It does mean the honest description of an identifier is a licence with a renewal date rather than a property you hold.
Two things follow for a business rather than for a lawyer. The renewal is a recurring line in an annual budget rather than a setup cost, which is where it belongs when you cost what it takes to keep a passport alive. And if the membership sits on your supplier's account rather than yours, the licence is theirs, the renewal decision is theirs and the identity printed on your goods depends on a payment you do not control. What allocating an identifier commits you to is set out in identifiers and allocation.
One thing we will not assert. Whether an identifier already printed onto goods in circulation can be reassigned after some period is governed by the numbering scheme's own specification, which this estate has not read. The permanence of a printed identifier gets stated in absolute terms in a great deal of material including some of ours, and that statement is being corrected rather than repeated here.
The decentralised route, and what it inherits
The alternative usually offered at this point is a decentralised identifier, on the reasoning that an identity nobody issues is an identity nobody can withdraw. It is a serious answer to a real problem and it deserves a serious reading rather than a dismissal.
The reading is this. A decentralised identifier is only as durable as whatever it is anchored to. Where a method anchors an issuer's identity to control of a domain name, the guarantee underneath the whole arrangement is domain control, and a domain is itself a licence with an expiry date, a registrar and an annual renewal. The failure mode does not go away. It moves from a membership organisation to a registrar, and the party who forgets to renew is the same party in both cases.
We have not read the method specifications, so this page names no method, describes no method's contents and makes no comparison between them. What it does say is narrower and holds regardless: if the thing an identity is anchored to is a domain, then whoever controls that domain controls the identity, and asking which anchor is in use is a fair question to put to anyone offering the decentralised route as the answer to this page.
The standard that covers this, which we have not read
There is a European standard covering data storage, archiving and persistence for the Digital Product Passport. Its reference is published, which means conformity with it carries a presumption of conformity, and that makes it the most authoritative document in existence on the subject of this page.
We have not read it. It is sold by national standards bodies rather than published freely, it has not been bought here and not one sentence of it has been read. So this page describes none of its contents. It states no persistence period from it, no archiving requirement from it and no storage architecture from it, because describing a document nobody here has opened would be exactly the failure the rest of the estate exists to correct in other people.
Two consequences worth carrying away. The first is practical: if a provider tells you their persistence arrangement meets that standard, the useful next question is which clause, because the answer is checkable and the claim is not. The second is about this page's own reliability, which is that its sharpest section is gated behind a purchase, and the honest version of that sentence is the one printed here rather than a silence a reader would mistake for coverage. We should also record that the citation state itself was confirmed through secondary routes rather than at the Official Journal directly, and it is on the list to be confirmed at source.
The questions to ask before you sign
This is the part of the page worth taking into a room. None of it needs a lawyer to start with, and every item is answerable in a sentence by any provider who has thought about it. A provider who has not thought about it will answer in paragraphs.
- The export. Ask what a full export contains and in what format, then whether it can be read without their software. Then ask for a sample export of a real record today, rather than a description of one. An export that has never been produced is a plan, and a plan is not a file.
- Who holds the identifier. Ask on whose account the issuer membership sits. If it sits on the provider's account, the identifier licence is theirs, the annual renewal decision is theirs and the identity on your goods moves when the relationship does.
- Whose domain is printed. Ask which domain appears in the address encoded into the code on the garment, and who is the registrant of it. This is the one decision on the whole list that cannot be revisited after the goods ship, because the address is physically on the product.
- What happens to the address when the contract ends. Ask for the commitment in writing: whether resolution continues, for how long, who pays for it and what happens at the end of that period. A commitment with no stated period is a notice period in disguise.
- The persistence commitment, read closely. Ask for it in full and look for the condition, because every persistence commitment we have read carries one. Renewal, membership, an active subscription or continued trading are all conditions, and a guarantee quoted without its condition is being quoted wrongly.
- The backup copy. The framework names a backup copy through an independent third-party service provider. Ask whether one exists, who the third party is, what triggers them taking over and whether they have agreed in writing to accept the role. Escrow that depends on the failed company acting is not escrow.
- Insolvency, specifically. Ask who has the right to the data if an administrator is appointed, and whether that right is recorded somewhere an administrator will actually look. The framework's requirement continues past cessation of activity; a supplier contract that terminates on insolvency does not carry it.
- What conformance is being claimed. Ask which standard is being named, and whether the claim is resolver conformance or something wider. Both are legitimate. They are not the same claim, and the difference matters exactly when the resolver stops.
- The annual cost of standing still. Ask which charges recur, which of them stop being optional the day goods carrying the code are in circulation and what the renewal path looks like if you stop adding products entirely.
- Who owns the record you publish. Ask who is responsible for a published value once it is out in the world, and whether the answer changes when the provider changes. It should not. Responsibility for a published field stays with the operator whatever the software underneath it does.
Two of those questions have no settled answer anywhere today, and it is better to know which. How long a passport must remain reachable is undetermined by law. Whether continuity terms differ between identifier issuers in different countries is not established by us, because we read the published material of some national member organisations and not of others.
A closing note, in fairness to whoever is being asked. This business would have to answer the same ten questions, and the address its own service answers on is an open internal decision at the time of writing. This page is not an implied claim to have solved the problem it describes. It is the list we think a buyer should be holding, including when the person on the other side of the table is us.
You might want to read next
Sources
Four sources, and the two that matter most to this subject are read to different depths. The resolver standard was read at its reference site, including for the things it does not contain. The European standard covering persistence has not been bought and has not been read, and the section that would have depended on it says that rather than describing contents nobody here has seen.
-
CELEX 02024R1781-20240628In forceRelevant provisions reviewed
The availability requirement, the clause carrying it past cessation of activity, the backup copy through an independent third-party service provider and the delegation of the availability period to product-specific acts were all read at the consolidated text. No article number is cited on this page. Two independent reads of the same instrument attributed the passport-establishing provision to two different articles, so the numbering is held as contested until the articles are read verbatim in one sitting, and a contested citation is worse than none.
-
Ratified standardRelevant provisions reviewed
Read at the reference site rather than the marketing site, which was two ratifications stale on the same day the reference site was current. Read for the required behaviours and read as an absence for five things it does not contain, of which three carry this page: no trust model, no continuity or retirement protocol and no caching guidance. It is a resolver standard, and conformance to it is resolver conformance rather than passport conformance.
-
Identifier issuer published fee, allocation and continuity materialIssuer published termsRelevant provisions reviewed
The published fee, allocation and continuity material of national member organisations of GS1. Two things rest on it here. The first is the published statement that product data remains linked as long as membership is renewed annually, which is quoted on this page with its condition attached. The second is the prohibition on transferring or reselling an allocated identifier. Fee and continuity terms across other national organisations were not read and may differ.
-
EN 18221, data storage, archiving and persistence for the Digital Product PassportEuropean StandardBehind a purchase, not bought, not read
The standard covering data storage, archiving and persistence for the passport. It is named here so that a reader can ask for it by name. Its reference is published, so conformity with it carries a presumption of conformity, and that citation state was confirmed through secondary routes rather than at the Official Journal directly. Not one sentence of the standard has been read here, and nothing on this page describes what it requires.
Help someone else make sense of product passports.