Skip to content

Not everything in a passport is public. For textiles, nobody has been told which parts are.

The framework is built for differentiated access. It names a long list of actors who are to reach a passport according to their respective access rights, it bounds what a passport may contain to a closed list of twelve elements, and it hands the question of who gets which of them, and who may write to the record, to the delegated act covering each product group. No such act has been adopted for textiles. The European standard written to answer that question is one of two, out of eight, whose reference the Commission has not published. So the answer today is that whatever a business publishes is an access decision it has taken, whether or not it noticed taking one.

Sources as at
28 August 2026
Share
LinkedIn X Email
On this page

What the framework establishes, provision by provision

Five provisions do the work.

Article 9, on what a delegated act must specify. Two of its points carry this whole subject: the actors that are to have access to data in the passport and to what data they are to have access, and the actors that are to create a passport or update the data in one and what data they may introduce or update.

Article 10, on the essential requirements for the passport. It requires that access be regulated in accordance with the specific access rights at product group level as specified in the applicable delegated act. It separately provides that personal data relating to customers is not to be stored in the passport without their explicit consent.

Article 11, on technical design and operation. This one names the audience, and the list is longer than most people expect: customers, manufacturers, importers, distributors, dealers, professional repairers, independent operators, refurbishers, remanufacturers, recyclers, market surveillance authorities and customs authorities, civil society organisations, trade unions and other relevant actors are all to have free of charge and easy access, based on their respective access rights set out in the applicable act. The same article restricts the rights to introduce, modify or update data on the same basis.

The restriction on service providers, in the same article. Where a passport is stored or otherwise processed by a passport service provider, that provider is not to sell, reuse or process the data beyond what is necessary to provide the service, unless specifically agreed with the economic operator placing the product on the market. Read the last clause. It is a default contract term rather than a prohibition, and the party who can agree it away is the party being asked to sign the contract.

Article 14, on the web portal. The Commission is to set up and manage a publicly accessible portal allowing stakeholders to search for and compare data included in passports, designed to guarantee that they can search and compare in a manner consistent with their respective access rights specified in the delegated acts.

Annex III, on what a passport may contain. The delegated act specifies what data are to or can be included in a passport from among twelve listed elements. Read them once, because the list is the outer edge of the whole subject: information required under the framework's information requirements or by other Union law applying to the product group; the unique product identifier at the level the act indicates; the Global Trade Identification Number or equivalent; relevant commodity codes such as a TARIC code; compliance documentation such as the declaration of conformity, technical documentation or conformity certificates; user manuals, instructions, warnings or safety information required by other Union law; information related to the manufacturer including its unique operator identifier; unique operator identifiers other than the manufacturer's; unique facility identifiers; importer information including its EORI number; the responsible economic operator established in the Union; and the reference of the service provider hosting the back-up copy.

That list has a shape. Eleven of the twelve are identity, documentation or instruction. The one that carries substantive product claims is the first, and it is a pointer to requirements set elsewhere rather than a list of its own.

The carrier, the data and the access right are three separate questions

The most common error in this territory is to collapse them into one.

The carrier is public by design. Article 10 requires a passport to be connected through a data carrier to a persistent unique product identifier, and requires the carrier to be physically present on the product, its packaging or accompanying documentation. Anybody holding the garment can read it.

The data it resolves to is a separate object, and nothing in the framework says all of it is public. Article 10 requires that access to the data be regulated in accordance with the access rights specified at product group level.

The access right is a third thing again, and it is the one nobody has set for textiles. Article 11 requires the named actors to have free and easy access based on their respective access rights, and empowers the Commission to adopt implementing acts setting out procedures to issue and verify the digital credentials of operators and other actors that have access rights. A credentialling scheme is not the architecture of an open document.

So a scannable code does not mean an open record. It means an open front door to a building whose rooms have not been allocated yet.

A note on the article numbers, because this estate withheld them for a long time. They are cited here because the consolidated text of the framework was read directly at the Official Journal on 28 August 2026, with the article headings visible, and the numbering was then checked against a Commission implementing decision which states that passports conforming to cited harmonised standards are presumed to conform with the requirements set out in Articles 10 and 11. A direct read of the enacting terms plus an adopted Union act agreeing with it is as good a warrant as this subject offers.

The confidentiality provisions that are not there

A negative finding, stated with what was searched, because it is the most useful thing on the page.

Across the whole of the enacting terms, read in full, the phrase confidential business information appears twice. Once in Article 5, in the list of things the Commission is to do when it prepares ecodesign requirements, where it is to take into consideration the protection of confidential business information. Once in Article 7, as one ground among several on which the Commission may exempt a substance of concern from an information requirement, with an express carve-out preventing that exemption reaching substances present above a stated threshold. The phrase commercially sensitive returns no occurrences anywhere in the instrument. Trade secret returns none. Confidentiality otherwise appears only in the provisions on notified bodies and on Commission investigations, which are different subjects. Intellectual property appears twice, in Annex I and in a provision about the destruction of unsold goods, and neither is about the passport.

The protective language people quote comes from the recitals. One recital says the passport is expected to let value chain actors and authorities do their work without endangering the protection of confidential business information. Another says that, to optimise access to the data while also protecting intellectual property rights, the passport needs to be designed and implemented in a manner that allows differentiated access depending on the type of data and the typology of stakeholders.

Both sentences are genuine and neither is an operative provision. A recital explains why an instrument was drafted as it was. It is read to interpret the articles, and it does not create a right the articles do not.

The registry is the other place people look, and it is not there either. The implementing regulation establishing the digital product passport registry was searched for confidential, confidentiality, commercially sensitive, business confidentiality, trade secret, sensitive information and a reference to the trade secrets directive. Trade secret returns none. Commercially sensitive returns none. Business confidentiality returns none. The trade secrets directive is not referenced. Confidentiality appears twice and both are information security rather than commercial protection: a requirement that delegated access be carried out in a way that ensures the security, integrity and confidentiality of registry data, and a requirement that log measures ensure the immutability and confidentiality of the logs. What registration does commit an operator to is on registering a passport.

So the honest position for a business worried about publishing something commercially sensitive is this. The framework gives you no right you can exercise over the contents of a passport. It gives you a Commission that must take confidentiality into consideration when it writes the act, a ground on which the Commission may exempt a substance from disclosure, and a recital saying the design should allow differentiated access. What protects a value is that the act covering your products does not require it to be published, and for textiles no act exists to require or not require anything.

Two things narrow the worry, and both come from Annex III. The first is that the passport's possible content is a closed list rather than an open field, so the question is never whether a delegated act could demand anything at all. The second is that the commercially sensitive things businesses name when asked, which are formulations, unit costs, supplier terms and process detail, are not on that list. What is on it, at points (h) and (i), is the identity of operators other than the manufacturer and the identity of facilities. That is the pressure point, and it is dealt with below.

The standard that answers this question is one of two the Commission has not cited

A joint technical committee was asked to produce eight European standards for digital product passports. A Commission implementing decision of July 2026 published the references of six, and a published reference is what carries a presumption of conformity. Two were left out.

One of the two covers data authentication, reliability and integrity. The other covers access rights management, information system security and business confidentiality. That is the document written to answer this page's question.

The status of those two is more specific than simply uncited, and the specifics are the interesting part. Every national standards catalogue this estate could reach records both as drafts issued in 2025, not as published European standards. No catalogue record exists at any body we reached for a 2026 edition of either. Against that, the standards bodies' own announcement of July 2026 lists all eight in published form and states that six of the eight have been cited. Whether the remaining two have since been ratified is not established by us.

There is a further detail worth carrying with care. The draft of the standardisation request behind this work, published on Commission infrastructure and explicitly marked as a draft, asked for all eight standards with a deadline of 31 December 2025. The adopted request is a different document, named in the citation decision as an implementing decision of 2024 as amended in 2025, and neither adopted text could be read. So the deadline is a draft deadline and may well have moved. What can be said is that the two standards still outside the Official Journal are the two covering access and integrity, and that in the draft mandate they carried the same deadline as the six that made it.

Two guards before anybody makes more of this than it will carry. It is an observation about which titles a list contains, not about the contents of either standard, neither of which has been bought or read here. And a standard outside the presumption is not a prohibited standard: it is a standard whose correct application does not, by itself, produce a presumption of conformity.

That presumption is also narrower than the phrase suggests. On the implementing decision's own words, passports in conformity with harmonised standards or parts of them, whose references have been published in the Official Journal, are presumed to conform with the requirements set out in Articles 10 and 11 covered by those standards or parts. It is bounded by subject, to two articles, and bounded again by coverage, to the parts actually cited. What that is worth in practice is set out on which passport standards carry a presumption.

There is one sentence in that draft mandate that bears directly on the argument of this page, and it is quoted here at draft depth rather than as a requirement. It says that it will be the economic operators placing products on the Union market who are responsible for managing the corresponding access rights. The instruction the standards were asked to implement, in other words, was that this decision belongs to you.

The portal is built for comparison, not for scanning

Article 14 changes the commercial calculation and it is almost never mentioned.

The picture most people hold of a passport is one shopper, one garment, one scan. The framework also requires the Commission to set up and manage a publicly accessible portal through which stakeholders search for and compare data included in passports. Comparison across producers is the stated purpose, not a side effect.

Two limits before the consequence. The portal is a framework provision rather than a running service, and no textile data can reach it until a textile act exists. And the same provision requires the portal to be designed so that stakeholders search and compare consistently with their respective access rights, which means it is not a bulk download of everything to everybody. What a party can compare is what that party could see anyway.

The consequence still holds. A field a textile act eventually marks public will not be published once per garment to whoever happens to be holding it. It will be published into a searchable, comparable set alongside the same field from every other brand in scope. A value that is unremarkable on a swing tag can be a different object entirely in a column next to four hundred competitors.

That is not an argument against publishing. It is an argument for knowing, before a field is designed, whether the value is one you would be comfortable seeing sorted. And it is why the access question is a commercial question rather than a technical one.

Personal data, and the answer the same legislature gave next door

The framework's position on personal data is a consent gate rather than a prohibition. Article 10 provides that personal data relating to customers is not to be stored in a passport without their explicit consent, referring across to the data protection regulation. A recital puts it more flatly and says personal data of customers should not be stored in a passport. The recital is the policy and the article is the rule, and the article leaves a door open that the recital does not.

Our own view is that the door should not be used, and the reason is the object rather than the law. A passport is reached from a printed code on something that is sold, resold, lent, altered and eventually sorted by somebody who has never met the first owner. The code cannot be withdrawn, the consent was given by a person who is no longer in the picture, and the record is designed to outlive the product. Access control can protect the data behind the carrier. It cannot make a consent given at first sale mean anything to the fourth owner. So the operational rule this estate applies is to keep personal data out of the record entirely rather than to design a consent flow for it.

There is a second question underneath the first and it is about the scan rather than the record. Whether measuring the people who use a compliance carrier is permitted at all is not a question the framework answers, and one European regime that already places mandatory product information behind a code answered it in the opposite direction and refused consent as a cure. That comparison, its limits and the reasons it does not simply transfer to clothing are set out on what a scan actually tells you, which is the page that owns it.

What the industry has asked for, and where it meets the enacted text

The sector's trade association published a position on the apparel passport in March 2026, and it is the clearest available statement of what businesses in this industry want protected. It asks for access differentiated by user category, for access limited to what is strictly necessary for each user, for a clear separation between public, restricted and confidential data, and for protection against automated data extraction and misuse. It asks that disclosure of factory names, locations and operator identifiers remain optional, on the ground of business confidentiality and competitiveness. And it names what it means by confidential business information: supplier and customer networks, specific materials, formulations and production processes.

An industry position is evidence of what part of an industry is asking for. It is never evidence of what an act will require, and this page treats it as the first rather than the second.

Two of those asks are already in tension with the framework as enacted, and naming the tension is more useful than either endorsing or dismissing the position.

Facility identifiers. Annex III lists unique operator identifiers other than the manufacturer's at point (h) and unique facility identifiers at point (i), so both are already inside the set a textile act may draw on. Article 12 goes further. Where either identifier is not yet available, the operator that creates or updates the passport is to request one on behalf of the relevant actor, after first seeking confirmation from that actor that none exists, and is to pass the issued identifier back to them. That is an obligation to obtain identity, pointed at exactly the layer the position paper wants kept optional. Whether an obtained identifier is then published is a different question and the delegated act will answer it. But the obligation to obtain sits in the enacting terms and the discretion to withhold does not.

Automated extraction. Article 14's portal exists so that stakeholders can search and compare. A field a delegated act marks public is a field designed to be compared in bulk, by anybody the access rights admit. Protection against automated extraction of public fields and a comparison portal are not obviously compatible objectives, and only one of them is in the enacted text. The ask is coherent for restricted fields, which is where it should be pointed.

None of that makes the asks unreasonable. It makes them asks about the delegated act, which is the only instrument that can grant them, and it means a business planning on the assumption that they will be granted is planning on a hope.

The one sector far enough ahead to have faced this has not finished either

Batteries are years ahead of textiles and are routinely offered as the worked example of how access tiering will look. It is worth knowing what state that example is actually in.

The battery regulation does contain a tiered structure, with different parts of the passport available to different audiences. We could not reach those provisions or the annex behind them at their own text on any route, so this page states that the structure exists and reproduces none of it. A secondary account of the tier mapping was obtained and is not published here, because a Commission document appears to cut against it and publishing a mapping that a Commission document contradicts would be the worst outcome available.

What we did reach, at the Commission's own presentation for that sector of May 2026, is the shape of what is still missing. An implementing act is to specify which persons are to be considered persons with a legitimate interest, to which of the listed information they are to have access, and to what extent they can download, share, publish and re-use that information. As at the date of that presentation the act had not been adopted: a working document had been circulated to the battery expert group in April 2026, a draft was to be published for consultation in the following months, and the Commission's own scheduling placed the act in the last quarter of 2026.

Read that list of verbs. Whether a party who may see a value may also republish it is a different question from whether they may see it, and in the one sector far enough ahead to have faced it, it is being answered by a further instrument rather than by the regulation.

So the lesson from batteries is not a template to copy. It is that a tiered structure in a regulation leaves the operationally decisive questions to an instrument that comes later, and those questions are the ones a business actually needs answered.

The same shape is visible in the textile preparatory work. The study on passport content contains a section on access rights, including an assessment of access rights levels, and a section on data governance covering roles and responsibilities, acquisition and update, storage, integrity and verification. This estate established that both sections exist and where they sit, and could not read either. So even the proposal stage of the textile answer is written down somewhere and is not available to read.

What to keep out, and how to decide the rest

Five rules survive with no act at all. They are not compliance requirements, because there is nothing to comply with. They are the decisions a business is taking whether or not it takes them deliberately.

Keep personal data out of the record entirely. Not behind consent, not behind a tier. The record outlives the arrangement that authorised it, and no tier you set today follows the garment through four owners.

Decide, for each field, which of the two questions it belongs to. Is this a value you would print on the swing ticket, or a value you would show only to a named audience. The first goes in the public view. The second goes in the record with the access question written down beside it, and waits. What must not happen is a field entering the public view because nobody asked which of the two it was. Treating an unrestricted view as a semi-private channel is the most common design error in this category, and it is made once and discovered later.

Hold the evidence separately from the value. A value can be published without publishing the working, and the working is where supplier names, prices, formulations and internal method usually live. A system that stores the two in one object has decided a confidentiality question by accident. Who stays responsible for a value once it is out, and what a sign-off actually consists of, is on who has to own this.

Ask what each audience can act on rather than what is easy to expose. A recycler asking for end-of-life handling and receiving a marketing page has been given something worse than nothing. What a request actually reaches, and what a conformant resolver is and is not required to do when it holds nothing, is on what happens when you scan.

Write down the access decision you took and why. Where the law supplies no procedure, the record is the procedure. When an act arrives and names actors and tiers, a business that can say what it published to whom, and on what reasoning, is doing an afternoon's mapping. A business that cannot is doing an audit.

One thing this page will not do is give you a tiering model. There is no authority behind one, the standard that would supply the vocabulary is behind a purchase and is unread here, and a model invented for the purpose would be exactly the thing this estate exists to correct in other people. What can be said is which questions a tiering will have to answer, and those are the five above.

What would change this page

A textile act naming actors and access levels, at which point most of this page is replaced rather than revised.

The reference of the access rights standard being published in the Official Journal, which would give the subject its first document carrying a presumption of conformity.

The implementing acts on digital credentials, which Article 11 empowers the Commission to adopt and which would be the first description anybody has of how an access right is actually asserted at a resolver.

An implementing act in any sector defining who counts as a person with a legitimate interest and what they may do with what they see, which would be the first worked answer anybody has to the question this page is about.

You might want to read next

Since you have read this, these may answer the questions that usually come next.

Sources

  • In forceRelevant provisions reviewed

    CELEX 32024R1781. In force. Read in full at the Official Journal HTML rendering, 28 August 2026, including Annex I and Annex III. The load-bearing source. Read for Article 9 delegating access rights and update rights to a delegated act, Article 10's essential requirements including the carrier condition and the consent condition on customer personal data, Article 11's actor list, its restriction on write rights, its restriction on service providers and its empowerment for implementing acts on digital credentials, Article 12's identifier obligations, Article 13's registry and Article 14's portal, and Annex III's twelve elements and the standards paragraph beneath them. Read as an absence for the confidentiality finding, with the whole instrument searched rather than a sampled range.

    View official source

  • In forceReviewed in full

    CELEX 32026D1736. In force. Annex read; recitals read. Three propositions rest on it: the six references published in its annex; the absence from that list of the standards on access rights management and on data authentication; and the statement of what the presumption of conformity covers. Its recitals also name the adopted standardisation request and its amendment. It is now a corroborating source for the article numbering rather than the sole warrant for it, since the framework itself has been read.

    View official source

  • EN 18239, digital product passport, access rights management, information system security and business confidentiality
    European StandardBehind a purchase, not bought, not read

    European standard. Catalogue entries read at two national standards bodies. Standard behind a purchase, not bought, not read. Named so that a reader can ask for it by name. The title is confirmed identically at two bodies. Both record it as a draft issued in 2025 and no body reached carries a 2026 edition. Not one sentence of the standard has been read here and nothing on this page describes what it requires.

  • Draft standardisation request for digital product passports
    ProposedRelevant provisions reviewed

    Draft, not adopted. Read at the document itself. Two propositions rest on it and both are stated at draft depth. That the request asked for the eight standards with a deadline of 31 December 2025, and that it states the economic operators placing products on the Union market will be responsible for managing the corresponding access rights. The adopted request and its amendment are named in the implementing decision above and neither was read, so the adopted text may differ.

  • In forceRelevant provisions reviewed

    CELEX 32026R1778. In force. Read at the Official Journal in two renderings, with a term search. Registered for a negative finding. Seven terms were searched and no confidentiality, commercially sensitive, business confidentiality or trade secret provision was found. The two occurrences of confidentiality are in an information security sense and are described here. Internal article numbering is not published on this page, because it rests on fewer independent reads than the framework numbering does.

    View official source

  • EURATEX position on the digital product passport for apparel
    Industry positionRelevant provisions reviewed

    Industry position. Read at the association's own published paper. Evidence of what part of the industry is asking for, never evidence of what an act will require. The document is bulleted rather than continuous, so its asks are described here and none of its wording is presented as continuous prose.

  • European Commission presentation for the battery sector on the digital product passport
    Institutional guidanceRelevant provisions reviewed

    Institutional material. Read at a Commission-hosted file. Behind three propositions: that an implementing act is to specify which persons are persons with a legitimate interest and what they may download, share, publish and re-use; that the act had not been adopted, with a working document circulated to an expert group in April 2026 and a draft to follow; and that the Commission's own scheduling placed it in the last quarter of 2026. No statutory deadline is stated on this page, because two secondary sources give different dates and neither was checked against the regulation. The battery regulation's own tiering provisions and the annex behind them were not reached and none of their content is reproduced here.

  • Joint Research Centre, study on DPP content for textile apparel products under ESPR, 13 May 2026
    Pre-decisional researchCover and contents read, the substance not reachable

    Pre-decisional, and pre-publication. Front matter and contents read; the substantive sections were not reachable and were not read. Used for one proposition: that the study contains a section on access rights, including an assessment of access rights levels, and a section on data governance, and that neither could be read.

Worth sharing?

Help someone else make sense of product passports.

LinkedIn X Email