EU Digital Product Passport vs UNTP DPP: What Is the Difference and Can They Work Together?
Compare the EU Digital Product Passport with UNTP DPP, including law, registry, identity, data hosting and where UNTP can support EU implementation.

The EU and UNTP both use the phrase “Digital Product Passport”, but they are describing different layers. One is a legal information system created by European product law. The other is an emerging interoperability protocol for exchanging verifiable supply-chain credentials.
Direct answer
An EU Digital Product Passport is a legal construct. Its obligations come from EU legislation and the product-specific rules made under it. Those rules determine which products need a passport, which data must be present, the required granularity, who can access what and when the obligation applies.
A UNTP Digital Product Passport is an emerging UN/CEFACT technical credential pattern. It uses W3C Verifiable Credentials to package product data so that it can be exchanged, discovered and verified across systems.
They can work together. UNTP credentials may carry upstream product or evidence data that a business later maps into an EU DPP. But a UNTP DPP is not a legal substitute for the EU DPP, EU Registry procedures, EU economic-operator identity checks or any product-specific delegated act.
Navigate this page
- Overview
- Direct answer
- The short answer: same words, different jobs
- EU DPP vs UNTP DPP
- Who defines and requires each one
- Data, hosting and the EU Registry
- Identity and trust: eIDAS is not the same as DID
- How UNTP can feed an EU DPP
- What UNTP cannot replace
- A practical architecture for supporting both
- What would change this page
- Keep exploring
- Sources
The short answer: same words, different jobs
The confusion starts because “DPP” sounds like one standard object. It is not.
In the EU, the DPP is part of a regulatory system. The Ecodesign for Sustainable Products Regulation establishes the framework, while product-group rules and other sector legislation determine the actual data obligation for a given product.
In UNTP, the DPP is one credential type inside a wider interoperability protocol. Its purpose is to make product information portable and machine-verifiable across supply chains and jurisdictions.
So the right comparison is not “Which DPP wins?” It is “Which layer is doing which job?”
EU DPP vs UNTP DPP
| Question | EU Digital Product Passport | UNTP Digital Product Passport |
|---|---|---|
| What creates it? | EU law, including ESPR or applicable sector legislation and later product rules | UN/CEFACT technical protocol and specification |
| Is it mandatory? | Mandatory when the applicable EU product law says so | Voluntary unless a contract, programme or other rule chooses to require it |
| What defines the required data? | The applicable EU legal act and product-specific measures | The UNTP credential profile plus the issuer's use case and data available |
| What is the main job? | Regulatory product information, access and market-facing compliance infrastructure | Interoperable exchange of verifiable product data between systems and organisations |
| Where does product data live? | Decentralised outside the EU Registry; the Registry holds identifiers and required metadata | Decentralised; credentials can be hosted and resolved through participating systems |
| How is operator identity handled? | Current Registry rules use Union identity and trust mechanisms, including eIDAS-based methods | Emerging DID and Digital Identity Anchor patterns |
| Does it require W3C Verifiable Credentials or DIDs? | No blanket EU requirement establishes those technologies as the DPP format | Yes, W3C Verifiable Credentials are a core part of the UNTP architecture |
| Current maturity, September 2026 | EU legal framework and Registry are live/current, with product obligations still depending on applicable product rules | Emerging, work in progress and described for pre-production pilots |
The table makes the central point visible: EU DPP is a regulatory outcome; UNTP DPP is an interoperability mechanism.
Who defines and requires each one
The EU DPP gets its authority from law. Under ESPR, the Commission can set product-specific DPP requirements through delegated acts. Sector laws can also establish their own passport requirements. The economic operator responsible for placing the product on the market has to satisfy the applicable legal requirements, not a generic industry interpretation of “DPP”.
UNTP has a different authority model. UN/CEFACT develops the protocol and its technical specification. An organisation can choose to issue or consume a UNTP credential because a trading partner, industry programme or interoperability architecture finds it useful.
That difference is why a UNTP credential cannot make an EU obligation disappear. A technically elegant credential is still only useful for EU compliance if its data, identifiers, access controls, availability and governance meet the actual EU requirements for the product in question.
For the UNTP architecture itself, see what the UN Transparency Protocol is and how it works.
Data, hosting and the EU Registry
The current EU architecture is decentralised in a specific way. The Commission's DPP Registry went live in July 2026. It registers identifiers and required metadata used by the EU system, while the product-passport data itself remains outside the central Registry.
That is not the same thing as saying “there is no central infrastructure”. There is a central Registry function. It simply does not become the universal database for every product field.
UNTP is also decentralised, but for a different reason. It is explicitly designed as a protocol over multiple platforms. Credentials can be held by issuers or service providers and discovered through identifiers and resolvers. There is no requirement to place every credential into one UNTP-owned database.
Those two decentralised models can coexist. An organisation might keep its governed product data in its own systems, publish a legally required EU DPP through its chosen service architecture and also issue a UNTP credential for cross-company exchange.
For the EU architecture in detail, use where Digital Product Passport data lives and the EU DPP Registry enrolment guide.
Identity and trust: eIDAS is not the same as DID
The identity difference is easy to miss because both systems use strong-sounding digital identity language.
For the current EU Registry, Commission Implementing Regulation (EU) 2026/1778 sets operator-verification methods rooted in Union trust and identity mechanisms. Those include qualified electronic signatures or seals, high-assurance electronic identification and qualifying electronic attestations under Union law.
UNTP uses W3C decentralised identifiers and an emerging Digital Identity Anchor pattern to connect digital identifiers with authoritative identity evidence.
These approaches can be mapped or connected in an implementation, but they are not legally interchangeable by default. Control of a DID does not, on its own, satisfy the current EU Registry verification rule. Equally, completing EU Registry identity verification does not automatically give an organisation the credential architecture needed for every UNTP exchange.
The underlying trust question is covered in what a verifiable credential actually proves.
How UNTP can feed an EU DPP
The most useful relationship is upstream interoperability.
Imagine a manufacturer receives conformity evidence, facility information and traceability events from several suppliers. Without a common exchange model, every supplier connection can become a bespoke integration. UNTP offers a way for those upstream parties to issue structured credentials that the manufacturer can verify and map into its governed product record.
That product record can then feed the EU DPP output required for the relevant product group.
A practical flow looks like this:
- A supplier or assessment body issues a credential containing a defined product, facility or conformity claim.
- The receiving business verifies the credential and evaluates whether the issuer and evidence are acceptable for its purpose.
- Accepted facts are mapped into the business's governed product record with provenance and granularity intact.
- The EU DPP publishing process selects the fields, identifiers and access treatment required by the applicable EU rules.
- The responsible economic operator completes the EU Registry and publication steps required for that product.
In that model, UNTP is useful because it reduces translation friction before the EU DPP is assembled. It does not become the law or the compliance decision.
What UNTP cannot replace
A UNTP DPP cannot replace the parts of the EU system that get their authority from EU law.
It cannot, by itself:
- decide whether a product is in scope of an EU DPP obligation
- define the legally required product data or granularity
- create the statutory access-right matrix for a product group
- verify an economic operator for the EU Registry under the current legal method
- complete EU Registry registration requirements
- turn an unsupported product claim into compliant evidence
- prove that the physical product carrying a code is authentic
- guarantee that a product satisfies every applicable EU conformity requirement.
The EU Registry also performs specified automated technical, semantic and coherence checks. Passing those checks is not a universal truth test for every product claim. The legal and evidential responsibility remains wider than successful data submission.
For the current European horizontal standards position, use the DPP standards status page rather than treating UNTP as the owner of that question.
A practical architecture for supporting both
Businesses do not need to choose one master “passport format” and force every system around it.
A stronger architecture has a governed internal record at the centre:
Source systems and evidence → governed product record → channel-specific outputs
The internal record decides which fact is current, what evidence supports it, where it came from and at what level it applies. From there, the business can generate:
- the EU DPP presentation and data services required for a regulated product
- UNTP credentials for partners that use the protocol
- retailer, marketplace or customer feeds
- internal compliance and evidence views.
This keeps the legal obligation and the interoperability protocol in their proper places. It also avoids a common failure mode: making an emerging exchange profile the only place where the business knows what is true about its own product.
What would change this page
The comparison should be rechecked when product-specific EU DPP delegated acts establish more detailed mandatory schemas or access requirements, when the EU Registry identity or technical rules change or when UN/CEFACT publishes a stable UNTP release with stronger conformance and production evidence.
None of those changes would erase the basic law-versus-protocol distinction, but they could make the integration between the two more specific.
Keep exploring
The questions this page usually raises next.
- Another angleNext questionWhat Is the UN Transparency Protocol (UNTP), and How Does It Work?What UNTP is, how its product, conformity, traceability and identity credentials work, and why the protocol remains emerging as of…
- Evidence behind thisNext questionWhat Does a Verifiable Credential Actually Prove? Digital Conformity Credentials and Product TrustLearn what verifiable credentials and Digital Conformity Credentials prove, what they do not prove and how issuer, evidence and…
- CompareNext questionHow to Enrol Your Organisation in the EU DPP RegistryHow EU DPP Registry enrolment works: EU Login, organisation verification, QSeal or QES, Commission declaration, rejection handling…
Sources
-
EU law
-
Delegated act
-
European Commission
Does this reach your products?
Give ActivateDigital one product and it works out which obligations apply from the product's own character, and says which it cannot decide.