Industry Strategy閱讀中文版

Products Need a Résumé Too: The EU's DPP Registry Is Live — Who Controls Taiwanese Suppliers' Data?

The EU's DPP Registry has gone live, but not every product becomes mandatory on the same day, and it does not mean a complete data set gets uploaded to a central EU database. What Taiwanese suppliers really need to decide now is who controls identifiers, hosting, access, updates and transfer.

🗓 2026.08.2418 min read8 sourcesThe Geopolitical Review Editorial Team
Products Need a Résumé Too: The EU's DPP Registry Is Live — Who Controls Taiwanese Suppliers' Data?
Article contents01 / 11
Key Points
  • What went live on 20 July 2026 is the DPP Registry and its testing environment — not a single day on which all products sold into the EU become subject to mandatory digital product passports.
  • The Registry stores identifiers, registration data and high-level metadata; the complete DPP data set is, in principle, kept in distributed storage.
  • Product-specific delegated acts decide the data fields, granularity, access roles and applicability dates; batteries additionally carry a statutory milestone of 18 February 2027.
  • Taiwanese suppliers should control five governance levers — identification, hosting, access rights, updates and transfer — to avoid being locked in by a single customer or platform.
3-Layer Architecture

“Products Need a Résumé Too: The EU's DPP Registry Is Live — Who Controls Taiwanese Suppliers' Data?” reports that A DPP does not cram all data into one QR code(3-Layer Architecture)。 Product data carrier → identifiers and metadata in the EU Registry → detailed data kept in distributed storage by economic operators and released by role。

3 Kinds of Dates

“Products Need a Résumé Too: The EU's DPP Registry Is Live — Who Controls Taiwanese Suppliers' Data?” reports that Statutory dates, indicative planning and unknown dates cannot be treated the same(3 Kinds of Dates)。 Certain large batteries already have a statutory milestone; steel, textiles, aluminium and tyres remain at the planning stage; final applicability and transition dates for each product await formal rules。

On 20 July 2026, the European Union's Digital Product Passport registration system officially went live. [1] For Taiwanese exporters, this news is easily translated into an anxiety-inducing command: "From now on, every product sold into Europe needs a QR code, and supply-chain data has to be uploaded to the EU." Neither reading is accurate.

What went live is the common DPP Registry and its testing environment, not a single day on which all products become subject to mandatory digital product passports. The Registry primarily records unique identifiers, registration data and high-level metadata for products, operators and facilities; the full content of a product passport is, in principle, kept in distributed storage by economic operators, rather than being concentrated entirely in an EU database. [1][2]

Exactly which data a product must disclose, who can view it, whether it must reach the level of a model, batch or individual unit, and when it starts to apply, is still determined by the delegated acts or product-specific rules for each product group. [3][4][5] So July 2026 is an important milestone for the institutional infrastructure, but it is not a finish line where every industry starts the race on the same day.

That said, companies cannot simply keep waiting either. The genuinely difficult part of the digital product passport was never printing a QR code — it is stitching materials, manufacturing processes, environmental data, repair, recycling and compliance information into a credible chain of evidence, and deciding who controls the identifier, the data hosting, access rights, update responsibility and the ability to switch service providers. For Taiwanese suppliers, these five levers of control are the concrete substance of "data sovereignty."

A DPP Is Not an Electronic Label — It Is a Data Governance System

The EU's Ecodesign for Sustainable Products Regulation (ESPR) establishes the common framework for the DPP. [3] A product or its documentation carries a data carrier that links to the passport, such as a QR code or another machine-readable format; the information within the passport may then be made available to consumers, business partners, repairers, recyclers, customs and market surveillance authorities according to different roles. [5] The same product can have a public layer, a commercial layer and a regulatory layer — not everyone sees all of the data.

This architecture has at least three layers. The first is the physical product and its data carrier, which lets a person or a machine locate the corresponding passport. The second is the EU Registry, which holds the core identifiers and metadata used for identification and oversight. The third is the detailed product data, kept by the responsible economic operator or the service architecture it chooses, and released according to permissions. [1][2]

Conflating these three layers produces two opposite misunderstandings. One is panic — the belief that the EU is going to collect a company's formulas, supplier lists and carbon data all at once into a central pool. The other is complacency — the belief that buying a bit of code-generating software finishes the job of compliance. In fact, the Registry does not centrally store all the details, but companies still have to ensure the data is usable, updatable, verifiable and accessible throughout the product's life cycle. Distributed storage gives companies architectural choice, but it also leaves the operational responsibility with them.

A Common Framework Going Live Does Not Mean Every Product Is Already Mandatory

ESPR is a framework regulation. It sets out what types of information a DPP can carry, principles of identification and interoperability, obligations for economic operators, and how customs and competent authorities may use it — but the specific requirements for each product group must be set by subsequent delegated acts. [3] Textiles, for instance, might emphasize fibre composition, durability and repairability; steel might emphasize the origin of materials and carbon emissions; electronics might involve components, software, security updates and recycling.

The European Commission has published the ESPR Working Plan 2025–2030, listing steel and aluminium, textiles, furniture and tyres among its priority products. [8] The official DPP timeline also lists several quarters in which delegated acts are expected to be adopted. [4] But the Commission itself notes that many of these dates are "indicative" — that is, planning estimates. When a delegated act is formally adopted, how long its transition period will run, and when companies must comply, still depends on the final legal text.

One clearer exception is batteries. The EU Battery and Waste Batteries Regulation already provides that, from 18 February 2027, electric-vehicle batteries, light means of transport batteries, and industrial batteries with a capacity greater than 2 kWh must carry a battery passport. [7] This is a date fixed directly in the regulation, and it carries stronger evidentiary weight than an estimated quarter in a working plan.

Companies' timelines should therefore be sorted into at least three colours: applicability dates already fixed by formal rules; indicative dates on which the Commission expects to propose or adopt rules; and watch-list items whose final fields and transition periods are not yet known. Marking all three as "deadline" will misallocate resources, and it may also lead a company to make promises to customers that it cannot keep.

Non-EU Manufacturers Are Not Exempt Simply Because of Distance

The DPP is part of the EU's market-access regime. Once a product group's rules require a DPP, imported products must comply as well — a manufacturer being located in Taiwan is not an exception. [3][5] In practice, the chain of responsibility can involve the manufacturer, the EU importer, the authorised representative, distributors, online platforms or fulfilment service providers; the obligations of each role still have to be judged against the specific product rules and the actual commercial relationship. [6]

This has one direct consequence for Taiwanese suppliers: EU customers are very likely to require upstream suppliers, through procurement specifications, to provide fields on materials, carbon emissions, durability, recyclability or compliance well before the statutory date arrives. Large brands and importers are responsible for the products on the market, and they will naturally push data requirements up the supply chain. Even if a supplier is not the final legal registrant, it may still be the producer of most of the underlying evidence.

There is another consequence: a power asymmetry. If an importer says "just hand the data to me, and I'll build the passport for you," that may be the least effort in the short run. But if all the identifiers, accounts, hosting contracts and data formats sit in the customer's hands, a supplier that later needs to switch distributors, enter another EU member state, or handle a recall or repair may find it cannot take its own product history with it. Outsourcing compliance should not amount to surrendering governance.

Reasonable inference | medium-to-high confidence: the later data responsibility is clarified, the more likely it becomes that the large customer closest to the EU market unilaterally defines the fields, the platform and the cost allocation. This is not something the DPP regulation itself mandates — it is a consequence of bargaining power within the supply chain.

The First Line of Data Sovereignty: Who Owns the Product Identifier

The entry point of a DPP is unique identification. A company first needs to know whether the identified unit is a model, a batch or an individual product, and it must link the product identifier to the economic operator's and facility's identifiers. [2][3] The finer the granularity, the more precise tracing and recalls become, but the greater the data volume, update frequency and serial-number governance also become. The final granularity is set by the product-specific rules.

Taiwanese suppliers should ask in their contracts: who applies for and maintains the identifier? Can it continue to be used if the customer changes? When the same product is supplied to multiple brands, is there a shared base identifier or does each get its own label? If a contract manufacturing relationship ends, who keeps the historical passports? Without these clauses, what looks like a purely technical coding decision can turn into a lever of market-access control down the road.

Identifiers also cannot be reused arbitrarily. There must be versioning rules for how much a change in product design, materials or manufacturing process requires a new passport. If a company only generates codes on an ad hoc basis through sales staff, without any link to engineering change control and quality systems, the passport will quickly drift out of sync with the physical product.

The Second Line: Where Detailed Data Is Stored

The EU's choice of a distributed architecture means companies can choose how to store detailed data under the rules, but they must also ensure it is accessible, interoperable and usable over the long term. [1][2][5] Common options might include building it in-house, using a customer's platform, an industry data space, or a third-party DPP service provider. Every option carries cost, and every option carries exit risk.

Building it in-house gives a company more control, but it must also bear the cost of cybersecurity, availability, standards changes and long-term maintenance. Using a customer's platform is easier to integrate but risks lock-in to a single buyer. Using a third-party service means checking data portability, what happens if the provider goes out of business, cross-border backup, sub-processors, and liability for security incidents. Where the data is stored is only one question — who can decide to move it and export it matters more.

"Keeping the data in Taiwan" does not automatically equal data sovereignty either. If an EU customer controls every account, access policy and identifier, a supplier still has no real decision-making power even if the server sits in Taipei. Conversely, if a company retains original evidence, portable copies, access logs and transfer clauses, it may retain fairly complete governance capacity even while using a European service provider.

The Third Line: Who Can See Which Layer

The value of a DPP comes from letting the right people access the right data at the right time — not from making all of the data completely public. [3][5] Consumers may need information on materials, repair, durability and recycling; repairers need parts and disassembly instructions; customs need identification and compliance verification; market surveillance authorities may need deeper technical documentation. Commercial customers, meanwhile, may ask for proof of carbon footprint, origin and quality.

Taiwanese companies should build a "role–field–purpose–retention period" matrix. Every field should have a known legal basis or commercial purpose, a source system, who is permitted to access it, who updates it, and how many years it is retained. Supplier formulas, yield rates, production capacity, prices and complete supplier lists should not be opened without limit simply because a platform's default setting does so, unless the law actually requires it.

At the same time, trade secrecy cannot be used as a blanket excuse to refuse all disclosure. When a delegated act requires specific material or environmental information, a company needs to design the right level of granularity between legal compliance and protecting confidential information — for example, providing a verified ratio, region or certificate rather than publishing the formula and every tier-two supplier directly. Whether this is ultimately possible still depends on the product-specific rules.

The Fourth Line: How Data Gets Updated, and Who Is Responsible for Errors

A product's history is not generated once at the point of shipment and then frozen forever. Repairs, part replacements, software security updates, recalls, changes in material sourcing, and recycling handling may all require the passport to be updated. If manufacturers, importers, repairers and recyclers can all write to it, a company needs to define who may modify which field, whether verification is required, and how old versions are preserved.

Taiwanese suppliers are especially prone to fragmentation across systems: material data sits in procurement or the ERP system, design versions sit in the PLM system, process and batch data sit in the MES, carbon data sits in a spreadsheet or a consultant's report, and after-sales records sit in the customer's system. What a DPP requires is not a one-time upload of all these files, but building a stable link between the product and its evidence.

A trustworthy field should at minimum have a source, a calculation method, a timestamp, a version, and a responsible party. If a carbon-footprint figure is just a number entered on some past questionnaire, with no way to explain its boundaries, coefficients or product version, then no matter how polished the QR code looks, it will not hold up when a customer audit or a regulator's inquiry eventually comes.

The Fifth Line: Can the Passport Survive After the Partnership Ends

ESPR looks at a product's entire life cycle, which can outlast the partnership between a brand, an importer or a software service provider. [3] Years after a product is sold, consumers may still need repair information, regulators may still investigate compliance, and recyclers still need to read material and disassembly data. Contracts therefore must address service termination, company insolvency, customer changes and data migration.

Companies can require: regular exports of machine-readable data; preservation of identifiers and version mappings; a transition period if a third-party service stops operating; portable copies of the original evidence and access logs; and a technical interface for a new service provider to take over. These are not information-governance luxuries reserved for large enterprises — they are the minimum insurance a small or medium-sized supplier needs against being locked in.

What remains unknown is which interoperability standards the market will eventually settle on, whether the EU will impose more detailed requirements on data service providers, and whether each industry will converge on a small number of platforms. Precisely because these things are unknown, current investment should prioritize a portable data model and evidence governance, rather than locking every process into a single tool that has not yet been validated against the product-specific rules.

Different Industries Are Running on Different Clocks

The battery supply chain is under the most pressure. Certain large batteries already have a statutory passport milestone of 18 February 2027. [7] Suppliers need to match the battery regulation's data requirements, responsible roles and life-cycle obligations, rather than waiting for the general ESPR delegated acts. Taiwanese companies making cells, modules, materials, battery-management systems or recycling services may already have their data interfaces requested early by EU vehicle makers or importers.

Steel, aluminium, textiles, furniture and tyres are priority products under the ESPR working plan. [8] These industries should track the product research, consultations and draft delegated acts, but they should not treat the Commission's planned quarters as fixed effective dates. A more sensible approach is to build common fields and evidence first, and add product-specific requirements once the drafts become clear.

Electronic-component makers, meanwhile, should note that their own parts may not immediately become independent DPP subjects, but downstream customers may still request data for a finished product's passport. A supplier's exposure comes not only from direct legal applicability but also from customer contracts. Whether a product is "on the list" is not the only question — what matters more in practice is whether your data will be used by a downstream customer to fulfil its own obligations.

A Ninety-Day Preparation Checklist for Taiwanese Companies

In the first month, define the scope. List the products exported to the EU, the EU importers, customer brands, applicable rules and expected product groups; separate what already has a confirmed statutory date from what is only indicative timing or still unknown. Do not buy a system before asking what products you actually have.

In the second month, build a data inventory. Pick one high-exposure product and list where its material, sourcing, environmental, durability, repair, software, compliance and recycling data currently live, who produces it, and whether it has a version and supporting evidence. Sort the gaps into "no data," "data exists but is not trustworthy," and "trustworthy but not linked to the product."

In the third month, build governance and contract baselines. Decide who is responsible for the identifier, data hosting, role-based access, the update process, audit logs and exit portability. Confirm with EU customers who is the registrant, who is liable for errors, and who pays for the platform and verification costs. If the final delegated act has not yet been published, the contract should keep a mechanism for adjustment.

These ninety days will not complete DPP compliance, but they will keep a company from being left, when a customer makes a demand, with only two options: hand over all the data, or offer no response at all.

Conclusion: The Passport Belongs to the Product — Governance Should Not Be Given Away by Accident

What is confirmed is that the DPP Registry went live on 20 July 2026, and the EU's common identification and registration infrastructure is now operating; the complete DPP data set is not stored entirely in one central location, and the specific obligations for each product are still determined by product-specific rules. [1][2][3]

Another confirmed point is that imported products are not automatically excluded because their manufacturing takes place in Taiwan, and certain large batteries already have a statutory milestone of 18 February 2027. [5][7] Dates such as those for steel and textiles in the working plan are mostly indicative and must wait for the formal delegated acts.

Reasonable inference | medium-to-high confidence: the DPP will make data quality and governance capability part of market access. If a Taiwanese supplier hands its identifier, hosting account, access rules and data copies entirely to a single customer, it may save costs in the short run, but in the long run it may lose the ability to switch customers, handle after-sales issues, and demonstrate its own value.

What remains unknown is the final fields, applicability dates, industry formats and platform market for most product groups. These unknowns are not a reason to delay preparation — they are a reminder for companies to invest first in the foundations that are unlikely to be regretted later: data inventory, chains of evidence, an access-rights matrix, version governance, and portability clauses.

The Digital Product Passport is not just the EU adding an electronic ID card to products. It turns data that was once scattered and silent across a product's life cycle into infrastructure that customers, regulators, and repair-and-recycling systems can all demand access to. What Taiwanese suppliers really need to ask is not who will print the QR code for them, but this: once a product has a readable, verifiable, persistent history, who has the right to name it, store it, update it, open it up, and carry it away.

Sources

  1. European Commission — Digital Product Passport Registry now live
  2. European Commission — DPP Registry
  3. EUR-Lex — Regulation (EU) 2024/1781, Ecodesign for Sustainable Products Regulation
  4. European Commission — Digital Product Passport
  5. European Commission — Digital Product Passport FAQs
  6. European Commission — DPP for economic operators
  7. EUR-Lex — Regulation (EU) 2023/1542 concerning batteries and waste batteries
  8. European Commission — ESPR Working Plan 2025–2030