Logo

DPP Compliance - An Overview of Responsibility and Liability

Reading time:

minutes

When it comes to the Digital Product Passport, simply making data available technically is not enough. It is also crucial to determine who is responsible for ensuring that the data is accurate, complete, and up-to-date. A governance issue can quickly arise, particularly in international supply chains: data comes from suppliers, is stored in different systems, and may be published via an external DPP service provider.
For company management, the DPP thus also becomes a compliance task.

Who is responsible?


The ESPR requires that the data in the Digital Product Passport be accurate, complete, and up-to-date. The specific DPP requirements are determined by the relevant product-specific legal acts.


The role of the economic operator is relevant here. Depending on product law, obligations may be assumed by manufacturers, importers, authorized representatives, distributors, or other parties, among others.


Therefore, what matters is not only who technically enters the data into the DPP, but also who makes the product available on the EU market and under what conditions.

 

A service provider does not automatically transfer responsibility


Companies may use specialized DPP service providers for storage, provision, or other technical functions. However, this should not be equated with a complete transfer of regulatory responsibility.


The European Commission generally assigns responsibility for the creation and accuracy of the DPP to the relevant economic operators who place the product on the EU market.


For management, this means that outsourcing requires clear contracts, data quality rules, access rights, and exit scenarios. “The service provider creates the DPP” is not a sufficient governance model.

 

Supplier Data


Much of the DPP information originates outside the company. Materials, ingredients, or other supporting documentation may pass through multiple stages of the supply chain.


This raises a key compliance question: How does supplier information become reliable product information?


Companies should therefore define which data requires supporting documentation, which checks are performed, how changes are reported, and who approves the information. The more critical a data field is to compliance, the more important it is to have a traceable origin and approval process.


The DPP thus makes data governance an integral part of compliance management.

 

Manufacturers, Importers, and Distributors

Clearly Defining Roles

Imported products deserve special attention. Just because a manufacturer is based outside the EU does not mean that DPP requirements fall outside the European chain of responsibility.


The DPP Registry supports this oversight:

Before a product is placed on the market, relevant DPPs must be registered in accordance with applicable law. The registry can also assist market surveillance and customs authorities during inspections.


Companies should therefore document the following for each product group:

  • Who is the responsible economic operator?
  • Who creates or updates the DPP?
  • Who approves the data?
  • Who monitors changes?
  • Who can provide evidence to authorities?
  •  

Liability Risk Begins with Unclear Governance

The specific sanctions or legal consequences that apply depend on the relevant EU legislation and its national enforcement. There is therefore no blanket “DPP liability.”


Operational risks, however, arise even earlier: due to incorrect product information, failure to update data, unclear responsibilities, or unverifiable supplier data.


C-level executives should therefore separate three levels:


Legal Ownership: Who bears regulatory responsibility?
Data Ownership: Who is responsible for the quality and approval of a data field?
System Ownership: Who ensures availability, change history, and technical provision?


These roles may fall to different functions, but they must be interconnected.

 

DPP Compliance Requires a Control Process


Instead of treating the product passport as a one-time project, companies should establish a repeatable process: map requirements, collect data, verify evidence, approve information, publish the DPP, and monitor changes.


Compliance, procurement, product management, and IT must share responsibility for this. A traceable audit trail also helps document when data was changed and approved.

DPP compliance involves more than simply having a product passport. What is crucial is that responsibilities for regulatory obligations, product data, and systems are clearly defined.


Companies should therefore establish DPP governance early on. Especially in complex supply chains, a clear chain of responsibility reduces the risk that missing or unverified information will only come to light when the product is placed on the market or during a regulatory audit.

 

FAQ


Who is responsible for the Digital Product Passport?
That depends on the product group, the applicable legal act, and the role in the value chain. Manufacturers, importers, and other economic operators may be affected.


Can a DPP service provider assume responsibility?
A service provider can handle technical tasks. However, companies should not assume that this automatically relieves them of their legal obligations.

Who is liable for incorrect supplier data?
There is no one-size-fits-all answer. Companies should review contractual responsibilities and legal obligations separately and validate critical information in a traceable manner.


Does a company need a DPP officer?
The EU does not generally require a specific internal job title. However, it makes sense to have clearly defined responsibilities for compliance, data approval, and technical implementation.

Who is currently responsible for which DPP data in your company? A DPP governance check with asioso can provide transparency regarding roles, data flows, and system responsibilities, and help identify organizational gaps early on

Does this fit your project?

Share

Categories

Implementing DPP Technically—Data, Standards, and Systems


September 29, 2026

Digital Product Passport - Is my product affected?


September 29, 2026

DPP Basics: An Overview of Regulations and Deadlines


September 29, 2026