No, the DPP does not publish your bill of materials to the world.
The most common objection we hear from manufacturers is not about cost or effort — it is fear of exposure. "If everything about our product goes behind a public QR code, our competitors can read our BOM, our supplier list and, by inference, our margins." That fear is understandable and, on the facts, misplaced. The Digital Product Passport is designed around tiered access: different audiences see different slices of the data, and trade-secret protection is built into the framework's design, not bolted on afterwards.
Last updated:
In one line: DPP data is tiered — consumers see a public summary, legitimate-interest parties such as repairers and recyclers see more, and only authorities see the most sensitive layer — so scanning the QR code never exposes your full BOM, supplier list or cost structure to a competitor.
The fear, stated plainly
A serious passport for a serious product touches sensitive territory: material composition close to formulation level, named suppliers, process data, performance test results. If all of that were one flat public record, the DPP would be a competitive-intelligence gift and no manufacturer would cooperate willingly. The EU legislator understood this. The ESPR framework explicitly balances transparency against the protection of confidential business information and trade secrets — the passport is a controlled-access record, not an open database of everything you know about your product.
The practical consequence: the question is never "is our data public?" but "which tier does each field sit in?" — and that is a design decision you make deliberately when building the passport, within the rules of your product group.
The three access tiers
Think of the passport as three concentric layers. The exact allocation of fields is set per product group in its delegated act, so treat the examples below as illustrative rather than a fixed template.
Public tier — what anyone scanning the QR code sees: product identity, a materials summary, circularity information such as repair and recycling guidance, and general sustainability characteristics. Consumer-facing, competitor-safe.
Restricted tier — for parties with a legitimate interest: professional repairers needing disassembly and spare-part data, recyclers needing detailed composition for safe processing, professional buyers verifying claims. More depth, granted by role, not published to the open web.
Authority tier — for market surveillance authorities and customs: the compliance-critical detail needed to verify that what you declared is true. Visible to regulators, not to the market.
Your full BOM, named supplier relationships and anything cost-revealing belong in the deeper tiers — which is exactly where the framework expects them.
How platforms enforce tiers technically
One QR code does not mean one response. The GS1 Digital Link on the product resolves to the passport, and what the requester sees depends on who they are: an anonymous scan returns the public layer; an authenticated repairer, recycler or authority presents credentials and receives an access grant or token scoped to their role. Requests to deeper tiers can be logged, so you know who accessed what.
This is how PassPer implements it: role-based access grants on every field group, the public layer served instantly to consumer scans, and deeper tiers released only against verified credentials. The record itself carries an eIDAS qualified seal, so every tier — public or restricted — is tamper-evident and provably yours.
What to do with this now
The tiering only protects you if you use it deliberately. Three practical steps:
Classify before you populate. Walk your data fields with one question per field: who genuinely needs this? Public, legitimate-interest or authority-only — decided up front, not after publication.
Check your product group's rules. The delegated act for your group determines which fields are mandatory and at which tier; where it has not yet landed, prepare the classification so you can slot fields in quickly.
Involve whoever owns confidentiality. Supplier NDAs and trade-secret policy should inform the tiering — the framework gives you the mechanism, but the judgement calls are yours.
Run the free readiness check to see how your current data splits across the three tiers.
Frequently asked questions
Can competitors see our supplier list by scanning the QR code?
No. An anonymous scan returns only the public tier — product identity, a materials summary and circularity information. Supplier-level and composition detail sits in restricted or authority-only tiers, released against verified credentials, not to whoever holds a phone.
Do we have to publish our full bill of materials?
No. The framework requires specific data fields per product group, at specified access levels — not wholesale BOM publication. Detailed composition data that recyclers or authorities need lives in the deeper tiers. The exact field list and tiering depend on your product group's delegated act, so treat any generic template as indicative.
Who counts as a "legitimate interest" party?
Typically professional actors with a functional need for deeper data: repairers, refurbishers, recyclers and waste operators, and professional buyers verifying compliance claims. Their access is role-scoped — a repairer sees disassembly and spare-part data, not your commercial terms. The precise list is defined within the rules for each product group.
How is restricted access actually enforced — is it just a login page?
Technically it is credentialed access on the passport record itself: the QR resolves to the public layer, and deeper tiers require an access grant or token tied to a verified role. On PassPer, access is enforced per field group, requests to deeper tiers are logged, and the whole record is sealed — with the eIDAS qualified seal live on QTSP activation — so any tampering is detectable.