PassPer / Resources / Who can see DPP data
Confidentiality guide

No, the DPP does not publish your bill of materials to the world.

The most common objection we hear from manufacturers is not about cost or effort — it is fear of exposure. "If everything about our product goes behind a public QR code, our competitors can read our BOM, our supplier list and, by inference, our margins." That fear is understandable and, on the facts, misplaced. The Digital Product Passport is designed around tiered access: different audiences see different slices of the data, and trade-secret protection is built into the framework's design, not bolted on afterwards.

Last updated:

In one line: DPP data is tiered — consumers see a public summary, legitimate-interest parties such as repairers and recyclers see more, and only authorities see the most sensitive layer — so scanning the QR code never exposes your full BOM, supplier list or cost structure to a competitor.

The fear, stated plainly

A serious passport for a serious product touches sensitive territory: material composition close to formulation level, named suppliers, process data, performance test results. If all of that were one flat public record, the DPP would be a competitive-intelligence gift and no manufacturer would cooperate willingly. The EU legislator understood this. The ESPR framework explicitly balances transparency against the protection of confidential business information and trade secrets — the passport is a controlled-access record, not an open database of everything you know about your product.

The practical consequence: the question is never "is our data public?" but "which tier does each field sit in?" — and that is a design decision you make deliberately when building the passport, within the rules of your product group.

The three access tiers

Think of the passport as three concentric layers. The exact allocation of fields is set per product group in its delegated act, so treat the examples below as illustrative rather than a fixed template.

Your full BOM, named supplier relationships and anything cost-revealing belong in the deeper tiers — which is exactly where the framework expects them.

How platforms enforce tiers technically

One QR code does not mean one response. The GS1 Digital Link on the product resolves to the passport, and what the requester sees depends on who they are: an anonymous scan returns the public layer; an authenticated repairer, recycler or authority presents credentials and receives an access grant or token scoped to their role. Requests to deeper tiers can be logged, so you know who accessed what.

This is how PassPer implements it: role-based access grants on every field group, the public layer served instantly to consumer scans, and deeper tiers released only against verified credentials. The record itself carries an eIDAS qualified seal, so every tier — public or restricted — is tamper-evident and provably yours.

What to do with this now

The tiering only protects you if you use it deliberately. Three practical steps:

Run the free readiness check to see how your current data splits across the three tiers.

Frequently asked questions

Can competitors see our supplier list by scanning the QR code?
No. An anonymous scan returns only the public tier — product identity, a materials summary and circularity information. Supplier-level and composition detail sits in restricted or authority-only tiers, released against verified credentials, not to whoever holds a phone.
Do we have to publish our full bill of materials?
No. The framework requires specific data fields per product group, at specified access levels — not wholesale BOM publication. Detailed composition data that recyclers or authorities need lives in the deeper tiers. The exact field list and tiering depend on your product group's delegated act, so treat any generic template as indicative.
Who counts as a "legitimate interest" party?
Typically professional actors with a functional need for deeper data: repairers, refurbishers, recyclers and waste operators, and professional buyers verifying compliance claims. Their access is role-scoped — a repairer sees disassembly and spare-part data, not your commercial terms. The precise list is defined within the rules for each product group.
How is restricted access actually enforced — is it just a login page?
Technically it is credentialed access on the passport record itself: the QR resolves to the public layer, and deeper tiers require an access grant or token tied to a verified role. On PassPer, access is enforced per field group, requests to deeper tiers are logged, and the whole record is sealed — with the eIDAS qualified seal live on QTSP activation — so any tampering is detectable.

Related

See where you stand — three ways, all free.

Take the 2-minute readiness check, watch the 10-minute interactive walkthrough, or download the full 2026 compliance guide. No account needed.

Free readiness check See it in action Get the guide (PDF)