On 15 July 2026 the Official Journal of the European Union published the references of six harmonised standards for the digital product passport, under Commission Implementing Decision (EU) 2026/1736, adopted the previous day. From that date, anyone building a passport that conforms to those standards can rely on the presumption of conformity with the requirements of Articles 10 and 11 of Regulation (EU) 2024/1781, the Ecodesign for Sustainable Products Regulation known as the ESPR. This is the step that turns the digital product passport from an announcement into a technically executable obligation. The standards drafted by the joint technical committee CEN-CLC/JTC 24 were eight, however, and the two missing from the Official Journal are precisely the one on access rights management, information system security and business confidentiality, and the one on data authentication, reliability and integrity.
Six references, and the date that matters
The decision was adopted on 14 July 2026 and enters into force on the very day of its publication in the Official Journal. Its formal basis is Article 10(6) of Regulation (EU) No 1025/2012 on European standardisation, while the substantive effect flows from Article 41(2) of the ESPR: passports that conform to harmonised standards whose references are published in the Official Journal are presumed to conform to the requirements of Articles 10 and 11, to the extent that those requirements are covered by the standards or parts of them. The six cited standards address data exchange protocols (EN 18216:2026), unique identifiers (EN 18219:2026), data carriers (EN 18220:2026), data storage, archiving and persistence (EN 18221:2026), application programming interfaces for passport lifecycle management and searchability (EN 18222:2026) and system interoperability (EN 18223:2026). They were drafted by CEN, Cenelec and ETSI following the request the Commission made through Implementing Decision C(2024) 5423, later amended by Decision C(2025) 8024.
The plumbing is presumed compliant, trust in the data is not
The six published standards describe how data travels, how a product is identified, where the data sits over time and how systems speak to one another. Left out, according to the list of eight standards released by CEN and CENELEC, are EN 18239 on access rights management, information system security and business confidentiality, and EN 18246 on data authentication, reliability and integrity. This is not a scheduling detail. Article 11 of the ESPR requires, among the essential requirements, that data authentication, reliability and integrity be ensured, and that the passport be designed and operated so as to guarantee a high level of security and privacy and to avoid fraud. These are exactly the requirements for which no harmonised reference currently offers the evidentiary shortcut of the presumption. The obligation stands and must be met, but whoever places the product on the market will have to prove it by other means, documenting their technical choices rather than leaning on a published standard. It is the same asymmetry visible in the implementation of the Cyber Resilience Act, where responsibility has already been allocated and the tools to evidence it arrive later.
Where the passport meets the GDPR
Article 10(1)(e) of the ESPR is blunt: personal data relating to customers shall not be stored in the digital product passport without their explicit consent, in accordance with Article 6 of Regulation (EU) 2016/679. The cross-reference singles out one legal basis, consent, for data that in other settings might rest on different grounds. Article 11 adds that, where the passport is stored or otherwise processed by passport service providers, those providers shall not sell, reuse or process the data beyond what is necessary to deliver the service, unless specifically agreed with the economic operator placing the product on the market. Working out where the boundary of personal data falls, in a system built to circulate data along the entire value chain and well beyond the life of the product, therefore becomes an operational question rather than a theoretical one, much as the recent EDPB guidelines on anonymisation showed in a different field governed by the same logic.
A public registry, private archives, and data that outlives the company
The European system is neither centralised nor fully distributed. According to the description provided by CEN and CENELEC, the Commission will operate a registry holding the identifiers of products, manufacturers and factories, while the operational management of product data and their storage, including long-term backup, will be delegated to third-party service providers, ordinarily private companies. To this must be added a provision of Article 11 that deserves attention: the passport remains available for the period set by the delegated acts even where the economic operator that created it becomes insolvent, or is wound up, or ceases its activity in the Union. The data must therefore outlive the undertaking that generated it, and the standard governing persistence itself, EN 18221:2026, is among those now cited in the Official Journal. Who will actually carry that survival, and with what guarantees towards the market, remains a matter for the contractual relationship between economic operators and service providers.
What these standards do not do
The JTC 24 standards are transverse and product agnostic: they define the container, not the content. Which data must be recorded for each category will be set by the delegated acts adopted under Article 4 of the ESPR, following the priorities of the Commission’s 2025/2030 working plan, and the methods for calculating that data will require further standardisation requests addressed to the technical committees responsible for each product group. Access, too, remains to be defined: the Commission will adopt implementing acts identifying which persons have a legitimate interest in accessing given information, and for which purposes. The presumption of conformity published on 15 July therefore concerns how the passport works, not what the passport will have to say. The distinction is worth holding onto, because not every adequate instrument produces a presumption of conformity, and no presumption covers the whole of an obligation.
The infrastructure designed to make a product’s sustainability verifiable now enjoys, as of today, a presumption of conformity as to how data circulates, but not as to what secures its authenticity and protects its access. Until the two missing standards are cited in the Official Journal, the burden of showing that the data is reliable and that only those entitled can reach it rests entirely on whoever places the product on the market, together with the documentation that will have to sustain it before market surveillance authorities.




