TracePass
Regulatory

The back-up copy obligation a real ESPR duty with no provider to satisfy it

ESPR Article 10(4) requires the economic operator to lodge a back-up copy of the digital product passport with a digital product passport service provider. The delegated act that defines and governs that role has not been adopted. Here is what the obligation actually says, and what you can do before it can be met.

Regulation (EU) 2024/1781 — ESPR — contains an obligation most passport discussions never reach. Article 10(4) reads: “The economic operator, when placing the product on the market, shall make available a back-up copy of the digital product passport through a digital product passport service provider.” It is one sentence, it is unconditional in form, and it is not a duty an operator can discharge alone.

The reason it matters is Article 11(e). The passport “shall remain available for the period specified in delegated acts adopted pursuant to Article 4, including after an insolvency, a liquidation or a cessation of activity in the Union of the economic operator responsible for the creation of the digital product passport.” Read those two provisions together and the intent is plain: a passport is supposed to outlive the company that created it. The back-up copy is the mechanism that makes that possible.

The problem is that a “digital product passport service provider” is a defined role, not a description of any vendor holding your data. It is an independent third party, authorised by the economic operator, that processes passport data in order to make it available to the actors entitled to access it. The rules governing that role — who may act as one, what they must guarantee, how they are supervised — come from the DPP service provider delegated act. That act has not been adopted.

So the honest position is that a real obligation exists, its counterparty does not yet exist, and no vendor — including us — can be a qualified back-up provider today, because the qualification has not been created. That is not a gap in one product. It is a gap in the field. This page sets out what the text says, why it cannot be satisfied yet, and the things worth doing in the meantime that will still be worth having when it can.

What the regulation actually says

Four provisions do the work. Three are quoted or paraphrased from the consolidated ESPR text; the fourth is the scope rule that determines when any of them bite. Read the scope item first if you are trying to work out whether this applies to your product today.

Article 10(4) — the back-up copy itselfThe provision is one sentence: “The economic operator, when placing the product on the market, shall make available a back-up copy of the digital product passport through a digital product passport service provider.” Three things are worth noticing. The trigger is placing on the market, not some later date. The duty falls on the economic operator, so it cannot be delegated away by contract. And the copy must be made available through a service provider — a back-up you hold yourself, however robust, is not the form the article describes. That third element is the one that cannot currently be complied with, and it is not optional wording.
Article 11(e) — survival beyond the companyThe passport “shall remain available for the period specified in delegated acts adopted pursuant to Article 4, including after an insolvency, a liquidation or a cessation of activity in the Union of the economic operator responsible for the creation of the digital product passport.” This is the reason Article 10(4) exists. A passport hosted only by the manufacturer disappears with the manufacturer, and the products it describes do not — they are still in use, still being resold, still heading for a recycler who needs the data. Note also that the availability period itself is set by the Article 4 delegated act, so how long is a per-product-group question, not a single number.
Article 11(c) — what a processor may not do with the dataWhoever stores or processes passport data “shall not sell, reuse or process such data, in whole or in part, beyond what is necessary for the provision of the relevant storing or processing services.” This is a useful clause to know even now, because it is the standard a back-up arrangement will eventually be measured against. It rules out treating the data you are entrusted with as a commercial asset in its own right — aggregating it, monetising it, or building an unrelated product on top of it. It is a reasonable question to put to any vendor holding your passport data today, delegated act or not.
Scope — Article 10 bites where a passport is required at allThis nuance decides whether the duty is yours yet. Article 10 sets essential requirements for a digital product passport. Those requirements apply where Article 9(1) requires a passport in the first place — that is, once the product's own delegated act under Article 4 applies to it. The back-up duty is therefore not a free-standing obligation on every product on the market today; it attaches wherever a passport is mandatory. The only adopted mandate is battery, under Article 77 of Regulation (EU) 2023/1542, from 18 February 2027. That is the first date on which this becomes real for anyone.

Why nobody can satisfy this today

The obstacle is not technical. Copying a passport to a second organisation is a solved engineering problem, and several vendors could do it this afternoon. The obstacle is that Article 10(4) does not ask for a copy held by another company — it asks for a copy made available through a digital product passport service provider, which is a role the regulation defines and the DPP service provider delegated act is meant to govern. That act has not been adopted. Public sources place it variously in Q1 and in Q2–Q3 of 2027; none of those is a legal date, so the sensible way to treat it is as a trigger to watch rather than a deadline to plan against.

Because the act has not landed, there is no qualification to hold. DIGITALEUROPE has recommended a common, EU-wide certification scheme for back-up services by DPP providers as the way to fulfil Article 10(4) — but a recommendation is not a scheme, and no body is currently certifying anyone against it. Any vendor claiming today to be a qualified or certified back-up provider is claiming a status that does not exist. We are not one, we do not claim to satisfy Article 10(4), and the same test should be applied to anyone who says otherwise: name the scheme, name the body that granted it.

There is also a live question about what the role will even be worth buying separately. DIGITALEUROPE has proposed allowing an economic operator to authorise a single provider for both primary and back-up services, and exempting operators who make passports available themselves from certification altogether. If either proposal is adopted, a standalone back-up vendor becomes a much narrower product than it looks today. Nothing here is decided — that is the point. Committing money or architecture to a market that has not been defined yet is the most expensive thing you can do in response to this article.

What you can usefully do before the act lands

None of the following satisfies Article 10(4), and none of it should be sold to you as if it does. What it does is put you in the position where satisfying the article later is a small step rather than a migration — and every item is worth having on its own merits even if the delegated act never arrives in the shape anyone expects.

  1. 1

    Keep a complete, standards-shaped export you could take elsewhere

    This is the honest interim answer to a back-up duty you cannot yet discharge: a full export of the passport, in a documented format, that another system could ingest without your current vendor's cooperation. Take it on a schedule, keep it somewhere you control, and confirm at least once that it actually loads somewhere else — an export nobody has ever restored is a hypothesis, not a back-up. Be clear with yourself about what it is. It is continuity insurance and it is portability. It is not a copy made available through a digital product passport service provider, and it should never be described as satisfying Article 10(4).

  2. 2

    Ask where the data would live if your vendor stopped trading tomorrow

    Ask it plainly, and get the answer in writing rather than in a sales call. What happens to hosted passports on insolvency or wind-down? Is there an escrow arrangement, a notice period, a defined export window, or nothing at all? Who holds the data, in what jurisdiction, and under what commitment not to reuse it — the standard Article 11(c) sets out is a good yardstick to borrow early. A vendor with an honest answer that is “nothing formal yet” is more useful than one that answers with a certification nobody issues.

  3. 3

    Prefer formats and identifiers that survive a provider change

    The thing that makes a back-up transferable is not the copy, it is the shape of the data inside it. A resolvable identifier you control, rather than one minted by and tied to a vendor's domain, means a passport keeps its address when the host changes. Standards-shaped, self-describing data means the receiving system can read it without a bespoke mapping. Proprietary stores and vendor-scoped identifiers are the two things that make a future migration expensive, and they are cheap to avoid at the point where you first choose them.

  4. 4

    Watch the DPP service provider delegated act, not the ESPR headlines

    This is the trigger that turns a design question into a compliance one. Until it is adopted, there is no role to contract with and no scheme to be certified under, and the correct posture is readiness rather than procurement. When it lands, the things that matter are what a service provider must guarantee, whether one provider may serve both primary and back-up roles, and whether self-hosting operators are exempted. Those answers will determine whether you need to buy anything at all. Until then, treat any deadline you are quoted for this as an estimate, because nothing has been adopted.

Build the passport now — and keep it portable enough to move

We are not a digital product passport service provider in the Article 10(4) sense, and we do not claim to satisfy that obligation — nobody can, because the delegated act defining the role has not been adopted. What is worth doing today is the part that will still be worth having whenever it does land: a complete passport, in a standards-shaped format, exportable in full, under an identifier you control. If the back-up duty becomes yours — for batteries, from 18 February 2027 — the work will be lodging a copy, not rebuilding the data.

Start a free passport