TracePass
Regulatory

Standards are not law what actually makes a DPP field mandatory

A harmonised European standard supports a presumption of conformity. It binds nothing on its own. Here is the difference between a standard and a legal obligation — and what happened when we applied that test to our own product.

We audited our own 12 category templates against a single question: for every field marked “required”, which EU instrument actually requires it? Of 307 required fields, 46 rested on authority that is not legislative — an EN standard, a certification scheme, a non-EU convention, or in three cases the phrase “Product specification”. We corrected all 46. Every remaining required field cites legislation.

We are naming our own defect first because it is the most useful thing on this page. A compliance vendor that tells you a law exists when it does not is the worst failure mode in this category: you spend real effort chasing an obligation nobody can enforce, and you learn to distrust the fields that genuinely are mandatory.

The rule underneath is simple. A field in a Digital Product Passport is legally mandatory only when two things hold at once: an EU instrument that is in force mandates the data, and the passport is how that duty is discharged. Both halves matter. Plenty of data is genuinely required by EU law but discharged by a physical label, a technical file held on request, or a database entry — not by publishing it in a passport.

A harmonised standard sits outside that test entirely. Standards are drafted by CEN, CENELEC and ETSI, not by the legislator, and their legal effect is a presumption of conformity: follow the standard and an authority presumes you meet the essential requirement it was written against. That presumption is a shortcut, not a source of obligation. Unless a regulation names the standard and makes it mandatory, you may meet the requirement any other way you can demonstrate.

Four things routinely mistaken for law

Each of these is real, useful, and widely cited in DPP field specifications. None of them, by itself, makes a passport field legally mandatory.

EN standardsEN 15804+A2 defines the environmental indicators in an EPD. EN 10204 defines mill certificate types. EN 12520 sets furniture durability tests, EN 71 toy safety methods. All four are voluntary technical documents that support a presumption of conformity — they carry a legal obligation only where a regulation makes that specific standard mandatory.
Certification schemesFSC, PEFC, RJC and the EU Ecolabel are voluntary by construction — a producer chooses to be certified, and one who declines is not in breach of anything. The EU Ecolabel is the subtle case: it has a real CELEX number (32010R0066), so a citation to it looks legislative on the page. The regulation establishes a voluntary award scheme. Holding the label imposes duties; not holding it imposes none.
Non-EU conventionsThe Vienna Convention 1972 on the control and marking of articles of precious metals is a Council of Europe instrument. The EU is not a party to it, so it binds nothing at EU level. It also mandates the wrong artefact: a physical common control mark struck into the metal, not a value published in a passport.
Type-approval regulationsUNECE R30 and R54 genuinely bind tyre manufacturers — but the duty is discharged by obtaining type approval and carrying the approval mark, with the supporting values held in the approval dossier. Nothing in either regulation requires publishing those values in a product passport. A real obligation, discharged somewhere other than here.

What our own audit found, and what we changed

307 fields across our 12 category templates were marked required. 46 rested on non-legislative authority. Nothing was deleted: a field demoted from required is still in the template, still collectable, still exported. It simply no longer claims a law behind it.

Why over-claiming is the worse error

Both directions of error are real. Mark a field optional when the law requires it and a customer can end up non-compliant; that is the failure everyone in this market designs against, and rightly. But the two errors are not symmetric.

Under-claiming risks non-compliance, and the cost lands on the customer at inspection. Over-claiming wastes a customer's effort chasing data nobody can compel, and it does something worse: it asserts a law that does not exist. Only one of these two errors involves inventing an obligation, and a vendor is uniquely well-placed to be believed when it does.

What changes is what the word “required” is worth. If every field carries an equal-looking asterisk, the ones backed by an actual regulation with an actual deadline get no more attention than the ones backed by a trade body's scheme. Reserving the label for legislation is what makes it informative.

How to check any field yourself

This is not a proprietary method and there is nothing to buy to use it. Take any field marked required, in any passport product including ours, and run it through four questions. If a vendor cannot answer all four for a given field, that is the answer.

  1. 1

    Does the citation name an EU instrument, or just a standard?

    Look for a CELEX number — the identifier EUR-Lex assigns to every EU legal act, like 32023R1542 for the Battery Regulation. A standard number (EN 15804+A2, ISO 148-1, UNECE R30) is not one. If the authority column holds only a standard number, a scheme name, or a phrase like “product specification”, no legislation has been cited at all.

  2. 2

    Is that instrument actually in force for this product?

    An instrument can be adopted, in force, and still impose nothing on your product yet, because the operative duty waits on a delegated act that has not been adopted. Check the date of application and whether the product group has been brought into scope, rather than reading the parent regulation's existence as a live obligation.

  3. 3

    Is the duty discharged by the passport, or somewhere else?

    This catches the most false positives. Data can be genuinely mandatory and still not belong in a passport — because the obligation is met by a physical label or stamped mark, by technical documentation held and produced on request, by an entry in a Commission database such as EPREL or SCIP, or by an importer's declaration. Find the article that says where the information goes.

  4. 4

    For ESPR specifically, has a delegated act landed?

    ESPR (EU) 2024/1781 Articles 7 and 9 impose no data fields on their own — they set out what a delegated act may require and how a passport must work. Every actual DPP obligation flows through a product-specific delegated act adopted under Article 4. The only adopted one is battery, under Regulation (EU) 2023/1542 Article 77, mandatory from 18 February 2027. A field justified by “ESPR requires it” with no delegated act behind it is not yet required by anything.

Collect the data anyway — just know which fields the law is behind

Nothing on this page argues for collecting less. EPD indicators, mill certificates, chain-of-custody records and test results are all worth having, and buyers increasingly ask for them regardless of what the law compels. What our audit changed is which fields carry a legal claim: every field still marked required in our templates now cites an EU instrument that is in force and discharged through the passport. You can check any of them with the four questions above.

Start a free passport