Galileo Protocol · MMXXVI
Back to Blog
dppesprregulationluxurycompliance

EU DPP Registry Is Live: What Luxury Brands Must Do Now

August 25, 2026Pierre Beunardeau

The European Commission's central Digital Product Passport registry opened on 20 July 2026, and the first CEN-CENELEC DPP standards were published on 27 May 2026. Not mandatory for luxury yet — here is the decision framework, the readiness grid and the pilot plan to run before your category's delegated act lands.


The Digital Product Passport is not mandatory for luxury goods today — no maison is yet legally required to issue one. But the registry that will host passports and the standards that will define them became real this summer, so the rational move for any brand selling into the EU is to structure its product data and run a pilot now, rather than rebuild under deadline pressure when a delegated act finally names its category.

The decision you actually face

Strip away the news cycle and the choice in front of a luxury maison is binary:

  • Start now: consolidate product data, align it with the published CEN-CENELEC standards, and pilot a passport on one product line while the rules for your category are still being drafted.
  • Wait: do nothing until a delegated act imposes the obligation, then execute a data, IT and supplier programme inside whatever transition period the act grants.

The cost of waiting is not a fine — there is nothing to be fined for yet. It is three more concrete things. First, the delegated acts will be drafted around the standards already published, so early adopters face no redesign risk while late movers inherit a template they had no hand in testing. Second, the battery passport becomes mandatory in February 2027 and will set the operational reference — data formats, registry workflows, customs practice — against which every later category is measured; watching it go live without internal capability means learning from press releases instead of from your own pilot. Third, DPP readiness is mostly a data-consolidation project, and data consolidation is the part with the longest lead time in any maison: identifiers scattered across PLM and ERP systems, provenance held in supplier PDFs, repair history trapped in after-sales databases. That work takes quarters, not weeks, regardless of when the legal clock starts.

What actually changed this summer

Three milestones turned the DPP from policy into infrastructure.

The central registry is open. On 20 July 2026, the European Commission opened the central DPP registry, meeting the legal deadline of 19 July 2026 set by Article 13 of the ESPR — Regulation (EU) 2024/1781. The registry is the backbone of the system: it stores passport identifiers and lets customs and market-surveillance authorities verify that a product entering the EU has a valid passport. The implementing rules governing how the registry operates took effect in early August 2026.

The technical standards are published. On 27 May 2026, CEN and CENELEC published the first six harmonised European standards for the DPP — the EN 18xxx family developed by CEN/CLC/JTC 24 under Commission mandate M/604. They fix the technical layer: unique product identifiers, data carriers, data exchange and storage, access APIs, interoperability, and access rights for different stakeholder categories. In July 2026 they were cited in the Official Journal through Commission Implementing Decision (EU) 2026/1736, which gives them legal weight: a DPP built on these standards benefits from a presumption of conformity with the ESPR. According to the EU Digital Product Passport Foundation, the family spans eight modular standards — six published, with two further security standards still completing the formal process — covering identifiers (EN 18219), data carriers (EN 18220) and the exchange, storage and API layers around them.

The first product-specific obligation is already binding. Since 19 July 2026, large enterprises are banned from destroying unsold apparel, clothing accessories and footwear under Article 25 of the ESPR. It is the first product-specific ESPR obligation to bite, it touches fashion maisons directly, and it signals where enforcement attention is heading: textiles first, everything else on a rolling calendar.

Is the DPP mandatory for luxury today? No — and then by sector waves

This is the question every board asks, and it deserves a straight answer in the body of the article, not just in the FAQ.

Today, no. Nothing in the ESPR requires a watchmaker, jeweler, leather-goods house or art market actor to issue a product passport right now. The ESPR is a framework regulation: it creates the passport system and empowers the Commission to impose it, but product-level obligations only exist once a delegated act is adopted for a specific product group, with its own data requirements and transition period. As of this writing, no delegated act covers any luxury category.

Tomorrow, yes — category by category. The mechanism is already loaded. The first ESPR working plan, adopted on 16 April 2025, set the priorities for 2025–2030: textiles and apparel are among the first product groups targeted, alongside furniture, tyres and mattresses, with iron, steel and aluminium also in the early waves (see the Commission's ESPR page). And one product-level passport obligation is already scheduled outside the ESPR: the digital battery passport becomes mandatory on 18 February 2027 under Article 77 of the EU Battery Regulation (EU) 2023/1542 — the reference implementation every other category will be measured against.

Two consequences for maisons. First, scope is not the question: the ESPR covers virtually all physical goods placed on the EU market, with only narrow exemptions such as food and medicinal products — watches, leather goods, jewelry and art are in. Second, "not mandatory today" does not mean "not actionable today". The standards the delegated acts will reference are published and carry presumption of conformity; the registry that customs will query is live; the destruction ban shows the Commission is willing to let obligations bite before any passport exists. The unknown is the date and the exact dataset for your category, not the direction.

What a DPP will contain

The ESPR defines the DPP as a digital identity card for products, components and materials. The precise dataset is set per product group by each delegated act, but the framework and the published standards converge on a common core:

  • A unique product identifier, linked to a data carrier on the product (QR code, NFC tag, RFID) and registered in the central registry.
  • Product and material information: technical performance, materials and their origin, substances of concern, recycled content.
  • Circularity data: repairability, availability of spare parts, disassembly and recycling instructions.
  • Compliance information: the declarations and documents demonstrating conformity with the applicable delegated act.
  • Access-controlled visibility: consumers, repairers, recyclers, customs and market-surveillance authorities each see the slice of the passport they are entitled to — a requirement the EN 18xxx standards make concrete, and the one that matters most to maisons protective of trade secrets and supplier lists.

For luxury, this maps naturally onto what maisons already track — serial numbers, certificates, service history, provenance — but in a structured, interoperable, machine-readable form. The hard part is rarely the technology. It is the data: decades of product information scattered across PLM systems, ERP exports, atelier records and after-sales spreadsheets.

The readiness grid: data, standards, pilot

The tool below is how we recommend structuring preparation. Three columns, applied to each workstream: what data to consolidate, which standard layer to align it with, and how to test it in a pilot. It works with the ESPR framework and the published EN 18xxx standards as they exist today, before any luxury delegated act exists.

| Workstream | Data: what to prepare | Standards: what to align to | Pilot: how to test it | | --- | --- | --- | --- | | Unique product identity | One serial/identifier scheme per item, deduplicated across ERP, PLM and after-sales | Unique identifier + data carrier standards (EN 18xxx identifier and carrier layers) | Tag one product line with QR or NFC; scan at every handover for a full season | | Materials and composition | Bill of materials per SKU, including hardware and packaging, with supplier origin | ESPR product-information fields as framed by the framework regulation | Complete the BOM for the pilot line to 100% of components — no "TBD" tolerated | | Provenance and chain of custody | Supplier certificates and lot records in structured form, not PDFs in inboxes | Interoperability and data-exchange layers of the EN 18xxx family | Digitise the certificate flow for the pilot line's top five suppliers | | Service and repair history | Repair events linked to the product identifier, with actor and date | Access-rights model: repairers see the service slice, not the full passport | Log every after-sales intervention on the pilot line against the passport | | Circularity | Repairability information, spare-parts availability, end-of-life instructions | ESPR circularity parameters as defined for your category's future act | Publish repair and care data in the consumer-facing view of the pilot passport | | Confidentiality and access | A map of who may see what: consumer, repairer, recycler, customs, authority | Access-control and security requirements of the standards | Role-test the passport: what a client sees vs. what a customs officer sees |

And the Monday-morning checklist to launch it:

  1. Appoint one owner for DPP readiness — this fails as a shared responsibility.
  2. Inventory where product identifiers live today (ERP, PLM, after-sales, e-commerce) and measure the overlap.
  3. Pick one pilot line: iconic enough to matter, small enough to control.
  4. Freeze the identifier scheme for that line and choose the data carrier (QR, NFC, or both).
  5. Complete the bill of materials for the pilot line, supplier by supplier.
  6. Link after-sales records to identifiers, even manually at first.
  7. Define the access matrix: what the consumer, the repairer and the authority may each see.
  8. Run the pilot for a full sales season and write down what broke — that document is your head start when the delegated act arrives.

Applying the grid: a bounded case

Take an illustrative mid-size leather-goods maison — three product lines, roughly 40,000 units a year, two ateliers, most sales in the EU. The figures are fictional; the data gaps are the ones we consistently see.

  • Identity: serials exist in the ERP but after-sales uses a different numbering; step 1 is a mapping table, not new software.
  • Materials: the BOM is complete for leather and lining, incomplete for hardware and adhesives; two suppliers provide composition data only as PDF certificates. The pilot forces structured capture for one line.
  • Provenance: tannery certificates exist per lot but are not linked to individual products. The pilot links lots to serials at assembly.
  • Service: repair records exist but are keyed to customer accounts, not products. Relinking them to serials is the single highest-value data task, because service history is what makes a passport useful on the resale market.
  • Access: the maison wants clients to see authenticity, materials and care; repairers to see construction and spare parts; and nobody to see the supplier list. The access-rights layer of the standards handles this natively.

Six months of pilot on 5,000 units of one line produces three assets the maison keeps whatever the delegated act says: a clean identifier backbone, a structured dataset for its flagship line, and an internal team that has issued and used real passports. When the act for its category lands, the compliance conversation becomes "extend what works", not "start a programme".

What the texts do not say

Intellectual honesty about the current state of play:

  • No luxury delegated act exists. The exact dataset, data carrier and transition period for watches, jewelry or leather goods are not yet written anywhere. Any vendor claiming to sell a "fully compliant luxury DPP" today is selling alignment with published standards, which is valuable but is not certified compliance.
  • The textile date is an expectation, not a law. The delegated act for textiles is widely expected around 2027; the working plan sets priorities, not binding adoption dates. Plan against the priority order, not against a rumoured month.
  • Two standards are still in the pipeline. Per the EU DPP Foundation, the two security-related standards of the EN 18xxx family were still completing their formal process after the first six were published. Security and access control are exactly the layers maisons care most about — track them.
  • SME treatment is unclear. Delegated acts may include simplified requirements or longer transitions for smaller companies, but nothing is guaranteed until the acts exist.
  • Enforcement economics are unknown. Penalties are set by member states under the ESPR's national enforcement provisions; market-surveillance practice around the registry will take time to become predictable.

Galileo's take

Galileo's take: the DPP will be won on data discipline, not on technology procurement. Every maison will eventually be able to buy a passport tool; not every maison will have twenty years of clean, structured product data to pour into it. The winners will be the brands that treat the passport as a customer-facing asset — proof of authenticity, a service record, a resale enabler — and recover the compliance cost through trust and secondary-market value. The losers will treat it as a regulatory tax and pay it twice: once to comply, once to catch up with competitors who turned the same data into a client experience. Starting the data work now is a low-regret move under every plausible scenario: the standards are fixed, the registry is live, and the only variable left is the date.

Galileo Protocol is an open protocol for product identity and the tokenization of physical assets: each item gets a verifiable digital twin, authenticity and service events are recorded as interoperable attestations, and personal data stays off-chain. The schemas are published openly in our specifications, so a maison can pilot a full passport lifecycle — issue, authenticate, service, resell — against the standards that now carry presumption of conformity. Explore the documentation or contact us to discuss a pilot.

FAQ

Is the EU Digital Product Passport mandatory for luxury goods today?

No. The central registry opened on 20 July 2026 as infrastructure, but product-level obligations arrive through ESPR delegated acts per product group, and none covers luxury categories yet. The battery passport is first, from 18 February 2027; the delegated act for textiles is expected around 2027. What is already binding for large enterprises is the ban on destroying unsold textiles and footwear, since 19 July 2026.

What is the EU DPP registry?

The central registry required by Article 13 of the ESPR, operated by the European Commission. It stores the identifiers of Digital Product Passports and lets customs and market-surveillance authorities verify that a product has a valid passport.

What standards define the technical format of a DPP?

The first six harmonised European standards, published by CEN and CENELEC on 27 May 2026 (the EN 18xxx family from CEN/CLC/JTC 24) and cited in the Official Journal by Commission Implementing Decision (EU) 2026/1736. They cover identifiers, data carriers, interoperability and access rights, and carry presumption of conformity with the ESPR.

Does the DPP requirement apply to watches, leather goods and jewelry?

Yes, in principle. The ESPR covers virtually all physical products placed on the EU market. The timing and data requirements for each luxury category will be set by product-specific delegated acts, with textiles among the first priorities.

What should a luxury brand do first?

Start with data: consolidate product identifiers, bills of materials, provenance and repair records into structured, shareable data. Then align with the published CEN-CENELEC standards and run a pilot on one product line before your category's delegated act lands.