Skip to main content

Digital product passports: a new trust infrastructure for industry

Digital product passports: a new trust infrastructure for industry

Industrial digitalisation has made it possible to connect machines, factories, suppliers and customers. However, product-related information remains scattered across business systems, production platforms, databases and separate documents. This fragmentation makes it difficult to reliably ascertain what materials a product contains, how it was manufactured, what checks it has passed, what modifications it has undergone, or how it should be repaired, reused or recycled.

The Digital Product Passport, or DPP, aims to solve this problem by providing a persistent digital identity that accompanies a product, component or material throughout its entire life cycle. It is not limited to a QR code or a document repository, but creates a digital thread linking the physical product to the information generated during its design, manufacture, use and end-of-life. It may include the product’s identification, origin and composition, design version, certificates, environmental footprint, repairs and instructions for reuse or recycling.

image1

European regulations stipulate that this information must be interoperable, structured, machine-readable and accessible via open standards. However, having a DPP does not mean that all data is public. Manufacturers, customers, repairers, recyclers, certifiers and authorities should only have access to the information they need, in accordance with their role and rights.

The value of DPPs is particularly significant in the manufacture of complex, large-scale industrial parts or those produced in small batches. These parts often pass through various plants, suppliers and processes before being integrated into a machine or infrastructure. In a distributed manufacturing environment such as REED, the passport can link each part to its production order, design, materials, operations carried out, dimensional checks, carbon footprint, etc.

At REED, we envisage the DPP as a tool capable of tracking the part from the initial request and selection of the manufacturer right through to its production, delivery, maintenance, reuse or recycling. Each participant in the value chain could access a view tailored to their needs, avoiding the sharing of unnecessary or confidential information.

image2

Blockchain can strengthen trust in this model by providing a shared, tamper-resistant ledger. It can be used to record the creation of a part, the completion of a manufacturing operation, the issuance of a certificate, the carrying out of an inspection, a repair or a change of ownership. This facilitates the traceability of key events associated with the product.

However, ensuring that the information has not been altered is not enough. It is also necessary to know who issued it and under what authority. Decentralised, self-sovereign digital identities enable companies, plants, machines, laboratories, certifying bodies or even the products themselves to be reliably identified.

Building on these identities, verifiable credentials enable digitally signed statements to be issued. For example, they can attest to the origin of a material, the result of an inspection, compliance with a standard, a company’s authorisation to manufacture a part, or the calibration status of a machine.

These credentials can be verified automatically and, through selective disclosure techniques, make it possible to demonstrate that a specific condition is met without revealing unnecessary information. A company could certify that a material meets a specific specification without sharing its price, the supplier’s name or the full report. This facilitates collaboration between organisations without compromising confidentiality, trade secrets or intellectual property.

Information control must also go beyond simply deciding who can open a document. It is necessary to establish what the information may be used for, how long it will remain available, whether it may be shared with third parties, and what obligations the recipient must fulfil. Data spaces, usage policies and attribute-based access controls enable permissions to be granted according to the role and credentials of each participant, such as an authorised manufacturer, customer, approved repairer or inspection body.

At REED, we aim to ensure that each participant shares and receives only the information necessary at each stage of the process. A supplier could access the geometry and tolerances required to manufacture a part without viewing the complete design. The customer could verify that the agreed requirements are met without knowing confidential process parameters. Similarly, a recycler could access the part’s composition and dismantling instructions without viewing commercial or technical information they do not require.

The success of DPPs will not depend solely on technology. It will also be necessary to agree on data models, common vocabularies, responsibilities, update procedures and clear criteria for distinguishing between public, restricted and confidential information.

When these elements are properly combined, the DPP ceases to be a mere documentary obligation and becomes a genuine infrastructure of trust for building more transparent, efficient and circular supply chains. Blockchain provides integrity and traceability; digital identities enable participants to be recognised; verifiable credentials provide reliable evidence; and data spaces make it possible to share information in a flexible, sovereign and controlled manner.

Authors: Ianire Bizkarra, Unai Arenal , Pedro de la Peña (i3B)