DPP Interoperability: Avoiding Vendor Lock-In When Choosing Your Provider
How to structure your data and architecture to stay independent from any Digital Product Passport vendor.
- The EU's Digital Product Passport regulation does not mandate any specific technology provider
- Vendor lock-in risks include proprietary data formats, closed APIs, and non-portable identifiers
- Open standards like GS1 EPCIS, JSON-LD, and W3C Verifiable Credentials ensure long-term portability
- Your DPP architecture should separate data ownership from service delivery
- Contractual exit clauses and data export rights are as important as technical choices
The hidden cost of choosing wrong#
As the ESPR regulation takes shape, fashion brands face a critical decision: which technology partner will manage their Digital Product Passports? The market is crowded—dozens of platforms promise compliance. But here's what the sales pitches won't tell you: the wrong choice today could lock you into a single vendor for a decade.
The European Commission has been explicit that DPP infrastructure should be "interoperable and technology-neutral" (European Commission, Sustainable Products Initiative, 2022). Yet many current solutions use proprietary data models that make switching providers expensive or impossible.
What vendor lock-in actually looks like#
Lock-in doesn't happen overnight. It accumulates through small decisions:
| Lock-In Vector | How It Manifests | Long-Term Risk |
|---|---|---|
| Proprietary identifiers | Your products get IDs that only work in one system | Cannot migrate to another provider without re-tagging all inventory |
| Closed data formats | Product data stored in non-standard schemas | Export requires costly transformation; some fields may not map |
| Platform-only integrations | ERP/PLM connectors tied to vendor's API | Switching means rebuilding all integrations from scratch |
| Vendor-hosted credentials | Sustainability claims signed by vendor's keys | Claims become unverifiable if you leave the platform |
The interoperability stack: what to demand#
A truly portable DPP architecture rests on open standards at every layer. Here's how the pieces fit together:
Layer 1 is the foundation. GS1 Digital Link URIs (the "new barcode") are globally unique, vendor-agnostic, and already supported by 116 national GS1 organisations (GS1, 2024). If your provider mints proprietary IDs instead, ask why.
Layer 2 is where CIRPASS—the EU's pilot consortium for DPP infrastructure—has done essential groundwork. Their data model, released in 2024, defines how to express product attributes, supply chain events, and sustainability claims in a standard way (CIRPASS Consortium, 2024).
Layer 3 ensures that certifications and claims can be verified independently. W3C Verifiable Credentials allow any party to cryptographically confirm that a claim (e.g., "this cotton is GOTS-certified") was issued by an authorised body—without calling the vendor's API.
Five questions to ask any DPP vendor#
Before signing, get written answers to these:
- Can I export all my data in a standard format? Look for EPCIS 2.0 XML/JSON or CIRPASS-compliant JSON-LD.
- Who owns the cryptographic keys? If the vendor controls all signing keys, your credentials die with the contract.
- Are identifiers portable? GS1 Digital Link URIs remain valid regardless of which platform resolves them.
- What's the exit timeline? A reasonable SLA is full data export within 30 days of contract termination.
- Is the API documented publicly? Closed APIs create integration dependencies that increase switching costs.
Frequently asked questions
Does interoperability mean I have to build everything myself?
No. You can—and should—use a managed platform. Interoperability means you're free to leave that platform without losing your data or breaking your products' digital identities. It's insurance, not extra work.
Isn't this just theoretical until the regulation is finalised?
The ESPR delegated acts for textiles are expected in late 2027 (European Commission, ESPR timeline, 2024). But data architecture decisions made today will be expensive to reverse. Brands that choose interoperable foundations now avoid costly migrations later.
What if my current provider uses proprietary formats?
Start by requesting a data export in a neutral format. If they can't provide one, negotiate it into your next contract renewal—or factor migration costs into your planning horizon.
Building for the long term#
The brands that will navigate DPP compliance most smoothly are those treating data portability as a requirement, not a nice-to-have. Vendor relationships will evolve; regulations will tighten; new platforms will emerge. Your architecture should outlast any single contract.
At Trama, we build on GS1 identifiers, CIRPASS-aligned data models, and open APIs precisely because we believe you should never be trapped. If a better solution emerges in five years, your data comes with you. That's not a feature—it's a principle.
Generate your collection's passports
From product sheet to compliant, hosted, print-ready QR codes.
Get started