Journal
Technical16 September 2026 4 min read

DPP Interoperability: Avoiding Vendor Lock-In When Choosing Your Provider

How to structure your data and architecture to stay independent from any Digital Product Passport vendor.

The hidden cost of choosing wrong

As the ESPR regulation takes shape, fashion brands face a critical decision: which technology partner will manage their Digital Product Passports? The market is crowded—dozens of platforms promise compliance. But here's what the sales pitches won't tell you: the wrong choice today could lock you into a single vendor for a decade.

The European Commission has been explicit that DPP infrastructure should be "interoperable and technology-neutral" (European Commission, Sustainable Products Initiative, 2022). Yet many current solutions use proprietary data models that make switching providers expensive or impossible.

What vendor lock-in actually looks like

Lock-in doesn't happen overnight. It accumulates through small decisions:

The interoperability stack: what to demand

A truly portable DPP architecture rests on open standards at every layer. Here's how the pieces fit together:

LAYER 4: PRESENTATION
QR codes, NFC, consumer-facing apps
LAYER 3: TRUST & VERIFICATION
W3C Verifiable Credentials · Decentralised identifiers (DIDs)
LAYER 2: DATA EXCHANGE
GS1 EPCIS 2.0 · JSON-LD · CIRPASS data model
LAYER 1: IDENTIFIERS
GS1 Digital Link URIs · GTIN · SGTIN

Layer 1 is the foundation. GS1 Digital Link URIs (the "new barcode") are globally unique, vendor-agnostic, and already supported by 116 national GS1 organisations (GS1, 2024). If your provider mints proprietary IDs instead, ask why.

Layer 2 is where CIRPASS—the EU's pilot consortium for DPP infrastructure—has done essential groundwork. Their data model, released in 2024, defines how to express product attributes, supply chain events, and sustainability claims in a standard way (CIRPASS Consortium, 2024).

Layer 3 ensures that certifications and claims can be verified independently. W3C Verifiable Credentials allow any party to cryptographically confirm that a claim (e.g., "this cotton is GOTS-certified") was issued by an authorised body—without calling the vendor's API.

Five questions to ask any DPP vendor

Before signing, get written answers to these:

  1. Can I export all my data in a standard format? Look for EPCIS 2.0 XML/JSON or CIRPASS-compliant JSON-LD.
  2. Who owns the cryptographic keys? If the vendor controls all signing keys, your credentials die with the contract.
  3. Are identifiers portable? GS1 Digital Link URIs remain valid regardless of which platform resolves them.
  4. What's the exit timeline? A reasonable SLA is full data export within 30 days of contract termination.
  5. Is the API documented publicly? Closed APIs create integration dependencies that increase switching costs.

Frequently asked questions

Generate your collection's passports

From product sheet to compliant, hosted, print-ready QR codes.

Get started