EN 18220 Explained: How RFID and NFC Became Legal DPP Data Carriers

A UHF RFID label and a printed 2D code on the same garment tag, next to a handheld reader showing a decoded product identifier

Ask ten suppliers what a Digital Product Passport looks like and nine will hold up a QR code. That was a fair answer while the DPP was still a policy intention with no engineering detail behind it. It became an incomplete answer on 15 July 2026, when six of the first European Standards written for the DPP were cited in the Official Journal as harmonised standards.

One of those six is EN 18220:2026, Digital product passport — Data carriers. Its scope covers optical 2D codes, NFC, HF RFID and RAIN (UHF) RFID. RFID sits in the published text at the same level as the QR code, carrying the same presumption of conformity. For anyone specifying a carrier for a product that has to survive years of handling, that single fact reorders the decision.

We build UHF readers and encode tags for export customers, so we read these documents as specifications rather than as news. What follows is the standards stack as it now stands — numbers, dates, what each document answers — and then the practical question underneath it: how a RAIN tag actually resolves to a passport record, and how to write a carrier requirement you can put in a tender. If you want the system view first, our Digital Product Passport page covers the platform side.

The DPP is a standards stack now, not a policy intention

The joint technical committee CEN-CLC/JTC 24, Digital Product Passport: Framework and System, developed the first series of eight European Standards supporting the EU Digital Product Passport framework under the Ecodesign for Sustainable Products Regulation, Regulation (EU) 2024/1781, in response to standardisation request M/604. They cover the horizontal infrastructure: identifiers, carriers, storage, exchange, APIs and interoperability.

Six of those eight have taken the step that matters most commercially. Commission Implementing Decision (EU) 2026/1736 of 14 July 2026, on harmonised standards for digital product passports drafted in support of Regulation (EU) 2024/1781, published their references in the Official Journal. The decision entered into force on the day of its publication, 15 July 2026.

What citation in the Official Journal buys you

A harmonised standard cited in the Official Journal confers a presumption of conformity with the requirements it covers — in this case ESPR Articles 10 and 11. The practical translation for a manufacturer is straightforward: build the carrier to EN 18220 and a market surveillance authority starts from the position that your physical-to-digital link conforms, rather than asking you to argue the point from first principles. Build it to a proprietary scheme and the burden of demonstration sits with you.

Two of the eight were still finishing. At CEN and CENELEC’s DPP webinar on 25 June 2026, FprEN 18239 (access rights management, information system security and business confidentiality) and FprEN 18246 (data authentication, reliability and integrity) were shown as under Formal Vote until 16 July 2026. Those two carry the security and authenticity requirements, which is worth knowing when you are comparing security models: the two documents that will govern them closed Formal Vote on 16 July 2026.

What EN 18220 covers

EN 18220:2026 is about one thing: the physical-to-digital connection. The object on the product that a person, a phone or a reader interrogates to reach the passport record.

CEN and CENELEC’s own presentation of the standard sets out five carrier technologies side by side, each with a one-line characterisation:

The requirement headings

The standard groups its requirements under headings that read like a hardware test plan rather than a policy annex: data encoding, scannability, accessibility, data carrier design, durability, quality, performance, placement and marking, plus further considerations including security. And the carrier has to work for a defined set of readers — consumers, businesses, repairers, recyclers, market surveillance authorities and automated systems.

That last list is the clause most people skim past, and it is the one that sets the bar a carrier choice has to clear. A carrier that still reads for a recycler years into service satisfies all six readers on that list. A carrier chosen for the point of sale satisfies one of them.

Why durability and placement favour an embedded carrier

Durability and placement are where long-lived goods separate from fast-moving ones. A printed 2D code lives exactly as long as the surface it is printed on: the swing tag that gets cut off at first wear, the care label that fades over a garment’s washing life, the paint that gets abraded off a steel section in a yard. If the passport has to remain reachable across the product’s life — which is the entire premise of a passport — then the carrier has to be attached the way the product is built, so that it travels with the product rather than with the packaging.

An RFID inlay laminated into a label, sewn into a seam, moulded into a housing or specified as an on-metal tag stays readable through the handling the product will actually meet. That is a durability and placement argument, grounded in the standard’s own headings. It is also why the carrier decision belongs with the product engineer and not only with the packaging team.

The other seven standards, and which one answers which question

Most DPP confusion clears the moment you ask each document the question it was written to answer. EN 18220 tells you what may go on the product and how well it has to read. Identifier shape belongs to EN 18219, where the record lives to EN 18221, and who may see which field to FprEN 18239. Each is worth knowing by number when you are interrogating a platform vendor.

StandardWhat it answersStatus
EN 18216:2026Data exchange protocols — how passport data moves between systemsCited in the OJEU, in force 15 July 2026
EN 18219:2026Unique identifiers — product, economic operator and facilityCited in the OJEU
EN 18220:2026Data carriers — 2D codes, NFC, HF RFID, RAIN RFIDCited in the OJEU
EN 18221:2026Data storage, archiving and data persistenceCited in the OJEU
EN 18222:2026APIs for passport lifecycle management and searchabilityCited in the OJEU
EN 18223:2026System interoperabilityCited in the OJEU
FprEN 18239Access rights management, information system security, business confidentialityFormal Vote closed 16 July 2026
FprEN 18246Data authentication, reliability and integrityFormal Vote closed 16 July 2026

Keep the table beside you in vendor meetings. When a DPP platform says it is “standards compliant”, the useful follow-up is which of these eight it implements and which it merely interfaces with. A platform that handles EN 18222 and EN 18223 beautifully still leaves the carrier in your product where it belongs: with you and your supplier.

EN 18219 and identifier granularity: model, batch or item

EN 18219 specifies the identifiers at the centre of every passport: the unique product identifier, the unique operator identifier and the unique facility identifier. Its general requirements are the ones you would write yourself if you had to — the identifier must be globally unique, persistent, machine-readable, usable across systems, and valid throughout the lifecycle from manufacture to recycling.

The commercially consequential clause is granularity. The standard recognises three levels, and CEN and CENELEC illustrate them with furniture: one identifier for a furniture model, one identifier for a production batch, or one identifier for each unique furniture item.

What each level costs you

ESPR Annex III requires the unique product identifier, the data carrier and the operator and facility identifiers to be issued in accordance with internationally recognised standards, with the Commission empowered to update the referenced standards as technology moves. That wording is deliberately scheme-neutral, which matters for exporters: the obligation is satisfied by any recognised, interoperable identifier system. In practice, most European buyers will ask for GS1 identifiers because their trading partners already resolve them, and it is worth knowing the difference between what the law requires and what your customer prefers.

How a RAIN tag actually resolves to a passport

This is the step that gets hand-waved in most DPP articles, so here it is concretely. A passive UHF tag holds a bit string in EPC memory. Something has to turn that bit string into a web address that returns the passport.

Historically that took a lookup: decode the EPC, convert it to a GTIN and serial, then hand it to a resolver that your systems already knew about. The tag carried the identity; your software supplied the destination. That works inside a controlled supply chain. Open-loop reading — a repairer, a recycler or a customs officer meeting a tag from a company they have never traded with — is the case that GS1’s EPC Tag Data Standard 2.3 was written for.

TDS 2.3, ratified in October 2025, introduces twelve new ‘++’ EPC schemes, including SGTIN++ and DSGTIN++, modelled on the existing ‘+’ schemes but extended to support binary encoding of a custom domain name after the serial number, specifically to better support translation back to non-canonical GS1 Digital Link URIs. In plain terms: the tag can now carry the host name alongside the identity, so a reader that has never seen your company before can decode a tag and construct a resolvable web address from the tag contents alone.

Who operates the resolver

The resolver is the service that receives that URI and returns the right passport for the requester. It can be run by the brand owner, by a DPP service provider, or by a GS1-style resolver infrastructure. Three questions decide whether the arrangement is sound:

The industry direction is clear. GS1 and the RAIN Alliance published a joint position statement naming RAIN RFID as well positioned to serve as a DPP data carrier, citing item-level precision, automatic and scalable data access and interoperability with GS1 identification standards, and pointing at the textiles, tyres and furniture categories prioritised in the ESPR working plan. Michelin’s tyre work referenced in that statement uses SGTIN-96 encoding — a reminder that the encoding schemes involved are ordinary production RFID practice, not a research project. For goods moving in cartons and on pallets, that same tag does double duty in supply chain and logistics tracking long before any regulator reads it.

Choosing a carrier by product category

EN 18220 permits five carriers and leaves the choice to you. Five inputs drive it: unit cost, expected service life, required read distance, whether a consumer needs to read it unaided, and what your in-plant or in-store operations need anyway.

CarrierRead byLine of sightItems per passBest fit
QR codeAny phone cameraRequiredOneConsumer access, printed labels, lowest unit cost
Data MatrixIndustrial scanner, phoneRequiredOneDirect part marking where print area is tiny
NFCPhone tapNone, contact rangeOneHigh-value goods, in-hand consumer proof
HF RFIDShort-range readerNone, short rangeOneClosed-loop items and short-range interactions
RAIN (UHF) RFIDHandheld or fixed readerNoneMany in a single passCartons, pallets, apparel, work in progress, returnable assets

How this plays out by category

Textiles and apparel. The category most likely to see an early delegated act, and the one where UHF is already installed at scale for stock accuracy. A woven or care-label inlay carries the serialised identifier through the garment’s life, and the same tag drives receiving, replenishment and returns in apparel and fashion retail operations. A printed code on a swing tag is the cheapest carrier at the point of sale, and pairing the two gives each job its own carrier.

Steel, aluminium and heavy components. Long service life, harsh handling, metal substrate. On-metal UHF tags and direct-marked Data Matrix are the two credible carriers; the choice usually comes down to whether the reading party will have a reader or only a camera.

Furniture and mattresses. Long life, low read frequency, consumer-facing. A dual carrier — a printed code for the consumer plus an embedded tag for the trade — is often the honest answer here.

High-value discrete goods. NFC gives the end customer a tap-to-read experience with no app and no reader, which is worth real money as a brand asset alongside its compliance role.

A fair framing of the market today: the QR code carrying a GS1 Digital Link is the familiar starting point, because it is cheap and every consumer already holds a reader. RAIN RFID is a fully permitted carrier under the same standard that adds bulk, no-line-of-sight reading — and on a factory floor it already earns its keep in work-in-progress tracking whether or not a passport is involved. The strongest specifications we see put both on the product and let each do what it is good at.

ESPR’s open-standards and back-up clauses

Underneath the EN standards sits the regulation itself, and two clauses in ESPR Article 10 tend to decide which vendors survive a procurement review.

Open, interoperable, no lock-in

Article 10 requires the passport data to be machine-readable, structured and searchable, and transferable through an open interoperable data exchange network without vendor lock-in. Read that as a procurement test rather than a principle: the test is whether you can export your passport records in a structured form and stand them up on another provider’s infrastructure with your identifiers intact. Ask for a sample export before you sign, not after.

The carrier must be physically present

The regulation puts the data carrier on the product itself so the data stay accessible throughout the life cycle, with derogations available — carrier on the packaging or on the documentation — depending on the nature, size or use of the product. If the passport rides on packaging, expect that choice to be examined against the accessibility and durability language, and have the reasoning ready under the derogation for nature, size or use.

The back-up clause almost nobody costs in

Article 10 also requires economic operators to make available a back-up copy of the digital product passport through a DPP service provider that is an independent third party. This exists so that a passport survives the insolvency or cessation of activity of whoever hosts it. It is a second contract and a second line in the budget, and EN 18221 — data storage, archiving and data persistence — is the standard that gives you the vocabulary to specify it.

Three questions to put to any DPP platform before signing: who holds the independent back-up copy, in what format is the back-up written, and what is the documented process by which a passport is reconstructed from that copy if the primary host stops trading.

Where the deadlines actually fall

ESPR’s carrier obligations arrive through product-specific delegated acts, so the useful exercise is to map your product group onto the published sequence rather than onto the general anxiety.

Batteries are the first hard date

The battery passport is the fixed point everyone else is watching. The European Commission gives 18 February 2027 as the date from which the battery passport becomes mandatory, applying to electric vehicle batteries, light-means-of-transport batteries such as those in e-bikes, e-mopeds and e-scooters, home storage batteries and industrial batteries. It rides on the same DPP technical system created under ESPR, which is why battery implementations are the closest thing to a working reference for everyone else.

The ESPR sequence

The Ecodesign for Sustainable Products and Energy Labelling Working Plan 2025–2030, COM(2025) 187 final, adopted on 16 April 2025, sets the order. Its indicative timings for adoption of measures run roughly: iron and steel in 2026, textiles and apparel and tyres in 2027, aluminium in 2027, furniture in 2028 and mattresses in 2029, with a mid-term review in 2028. The Commission notes that the new final and intermediate products to be regulated annually account for over EUR 1 trillion in annual sales on the EU market.

Add the eighteen months

ESPR Article 4(4) provides that a delegated act shall apply 18 months after its entry into force, except where a different period is duly justified. Do the arithmetic early: an indicative 2027 act for textiles points at compliance around 2028 to 2029. That is one product development cycle, one label redesign and one supplier qualification away — comfortable timing for anyone who starts now.

The infrastructure already exists

The plumbing is being built ahead of the obligations. Commission Implementing Regulation (EU) 2026/1778 of 16 July 2026 lays down the implementation arrangements for the digital product passport registry, covering the registry website, the API for registering passports, a verification component, a semantic repository for data models and a log system. Member States are required to appoint a designated national administrator by 18 February 2027 at the latest, and registry entries are deleted ten years after registration unless other Union law says otherwise. Registration is a real integration with a real API, and it belongs in the project plan alongside the carrier work.

A carrier specification you can put in a tender

Here is the specification we would want to receive as a supplier, and the one we would write as a buyer. Nine lines, each of which forces a decision that is otherwise made by accident.

  1. Carrier type and standard reference. Name the carrier and cite EN 18220:2026. If you are specifying two carriers — a printed code plus a tag — say which is authoritative when they disagree.
  2. Identifier scheme. State the scheme and the issuing arrangement, and cite EN 18219:2026 for the identifier requirements.
  3. Granularity. Model, batch or item. Write it explicitly. This single word drives tag cost, encoding cost and database design more than anything else on the page.
  4. Encoding. For a RAIN tag, name the EPC scheme and memory bank layout, and say whether the tag must carry a domain name for standalone URI construction. TDS 2.3 makes that a real option; the tag has to be encoded to use it.
  5. Durability and placement. Tie the requirement to expected product life and to the environment: wash cycles, temperature range, UV, abrasion, on-metal or not, and the physical location on the product.
  6. Read verification before dispatch. Specify the acceptance criterion — every tag read and verified against its intended identifier, with the pass rate logged — so that encoding quality is proven on the line before the goods leave. On our own line this is the step that turns a carrier specification into a shippable one.
  7. Interoperability evidence. Require a decoded read from a reader the buyer nominates, alongside the supplier’s own equipment.
  8. Hosting and back-up. Name who hosts the passport record and who holds the independent third-party back-up copy required by ESPR Article 10.
  9. Identifier handover. State how the identifier reaches downstream parties — customer systems, customs documentation, the EU registry — and in what format.

Two closing notes for exporters. First, band configuration is an order parameter, set at the point of order: we supply FCC-band 902–928 MHz and ETSI-band 865–868 MHz reader variants configured per destination, and our UHF reader models carry WPC ETA and BIS registration for India’s de-licensed UHF band. Get the destination band written into the purchase order. Second, hardware and software from one vendor keeps the encoding, the verification and the resolver behaviour in a single accountable chain — which is exactly what a carrier specification is trying to guarantee. If you are sourcing tags and readers for a passport programme, our RFID manufacturer and exporter page sets out how we quote and ship.

Frequently asked questions

Is RFID allowed as a Digital Product Passport data carrier?

Yes. EN 18220:2026, Digital product passport — Data carriers, covers optical 2D codes, NFC, HF RFID and RAIN (UHF) RFID. Its reference was published in the Official Journal by Commission Implementing Decision (EU) 2026/1736 of 14 July 2026, so a carrier built to it carries a presumption of conformity with ESPR Articles 10 and 11. RFID stands as a first-class carrier in the published standard.

What is EN 18220 and is it a harmonised standard?

EN 18220:2026 is the European Standard for Digital Product Passport data carriers, developed by the joint technical committee CEN-CLC/JTC 24 as part of the first series of eight DPP standards. It is harmonised: its reference was cited in the Official Journal by Implementing Decision (EU) 2026/1736 of 14 July 2026, in force from 15 July 2026, alongside EN 18216, EN 18219, EN 18221, EN 18222 and EN 18223.

Does a Digital Product Passport have to use a QR code?

The QR code is one of five carrier technologies described under EN 18220, together with Data Matrix, NFC, HF RFID and RAIN RFID. ESPR sets the requirement that the carrier be physically present on the product, its packaging or its documentation and remain accessible through the life cycle, and leaves the symbology to the standard. Many implementations use a QR code carrying a GS1 Digital Link because consumers already have readers, and pair it with an RFID tag for trade and operational use.

What is the difference between EN 18219 and EN 18220?

EN 18219 governs the identifier — the unique product, operator and facility identifiers, their granularity and the requirement that they be globally unique, persistent, machine-readable and usable across systems. EN 18220 governs the physical carrier that holds or points to that identifier, covering encoding, readability, durability, quality, performance and placement. One answers what the identity is; the other answers what it is written on.

Do Digital Product Passports need item-level serialisation or is model level enough?

EN 18219 recognises three levels — model, batch and item — and CEN and CENELEC illustrate all three. The right level depends on what the product-specific delegated act requires and what claims you need to support. Model level is cheapest and answers what the product is. Batch level bounds a recall to a lot. Item level is what a passport needs to hold a unit-specific service, repair or ownership history, and it is the level at which a serialised RFID tag also delivers inventory accuracy.

When does the EU Digital Product Passport become mandatory?

The dates arrive product group by product group. The battery passport is the first hard deadline, mandatory from 18 February 2027 for electric vehicle, light-means-of-transport, home storage and industrial batteries. Under ESPR, obligations arrive through product-specific delegated acts sequenced by the Working Plan 2025–2030, COM(2025) 187 final of 16 April 2025, with indicative timings around 2026 for iron and steel, 2027 for textiles, tyres and aluminium, 2028 for furniture and 2029 for mattresses. ESPR Article 4(4) then adds 18 months before an act applies, except where a different period is duly justified.

How does an RFID tag link to a Digital Product Passport record?

The tag holds a serialised identifier in EPC memory. A reader decodes it and converts it into a web address that a resolver answers with the passport view appropriate to the requester. GS1’s EPC Tag Data Standard 2.3, ratified in October 2025, added twelve ‘++’ EPC schemes such as SGTIN++ and DSGTIN++ that encode a custom domain name after the serial number, so a decoded tag can be translated back into a resolvable GS1 Digital Link URI using the tag contents alone.

Sources