---
title: Which European standards define the EU-DPP architecture?
description: Learn which European standards define the technical architecture of the EU Digital Product Passport, including identifiers, data carriers, APIs, persistence, interoperability, security and access.
---

[Skip to content](https://support.syncforce.com/knowledge/which-european-standards-define-the-eu-dpp-architecture#main-content)

[![Syncforce\_logo\_tagline](https://support.syncforce.com/hs-fs/hubfs/Syncforce_logo_tagline.webp?width=480&height=72&name=Syncforce_logo_tagline.webp)](https://www.syncforce.com/)

Open main navigation

Close main navigation

 Hello. How can we help you?

- There are no suggestions because the search field is empty.

1. [Home](https://support.syncforce.com/knowledge?hsLang=en)
2. [Industry & Regulatory Knowledge](https://support.syncforce.com/knowledge/industry-regulatory-knowledge?hsLang=en)
3. [EU Digital Product Passport - DPP](https://support.syncforce.com/knowledge/industry-regulatory-knowledge?hsLang=en#eu-digital-product-passport-dpp)

# Which European standards define the EU-DPP architecture?

#### Short answer

The EU-DPP is supported by a family of horizontal European standards.

The most relevant standards for the SyncForce architecture are:

- **EN 18216** for data exchange protocols
- **EN 18219** for unique identifiers
- **EN 18220** for data carriers
- **EN 18221** for data storage, archiving and persistence
- **EN 18222** for EU-DPP lifecycle and search APIs
- **EN 18223** for system interoperability
- **EN 18239** for access rights, information security and confidentiality
- **EN 18246** for authentication, reliability and integrity

These standards define the horizontal EU-DPP infrastructure.

Product-specific legislation and delegated acts then determine which data must be present, where the data carrier must be placed, which users may access which information and whether the EU-DPP exists at Product Model, Batch or individual Item level.

---

#### Why are there several EU-DPP standards?

An EU-DPP is not a single webpage or QR code.

A complete EU-DPP architecture needs rules for:

- identifying Products
- encoding those identifiers in data carriers
- exchanging information
- resolving identifiers
- providing APIs
- controlling access
- ensuring integrity
- preserving information over time
- supporting interoperability between different systems

No single standard covers all of these topics.

The European standards therefore divide the technical architecture into separate areas.

---

#### What does EN 18216 Data exchange protocols cover?

EN 18216 defines how EU-DPP systems exchange data.

For SyncForce, this affects communication between:

- SyncForce Circular PIM
- prodigi.link
- Perennis
- external systems consuming EU-DPP information

The standard is relevant for both human-readable and machine-readable access.

A system may, for example, request a browser-oriented representation or a structured machine-readable representation.

The underlying Product identity remains the same.

---

#### What does EN 18219 Unique identifiers cover?

EN 18219 is one of the most important standards for the SyncForce Golden Hierarchy.

It defines how unique identifiers are used within the EU-DPP architecture.

It supports identification at different levels, including:

- Product Model
- Batch
- Individual Item

For the VTA-based EU-DPP route, SyncForce uses the ASC MH10.8.2 Data Identifier scheme consistently.

For example:

**Product Model**

`?.25P={VTA-PM}`

**Product Model + Batch**

`?.25P={VTA-PM}&.1T={lot}`

**Product Model + Serial Number**

`?.25P={VTA-PM}&.S={serial}`

**Globally unique Serialized Item**

`?.25S={VTA-SN}`

EN 18219 is therefore central to keeping Product identity separate from commercial Sales Unit identity.

**Read more:** [*How are Product Model, Batch and Serialized Item identified for an EU-DPP?*](https://support.syncforce.com/knowledge/how-are-product-model-batch-and-serialized-item-identified-for-an-eu-dpp?hsLang=en)

---

#### Does EN 18219 require GTIN as the Product identifier?

No.

The architecture supports different standards-based identifier schemes.

A GTIN remains highly relevant for the commercial Sales Unit, but the Product Model that is the subject of an EU-DPP does not necessarily have to be identified by the Sales Unit GTIN.

This matters where:

- one Product Model occurs in several Sales Units
- one Sales Unit contains several Product Models
- the Product exists before the final Sales Unit is known

SyncForce therefore keeps Product Model identity and Sales Unit identity separate.

**Read more:** [*Why is a GTIN not necessarily the Product Model identifier for an EU-DPP?*](https://support.syncforce.com/knowledge/why-is-a-gtin-not-necessarily-the-product-model-identifier-for-an-eu-dpp?hsLang=en)

---

#### What does EN 18220 Data Carriers cover?

EN 18220 covers the physical or machine-readable carrier used to access the EU-DPP.

A data carrier may be, for example:

- QR code
- another machine-readable carrier allowed by the applicable regulation (e.g. RFID, DataMatrix)

The data carrier encodes or provides access to the Product identifier.

This is an important conceptual distinction:

**Data carrier**

is not the same as:

**Product identifier**

and neither is the same as:

**EU-DPP**

For example:

**QR code**

↓

`https://prodigi.link/?.25P=VTA-MPLA-PM-346UJI3NUM`

↓

prodigi.link

↓

EU-DPP

The QR code is the carrier.

The URL contains the identifier.

The EU-DPP is the regulated digital information object.

---

#### Where can the EU-DPP data carrier be placed?

The horizontal standards support the technical framework.

The final placement requirement depends on the applicable Product regulation or delegated act.

Depending on the Product category, the carrier may be placed:

- on the Product
- on the Product packaging
- on accompanying documentation

The Product-specific legislation determines what is acceptable for that Product group.

---

#### What does EN 18221 Data Storage, Archiving persistence cover

EN 18221 addresses one of the most important lifecycle questions:

> **What happens to the EU-DPP when the commercial Product page or original system no longer exists?**

A Product can remain in use long after:

- the Sales Unit has been discontinued
- the manufacturer's website has changed
- the original marketing page has disappeared
- the active PIM platform has been replaced

EU-DPP information may still need to remain available.

In the SyncForce architecture:

**SyncForce Circular PIM**

creates and governs the Product and compliance information

↓

**prodigi.link**

maintains persistent identity and resolution

↓

**Perennis**

provides long-term publication and persistence

This separates the regulatory lifetime from the commercial website lifetime.

---

#### What does EN 18222 EU-DPP Lifecycle and search APIs cover?

EN 18222 addresses APIs used for managing and accessing the EU-DPP lifecycle.

For SyncForce, this is relevant for:

- creation of EU-DPP records
- updates
- access
- search
- exchange between systems
- lifecycle management

This allows the EU-DPP to function as a machine-readable regulatory information object rather than only as a webpage intended for people.

---

#### Why are APIs important for the EU-DPP?

The EU-DPP must be useful to more than consumers with a browser.

Potential users include:

- manufacturers
- importers
- authorities
- repairers
- recyclers
- service providers
- downstream business systems
- AI and software agents

These users may need structured data rather than a formatted webpage.

The SyncForce architecture therefore separates:

**identity**

from:

**resource**

and supports structured access through APIs and machine-readable representations.

---

#### What does EN 18223 Sytem Interoperabilty cover?

EN 18223 focuses on interoperability between EU-DPP systems.

This is important because the EU-DPP should not depend on one proprietary software platform.

Different systems need to understand and exchange common concepts.

The SyncForce Golden Hierarchy contributes to this by keeping distinct objects such as:

- Product Model
- Batch
- Serialized Item
- Economic Operator
- Facility
- EU-DPP
- Sales Unit
- Packaging System

separate but explicitly related.

The EU-DPP itself also has its own identifier, distinct from the Product identifier and the EU registry Registration ID.

**Read more:** [*Which identifiers are used in an EU-DPP?*](https://support.syncforce.com/knowledge/which-identifiers-are-used-in-an-eu-dpp?hsLang=en)

---

#### What does EN 18239 Access rights, security and confidentiality cover?

Not every EU-DPP data element necessarily has the same access level.

Some information may be public.

Other information may only be available to particular actors.

Examples may include:

- authorities
- repairers
- recyclers
- other authorised economic actors

EN 18239 addresses access rights, security and confidentiality.

The EU-DPP architecture therefore needs to distinguish between:

- public information
- controlled information
- authorised actors

while preserving the same underlying Product and EU-DPP identity.

---

#### Does public EU-DPP information require a login?

Public EU-DPP information should be accessible without turning the regulatory access route into a marketing login process.

In the SyncForce architecture, public EU-DPP routes are therefore designed to work without:

- mandatory account creation
- login
- app installation
- marketing profiling in the regulatory access path

This is intentionally different from a commercial Marketing Landing Page, where other functionality may exist.

---

#### What does EN 18246 Authentication, reliability and integrity cover?

EN 18246 addresses trust in the EU-DPP information.

The system must be able to support confidence that:

- information originates from the appropriate source
- information has not been improperly changed
- regulated data can be relied upon
- access and changes can be controlled and audited

This is particularly relevant where information is updated during the Product lifecycle.

SyncForce therefore maintains governance and audit information around regulatory data rather than treating the EU-DPP as a static webpage.

---

#### How do the standards fit together?

A simplified view is:

| Standard | Main question |
| --- | --- |
| **EN 18216** | How is EU-DPP data exchanged? |
| **EN 18219** | How are Products and related objects uniquely identified? |
| **EN 18220** | How is the identifier physically carried? |
| **EN 18221** | How is the information stored and preserved? |
| **EN 18222** | How is the EU-DPP managed and accessed through APIs? |
| **EN 18223** | How do different EU-DPP systems interoperate? |
| **EN 18239** | Who may access which information? |
| **EN 18246** | How are authenticity, reliability and integrity protected? |

Together, these standards create the horizontal EU-DPP infrastructure.

---

#### What do the standards not determine?

The horizontal standards do not define all Product-specific regulatory content.

The applicable Product regulation or delegated act determines topics such as:

- which information must be included
- which data elements are public
- which data elements require controlled access
- where the data carrier must be placed
- how long information must remain available
- whether the EU-DPP is created at Model, Batch or Item level

The horizontal standards define **how the EU-DPP infrastructure works**.

The Product-specific legislation defines **what the EU-DPP for that Product must contain and how it applies**.

---

#### How does prodigi.link fit into these standards?

prodigi.link is the persistent resolution layer.

For EU-DPP routes, it sits directly in the access path between:

**data carrier**

↓

**Product identifier**

↓

**prodigi.link**

↓

**EU-DPP resource**

It therefore has a role in several parts of the architecture, particularly:

- identifier handling
- resolution
- secure access
- persistence
- human and machine-readable access

For example:

`https://prodigi.link/?.25P=VTA-MPLA-PM-346UJI3NUM`

can remain the stable Product identifier while the actual EU-DPP resource changes over time.

**Read more:** [*How does prodigi.link support EU-DPP identification and resolution?*](https://support.syncforce.com/knowledge/how-does-prodigi.link-support-eu-dpp-identification-and-resolution?hsLang=en)

---

#### How does Perennis fit into these standards?

Perennis provides the long-term regulatory publication and persistence layer.

Its main relevance is where regulated EU-DPP information must survive changes to:

- commercial websites
- PIM systems
- Product lifecycle status
- active marketing systems

This is particularly aligned with the persistence and archiving requirements addressed by EN 18221.

A persistent Product identity can therefore continue to resolve to the required regulatory information beyond the active commercial lifecycle.

---

#### How does SyncForce Circular PIM fit into these standards?

SyncForce Circular PIM is where the underlying business and regulatory objects are managed.

These include:

- Product Models
- Economic Operators
- Facilities
- Packaging Systems
- Sales Units
- compliance data
- regulatory evidence
- technical documentation
- EU-DPP data

SyncForce therefore creates and governs the information from which the EU-DPP is built.

The European standards define how that information is identified, exchanged, published, protected and preserved.

---

#### What is the SyncForce principle behind this architecture?

The SyncForce Golden Hierarchy separates the business objects first.

The EU-DPP standards then provide the infrastructure for identifying, resolving, exchanging and preserving those objects and their regulatory information.

This prevents a common architectural mistake:

> treating the EU-DPP as simply a QR code connected to a Product webpage.

Instead:

**Product Model**

has its own identity

↓

**data carrier**

provides access to that identity

↓

**prodigi.link**

resolves it

↓

**EU-DPP**

provides the regulated information

↓

**Perennis**

ensures that information can remain available for the required lifetime

**See the full overview:** [*How does SyncForce support the EU Digital Product Passport, EU-DPP?*](https://support.syncforce.com/knowledge/how-does-syncforce-support-the-eu-digital-product-passport?hsLang=en)

 In one sentence

**The European EU-DPP standards define a complete infrastructure for identification, data carriers, exchange, APIs, interoperability, security and long-term persistence, while Product-specific legislation determines what each Product's passport must contain.**

- [Industry & Regulatory Knowledge](https://support.syncforce.com/knowledge/industry-regulatory-knowledge?hsLang=en#main-content)

    - [Product Portfolio](https://support.syncforce.com/knowledge/industry-regulatory-knowledge?hsLang=en#product-portfolio)
    - [Packaging & PPWR](https://support.syncforce.com/knowledge/industry-regulatory-knowledge?hsLang=en#packaging-ppwr)
    - [EU Digital Product Passport - DPP](https://support.syncforce.com/knowledge/industry-regulatory-knowledge?hsLang=en#eu-digital-product-passport-dpp)
    - [GS1 & GDSN](https://support.syncforce.com/knowledge/industry-regulatory-knowledge?hsLang=en#gs1-gdsn)
    - [Food & Label Information](https://support.syncforce.com/knowledge/industry-regulatory-knowledge?hsLang=en#food-label-information)
    - [EPR & Sustainability Data](https://support.syncforce.com/knowledge/industry-regulatory-knowledge?hsLang=en#epr-sustainability-data)
    - [Product Identification & GTIN](https://support.syncforce.com/knowledge/industry-regulatory-knowledge?hsLang=en#product-identification-gtin)
    - [PIM & Data Architecture](https://support.syncforce.com/knowledge/industry-regulatory-knowledge?hsLang=en#pim-data-architecture)
- [Product Data Management](https://support.syncforce.com/knowledge/product-data-management?hsLang=en#main-content)

    - [Packaging Data Management](https://support.syncforce.com/knowledge/product-data-management?hsLang=en#packaging-data-management)
    - [Product data imports](https://support.syncforce.com/knowledge/product-data-management?hsLang=en#product-data-imports)
    - [PDM setup and config](https://support.syncforce.com/knowledge/product-data-management?hsLang=en#pdm-setup-and-config)
- [Digital Asset Management](https://support.syncforce.com/knowledge/digital-asset-management?hsLang=en#main-content)

    - [FileConvert](https://support.syncforce.com/knowledge/digital-asset-management?hsLang=en#fileconvert)
- [Project Portfolio Management](https://support.syncforce.com/knowledge/project-portfolio-management?hsLang=en#main-content)

    - [Team & Planning](https://support.syncforce.com/knowledge/project-portfolio-management?hsLang=en#team-planning)
    - [Proofing & Approval](https://support.syncforce.com/knowledge/project-portfolio-management?hsLang=en#proofing-approval)
    - [Budget & Spend Management](https://support.syncforce.com/knowledge/project-portfolio-management?hsLang=en#budget-spend-management)
    - [Resource Management](https://support.syncforce.com/knowledge/project-portfolio-management?hsLang=en#resource-management)
    - [To Do (task & actions)](https://support.syncforce.com/knowledge/project-portfolio-management?hsLang=en#to-do-task-actions)
    - [Project definition](https://support.syncforce.com/knowledge/project-portfolio-management?hsLang=en#project-definition)
- [Product Catalog](https://support.syncforce.com/knowledge/product-catalog?hsLang=en)
- [Media Library](https://support.syncforce.com/knowledge/media-library?hsLang=en)
- [Product Data Syndication](https://support.syncforce.com/knowledge/product-data-syndication?hsLang=en#main-content)

    - [GS1-GDSN](https://support.syncforce.com/knowledge/product-data-syndication?hsLang=en#gs1-gdsn)
    - [DataPorts](https://support.syncforce.com/knowledge/product-data-syndication?hsLang=en#dataports)
    - [PS in Foodservice](https://support.syncforce.com/knowledge/product-data-syndication?hsLang=en#ps-in-foodservice)
    - [REST API](https://support.syncforce.com/knowledge/product-data-syndication?hsLang=en#rest-api)
- [Document Automation](https://support.syncforce.com/knowledge/document-automation?hsLang=en)
- [Exports & reports](https://support.syncforce.com/knowledge/exports-reports?hsLang=en)
- [Business Network Management](https://support.syncforce.com/knowledge/business-network-management?hsLang=en#main-content)

    - [Single Sign-On](https://support.syncforce.com/knowledge/business-network-management?hsLang=en#single-sign-on)
- [Services & Support](https://support.syncforce.com/knowledge/services-support?hsLang=en)
- [Partner Support](https://support.syncforce.com/knowledge/partner-support?hsLang=en)
- [General setup](https://support.syncforce.com/knowledge/general-setup?hsLang=en)
- [Campaign management](https://support.syncforce.com/knowledge/campaign-management?hsLang=en)
- [General](https://support.syncforce.com/knowledge/general?hsLang=en)

[![Chill listening crop-3](https://support.syncforce.com/hs-fs/hubfs/SyncForce_plus_1024-2.png?width=105&height=24&name=SyncForce_plus_1024-2.png "Chill listening crop-3")](https://www.syncforce.com/)

Copyright © 2026, SyncForce