GuideFeatured4 July 2026

Why Supplier Data Is the Biggest Barrier to DPP Readiness in 2027

Most brands aren't ready for the EU Digital Product Passport—not because of the tech, but the data. Learn what's missing and how to fix it before 2027.

ayman zared

ayman zared

CEO

11 min read
Why Supplier Data Is the Biggest Barrier to DPP Readiness in 2027

Why Supplier Data Is the Hardest Part of DPP Readiness

TL;DR: Most fashion brands are behind on Digital Product Passport (DPP) readiness—not because of the QR code or the compliance portal, but because they don't have the supplier data to fill them. This post breaks down exactly what data is missing, why it's so hard to collect, and what a credible data infrastructure looks like ahead of the EU's 2027 ESPR deadline.

The conversation around Digital Product Passports has a tendency to start in the wrong place. Brands ask about QR code formats, consumer-facing interfaces, and which registry to use. Those questions matter—but they're the last five percent of the problem.

The harder question is the one most teams avoid: What data do we actually have, and what are we missing?

For fashion and textile brands, the honest answer is usually uncomfortable. Supply chains are long, fragmented, and poorly documented beyond the first tier. Certifications expire and aren't tracked centrally. Material composition records exist in someone's email inbox. Origin data is estimated, not verified.

The EU's Ecodesign for Sustainable Products Regulation (ESPR) entered into force in July 2024. Textile-specific delegated acts—and with them mandatory DPP compliance for apparel—are expected in 2027. That window sounds generous. It isn't, once you understand what collecting credible, structured, audit-ready supplier data actually requires.

This post is about that gap: what data DPPs demand, where fashion brands are falling short, and how to close it before the deadline makes the problem urgent in the worst possible way.

What Most Brands Get Wrong: It's a Data Problem, Not a Technology Problem

The instinct when facing a compliance requirement is to find a software tool that solves it. That instinct leads teams to evaluate DPP platforms before they've established what data those platforms will need to run.

A Digital Product Passport is, at its core, a structured data record. The QR code is just the delivery mechanism—a way to surface information that either exists or it doesn't. No platform, however sophisticated, can generate a compliant DPP from data that hasn't been collected.

The ESPR framework requires DPPs to include material composition, supply chain traceability documentation, environmental impact metrics, social compliance information, and circularity potential—at the product or variant level. Each data point has to come from somewhere. Most of it has to come from suppliers.

This is where the real challenge sits: not in the technology stack, but in the supplier relationships, data collection workflows, and internal processes that determine whether that information can be gathered, verified, and kept current at catalog scale.

The Supplier Data Problem: What's Missing and Why

Fashion supply chains are structurally difficult to document. The average garment passes through 4 to 7 countries before it reaches a consumer (Kōbō Labs). Each country represents a handoff point, a new supplier relationship, and a new gap in the data record.

The data that DPPs require from suppliers is specific. According to the EU's framework and industry guidance compiled by Renoon, compliant DPPs need:

  • Raw material details: fiber type, percentage breakdown, country of origin, and sustainability certifications for each material

  • Manufacturing process data: energy use, water consumption, emissions, and waste management at each processing stage

  • Social compliance information: labor conditions, wage data, worker safety certifications

  • Chemical usage records: compliance with REACH and restrictions on hazardous substances

  • Environmental certifications: GOTS, OEKO-TEX, Bluesign, GRS, and similar third-party verifications

Most brands have a fraction of this. The data that does exist is often scattered across procurement emails, supplier onboarding forms, audit reports from third parties, and legacy spreadsheets that haven't been updated in two or three seasons.

The root cause isn't negligence. It's that this level of documentation was never previously required. Supplier relationships were built on quality, price, and lead time—not data architecture.

Why Tier Mapping Is Where Most Brands Stall

Supply chain transparency breaks down fast beyond Tier 1. The numbers make this plain.

According to data from Kōbō Labs, 85% of fashion brands have visibility into their Tier 1 suppliers—the cut-and-sew factories assembling finished garments. That figure drops to 40% at Tier 2 (fabric mills handling weaving, knitting, and dyeing), to 15% at Tier 3 (yarn and fiber processors), and to just 5% at Tier 4 (raw material producers, including farms and fiber sources). More starkly, 52% of brands have visibility only to Tier 1.

This matters for DPP compliance because the regulation reaches all the way down. Material composition data has to be traced to its origin. Carbon footprint calculations have to account for upstream processing. Certifications like GOTS (Global Organic Textile Standard) only carry weight when they can be linked to verified facilities at every relevant tier.

The challenge at each level is distinct:

  • Tier 1 suppliers are generally cooperative—they're the direct commercial relationship. Getting structured data from them is feasible, though often still manual.

  • Tier 2 suppliers (mills) are typically known to Tier 1, but not always known to the brand. Getting them to participate in a data collection process they weren't contracted for requires either upstream leverage or supplier incentives the brand may not have.

  • Tier 3 and Tier 4 are frequently opaque by default. Yarn spinners and raw material producers operate at industrial scale, often serving hundreds of brands, with little incentive to customize reporting for any one customer. Getting verified origin data from a cotton farm in Uzbekistan or a flax processor in Belgium is a different category of problem than onboarding a new factory.

As TraceX Technologies notes, the absence of Tier 2 and Tier 3 supplier information is one of the most critical failure points in DPP implementation. Brands that assume this data can be collected quickly once a deadline approaches will find otherwise.

The Certification Gap: Records That Exist—But Not Where You Need Them

Certifications are a particular pain point because they represent data that technically exists but isn't structured for DPP use.

OEKO-TEX, GOTS, GRS, Bluesign, and similar certifications are held by specific facilities, for specific processes, and are valid for defined periods. A brand may know that a supplier holds GOTS certification in general terms, without knowing which specific facility it applies to, what product scope it covers, or when it expires.

For a DPP, that information has to be attached to a specific supply chain node—not asserted at the brand level. The certification has to be linked to the facility where it applies, connected to the products produced at that facility, and refreshed when it lapses.

Similarly, country-of-origin records—which DPPs require for material traceability—are often estimates based on supplier self-reporting rather than verified documentation. "Made in Portugal" may refer only to final assembly. The yarn came from Turkey, the cotton from India, and neither country appears anywhere in the brand's records.

This level of granularity is not unusual to request. It is unusual to already have.

Why Spreadsheets and Manual Processes Break Down at Scale

Many brands begin their DPP preparation the same way: a spreadsheet. One tab for suppliers, one for certifications, one for materials. It looks manageable at first.

The problem appears at scale. A mid-sized fashion brand might carry 200 to 500 active SKUs. Each SKU may have multiple variants. Each variant has its own material composition, its own supply chain path, and potentially its own certification requirements. When you multiply those variables across a catalog, you're no longer managing a spreadsheet—you're managing a relational database problem with a spreadsheet tool.

Manual processes also break under the pressure of change. Suppliers update their facilities. Certifications expire. Material sourcing shifts between seasons. Every change that goes unrecorded creates a gap in the DPP record—and a potential compliance liability.

Brands using PLM systems for supply chain transparency have been shown to reduce time spent on compliance reporting by 60% compared to manual approaches (Kōbō Labs). The efficiency gain is real, but the more important benefit is accuracy: structured data systems catch inconsistencies that spreadsheets miss entirely.

There's also an audit dimension. ESPR compliance isn't self-certified. The data behind a DPP needs to be auditable—traceable to its source, with documentation that can be reviewed by regulators or third-party verifiers. A spreadsheet doesn't produce an audit trail. A structured platform does.

What "Ready" Supplier Data Actually Looks Like

Understanding the gap requires knowing what the destination looks like. Supplier data that is genuinely DPP-ready has several consistent characteristics:

It's structured at the variant level. Material composition percentages, origin records, and certifications are linked to specific SKUs and variants—not asserted at the brand or collection level. A white linen shirt and a wool-blend version of the same style have different supply chain paths, different certifications, and different carbon footprints.

It's node-specific. Each supplier in the chain is recorded as a distinct entity with its own location, facility identifier, certification records, and process data. The relationship between nodes is documented—which mill supplies which factory, which raw material source feeds which spinner.

It's certification-verified. Sustainability claims are supported by named third-party certifications, linked to specific facilities, with expiry dates tracked.

It includes environmental process data. Energy consumption, water use, and emissions figures are captured at each processing stage, not just estimated at the finished-product level. This is the input that makes LCA calculations credible.

It's current. Supplier data has a shelf life. "Ready" data is maintained in a system that flags when certifications expire, when suppliers change facilities, or when material sourcing shifts.

Most brands are somewhere in the middle—better than a blank slate, but well short of audit-ready.

How to Start Collecting the Right Data Before 2027

The 2027 deadline for textile DPP compliance is fixed. The preparation window is not infinite, and supplier data collection takes longer than most teams expect. Here's a practical starting point:

Start with a supply chain audit. Map every direct supplier (Tier 1) first. For each, document facility name, address, production scope, and current certifications. This baseline is both useful immediately and necessary before you can move deeper.

Push the mapping to Tier 2 systematically. Ask Tier 1 suppliers to identify and document their fabric and processing partners. Prioritize high-volume product categories and materials that carry certification requirements (organic cotton, recycled content, etc.).

Standardize what you ask for. Inconsistent data requests produce inconsistent data. Use a defined supplier data template that specifies exactly which fields are required, in which format, and at which update cadence. Ambiguity is where gaps form.

Attach certifications to nodes, not brands. When a supplier provides a certification document, record which facility it covers and what its expiry date is. This turns a certification into a structured data point rather than a file attachment.

Choose infrastructure that scales. A system that can ingest existing spreadsheet data, map it to a supply chain structure, flag missing fields, and generate DPPs at catalog scale will return its cost quickly. NormaTrack, for example, handles Tier 1–4 supplier mapping, calculates LCA automatically using ISO 14040 methodology, and generates EU-compliant Digital Product Passports at variant level—without requiring consultants or months of configuration.

The goal for 2025 and 2026 is not a perfect DPP. It's clean, structured, credible data for the products most likely to be audited first—high-volume lines, products with sustainability claims, and items sold into EU markets.

The Window Is Narrower Than It Looks

The brands that will be in genuine trouble in 2027 are not those that chose the wrong DPP platform. They're the ones that delayed supplier data collection until the platform decision was already made—and discovered they had nothing to put into it.

Supply chain data infrastructure takes time to build because it depends on supplier cooperation, internal process change, and systematic verification. None of those things happen quickly.

A useful benchmark: of supply chain professionals surveyed ahead of ESPR enforcement, 49% expressed concern about their organization's readiness to meet DPP requirements, and 37% expected to miss compliance deadlines (Fluxy.One, citing industry data). Those aren't small margins.

The ESPR timeline is not ambiguous. ESPR entered into force in July 2024. The EU digital registry is scheduled for establishment by July 2026. Mandatory textile DPP compliance follows in 2027. That's a compressed sequence for an industry where supplier relationships are measured in seasons, not quarters.

The brands that will have a material advantage are the ones building data infrastructure now—mapping tiers, standardizing supplier data requests, and connecting certifications to specific nodes in a system that can produce a compliant passport on demand.

If you want to see what that infrastructure looks like in practice, explore a live DPP sample or request a demo to walk through NormaTrack's supply chain mapping and LCA engine using your own catalog data.


Frequently Asked Questions

What data do fashion brands need to collect from suppliers for Digital Product Passport compliance?

For EU DPP compliance, fashion brands need to collect: raw material type, percentage composition, and country of origin; manufacturing process data (energy, water, waste, emissions); social compliance records (labor conditions, worker safety); chemical usage documentation (REACH compliance); and relevant sustainability certifications such as GOTS, OEKO-TEX, or GRS. This data must be linked to specific supply chain facilities—not just asserted at the brand level—and must be maintained at the product or variant level.

When does the EU Digital Product Passport become mandatory for textiles?

The EU's Ecodesign for Sustainable Products Regulation (ESPR) entered into force in July 2024. Textile-specific delegated acts—which define precise DPP requirements for apparel—are expected in 2027, with mandatory compliance for textile and apparel products following in 2027–2028. The EU centralized digital registry is scheduled for establishment by July 2026.

Why is Tier 2 and Tier 3 supplier data so difficult to collect?

Tier 2 suppliers (fabric mills) and Tier 3 suppliers (yarn and fiber processors) are typically not direct commercial relationships for the brand. They are suppliers to Tier 1 factories, which means the brand has limited leverage to require data sharing. These facilities often serve many brands simultaneously and have no standard reporting format. Getting verified, structured data from Tier 2 and below requires either upstream contractual pressure through Tier 1 or direct outreach that takes time to establish.

How many fashion brands currently have supply chain visibility beyond Tier 1?

According to Kōbō Labs, only 40% of fashion brands have visibility into Tier 2 suppliers (fabric mills), 15% into Tier 3 (yarn processors), and 5% into Tier 4 (raw material producers). 52% of brands have visibility only to their Tier 1 cut-and-sew factories. This is the central challenge for DPP compliance, which requires traceability across the full supply chain.

What does "audit-ready" supplier data mean in the context of DPP compliance?

Audit-ready supplier data is structured at the variant level, linked to specific supply chain nodes (not asserted at the brand level), supported by named and dated third-party certifications, inclusive of environmental process data at each production stage, and maintained in a system that tracks changes and flags expiries. It must be traceable to its source and accessible to regulators or third-party verifiers on demand. A spreadsheet does not produce this standard of documentation; a structured data platform does.

Is 2027 enough time to build DPP-ready data infrastructure?

For brands starting from a strong Tier 1 data baseline, 2027 is achievable. For brands with significant gaps in Tier 2–4 visibility, missing certification records, or no standardized supplier data process, 2027 is tight. Supplier data collection, verification, and structuring takes months—not weeks. According to Fluxy.One's industry survey data, 37% of supply chain professionals already expect to miss DPP compliance deadlines. Starting supplier data collection and infrastructure decisions in 2025 significantly improves the likelihood of compliance.

About the author

ayman zared

ayman zared

CEO

More from ayman

TEST

Ready to get started with NormaTrack?

Join fashion brands using NormaTrack to achieve EU ESPR compliance with confidence.