What Data Does a Fashion Brand Need for a Digital Product Passport?
What data does your fashion brand need for an EU Digital Product Passport? Fiber composition, carbon footprint, supplier tiers, certifications — full ESPR field guide inside.
ayman zared
CEO

What Data Does a Fashion Brand Need for a Digital Product Passport?
TL;DR: Under the EU's ESPR regulation, fashion and textile brands must collect and structure the following data for a compliant Digital Product Passport: fiber composition by weight, country of origin, carbon footprint (ISO 14040 / PEF methodology), substances of concern under REACH, recyclability score, repairability index, supplier information across Tier 1–4, and product certifications such as GOTS, OEKO-TEX, and GRS. Enforcement begins July 2027. Data collection starts now.
Most brands already hold more DPP-relevant data than they realize. The problem is where it lives — scattered across PLM systems, supplier emails, sustainability reports, and spreadsheets that nobody owns. Getting DPP-ready is not primarily a technology problem. It is a data architecture problem. This article maps every data field you will need, explains which ones are public-facing and which stay internal, and shows you exactly where to start collecting.
This is article six in NormaTrack's DPP compliance series for fashion and textile brands. If you are new to the topic, start with What Is a Digital Product Passport in Fashion and ESPR for Fashion Brands: What You Need to Prepare Before 2027. If you have already read those and you understand why supply chain data is the hardest part of DPP readiness, this article is your field guide to the specific data you need to collect — and how to collect it at scale.
One clarification before we get into the data: the textile delegated act under ESPR has not yet been formally adopted as of mid-2026. However, the European Commission and Joint Research Centre (JRC) have published three major preparatory studies that provide the clearest available view of what will be required. The data fields covered in this article reflect those studies and the broader ESPR Regulation (EU) 2024/1781 framework. Brands that wait for "final clarity" before building data infrastructure will not have enough time to comply.
The ESPR enforcement deadline for textiles is July 1, 2027. A realistic data collection and implementation timeline runs six to twelve months. That means the window for a structured pilot is now.
What Data Fields Are Required in a Textile Digital Product Passport?
The JRC preparatory studies organize DPP content into four broad categories: product identification, producer information, product information (composition, care, durability), and compliance information (certificates, declarations). Within those categories, here are the specific data fields you need to collect.
Fiber Composition
What it is: A breakdown of all fibers used in the product, expressed as a percentage by weight.
What ESPR requires: All fibers present above 1% by weight must be declared. This aligns with existing EU textile labeling requirements under Regulation (EU) No 1007/2011, but the DPP version must be machine-readable and structured — not just printed on a label.
Where to collect it: Product specifications, PLM systems, supplier declarations. For blended fabrics, you will need verified composition data from your fabric mill — not an estimate. If your Tier 2 supplier is providing fabric, fiber composition data must come directly from them with documentation.
Common gap: Brands often hold composition data for the primary fabric but not for trims — zippers, linings, elastic, thread. ESPR covers the full product. Trims above the 1% threshold need to be declared.
Country of Origin
What it is: The country in which the product was manufactured, recorded as an ISO 3166 country code.
What ESPR requires: Manufacturing country — not country of brand registration, not country of fabric origin. For products manufactured across multiple countries (cut in one, assembled in another), the "substantial transformation" rule under EU customs law determines the declared origin.
Where to collect it: Tier 1 supplier records, purchase orders, certificates of origin. This data typically exists. The challenge is ensuring it is recorded at variant level — not just at brand or collection level — and that it stays current as production shifts between factories.
Carbon Footprint
What it is: The lifecycle greenhouse gas emissions of the product, expressed in kg CO2e per unit.
What ESPR requires: A lifecycle assessment (LCA) based on ISO 14040 methodology or the EU's Product Environmental Footprint (PEF) Category Rules for apparel. The carbon footprint figure must be calculated at product level — not at brand level, not as a category average.
Where to collect it: LCA data draws from multiple sources: raw material emission factors, spinning and weaving processes, dyeing and finishing, assembly, transport, and end-of-life assumptions. Most brands do not have this structured at variant level. Collecting it requires supplier process data — energy sources, transport modes, processing locations — mapped from Tier 1 through Tier 4.
The scale problem: Running a manual LCA for one product takes weeks. Running it for a catalog of 500 SKUs, each with multiple variants, is not operationally viable without automation. This is exactly why NormaTrack built its LCA engine — it maps material inputs, processing steps, and transport for every product variant automatically using ISO 14040 methodology, then recalculates as data changes. No consultants, no spreadsheets, no bottleneck.
Certifications: GOTS, OEKO-TEX, and GRS
What they are:
GOTS (Global Organic Textile Standard): Certifies organic fiber content and responsible manufacturing practices across the supply chain.
OEKO-TEX STANDARD 100: Certifies that every component of a product has been tested for harmful substances.
GRS (Global Recycled Standard): Certifies the percentage of recycled content in a product and responsible social and environmental practices.
What ESPR requires: Certifications are listed as recommended — not yet confirmed as mandatory — in the current JRC proposals. However, they feed directly into required fields: GRS certification supports recyclability claims, OEKO-TEX supports REACH compliance documentation, and GOTS supports fiber composition declarations. Including them in your DPP also significantly strengthens the auditability of sustainability claims under the EU Green Claims Directive, which runs parallel to ESPR.
Where to collect it: Certifications are issued at supplier node level — not at brand level. A GOTS certificate covers a specific spinning mill or dyehouse, not your brand. This means certifications must be attached to specific supply chain nodes and mapped to the variants that flow through those nodes. NormaTrack attaches OEKO-TEX, GOTS, and GRS certifications at node level within the supply chain map, so they automatically propagate to the correct variants.
Expiry is a real operational risk. Certifications renew annually. A valid GOTS certificate at the time of product launch may be expired by the time a regulator scans your QR code. Your DPP infrastructure needs to track certification expiry dates and flag renewals — not just store a certificate as a static document.
Substances of Concern
What it is: A declaration of hazardous or restricted chemical substances present in the product, referenced against the EU's REACH regulation and the ESPR substances of concern framework.
What ESPR requires: Chemical compliance documentation for substances above threshold concentrations defined under REACH (Regulation EC No 1907/2006). The DPP must make this information accessible to waste operators and recyclers, not just regulators.
Where to collect it: This data must come from your supply chain — specifically from dyehouses, finishers, and chemical suppliers. Many brands request Safety Data Sheets (SDS) or REACH compliance declarations from Tier 2 and Tier 3 suppliers but have no systematic way to structure that data at variant level. If your finishing process changes — a different dye lot, a new supplier — the substances declaration may also change. This field requires active data management, not a one-time collection.
Recyclability
What it is: A structured declaration of how the product should be recycled at end of life, including material-specific recycling pathways.
What ESPR requires: A recyclability score — currently proposed on the ESPR scale — along with care and recycling instructions accessible via the QR code. This field overlaps with GRS certification data and with the disassembly information required for the repairability index.
Where to collect it: Recyclability data is partly derived from fiber composition (mono-material products are easier to recycle than blended ones) and partly from the presence of non-recyclable components — metal hardware, coatings, bonded layers. Your product design team and materials sourcing team are the primary sources for this data.
Design decisions affect this field directly. A product designed with recyclability in mind will have better data to report. This is where DPP requirements begin to influence upstream design decisions — a dynamic that makes DPP implementation a cross-functional project, not just a compliance exercise.
Repairability
What it is: A score reflecting how easily the product can be repaired, maintained, or have components replaced.
What ESPR requires: A repairability index scored on the EU methodology (1–10 scale), plus repair instructions accessible to consumers and repair professionals via the DPP.
Where to collect it: Repair instructions and disassembly information typically exist within your product development documentation. The scoring methodology maps specific product characteristics — availability of spare parts, ease of disassembly, access to repair guides — to a numeric score. This is not data most brands have structured. It requires a deliberate documentation process, usually involving your product development and quality teams.
Supplier Information Across Tiers
What it is: Company name, location, and role for every supplier in the product's supply chain.
What ESPR requires: Tier 1 supplier information is confirmed as a minimum requirement. The JRC proposals indicate that Tier 2 and beyond will increasingly be required for specific data points — particularly where carbon footprint, substance compliance, or certification data originates at a deeper tier.
Where to collect it: Tier 1 data — your direct manufacturers — is typically available. The challenge is Tier 2 (fabric mills, yarn spinners), Tier 3 (fiber processors, dye houses), and Tier 4 (raw material producers). Collecting structured, verified data at these tiers requires supplier engagement programs, not just data entry. As covered in detail in Why Supplier Data Is the Hardest Part of DPP Readiness, this is where most brands encounter their biggest implementation bottleneck.
NormaTrack maps Tier 1 through Tier 4 supplier relationships at variant level — not just at collection or brand level. Each node carries its own certifications, process data, and location information, which feeds directly into the LCA calculation and the published DPP.
Public Data vs. Internal Data: What Goes on the QR Code?
Not all DPP data is consumer-facing. ESPR establishes a layered access structure — different data is visible to different actors.
Public data — accessible to anyone who scans the QR code — typically includes:
Fiber composition
Country of origin
Carbon footprint
Care and recycling instructions
Repairability score and repair instructions
Certifications (GOTS, OEKO-TEX, GRS)
Restricted data — accessible only to authorized parties such as market surveillance authorities, waste operators, and certified recyclers — typically includes:
Detailed chemical substance declarations
Raw LCA input data and confidence scores
Full supplier names and locations beyond Tier 1
Precise processing costs and commercial data
Internal data — not published in the DPP but stored in your system for audit purposes — includes:
Supplier pricing and contract terms
Internal compliance notes
Raw LCA methodology inputs
In NormaTrack, this distinction is configurable at field level. Each data field carries a visibility setting — Public, Restricted, or Internal — and the platform generates the QR code and DPP output accordingly. You decide what consumers see. You retain full control of commercially sensitive supplier information while still meeting the regulatory requirement to make it available to authorized parties.
How to Start Collecting DPP Data: A Practical Framework
The following sequence reflects how NormaTrack recommends approaching data collection for brands starting their DPP pilot.
1. Audit what you already have. Most brands hold 60–70% of required DPP data already — in PLM systems, supplier specifications, existing certifications, and sustainability reports. Run a data audit before you start collecting anything new. Map what exists, where it lives, and what is missing. As explored in Build Your Digital Product Passport with Data You Already Own, the gap is usually smaller than expected — but it is often scattered across disconnected systems.
2. Start with fiber composition and country of origin. These two fields are the most stable, most likely to already exist, and create the foundation for every other data field. Get them structured and verified at SKU level before moving to LCA or substances.
3. Issue formal data requests to Tier 1 and Tier 2 suppliers. Carbon footprint, substance compliance, and certification data must come from your supply chain. A formal data request — not an informal email — establishes that this is a compliance requirement, not an optional survey. Include specific data fields, acceptable formats, and deadlines. Templates help; NormaTrack provides them.
4. Attach certifications at node level, not brand level. Store GOTS, OEKO-TEX, and GRS certificates against the specific supplier that holds them — not against your brand or your product line. This ensures the right certification applies to the right variant and that expiry tracking works correctly.
5. Run your LCA on one product first. Carbon footprint is the most data-intensive field to collect and calculate. Start with one SKU. Validate the data flow from Tier 4 raw material through to finished product. Identify where your data confidence is low and where you need supplier input. NormaTrack's LCA engine runs this automatically using ISO 14040 methodology once supplier data is in the system — but the supplier data still has to be collected first.
6. Pilot your QR code and public DPP on one product. Before scaling to your full catalog, test the full flow: data collection, LCA calculation, QR code generation, and the consumer-facing passport. The pilot reveals operational gaps that documentation cannot anticipate. Why Spreadsheets Break Down in Supply Chain Traceability covers exactly what those gaps look like and why they compound at scale.
How NormaTrack Handles DPP Data at Catalog Scale
NormaTrack is purpose-built for fashion and textile brands that need to generate EU-compliant Digital Product Passports across a full product catalog — not just a single pilot product.
The platform handles:
Tier 1–4 supplier mapping at variant level, with certifications attached at each node
Automated LCA calculation per variant using ISO 14040 methodology, with bulk processing and confidence scoring
Structured data fields mapped directly to ESPR DPP requirements, including fiber composition, country of origin, carbon footprint, substances of concern, recyclability, repairability, and certifications
QR code generation per variant, with configurable public, restricted, and internal visibility settings
20+ integrations with tools already in your stack — Shopify, SAP, EcoVadis, Airtable, Google Sheets, Microsoft Dynamics, and more
CSV and Excel import with automatic column detection — no reformatting, no IT project
Setup takes days, not months. No consultants required.
Start Building Your DPP Data Infrastructure
The brands that will meet the July 2027 ESPR deadline are already collecting data. The ones that wait for the delegated act to be formally published will face a six-to-twelve-month implementation timeline with no runway left.
DPP compliance is not a technology decision. It is a data decision — made now, by the people responsible for supply chain, sustainability, and compliance. The data fields are clear. The methodology is defined. The deadline is fixed.
Request a NormaTrack demo and see how your catalog maps against ESPR data requirements — or explore a live DPP sample to see exactly what a compliant passport looks like at product level.
Frequently Asked Questions
What data fields are mandatory in a textile Digital Product Passport under ESPR?
Based on the current JRC preparatory studies and ESPR Regulation (EU) 2024/1781, mandatory fields for textile DPPs include: fiber composition by percentage weight, country of manufacture (ISO 3166 code), carbon footprint in kg CO2e per unit using ISO 14040 or PEF methodology, chemical compliance under REACH, recyclability score, repairability index (EU 1–10 scale), care instructions, and Tier 1 supplier information. The textile delegated act has not yet been formally adopted, but these fields reflect the most detailed regulatory guidance currently available as of mid-2026.
How is the carbon footprint calculated for a textile DPP?
Carbon footprint for a textile DPP must be calculated using lifecycle assessment (LCA) methodology — specifically ISO 14040 standards or the EU Product Environmental Footprint (PEF) Category Rules for apparel. The calculation covers raw material production, fiber processing, fabric manufacturing, dyeing and finishing, assembly, transport, and end-of-life assumptions. It must be calculated at product variant level, not as a brand or category average. Manual LCA calculation is not scalable at catalog level; NormaTrack automates this calculation per variant using ISO 14040 methodology.
Do certifications like GOTS and OEKO-TEX count as DPP data?
Yes. Certifications such as GOTS (Global Organic Textile Standard), OEKO-TEX STANDARD 100, and GRS (Global Recycled Standard) feed directly into DPP data fields covering fiber composition, chemical compliance, and recyclability. They are listed as recommended fields in current JRC proposals and are likely to be formally required in the textile delegated act. Critically, certifications must be stored at the specific supplier node that holds them — not at brand level — and must be tracked for expiry, since they renew annually.
What is the difference between public and internal data in a Digital Product Passport?
ESPR establishes a layered access structure for DPP data. Public data — accessible to any consumer who scans the QR code — includes fiber composition, carbon footprint, country of origin, certifications, and care and recycling instructions. Restricted data — accessible only to regulators, waste operators, and authorized recyclers — includes detailed chemical substance declarations and full supply chain depth. Internal data — not published in the DPP — includes supplier pricing, raw LCA inputs, and commercially sensitive supply chain details.
Does the ESPR DPP requirement apply to non-EU fashion brands?
Yes. Any textile or apparel product placed on the EU market requires a Digital Product Passport regardless of where the brand is headquartered or where the product is manufactured. Importers carry responsibility for ensuring DPP data is in place before products enter the EU market. Brands manufacturing in Bangladesh, Vietnam, Turkey, or any other country and selling into EU retail channels must comply with the same requirements as EU-based manufacturers.
How many supplier tiers does a DPP need to cover?
Tier 1 supplier information — your direct manufacturer — is the confirmed minimum under current ESPR guidance. However, carbon footprint calculations using ISO 14040 methodology require process data from Tier 2 (fabric mills), Tier 3 (yarn spinners, dyehouses), and Tier 4 (raw material producers). Chemical substance compliance data also traces back to Tier 2 and Tier 3 processing stages. Brands aiming for full DPP compliance — not just minimum compliance — need structured supplier data across all four tiers.
When does the ESPR textile DPP deadline take effect?
The EU's ESPR enforcement deadline for the textile and apparel category is July 1, 2027. The textile delegated act — which will formally define mandatory data fields and technical implementation requirements — is expected to be adopted before that date. A realistic data collection and system implementation timeline runs six to twelve months, which means brands need to begin their DPP pilot no later than Q3 2026 to have a validated system in place before enforcement begins.
About the author
ayman zared
CEO
TEST
More Blogs
View all →
Why Spreadsheets Break Down in Supply Chain Traceability
Spreadsheets can't meet EU DPP compliance demands. Learn why version control, audit trails, and variant tracking break down — and what fashion brands should use instead.

Build Your Digital Product Passport with Data You Already Own
Most fashion brands already hold the core data needed for EU Digital Product Passports. Learn how to map, structure, and activate it for ESPR compliance with NormaTrack.

ESPR for Fashion Brands: What You Need to Prepare Before 2027
The EU's ESPR sets binding rules for fashion brands by 2027. Learn what the regulation requires, what timelines apply, and how to start building compliance infrastructure now.
Ready to get started with NormaTrack?
Join fashion brands using NormaTrack to achieve EU ESPR compliance with confidence.