Why Spreadsheets Break Down in Supply Chain Traceability
Spreadsheets can't meet EU DPP compliance demands. Learn why version control, audit trails, and variant tracking break down — and what fashion brands should use instead.
ayman zared
CEO

Why Spreadsheets Break Down in Supply Chain Traceability
TL;DR: Spreadsheets cannot meet the traceability demands of EU Digital Product Passport compliance. They lack reliable audit trails, collapse under version control issues, cannot scale across a product catalog, and make variant-level tracking nearly impossible. For fashion and textile brands facing mandatory ESPR enforcement from 2027, spreadsheet-based systems are a structural liability — not a stopgap solution.
Most fashion brands didn't choose spreadsheets deliberately. They accumulated them. A supplier contact list here, a material composition file there, a tab for certifications someone built two seasons ago. At small scale, the system holds. Teams learn which file to trust, who owns which column, and where the "real" version lives.
Then the catalog grows. Supplier tiers multiply. The EU asks for fiber composition, carbon footprint, country of origin, and repairability scores — per variant, not per collection. Suddenly, the spreadsheet that worked for 50 SKUs is being asked to carry 500. And it can't.
This isn't a matter of skill or discipline. Spreadsheets were not designed for supply chain traceability. They were designed for calculation. Asking them to manage multi-tier supplier relationships, track data lineage, and produce audit-ready records is asking the wrong tool to do the right job. The costs — operational, financial, and regulatory — compound quietly until they don't.
This article breaks down exactly where spreadsheets fail in supply chain traceability for EU DPP compliance: version control, audit trails, catalog scale, and variant tracking. If you've read the earlier articles in this series on what a Digital Product Passport is, why supplier data is the hardest part of DPP readiness, what ESPR requires before 2027, and how to build a DPP with data you already own, you already understand the compliance stakes. Now it's time to understand why the tools most teams are currently using will not get them there.
What Does Supply Chain Traceability Actually Require for DPP?
Under ESPR, the EU's Digital Product Passport for textiles — mandatory from 2027 — requires specific, verifiable data attached to every product. The confirmed data fields include fiber composition by percentage, country of origin, carbon footprint per unit, recycling instructions, a repairability index, hazardous substance declarations, and supplier information at minimum Tier 1.
Every one of those fields requires a source. That source must be traceable — meaning the data must carry a clear record of where it came from, when it was captured, who provided it, and whether it has changed. Regulators reviewing DPP compliance are not just checking whether the fields are filled in. They are evaluating whether the system managing that data is trustworthy.
A spreadsheet can store a fiber composition percentage. It cannot prove that percentage was verified, approved, or unchanged since your Tier 2 supplier submitted it six months ago. That distinction — between storing data and having auditable, traceable data — is precisely where spreadsheet-based traceability breaks down.
Why Do Spreadsheets Fail at Version Control for Supplier Data?
Version control is where most brands first feel the pain. A team member updates a supplier's material composition. Someone else, working from a downloaded copy, overwrites a different cell in the same row. A third person emails a static export to the sourcing manager, who makes edits offline and re-uploads a new file. Three weeks later, no one can confidently say which version of that supplier record is current.
According to research cited by GAINS Systems, the European Spreadsheet Risks Interest Group found that more than 90% of spreadsheets contain errors — and because spreadsheets are rarely tested, many of those errors go undetected. In supply chain management specifically, 67.4% of supply chain managers still rely on Excel for management tasks, according to G2 research. The combination of widespread use and high error rates is not a coincidence. It is a structural feature of how spreadsheets work.
Supply chain data changes constantly. Suppliers update certifications. Mills change. Material compositions shift between seasons. Each change needs to be captured, attributed, and preserved — not overwritten. Spreadsheets have no native mechanism for this. You can add a "last updated" column, but nothing enforces its accuracy. You can color-code the "final" version, but nothing prevents someone from editing a copy.
For DPP compliance, version confusion is not a minor inconvenience. If an EU market surveillance authority asks which supplier provided a specific material input for a specific SKU in a specific season, your answer cannot depend on which file someone opens first.
Why Don't Spreadsheets Provide the Audit Trails That DPP Requires?
An audit trail, in the context of supply chain traceability, is a time-stamped record of every change made to a data point: what changed, who made the change, and what the previous value was. DPP compliance depends on this. So does any serious compliance audit.
Spreadsheets were not built to be robust audit trails. As QT9 Software describes it, "lost traceability is a major hidden cost because spreadsheets do not provide robust audit trails or dependable record history." Cells can be overwritten without trace. Rows can be deleted. Files can be saved over earlier versions. The context — why a change was made, who authorized it, what the original value was — disappears.
The practical consequence plays out when you need to reconstruct the data history for a product under investigation. Instead of querying a system, teams end up searching email threads, comparing file timestamps, and asking colleagues what they remember. That reconstruction process is expensive, slow, and — in a compliance context — deeply unconvincing to a regulator.
A strong DPP system creates evidence as work happens, not after the fact. Spreadsheets do the opposite: they require you to reconstruct evidence you never actually captured.
How Does Scaling a Spreadsheet Across a Full Product Catalog Break Down?
A spreadsheet can handle a small catalog with manual effort. As the catalog grows, the manual effort grows proportionally — but the system's reliability does not grow with it.
Consider what scaling actually means for a mid-sized fashion brand preparing for DPP compliance. Each product has multiple variants (colorways, sizes, fabric weights). Each variant may have a different supplier for certain components. Each supplier relationship has associated certifications, each with its own expiry date. Each certification may apply at different tiers. Multiply this across several hundred SKUs and the data structure alone becomes unmanageable in a flat-file format.
Only 13% of companies surveyed by Deloitte could fully map their supply chain networks, with 72% having limited visibility beyond their Tier 2 suppliers. Spreadsheets are a significant contributor to that visibility gap. They are flat; supply chains are not. Representing a multi-tier supplier relationship in a spreadsheet requires either collapsing complexity into a single cell (losing accuracy) or building an elaborate multi-tab structure that breaks the moment someone adds a column in the wrong place.
The result is what supply chain professionals describe as "the 27th spreadsheet problem." The first file made sense. The second was necessary. By the time there are two dozen files managed by different people with different naming conventions and different update schedules, the system has become more of a liability than an asset. The time spent maintaining files displaces the time that should be spent improving data quality.
Why Is Tracking Product Variants So Difficult in Spreadsheets?
For DPP compliance, variant-level traceability is not optional. The EU requires that passport data attach to specific products — not to a collection, a material category, or a brand-level claim. A white linen shirt and a navy version of the same shirt may share a base material but differ in dye processing, which affects their environmental footprint. Both need their own accurate passport.
Spreadsheets have no native concept of a product variant. Teams typically solve this by duplicating rows — one row per variant — and manually copying shared data fields across all duplicates. When the shared data changes (say, a supplier updates their carbon footprint data), every duplicate row must be updated separately. That manual propagation is where errors concentrate.
The average cost of a spreadsheet error in supply chain operations is estimated at $10,000, according to Security Boulevard research. That figure reflects direct costs. The indirect costs — failed audits, regulatory penalties, reputational damage — are harder to quantify but considerably higher.
Variant-level tracking also matters for confidence. When a regulator or retailer asks for the passport data for a specific SKU in a specific colorway from a specific season, the answer should come from a system with clean, linked records — not from someone manually cross-referencing three files to reconstruct an answer.
What Does a Structured Alternative to Spreadsheets Look Like for DPP Compliance?
The structured alternative to spreadsheets is a purpose-built traceability platform that treats supply chain data as linked, versioned, and auditable — rather than as flat rows in a file.
NormaTrack is built specifically for this. Fashion and textile brands use NormaTrack to map supply chains from Tier 1 to Tier 4, collect and verify supplier data, calculate lifecycle assessments automatically per variant using ISO 14040 methodology, and publish EU-compliant Digital Product Passports with a scannable QR code. Every change to supplier data is logged. Every certification is attached at the relevant supply chain node. Every variant has its own passport.
The platform integrates with tools teams already use — Shopify, SAP, Airtable, Google Sheets, Microsoft Dynamics, and 20+ others — so migrating from spreadsheets does not require rebuilding from scratch. NormaTrack maps columns automatically on upload. The shift from spreadsheet to structured system does not take months. Setup takes days.
Crucially, NormaTrack's audit inspector gives brands visibility into data confidence — flagging where supplier information is incomplete, outdated, or unverified before that gap becomes a compliance problem. That is the difference between a system that stores data and a system that manages it.
Brands that build structured traceability infrastructure now will have clean, auditable supply chain data when ESPR enforcement begins in 2027. The ones still reconciling spreadsheets will be scrambling to produce records they never properly captured.
Stop Managing Traceability in Files. Start Managing It in a System.
Spreadsheets are not failing because the teams using them lack rigor. They are failing because the demands of DPP compliance — multi-tier supplier visibility, variant-level data, audit-ready records, catalog-scale management — exceed what any flat-file system can structurally deliver.
The gap between what spreadsheets can do and what ESPR requires is not closeable with better naming conventions or stricter update protocols. It requires a different kind of tool.
Request a NormaTrack demo to see what a structured traceability system looks like against your actual catalog. Or explore a live DPP sample to understand what your products' passports need to contain before 2027 enforcement begins.
Frequently Asked Questions
Can spreadsheets be used as part of a DPP compliance workflow?
Spreadsheets can serve as a data source for initial import, but they cannot function as the system of record for DPP compliance. EU market surveillance authorities evaluate whether the system managing product data is auditable and controlled. Spreadsheets lack version control, change history, and data integrity safeguards that a regulated compliance environment requires. NormaTrack accepts spreadsheet imports and maps columns automatically, so existing data does not go to waste — it simply moves into a system that can manage it properly.
What specific audit trail requirements does the EU DPP impose on fashion brands?
The EU ESPR framework requires that DPP data be verifiable and traceable to its source. This means brands must be able to demonstrate who provided specific data, when it was captured, and whether it has been modified. Regulators assessing DPP compliance are not only checking field completeness — they are evaluating data integrity. A spreadsheet that has been overwritten, duplicated, or emailed across teams cannot provide that assurance.
How many tiers of the supply chain does DPP compliance require brands to map?
Under ESPR delegated acts for textiles, supplier information is required at a minimum at Tier 1. However, data fields such as fiber composition and carbon footprint per unit require inputs from deeper in the supply chain — typically Tier 2 and Tier 3 — to be calculated accurately. NormaTrack maps supply chains from Tier 1 to Tier 4, attaching certifications and material data at each node.
How long does it take to migrate from spreadsheets to a traceability platform like NormaTrack?
NormaTrack is designed for setup in days, not months. The platform accepts CSV and Excel imports with automatic column detection, so existing supplier and product data transfers without manual reformatting. A pilot on a single SKU can be live in days, providing a validated data flow and QR code before scaling to the full catalog.
What happens if a fashion brand does not have DPP-compliant data in place before the 2027 ESPR deadline?
Non-compliant products can be blocked from entering the EU market or withdrawn from retail channels by national market surveillance authorities. Brands may also face financial penalties under national laws implementing ESPR. Additionally, retailers sourcing from non-compliant suppliers increasingly carry liability themselves — meaning trade partners will require DPP readiness as a condition of supplier qualification well before the formal enforcement date.
Is variant-level traceability required for EU Digital Product Passport compliance?
Yes. EU ESPR requires that DPP data attach to specific products, not to collections or brand-level categories. Two variants of the same garment that differ in material processing — for example, different dye methods — may have different carbon footprints and require separate passports. NormaTrack handles variant-level traceability natively, with each variant receiving its own passport and QR code.
About the author
ayman zared
CEO
TEST
More Blogs
View all →
What Data Does a Fashion Brand Need for a Digital Product Passport?
What data does your fashion brand need for an EU Digital Product Passport? Fiber composition, carbon footprint, supplier tiers, certifications — full ESPR field guide inside.

Build Your Digital Product Passport with Data You Already Own
Most fashion brands already hold the core data needed for EU Digital Product Passports. Learn how to map, structure, and activate it for ESPR compliance with NormaTrack.

ESPR for Fashion Brands: What You Need to Prepare Before 2027
The EU's ESPR sets binding rules for fashion brands by 2027. Learn what the regulation requires, what timelines apply, and how to start building compliance infrastructure now.
Ready to get started with NormaTrack?
Join fashion brands using NormaTrack to achieve EU ESPR compliance with confidence.