Supply Chain Intro and Table of Contents Supply Chain August 2026 | Page 16

Digital Product Passports for Circular Supply Chains
3.3 CONFIDENTIALITY VERSUS TRANSPARENCY
The third barrier is governance, not technology. A DPP makes claims about material origin, recipe details, and factory locations that suppliers, especially below T1, regard as confidential. The pilot community converged on three mitigations:( 1) credential-level transparency, signed claims about a property without disclosing the underlying calculation, anchored in W3C Verifiable Credentials [ 9 ][ 16 ];( 2) tiered access, public claims for consumers, more detail for downstream economic operators, full detail for regulators; and( 3) decentralized identifiers( DIDs), so suppliers retain control over the resolution endpoint [ 9 ].
These mitigations work, but they shift the governance burden. The DPP is no longer a single document; it is a set of credentials, issued by different parties, verified against different trust anchors, presented to different audiences. A further governance layer is needed to answer the question the technical resolution layer cannot answer on its own: whether the issuing legal entity is authorised to make product claims in its home member state and whether that authorisation is recognised cross-border. This is the function of what this paper terms the Cross-border Recognition Bridge( see Figure 5.1)— the eIDAS 2.0 Qualified Trust Service Provider( QTSP) infrastructure that issues Qualified Electronic Attestations of Attributes( QEAAs) to legal entities, anchors them to national trusted lists, and makes them verifiable across all member states via the Commission’ s List of Trusted Lists( LotL) chain [ 28 ]. Designing for that full complexity is a supply-chain governance problem, not a labelling problem; and it is the principal reason the architecture in Section 5 is built on a federated rather than centralised model.
BASE project experience reinforces this: its federated data space architecture balances verifiable data exchange with industrial confidentiality through fine-grained access control, standardized semantic layers, and federated governance.
4 ALIGNMENT WITH UN / CEFACT AND EDM ASSOCIATION( OMG)
FRAMEWORKS
A DPP that is robust at national level but isolated at international level is a brittle infrastructure. The European DPP design space already extends beyond the EU institutional perimeter and aligning it with two existing global frameworks materially reduces implementation risk.
4.1 UN / CEFACT RECOMMENDATION 49 AND THE UNITED NATIONS TRANSPARENCY PROTOCOL
UN / CEFACT Recommendation 49 and its companion United Nations Transparency Protocol( UNTP) provide policy and technical guidance on traceability and transparency at scale, designed for DPP-style use cases [ 7 ].( At the time of writing, UNTP v0.7.0 is in a formal 60-day public review closing in July 2026 and is specified as suitable for pre-production pilot implementations; v1.0 is expected to follow.) UNTP is built on the same W3C primitives, namely DIDs, Verifiable Credentials, and JSON-LD vocabularies, that the EU’ s emerging DPP architecture relies on. Because UNTP was designed for global trade rather than only for EU compliance, it carries proven
12