One printed QR code: it passes checkout, reaches your customers, and will carry your product passport. Unitag runs the links behind it.
The full technical requirements for a DPP-ready resolver: EN 18xxx standards, GS1-Conformant behaviour, link types, timelines. Open, indexable, no form in the way. A formatted PDF edition arrives by email if you want a portable copy.


Unitag is certified by GS1 France on the GS1 Digital Link URI structure and the QR Code symbol.

Live in production: the Floris van Bommel product passport, opened from the shoe’s GS1 Digital Link QR code, resolved at batch level.
The obscure bits, translated
Open any Digital Product Passport text and you meet a wall of acronyms: ESPR, EN 18219, JTC 24, resolver, linkType. Three ideas are enough to navigate all of it.
The switchboard behind the QR code. Every scan lands there, and it decides where to send it: product page, passport, instructions, recall notice. The destination can change at any time; the printed QR code never does.
Without a resolver, the printed URL is frozen for the product’s lifetime, and a change of destination means a reprint.
A web address that carries the product’s identity. The GTIN you already have, the batch, the serial: all readable in the URL, by a checkout scanner and by a smartphone.

Europe’s checklist for the passport, written by CEN-CLC/JTC 24. Eight standards, each answering one plain question: who is identified, on which carrier, how data moves, how long it lives, who may read it.
Six of the eight are already cited in the EU Official Journal. Your next tender will quote them.

2013
platform founded, hosted in the EU
1,000+
recurring clients
189
countries where our QR codes are scanned
Brands such as Bonduelle, Migros and Schneider Electric manage their QR codes on Unitag.
The checklist
Each standard in the DPP package fits in one sentence. The full specification lower on this page carries the detailed requirements of each one.
Identifiers. Who is what: product, economic operator, facility. GS1 Digital Link is one of five permitted schemes, and the only one your checkouts already read.
Data carriers. QR code, Data Matrix or RFID. At least one carrier must be readable free of charge with an ordinary smartphone, no app: in practice, the QR code.
Data exchange. Systems talk over secured, authenticated, tamper-resistant APIs (HTTPS).
Lifecycle. Create, read, update and search passports, and submit identifiers to the EU registry that customs checks.
Interoperability. One shared data model, so a passport stays portable across service providers.
Persistence. The passport stays available for the product’s lifetime, backup included, even if the operator disappears.
Access. Public data for everyone, confidential data behind role-based access aligned with eIDAS. Completing formal approval.
Authenticity. Passport data is electronically signed, so it can be verified. Completing formal approval.

In practice
Everything the specification describes (identifiers, typed links, redirects) runs from the same Unitag dashboard that already manages marketing QR codes. Compliance is not a second tool.
Each product is created with its GS1 primary key, brand and range. The resolver publishes the matching GS1 Digital Link URI and routes every scan to the right destination, at item, batch or serial level.
The checkout scan and the consumer scan land in the same place: with you.


Redirects, link types, scan statistics per product and per country: the dashboard gives the overview that auditors and retailers ask for.
Illustrative interface, sample data.
Have a question about these standards, or want help preparing your company’s transition?
Contact usThe reference
Version 1.2.1, August 2026. This is the working reference, complete on this page. The email box below sends the same content as a formatted PDF.
Version 1.2.1 · August 2026 · Unitag technical reference. This page is the full specification, freely readable and indexable. Prefer a portable copy? Use the email box at the end to receive the formatted PDF.
This document specifies the technical requirements applicable to a DPP-ready resolver under the EU Ecodesign for Sustainable Products Regulation (ESPR, Regulation (EU) 2024/1781) and the harmonised European standards published by CEN-CLC/JTC 24 (EN 18xxx family, 2026; six of the eight already cited in the EU Official Journal), together with the GS1-Conformant Resolver standard, aligned with ISO/IEC 18975.
| Reference | Scope |
|---|---|
| Regulation (EU) 2024/1781 (ESPR) | Legal basis for the DPP; delegated acts per product group define data content and granularity (model / batch / item). |
| EN 18219:2026 - Unique identifiers | Product, economic operator and facility identifiers; five permitted product-identifier schemes including GS1 Digital Link URIs, self-issued Identification Links, W3C DIDs, RFID/2D identifiers and DOIs; uniqueness rules per ISO/IEC 15459. |
| EN 18220:2026 - Data carriers | QR Code (ISO/IEC 18004), Data Matrix (ISO/IEC 16022), RFID (HF/NFC/UHF RAIN); print quality, durability, placement; at least one carrier readable free of charge with an ordinary smartphone, no app. |
| EN 18216:2026 - Data exchange protocols | RESTful APIs over HTTPS/TLS; authenticated, confidential, tamper-resistant exchange. |
| EN 18222:2026 - Lifecycle APIs | Create/read/update/search operations, element-level access, batch retrieval, versioning, EU DPP registry submission, gateway link resolution to the correct database. |
| EN 18223:2026 - System interoperability | Shared data model: passport container, metadata, and linkage of each data element to a machine-readable definition in a semantic repository. |
| EN 18221:2026 - Storage & persistence | Availability for the product’s lifetime; mandatory backup via a DPP service provider; archiving of passport versions. |
| EN 18239 - Access rights & security | Role-based access aligned with eIDAS levels of assurance; separation of public data from business-confidential data. (Completing formal approval mid-2026.) |
| EN 18246 - Data authentication & integrity | Electronically signed passport data: W3C Verifiable Credentials, eIDAS Electronic Attestation of Attributes, Visible Digital Seal, or digital signature structures. (Completing formal approval mid-2026.) |
| GS1-Conformant Resolver / ISO/IEC 18975 | Resolver behaviour: redirection, linkType semantics, linkset responses (RFC 9264), resolver description file. |
| GS1 Digital Link URI syntax | Structure of the URI encoded in the data carrier (GS1 Application Identifiers as path segments). |
Three identifier types are defined: product, economic operator (typically EORI, VAT number or GLN) and facility (GLN or equivalent). The product identifier is carried as a web-enabled structured path; with GS1 identification the carrier encodes a GS1 Digital Link URI whose primary key is the GTIN (AI 01), optionally qualified to batch/lot (AI 10) and serial (AI 21), matching the granularity required by the applicable delegated act:
https://id.unitag.io/01/09506000134352/10/LOT123/21/SER456
If a primary key (e.g. GTIN) is supported by the resolver, all of its key qualifiers and data attributes shall be fully supported (CPV, batch/lot, serial). For every entry-point URI, however granular, a default link shall exist at that level or be inherited from a higher level of the identifier hierarchy.
The identifier reaches the reader through a 2D optical symbol (QR Code per ISO/IEC 18004 or Data Matrix per ISO/IEC 16022) or RFID (HF/NFC/UHF RAIN). At least one carrier per product must be readable free of charge with an ordinary smartphone without installing an app, which in practice makes the QR code the baseline carrier. Print quality is verified per ISO/IEC 15415 (grade C / 1.5 is the common industry minimum); the QR code quiet zone (4 modules) must be preserved; module size is chosen for the intended scan distance; substrate and ink must keep the symbol readable for the product’s lifetime under the durability conditions of the applicable delegated act.
The resolver answers HTTP GET/HEAD/OPTIONS over HTTPS (TLS mandatory), supports CORS, and redirects the client to the most appropriate destination. By default the entire query string is passed through to the target URL on redirect. EPC binary strings shall be decompressed per the GS1 Digital Link compression standard; full URI compression support is optional. When redirecting to another resolver, the uncompressed URI should be used.
| Scenario | HTTP response |
|---|---|
| Successful resolution | 302 / 303 redirect to target (or 200 with a linkset) |
| Invalid GS1 Digital Link URI syntax | 400 Bad Request |
| Identifier unknown to the resolver | 404 Not Found |
| Requested linkType not available | 404 Not Found (optionally with the available linkset) |
| Several equally valid links | 300 Multiple Choices with linkset |
Exactly one default link shall exist per identified entity, typed gs1:defaultLink plus a descriptive type (e.g. gs1:pip), with no optional attributes. The resolver redirects to it unless the request carries information allowing a better response (linkType, language, context). Optional gs1:defaultLinkMulti enables content negotiation by language or media type via Accept headers.
Links are typed with the GS1 Web Vocabulary. The main linkType to implement for DPP is gs1:dpp: it signals that the requesting system (consumer app, recycler, market surveillance or customs tooling) wants the Digital Product Passport itself.
GET https://id.unitag.io/01/09506000134352?linkType=gs1:dpp
Accept: application/ld+json → signed JSON-LD DPP document
| linkType | Purpose | Priority |
|---|---|---|
| gs1:dpp | The Digital Product Passport document / viewer, the core DPP linkType. | Mandatory (DPP) |
| gs1:defaultLink | Fallback destination when no better match exists; required by the resolver standard. | Mandatory |
| gs1:pip | Product information page (brand owner / retailer). | Recommended |
| gs1:productSustainabilityInfo | Sustainability of manufacture, recycling information. | Recommended |
| gs1:certificationInfo | Certification information about the product. | Recommended |
| gs1:instructions | Assembly / usage / repair instructions. | Optional |
| gs1:safetyInfo | Safety information about the item. | Optional |
| gs1:recallStatus | Whether the product has been recalled. | Optional |
| gs1:traceability | Track-and-trace information. | Optional |
To list every link available for a given product, request the linkset: ?linkType=linkset or header Accept: application/linkset+json (serialised per RFC 9264, validating against the GS1 linkset schema). Each link entry carries a mandatory target URL, link type and title, plus optional language tags, media type and context values.
The resolver description file, served at this route, declares the resolver’s capabilities: supported identifier keys, additional linkType vocabularies, and the context values used for conditional routing (language, country, device; the resolver-standard equivalent of Unitag’s smart redirects). It shall validate against the JSON schema published by GS1.
GET https://id.unitag.io/.well-known/gs1resolver
{ "name": "Unitag Digital Link Resolver",
"resolverRoot": "https://id.unitag.io",
"supportedPrimaryKeys": ["01", "414", "417"],
"supportedLinkType": [{"namespace": "https://gs1.org/voc/", "prefix": "gs1:"}],
"linkTypeDefaultCanBeLinkset": false,
"supportedContextValuesEnumerated": ["language", "country", "device"],
"contact": "vcard..." }
Required properties: resolverRoot and supportedPrimaryKeys. Recommended: name, supported linkType namespaces, context values (enumerated or external), JSON-LD context location and contact details.
Beyond redirection, DPP systems expose RESTful APIs over HTTPS/TLS with authenticated, tamper-resistant exchange (EN 18216). EN 18222 specifies the lifecycle API surface: create, read, update and search operations on passports, element-level access, batch retrieval, versioning queries, and submission of unique identifiers to the EU DPP registry (checked by customs at import). EN 18223 defines the shared data model (the passport container, its metadata, and the linkage of every data element to a machine-readable definition in a semantic repository) so that passports remain portable across DPP service providers.
The passport must remain available for the product’s lifetime: EN 18221 mandates a backup through a DPP service provider and the archiving of passport versions, including after an economic operator ceases activity. EN 18239 separates public data (e.g. recyclability) from business-confidential data through authenticated, role-based access aligned with eIDAS levels of assurance. EN 18246 requires passport data to be verifiable as authentic via an electronically signed data construct, implementable with W3C Verifiable Credentials, an eIDAS Electronic Attestation of Attributes, a Visible Digital Seal, or a standard digital signature structure.
| Milestone | Date |
|---|---|
| Battery passport mandatory (Regulation (EU) 2023/1542), QR code data carrier | February 2027 |
| ESPR delegated acts for first product groups (iron & steel first; textiles, tyres and aluminium announced for 2027; furniture 2028; mattresses and ICT products 2029) | 2026–2029 |
| Application of first ESPR delegated acts (typically ~18 months after adoption) | ~2028–2030 |
Note: EN 18239 (access rights) and EN 18246 (data authentication) were still completing formal approval in mid-2026; verify final texts before locking implementation details that depend on them. Unitag is certified by GS1 France on the GS1 Digital Link URI Standard structure and the QR Code symbol, and is a GS1 Solution Provider.
PDF · v1.2.1 · 12 pages A4
The same content as this page, laid out to travel: attach it to a tender, forward it to procurement, your IT lead or your integrator. One email address, the document arrives within a minute.
One email only, the one with the document. Data processed in the EU, GDPR-compliant.
Frequently asked questions
No. The first dated obligation is the battery passport, in February 2027; other sectors follow as the delegated acts land, from 2026 to 2029. Infrastructure choices happen now though: a conformant resolver installed today avoids a forced migration later.
Yes, if they are dynamic and served by a resolver. The printed visual stays as it is: the resolver adds a gs1:dpp destination when the time comes. Static QR codes will need regenerating.
Two timelines, one carrier. Sunrise 2027 comes from retail: by the end of 2027, retailers will need to be able to accept GS1 Digital Link QR codes at the till. The passport comes from the ESPR regulation and arrives sector by sector. The same printed QR code serves both, and that is exactly the resolver’s job.
The GS1-Conformant Resolver standard defines the expected behaviour, and GS1 publishes the validation schema for the resolver description file. Unitag is certified by GS1 France on the GS1 Digital Link URI structure and the QR Code symbol, and is referenced as a GS1 Solution Provider.
Yes. Everything is on this page, readable and indexable. The email box only exists for the formatted PDF edition, the version that travels well in a tender file or an inbox.
Create a GS1 product on the console, get its Digital Link URI, and scan it. It takes a few minutes and no payment details.
Try it on the consoleContext first? Read the GS1 Digital Link guide . Running a DPP programme? Talk to our team.