EN 18239:2026
(Main)Digital product passport - Access rights management, information system security, and business confidentiality
General Information
- Abstract
This document specifies the requirements for digital product passport (DPP) access rights management, including IT security, data protection, and responsibility transfer between economic operators. It defines the framework for managing confidential information access, while acknowledging that public DPP data requires no access restrictions to be read.
- Status
- Published
- Publication Date
- 15-Sep-2026
- Technical Committee
- JTC 24 - Digital Product Passport (DPP)
- Drafting Committee
- WG 3 - Security
- Current Stage
- 6060 - Definitive text made available (DAV) - Publishing
- Start Date
- 16-Sep-2026
- Due Date
- 02-Sep-2026
- Completion Date
- 16-Sep-2026
Overview
EN 18239:2026 sets the comprehensive requirements for access rights management, information system security, and business confidentiality in the context of Digital Product Passports (DPP). Issued by CEN, this standard aligns with digital product tracking under Regulation (EU) 2024/1781, providing a unified framework for controlling access to confidential product information across the complete product lifecycle. The document addresses IT security, data protection, and mechanisms for secure responsibility transfer between economic operators, ensuring sensitive DPP data is adequately protected while public data remains openly accessible. This standard applies to all product groups required to implement DPPs and is a key reference for regulatory compliance, industry best practices, and supply chain transparency in the circular economy.
Key Topics
Access Rights Management
Establishes an operator-based system enabling assignment, authentication, and delegation of access rights to DPP data. Roles and responsibilities can be customized for different types of economic operators, authorities, and value chain actors, with specific access rights defined through delegated acts.Information System Security
Details security measures to ensure the confidentiality, integrity, and availability of controlled DPP data. Emphasizes robust IT security strategies, including security by design, operational resilience, and continuous improvement processes in line with recognized standards such as ISO/IEC 27001.Business Confidentiality
Outlines requirements for protecting proprietary and sensitive information within DPP systems. Includes process logging, controlled vocabularies for rights management, and strong authentication protocols to prevent unauthorized access and data scraping.Responsibility Transfer
Provides clear rules for transferring access and responsibility for DPP data between supply chain partners, ensuring business continuity and compliance with data protection regulations as products move through different lifecycle stages.
Applications
EN 18239:2026 is relevant for a wide range of stakeholders involved in the manufacturing, distribution, and lifecycle management of products within the EU:
- Manufacturers and Importers: Implement compliant DPP systems ensuring only authorized parties can access sensitive product information, facilitating certification and market entry.
- Distributors, Dealers, and Fulfilment Providers: Maintain transparent and secure product information handling, supporting downstream partners and end-users.
- Professional Repairers and Recyclers: Gain authenticated access to technical details required for lawful repair, refurbishment, or recycling, supporting the sustainable use of products.
- Authorities and Market Surveillance: Securely access relevant DPP data for regulatory checks while respecting confidentiality, supporting efficient enforcement and reporting.
- IT Service Providers: Design and maintain DPP platforms aligned with standardized approaches to security, identity management, and resilient operations.
By ensuring robust access management and information security, the standard helps organizations comply with EU obligations, mitigate risks of data breaches, and enable safe sharing of information essential for the circular economy, sustainability, and digital product lifecycle management.
Related Standards
Adherence to EN 18239:2026 should be complemented by related standards to ensure holistic compliance and best practices, including:
EN ISO/IEC 27001
Information security management systems – Requirements
(Covers controls and processes for safeguarding information assets.)EN ISO/IEC 27000
Information security management systems – Vocabulary and overviewISO/IEC 27031
Guidelines for ICT readiness for business continuityEN ISO 22301
Security and resilience – Business continuity management systemsEN 18219
Operator identifiers in digital product passport systems (referenced for unique identification structures)
Aligning with these standards supports organizations in implementing secure, resilient, and efficient Digital Product Passport solutions, fostering trust and transparency throughout the product value chain. For comprehensive compliance, review delegated acts under Regulation (EU) 2024/1781 for product-specific requirements.
Get Certified
Connect with accredited certification bodies for this standard

BSI Group
BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

Bureau Veritas
Bureau Veritas is a world leader in laboratory testing, inspection and certification services.

DNV
DNV is an independent assurance and risk management provider.
Sponsored listings
Frequently Asked Questions
EN 18239:2026 is a standard published by the European Committee for Standardization (CEN). Its full title is "Digital product passport - Access rights management, information system security, and business confidentiality". This standard covers: This document specifies the requirements for digital product passport (DPP) access rights management, including IT security, data protection, and responsibility transfer between economic operators. It defines the framework for managing confidential information access, while acknowledging that public DPP data requires no access restrictions to be read.
This document specifies the requirements for digital product passport (DPP) access rights management, including IT security, data protection, and responsibility transfer between economic operators. It defines the framework for managing confidential information access, while acknowledging that public DPP data requires no access restrictions to be read.
EN 18239:2026 is classified under the following ICS (International Classification for Standards) categories: 13.020.20 - Environmental economics. Sustainability; 35.240.63 - IT applications in trade. The ICS classification helps identify the subject area and facilitates finding related standards.
EN 18239:2026 is associated with the following European legislation: EU Directives/Regulations: 2024/1781, (EU) 2024/1781; Standardization Mandates: M/604, M/604 Amd 1. When a standard is cited in the Official Journal of the European Union, products manufactured in conformity with it benefit from a presumption of conformity with the essential requirements of the corresponding EU directive or regulation.
EN 18239:2026 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.
Standards Content (Sample)
SLOVENSKI STANDARD
01-november-2026
Digitalni potni list izdelka - Upravljanje dostopnih pravic, varnost informacijskega
sistema in poslovna zaupnost
Digital product passport - Access rights management, information system security, and
business confidentiality
Digitaler Produktpass - Management der Benutzerrechte, IT-Sicherheit und
Geschäftsgeheimnisse
Passeport numérique des produits - Gestion des droits d'accès, sécurité du système
d'information et confidentialité des affaires
Ta slovenski standard je istoveten z: EN 18239:2026
ICS:
13.020.20 Okoljska ekonomija. Environmental economics.
Trajnostnost Sustainability
35.240.63 Uporabniške rešitve IT v IT applications in trade
trgovini
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.
EUROPEAN STANDARD EN 18239
NORME EUROPÉENNE
EUROPÄISCHE NORM
September 2026
ICS 13.020.20
English version
Digital product passport - Access rights management,
information system security, and business confidentiality
Passeport numérique des produits - Gestion des droits Digitaler Produktpass - Management der
d'accès, sécurité du système d'information et Benutzerrechte, IT-Sicherheit und
confidentialité des affaires Geschäftsgeheimnisse
This European Standard was approved by CEN on 17 August 2026.
CEN and CENELEC members are bound to comply with the CEN/CENELEC Internal Regulations which stipulate the conditions for
giving this European Standard the status of a national standard without any alteration. Up-to-date lists and bibliographical
references concerning such national standards may be obtained on application to the CEN-CENELEC Management Centre or to
any CEN and CENELEC member.
This European Standard exists in three official versions (English, French, German). A version in any other language made by
translation under the responsibility of a CEN and CENELEC member into its own language and notified to the CEN-CENELEC
Management Centre has the same status as the official versions.
CEN and CENELEC members are the national standards bodies and national electrotechnical committees of Austria, Belgium,
Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Italy,
Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Republic of North Macedonia, Romania, Serbia,
Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye and United Kingdom.
CEN-CENELEC Management Centre:
Rue de la Science 23, B-1040 Brussels
© 2026 CEN/CENELEC All rights of exploitation in any form and by any means
Ref. No. EN 18239:2026 E
reserved worldwide for CEN national Members and for
CENELEC Members.
Contents Page
European foreword . 3
Introduction . 4
1 Scope . 6
2 Normative references . 6
3 Terms and definitions . 6
4 Business transactions and responsibilities related to the DPP . 7
4.1 Business aspects of the DPP life cycle as basis of access management . 7
4.2 Actors along the DPP life cycle . 8
5 Requirements for the protection of business confidentiality and the management of access
rights . 9
5.1 General. 9
5.2 Requirements for the protection of business confidentiality . 9
6 Requirements on system and service resilience . 11
6.1 General requirements . 11
6.2 Access management . 11
6.3 Access revoking policy . 11
6.4 Digital operational resilience . 11
6.4.1 General. 11
6.4.2 Business continuity . 12
6.4.3 Continuous improvement . 12
6.5 Security management . 12
6.5.1 Service availability . 12
6.5.2 Security by design . 12
6.5.3 Incident detection and response . 12
6.5.4 Recovery capability . 12
6.5.5 Continuous improvement . 12
Annex A (informative) Authentication assumptions . 14
Annex ZA (informative) Relationship between this European Standard and the requirements of
Regulation (EU) 2024/1781 aimed to be covered . 15
Bibliography . 16
European foreword
This document (EN 18239:2026) has been prepared by the Joint Technical Committee CEN-CENELEC/
JTC 24 “Digital Product Passport - Framework and System”, the secretariat of which is held by DIN.
This European Standard shall be given the status of a national standard, either by publication of an
identical text or by endorsement, at the latest by March 2027, and conflicting national standards shall be
withdrawn at the latest by March 2027.
Attention is drawn to the possibility that some of the elements of this document may be the subject of
patent rights. CEN-CENELEC shall not be held responsible for identifying any or all such patent rights.
This document has been prepared under a standardization request addressed to CEN-CENELEC by the
European Commission. The Standing Committee of the EFTA States subsequently approves these
requests for its Member States.
For the relationship with EU Legislation, see informative Annex ZA, which is an integral part of this
document.
Any feedback and questions on this document should be directed to the users’ national standards
body/national committee. A complete listing of these bodies can be found on the CEN and CENELEC
websites.
According to the CEN-CENELEC Internal Regulations, the national standards organisations of the
following countries are bound to implement this European Standard: Austria, Belgium, Bulgaria, Croatia,
Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Ireland,
Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Republic of North
Macedonia, Romania, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye and the United
Kingdom.
Introduction
0.1 Background
A digital product passport (DPP) is a key enabling mechanism to make product information traceable and
accessible across value chains – supporting economic operators, manufacturers, distributors, repairers,
recyclers and consumers to make informed decisions and to support a circular economy. The
implementation of DPPs will be carried out progressively. Sector-specific initiatives will determine the
precise DPP content and requirements for individual product groups.
To support the implementation of DPPs, 8 standards have been developed:
— EN 18219:2026 – Digital product passport – Unique identifiers
— EN 18220:2026 – Digital product passport – Data carriers
— EN 18216:2026 – Digital product passport – Data exchange protocols
— EN 18222:2026 – Digital product passport – Application Programming Interfaces (APIs) for the
product passport lifecycle management and searchability
— EN 18223:2026 – Digital product passport – System interoperability
— EN 18221:2026 – Digital product passport – Data storage, archiving, and data persistence
— EN 18239:2026 – Digital product passport – Access rights management, information system security,
and business confidentiality (this document)
— EN 18246:2026 – Digital product passport – Data authentication, reliability and integrity
0.2 Overview
This document aims at harmonizing the identity management that ensures that organisations,
individuals, machines and services are provided with acknowledged identities. This document defines
clear requirements related to access control measures to regulate the access to controlled DPP data.
This document defines rules and requirements related to:
— access right management;
— access control;
— clarification of DPP system roles and responsibilities to provide the means to define mechanisms on
how to exchange access right information between economic operators, back-up system operators
and registry of the regulated market controlling entity;
— measures to regulate the access to controlled DPP data;
— possibility for product group specific definition of access rights by relevant legal acts;
— information system security;
— business confidentiality and their representation in access rights management;
— differentiation of access rights of different user groups and authorities;
— guarantee of IT-security, cybersecurity, and data protection; and
— clarification of DPP system roles and responsibilities to provide the means to define mechanisms on
how to transfer responsibilities, access-rights, and data from one economic operator to another.
EXAMPLE When a DPP will need to be updated to include information related to repair activities performed
by a professional repairer.
1 Scope
This document specifies the requirements for digital product passport (DPP) access rights management,
including IT security, data protection, and responsibility transfer between economic operators. It defines
the framework for managing confidential information access, while acknowledging that public DPP data
requires no access restrictions to be read.
2 Normative references
The following documents are referred to in the text in such a way that some or all of their content
constitutes requirements of this document. For dated references, only the edition cited applies. For
undated references, the latest edition of the referenced document (including any amendments) applies.
EN 18219:2026, Digital product passport — Unique identifiers
3 Terms and definitions
For the purposes of this document, the following terms and definitions apply:
ISO and IEC maintain terminology databases for use in standardization at the following addresses:
— ISO Online browsing platform: available at https://www.iso.org/obp
— IEC Electropedia: available at https://www.electropedia.org/
3.1
controlled DPP data
information on DPP whose access is controlled based on the user’s access rights
Note 1 to entry: User: person who interacts with a system, product or service
[SOURCE: ISO 26800:2011, 2.10, modified – Notes changed]
3.2
system resilience
ability to recover from security compromises or attacks
[SOURCE: ISO/IEC 29180:2012]
3.3
system availability
property of being accessible and usable on demand by an authorized actor
[SOURCE: EN ISO/IEC 27000:2020]
3.4
cyber resilience
ability to maintain business continuity despite adverse conditions, attacks, or compromises on critical
data flow and related information systems
3.5
actor
organization or individual that fulfils a role
[SOURCE: ISO 23234:2021, 3.4]
3.6
notified actor
organization or individual entitled by an authorized accrediting body or authority, that fulfils a role in the
DPP life cycle
3.7
digital product passport
DPP
digital record of product characteristics throughout its life cycle
Note 1 to entry: Example characteristics include environment sustainability, environmental impact and
recyclability.
3.8
non-repudiation
ability to protect against denial by one of the entities involved in an action of having participated in all or
part of the action
[SOURCE: ISO/IEC 29115:2013, 3.19]
3.9
information/communication technology
ICT
technology for gathering, storing, retrieving, processing, analysing and transmitting information
[SOURCE: ISO 9241-20:2021, definition 3.4]
3.10
identity proofing
process by which the registration authority captures and verifies sufficient information to identify an
entity to a specified or understood level of assurance
[SOURCE: ISO/IEC 29115:2013, 3.15]
4 Business transactions and responsibilities related to the DPP
4.1 Business aspects of the DPP life cycle as basis of access management
Access rights management is defined for the different life cycle phases and stages of a DPP. Such phases
and stages are based on EN ISO 11354-1:2011.
In general, not all the phases and the stages mentioned in this document might be applicable to every
product sector. Therefore, only the phases and stages relevant for a specific product group shall be
considered. Moreover, in case a product group specific stage is not represented in the following list, it
shall be considered during the access rights management implementation.
4.2 Actors along the DPP life cycle
This section identifies the main actors who are responsible for the handling of a DPP relevant product
across the value chain and therefore need to access a DPP along its business stages. The identified actors
are the following:
1. Economic operators (in short EOs): role encompassing the manufacturer, the authorized
representative, the importer, the distributor, the dealer and the fulfilment service provider.
a. Manufacturers: any natural or legal person that manufactures a product or that has a product
designed or manufactured and markets that product under their name or trademark.
b. Authorized representatives: any natural or legal person established in the regulated market
that has received a legally binding (e.g. written) mandate from the manufacturer to act on the
manufacturer’s behalf in relation to specified tasks with regard to the manufacturer’s
obligations.
c. Importers: any natural or legal person that places a product coming from outside the regulated
market on the regulated market.
d. Distributors: any natural or legal person in the supply chain, other than the manufacturer or
the importer, that makes a product available on the market.
e. Dealers: a distributor or any other natural or legal person that offers products for sale, hire or
hire purchase, or that displays products to end users in the course of a commercial activity,
including through distance selling; and includes any natural or legal person that puts a product
into service in the course of a commercial activity.
f. Fulfilment service providers: any natural or legal person offering, in the course of commercial
activity, services such as: warehousing, packaging, addressing and dispatching, without having
ownership of the products involved.
2. Other value chain actors
a. Consumers: individual member of the general public purchasing or using goods, property or
services for private purposes [EN ISO 14025:2010, 3.16].
b. Professional repairers: a natural or legal person that provides professional repair or
maintenance services for a product, irrespective of whether that person acts within the
manufacturer’s distribution system or independently.
c. Independent operators: natural or legal person that is independent of the manufacturer and is
directly or indirectly involved in the refurbishment, repair, maintenance or repurposing of a
product, and includes waste management operators, refurbishers, repairers, manufacturers or
distributors of repair equipment, tools or spare parts, as
...



