Digital Product Passport - access rights management, information system security, and business confidentiality

This document specifies the requirements for Digital Product Passport (DPP) access rights management, including IT security, data protection, and responsibility transfer between economic operators. It defines the framework for managing confidential information access, while acknowledging that public DPP data requires no access restrictions. The document applies to all product groups subject to DPP requirements under Regulation (EU) 2024/1781, with specific access rights to be detailed in respective delegated acts.

Digitaler Produktpass - Management der Benutzerrechte, IT-Sicherheit und Geschäftsgeheimnisse

Dieses Dokument legt die Anforderungen an die Zugangsrechteverwaltung des Digitalen Produktpasses (DPP) fest. Dazu gehören die IT Sicherheit, der Datenschutz und die Übertragung der Verantwortlichkeiten von einem Wirtschaftsteilnehmer an einen anderen. Es definiert das Rahmenwerk für die Zugangsverwaltung von vertraulichen Informationen und berücksichtigt dabei, dass öffentliche DPP Daten keine Zugangsbeschränkungen erfordern. Das Dokument gilt für alle Produktgruppen, die den DPP Anforderungen nach Verordnung (EU) 2024/1781 unterliegen, wobei die spezifischen Zugangsrechte in den jeweiligen delegierten Rechtsakten aufzuführen sind.

Passeport numérique des produits - Gestion des droits d'accès, sécurité du système d'information et confidentialité des affaires

Digitalni potni list izdelka - Upravljanje dostopnih pravic, varnost informacijskega sistema in poslovna zaupnost

General Information

Status
Not Published
Publication Date
01-Sep-2026
Drafting Committee
WG 3 - Security
Current Stage
4060 - Closure of enquiry - Enquiry
Start Date
23-Oct-2025
Due Date
24-Dec-2025
Completion Date
23-Oct-2025

Overview

prEN 18239 (Draft) defines a framework for Digital Product Passport (DPP) access rights management, information system security, and business confidentiality. Developed by CEN/CLC JTC 24, it applies to all product groups subject to DPP obligations under Regulation (EU) 2024/1781. The standard harmonizes identity management, access control, data protection, and responsibility transfer between economic operators while recognising that public DPP data requires no access restrictions.

Key Topics

  • Access rights management: Rules for granting, delegating and revoking access to controlled DPP data, including role-based access and product-group specific rights defined in delegated acts.
  • Identity and authentication: Requirement for globally unique operator identifiers (see prEN 18219) and non-repudiable authentication to ensure accountability and trust.
  • Business confidentiality: Mechanisms to represent confidential business information within DPP access models while allowing public data to remain open.
  • Information system security & cybersecurity: Security-by-design, detect-and-respond capabilities, service availability, and recovery measures to protect DPP services.
  • System resilience and continuity: Requirements referencing RTO/RPO and business continuity principles to ensure cyber resilience and recovery after incidents.
  • Responsibility transfer: Procedures to transfer responsibilities, access rights and data between economic operators (e.g., when ownership or service providers change).
  • Stakeholders & roles: Definitions for economic operators (manufacturers, importers, distributors, fulfilment providers), notified actors, service providers (main and back-up DPP providers), repairers, recyclers, market surveillance and customs authorities.
  • Interoperability & exchanges: Exchange of access-right information between economic operators, backup system operators and the European Commission registry.

Applications

Who uses this standard and why:

  • Manufacturers & importers implementing DPP compliance under Regulation (EU) 2024/1781.
  • DPP service providers (main and back-up) designing secure platforms for publishing and controlling DPP data.
  • IT/security teams applying information security, identity management and cyber resilience practices for product-data systems.
  • Supply‑chain actors (repairers, recyclers, distributors) who need controlled access to DPP controlled data.
  • Regulators & market surveillance authorities auditing access controls and confidentiality safeguards.

Practical benefits include consistent access control across the product lifecycle, improved accountability via unique operator identifiers, and enhanced resilience and confidentiality for commercially sensitive product information.

Related Standards (if applicable)

  • EN ISO 22301:2019 (Business continuity management)
  • EN ISO/IEC 27000:2020 and EN ISO/IEC 27001:2023 (Information security management)
  • ISO/IEC 27031:2025 (ICT readiness for business continuity)
  • prEN 18219 (Globally unique operator identifiers) and prEN 18221 (DPP backup provisions)

Keywords: Digital Product Passport, DPP, access rights management, information system security, business confidentiality, Regulation (EU) 2024/1781, cybersecurity, globally unique operator identifier.

Frequently Asked Questions

prEN 18239 is a draft published by the European Committee for Standardization (CEN). Its full title is "Digital Product Passport - access rights management, information system security, and business confidentiality". This standard covers: This document specifies the requirements for Digital Product Passport (DPP) access rights management, including IT security, data protection, and responsibility transfer between economic operators. It defines the framework for managing confidential information access, while acknowledging that public DPP data requires no access restrictions. The document applies to all product groups subject to DPP requirements under Regulation (EU) 2024/1781, with specific access rights to be detailed in respective delegated acts.

This document specifies the requirements for Digital Product Passport (DPP) access rights management, including IT security, data protection, and responsibility transfer between economic operators. It defines the framework for managing confidential information access, while acknowledging that public DPP data requires no access restrictions. The document applies to all product groups subject to DPP requirements under Regulation (EU) 2024/1781, with specific access rights to be detailed in respective delegated acts.

prEN 18239 is classified under the following ICS (International Classification for Standards) categories: 13.020.20 - Environmental economics. Sustainability; 35.240.63 - IT applications in trade. The ICS classification helps identify the subject area and facilitates finding related standards.

prEN 18239 is associated with the following European legislation: Standardization Mandates: M/604, M/604 AMD 1. When a standard is cited in the Official Journal of the European Union, products manufactured in conformity with it benefit from a presumption of conformity with the essential requirements of the corresponding EU directive or regulation.

You can purchase prEN 18239 directly from iTeh Standards. The document is available in PDF format and is delivered instantly after payment. Add the standard to your cart and complete the secure checkout process. iTeh Standards is an authorized distributor of CEN standards.

Standards Content (Sample)


SLOVENSKI STANDARD
01-september-2025
Digitalni potni list za proizvode - Upravljanje dostopnih pravic, varnost
informacijskega sistema in poslovna zaupnost
Digital Product Passport - access rights management, information system security, and
business confidentiality
Digitaler Produktpass - Management der Benutzerrechte, IT-Sicherheit und
Geschäftsgeheimnisse
Passeport numérique des produits - Gestion des droits d'accès, sécurité du système
d'information et confidentialité des affaires
Ta slovenski standard je istoveten z: prEN 18239
ICS:
13.020.20 Okoljska ekonomija. Environmental economics.
Trajnostnost Sustainability
35.240.63 Uporabniške rešitve IT v IT applications in trade
trgovini
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.

EUROPEAN STANDARD DRAFT
NORME EUROPÉENNE
EUROPÄISCHE NORM
July 2025
ICS 13.020.20; 35.240.63
English version
Digital Product Passport - access rights management,
information system security, and business confidentiality
Passeports numériques de produit - Gestion des droits Digitaler Produktpass - Management der
d'accès, sécurité des systèmes d'information et Benutzerrechte, IT-Sicherheit und
confidentialité des affaires Geschäftsgeheimnisse
This draft European Standard is submitted to CEN members for enquiry. It has been drawn up by the Technical Committee
CEN/CLC/JTC 24.
If this draft becomes a European Standard, CEN and CENELEC members are bound to comply with the CEN/CENELEC Internal
Regulations which stipulate the conditions for giving this European Standard the status of a national standard without any
alteration.
This draft European Standard was established by CEN and CENELEC in three official versions (English, French, German). A
version in any other language made by translation under the responsibility of a CEN and CENELEC member into its own language
and notified to the CEN-CENELEC Management Centre has the same status as the official versions.

CEN and CENELEC members are the national standards bodies and national electrotechnical committees of Austria, Belgium,
Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Italy,
Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Republic of North Macedonia, Romania, Serbia,
Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye and United Kingdom.

Recipients of this draft are invited to submit, with their comments, notification of any relevant patent rights of which they are
aware and to provide supporting documentation.Recipients of this draft are invited to submit, with their comments, notification
of any relevant patent rights of which they are aware and to provide supporting documentation.

Warning : This document is not a European Standard. It is distributed for review and comments. It is subject to change without
notice and shall not be referred to as a European Standard.

Contents Page
European foreword . 3
Introduction . 4
1 Scope . 5
2 Normative references . 5
3 Terms and definitions . 5
4 Business transactions and responsibilities related to the DPP . 6
4.1 Business aspects of the DPP lifecycle as basis of access management . 6
4.2 Stakeholders along the DPP lifecycle. 7
5 Functional Requirements for business confidentiality and access rights requirements . 8
5.1 General. 8
5.2 Functional requirements for business confidentiality . 8
6 Requirements on system and service resilience . 10
6.1 General requirements . 10
6.2 Access management . 10
6.3 Access revoking mechanism . 10
6.4 Digital operational resilience . 10
6.4.1 Business continuity . 10
6.4.2 Continuous improvement . 11
6.5 Security management . 11
6.5.1 Service availability . 11
6.5.2 Security by design . 11
6.5.3 Detect and response. 12
6.5.4 Recovery capability . 12
Annex A (informative) Basis for business phases . 13
Bibliography . 17

European foreword
This document (prEN 18239:2025) has been prepared by Technical Committee CEN/CLC JTC 24 “Digital
Product Passport - Framework and System”, the secretariat of which is held by DIN.
This document is currently submitted to the CEN Enquiry.
This document has been prepared under a standardization request addressed to CEN by the European
Commission. The Standing Committee of the EFTA States subsequently approves these requests for its
Member States.
Introduction
This document aims at harmonizing the identity management that ensures that organisations,
individuals, machines and services are provided with acknowledged identities. This document defines
clear rules and requirements related to access control measures to regulate the access to restricted
product passport information.
This document defines rules and requirements related to:
— access right management;
— access control;
— exchange of access right information between economic operators, back-up system operators and
registry of the European Commission;
— measures to regulate the access to restricted product passport information;
— possibility for product group specific definition of access rights by delegated acts;
— requirement on information system security;
— requirements on business confidentiality and their representation in access rights management;
— differentiate access rights of different user groups and authorities;
— rules to guarantee IT-security, cybersecurity, and data protection; and
— mechanism on how to transfer responsibilities, access-rights, and data from one economic operator
to another.
EXAMPLE When a DPP will need to be updated to include information related to repair activities performed
by a professional repairer.
1 Scope
This document specifies the requirements for Digital Product Passport (DPP) access rights management,
including IT security, data protection, and responsibility transfer between economic operators. It defines
the framework for managing confidential information access, while acknowledging that public DPP data
requires no access restrictions. The document applies to all product groups subject to DPP requirements
under Regulation (EU) 2024/1781, with specific access rights to be detailed in respective delegated acts.
2 Normative references
The following documents are referred to in the text in such a way that some or all of their content
constitutes requirements of this document. For dated references, only the edition cited applies. For
undated references, the latest edition of the referenced document (including any amendments) applies.
EN ISO 22301:2019 , Security and resilience — Business continuity management systems — Requirements
(ISO 22301:2019)
EN ISO/IEC 27000:2020, Information technology — Security techniques — Information security
management systems — Overview and vocabulary (ISO/IEC 27000:2018)
EN ISO/IEC 27001:2023, Information security, cybersecurity and privacy protection — Information
security management systems — Requirements (ISO/IEC 27001:2022)
ISO/IEC 27031:2025, Cybersecurity — Information and communication technology readiness for business
continuity
3 Terms and definitions
For the purposes of this document, the following terms and definitions apply:
ISO and IEC maintain terminology databases for use in standardization at the following addresses:
— ISO Online browsing platform: available at https://www.iso.org/obp
— IEC Electropedia: available at https://www.electropedia.org/
3.1
controlled DPP data
information on digital product passport whose access is controlled based on the user's access rights
Note 1 to entry: User: person who interacts with a system, product or service [SOURCE: ISO 26800:2011, 2.10;
modified, Notes changed]
3.2
system resilience
ability to recover from security compromises or attacks
[SOURCE: ISO/IEC 29180:2012]
3.3
system availability
property of being accessible and usable on demand by an authorized entity

As impacted by EN ISO 22301:2019/A1:2024.
[SOURCE: EN ISO/IEC 27000:2020]
3.4
cyber resilience
ability to maintain business continuity despite adverse conditions, attacks, or compromises on critical
data flow and related information systems
3.5
RPO
recovery point objective
point in time to which data must be recovered after a disruption has occurred
[SOURCE: ISO/IEC 27031:2025, 3.12]
3.6
RTO
Recovery Time Objective
period of time within which minimum levels of services and/or products and the supporting systems,
applications, or functions must be recovered after a disruption has occurred
[SOURCE: ISO/IEC 27031:2025]
3.7
actor
organization or individual that fulfils a role
[SOURCE: ISO 23234:2021, 3.4]
3.8
notified actor
organization or individual entitled by an authorized accrediting body or authority, that fulfils a role in the
DPP lifecycle
3.9
digital product passport
DPP
digital record of product characteristics throughout its life cycle
Note 1 to entry: Example characteristics include environment sustainability, environmental impact and
recyclability
4 Business transactions and responsibilities related to the DPP
4.1 Business aspects of the DPP lifecycle as basis of access management
Based and informed by EN ISO 11354-1:2011, understanding product lifecycle phases and stages,
stakeholders along the product life cycle, as well as relevant business transactions occurring in this
lifecycle, is indispensable to defining the relevant business responsibility and access management
requirements along the lifecycle stages of Digital Product Passports. The lifecycle phases and stages are
outlined in Annex A.
In general, not all the phases and the stages mentioned in this document might be applicable to every
product sector. Therefore, only the phases and stages relevant for a specific product group shall be
considered. Moreover, in case a product group specific stage is not represented in the following list, it
should be added where relevant.
4.2 Stakeholders along the DPP lifecycle
This section identifies the main stakeholders who are responsible for the handling of a DPP relevant
product across the value chain and therefore need to access a DPP along its business stages. The identified
stakeholders are the following:
1. Economic operators (in short EO): a top-level role encompassing the manufacturer, the authorized
representative, the importer, the distributor, the dealer and the fulfilment service provider.
a. Manufacturers: any natural or legal person that manufactures a product or that has a product
designed or manufactured and markets that product under their name or trademark.
b. Authorized representatives (of non-EU companies in the EU market): any natural or legal
person established in the Union that has received a written mandate from the manufacturer to
act on the manufacturer’s behalf in relation to specified tasks with regard to the manufacturer’s
obligations.
c. Importers: any natural or legal person established in the Union that places a product from a
third country on the Union market.
d. Distributors: any natural or legal person in the supply chain, other than the manufacturer or
the importer, that makes a product available on the market.
e. Dealers: a distributor or any other natural or legal person that offers products for sale, hire or
hire purchase, or that displays products, to end users in the course of a commercial activity,
including through distance selling; and includes any natural or legal person that puts a product
into service in the course of a commercial activity.
f. Fulfilment service providers: any natural or legal person offering, in the course of commercial
activity, at least two of the following services: warehousing, packaging, addressing and
dispatching, without having ownership of the products involved, excluding postal services,
parcel delivery services, and any other postal services or freight transport services.
2. Other value chain actors
a. Customers: a natural or legal person that purchases, hires or receives a product for their own
use whether or not acting for purposes which are outside their trade, business, craft or
profession.
b. Professional repairers: a natural or legal person that provides professional repair or
maintenance services for a product, irrespective of whether that person acts within the
manufacturer’s distribution system or independently.
c. Independent operators: means a natural or legal person that is independent of the
manufacturer and is directly or indirectly involved in the refurbishment, repair, maintenance or
repurposing of a product, and includes waste management operators, refurbishers, repairers,
manufacturers or distributors of repair equipment, tools or spare parts, as well as publishers of
technical information, operators offering inspection and testing services and operators offering
training for installers, manufacturers and repairers of equipment.
d. Recycler: any natural or legal person who is responsible for the collection, processing and
recovery of reusable materials and who applies a decontamination process.
e. Market surveillance authority: an authority designated by a Member State as responsible for
carrying out market surveillance in the territory of that Member State.
3. Customs authorities: customs authorities as defined in point 1 of Article 5 of Regulation (EU) No
952/2013.
4. Service provider: any natural or legal person providing an information service.
a. Digital product passport service provider (main or back-up): a natural or legal person that is
an independent third-party authorized by the economic operator which places the product on
the market or puts it into service and that processes the digital product passport data for that
product for the purpose of making such data available to economic operators and other relevant
actors with a right to access those data.
1. Back-up digital product passport service provider as “digital product passport service
provider that is hosting the back-up copy of the digital product passport” [prEN 18221].
5. Parties not defined by the ESPR: Such as for example system administrators or non-EU state
bodies.
5 Functional Requirements for business confidentiality and access rights
requirements
5.1 General
Based on the product lifecycle as per Annex A and the different business roles along this lifecycle
[Clause 4.2] the following axioms for DPP access rights management, information system security and
business confidentiality can be distilled.
5.2 Functional requirements for business confidentiality
1. Actors in a DPP system need to have globally unique operator identifiers, as defined in prEN 18219.
2. Access to public data shall be possible for EU and non-EU actors without additional authentication.
3. Access to DPP controlled data and its management shall be possible for EU and non-EU actors.
4. Obtaining a globally unique operator identifier shall be possible outside of the EU for non-EU actors.
5. Authentication of actors accessing or managing controlled DPP data shall allow for accountability
and be non-refutable.
6. It shall be possible to verify the authenticity of a globally unique operator identifier (“trust”).
7. Each Economic Operator may assign, based on a globally unique operator identifier, certain rights
and roles to any notified actor that wishes to access its Digital Product Passport controlled data
provided that the requesting notified actor fulfils the legal requirements.
8. Base roles (for instance “recycler” or “refurbisher”) which grant access to DPP’s controlled data will
be defined by the delegated acts. The Economic Operators can however create additional roles.
9. Globally unique operator identifiers of notified actors fulfilling state or official base roles need to be
attached to a system, which allows them to carry trustworthy credentials, allowing for access to
controlled data without the need of individual Economic Operator’s explicit approval.
10. For actors fulfilling additional roles not regulated but defined by the Economic Operator, the
Economic Operator can decide which authentication mechanism to apply.
11. As roles can evolve over time, access rights shall be defined at property level and defined through
controlled vocabularies.
12. Search functionalities in EU registries and DPP services shall be limited in such a way as to prevent
mass data scraping. Technical solutions providing exceptions for actor
...

Questions, Comments and Discussion

Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.

Loading comments...

표준 문서 prEN 18239에 대한 리뷰는 다음과 같습니다. 이 표준은 디지털 제품 여권(Digital Product Passport, DPP)의 접근 권한 관리, 정보 시스템 보안, 그리고 비즈니스 기밀성을 다루는 매우 중요한 문서입니다. 문서의 범위는 DPP에 관한 접근 권한 관리의 요구 사항을 명확히 정의하여, IT 보안, 데이터 보호, 경제 운영자 간의 책임 이전 등의 중요한 요소를 포함합니다. 표준의 강점 중 하나는 기밀 정보 접근 관리 프레임워크를 체계적으로 설정한 점입니다. 이는 우리가 데이터 보호와 보안성을 명확하게 이해하고 관리할 수 있도록 해 주며, 특히 민감한 정보가 다루어질 때 필요한 규정을 제공합니다. 또한, 공개 DPP 데이터는 접근 제한이 없음을 인정하여, 사용자가 필요한 정보를 보다 쉽게 얻을 수 있도록 하고 있습니다. 이 표준은 EU 규정(2024/1781)에 따라 DPP 요구 사항이 적용되는 모든 제품군에 적용되며, 각 위임 법령에서 구체적인 접근 권한이 정의될 것을 명시하고 있습니다. 이러한 점은 DPP의 일관성을 높이고, 경제 운영자들이 책임을 명확히 할 수 있도록 도와줍니다. prEN 18239는 디지털 제품 여권 시스템 내에서 정보 보호 및 접근 권한의 중요성을 강조하며, 이는 현재의 비즈니스 환경에서 절대적으로 필요한 요소입니다. 전반적으로 이 표준은 디지털 제품 여권의 신뢰성 및 안전성을 확보하기 위한 필수 문서로, 관련 분야의 전문가들에게 큰 도움이 될 것입니다.

標準化文書「oSIST prEN 18239:2025」は、デジタル製品パスポート(DPP)のアクセス権管理に関する要求事項を詳細に定義しています。この文書は、ITセキュリティ、データ保護、および経済運営者間の責任移転を含む幅広い範囲にわたっており、デジタル環境において非常に重要な役割を果たします。 この標準の強みは、機密情報へのアクセス管理のフレームワークを明確に定めている点です。これにより、製品データが商業機密と公共データの間で適切に扱われることが保障されます。具体的には、EU規則2024/1781の下でのDPP要件に従ったすべての製品グループに適用され、関連する委任行為において特定のアクセス権が詳細に記載されることが求められます。 さらに、公共のDPPデータにはアクセス制限が不要であることを認めており、情報の透明性と流通を促進しています。このことは、業界における信頼性の向上とともに、消費者への情報提供を強化し、デジタル製品パスポートの意義をより一層高めています。 総じて、この「oSIST prEN 18239:2025」標準は、デジタル製品パスポートのアクセス権管理や情報システムのセキュリティに関する指針を提供し、経済活動における信頼と効率性を確保するための基盤として非常に重要です。

La norme prEN 18239, intitulée "Digital Product Passport - gestion des droits d'accès, sécurité des systèmes d'information et confidentialité des affaires", établit un cadre essentiel pour la gestion des droits d'accès au Passeport Numérique des Produits (DPP). Elle s'applique à tous les groupes de produits soumis aux exigences du DPP conformément au règlement (UE) 2024/1781, ce qui en fait un instrument crucial pour toutes les parties prenantes dans l'économie numérique. L’un des principaux atouts de cette norme est sa prise en compte des enjeux de sécurité informatique et de protection des données. En définissant clairement les exigences pour la gestion des droits d'accès, elle aide les opérateurs économiques à transférer de manière responsable les informations confidentielles tout en protégeant les données sensibles. Cela permet non seulement de sécuriser les informations, mais également d’établir un climat de confiance entre les différents acteurs impliqués. De plus, la norme prEN 18239 reconnaît que les données publiques du DPP ne nécessitent pas de restrictions d'accès, ce qui est particulièrement pertinent dans le contexte actuel où la transparence et l'accès à l'information sont de plus en plus valorisés. Cela permet un équilibre entre la protection des données sensibles et la nécessité d'offrir une accessibilité aux informations publiques. En termes de pertinence, la norme répond à un besoin croissant d'harmonisation dans la gestion de l'accès aux informations produit dans un cadre réglementaire complexe. Grâce à ses spécifications claires, elle est adaptée aux exigences variées des différents secteurs économiques sans compromettre les obligations de sécurité, de confidentialité et de protection des données. En synthèse, prEN 18239 représente une avancée significative vers une gestion systématique et sécurisée des droits d'accès dans le cadre du Passeport Numérique des Produits, renforçant ainsi la confiance des utilisateurs et des opérateurs économiques.

The standard prEN 18239, titled "Digital Product Passport - access rights management, information system security, and business confidentiality," provides a comprehensive framework for managing access rights associated with Digital Product Passports (DPP). The scope of this standard is notably relevant as it outlines critical requirements for access rights management, particularly in the context of IT security and data protection. One of the significant strengths of prEN 18239 is its emphasis on the transfer of responsibility between economic operators, ensuring that all parties involved in the DPP framework understand their obligations concerning access and confidentiality. This clarity is vital for promoting accountability and fostering trust among various stakeholders in the supply chain. Additionally, the standard recognizes the dual nature of DPP data, distinguishing between confidential and publicly accessible information. By explicitly stating that public DPP data does not require access restrictions, the document effectively simplifies data management processes for economic operators while still maintaining a robust approach to information security for sensitive data. Furthermore, prEN 18239 supports a wide range of product groups that fall under the DPP requirements as stipulated by Regulation (EU) 2024/1781. This inclusivity broadens the standard's applicability, making it an essential tool for businesses navigating the complexities of compliance with EU regulations. The detailed access rights will be outlined in subsequent delegated acts, ensuring that the standard remains adaptable to evolving regulatory landscapes and market needs. Overall, the prEN 18239 standard is a strong and relevant framework for managing DPP access rights, underpinned by principles of security, data protection, and confidentiality. Its focus on responsibility transfer and the clear delineation of public versus confidential data management significantly enhances its utility for economic operators engaged in DPP initiatives.

Die Norm prEN 18239 behandelt das Thema des Digital Product Passport (DPP) und legt die Anforderungen an das Management von Zugriffsrechten im Zusammenhang mit IT-Sicherheit, Datenschutz und der Übertragung von Verantwortlichkeiten zwischen wirtschaftlichen Akteuren fest. Die Norm definiert ein umfassendes Rahmenwerk, das es ermöglicht, den Zugang zu vertraulichen Informationen effektiv zu verwalten. Die Berücksichtigung der öffentlichen DPP-Daten, die keine Zugangsbeschränkungen benötigen, zeigt die Balance zwischen Sicherheit und Transparenz. Ein wesentlicher Stärke der Norm prEN 18239 ist ihre breite Anwendbarkeit auf alle Produktgruppen, die den Anforderungen des DPP gemäß der Verordnung (EU) 2024/1781 unterliegen. Dies gewährleistet eine einheitliche Handhabung der Zugriffsrechte über verschiedene Sektoren hinweg und unterstützt Unternehmen dabei, ihre Geschäftsprozesse in Übereinstimmung mit den aktuellen gesetzlichen Vorgaben zu gestalten. Zusätzlich bietet die Norm konkrete Vorgaben, die in den jeweiligen delegierten Rechtsakten ausgeführt werden. Diese klaren Richtlinien ermöglichen es den wirtschaftlichen Akteuren, ihre Verantwortung effektiv zu übertragen und gleichzeitig die Sicherstellung von Datenschutz und IT-Sicherheit zu gewährleisten. Die Relevanz der Norm prEN 18239 ist unbestreitbar, insbesondere im Kontext der fortschreitenden Digitalisierung und der Notwendigkeit, Sicherheitsstandards für digitale Produkte zu implementieren. Insgesamt stellt die prEN 18239 eine wegweisende Norm dar, die nicht nur den Umgang mit digitalen Produktpässen regelt, sondern auch einen Beitrag zur standardisierten Handhabung von Zugriffsrechten im digitalen Zeitalter leistet.