Battery passport data residency is not a technical detail you can defer to your IT team. Under EU Regulation 2023/1542 (the Battery Regulation), manufacturers placing batteries on the EU market must operate a digital product passport — and the data inside that passport includes commercially sensitive supplier records, chemical composition data, and carbon footprint figures. Where that data is stored, who can access it, and how it is protected are questions you need to answer before you sign a contract with any DPP platform provider.
What the Battery Regulation Says About Passport Data
EU Regulation 2023/1542 establishes the legal framework for battery passports. Article 77 requires that a battery passport be created for each industrial battery, EV battery, and LMT battery with a capacity above 2 kWh, as well as for battery packs. Article 77(3) specifies that the passport must be accessible via a data carrier — typically a QR code — attached to the battery.
Not all data in the passport is public. Article 77(4) draws a clear line between information accessible to any person and information restricted to specific persons with a legitimate interest. Consumers scanning a QR code will see public fields such as battery model, capacity, and recycled content. Restricted fields — which can include detailed supply chain data, test results, and commercially sensitive composition information — are visible only to authorised parties such as economic operators, notified bodies, market surveillance authorities, and the Commission.
The specific data fields required in a battery passport are set out in Annex XIII of the regulation. These cover battery identification, performance and durability parameters, carbon footprint data, material composition, supply chain due diligence information, and end-of-life handling instructions. Many of these fields will contain information your suppliers regard as confidential.
Battery Passport Data Residency: Where Is Your Data Actually Stored?
The Battery Regulation does not specify a single centralised database. Article 77(2) requires that battery passport data be stored in a decentralised way, meaning each economic operator or their chosen platform provider holds the data rather than submitting it to one EU-run repository. A registry system links passport IDs to the data location, but the data itself sits with the operator or their service provider.
This architecture has a direct consequence: the physical and legal location of your data depends entirely on the platform you choose. A provider headquartered in the EU but running infrastructure on servers in the United States, for example, may expose your data to US legal jurisdiction under laws such as the CLOUD Act. A provider using EU-based cloud infrastructure with no data transfers outside the European Economic Area offers a different risk profile.
When evaluating a DPP provider, ask these specific questions:
- In which country or countries are your servers located?
- Do you use sub-processors, and where are those sub-processors based?
- Does any data leave the EEA, and if so, under what legal transfer mechanism (Standard Contractual Clauses, adequacy decision, or other)?
- Are data residency commitments written into the contract, or only described in marketing materials?
These are not hypothetical concerns. Digital product passport data storage decisions made today will govern where your supplier data sits for the operational life of the products you place on the market.
Access Controls for Restricted Fields
Article 77(4) of the Battery Regulation requires that access to restricted passport fields be limited to persons with a legitimate interest. The regulation identifies several categories: economic operators in the supply chain, notified bodies, market surveillance authorities, and the European Commission. Your DPP platform must be able to enforce these distinctions technically, not just as a policy statement.
In practice, this means your platform provider needs role-based access controls that map to the categories defined in the regulation. A supplier uploading composition data should not be able to view another supplier’s data. A market surveillance authority requesting access should be able to retrieve restricted fields without requiring you to manually export and send files. A consumer scanning a QR code should see only the public fields.
Ask any prospective provider to demonstrate how their system enforces these access tiers. Request documentation of their access control architecture. If they cannot show you a clear technical implementation, that is a gap in their compliance readiness — and potentially in yours, since you as the manufacturer remain the responsible economic operator under Article 38 of the Battery Regulation.
DPP data security also extends to audit logging. You should be able to produce a record of who accessed which fields and when, particularly for restricted data. This is relevant both for regulatory accountability and for your own internal governance.
GDPR Obligations and Battery Passport Data
GDPR obligations can apply where a digital product passport processes personal data. This is more common than it might appear. Supplier records often include named contact persons with email addresses and phone numbers. Manufacturer records may reference individual employees. If any of these details are stored in passport fields, GDPR applies to that processing.
Under GDPR Article 4(7), the manufacturer operating the passport is likely to be the data controller for personal data processed in connection with the passport. The DPP platform provider is likely to be a data processor under Article 4(8). This means you need a Data Processing Agreement (DPA) with your platform provider, as required by GDPR Article 28.
The DPA must specify, among other things: the subject matter and duration of processing, the nature and purpose of processing, the type of personal data involved, the categories of data subjects, and the obligations and rights of the controller. If your provider cannot supply a compliant DPA, you are exposed under GDPR regardless of your Battery Regulation compliance status.
Data subject rights under GDPR Articles 15–22 also apply. If a named individual in a supplier record submits a Subject Access Request or a deletion request, you need a process to handle it — and your platform provider needs to support that process technically. Confirm before you sign that the provider can execute deletion and data portability requests within the timeframes GDPR requires (one month under Article 12(3), extendable by two further months in complex cases).
For a detailed breakdown of how GDPR intersects with digital product passport obligations, see Traceable’s GDPR and Digital Product Passports data protection guide.
What to Check When Evaluating a DPP Provider
Manufacturers should confirm four things before committing to a digital product passport platform for battery compliance.
- Data storage location. Confirm the country and legal jurisdiction of all servers and sub-processors. Get this in writing in the contract, not just in a FAQ.
- Access control implementation. Verify that the platform technically enforces the public/restricted field distinction required by Article 77(4), with role-based permissions mapped to the legitimate interest categories in the regulation.
- GDPR documentation. Obtain a signed Data Processing Agreement compliant with GDPR Article 28 before any personal data is transferred to the platform.
- Deletion and portability support. Confirm the provider can execute data deletion and export requests within GDPR timelines, and that this process does not require manual intervention on their part that could cause delays.
These checks apply regardless of which platform you use. They are due diligence steps, not optional extras.
Battery Passport Timelines and What They Mean for Data Decisions
The Battery Regulation entered into force on 17 August 2023. Battery passport requirements under Article 77 apply to industrial batteries, EV batteries, and LMT batteries with a capacity above 2 kWh. The specific application date for battery passports is expected around 2027, pending adoption of the relevant delegated acts by the European Commission — this date is not yet confirmed in the regulation itself.
This means manufacturers have time to make considered decisions about platform selection. But data residency and security decisions are not ones you want to reverse mid-operation. Migrating battery passport data from one provider to another after go-live carries compliance risk: passport IDs are registered in the EU registry system, and any migration must preserve the link between the ID and the data location without creating gaps in accessibility.
Choose a provider whose data residency commitments, security architecture, and GDPR documentation you can verify now — before you are under pressure to go live.
Security Certifications and Independent Verification
Policy statements about security are not the same as verified security. When evaluating a DPP provider, look for independent certification. ISO 27001 is the internationally recognised standard for information security management systems. SOC 2 Type II reports provide independent auditor verification of security, availability, and confidentiality controls over a defined period.
Ask whether the provider holds current ISO 27001 certification and whether they can share a recent SOC 2 Type II report. If they hold neither, ask what independent verification of their security controls exists. A provider that cannot answer this question clearly is not ready to hold commercially sensitive battery supply chain data on your behalf.
You can review the security and compliance documentation for Traceable’s platform on Traceable’s Trust & Security page.
Practical Next Steps
Battery passport data residency decisions are operational decisions with legal consequences. The Battery Regulation sets the data requirements. GDPR sets the personal data obligations. Your contract with a DPP provider determines whether those obligations are met in practice.
Before selecting a provider: confirm server locations in writing, review the access control architecture against Article 77(4) requirements, obtain a GDPR Article 28 compliant DPA, and verify independent security certification. These steps take time. Start them before the delegated acts confirm the go-live date, not after.
If you are ready to evaluate a platform that publishes its security documentation and offers contractual data residency commitments, visit traceable.digital/pricing to start a free trial and speak with the compliance team about your specific requirements.