Battery passport implementation is not a QR-label project. For batteries placed on the EU market, the responsible economic operator must combine scope decisions, ownership of 71 data points, PLM/MES/QMS/BMS/ERP integration, controlled access, updates and audit evidence into one operating model. This guide focuses on EV, LMT and industrial batteries above 2 kWh made in Thailand or ASEAN and turns the requirements into an RFP and acceptance plan.
Executive answer: assign responsibility and update paths before collecting data
From 18 February 2027, every EV battery, every light means of transport (LMT) battery and every industrial battery with a capacity greater than 2 kWh that is placed on the EU market or put into service must have an electronic battery passport. The economic operator placing the finished battery on the market must ensure that the passport information is accurate, complete and up to date. Work may be delegated, but signing a DPP platform contract does not automatically transfer this responsibility.
A workable programme makes seven decisions early:
- Confirm the battery category, responsible economic operator, model boundary and individual-unit boundary.
- Convert the 71 data points into an owner/source/frequency/access class/validation matrix.
- Separate common model data from individual status, event and usage time-series data.
- Separate public, legitimate-interest and authority/Commission access.
- Keep the QR carrier, unique identifier, DPP Registry record and detailed DPP data store distinct.
- Create a new passport after repurposing or remanufacturing and link it to the original passport or passports.
- Contract not only functions, but also FAT/SAT evidence, continuity and regulatory-change responsibilities.
The European Commission guidance published on 21 August 2026 organises 71 data points as mandatory, optional, conditional or not required to be completed or displayed as of February 2027. The guidance also says that it creates no additional legal requirements and is not an authoritative interpretation. Final decisions for a product must be checked against Regulation (EU) 2023/1542, the delegated and implementing acts applicable at the time, relevant standards, contracts and qualified advisers. This article is an implementation and procurement guide, not legal advice.
Determine the battery passport implementation scope first
Do not classify an entire company as “in scope” merely because it handles batteries. Decide by product model, category, capacity, use, EU placing-on-the-market route and the role of each economic operator.
| Decision axis | What to confirm | Evidence example | Implementation impact |
|---|---|---|---|
| Battery category | EV, LMT or industrial | Specification, intended use, type documents | Changes data-point applicability |
| Capacity | For industrial batteries, is it greater than 2 kWh? | Rated specification, product BOM | Prevents confusion between “greater than” and “at least” |
| EU relationship | Placed on the EU market or put into service? | Sales contract, Incoterms, importer data | Affects responsible party and timing |
| Finished battery | Cell/module component or finished battery? | Product structure, packaging, label | Separates upstream supplier from finished-product operator |
| Economic operator | Who places the finished battery on the market? | Trade flow, contracts, EU entity/importer | Identifies the Article 77(4) responsibility candidate |
| Lifecycle state | Original, re-used, repurposed, remanufactured or another state? | Work order, ownership and re-market record | Determines whether a new passport and lineage are needed |
Do not confuse EV, LMT and industrial batteries above 2 kWh
EV batteries are used in electric vehicles. LMT batteries cover light means of transport such as e-bikes, e-mopeds and e-scooters. Industrial batteries can include batteries for industrial equipment, communications, agriculture, energy generation and distribution, stationary storage and other uses defined by the Regulation. Use the legal definitions rather than a commercial nickname. For an industrial battery, the passport threshold is greater than 2 kWh, not “2 kWh or more.”
Trace the commercial chain even when the Thai plant does not sell directly to the EU
A Thai factory may ship a finished battery to an EU importer, supply it as an OEM product to a brand owner, or embed it in equipment sold into the EU. These routes can assign different roles. A cell supplier may provide essential composition and due-diligence data without becoming the responsible operator for the finished-battery passport. Conversely, the responsible operator cannot create upstream material composition, carbon-footprint, recycled-content or due-diligence evidence alone. Draw four types of arrows in the trade map: legal responsibility, data supply, system operation and approval.
Required output of the scope exercise
Before a PoC, create a scope register covering model, category, capacity, use, EU market route, candidate responsible operator, applicable data points, evidence URL or document, reviewer and review date. When a decision changes, the register must show which passport, label, contract and acceptance test is affected.

Responsibility under the EU Batteries Regulation 2027 requirement
Article 77(4) requires the economic operator placing the battery on the market to ensure that passport information is accurate, complete and up to date. Another operator can be authorised in writing to act on its behalf, but “our DPP SaaS provider handles compliance” is not an adequate responsibility model. Build a RACI by data-point group.
| Role | Main responsibility | Typical inputs | Approval and evidence |
|---|---|---|---|
| EU placing-on-market owner | Scope, final approval, registration, continuity | All systems and suppliers | Passport release and change approval |
| Engineering / PLM | Model, chemistry, ratings, BOM | Released BOM, specifications, change number | Design release and version history |
| Manufacturing / MES | Unit ID, lot, process and inspection genealogy | Execution, equipment, timestamps | Trace chain and rework record |
| Quality / QMS | Tests, conformity, deviations and CAPA | Inspection and audit records | Conformity decision and signature |
| BMS / connected product | Status, cycles, temperature, SOC and events | Unit time series and event data | Timestamp, quality and missing-data flags |
| ERP / supply chain | Economic operator, supplier, sales and shipment | Partners, orders and shipments | Trade flow and shipment hold |
| Sustainability / compliance | Footprint, due diligence and recycled content | Verification and declarations | Period, basis and approval |
| DPP service / IT | IDs, API, access, availability and audit | Synchronised source data | Logs, backup and recovery |
The RACI must state not only who enters a value, but who owns the evidence, approves changes, detects expiry and can suspend publication or shipment. A multinational arrangement may have a headquarters compliance owner, a Thailand plant data owner and an EU importer as registration owner. Use named organisational roles so the control survives personnel changes.
Turn the 71 battery passport data points into a five-control matrix
Treating “71 fields completed” as the KPI creates a spreadsheet without a reliable source or update trigger. Add five implementation-control columns to every row of the Commission guidance. This 71 × 5 matrix is a proposed implementation method, not a form mandated by the Regulation.
| Control column | Design question | Weak answer | Acceptance-ready definition |
|---|---|---|---|
| Owner | Who owns meaning and quality? | IT | PLM Product Data Owner |
| Source | What system/document is authoritative? | Excel | Released PLM BOM vX, QMS report ID |
| Frequency | What triggers an update? | As needed | Model release, unit event, daily sync |
| Access class | Who may read it? | Stakeholders | Public / legitimate interest / authority |
| Validation | What permits publication? | Visual check | Type, unit, range, reference, signature, freshness |
Preserve applicability instead of flattening all 71 points
Keep the guidance classification—mandatory, optional, conditional or not required/displayed as of February 2027—together with battery-category applicability and legal source. Do not interpret optional as “discard forever,” and do not interpret the count of 71 as “all mandatory for all batteries on the same date.” A conditional field needs an explicit condition rule and evidence so that it can be reevaluated when the product changes.
Define a data contract before building APIs
For each data element define its name, meaning, type, unit, allowed range, missing-value representation, enumerations, timestamp basis, referenced identifiers, version and confidentiality class. “Capacity” alone does not say whether it is rated or remaining, Ah or kWh, model data or an individual measurement. “Temperature” may mean a current value, a period statistic, an event value or a storage tolerance. Stabilise semantics before integration.
Divide updates into three patterns
- Model updates: BOM, chemistry, rating, warranty and design-test revisions.
- Individual events: manufacturing, shipment, repair, accident, status change and repurposing.
- Time series: cycles, SOC, temperature and state of health at an agreed interval or on events.
Not every field requires real-time integration. However, an annual batch may be insufficient for data resulting from use. Define a freshness SLA, retries, missing-data handling, late arrival and correction for each data class.
Separate model data from individual and usage time-series data
Annex XIII distinguishes information relating to the battery model from information relating to an individual battery. The implementation should use a model ID and an individual unique ID as separate keys.
| Data layer | Examples | Typical authoritative source | Update trigger |
|---|---|---|---|
| Model master | Chemistry, composition, rated capacity/voltage, expected life, warranty, dismantling | PLM, QMS, compliance repository | Approved design change |
| Unit identity | Unique ID, model ID, lot, build date/time, shipment state | MES, ERP, DPP | Build and shipment |
| Unit status | Original, re-used, repurposed, remanufactured, waste | Service/lifecycle system | Controlled state transition |
| Usage time series | Cycles, SOC, temperature, state of health | BMS, IoT platform | Interval or event |
| Negative events | Accident, abnormal event, material safety event | BMS, QMS, service | Event and confirmation |
| Evidence | Test report, declaration, approval, calculation basis | QMS, document store | Approval or expiry |
The passport presentation layer does not necessarily need a duplicate of every raw time-series sample. Check the required granularity, retention, aggregation, access and download rights under the applicable rules, then make the data available from an authoritative BMS/IoT record. A sensor replacement, clock drift, communications outage or changed unit binding can destroy traceability even when a dashboard appears complete.
Separate public, legitimate-interest and authority access
A scannable battery passport QR code does not make all data public. The Regulation separates information into at least three access layers.
| Access layer | Typical users | Information examples | Technical controls |
|---|---|---|---|
| Public | Consumers and general business users | Model identification and applicable public characteristics | Anonymous read, integrity and availability |
| Legitimate interest | Repairers, remanufacturers, second-life operators, recyclers and eligible purchaser-side actors | Detailed composition, dismantling/safety, unit status and use data | Organisation verification, purpose, scope, expiry, audit |
| Authority / Commission | Notified bodies, market-surveillance authorities and Commission | Required test reports and regulated information | Strong identity, entitlement and evidence retention |
Legitimate interest is not a shared URL
Verify the applicant’s organisation, role, purpose, target units, requested data and access period. Grant the minimum necessary scope and revoke it when employment, contract or purpose ends. Record who viewed or downloaded what. Prevent bulk extraction, forwarded URLs and shared API credentials. Confirm the exact eligible persons and permitted reuse against the implementing measures applicable at the time.
Protect fields and supporting evidence consistently
Hiding a field in the user interface is insufficient if a PDF attachment, API response, CSV export, cache, log or support tool exposes it. Apply access decisions across fields, documents, APIs, exports, caches, backups and administrator support. Avoid putting sensitive values into public error messages or search-engine indexes.

Define the boundary among QR, unique ID, DPP Registry and the data store
Treat these as four different components:
- QR carrier: the physical entry point on the battery. It needs print quality, durability, placement and replacement procedures.
- Unique identifier: the key that identifies the battery. It needs controlled issuance, duplicate prevention, retirement, reprint and lineage rules.
- DPP Registry: the EU-level index. The Commission describes it as storing unique identifiers, registration data and high-level metadata, rather than the full detailed DPP content. Additional information may be required by applicable acts.
- DPP data store/resolver: the decentralised detailed-information service operated by the responsible economic operator or its authorised provider, enforcing the relevant access classes.
A typical read path is QR → unique ID/resolver → access decision → DPP data store. Before placing a product on the EU market, the DPP is registered as required by applicable legislation. Do not postpone internal data work while waiting for the Registry. Equally, do not hard-code a guessed API where current official specifications and the test environment must be checked. Isolate a Registry adapter from business data so interface change can be absorbed at the boundary.
Proposed six-system reference architecture
This guide uses six systems—PLM, MES, QMS, BMS, ERP and DPP—as a planning model, not a statutory system count. PLM owns model and BOM, MES unit genealogy, QMS tests and conformity, BMS usage condition, ERP trade flow, and DPP resolution/access/publication. A company may add an IoT platform, MDM, data lake or document system, or combine MES and QMS.
Non-functional requirements that belong in the design
- Open, machine-readable, structured, searchable and interoperable delivery
- Data export and a tested exit plan to reduce vendor lock-in
- Continuity if the responsible operator or provider ceases activity in the EU
- Data authentication, reliability, integrity, security and privacy
- Time synchronisation, correlation IDs, audit logs, signatures/hashes and version history
- Redundancy, backup, recovery tests and clear behaviour during resolver failure
- Quality gates for expired supplier evidence, unit mismatch and version inconsistency
Create a new passport and lineage after repurposing or remanufacturing
Overwriting the original record removes the design, use and responsibility history. Article 77(7) requires a new passport for a battery subject to preparation for re-use, preparation for repurposing, repurposing or remanufacturing, linked to the passport or passports of the original battery or batteries. Responsibility transfers to the economic operator placing that transformed battery on the market or putting it into service.
Lineage is not always one-to-one
A second-life stationary pack may combine modules from several original packs, so one new passport may link to several originals. One original pack may also be split into several products. A single previous_id cannot represent this. Use a relationship table containing relation type, source passport, target passport, operator, timestamp, included/excluded components, tests and approval.
Control lifecycle state transitions
Define permitted transitions such as original → repurposed → waste → recycled, rejecting unauthorised reversals and deletion. Do not automatically inherit rating, capacity, safety information or warranty. Hold shipment until the new responsible operator has approved the transformed battery and the new passport is ready.

A 90-day PoC model for a procurement-ready battery passport
The 90-day schedule below is a TOMAS TECH proposal model—not a statutory period, certification process or grace period before 2027. Product diversity, data quality, supplier count, updated implementing measures and customer audits may extend it. The goal is not a polished screen; it is to prove the hardest responsibility, data, access and evidence flows on a limited scope and convert them into a production RFP.
Days 0–15: confirm scope and the responsible operator
- Select one representative model and, as a modelling assumption, roughly 10–50 units.
- Document why it is an EV, LMT or industrial battery above 2 kWh.
- Map manufacturer, brand owner, importer, service provider and EU trade route.
- Have legal/compliance confirm the dated version of the 71-point guidance and applicable acts.
- Use the general EU Digital Product Passport readiness guide for shared foundations, while this PoC stays battery-specific.
Days 16–30: build the 71 × 5 matrix and gap register
- Preserve mandatory, optional, conditional and not-required-as-of-February-2027 status by category.
- Assign owner, source, frequency, access and validation.
- Record current value, evidence, gap, required system change and supplier dependency.
- Compare data ownership with the iron and steel DPP readiness guide without copying material-specific assumptions into batteries.
Days 31–50: implement identifiers and six-system integration
- Map model ID, unit unique ID, lot and passport ID.
- Extract only required data from PLM, MES, QMS, BMS and ERP.
- Normalise into the DPP store while retaining source record ID and version.
- Test QR resolution for valid, unknown, duplicate and retired identifiers.
- Validate Registry connectivity against current official specifications and the test environment; do not accept only a mock.
Days 51–70: test access and lifecycle
- Run positive and negative tests for public, legitimate-interest and authority roles.
- Test unauthorised access through API, CSV, attachment, log, cache and support tools.
- Bind cycles, temperature, SOC, state of health and negative events to the correct unit.
- Create a new repurposed passport linked to its original passport.
- Inject supplier delay, communications outage, clock drift, duplicate events and corrections.
Days 71–90: complete FAT/SAT and the production RFP
- Link every requirement to a test ID, expected result, evidence and owner.
- Use FAT for mapping, access, APIs, audit, backup/recovery and portability.
- Use SAT for physical QR labels, factory networks, actual BMS/MES data, operators and shipment holds.
- Approve unresolved gaps, temporary manual controls, regulatory-change risks and production cost drivers.
- Add rollout waves, supplier onboarding, support and change control to the RFP.
What to put in a battery passport RFP
“EU Batteries Regulation compliant” or “DPP ready” is too vague to compare suppliers. Require method, constraints, responsibility, evidence, standard-versus-custom status, version and cost-trigger conditions—not a yes/no answer.
| RFP section | Required question | Delivery evidence |
|---|---|---|
| Scope | How are EV/LMT/industrial >2 kWh batteries classified? | Scope register and rationale |
| 71 data points | What is covered by category and condition? | 71 × 5 matrix, gap and mapping |
| Identity | How are QR, unique ID, model, unit and lot bound? | ID specification and duplicate test |
| Architecture | How are Registry and detailed store separated? | Data flow, interfaces and boundary |
| Access | How are public/legitimate/authority roles enforced? | Role matrix and negative-test log |
| Updates | How are model, event and time-series data updated? | SLA, retry and reconciliation |
| Lifecycle | How is a new repurposed/remanufactured passport created? | Lineage demo and status audit |
| Interoperability | How are export, migration and schema changes handled? | Machine-readable export and exit plan |
| Continuity | How does the passport survive operator/provider failure? | Backup, transition and restore test |
| Security | How are authenticity, integrity and privacy protected? | Threat model, logs and incident plan |
| Regulatory change | Who monitors acts, guidance and standards? | Dated baseline and impact SLA |
| Acceptance | What precisely passes FAT/SAT? | Traceability matrix and evidence pack |
The contract should also cover data ownership, provider reuse restrictions, subprocessors, data location, outage notification, vulnerability handling, end of support, specification change, export and termination migration. Avoid unsupported “industry average” price or ROI claims. Break cost into model count, unit count, BMS update volume, supplier count, interfaces, languages, availability, retention and audit frequency.
FAT/SAT acceptance: decide with traceable evidence, not a screen demo
| Test ID | Test | Expected result | Required evidence |
|---|---|---|---|
| T01 | Trace a passport value to its source | Reach authoritative record, version and approval | Mapping export, screens, audit log |
| T02 | Condition does not apply | Preserve reason, not an unexplained blank | Rule, inputs and decision |
| T03 | Duplicate unique ID | Reject issuance/registration and hold shipment | Error and MES/ERP hold log |
| T04 | Damaged QR and reprint | Reissue approved carrier without changing unit | Reprint history and old-carrier disposition |
| T05 | Public user requests restricted data | Return no legitimate-interest/authority data | UI/API/export negative log |
| T06 | Expired legitimate-interest access | Reject immediately and require renewal | Entitlement and access log |
| T07 | BMS communications outage | Show last update/missing state; do not invent values | Timestamp, quality flag and alert |
| T08 | Duplicate/out-of-order event | Process idempotently and reconcile chronology | Correlation ID and reconciliation log |
| T09 | Repurposing | Create a new passport linked to originals | Relationship record and approval |
| T10 | Registry or data-store partial failure | Detect and reconcile inconsistency | Queue, alert and reconciliation log |
| T11 | Provider export | Move data, relations and evidence in agreed format | Export/import rehearsal |
| T12 | Backup restore | Restore to target point and resolve QR again | Restore report and hash comparison |
FAT verifies mappings, logic, security and interfaces in a controlled supplier environment. SAT verifies physical labels, scanners, plant networks, BMS/MES data, operating shifts and shipment-control procedures in the Thai site. Do not complete SAT using synthetic records only; pass an approved representative unit end to end. Regulatory conformity assessment and legal review remain separate from IT acceptance.
Common failures and how to avoid them
Treating the QR code as the deliverable
The QR code is only the entry point. Without reliable identity, access, authoritative data, updates, availability, Registry registration and audit, it is not an operating passport. Test that the physical unit, model, Registry metadata and detailed store remain consistent.
Completing 71 rows in a spreadsheet and stopping
A spreadsheet is useful for initial gap analysis, but manual edits cannot reliably follow engineering changes, manufacturing, BMS events and expiring supplier evidence. A temporary manual control needs an owner, dual check, expiry date and migration plan.
Publishing every field
Transparency does not eliminate confidentiality. Make access class part of the data model and enforce it beyond the UI. Control out-of-purpose reuse, bulk export and support access.
Treating the EU DPP Registry as the full DPP database
The Registry is primarily the shared index. Detailed-data hosting, provider exit, access requests, retention and continuity remain separate responsibilities.
Overwriting the original record after repurposing
This destroys lineage and makes it impossible to explain prior design, use, state, test and responsibility. Preserve many-to-many relations and an immutable audit history.
Contracting a guessed final specification
Check current delegated/implementing acts, standards and Registry specifications at the decision point. Contract a change process containing baseline date, monitoring, impact assessment, estimate, test and controlled release.
Implementation points for Thailand and ASEAN sites
Projects such as the Hyundai BEV and battery-assembly investment reported by Thailand’s BOI illustrate the region’s expanding EV/battery supply chain. They do not by themselves determine passport scope or responsibility. Follow the EU route for each finished product.
In a multilingual chain, the harder problem is usually not the Thai, Japanese, English or Vietnamese label; it is the shared identity and data definition. Local-language screens are compatible with common API fields, units, codes and timestamps. Supplier onboarding should include sample payloads, validation rules, error returns, correction processes and evidence-expiry rules—not only a CSV template.
Where plant connectivity is intermittent, design store-and-forward, sequence, retries and deduplication. When the BMS cloud and MES use different time sources, normalise to UTC while retaining original timestamp and timezone. Do not assume that EU hosting is automatically compliant or that non-EU hosting is automatically prohibited; assess privacy, trade secrets, contracts and transfers with qualified specialists.
Pre-procurement checklist
- [ ] Classified each model as EV, LMT or industrial above 2 kWh
- [ ] Mapped the candidate responsible economic operator in the EU trade flow
- [ ] Recorded the guidance/legal baseline version and review date
- [ ] Preserved mandatory/optional/conditional/not-required classification
- [ ] Assigned owner/source/frequency/access/validation to all 71 rows
- [ ] Defined model ID, unit unique ID, lot and passport relationships
- [ ] Assigned authoritative data to PLM/MES/QMS/BMS/ERP/DPP
- [ ] Enforced public/legitimate/authority access in UI, API, export and attachments
- [ ] Designed QR, unique ID, Registry and detailed store as separate components
- [ ] Isolated Registry changes behind an adapter and change process
- [ ] Can create a new passport and original links after repurposing/remanufacturing
- [ ] Controls timestamps and quality for events, temperature, SOC, cycles and state of health
- [ ] Tested continuity, export and restoration after operator/provider failure
- [ ] Wrote negative FAT/SAT tests and evidence formats into the RFP
- [ ] Labelled the 90-day PoC as a proposal model, not a legal period
- [ ] Added a gate for final review against current law, acts, standards and specialists
Conclusion: turn battery passport implementation into a releasable operation
The core of 2027 readiness is not a 71-row table or a QR image. It is the ability of the responsible operator to identify model and unit, collect controlled data from systems and suppliers, separate access, update changes and trace every material value back to evidence. Connecting the scope register, 71 × 5 matrix, six-system interfaces, Registry boundary, lifecycle lineage and FAT/SAT in one requirements traceability matrix changes the RFP from “Can you support DPP?” to “We will accept the system when this evidence passes.”
You can discuss battery category and EU trade-flow questions, a 71-point gap assessment, the proposed 90-day PoC, RFP or FAT/SAT with TOMAS TECH even while the programme is still at the concept stage. Contact TOMAS TECH with the likely battery category, EU placing-on-market party and current PLM/MES/QMS/BMS/ERP landscape.
FAQ
When does the battery passport become mandatory?
Article 77(1) of Regulation (EU) 2023/1542 sets 18 February 2027 for every EV battery, every LMT battery and every industrial battery above 2 kWh placed on the EU market or put into service. Confirm product scope and economic-operator roles against the rules applicable at the time.
Are all 71 battery passport data points mandatory?
No. The Commission’s August 2026 guidance classifies the 71 points as mandatory, optional, conditional or not required/displayed as of February 2027 and gives category applicability and legal sources. Read the current guidance with the Regulation; the guidance is not an authoritative legal interpretation.
Does the battery passport QR code contain all data?
The QR code links to a unique identifier and provides the entry point to the passport. It does not mean that all detailed content is encoded in the image. Design the carrier, identifier, resolver, access decision, detailed store and Registry registration end to end.
Is a DPP Registry connection sufficient?
No. The Commission describes the Registry as the index for unique identifiers, registration data and high-level metadata, while the detailed DPP follows a decentralised model. Internal sources, updates, access, continuity and audit remain necessary.
Who is responsible for data accuracy?
Under Article 77(4), the economic operator placing the battery on the market ensures accuracy, completeness and currency. It may authorise another operator in writing, but outsourced data entry or a platform subscription does not automatically transfer the legal responsibility.
Can a repurposed battery reuse the original passport?
The Regulation requires a new passport linked to the passport or passports of the original battery or batteries. Keep the new purpose, responsible operator, status and tests in the new record while preserving lineage.
Does a 90-day PoC guarantee compliance?
No. Ninety days is the proposal model in this article, not a legal period or conformity guarantee. It is intended to test a representative scope and produce a production RFP and documented gaps. A separate review against current law and qualified advice is required.
What is the most important battery passport RFP deliverable?
A requirements traceability matrix linking requirement, design, source data, test and evidence. The 71 × 5 matrix, identity specification, access matrix, data flow, lineage, negative tests, export/recovery and change control should accompany it.
References
- Regulation (EU) 2023/1542 — Articles 77–78 and Annex XIII
- European Commission — Guidance to support preparations for the Digital Batteries Passport (21 August 2026)
- European Commission — Digital Product Passport for Batteries
- European Commission — Digital Product Passport overview
- European Commission — The DPP Registry
- Thailand BOI — Hyundai BEV and battery assembly project