The Toy Digital Product Passport: What Regulation (EU) 2025/2509 Actually Requires
Toy compliance leads have spent the last two years scanning ESPR working plans for a mention of toys. There isn't one. The ESPR Working Plan 2025-2030 names iron and steel, aluminium, textiles, furniture and tyres. Toys are absent from the priority list entirely.
That absence has been widely read as breathing room. It is closer to the opposite. Toys already have a Digital Product Passport obligation on the statute book - it just doesn't come from ESPR. It comes from Regulation (EU) 2025/2509 on the safety of toys, which repeals Toy Safety Directive 2009/48/EC and rebuilds toy compliance around a digital record.
And it does something no ESPR delegated act has yet attempted: it uses the DPP to replace the EU Declaration of Conformity, rather than sit alongside it.
Why you were looking in the wrong place
ESPR is a framework regulation. It sets almost no product rules itself; the binding requirements arrive through delegated acts, product group by product group, on the timetable set out in the Working Plan. If your product group isn't in the plan, ESPR genuinely hasn't reached you yet.
But ESPR is not the only route to a Digital Product Passport. The EU is now running several parallel DPP tracks in sectoral legislation - batteries under Regulation (EU) 2023/1542, construction products under CPR 2024/3110, and now toys under Regulation (EU) 2025/2509. Each has its own scope, its own content requirements, and its own timeline. What they increasingly share is the underlying plumbing.
For a toy manufacturer, the practical consequence is that "we're not in the ESPR Working Plan" is not a compliance position. It is a category error.
Directive to Regulation: the change beneath the change
Directive 2009/48/EC had to be transposed into 27 national laws. That transposition produced two decades of drift - different national interpretations of what counts as a toy, different enforcement postures, different documentation expectations from different market surveillance authorities.
Regulation (EU) 2025/2509 applies directly. There is no transposition step and no national variation to arbitrage. A toy that is compliant in Ireland is compliant in Poland, and a market surveillance authority in either place is reading the same text you are.
This matters more than it sounds for the DPP specifically. A digital record only works as an enforcement tool if every authority that scans it expects the same fields in the same structure. The Regulation form is what makes that possible.
The timeline, precisely
The dates here are where most published commentary gets confused, because the Regulation staggers its own application.
- Published in the Official Journal on 12 December 2025, repealing Directive 2009/48/EC.
- Entered into force 1 January 2026.
- Articles 28 to 44 and Articles 49 to 55 apply from 1 January 2026. These cover notification of conformity assessment bodies, delegated powers and committee procedure - the machinery the Commission needs in place before it can regulate anything substantive.
- Member States must have their penalty frameworks in place by 1 August 2028.
- General application from 1 August 2030, when Directive 2009/48/EC is repealed. During the transition, both instruments can be used to demonstrate conformity.
That is a transition of roughly 54 months from entry into force. It is long for a reason, and the reason is not the DPP alone - see the chemical-restrictions section below.
One caution: several secondary sources report entry into force as late December 2025 rather than 1 January 2026, and a few report substantive provisions applying from mid-2028. Before you build a programme plan around any of these dates, read the application article in the ELI record yourself. We have seen at least three mutually inconsistent timelines in circulation from otherwise reputable compliance advisers.
The DPP-replaces-DoC point
This is the structurally interesting part, and it is why toy people should care even though 2030 sounds distant.
Under Directive 2009/48/EC, the EU Declaration of Conformity is a document. The manufacturer draws it up, signs it, keeps it for ten years, and makes it available to authorities on request. It is a static artefact asserting that a specific toy meets specific harmonised standards.
Under Regulation (EU) 2025/2509, that function moves into the Digital Product Passport. The passport carries everything the DoC carried, plus content that has no paper equivalent:
- Manufacturer identification and, where relevant, importer details - traceability data that previously lived in labelling requirements rather than the conformity record.
- A list of allergenic fragrances present in the toy. This is a genuine addition. Fragrance allergen disclosure has been a labelling problem constrained by the physical space on a package; moving it into a digital record removes that constraint entirely, which is precisely why the obligation could be widened.
- A consumer complaint channel - an email address or web form through which consumers or other end users can raise issues directly.
The passport is reached through a data carrier - a QR code or equivalent machine-readable element - affixed to the toy itself, its label, or in defined cases its packaging.
Read that list again with an enforcement hat on. The DoC was something an authority had to ask you for. The DPP is something anyone with a phone can pull in a shop aisle, including your competitor's compliance team and a journalist working on fragrance allergens.
Where the toy DPP and the ESPR DPP converge
Here is what is reasonably clear, and what is not.
Reasonably clear: the EU is not building a separate passport infrastructure for each sectoral regulation. The central DPP Registry established under ESPR Article 13 is designed as a shared index - it resolves unique product identifiers to the operator's own data host, and it is already being referenced by legislation outside ESPR. The detergents regulation adopted in early 2026 does this explicitly, requiring registration in the ESPR registry and compliance with ESPR data-carrier and identifier standards. It would be surprising if toys went a different way.
Reasonably clear: the CEN/CENELEC EN 1821x series published in May 2026 is the technical substrate for DPP implementation generally, not for ESPR products only. If you are specifying a passport architecture now, EN 18220 is the document to start from.
Not clear, and do not let a vendor tell you otherwise: the specific technical and procedural requirements for the toy DPP. The Commission has to adopt implementing acts, and it has not done so. As of now you cannot generate a compliant toy DPP data carrier, because the specification that would make one compliant does not exist yet.
So the answer to "one architecture or two" is: plan for one, but don't sign a contract that assumes it. Build to the ESPR registry model and the EN 1821x standards, keep your data model loosely coupled to any one carrier specification, and hold procurement until the toy implementing acts land.
The other half of the Regulation
The DPP gets the attention, but the 54-month transition is not really about passports. It is about chemistry.
Regulation (EU) 2025/2509 substantially tightens restrictions on chemical substances in toys - extending prohibitions beyond the CMR substances covered by the Directive to categories including endocrine disruptors and certain PFAS, with the detail to be developed through delegated acts. Reformulating a toy portfolio, requalifying suppliers and re-testing takes years, not months.
This matters for sequencing. If your 2027 and 2028 engineering capacity is consumed by substance reformulation, the DPP data work will not get done in 2029 by a team that is already behind. The two workstreams compete for the same people.
What to do in the next twelve months
Implementing acts are missing, so anything that depends on the final carrier specification is premature. Everything below is not.
Inventory what your current DoC actually contains, per product family. Most manufacturers discover the DoC is assembled at the last minute from data scattered across PLM, supplier declarations and test reports. The DPP obligation turns that from an annoyance into a structural problem, because a digital record has to be maintained, not just produced once.
Find your fragrance allergen data. For most toy makers this sits with a fragrance supplier under a confidentiality arrangement, at a level of granularity that was never designed for public disclosure. Renegotiating that takes a long time. Start now.
Stand up the complaint channel. It is the cheapest requirement in the Regulation and the one most likely to be forgotten, because it is a customer-service obligation buried in a product-safety instrument.
Map your substance exposure before the delegated acts land. Know which SKUs would fail under a widened restriction list, and which of those are worth reformulating versus discontinuing.
Do not buy a toy DPP platform yet. Evaluate vendors on their DPP Registry integration and EN 1821x conformance, ask them directly what they will do when the toy implementing acts differ from their assumptions, and treat "toy-DPP-ready" claims made in 2026 as marketing.
Read the application article yourself. Given how much published commentary disagrees on the dates, this is a thirty-minute task that protects a multi-year programme plan.
The short version
Toys are not in the ESPR Working Plan and toys have a Digital Product Passport obligation anyway. It arrives through Regulation (EU) 2025/2509, it replaces the paper Declaration of Conformity rather than supplementing it, and it applies in full from 1 August 2030 - with the notified-body and comitology machinery already live since 1 January 2026.
The specification you would need to implement it does not exist yet. The data you would need to fill it largely does, scattered across systems that were never designed to keep it current. That is the work available to you right now.
Related reading

ESPR Performance Classes: The Ranking System That Makes Compliance Irrelevant to Competitiveness
ESPR's classes of performance rank compliant products against each other. A product can be fully lawful and still be publicly graded near the bottom of its category. Here's what that means for your product roadmap.
Who Sees What in a Digital Product Passport: Access Rights, Customs and Confidential Business Data
A passport is not a public web page. ESPR gives consumers, repairers, recyclers, authorities and customs different views of the data. Here is how role-based access works, what the pending security standards add, and how to protect trade secrets.
The ESPR Textiles Delegated Act: What the Draft Is Expected to Require from Apparel Brands
The textiles delegated act is the next big ESPR measure for fashion. Here is what the JRC preparatory work points to on durability, recyclability of mixed fibres and data points, the likely timeline, and how brands should prepare now.