EU Digital Battery Passport · Process
The path of a battery passport
A passport is not created with one click. It goes through a draft, a delivery, two checks, and only then a publication nobody can take back. What happens afterwards — correction, reissue, handover — follows the same rule: nothing is overwritten, everything carries a reason.
From draft to document
Four steps, in this order. Each builds on the one before it.
- 01
Create
A draft is created — by hand in the studio, or automatically from a manufacturer's delivery. It is not public yet; a draft does not exist for the outside world.
- 02
Deliver data
Up to 112 mandatory fields (electric-vehicle battery), spread across master data, sustainability, procurement, engineering, quality, service and IT. Every field carries where it came from.
- 03
Check
Two checks stand before any publication is even possible. Both are explained in detail below.
- 04
Publish
The identifier is created, the content is fixed as version 1 with a checksum, and the passport becomes reachable through its QR code — and unchangeable.
The two checks
A publication fails while either one is open. That is deliberate: a draft that waits is better than a passport that claims something untrue.
Check 1
Completeness — against today's deadline
Every mandatory field of the battery category needs a value — but only once its obligation has started. A field that only becomes mandatory on 18 February 2027 blocks nothing today.
Without a date, a field counts as due immediately — a missing date in the catalogue is a gap, not a permission.
Check 2
Provenance — checked, not just read
Every value carries where it came from. A value a language model read out of a document blocks publication until a person confirms it against the source.
A value is not verified by someone claiming it — but by someone confirming it. That is the only path to the green status.
What publication produces
Three things that together form the proof.
A unique identifier
Under ISO/IEC 15459 — issuing agency, company, the battery's serial number. Printed on the QR code, unique worldwide.
A chained checksum
Every version points to the hash of the one before it. Tampering with a version breaks the chain — that is provable, not just claimed.
A digital signature
Confirms who was responsible for the content at that point in time — on top of the hash, which only says whether something changed.
Identity
The economic operator carries a decentralized identifier (did:oyd, OwnYourData). Its document names the signing key. Anyone resolves it without us.
None of this is ever overwritten. A correction produces a new version, never a change to the old one — a passport's history is itself part of the proof.
After publication
A published passport is not static. Three paths lead onward, none of them deletes anything.
New version
A correction or an operational reading (charge cycles, state of health) is not overwritten but published as the next version — with a reason, through both checks again. Earlier versions stay retrievable.
Reissue
After reconditioning, repurposing or preparation for reuse, a new passport is created. The old one is archived — not revoked, it was never wrong — and stays readable with a link to its successor.
Handover
If the battery passes to another economic operator, the new passport is created in their account — as a draft.
The new passport becomes public only once the new operator publishes it themselves. That is the acceptance of responsibility — until then, the old passport's page reveals neither the new one's serial number nor the new operator's name.
Where the process deliberately stops
Six places where the service would rather stop than guess.
No identifier without a registered issuing agency
An identifier is printed on the battery and cannot be corrected afterwards. Without the manufacturer's issuing-agency number, none is created.
No private address in the passport
The passport's web address ends up in an unchangeable record. A development test address is rejected, not written down.
No incomplete passport
If a field due today is missing, the system names every single one — instead of allowing a publication that only claims completeness.
Honest registry status
The central EU registry is not yet operational. The service reports this openly as 'pending' instead of faking a success that doesn't exist.
No key from the software itself
A signing key is created only by a person, never automatically. Without it, the proof carries only the checksum, honestly marked as unsigned.
No silent correction
A value once written can only record since when it no longer applies — never what it once was.
These six places are the reason the service sometimes waits instead of delivering — and the reason what it does deliver can be trusted.
A real example
Not a mock-up — an actually published passport in this system, live and retrievable.
Several versions, publicly readable with the complete change history and content hash.
One complete life story
A pilot sample passport — published, corrected, then reissued twice. Archived at every step, never deleted. The struck-through identifiers stay retrievable at their own address.
Four real fields from this chain, version 1
Batteriegewicht (kg)
474
Nennkapazität (kWh)
111
Chemische Zusammensetzung
Published (Volvo CFR EX90):
Kapazitaetsverlust (Typpruefung)
Legal basis: Verordnung (EU) 2023/1542 Art. 77 · EN 18219, 18220, 18221, 18222, 18223 (2026-08-01) · EN 18239, 18246 (Entwürfe) · DKE SPEC 99100.