Skip to main content
Sustainista

EU Digital Battery Passport · Process

The path of a battery passport

A passport is not created with one click. It goes through a draft, a delivery, two checks, and only then a publication nobody can take back. What happens afterwards — correction, reissue, handover — follows the same rule: nothing is overwritten, everything carries a reason.

From draft to document

Four steps, in this order. Each builds on the one before it.

  1. 01

    Create

    A draft is created — by hand in the studio, or automatically from a manufacturer's delivery. It is not public yet; a draft does not exist for the outside world.

  2. 02

    Deliver data

    Up to 112 mandatory fields (electric-vehicle battery), spread across master data, sustainability, procurement, engineering, quality, service and IT. Every field carries where it came from.

  3. 03

    Check

    Two checks stand before any publication is even possible. Both are explained in detail below.

  4. 04

    Publish

    The identifier is created, the content is fixed as version 1 with a checksum, and the passport becomes reachable through its QR code — and unchangeable.

The two checks

A publication fails while either one is open. That is deliberate: a draft that waits is better than a passport that claims something untrue.

Check 1

Completeness — against today's deadline

Every mandatory field of the battery category needs a value — but only once its obligation has started. A field that only becomes mandatory on 18 February 2027 blocks nothing today.

Without a date, a field counts as due immediately — a missing date in the catalogue is a gap, not a permission.

Check 2

Provenance — checked, not just read

Every value carries where it came from. A value a language model read out of a document blocks publication until a person confirms it against the source.

VerifiedManufacturer-providedEstimatedMachine-read

A value is not verified by someone claiming it — but by someone confirming it. That is the only path to the green status.

What publication produces

Three things that together form the proof.

A unique identifier

Under ISO/IEC 15459 — issuing agency, company, the battery's serial number. Printed on the QR code, unique worldwide.

A chained checksum

Every version points to the hash of the one before it. Tampering with a version breaks the chain — that is provable, not just claimed.

A digital signature

Confirms who was responsible for the content at that point in time — on top of the hash, which only says whether something changed.

Identity

The economic operator carries a decentralized identifier (did:oyd, OwnYourData). Its document names the signing key. Anyone resolves it without us.

None of this is ever overwritten. A correction produces a new version, never a change to the old one — a passport's history is itself part of the proof.

After publication

A published passport is not static. Three paths lead onward, none of them deletes anything.

New version

A correction or an operational reading (charge cycles, state of health) is not overwritten but published as the next version — with a reason, through both checks again. Earlier versions stay retrievable.

Reissue

After reconditioning, repurposing or preparation for reuse, a new passport is created. The old one is archived — not revoked, it was never wrong — and stays readable with a link to its successor.

Handover

If the battery passes to another economic operator, the new passport is created in their account — as a draft.

The new passport becomes public only once the new operator publishes it themselves. That is the acceptance of responsibility — until then, the old passport's page reveals neither the new one's serial number nor the new operator's name.

Where the process deliberately stops

Six places where the service would rather stop than guess.

No identifier without a registered issuing agency

An identifier is printed on the battery and cannot be corrected afterwards. Without the manufacturer's issuing-agency number, none is created.

No private address in the passport

The passport's web address ends up in an unchangeable record. A development test address is rejected, not written down.

No incomplete passport

If a field due today is missing, the system names every single one — instead of allowing a publication that only claims completeness.

Honest registry status

The central EU registry is not yet operational. The service reports this openly as 'pending' instead of faking a success that doesn't exist.

No key from the software itself

A signing key is created only by a person, never automatically. Without it, the proof carries only the checksum, honestly marked as unsigned.

No silent correction

A value once written can only record since when it no longer applies — never what it once was.

These six places are the reason the service sometimes waits instead of delivering — and the reason what it does deliver can be trusted.

A real example

Not a mock-up — an actually published passport in this system, live and retrievable.

LiveATDEMODEMO0002

Several versions, publicly readable with the complete change history and content hash.

One complete life story

ATPILOTPILOTEX900001…EX900001R1…EX900001R2 (draft)

A pilot sample passport — published, corrected, then reissued twice. Archived at every step, never deleted. The struck-through identifiers stay retrievable at their own address.

Four real fields from this chain, version 1

A

Batteriegewicht (kg)

474

Verified
A

Nennkapazität (kWh)

111

Verified
A

Chemische Zusammensetzung

Published (Volvo CFR EX90):

Estimated
E

Kapazitaetsverlust (Typpruefung)

Missing

Legal basis: Verordnung (EU) 2023/1542 Art. 77 · EN 18219, 18220, 18221, 18222, 18223 (2026-08-01) · EN 18239, 18246 (Entwürfe) · DKE SPEC 99100.