ESPR Enforcement: How Penalties, Market Surveillance, and the DPP Registry Actually Work

Most compliance conversations about ESPR focus on what the regulation requires - which product groups are in scope, what data a Digital Product Passport must carry, when delegated acts are expected. Far fewer ask the harder governance question: what actually happens when you get it wrong, and who enforces it?
This piece answers that question precisely. It covers how enforcement is structured, what powers national market surveillance authorities hold, how a finding in one Member State can follow a product across all 27, and what you need to have defensible before your product group's delegated act enters into force.
The Penalty Framework: No Single EU Fine Scale
ESPR (Regulation (EU) 2024/1781) sets no single EU-wide penalty scale. Article 74 requires each Member State to lay down "effective, proportionate and dissuasive" penalties in national law. The regulation does not prescribe specific fine amounts - that is left to national law. This creates a patchwork where the financial consequence of the same violation can differ materially between Germany, France, Spain, and other markets.
What Article 74 does fix is the framework that national penalty regimes must satisfy. Penalties must take into account:
- The nature, gravity, and duration of the infringement
- The economic benefit derived from non-compliance
- The environmental damage caused
- Whether the conduct was intentional, negligent, or repeated - all treated as aggravating factors
The regulation also specifies a minimum floor for what national penalty regimes must include. Penalties under ESPR "shall at least include fines and, in the event of repeated infringement, temporary exclusion from public procurement processes and from access to public funding, including tender procedures, grants and concessions."
That last point has direct commercial weight. ESPR's Article 65 makes Green Public Procurement (GPP) criteria mandatory for contracting authorities - meaning compliant DPP data is increasingly a prerequisite for winning public contracts. A repeat ESPR infringement can lock a supplier out of that market entirely. If your business sells into the public sector, non-compliance is not just a regulatory risk; it is a revenue risk. You can read more about the GPP dimension in our dedicated Article 65 post.
Exact fine amounts depend on national transposition — no EU-wide figure applies. Compliance teams should verify the penalty regime in each Member State where they place products on the market, in the same way REACH or GPSR penalties are checked market by market.
How Enforcement Actually Works: Market Surveillance Authorities
Enforcement runs through national market surveillance authorities (MSAs), operating under the framework of Regulation (EU) 2019/1020 on market surveillance and compliance of products. These are not passive bodies. Their powers under ESPR include:
- Requesting technical documentation and the Digital Product Passport on demand
- Inspecting and testing products, including laboratory testing, to verify conformity claims
- Ordering corrective action - requiring a manufacturer or importer to bring a product into compliance within a defined timeframe
- Ordering withdrawal or recall - removing non-compliant products from all sales channels, including online platforms
- Restricting or prohibiting market availability - blocking further sales until compliance is achieved
Market surveillance authorities can order the immediate withdrawal of non-compliant products from all sales channels - physical and online - and for online sales, can order platforms to de-list the product.
The Commission coordinates MSA activity through the ESPR Enforcement Forum and publishes annual enforcement reports. It has also added a new "safeguard clause" feature to ICSMS - the EU's Information and Communication System for Market Surveillance - allowing MSAs to share information on products presenting a risk under Article 69 of ESPR.
The EU-Wide Reach: Why One Finding Is Never Just One Market
This is the enforcement dynamic that most compliance teams underestimate. Non-compliance in one Member State can trigger coordinated actions across the EU through the ICSMS network, which allows market surveillance bodies in EU and EFTA countries to exchange information about non-compliant products.
ICSMS includes a public access area where anyone can search for specific products reported on the platform. A product flagged in one market does not stay contained to that market - the finding becomes visible and actionable across all 27 Member States. For manufacturers operating across multiple Member States, enforcement risk is cumulative.
The Safety Gate (formerly RAPEX) operates in parallel for products presenting a safety risk, enabling swift circulation of alerts among MSAs and the European Commission. Daily alerts from national authorities are publicly searchable.

The DPP Registry and Customs: The Border Is Now a Compliance Checkpoint
The EU Central DPP Registry went live on 19 July 2026, providing the infrastructure for registering digital product passports and enabling enforcement checks by customs authorities and market surveillance bodies.
The registry does not store full product data. It functions as a lookup directory: when a customs officer or MSA scans a product's data carrier (QR code or NFC tag), the registry resolves the unique identifier to the manufacturer's approved data host. What it checks is formal structure, authenticity, and integrity - whether a DPP exists, is correctly structured, and was created by an authorised entity.
The enforcement implication is direct. Customs authorities can suspend the release of products into free circulation where DPP or registry data is missing or fails checks - a shipment without a registered DPP can be detained pending resolution, not simply delayed with a warning.
Customs access the registry through the EU Customs Single Window Environment (Regulation (EU) 2022/2399), the digital framework connecting EU border controls to regulatory registries. Once a DPP is registered, the economic operator can generate a proof of registration - a secure electronic document sealed with the Commission's qualified electronic seal - which serves as legal evidence for customs authorities, retailers, and B2B buyers that the registration obligation has been fulfilled.
The practical implication for importers: if a platform provider registers the DPP on your behalf, the economic operator remains legally accountable for the accuracy of every data point in every passport. Delegating the technical task does not delegate the legal liability.
What to Have Defensible Before Your Delegated Act Bites
The delegated act for your product group is the trigger that makes ESPR obligations binding. But the data and documentation you need to satisfy enforcement scrutiny takes months - sometimes longer - to assemble. Here is what defensible compliance looks like in practice:
Beyond the self-assessment, the practical checklist for defensible compliance breaks into three areas:
Technical documentation
- Maintain complete technical files for each product, accessible on demand. Under ESPR, technical documentation and declarations must remain digitally accessible for 10 years after market placement.
- Document the conformity assessment procedure followed and the basis for any performance claims.
DPP data quality
- Treat DPP data as a live legal record, not a one-time filing. Every change is logged in the registry's audit trail with a timestamp; each new version is added to the record, not replacing it.
- Define internal ownership: who updates the passport, how errors are corrected, and how the audit log is maintained.
- Ensure your data carrier (QR code or NFC tag) resolves correctly at all times - a broken link at the border is a compliance failure.
Supplier data trail
- The data that makes a DPP defensible - material composition, substances of concern, recycled content, carbon footprint by lifecycle stage - comes from your supply chain. Structured, machine-readable data from Tier 1 and Tier 2 suppliers is not optional; it is the evidentiary foundation of the passport.
- Embed data-provision obligations in supplier contracts now. Collecting this data typically takes months, and the relationships built during preparation are reusable across every future compliance cycle.
The Enforcement Trajectory
It is worth being precise about timing. The DPP Registry is live as of 19 July 2026, but product-specific DPP obligations only become enforceable when the delegated act for a given category enters into force and its transition period expires. The first ESPR-based DPP obligations for most product groups are realistically expected in the 2028-2030 window, with textiles and iron and steel moving fastest.
What is already live and enforceable: the ESPR framework itself, the registry infrastructure, and the customs integration that allows border checks to begin as soon as a product's delegated act is in force. The window between now and your product group's deadline is preparation time - not waiting time.
The companies that will navigate enforcement most smoothly are those that treat the preparation window as a data infrastructure project, not a documentation exercise. The DPP is only as defensible as the supplier data trail behind it.
Related reading

ESPR Carbon Footprint: How PCF Data Actually Enters the Digital Product Passport
ESPR requires carbon footprint disclosure in the Digital Product Passport - but the methodology, data quality, and verification rules are more demanding than most teams expect. Here's what defensible PCF data actually requires.

ESPR and Furniture: Your Practical Roadmap to 2028 and Beyond
Furniture is a named priority in the ESPR Working Plan, with an indicative 2028 delegated-act date. Here's what's fixed, what's indicative, and what to do right now.

Digital Product Passport for Electronics and ICT: What the ESPR Means for Your Product Category
Electronics already sit under a dense EU regulatory stack. Here's how ESPR's digital product passport will reshape compliance for ICT and consumer electronics - and what the indicative 2027-2029 timeline means for manufacturers and importers today.