Automating Accountability: Smart Contracts and the Legal Future of Digital Product Passports in the EU Circular Economy | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Article Automating Accountability: Smart Contracts and the Legal Future of Digital Product Passports in the EU Circular Economy Rakan Alrdaan This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-8397708/v1 This work is licensed under a CC BY 4.0 License Status: Under Review Version 1 posted 12 You are reading this latest preprint version Abstract The European Union’s 2050 climate neutrality target relies heavily on circular economy strategies, with the newly introduced Ecodesign for Sustainable Products Regulation (ESPR) establishing Digital Product Passports (DPPs) as a key tool to close information gaps in product lifecycles. Despite the regulatory momentum, the scalability of DPPs across diverse sectors - such as batteries by 2027 and textiles by 2030 - poses significant challenges for data management and compliance verification. Methodologically, the study applies a multi-layered doctrinal-comparative framework triangulating EU law, CJEU jurisprudence, and industry pilot projects. This approach reveals that smart contracts, as automated executors of predefined conditions, can effectively govern DPP data, enhancing transparency and operational efficiency. Pilot initiatives by the Global Battery Alliance and textile industry experiments demonstrate the practical viability of blockchain-enabled smart contract automation for sustainability data collection, supplier verification, and regulatory compliance. The findings underscore the transformative potential of integrating legal frameworks with emerging digital technologies to support circular economy objectives. However, the study also highlights unresolved legal complexities concerning data access, liability, and regulatory oversight. These insights inform policymakers and industry stakeholders on designing robust, scalable, and legally compliant DPP systems, advancing the EU’s sustainability agenda through innovative digital governance mechanisms. Business and commerce/Information systems and information technology Social science/Science technology and society digital product passports smart contracts circular economy GDPR Data Act EU law sustainability automated governance Figures Figure 1 Introduction The European Union has set an ambitious goal to achieve climate neutrality by 2050, with the circular economy playing a pivotal role in this transition (European Commission, 2019). This analysis bridges environmental governance, data law, and circular-economy. In June 2024, the EU introduced the Ecodesign for Sustainable Products Regulation (ESPR), which lays out a comprehensive framework for Digital Product Passports (DPPs) (European Union, 2024a). These passports aim to overcome persistent information gaps that have hindered circular business models by providing standardized, machine-readable product data accessible via QR codes or other data carriers throughout a product’s lifecycle. Looking ahead, the ESPR framework will extend to cover most product categories sold within the EU. For instance, battery passports will become mandatory starting February 2027 (European Union, 2023b), while textile DPPs are anticipated by 2030 (European Parliament, 2024). This initiative represents an unprecedented digital infrastructure project, engaging millions of economic operators and billions of products. As DPP systems expand, relying on manual data entry, access control, and compliance verification will become impractical. Automation, therefore, shifts from being merely advantageous to absolutely essential. Smart contracts - computer programs that automatically execute agreements when predefined conditions are met - offer promising solutions to automate DPP data governance. The Global Battery Alliance’s 2024 pilot projects, encompassing 80% of global electric vehicle battery manufacturing capacity, have demonstrated the practical feasibility of automated sustainability data collection and aggregation (Global Battery Alliance, 2024). Similarly, pilots in the textile industry are exploring blockchain-based traceability combined with smart contract automation for supplier verification and certification. In real-world terms, smart contracts could automatically grant repairers access to technical documentation, flag non-compliant products, or trigger customs clearance processes based on verified DPP data. However, this automation raises fundamental legal questions. For example, when a smart contract automatically denies a repairer access to technical documentation, flags a product as non-compliant, or triggers a customs hold due to missing DPP data, who bears responsibility? Can such decisions be challenged? Does the prohibition on automated decision-making under GDPR Article 22 apply (European Union, 2016a)? Moreover, how can transparency be ensured when smart contract logic might be proprietary or technically complex? These concerns are far from theoretical - they strike at the core of how the EU balances efficiency with the protection of fundamental rights. Recent developments have intensified the urgency of these questions. First, the Court of Justice of the European Union’s December 2023 ruling in the SCHUFA case clarified that automated credit scoring systems qualify as automated decision-making under Article 22 when their outputs significantly impact individuals (CJEU, 2023). The Court underscored that preparatory acts feeding into human decisions can themselves trigger Article 22 protections if they involve “heavy reliance” on automated outputs. Second, the European Data Protection Board’s April 2025 blockchain guidelines explicitly confirmed that smart contract execution may activate Article 22 protections (EDPB, 2025), emphasizing that blockchain immutability does not exempt data controllers from respecting data subject rights. Reflecting on these developments, it becomes clear that the integration of automation in DPP governance demands careful legal scrutiny to uphold transparency, accountability, and rights protection. Examining the existing literature reveals a notable gap. As Djurovic and Janssen point out, most smart contract research concentrates on financial applications, especially cryptocurrency transactions and decentralized finance (Djurovic and Janssen, 2018). Goldenfein and Leiter delve into smart contracts from an abstract legal perspective, exploring the “code as law” paradigm (Goldenfein and Leiter, 2018). Levy offers a critical viewpoint, arguing that smart contracts are “book-smart, not street-smart,” as they lack the flexibility and contextual sophistication inherent in legal systems (Levy, 2017). In contrast, literature on DPPs tends to focus on data requirements and standardization. For example, Götz et al. analyze the potential of DPPs to advance climate neutrality and circular economy goals (Götz et al., 2022), while Adisorn et al. propose a conceptual framework for DPPs contributing to circular objectives (Adisorn et al., 2021). Walden et al. highlight challenges in data collection, verification, and governance within DPPs (Walden et al., 2021). Yet, these works give limited attention to automation and algorithmic governance. Crucially, no existing scholarship systematically examines how EU law - particularly the Data Act’s novel smart contract provisions (Article 36) (European Union, 2023b) and GDPR’s automated decision-making protections (Article 22) - applies to DPP smart contracts. This gap is pressing: the Data Act came into force in January 2024; the EDPB adopted blockchain guidelines in April 2025; battery passports become mandatory in February 2027; and ESPR delegated acts are currently under development. The regulatory window to shape DPP smart contract governance is open now. From this perspective, while smart contract literature emphasizes enforceability and code determinism rooted in financial contexts, and DPP scholarship foregrounds data disclosure and supply chain traceability, this article bridges these views by demonstrating that DPPs require governance mechanisms - precisely where smart contracts, if properly constrained, can add value while respecting fundamental rights. This study offers three original contributions. First, it delivers the first comprehensive legal analysis of smart contracts in the DPP context, systematically exploring how Data Act Article 36, GDPR Article 22, ESPR, the Cyber Resilience Act, and related instruments interact. The methodological innovation lies in connecting Data Act Article 36 requirements with specific DPP implementation scenarios - a nexus previously unexplored in legal scholarship. Second, it identifies critical legal gaps where existing EU law provides insufficient guidance for deploying DPP smart contracts. These include unclear applications of Article 22 to specific use cases (e.g., when automated access control triggers Article 22), absence of explainability requirements tailored to smart contracts, uncertain liability allocation when multiple parties deploy shared smart contracts, and unresolved tensions between blockchain immutability and GDPR data subject rights under Articles 16-17. Third, the study proposes a practical accountability framework proposing a 10-point policy checklist for regulators, standard-setters, and economic operators. This framework balances automation efficiency with human oversight, legal compliance, and fundamental rights protection. The recommendations are grounded in real-world pilot experience and designed for immediate implementation as ESPR delegated acts are drafted. This article addresses nine core questions: 1. What is a Digital Product Passport under the ESPR framework, and how will it operate across product categories and lifecycle stages? 2. What legal functions could smart contracts perform for DPPs - and which functions raise heightened legal risks? 3. How do smart contracts interact with EU contract law principles, consumer protection, and information duties? 4. What governance and accountability models make automated DPP processes auditable, contestable, and lawful? 5. How do the Data Act and GDPR allocate roles, rights, and responsibilities over DPP data, particularly when processing is automated? 6. What cybersecurity, product safety, and product liability implications arise when compliance logic is partially automated? 7. What technical standards and identifiers are needed for cross-border interoperability and market surveillance access? 8. What safeguards are needed to avoid dark patterns, exclusion, and discrimination, especially for SMEs and repair markets? 9. What realistic implementation paths exist over the next 3-5 years, and what should the EU prioritize in delegated acts and guidance? The article proceeds as follows: Section 2 reviews relevant literature on circular economy policy, DPP concepts, and smart contract legal frameworks. Section 3 outlines the research methodology, including source selection and analytical framework. Section 4 presents the EU legal architecture for DPPs, examining ESPR, the Data Act, GDPR, and related instruments. Section 5 analyzes five smart contract use cases for DPPs with detailed legal risk assessments. Section 6 develops an accountability framework addressing explainability, contestability, and liability allocation. Section 7 presents case studies from batteries, textiles, and electronics, drawing lessons from real-world pilots. Section 8 discusses the findings and their implications for EU digital governance of circular economy transitions. Finally, section 9 concludes with policy recommendations and future research directions. Literature Review This review synthesizes four domains of scholarship: circular economy policy and DPP concepts, smart contract legal frameworks, blockchain traceability applications, and sector-specific DPP implementations. Table 2 summarizes the core literature informing this analysis. Table 1. synthesizes key scholarly contributions across four research areas: (1) circular economy policy and Digital Product Passport (DPP) concepts, (2) smart contract legal frameworks, (3) blockchain traceability applications, and (4) sector-specific DPP implementations. Each entry identifies the author(s)/year, focus area, key contribution, and relevance to DPP smart contract automation. The table demonstrates the interdisciplinary nature of the research gap this study addresses, highlighting the fragmentation between technical, legal, and empirical perspectives on automated DPP systems. Table 1. Overview of Key Literature Informing the Analysis. Author(s)/Year Focus Area Key Contribution Relevance to DPP Smart Contracts UNECE, ISO (ISO, 2024; Raskin, 2017) Circular Economy & DPPs International standardization efforts to ensure global interoperability of DPPs. Standards critical for cross-border data exchange and legal compliance in automated DPP smart contracts. European Parliament (European Parliament, 2024) Circular Economy & DPPs Proposed phased textile DPP deployment roadmap (2027-2033). Illustrates sector-specific timelines and challenges for automating DPP data access and verification via smart contracts. Various scholars (Götz et al., 2022; Adisorn et al., 2021; Walden et al., 2021) Circular Economy & DPPs Position DPPs as essential circular economy infrastructure, focusing on data governance design. Highlights the gap in legal-regulatory analysis for DPP automation relevant to smart contract implementation. EU Data Act (European Union, 2023) Smart Contracts & Legal Frameworks Provides the first EU legal definition of smart contracts, technology-neutral and broad. Establishes legal basis for smart contracts automating DPP data processes, framing regulatory compliance needs. UNCITRAL Model Law (UNCITRAL, 2024) Smart Contracts & Legal Frameworks Offers international guidance on automated contracting. Supports harmonization of smart contract legal frameworks applicable to DPP systems across jurisdictions. Djurovic & Janssen (Djurovic and Janssen, 2018) Smart Contracts & Legal Frameworks Demonstrate legal uncertainties in blockchain smart contract formation under traditional law. Identifies legal risks in automating DPP agreements, emphasizing need for clarity in contract formation via smart contracts. Goldenfein & Leiter (Goldenfein and Leiter, 2018) Smart Contracts & Legal Frameworks Conceptualize smart contracts as “legal engineering” shifting enforcement to code execution. Underlines potential and limits of smart contracts for automating DPP compliance and enforcement. Levy (Levy, 2017) Smart Contracts & Legal Frameworks Critiques smart contracts as lacking social and contextual legal flexibility. Points to challenges in capturing legal gradations in automated DPP smart contracts. Raskin (Raskin, 2017) Smart Contracts & Legal Frameworks Comprehensive analysis of smart contract validity and enforcement challenges across jurisdictions. Highlights cross-jurisdictional legal complexities relevant to DPP smart contract deployment. Von Hafe et al (Von Hafe et al., 2025) Smart Contracts & Legal Frameworks Comparative analysis of divergent EU member state approaches to smart contracts. Indicates regulatory fragmentation affecting DPP smart contract harmonization. Dhillon et al. (Dhillon et al., 2017) Blockchain & Traceability Analyze governance trade-offs between decentralization, scalability, and regulatory compliance. Informs design of blockchain-based DPP smart contracts balancing technical and legal requirements. Allen et al (Allen et al., 2019) Blockchain & Traceability Propose governance models for blockchain supply chain management emphasizing roles and dispute resolution. Provides frameworks potentially adaptable for DPP smart contract governance and conflict management. Various studies (Kumar et al., 2022; Agrawal et al., 2021; Caro et al., 2018) Blockchain & Traceability Demonstrate blockchain traceability benefits in agribusiness, textiles, and agri-food supply chains. Evidence of blockchain’s technical suitability for DPP data integrity and tamper-resistance. Various scholars (ISO, 2024; Raskin, 2017) Blockchain & Traceability Identify legal challenges of blockchain immutability and GDPR compliance in circular economy contexts. Highlights legal constraints critical for designing compliant DPP smart contracts using blockchain. Battery DPP studies (Sopha et al., 2022; Rizos et al., 2024; Abedi et al., 2024; Global Battery Alliance, 2024) Sector-Specific DPP Implementation Empirical analyses of battery DPP pilots reveal data quality, verification, and stakeholder access challenges. Illustrate practical implementation issues that smart contracts must address for effective DPP automation. Textile DPP roadmap (European Parliament, 2024) Sector-Specific DPP Implementation Phased deployment plan for textile DPPs with increasing complexity and circularity. Provides sector-specific context for smart contract automation timelines and legal considerations. Global Battery Alliance (Global Battery Alliance, 2024) Sector-Specific DPP Implementation Real-world pilot demonstrating feasibility and challenges of automated sustainability data collection. Offers empirical insights informing smart contract design for data verification and rights management in DPPs. Abedi et al. (Abedi et al., 2024) Sector-Specific DPP Implementation Systematic review identifying enablers and barriers to DPP adoption. Highlights factors influencing smart contract integration in DPP systems. Circular Economy and Digital Product Passports The European Green Deal, announced in December 2019, set climate neutrality by 2050 as the EU’s overarching objective (European Commission, 2019). The circular economy was identified as a key enabler to decouple economic growth from resource consumption. The second Circular Economy Action Plan, adopted in March 2020, launched a sustainable products initiative to make products more durable, reusable, repairable, and recyclable (European Commission, 2020). It explicitly called for “digital product passports” to enable information sharing throughout product lifecycles. The ESPR, adopted in June 2024, operationalizes this vision (European Union, 2024a). It establishes a comprehensive framework for ecodesign requirements and DPPs across product categories (European Commission, 2009). International standardization efforts through UNECE and ISO aim to ensure global interoperability (ISO, 2024; Raskin, 2017). These standards will be critical for cross-border data exchange and market surveillance. Recent scholarship positions DPPs as critical circular economy infrastructure (Götz et al., 2022; Adisorn et al., 2021; Walden et al., 2021), though it largely treats data governance as a design challenge rather than a legal-regulatory one. A 2024 European Parliament study proposes a three-phase textile DPP deployment: minimal DPP by 2027, advanced DPP by 2030, and full circular DPP by 2033 (European Parliament, 2024). Yet, the question of how to automate data access, verification, and compliance checking - and what legal constraints apply - remains underexplored. Taken together, these studies collectively underscore the centrality of DPPs in advancing circular economy objectives within the EU policy framework. A pattern emerges wherein policy and standardization efforts provide a robust infrastructural foundation, yet scholarly attention to the legal and automated operationalization of DPPs is limited. It is noteworthy that while the technical and design dimensions of DPPs receive considerable focus, the integration of legal constraints - particularly regarding automation and data governance - remains insufficiently addressed. This gap is particularly significant because the successful deployment of DPPs depends not only on technical interoperability but also on ensuring compliance with evolving regulatory frameworks. Thus, this subsection highlights a critical research need to bridge policy ambitions with legal and technical realities in DPP implementation. Smart Contracts and Legal Frameworks The Data Act provides the first EU legal definition of smart contracts: “a computer program used for the automated execution of an agreement or part thereof, using a sequence of electronic data records and ensuring their integrity and the accuracy of their chronological ordering” (Article 2(39)) (European Union, 2023). This definition is technology-neutral, covering both blockchain-based and conventional database implementations. The UNCITRAL Model Law on Automated Contracting (2024) offers complementary international guidance (UNCITRAL, 2024). Djurovic and Janssen demonstrate that the formation of blockchain-based smart contracts under traditional contract law remains legally uncertain (Djurovic and Janssen, 2018). Questions persist regarding offer, acceptance, and intention to create legal relations. Goldenfein and Leiter explore smart contracts as “legal engineering,” arguing they shift enforcement from ex-post legal interpretation to ex-ante code-based execution (Goldenfein and Leiter, 2018). Levy critiques smart contracts as “book-smart, not street-smart,” unable to capture the social and contextual flexibility of law (Levy, 2017). Raskin provides a comprehensive analysis of smart contract legal validity across jurisdictions, identifying persistent challenges in contract formation, interpretation, and enforcement (Raskin, 2017). Von Hafe et al.’s comparative analysis reveals significant divergence in EU member states’ approaches (Von Hafe et al., 2025). These studies reveal a tension between the promise of smart contracts to enhance efficiency through automation and the legal system’s inherent need for flexibility and contextual judgment. Hence, while smart contracts can automate certain contractual functions, their legal status and enforceability remain unsettled, particularly in cross-jurisdictional contexts. It is noteworthy that existing literature calls attention to the challenges of aligning code-based execution with traditional legal principles but stops short of proposing concrete frameworks for resolving these issues in regulatory applications. This tension is directly relevant to DPP systems, which require automated yet legally compliant mechanisms for data access and verification. Therefore, this subsection identifies a research gap concerning the reconciliation of smart contract automation with legal safeguards, a gap this study aims to address. Blockchain, Traceability, and Circular Economy Blockchain-based traceability systems have shown promise in agribusiness (Kumar et al., 2022), textiles (Agrawal et al., 2021), and agri-food supply chains (Caro et al., 2018), emphasizing data integrity and tamper-resistance. Dhillon et al. examine governance trade-offs between decentralization, scalability, and regulatory compliance (Dhillon et al., 2017). Allen et al. design governance models for blockchain-based supply chain management, stressing clear role allocation and dispute resolution (Allen et al., 2019). From a circular economy perspective, blockchain offers traceability and data integrity benefits but also legal challenges: immutability conflicts with data subject rights; distributed architectures complicate GDPR controller/processor roles; and smart contract automation raises Article 22 concerns. While blockchain traceability literature acknowledges these tensions, it does not systematically analyze them within the DPP regulatory context. Taken together, these works highlight the technical advantages and legal complexities of applying blockchain to circular economy traceability. Blockchain’s immutability enhances trust in data but simultaneously challenges compliance with data protection and governance standards. It is noteworthy that while governance models are proposed to mitigate these issues, there remains a lack of integrated legal analysis specifically tailored to DPP applications. This gap is significant because DPPs rely on trustworthy data flows that must comply with stringent regulatory requirements. Consequently, this subsection underscores the necessity for interdisciplinary research that bridges blockchain technology, legal frameworks, and circular economy objectives - a nexus that remains underexplored and which this study seeks to illuminate. Battery and Textile DPP Implementations Recent studies on battery DPPs identify challenges in data collection, verification, confidentiality, interoperability, and data quality across EV battery supply chains (Sopha et al., 2022; Rizos et al., 2024; Abedi et al., 2024). Wicaksono et al.’s systematic review highlights key enablers and barriers to DPP adoption (Abedi et al., 2024; Wicaksono et al., 2025). The Global Battery Alliance’s 2024 pilots, involving major manufacturers, demonstrate real-world feasibility of automated sustainability data collection (Global Battery Alliance, 2024). These pilots reveal practical challenges: data quality varies across supply chain tiers, verification remains largely manual, and stakeholder access rights require careful calibration. While battery and textile DPP literature is rich empirically, it remains legally thin, documenting implementation challenges without systematically analyzing the governing legal frameworks. Questions of automated decision-making, liability, and fundamental rights protection remain largely unaddressed. These empirical studies illustrate the practical complexities of deploying DPPs in industrial contexts, revealing recurring challenges related to data quality, interoperability, and stakeholder management. The evidence indicates that, despite technological advances and pilot successes, legal and regulatory considerations - particularly those concerning automation and rights protection - remain insufficiently integrated into implementation strategies. It is noteworthy that this disconnect between empirical practice and legal analysis limits the scalability and regulatory compliance of DPP systems. This gap is particularly significant because without addressing legal governance, automated DPP implementations risk non-compliance and stakeholder disputes. Thus, this subsection highlights the urgent need for research that combines empirical insights with rigorous legal analysis. Synthesis and Research Gap The literature establishes smart contracts as legally significant but undertheorized in regulatory contexts. DPP scholarship addresses data governance but overlooks automation mechanisms. Blockchain traceability literature emphasizes technical benefits while underanalyzing legal constraints. A notable gap emerges at the intersection of these fields. While extensive literature exists on DPPs and smart contracts separately, no scholarship systematically analyzes the legal implications of using smart contracts to automate DPP systems. This gap is critical because automation raises fundamental questions about accountability, contestability, and compliance with GDPR, the Data Act, and other EU frameworks. Taken together, these diverse bodies of literature reveal an interdisciplinary challenge at the nexus of circular economy policy, smart contract technology, blockchain traceability, and sector-specific DPP implementation. Hence, the integration of legal, technical, and empirical perspectives remains fragmented. Yet this fragmentation impedes the development of legally robust, automated DPP systems capable of supporting the EU’s ambitious sustainability goals. This gap is particularly significant because the effective deployment of DPPs depends on harmonizing automation with legal safeguards across multiple regulatory regimes and industrial contexts. By analyzing DPP smart contracts, the present study contributes an essential interdisciplinary framework that bridges legal theory, technological innovation, and practical implementation, thereby advancing academic knowledge and policy-relevant solutions in sustainable product governance. Methods The study adopts a mixed doctrinal-comparative and case study approach to analyze the evolving EU regulatory framework for DPPs and the legal implications of their automation through smart contracts. This methodological design is chosen to bridge the gap between normative legal analysis and the practical realities of technological implementation. The research synthesizes legal scholarship, EU legislation, jurisprudence, and empirical data from pilot projects to provide a comprehensive and contextualized understanding of the subject. Research Design The research design is centered on a doctrinal analysis of the primary legal instruments governing DPPs and smart contracts in the EU. This includes the Ecodesign for Sustainable Products Regulation (ESPR) (European Union, 2024a), the Data Act (European Union, 2023b), the General Data Protection Regulation (GDPR) (European Union, 2016a), and the Battery Regulation (European Union, 2023b). The analysis is supplemented by a review of pertinent jurisprudence from the Court of Justice of the European Union (CJEU), particularly the SCHUFA case (C-634/21) (CJEU, 2023), which provides critical insights into the application of automated decision-making provisions under the GDPR. To ground the legal analysis in practical application, the study also examines publicly documented DPP pilot projects in the battery and textile sectors, including initiatives by the Global Battery Alliance (Global Battery Alliance, 2024). Legal Sources The selection of legal sources was conducted with a focus on relevance and authoritativeness. Primary legal sources were retrieved from the EUR-Lex and CURIA databases, ensuring access to the most current and official versions of EU legislation and case law. The search for academic literature was conducted across multiple databases, including CrossRef and Google Scholar, with a focus on peer-reviewed articles published between 2018 and 2025. Regulatory guidance from the European Data Protection Board (EDPB) and the European Union Agency for Cybersecurity (ENISA) was also reviewed to incorporate the latest interpretive trends and best practices. Jurisprudence and Verification The jurisprudential analysis focused on identifying and interpreting key rulings from the CJEU that have a direct bearing on the use of smart contracts in DPPs. Case law was retrieved from the CURIA database, covering judgments up to October 2025. The analysis of the SCHUFA case (C-634/21) (CJEU, 2023), for instance, was crucial in delineating the boundaries of automated decision-making under Article 22 of the GDPR, particularly the “heavy reliance” test and the definitional scope of “decisions” affecting individuals. Regulatory guidance from the EDPB, including the April 2025 blockchain guidelines (EDPB, 2025), and ENISA (ENISA, 2023) was also reviewed to incorporate current interpretive trends. While the analysis is grounded in established jurisprudence such as SCHUFA, the application of GDPR Article 22 to smart contracts remains a developing area of law, and empirical data on large-scale DPP implementations is still limited to pilot initiatives. Results The legal-doctrinal analysis reveals a complex, multi-layered regulatory framework governing DPP smart contracts. This architecture comprises eight interconnected instruments, creating opportunities and tensions. The study systematically maps this architecture, identifying provisions directly relevant to smart contract automation. ESPR and the DPP Framework The Ecodesign for Sustainable Products Regulation (EU) 2024/1781 establishes the foundational framework for DPPS (European Union, 2024a). Notably, the ESPR does not define “digital product passport” explicitly; instead, it empowers the Commission to require, via delegated acts, that products be accompanied by a “product passport” containing specified information (Article 8). - Core DPP Elements: Article 8 authorizes the Commission to mandate passports containing product identification, composition, repairability, and end-of-life handling information (European Union, 2024). Article 10 requires passports to be accessible via data carriers - typically QR codes compliant with ISO/IEC 18004 (CEN/CENELEC, 2025) - affixed to products. Unique product identifiers must follow ISO/IEC 15459 standards (CEN/CENELEC, 2025). These technical standards are vital for interoperability. - Data Carrier and Registry : Article 10 requires each product passport to be accessible through a data carrier affixed to the product, while Article 12 establishes a Commission-managed registry as the legal infrastructure for storing passport information. The registry links physical products and unique identifiers to corresponding digital records, assigning data-entry duties to economic operators and regulated access to authorized actors. This centralized model embeds traceability and oversight within EU law, distinguishing it from decentralized blockchain architectures premised on distributed governance. - Differentiated Access Rights : Article 13 frames access to product-passport data according to user roles and regulatory functions, leaving the specific tiers to be detailed in delegated acts. In practice, access may range from public information (e.g., product identifiers), to restricted data for economic operators, to authority-only layers for market surveillance and customs. This graded model underpins legal interoperability with the GDPR and the Data Act, requiring smart contracts to authenticate identity and role before enabling compliant data exchange. - Interoperability Requirements: Article 12 establishes a Union-wide registry for product-passport data, forming the legal basis for interoperability across Member States and sectors. Standardisation efforts are underway to operationalize this framework, with CEN/CENELEC (ISO, 2024; CEN/CENELEC, 2025) developing common data formats, identifiers, and interface protocols, and ISO/IEC (ISO, 2024) contributing to global alignment and cross-sector compatibility. - Customs Integration: Article 13 grants customs authorities access to the product-passport registry to verify that imported products correspond to valid passport entries. This mechanism embeds DPP verification within border-control procedures, turning customs clearance into an operational compliance checkpoint. It also creates a potential use case for automated conformity checks and smart contract-based validation of import compliance (European Union, 2024). - Battery Regulation as First Implementation: Regulation (EU) 2023/1542 on batteries provides the first sector-specific implementation of a digital product passport framework (European Union, 2023b). Chapter IX, supported by Annex XIII, defines the battery-passport structure and data requirements. The obligation applies from 18 February 2027, positioning batteries as the initial testing ground for DPP automation and traceability. Data Act and Smart Contract Regulation Regulation (EU) 2023/2854 (Data Act) provides the first EU regulation specifically addressing smart contracts (European Union, 2023c). Article 2(39) defines smart contracts in technology-neutral terms, covering blockchain and conventional implementations. - Article 36 Essential Requirements: Article 36 sets essential requirements for smart contracts used in Data Act data-sharing agreements, including robustness and access control, safe termination and interruption, data archiving and continuity, and consistency with the terms of the data-sharing agreement (European Union, 2023). These provisions aim to mitigate risks arising from blockchain immutability, irreversible execution, and limited human oversight (Dwivedi et al., 2021). - Scope Limitation : Article 36 applies only to smart contracts used in Data Act data sharing agreements (Chapter III), not broadly. This creates a regulatory gap: DPP smart contracts outside Data Act sharing agreements are not subject to Article 36. ESPR delegated acts could incorporate similar requirements for DPP smart contracts; and this study recommends that they do so. - Termination and Modification: Article 36(1)(b) requires mechanisms for the safe termination and interruption of smart-contract execution to prevent unintended or irreversible outcomes (European Union, 2023). This provision directly addresses concerns about blockchain immutability and the absence of human oversight, which in practice may be mitigated through safeguards such as multi-signature controls, time-locks, or circuit-breaker functions. - Archiving and Auditability: Article 36(1)(c) requires preserving smart-contract transaction data to ensure continuity, auditability, and accountability (European Union, 2023). This provision supports the creation of verifiable audit trails and enables ex post review of automated execution. GDPR and Automated Decision-Making Regulation (EU) 2016/679 (GDPR) imposes comprehensive data protection requirements on DPP systems (European Union, 2016a). Two provisions are especially relevant: Article 22 on automated decision-making and Articles 13-14 on transparency. - Article 22 Prohibition: Article 22(1) prohibits decisions based solely on automated processing that produce legal effects or similarly significant impacts on individuals (European Union, 2016). Exceptions under Article 22(2) are permitted only where appropriate safeguards are in place, including human oversight, the right to contest decisions, and mechanisms ensuring explainability as required by Article 22(3). - SCHUFA Case Interpretation: The CJEU’s December 2023 SCHUFA ruling (Joined Cases C-634/21 and C-26/22) clarified that preparatory acts may constitute “decisions” under Article 22 where automated results are heavily relied upon by human decision-makers (CJEU, 2023). The Court confirmed that Article 22 safeguards cannot be circumvented through nominal human review lacking genuine, independent assessment. - Application to DPP Smart Contracts: The SCHUFA ruling has direct implications for DPP smart contracts. Where automated execution determines outcomes that significantly affect individuals, such as restricting access to repair documentation or triggering customs holds, Article 22 GDPR is likely to apply (CJEU, 2023). - EDPB Blockchain Guidelines: The EDPB’s April 2025 Guidelines 02/2025 on blockchain technologies emphasise that organisations cannot rely on blockchain immutability to bypass GDPR obligations (EDPB, 2025). While they do not explicitly state that “smart contract execution” always constitutes automated decision-making under Article 22, the guidance underscores that any automated process producing significant effects must be designed with data-protection safeguards in mind. - Transparency Obligations: GDPR Articles 13-14 require controllers to inform data subjects about automated decision-making, including “meaningful information about the logic involved” and “the significance and envisaged consequences” (European Union, 2016a). These apply to DPP smart contracts processing personal data, necessitating explainability mechanisms to ensure transparency and accountability. Cyber Resilience Act and Product Safety Regulation (EU) 2024/2847 establishes horizontal cybersecurity requirements for “products with digital elements” (European Union, 2024c). While the legislation does not explicitly list DPP systems or smart contracts, many implementations of these - when constituted as software or combined hardware-software modules made available on the EU market and connected to networks - may fall within its scope. Whether they qualify will depend on the concrete classification of the product or service under the Cyber Resilience Act (CRA). - Essential Cybersecurity Requirements: Annex I requires products to be delivered without known exploitable vulnerabilities, to minimise attack surfaces, and to ensure secure default configurations, data protection, and reliable update mechanisms (European Union, 2024). Smart contracts containing known vulnerabilities would be incompatible with these essential requirements. - Vulnerability Handling: Article 11 requires manufacturers to find, record, and fix security weaknesses throughout a product’s life (European Union, 2024). For blockchain-based smart contracts, this means including ways to update the code, such as using proxy systems or carefully managed redeployments, so that flaws can be corrected even though the blockchain itself cannot be changed. - Conformity Assessment: Articles 24-30 establish conformity assessment procedures, requiring third-party evaluation by notified bodies for products classified as critical under the Cyber Resilience Act (European Union, 2024). DPP implementations that meet this threshold would therefore undergo independent conformity checks. Product Liability and Consumer Protection The revised Product Liability Directive (EU) 2024/2853 broadens strict liability to cover defective products with digital elements, including software and updates (European Commission, 2024). Article 6 defines a defect as a failure to provide the safety that the public is entitled to expect. For DPP smart contracts, such defects may arise from security vulnerabilities, coding errors, or breaches of regulatory requirements. - Liability Allocation: Article 7 makes manufacturers, importers, and other economic operators liable for damage caused by defective products (European Commission, 2024). In the context of DPP smart contracts, liability questions arise where third-party developers, deployers, or registry operators are involved. The directive anticipates situations of shared responsibility, with multiple actors potentially liable depending on contractual roles and fault attribution. - Consumer Protection: The Directives on unfair commercial practices (European Commission, 2024) and unfair contract terms (European Union, 1993) apply to DPP systems that engage consumers. Smart contracts embedding unfair terms or misleading practices may be deemed unenforceable under EU consumer-protection law. Trade Secrets and Confidentiality Directive (EU) 2016/943 protects trade secrets from unlawful acquisition, use, or disclosure (European Commission, 2024). DPP systems must balance transparency obligations with the protection of confidential business information. Smart-contract logic itself may qualify as a trade secret, creating tension with legal requirements for transparency and explainability. - Differentiated Access: Article 13 establishes role-based access to product-passport data, balancing confidentiality and transparency. Access may range from public to restricted and authority-only tiers, which smart contracts must enforce precisely. - Confidentiality Obligations: Data Act Article 5 prohibits unauthorized use or disclosure of trade secrets in data sharing (European Union, 2023). Smart contracts must enforce safeguards such as encryption and access controls. The tension between transparency and trade secret protection remains unresolved. eIDAS and Electronic Signatures Regulation (EU) No 910/2014 (eIDAS) establishes a legal framework for electronic identification and trust services (European Union, 2011). DPP systems rely on electronic signatures and seals to authenticate data sources and ensure integrity. - Electronic Signatures: Article 25 confirms that electronic signatures cannot be denied legal effect solely because they are electronic. Smart contracts verifying signatures for access control or data validation must recognize eIDAS-compliant signatures. - Qualified Electronic Seals: Articles 35-36 establish qualified electronic seals for legal entities, providing high assurance of data origin and integrity. Smart contracts could verify seals before accepting data into DPP registries, enabling automated authenticity verification. International Legal Frameworks - UNCITRAL Model Law on Automated Contracting (MLAC): Adopted July 2024, MLAC provides a functional equivalence approach, ensuring contracts formed or performed via automated systems are not denied legal effect solely for that reason (UNCITRAL, 2024). This supports legal certainty for DPP smart contracts in adopting jurisdictions. - UNIDROIT Digital Assets Principles (DAPL): Adopted May 2023, DAPL establishes frameworks for proprietary rights in digital assets (UNIDROIT, 2023). While DPP data is typically informational rather than a “digital asset,” DAPL’s treatment of control as equivalent to possession informs DPP data governance. - UNCITRAL Model Law on Electronic Transferable Records (MLETR): Adopted July 2017, MLETR provides functional equivalence for electronic transferable records (UNCITRAL, 2017). Its approach to control and transfer informs mechanisms for transferring DPPs alongside products. Automated Access Control Smart contracts can automate access control to DPP data based on requester identity, role, and purpose. For example, when a repairer requests technical documentation, the smart contract verifies credentials against ESPR Article 13’s access tiers and grants or denies access automatically. This automation eliminates manual verification, enabling real-time access at scale for scenarios like customs clearance or consumer QR code scans (European Union, 2024). However, wrongful denial risks violating legal rights, for instance, denying a repairer access required under the Right to Repair Directive infringes their rights. If such denial significantly impacts business, GDPR Article 22 applies, requiring human review and contestability. Five essential safeguards emerge: clear access control rules aligned with ESPR Article 13; logging of access decisions; human review for contested denials; explanation functionality; and secure authentication using eIDAS-compliant mechanisms (European Union, 2011). Automated Supply Chain Data Aggregation Smart contracts can automatically update DPP records as products move through supply chains, adding data such as carbon footprints or material composition. This reduces manual entry and errors while enabling real-time tracking across complex multi-tier networks, as shown in Global Battery Alliance pilots (Global Battery Alliance, 2024). Legal risks include data-quality and verification issues: incorrect inputs can propagate through the chain, creating uncertainty over liability among data providers, deployers, and technology vendors (European Commission, 2024). Trade-secret protection and GDPR compliance add further complexity. Safeguards include role-based access control consistent with ESPR Article 13, audit logging, human review for contested entries, explanation functions, and eIDAS-compliant authentication. Automated Compliance Verification Smart contracts can verify DPP data against regulatory requirements, flagging non-compliance, for example, checking battery passport completeness per Annex XIII (European Union, 2023b). This enables real-time compliance enforcement, reducing market-surveillance burdens and allowing economic operators to correct issues before market entry. However, false positives or negatives carry serious consequences, including denial of market access or regulatory failure. Where automated decisions have significant effects, GDPR Article 22 may apply, requiring human oversight and contestability (CJEU, 2023; EDPB, 2025). The CRA (European Union, 2024) mandates robust cybersecurity for products with digital elements to prevent manipulation. Safeguards include data validation, human review, confidentiality protections, clear GDPR role allocations, and comprehensive audit trails. Automated Circular Transactions Smart contracts can automate circular economy transactions such as deposit-return schemes, extended producer responsibility payments, and recycling incentives. For instance, upon verified product return, a smart contract could refund deposits or credit incentives. This automation reduces administrative overhead and enables instant settlements, potentially boosting participation (European Parliament, 2024). Legal risks include payment errors and contract law questions about whether smart contracts constitute binding contracts or mere performance mechanisms (UNCITRAL, 2024). Consumer protection laws apply, and product liability may arise from malfunctions (European Commission, 2024). Safeguards include human review before enforcement, explanations with regulatory references, appeal mechanisms, logic validation, and cybersecurity measures. Automated Lifecycle Event Recording Smart contracts can record lifecycle events - repairs, refurbishments, ownership transfers, end-of-life processing - updating DPPs with event details, timestamps, and actor identities. This supports real-time enforcement and shifts market surveillance from ex-post penalties to ex-ante prevention (European Union, 2024). Legal risks mirror those in compliance verification. Integration with eIDAS electronic signatures ensures authenticity and non-repudiation (European Union, 2011). GDPR compliance requires careful handling of personal data, possibly necessitating off-chain storage with on-chain hashes (EDPB, 2025). Safeguards include transparent logic, dispute resolution mechanisms, consumer protection compliance, secure payment infrastructure, and liability insurance. Accountability Framework for DPP Smart Contracts GDPR Articles 13-14 require controllers to provide data subjects with “meaningful information about the logic involved” in automated decision-making (European Union, 2016a). For DPP smart contracts processing personal data, this creates explainability obligations. However, the precise level of detail required remains uncertain. Must controllers disclose actual code, or is a high-level description sufficient? The Data Act’s Article 36 requires legal consistency but does not explicitly mandate explainability (European Union, 2023), leaving a gap for DPP smart contracts outside GDPR’s scope. Technical complexity and proprietary trade secrets complicate explanations. To balance transparency and confidentiality, the study proposes explainability mechanisms such as plain language summaries of logic and criteria, decision logs recording inputs, outputs, and intermediate steps, visualization tools, documentation of external data sources, and version control to track updates. GDPR Article 22(3) mandates data subjects’ rights to human intervention, to express views, and to contest decisions (European Union, 2016a). The SCHUFA case stresses that human review must be meaningful, not nominal (CJEU, 2023). Furthermore, the EDPB’s April 2025 blockchain guidelines emphasize that blockchain immutability does not excuse non-compliance: controllers remain responsible even after smart contract execution (EDPB, 2025). Therefore, DPP smart contracts must incorporate contestability mechanisms from the outset. Design patterns enabling contestability include pause mechanisms before final execution; override functions for authorized actors; dispute resolution smart contracts; off-chain appeals with on-chain recording; and time delays allowing human review. Human oversight should be proportional: low-stakes decisions may require minimal oversight, while high-stakes decisions demand robust mechanisms. The revised Product Liability Directive (EU) 2024/2853 holds manufacturers and economic operators liable for defective products, including digital elements (European Commission, 2024). When DPP smart contracts malfunction, liability questions arise among developers, deployers, registry operators, and blockchain providers. The Directive does not clarify liability allocation in multi-party smart contract systems. Contract law principles apply to breaches of contractual obligations implemented by smart contracts, but allocation among multiple parties remains unclear. Liability gaps and regulatory silence on smart contract failures create uncertainty that may deter investment. Insurance could mitigate financial risks, but markets for smart contract risks are nascent. Standardized risk assessments and actuarial data are needed. Liability should be allocated according to control and responsibility: developers would be liable for code defects; deployers for configuration errors and misuse; registry operators for infrastructure failures; and blockchain providers would bear limited liability similar to that of internet service providers. Clear contractual arrangements are essential. Open standards are vital for interoperability, security, and accountability. Standards should cover smart contract interfaces, security practices, explainability formats, audit trails, testing, and conformity assessment. CEN/CENELEC Joint Technical Committee 24 is developing DPP standards (CEN/CENELEC, 2025); smart contract standards should integrate into this work to avoid fragmentation. Moreover, ISO’s ongoing work on DPP principles (ISO/PWI 25534-1) (ISO, 2024) supports global interoperability. Also, the Cyber Resilience Act mandates conformity assessments for products with digital elements (European Union, 2024). Critical DPP smart contracts may require third-party assessment. Voluntary certification schemes could promote high-quality smart contracts, covering compliance with Data Act Article 36, GDPR safeguards, cybersecurity, explainability, and security audits. This depicts the integrated structure of technical, legal, and governance components across six distinct layers. Each layer represents a critical dimension of accountability, illustrating their interconnections to ensure comprehensive governance and compliance within smart contract operations. Accordingly, this framework highlights the multi-faceted approach necessary to maintain transparency, responsibility, and trust in DPP ecosystems. This framework integrates legal requirements with technical and governance processes to ensure DPP smart contracts are accountable, transparent, and lawful. Case Studies from Battery, Textile, and Electronics Sectors The Global Battery Alliance’s 2024 pilots involved 10 consortia representing 80% of global EV battery manufacturing capacity (Global Battery Alliance, 2024). These pilots tested battery passport data collection, aggregation, and sharing across multi-tier supply chains. Data collection proved more challenging than expected. Tier 2 and 3 suppliers often lack digital infrastructure, making manual data entry error-prone and time-consuming. Data quality and verification remain critical challenges, indicating that smart contracts cannot assume input data accuracy and that validation mechanisms are essential. Verification and trust require robust mechanisms. Pilots explored third-party audits, blockchain tamper-evidence, and cross-validation. No single approach sufficed, suggesting verification must be tailored to data types and risks. Governance and access control proved complex. Economic operators expressed concerns about confidential information disclosure. Clear governance frameworks specifying access conditions are essential (Pohlmann et al., 2020). Smart contracts automating access control must implement these precisely to avoid violating trade secrets or legal rights. These lessons underscore that automated data aggregation via smart contracts is feasible but demands careful design, validation, human oversight, and governance frameworks, aligning with GDPR, Data Act, and trade secret requirements. A 2024 European Parliament study involving 81 stakeholders proposed a three-phase textile DPP deployment (European Parliament, 2024). Textile supply chains are highly fragmented, with numerous tiers and frequent sourcing changes, complicating automated data aggregation. Each added tier increases risks of data errors and verification challenges. Consumer privacy concerns are prominent. Textile DPPs may include purchasing behavior and preferences. Stakeholders agree on strong privacy protections, requiring careful data structuring and access controls. Smart contracts must prevent inadvertent personal data disclosure, aligning with GDPR principles of data minimization and purpose limitation (European Union, 2016a). The phased deployment, minimal DPP by 2027, advanced by 2030, and full circular by 2033, allows learning and risk reduction, consistent with the proportionality principle. These insights suggest smart contract deployment should start with low-stakes use cases (e.g., public information access) before advancing to high-stakes automation (e.g., compliance verification). Privacy-by-design principles must be embedded from the start, echoing EDPB blockchain guidelines (EDPB, 2025). Electronics DPPs support right to repair by providing independent repairers access to technical documentation, spare parts, and diagnostics. Smart contracts can automate access control, balancing repairer needs with manufacturers’ intellectual property protection, directly reflecting the automated access control use case. E-waste management benefits from DPPs by supplying recyclers with composition data, disassembly instructions, and recovery guidance. Smart contracts could automate recycling incentive payments, enhancing collection rates - a circular transaction use case with significant potential. Data security is critical. Electronics DPPs may contain sensitive information like software versions and vulnerability disclosures. Unauthorized access risks exploitation. Smart contracts must enforce robust authentication and authorization, complying with Cyber Resilience Act security requirements (European Union, 2024). This sector highlights that DPP automation is not only a data governance challenge but also a cybersecurity imperative. Discussion This section interprets findings from sections 4-7, focusing on three themes: the tension between automation efficiency and legal accountability, the adequacy of existing EU legal frameworks, and the path forward for responsible DPP smart contract deployment. The findings reveal a fundamental tension: while smart contracts enhance efficiency by processing millions of transactions without human intervention, they also diminish oversight, increase the risk of error propagation, and challenge contestability when decisions are automatic and irreversible. This suggests that while automation can streamline circular economy processes, it simultaneously introduces risks that could undermine trust and legal compliance if not carefully managed. This tension is not unique to DPPs but reflects broader algorithmic governance challenges in credit scoring, employment screening, and content moderation. The EU’s approach prioritizes accountability, emphasizing human oversight, contestability, and rights protection over pure efficiency. The implications extend beyond DPPs, highlighting a governance paradigm that insists on embedding human judgment within automated systems to safeguard fundamental rights. The SCHUFA case (CJEU, 2023) and EDPB blockchain guidelines (EDPB, 2025) make clear that technical constraints like blockchain immutability cannot justify legal non-compliance. Critically, this reveals that technological design must be subordinate to legal and ethical norms, reinforcing the primacy of accountability in sustainability governance. Consequently, DPP smart contracts must be designed from the outset to enable contestability, human review, and data subject rights-even if this reduces efficiency or complicates technical design. Practically, developers must balance speed and cost optimization with explainability, contestability, and human oversight. This dual optimization is technically demanding but legally essential. This suggests that innovation in the circular economy must incorporate legal safeguards as integral design parameters rather than afterthoughts. The integration of automation through DPP smart contracts in sustainability governance introduces complex cultural and ethical trust considerations that shape stakeholder acceptance within the EU circular economy. Consumers may exhibit skepticism toward algorithmic decision-making absent transparent, culturally sensitive frameworks that affirm data integrity and equitable outcomes. Producers face ethical imperatives to ensure that automated compliance mechanisms do not obscure accountability or marginalize artisanal practices incompatible with rigid coding. Regulators must balance technological efficiency with inclusivity, fostering trust by embedding normative values that resonate across diverse cultural contexts. Ultimately, the ethical legitimacy of automated DPP smart contracts hinges on their capacity to align with shared sustainability goals while respecting pluralistic stakeholder perspectives, thereby reinforcing trust as a foundational pillar of circular economy governance. Strengths include the Data Act’s Article 36 essential requirements addressing robustness and access control (European Union, 2023), GDPR Article 22’s protections against harmful automated decisions (European Union, 2016a), the Cyber Resilience Act’s cybersecurity requirements (European Union, 2024), and the revised Product Liability Directive’s extension to digital elements (European Commission, 2024). Together, these create a multi-layered protective framework that reflects the EU’s commitment to embedding sustainability and rights protection within digital governance. Table 2. Analysis of Legal Gaps and Recommended Mitigations for DPP Smart Contracts. Legal Gap Current Status Impact Recommended Mitigation 1. Limited Scope of Data Act Article 36 Applies only to smart contracts used in Data Act data sharing agreements, not DPP smart contracts generally Economic operators uncertain whether Article 36 requirements apply to their DPP smart contracts ESPR delegated acts should extend Data Act Article 36 essential requirements to all DPP smart contracts 2. Unclear Article 22 Application GDPR Article 22 prohibits automated decision-making with legal/significant effects, but application to specific DPP use cases unclear Risk of non-compliance or over-cautious avoidance of beneficial automation Commission guidance clarifying when DPP smart contracts trigger Article 22 and specifying required safeguards 3. Lack of Explainability Requirements Neither Data Act nor GDPR explicitly requires explainability for smart contracts Transparency obligations uncertain; risk of opaque automated systems ESPR delegated acts should mandate explainability mechanisms (plain-language descriptions, decision logs, audit trails) 4. Uncertain Liability Allocation Product Liability Directive extends to digital elements but does not clearly allocate liability for smart contract failures in multi-party systems Deters investment; leaves affected parties without clear remedies Commission guidance on liability allocation, clarifying developer, deployer, and data provider responsibilities 5. Absence of Conformity Assessment No conformity assessment requirements for DPP smart contracts, unlike Cyber Resilience Act's framework for products with digital elements No independent verification of compliance with legal and technical requirements ESPR delegated acts should establish conformity assessment for high-risk DPP smart contracts (compliance verification, safety-critical access control) 6. Blockchain-GDPR Tension EDPB confirms blockchain immutability not an excuse for non-compliance, but technical solutions for GDPR rights (erasure, rectification) on blockchain unclear Risk of non-compliance or avoidance of blockchain solutions Technical standards for GDPR-compliant blockchain architectures; guidance on permissioned blockchains and off-chain data storage 7. Trade Secret Protection Gaps DPP access requirements may conflict with trade secret protection; no clear guidance on balancing transparency and confidentiality Risk of excessive disclosure or insufficient transparency ESPR delegated acts should specify criteria for restricting access to confidential business information while ensuring necessary transparency 8. Lack of SME Support Complex legal and technical requirements may disadvantage SMEs lacking resources for compliance Market concentration; reduced SME participation in circular economy Commission and Member State technical assistance, guidance, and financial support for SME DPP smart contract compliance Note: This table synthesizes findings from sections 4-6 of the article, identifying critical legal gaps where existing EU law provides insufficient guidance for DPP smart contract deployment and proposing concrete mitigations. Source: Authors' analysis based on EU legal framework review. However, gaps persist. Article 36 applies only to Data Act sharing agreements, excluding broader DPP smart contracts; ESPR delegated acts should extend these requirements. Neither the Data Act nor GDPR explicitly mandates explainability for smart contracts, creating transparency uncertainty. Liability allocation for smart contract failures remains unclear, deterring investment. Conformity assessment requirements for DPP smart contracts are absent, unlike the Cyber Resilience Act’s framework. This suggests that while the EU legal architecture is robust in principle, its fragmented and partial application risks regulatory uncertainty that could slow circular economy innovation. Comparatively, the UNCITRAL Model Law on Automated Contracting (UNCITRAL, 2024) adopts a functional equivalence approach, removing barriers but leaving substantive regulation to domestic law. The EU’s prescriptive approach embeds values like data protection and fundamental rights into technology governance. The UNIDROIT Digital Assets Principles (UNIDROIT, 2023) focus on proprietary rights but offer limited guidance for DPP governance. Neither international instrument addresses DPP automation challenges in circular economy contexts. The implications extend beyond the EU, as this prescriptive model may serve as a benchmark for other jurisdictions grappling with digital sustainability governance, emphasizing the integration of rights and accountability in automated systems. A key policy challenge is balancing innovation incentives with regulatory protection. Overly prescriptive rules risk stifling innovation and delaying circular economy benefits; insufficient regulation risks harmful automation, undermining trust and creating liability. This suggests that regulatory frameworks must be adaptive and calibrated to evolving technological and market realities. The textile sector’s phased deployment model (European Parliament, 2024) offers a way to manage this balance, starting with low-stakes use cases to enable learning before high-stakes automation. Regulatory sandboxes could facilitate controlled testing under supervision, generating evidence to inform regulation. This approach reflects a pragmatic governance strategy that fosters innovation while safeguarding sustainability goals. Standards and certification are critical. Open standards promote interoperability and reduce costs; certification differentiates high-quality implementations. Accelerated, well-resourced standardization by CEN/CENELEC (ISO, 2024; CEN/CENELEC, 2025) and ISO (ISO, 2024) is essential. Without standards, DPP smart contracts risk becoming proprietary silos, undermining ESPR’s interoperability goals. This reveals that governance mechanisms extending beyond law, such as technical standardization, are vital for realizing circular economy ambitions. - Policymakers: Urgent legal clarity is needed. With battery passports mandatory from February 2027 (European Union, 2023b), guidance on Article 22 application, liability, and conformity assessment is critical. Priorities include clarifying Article 22’s scope, incorporating Data Act Article 36 into ESPR delegated acts, establishing liability frameworks, and supporting standardization. Delay risks legal uncertainty and slows circular economy progress. This suggests that proactive, coordinated policymaking is essential to avoid bottlenecks in DPP deployment. - Economic Operators : Early adopters face uncertainty but also opportunities. They should conduct Data Protection Impact Assessments (DPIAs), implement human-in-the-loop for high-stakes decisions, adopt secure development and audits, clarify contractual liability, and engage in standardization. Proactive compliance can confer competitive advantage. This implies that responsible innovation can be a market differentiator in sustainability transitions. - Technology Providers : Significant market opportunities exist for legally compliant, user-friendly smart contract solutions. Prioritizing explainability, contestability, and security will be key. Legal expertise must be integrated from design onward. This reveals a growing demand for interdisciplinary collaboration between technologists and legal experts. - Standard-Setting Bodies : Developing open standards for smart contract interfaces, explainability, and audit trails is vital. Multi-stakeholder participation, including SMEs, civil society, and consumer representatives, is essential to ensure diverse perspectives and avoid dominance by large providers. This suggests that inclusive governance mechanisms are critical to equitable and sustainable circular economy outcomes. The DPP smart contract challenge exemplifies broader digital governance issues. As automation, AI, and algorithmic decision-making proliferate, societies must address accountability, transparency, and balancing efficiency with human oversight. The EU’s approach - emphasizing legal compliance, data protection, contestability, and human rights - offers a model for responsible automation applicable beyond DPPs. By requiring technical systems to conform to legal and ethical norms, the EU charts a distinctive digital governance path. This suggests that sustainability governance increasingly demands integrated socio-technical frameworks that reconcile innovation with rights protection. Critics argue this imposes compliance costs and reduces competitiveness. Yet, unchecked automation risks undermining trust, enabling discrimination, and triggering liability crises. The EU judges that long-term trust and sustainability require upfront accountability investment. The implications transcend legal compliance, shaping the legitimacy and social acceptance of circular economy technologies. Success depends on timely guidance, adequate resources for standardization and conformity assessment, economic operators’ compliance investment, and effective enforcement. The 2025-2027 period is critical. Successful battery passport deployment could catalyze broader adoption; failure could delay progress and erode confidence. Achieving success demands coordinated action: policymakers clarifying law, operators investing in compliance, providers prioritizing accountability, and standard-setters accelerating interoperability. DPP smart contract deployment is a collective challenge requiring sustained cooperation. This reveals that governance of circular economy technologies must be multi-actor and multi-level, integrating legal, technical, and social dimensions. Conclusions This article has examined the legal implications of automating DPP systems with smart contracts in the EU circular economy. The analysis reveals a complex, evolving legal landscape with significant opportunities and challenges. The ESPR establishes a comprehensive DPP framework covering most EU product categories, with battery passports mandatory from February 2027 (European Union, 2024a ; European Union, 2023b ). DPPs aim to resolve information asymmetries by providing standardized, machine-readable product data throughout lifecycles. Smart contracts offer compelling automation solutions for data governance, supply chain sharing, compliance verification, and circular transactions. The Data Act introduces the first EU smart contract regulation via Article 36, setting essential requirements for robustness, termination, archiving, access control, and legal consistency (European Union, 2023). Yet critical gaps remain, especially regarding explainability, contestability, and liability allocation. GDPR Article 22 protections apply to smart contracts making legally significant determinations, requiring human intervention and appeal mechanisms (CJEU, 2023; EDPB, 2025). EDPB blockchain guidelines confirm that blockchain immutability does not excuse non-compliance with data subject rights (EDPB, 2025). This suggests that while the legal framework is pioneering, it requires refinement to fully address the unique challenges posed by DPP automation in the circular economy. The analysis has identified five critical legal gaps where existing EU law provides insufficient guidance for deploying DPP smart contracts: the unclear application of GDPR Article 22 to DPP use cases, the lack of explainability and contestability requirements in Data Act Article 36, uncertain liability allocation when multiple parties deploy shared smart contracts, the absence of conformity assessment for DPP smart contracts, and the unresolved tension between blockchain immutability and GDPR rights. The research has developed a six-layer accountability framework addressing explainability, contestability, liability, standards, certification, and governance. Drawing on battery, textile, and electronics case studies, the study has distilled practical lessons on data quality, phased deployment, and human oversight. These findings inform the 10-point policy checklist (Section 9.3), offering concrete recommendations for legislators, standard-setters, and operators to ensure DPP smart contracts are developed to be accountable, contestable, and lawful. Declarations Funding This research received no external funding. Data Availability Statement Funding This research received no external funding. Data Availability Statement This study is a legal‑doctrinal and comparative analysis based exclusively on publicly available EU legislation, official guidance, and case law. No new datasets were generated or analysed. A reproducibility package is provided as Supplementary Data 1 (“Data and Materials Package”), including: (i) a table of all primary sources used with stable direct URLs (EUR‑Lex/ELI, Curia, and EDPB); (ii) the operational definitions used to code legal requirements (e.g., accountability, contestability, termination, auditability); and (iii) the provision‑to‑framework mapping matrix underpinning the Results and Discussion. Primary sources are accessible via the direct URLs listed in Supplementary Data 1 and here for convenience: ESPR Regulation (EU) 2024/1781 (https://eur-lex.europa.eu/eli/reg/2024/1781/oj/eng); Data Act Regulation (EU) 2023/2854 (https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=OJ%3AL_202302854); GDPR Regulation (EU) 2016/679 (https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32016R0679); EDPB Guidelines 02/2025 on blockchain technologies (https://www.edpb.europa.eu/system/files/2025-04/edpb_guidelines_202502_blockchain_en.pdf); and CJEU judgment C‑634/21 SCHUFA (https://curia.europa.eu/juris/document/document.jsf?docid=280426&doclang=EN). Conflicts of Interest The author declares no conflicts of interest. Ethics approval and consent to participate : Not applicable. This study is based on doctrinal and comparative analysis of publicly available legal texts, regulations, policy documents, and secondary literature. It did not involve human participants, animals, or the collection of personal data. Conflicts of Interest The author declares no conflicts of interest. Ethics approval and consent to participate : Not applicable. This study is based on doctrinal and comparative analysis of publicly available legal texts, regulations, policy documents, and secondary literature. It did not involve human participants, animals, or the collection of personal data . References Abedi, F., Saari, U., Hakola, L., 2024. Implementation and Adoption of Digital Product Passports: A Systematic Literature Review. Tampere University, Tampere, Finland. Adisorn, T., Tholen, L., Götz, T., 2021. Towards a Digital Product Passport Fit for Contributing to a Circular Economy. Energies, 14(8), 2289. https://doi.org/10.3390/en14082289. Agrawal, T.K., Kumar, V., Pal, R., Wang, L., Chen, Y., 2021. Blockchain-based framework for supply chain traceability: A case example of textile and clothing industry. Computers & Industrial Engineering, 154, 107130. https://doi.org/10.1016/j.cie.2021.107130. Allen, D.W.E., Lane, A.M., Poblet, M., 2019. The Governance of Blockchain Dispute Resolution. Harvard Negotiation Law Review, 25, 75–114. Caro, M.P., Ali, M.S., Vecchio, M., Giaffreda, R., 2018. Blockchain-based traceability in Agri-Food supply chain management: A practical implementation. Proceedings of the 2018 IoT Vertical and Topical Summit on Agriculture - Tuscany (IOT Tuscany), pp. 1-4. https://doi.org/10.1109/IOT-TUSCANY.2018.8373021. CEN/CENELEC, 2025c. JTC 24 - Digital Product Passport: Framework and System (Work item under development), CEN/CENELEC, Brussels, Belgium. CEN/CENELEC, 2025a. Digital Product Passport for Printed Circuit Boards Assemblies (Draft CWA), CEN/CENELEC, Brussels, Belgium. CEN/CENELEC, 2025b. Guidelines to Create a Digital Product Passport – Draft CWA. Draft published February 2025. CEN/CENELEC, Brussels, Belgium. Commission Nationale de l’Informatique et des Libertés, 2018. Blockchain and the GDPR: Solutions for a Responsible Use of the Blockchain in the Context of Personal Data. CNIL, Paris, France. Court of Justice of the European Union, 2023. Case C-634/21, SCHUFA Holding AG v Finanzamt Wiesbaden, Judgment of 7 December 2023, ECLI:EU:C:2023:957. Dhillon, V., Metcalf, D., Hooper, M., 2017. Blockchain Enabled Applications: Understand the Blockchain Ecosystem and How to Make it Work for You. Apress, Berkeley, CA. DOI: 10.1007/978-1-4842-3081-7. Djurovic, M., Janssen, A., 2018. The Formation of Blockchain-Based Smart Contracts in the Light of Contract Law. European Review of Private Law, 26(6), 753-771. Dwivedi, V., Norta, A., Wulf, A., Leiding, B., Saxena, S., Udokwu, C., 2021. A Formal Specification Smart-Contract Language for Legally Binding Decentralized Autonomous Organizations. IEEE Access, 9, 76069-76082. https://doi.org/10.1109/ACCESS.2021.3081926. European Commission, 2019. The European Green Deal. COM(2019) 640 final. European Commission, Brussels, Belgium. European Commission, 2020. A New Circular Economy Action Plan. COM(2020) 98 final. European Commission, Brussels, Belgium. European Commission, 2022. Impact Assessment Accompanying the Proposal for a Regulation of the European Parliament and of the Council Establishing a Framework for Setting Ecodesign Requirements for Sustainable Products and Repealing Directive 2009/125/EC. SWD(2022) 82 final. European Commission, Brussels, Belgium, 30 March 2022. European Commission, 2025. Ecodesign for Sustainable Products and Energy Labelling Working Plan 2025-2030. Communication COM(2025) 187 final & Staff Working Document SWD(2025) 112 final. European Commission, Brussels, Belgium, 16 April 2025. European Data Protection Board, 2020. Guidelines 4/2019 on Article 25 - Data Protection by Design and by Default. Version 2.0. EDPB, Brussels, Belgium, October 2020. European Data Protection Board & European Data Protection Supervisor, 2022. Joint Opinion 2/2022 on the Proposal for a Regulation of the European Parliament and of the Council on harmonised rules on fair access to and use of data (Data Act). EDPB-EDPS, Brussels, Belgium, 4 May 2022. European Data Protection Board, 2025. Guidelines 02/2025 on the Processing of Personal Data Through Blockchain Technologies. Adopted 14 April 2025. EDPB, Brussels, Belgium. Available at: https://www.edpb.europa.eu/our-work-tools/documents/public-consultations/2025/guidelines-022025-processing-personal-data_en (accessed 29 October 2025). European Parliament, 2024. Digital Product Passport for Textiles. Study for the IMCO Committee. PE 757.808. European Parliament, Brussels, Belgium. European Union, 1993. Council Directive 93/13/EEC of 5 April 1993 on unfair terms in consumer contracts (Unfair Terms Directive). Off. J. Eur. Communities 1993, L 95, pp. 29-34. European Union, 2005. Directive (EU) 2005/29/EC of the European Parliament and of the Council of 11 May 2005 concerning unfair business-to-consumer commercial practices in the internal market. Off. J. Eur. Union 2005, L 149, 22-39. European Union, 2016a. Directive (EU) 2016/943 of the European Parliament and of the Council of 8 June 2016 on the protection of undisclosed know-how and business information (trade secrets). Off. J. Eur. Union 2016, L 157, 1-18. European Union, 2016b. Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation, GDPR). Official Journal of the European Union, L 119, 1–88. European Union, 2019. Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019 on ENISA and on information and communications technology cybersecurity certification (Cybersecurity Act). Off. J. Eur. Union 2019, L 151, 15-69. European Union, 2023a. Regulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assets (MiCA). Off. J. Eur. Union 2023, L 150, 40-205. European Union, 2023b. Regulation (EU) 2023/1542 of the European Parliament and of the Council of 12 July 2023 concerning batteries and waste batteries, repealing Directive 2006/66/EC and Regulation (EU) No 2019/1020 as regards market surveillance. Off. J. Eur. Union 2023, L 191, 1-135. European Union, 2023c. Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data (Data Act). Off. J. Eur. Union 2023, L 305, 1-88. European Union, 2024a. Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products (Product Liability Directive). Off. J. Eur. Union 2024, L 2853, 1-22. European Union, 2024b. Regulation (EU) 2024/1781 of the European Parliament and of the Council of 13 June 2024 establishing a framework for setting ecodesign requirements for sustainable products (ESPR). Off. J. Eur. Union 2024, L, 1-106. European Union, 2024c. Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) No 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act). Off. J. Eur. Union 2024, L 2847, 1-115. European Union Agency for Cybersecurity, 2023. Baseline Security Recommendations for IoT in the context of Critical Information Infrastructures. ENISA, Athens, Greece, November 2017. European Union Agency for Cybersecurity, 2023. Good Practices for Security of IoT – Secure Software Development Lifecycle. ENISA, Athens, Greece, 19 November 2019. Available at: https://www.enisa.europa.eu/publications/good-practices-for-security-of-iot-1 (accessed 2 November 2025). European Union Agency for Cybersecurity, 2023. Good Practices for Supply Chain Cybersecurity. ENISA, Athens, Greece, 13 June 2023. Available at: https://www.enisa.europa.eu/publications/good-practices-for-supply-chain-cybersecurity (accessed 2 November 2025). European Union Agency for Cybersecurity, 2023. Artificial Intelligence Cybersecurity Challenges - Threat Landscape for AI. ENISA, Athens, Greece. Available at: https://www.enisa.europa.eu/publications/artificial-intelligence-cybersecurity-challenges (accessed 2 November 2025). European Union Agency for Cybersecurity, 2025. Technical Implementation Guidance – NIS2 Directive. ENISA, Athens, Greece, 26 June 2025. Available at: https://www.enisa.europa.eu/publications/nis2-technical-implementation-guidance (accessed 2 November 2025). German Data Protection Conference (DSK). Guidance on the Use of Artificial Intelligence and Compliance with Data Protection Law. DSK, Germany, 6 May 2024. Global Battery Alliance, 2024. Battery Passport 2024 Pilots: Progress Report. GBA, Geneva, Switzerland. Goldenfein, J., Leiter, A., 2018. Legal Engineering on the Blockchain: “Smart Contracts” as Legal Conduct. Law Crit., 29(2), 141–149. https://doi.org/10.1007/s10978-018-9224-0. Götz, T., Berg, H., Jansen, M., Adisorn, T., Cembrero, D., Markkanen, S., Chowdhury, T., 2022. Digital Product Passport: The Ticket to Achieving a Climate Neutral and Circular European Economy? Wuppertal Institute: Wuppertal, Germany. International Organization for Standardization (ISO), 2024. ISO/PWI 25534-1 – Digital Product Passport: Overview and Fundamental Principles (Work item under development). Geneva, Switzerland, April 2025. International Organization for Standardization (ISO), 2014. ISO/IEC 15459-1:2014 - Information technology - Automatic identification and data capture techniques - Unique identification - Part 1: Individual transport units. Geneva, Switzerland. International Organization for Standardization (ISO), 2015. ISO/IEC 18004:2015 - Information technology - Automatic identification and data capture techniques - QR Code bar code symbology specification. International Organization for Standardization, Geneva, Switzerland. Kumar, N.M., Chopra, S.S., 2022. Leveraging Blockchain and Smart Contract Technologies to Overcome Circular Economy Implementation Challenges. Sustainability, 14(5), 9492. https://doi.org/10.3390/su14159492. Levy, K.E., 2017. Book-Smart, Not Street-Smart: Blockchain-Based Smart Contracts and the Social Workings of Law. Engag. Sci. Technol. Soc., 3, 1-15. https://doi.org/10.17351/ests2017.107. Pohlmann, C.R., Scavarda, A.J., Alves, M.B., Korzenowski, A.L., 2020. The role of the focal company in sustainable development goals: A Brazilian food poultry supply chain case study. J. Clean. Prod., 245, 118798. https://doi.org/10.1016/j.jclepro.2019.118798. Raskin, M., 2017. The Law and Legality of Smart Contracts. Georgetown Law Technology Review, 1, 305-341. European Union, 2014. Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 July 2014 on electronic identification and trust services for electronic transactions in the internal market (eIDAS Regulation). Off. J. Eur. Union 2014, L 257, 73-114. Rizos, V., Urban, P., 2024. Implementing the EU Digital Battery Passport: Opportunities and Challenges for Battery Circularity. CEPS In-Depth Analysis, 05. Centre for European Policy Studies, Brussels, Belgium. Available at: https://www.ceps.eu/ceps-publications/implementing-the-eu-digital-battery-passport/ (accessed 3 November 2025). Sopha, B.M., Purnamasari, D.M., Ma’mun, S. Barriers and Enablers of Circular Economy Implementation for Electric-Vehicle Batteries: From Systematic Literature Review to Conceptual Framework. Sustainability, 14(10), 6359. https://doi.org/10.3390/su14106359. UK Jurisdiction Taskforce (UKJT). Legal Statement on Cryptoassets and Smart Contracts. LawTech Delivery Panel, London, UK, 18 November 2019. UNCITRAL, 2017. Model Law on Electronic Transferable Records (MLETR). United Nations Commission on International Trade Law, Vienna, Austria, 13 July 2017. UNCITRAL, 2025. Model Law on Automated Contracting. United Nations Commission on International Trade Law, Vienna, Austria, 11 July 2024. UNIDROIT, 2023. Principles on Digital Assets and Private Law. International Institute for the Unification of Private Law, Rome, Italy. United Nations Economic Commission for Europe (UNECE) & International Organization for Standardization (ISO). Joint Initiative on Digital Product Passport (launch announcement). UNECE, Geneva, Switzerland, 08 April 2025. Available at: https://unece.org/digitalization/news/unece-and-iso-launch-joint-initiative-digital-product-passport-advance (accessed 29 October 2025). Von Hafe, F., Wagle, Y., Guede-Fernández, F., Giordano, A.P., Silva, L., Azevedo, S., 2025. Legal Frameworks for Blockchain Applications: A Comparative Study with Implications for Innovation in Europe. Frontiers in Blockchain, 8, 1655230. https://doi.org/10.3389/fbloc.2025.1655230. Walden, J., Steinbrecher, A., Marinkovic, M., 2021. Digital Product Passports as Enabler of the Circular Economy. Sustainability, 93(11), 1717-1727. https://doi.org/10.1002/cite.202100121. Wicaksono, H., Mengistu, A., Bashyal, A., Fekete, T., 2025. Digital Product Passport (DPP) Technological Advancement and Adoption Framework: A Systematic Literature Review. Procedia Comput. Sci., 253, 2980-2989. https://doi.org/10.1016/j.procs.2025.02.022. Additional Declarations No competing interests reported. Supplementary Files SupplementaryData1DataandMaterials.docx Cite Share Download PDF Status: Under Review Version 1 posted Editorial decision: Revision requested 22 Apr, 2026 Reviews received at journal 17 Mar, 2026 Reviews received at journal 11 Mar, 2026 Reviews received at journal 18 Feb, 2026 Reviewers agreed at journal 02 Feb, 2026 Reviewers agreed at journal 26 Jan, 2026 Reviewers agreed at journal 26 Jan, 2026 Reviewers invited by journal 13 Jan, 2026 Editor assigned by journal 13 Jan, 2026 Editor invited by journal 13 Jan, 2026 Submission checks completed at journal 08 Jan, 2026 First submitted to journal 08 Jan, 2026 You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-8397708","acceptedTermsAndConditions":true,"allowDirectSubmit":false,"archivedVersions":[],"articleType":"Article","associatedPublications":[],"authors":[{"id":575033452,"identity":"29c250a9-521a-45cb-a68a-da7c6b88b03e","order_by":0,"name":"Rakan Alrdaan","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAAA2klEQVRIiWNgGAWjYHACxgMMbECKvQHEYSZOD0QLzwHGBhK1SCQQqcW8gfnB4YoyO3lzyTfmDxgqrBMb+A8/wKtF5gCbwcEz55INd87OMWxgOJOe2CCRZoBXiwQDg8HBxjZmxg23gVoY2w4DtTAQ0sL+Aail3n7DzTNALf+AWviPfyCghQdky+HEDTd4gFoagFoYcgjYwsxTcLDh3PHkDWfSCmckHEs3bpPIKcCvhb1948OGsmrbDccPb/jwocZatp//+Aa8WlAjIgGI2fCrHwWjYBSMglFADAAAXTBID30aOX0AAAAASUVORK5CYII=","orcid":"","institution":"University of Tabuk","correspondingAuthor":true,"prefix":"","firstName":"Rakan","middleName":"","lastName":"Alrdaan","suffix":""}],"badges":[],"createdAt":"2025-12-18 17:08:47","currentVersionCode":1,"declarations":"","doi":"10.21203/rs.3.rs-8397708/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-8397708/v1","draftVersion":[],"editorialEvents":[],"editorialNote":"","failedWorkflow":false,"files":[{"id":100378760,"identity":"1c75928c-b53d-4031-a240-2059a186a9c5","added_by":"auto","created_at":"2026-01-16 08:58:09","extension":"docx","order_by":0,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":187366,"visible":true,"origin":"","legend":"","description":"","filename":"manuscript.docx","url":"https://assets-eu.researchsquare.com/files/rs-8397708/v1/e3effbc692604b425a9f251d.docx"},{"id":100373388,"identity":"76f00934-1429-4283-9b31-c43eee194586","added_by":"auto","created_at":"2026-01-16 08:14:13","extension":"json","order_by":1,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":4837,"visible":true,"origin":"","legend":"","description":"","filename":"3f13f4c5d77041268cdd9e617c135ba1.json","url":"https://assets-eu.researchsquare.com/files/rs-8397708/v1/8d84424c6e8a0f5fc9948ed2.json"},{"id":100355055,"identity":"0200178b-fa65-4cd8-af25-31d47b3d84ec","added_by":"auto","created_at":"2026-01-16 05:34:30","extension":"docx","order_by":2,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":39786,"visible":true,"origin":"","legend":"","description":"","filename":"SupplementaryData1DataandMaterials.docx","url":"https://assets-eu.researchsquare.com/files/rs-8397708/v1/5f82855a0f31394a0b4f4624.docx"},{"id":100355061,"identity":"0d1fbc20-17bc-4e2e-9d57-70e3cae2b0c8","added_by":"auto","created_at":"2026-01-16 05:34:30","extension":"xml","order_by":3,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":153980,"visible":true,"origin":"","legend":"","description":"","filename":"3f13f4c5d77041268cdd9e617c135ba11enriched.xml","url":"https://assets-eu.researchsquare.com/files/rs-8397708/v1/e4d93604c02bef7d2ebde7b4.xml"},{"id":100378057,"identity":"a38319c1-33fe-4dc1-a24d-69564bc0a7f6","added_by":"auto","created_at":"2026-01-16 08:49:39","extension":"png","order_by":4,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":154192,"visible":true,"origin":"","legend":"","description":"","filename":"floatimage1.png","url":"https://assets-eu.researchsquare.com/files/rs-8397708/v1/6c6805346785116c81c115b8.png"},{"id":100355059,"identity":"a598d2da-1422-4ed7-827b-a98d270ee10a","added_by":"auto","created_at":"2026-01-16 05:34:30","extension":"png","order_by":5,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":49835,"visible":true,"origin":"","legend":"","description":"","filename":"Onlinefloatimage1.png","url":"https://assets-eu.researchsquare.com/files/rs-8397708/v1/bdddadf7700eb606f188691d.png"},{"id":100355063,"identity":"4a28b01d-3e35-4fad-b507-1a0b83a29823","added_by":"auto","created_at":"2026-01-16 05:34:30","extension":"xml","order_by":6,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":151770,"visible":true,"origin":"","legend":"","description":"","filename":"3f13f4c5d77041268cdd9e617c135ba11structuring.xml","url":"https://assets-eu.researchsquare.com/files/rs-8397708/v1/ab1139b0b2f13623b9cc4e41.xml"},{"id":100355062,"identity":"375ce0b7-c1e4-4416-80d0-429c69938e16","added_by":"auto","created_at":"2026-01-16 05:34:30","extension":"html","order_by":7,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":162103,"visible":true,"origin":"","legend":"","description":"","filename":"earlyproof.html","url":"https://assets-eu.researchsquare.com/files/rs-8397708/v1/7e16eb0d8432fefc0e2433de.html"},{"id":100373626,"identity":"3428f867-7871-4d3f-922a-02a4edb3f2e8","added_by":"auto","created_at":"2026-01-16 08:15:31","extension":"png","order_by":1,"title":"Figure 1","display":"","copyAsset":false,"role":"figure","size":185492,"visible":true,"origin":"","legend":"\u003cp\u003e\u003cstrong\u003eSix-Layer Accountability Framework for Digital Product Passport (DPP) smart contracts\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eKeywords: \u003cem\u003edigital product passports; smart contracts; circular economy; GDPR; Data Act; EU law; sustainability; automated governance\u003c/em\u003e\u003c/p\u003e","description":"","filename":"floatimage1.png","url":"https://assets-eu.researchsquare.com/files/rs-8397708/v1/3f02e0d49c0bffeda9e4d7e7.png"},{"id":100406130,"identity":"f0b7ded6-96e8-4d7a-bbdc-c0881993e3d3","added_by":"auto","created_at":"2026-01-16 12:43:30","extension":"pdf","order_by":0,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":1199710,"visible":true,"origin":"","legend":"","description":"","filename":"manuscript.pdf","url":"https://assets-eu.researchsquare.com/files/rs-8397708/v1/40a45ed6-52b7-431b-b2e2-7b66675f7376.pdf"},{"id":100355054,"identity":"5eb2d14c-a2f5-41c5-9ee3-6fdeecc024d2","added_by":"auto","created_at":"2026-01-16 05:34:30","extension":"docx","order_by":0,"title":"","display":"","copyAsset":false,"role":"supplement","size":39786,"visible":true,"origin":"","legend":"","description":"","filename":"SupplementaryData1DataandMaterials.docx","url":"https://assets-eu.researchsquare.com/files/rs-8397708/v1/a5339981a14f850a8e1074c3.docx"}],"financialInterests":"No competing interests reported.","formattedTitle":"Automating Accountability: Smart Contracts and the Legal Future of Digital Product Passports in the EU Circular Economy","fulltext":[{"header":"Introduction","content":"\u003cp\u003eThe European Union has set an ambitious goal to achieve climate neutrality by 2050, with the circular economy playing a pivotal role in this transition (European Commission, 2019). This analysis bridges environmental governance, data law, and circular-economy. In June 2024, the EU introduced the Ecodesign for Sustainable Products Regulation (ESPR), which lays out a comprehensive framework for Digital Product Passports (DPPs) (European Union, 2024a). These passports aim to overcome persistent information gaps that have hindered circular business models by providing standardized, machine-readable product data accessible via QR codes or other data carriers throughout a product\u0026rsquo;s lifecycle.\u003c/p\u003e\n\u003cp\u003eLooking ahead, the ESPR framework will extend to cover most product categories sold within the EU. For instance, battery passports will become mandatory starting February 2027 (European Union, 2023b), while textile DPPs are anticipated by 2030 (European Parliament, 2024). This initiative represents an unprecedented digital infrastructure project, engaging millions of economic operators and billions of products. As DPP systems expand, relying on manual data entry, access control, and compliance verification will become impractical. Automation, therefore, shifts from being merely advantageous to absolutely essential.\u003c/p\u003e\n\u003cp\u003eSmart contracts - computer programs that automatically execute agreements when predefined conditions are met - offer promising solutions to automate DPP data governance. The Global Battery Alliance\u0026rsquo;s 2024 pilot projects, encompassing 80% of global electric vehicle battery manufacturing capacity, have demonstrated the practical feasibility of automated sustainability data collection and aggregation (Global Battery Alliance, 2024). Similarly, pilots in the textile industry are exploring blockchain-based traceability combined with smart contract automation for supplier verification and certification. In real-world terms, smart contracts could automatically grant repairers access to technical documentation, flag non-compliant products, or trigger customs clearance processes based on verified DPP data.\u003c/p\u003e\n\u003cp\u003eHowever, this automation raises fundamental legal questions. For example, when a smart contract automatically denies a repairer access to technical documentation, flags a product as non-compliant, or triggers a customs hold due to missing DPP data, who bears responsibility? Can such decisions be challenged? Does the prohibition on automated decision-making under GDPR Article 22 apply (European Union, 2016a)? Moreover, how can transparency be ensured when smart contract logic might be proprietary or technically complex? These concerns are far from theoretical - they strike at the core of how the EU balances efficiency with the protection of fundamental rights.\u003c/p\u003e\n\u003cp\u003eRecent developments have intensified the urgency of these questions. First, the Court of Justice of the European Union\u0026rsquo;s December 2023 ruling in the SCHUFA case clarified that automated credit scoring systems qualify as automated decision-making under Article 22 when their outputs significantly impact individuals (CJEU, 2023). The Court underscored that preparatory acts feeding into human decisions can themselves trigger Article 22 protections if they involve \u0026ldquo;heavy reliance\u0026rdquo; on automated outputs. Second, the European Data Protection Board\u0026rsquo;s April 2025 blockchain guidelines explicitly confirmed that smart contract execution may activate Article 22 protections (EDPB, 2025), emphasizing that blockchain immutability does not exempt data controllers from respecting data subject rights. Reflecting on these developments, it becomes clear that the integration of automation in DPP governance demands careful legal scrutiny to uphold transparency, accountability, and rights protection.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e\u0026nbsp;\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eExamining the existing literature reveals a notable gap. As Djurovic and Janssen point out, most smart contract research concentrates on financial applications, especially cryptocurrency transactions and decentralized finance (Djurovic and Janssen, 2018). Goldenfein and Leiter delve into smart contracts from an abstract legal perspective, exploring the \u0026ldquo;code as law\u0026rdquo; paradigm (Goldenfein and Leiter, 2018). Levy offers a critical viewpoint, arguing that smart contracts are \u0026ldquo;book-smart, not street-smart,\u0026rdquo; as they lack the flexibility and contextual sophistication inherent in legal systems (Levy, 2017).\u003c/p\u003e\n\u003cp\u003eIn contrast, literature on DPPs tends to focus on data requirements and standardization. For example, G\u0026ouml;tz et al. analyze the potential of DPPs to advance climate neutrality and circular economy goals (G\u0026ouml;tz et al., 2022), while Adisorn et al. propose a conceptual framework for DPPs contributing to circular objectives (Adisorn et al., 2021). Walden et al. highlight challenges in data collection, verification, and governance within DPPs (Walden et al., 2021). Yet, these works give limited attention to automation and algorithmic governance.\u003c/p\u003e\n\u003cp\u003eCrucially, no existing scholarship systematically examines how EU law - particularly the Data Act\u0026rsquo;s novel smart contract provisions (Article 36) (European Union, 2023b) and GDPR\u0026rsquo;s automated decision-making protections (Article 22) - applies to DPP smart contracts. This gap is pressing: the Data Act came into force in January 2024; the EDPB adopted blockchain guidelines in April 2025; battery passports become mandatory in February 2027; and ESPR delegated acts are currently under development. The regulatory window to shape DPP smart contract governance is open now.\u003c/p\u003e\n\u003cp\u003eFrom this perspective, while smart contract literature emphasizes enforceability and code determinism rooted in financial contexts, and DPP scholarship foregrounds data disclosure and supply chain traceability, this article bridges these views by demonstrating that DPPs require governance mechanisms - precisely where smart contracts, if properly constrained, can add value while respecting fundamental rights.\u003c/p\u003e\n\u003cp\u003eThis study offers three original contributions. First, it delivers the first comprehensive legal analysis of smart contracts in the DPP context, systematically exploring how Data Act Article 36, GDPR Article 22, ESPR, the Cyber Resilience Act, and related instruments interact. The methodological innovation lies in connecting Data Act Article 36 requirements with specific DPP implementation scenarios - a nexus previously unexplored in legal scholarship.\u003c/p\u003e\n\u003cp\u003eSecond, it identifies critical legal gaps where existing EU law provides insufficient guidance for deploying DPP smart contracts. These include unclear applications of Article 22 to specific use cases (e.g., when automated access control triggers Article 22), absence of explainability requirements tailored to smart contracts, uncertain liability allocation when multiple parties deploy shared smart contracts, and unresolved tensions between blockchain immutability and GDPR data subject rights under Articles 16-17.\u003c/p\u003e\n\u003cp\u003eThird, the study proposes a practical accountability framework proposing a 10-point policy checklist for regulators, standard-setters, and economic operators. This framework balances automation efficiency with human oversight, legal compliance, and fundamental rights protection. The recommendations are grounded in real-world pilot experience and designed for immediate implementation as ESPR delegated acts are drafted.\u003c/p\u003e\n\u003cp\u003eThis article addresses nine core questions:\u003c/p\u003e\n\u003cp\u003e1. What is a Digital Product Passport under the ESPR framework, and how will it operate across product categories and lifecycle stages?\u003c/p\u003e\n\u003cp\u003e2. What legal functions could smart contracts perform for DPPs - and which functions raise heightened legal risks?\u003c/p\u003e\n\u003cp\u003e3. How do smart contracts interact with EU contract law principles, consumer protection, and information duties?\u003c/p\u003e\n\u003cp\u003e4. What governance and accountability models make automated DPP processes auditable, contestable, and lawful?\u003c/p\u003e\n\u003cp\u003e5. How do the Data Act and GDPR allocate roles, rights, and responsibilities over DPP data, particularly when processing is automated?\u003c/p\u003e\n\u003cp\u003e6. What cybersecurity, product safety, and product liability implications arise when compliance logic is partially automated?\u003c/p\u003e\n\u003cp\u003e7. What technical standards and identifiers are needed for cross-border interoperability and market surveillance access?\u003c/p\u003e\n\u003cp\u003e8. What safeguards are needed to avoid dark patterns, exclusion, and discrimination, especially for SMEs and repair markets?\u003c/p\u003e\n\u003cp\u003e9. What realistic implementation paths exist over the next 3-5 years, and what should the EU prioritize in delegated acts and guidance?\u003c/p\u003e\n\u003cp\u003eThe article proceeds as follows: Section 2 reviews relevant literature on circular economy policy, DPP concepts, and smart contract legal frameworks. Section 3 outlines the research methodology, including source selection and analytical framework. Section 4 presents the EU legal architecture for DPPs, examining ESPR, the Data Act, GDPR, and related instruments. Section 5 analyzes five smart contract use cases for DPPs with detailed legal risk assessments. Section 6 develops an accountability framework addressing explainability, contestability, and liability allocation. Section 7 presents case studies from batteries, textiles, and electronics, drawing lessons from real-world pilots. Section 8 discusses the findings and their implications for EU digital governance of circular economy transitions. Finally, section 9 concludes with policy recommendations and future research directions.\u003c/p\u003e"},{"header":"Literature Review","content":"\u003cp\u003eThis review synthesizes four domains of scholarship: circular economy policy and DPP concepts, smart contract legal frameworks, blockchain traceability applications, and sector-specific DPP implementations. Table 2 summarizes the core literature informing this analysis.\u003c/p\u003e\n\u003cp\u003eTable 1. synthesizes key scholarly contributions across four research areas: (1) circular economy policy and Digital Product Passport (DPP) concepts, (2) smart contract legal frameworks, (3) blockchain traceability applications, and (4) sector-specific DPP implementations. Each entry identifies the author(s)/year, focus area, key contribution, and relevance to DPP smart contract automation. The table demonstrates the interdisciplinary nature of the research gap this study addresses, highlighting the fragmentation between technical, legal, and empirical perspectives on automated DPP systems.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eTable 1. Overview of Key Literature Informing the Analysis.\u003c/strong\u003e\u003c/p\u003e\n\u003ctable border=\"1\" cellspacing=\"0\" cellpadding=\"0\"\u003e\n \u003ctbody\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003e\u003cstrong\u003eAuthor(s)/Year\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003e\u003cstrong\u003eFocus Area\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003e\u003cstrong\u003eKey Contribution\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003e\u003cstrong\u003eRelevance to DPP Smart Contracts\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003e\u003cstrong\u003eUNECE, ISO (ISO, 2024; Raskin, 2017)\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eCircular Economy \u0026amp; DPPs\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eInternational standardization efforts to ensure global interoperability of DPPs.\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eStandards critical for cross-border data exchange and legal compliance in automated DPP smart contracts.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003e\u003cstrong\u003eEuropean Parliament (European Parliament, 2024)\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eCircular Economy \u0026amp; DPPs\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eProposed phased textile DPP deployment roadmap (2027-2033).\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eIllustrates sector-specific timelines and challenges for automating DPP data access and verification via smart contracts.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003e\u003cstrong\u003eVarious scholars (G\u0026ouml;tz et al., 2022; Adisorn et al., 2021; Walden et al., 2021)\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eCircular Economy \u0026amp; DPPs\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003ePosition DPPs as essential circular economy infrastructure, focusing on data governance design.\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eHighlights the gap in legal-regulatory analysis for DPP automation relevant to smart contract implementation.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003e\u003cstrong\u003eEU Data Act (European Union, 2023)\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eSmart Contracts \u0026amp; Legal Frameworks\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eProvides the first EU legal definition of smart contracts, technology-neutral and broad.\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eEstablishes legal basis for smart contracts automating DPP data processes, framing regulatory compliance needs.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003e\u003cstrong\u003eUNCITRAL Model Law (UNCITRAL, 2024)\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eSmart Contracts \u0026amp; Legal Frameworks\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eOffers international guidance on automated contracting.\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eSupports harmonization of smart contract legal frameworks applicable to DPP systems across jurisdictions.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003e\u003cstrong\u003eDjurovic \u0026amp; Janssen (Djurovic and Janssen, 2018)\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eSmart Contracts \u0026amp; Legal Frameworks\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eDemonstrate legal uncertainties in blockchain smart contract formation under traditional law.\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eIdentifies legal risks in automating DPP agreements, emphasizing need for clarity in contract formation via smart contracts.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003e\u003cstrong\u003eGoldenfein \u0026amp; Leiter (Goldenfein and Leiter, 2018)\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eSmart Contracts \u0026amp; Legal Frameworks\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eConceptualize smart contracts as \u0026ldquo;legal engineering\u0026rdquo; shifting enforcement to code execution.\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eUnderlines potential and limits of smart contracts for automating DPP compliance and enforcement.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003e\u003cstrong\u003eLevy (Levy, 2017)\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eSmart Contracts \u0026amp; Legal Frameworks\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eCritiques smart contracts as lacking social and contextual legal flexibility.\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003ePoints to challenges in capturing legal gradations in automated DPP smart contracts.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003e\u003cstrong\u003eRaskin (Raskin, 2017)\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eSmart Contracts \u0026amp; Legal Frameworks\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eComprehensive analysis of smart contract validity and enforcement challenges across jurisdictions.\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eHighlights cross-jurisdictional legal complexities relevant to DPP smart contract deployment.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003e\u003cstrong\u003eVon Hafe et al (Von Hafe et al., 2025)\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eSmart Contracts \u0026amp; Legal Frameworks\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eComparative analysis of divergent EU member state approaches to smart contracts.\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eIndicates regulatory fragmentation affecting DPP smart contract harmonization.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003e\u003cstrong\u003eDhillon et al. (Dhillon et al., 2017)\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eBlockchain \u0026amp; Traceability\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eAnalyze governance trade-offs between decentralization, scalability, and regulatory compliance.\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eInforms design of blockchain-based DPP smart contracts balancing technical and legal requirements.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003e\u003cstrong\u003eAllen et al (Allen et al., 2019)\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eBlockchain \u0026amp; Traceability\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003ePropose governance models for blockchain supply chain management emphasizing roles and dispute resolution.\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eProvides frameworks potentially adaptable for DPP smart contract governance and conflict management.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003e\u003cstrong\u003eVarious studies (Kumar et al., 2022; Agrawal et al., 2021; Caro et al., 2018)\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eBlockchain \u0026amp; Traceability\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eDemonstrate blockchain traceability benefits in agribusiness, textiles, and agri-food supply chains.\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eEvidence of blockchain\u0026rsquo;s technical suitability for DPP data integrity and tamper-resistance.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003e\u003cstrong\u003eVarious scholars (ISO, 2024; Raskin, 2017)\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eBlockchain \u0026amp; Traceability\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eIdentify legal challenges of blockchain immutability and GDPR compliance in circular economy contexts.\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eHighlights legal constraints critical for designing compliant DPP smart contracts using blockchain.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003e\u003cstrong\u003eBattery DPP studies (Sopha et al., 2022; Rizos et al., 2024; Abedi et al., 2024; Global Battery Alliance, 2024)\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eSector-Specific DPP Implementation\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eEmpirical analyses of battery DPP pilots reveal data quality, verification, and stakeholder access challenges.\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eIllustrate practical implementation issues that smart contracts must address for effective DPP automation.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003e\u003cstrong\u003eTextile DPP roadmap (European Parliament, 2024)\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eSector-Specific DPP Implementation\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003ePhased deployment plan for textile DPPs with increasing complexity and circularity.\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eProvides sector-specific context for smart contract automation timelines and legal considerations.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003e\u003cstrong\u003eGlobal Battery Alliance (Global Battery Alliance, 2024)\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eSector-Specific DPP Implementation\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eReal-world pilot demonstrating feasibility and challenges of automated sustainability data collection.\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eOffers empirical insights informing smart contract design for data verification and rights management in DPPs.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003e\u003cstrong\u003eAbedi et al. (Abedi et al., 2024)\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eSector-Specific DPP Implementation\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eSystematic review identifying enablers and barriers to DPP adoption.\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 144px;\"\u003e\n \u003cp\u003eHighlights factors influencing smart contract integration in DPP systems.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003c/tbody\u003e\n\u003c/table\u003e\n\u003cp\u003e\u003cem\u003eCircular Economy and Digital Product Passports\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eThe European Green Deal, announced in December 2019, set climate neutrality by 2050 as the EU\u0026rsquo;s overarching objective (European Commission, 2019). The circular economy was identified as a key enabler to decouple economic growth from resource consumption. The second Circular Economy Action Plan, adopted in March 2020, launched a sustainable products initiative to make products more durable, reusable, repairable, and recyclable (European Commission, 2020). It explicitly called for \u0026ldquo;digital product passports\u0026rdquo; to enable information sharing throughout product lifecycles.\u003c/p\u003e\n\u003cp\u003eThe ESPR, adopted in June 2024, operationalizes this vision (European Union, 2024a). It establishes a comprehensive framework for ecodesign requirements and DPPs across product categories (European Commission, 2009). International standardization efforts through UNECE and ISO aim to ensure global interoperability (ISO, 2024; Raskin, 2017). These standards will be critical for cross-border data exchange and market surveillance.\u003c/p\u003e\n\u003cp\u003eRecent scholarship positions DPPs as critical circular economy infrastructure (G\u0026ouml;tz et al., 2022; Adisorn et al., 2021; Walden et al., 2021), though it largely treats data governance as a design challenge rather than a legal-regulatory one. A 2024 European Parliament study proposes a three-phase textile DPP deployment: minimal DPP by 2027, advanced DPP by 2030, and full circular DPP by 2033 (European Parliament, 2024). Yet, the question of how to automate data access, verification, and compliance checking - and what legal constraints apply - remains underexplored.\u003c/p\u003e\n\u003cp\u003eTaken together, these studies collectively underscore the centrality of DPPs in advancing circular economy objectives within the EU policy framework. A pattern emerges wherein policy and standardization efforts provide a robust infrastructural foundation, yet scholarly attention to the legal and automated operationalization of DPPs is limited. It is noteworthy that while the technical and design dimensions of DPPs receive considerable focus, the integration of legal constraints - particularly regarding automation and data governance - remains insufficiently addressed. This gap is particularly significant because the successful deployment of DPPs depends not only on technical interoperability but also on ensuring compliance with evolving regulatory frameworks. Thus, this subsection highlights a critical research need to bridge policy ambitions with legal and technical realities in DPP implementation.\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eSmart Contracts and Legal Frameworks\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eThe Data Act provides the first EU legal definition of smart contracts: \u0026ldquo;a computer program used for the automated execution of an agreement or part thereof, using a sequence of electronic data records and ensuring their integrity and the accuracy of their chronological ordering\u0026rdquo; (Article 2(39)) (European Union, 2023). This definition is technology-neutral, covering both blockchain-based and conventional database implementations. The UNCITRAL Model Law on Automated Contracting (2024) offers complementary international guidance (UNCITRAL, 2024).\u003c/p\u003e\n\u003cp\u003eDjurovic and Janssen demonstrate that the formation of blockchain-based smart contracts under traditional contract law remains legally uncertain (Djurovic and Janssen, 2018). Questions persist regarding offer, acceptance, and intention to create legal relations. Goldenfein and Leiter explore smart contracts as \u0026ldquo;legal engineering,\u0026rdquo; arguing they shift enforcement from ex-post legal interpretation to ex-ante code-based execution (Goldenfein and Leiter, 2018). Levy critiques smart contracts as \u0026ldquo;book-smart, not street-smart,\u0026rdquo; unable to capture the social and contextual flexibility of law (Levy, 2017). Raskin provides a comprehensive analysis of smart contract legal validity across jurisdictions, identifying persistent challenges in contract formation, interpretation, and enforcement (Raskin, 2017). Von Hafe et al.\u0026rsquo;s comparative analysis reveals significant divergence in EU member states\u0026rsquo; approaches (Von Hafe et al., 2025). These studies reveal a tension between the promise of smart contracts to enhance efficiency through automation and the legal system\u0026rsquo;s inherent need for flexibility and contextual judgment. Hence, while smart contracts can automate certain contractual functions, their legal status and enforceability remain unsettled, particularly in cross-jurisdictional contexts. It is noteworthy that existing literature calls attention to the challenges of aligning code-based execution with traditional legal principles but stops short of proposing concrete frameworks for resolving these issues in regulatory applications. This tension is directly relevant to DPP systems, which require automated yet legally compliant mechanisms for data access and verification. Therefore, this subsection identifies a research gap concerning the reconciliation of smart contract automation with legal safeguards, a gap this study aims to address.\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eBlockchain, Traceability, and Circular Economy\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eBlockchain-based traceability systems have shown promise in agribusiness (Kumar et al., 2022), textiles (Agrawal et al., 2021), and agri-food supply chains (Caro et al., 2018), emphasizing data integrity and tamper-resistance. Dhillon et al. examine governance trade-offs between decentralization, scalability, and regulatory compliance (Dhillon et al., 2017). Allen et al. design governance models for blockchain-based supply chain management, stressing clear role allocation and dispute resolution (Allen et al., 2019).\u003c/p\u003e\n\u003cp\u003eFrom a circular economy perspective, blockchain offers traceability and data integrity benefits but also legal challenges: immutability conflicts with data subject rights; distributed architectures complicate GDPR controller/processor roles; and smart contract automation raises Article 22 concerns. While blockchain traceability literature acknowledges these tensions, it does not systematically analyze them within the DPP regulatory context.\u003c/p\u003e\n\u003cp\u003eTaken together, these works highlight the technical advantages and legal complexities of applying blockchain to circular economy traceability. Blockchain\u0026rsquo;s immutability enhances trust in data but simultaneously challenges compliance with data protection and governance standards. It is noteworthy that while governance models are proposed to mitigate these issues, there remains a lack of integrated legal analysis specifically tailored to DPP applications. This gap is significant because DPPs rely on trustworthy data flows that must comply with stringent regulatory requirements. Consequently, this subsection underscores the necessity for interdisciplinary research that bridges blockchain technology, legal frameworks, and circular economy objectives - a nexus that remains underexplored and which this study seeks to illuminate.\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eBattery and Textile DPP Implementations\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eRecent studies on battery DPPs identify challenges in data collection, verification, confidentiality, interoperability, and data quality across EV battery supply chains (Sopha et al., 2022; Rizos et al., 2024; Abedi et al., 2024). Wicaksono et al.\u0026rsquo;s systematic review highlights key enablers and barriers to DPP adoption (Abedi et al., 2024; Wicaksono et al., 2025). The Global Battery Alliance\u0026rsquo;s 2024 pilots, involving major manufacturers, demonstrate real-world feasibility of automated sustainability data collection (Global Battery Alliance, 2024). These pilots reveal practical challenges: data quality varies across supply chain tiers, verification remains largely manual, and stakeholder access rights require careful calibration. While battery and textile DPP literature is rich empirically, it remains legally thin, documenting implementation challenges without systematically analyzing the governing legal frameworks. Questions of automated decision-making, liability, and fundamental rights protection remain largely unaddressed.\u003c/p\u003e\n\u003cp\u003eThese empirical studies illustrate the practical complexities of deploying DPPs in industrial contexts, revealing recurring challenges related to data quality, interoperability, and stakeholder management. The evidence indicates that, despite technological advances and pilot successes, legal and regulatory considerations - particularly those concerning automation and rights protection - remain insufficiently integrated into implementation strategies. It is noteworthy that this disconnect between empirical practice and legal analysis limits the scalability and regulatory compliance of DPP systems. This gap is particularly significant because without addressing legal governance, automated DPP implementations risk non-compliance and stakeholder disputes. Thus, this subsection highlights the urgent need for research that combines empirical insights with rigorous legal analysis.\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eSynthesis and Research Gap\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eThe literature establishes smart contracts as legally significant but undertheorized in regulatory contexts. DPP scholarship addresses data governance but overlooks automation mechanisms. Blockchain traceability literature emphasizes technical benefits while underanalyzing legal constraints. A notable gap emerges at the intersection of these fields. While extensive literature exists on DPPs and smart contracts separately, no scholarship systematically analyzes the legal implications of using smart contracts to automate DPP systems. This gap is critical because automation raises fundamental questions about accountability, contestability, and compliance with GDPR, the Data Act, and other EU frameworks. Taken together, these diverse bodies of literature reveal an interdisciplinary challenge at the nexus of circular economy policy, smart contract technology, blockchain traceability, and sector-specific DPP implementation. Hence, the integration of legal, technical, and empirical perspectives remains fragmented. Yet this fragmentation impedes the development of legally robust, automated DPP systems capable of supporting the EU\u0026rsquo;s ambitious sustainability goals. This gap is particularly significant because the effective deployment of DPPs depends on harmonizing automation with legal safeguards across multiple regulatory regimes and industrial contexts. By analyzing DPP smart contracts, the present study contributes an essential interdisciplinary framework that bridges legal theory, technological innovation, and practical implementation, thereby advancing academic knowledge and policy-relevant solutions in sustainable product governance.\u003c/p\u003e"},{"header":"Methods","content":"\u003cp\u003eThe study adopts a mixed doctrinal-comparative and case study approach to analyze the evolving EU regulatory framework for DPPs and the legal implications of their automation through smart contracts. This methodological design is chosen to bridge the gap between normative legal analysis and the practical realities of technological implementation. The research synthesizes legal scholarship, EU legislation, jurisprudence, and empirical data from pilot projects to provide a comprehensive and contextualized understanding of the subject.\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eResearch Design\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eThe research design is centered on a doctrinal analysis of the primary legal instruments governing DPPs and smart contracts in the EU. This includes the Ecodesign for Sustainable Products Regulation (ESPR) (European Union, 2024a), the Data Act (European Union, 2023b), the General Data Protection Regulation (GDPR) (European Union, 2016a), and the Battery Regulation (European Union, 2023b). The analysis is supplemented by a review of pertinent jurisprudence from the Court of Justice of the European Union (CJEU), particularly the SCHUFA case (C-634/21) (CJEU, 2023), which provides critical insights into the application of automated decision-making provisions under the GDPR. To ground the legal analysis in practical application, the study also examines publicly documented DPP pilot projects in the battery and textile sectors, including initiatives by the Global Battery Alliance (Global Battery Alliance, 2024).\u003c/p\u003e\n\u003cp\u003e\u003cem\u003e\u0026nbsp;Legal Sources\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eThe selection of legal sources was conducted with a focus on relevance and authoritativeness. Primary legal sources were retrieved from the EUR-Lex and CURIA databases, ensuring access to the most current and official versions of EU legislation and case law. The search for academic literature was conducted across multiple databases, including CrossRef and Google Scholar, with a focus on peer-reviewed articles published between 2018 and 2025. Regulatory guidance from the European Data Protection Board (EDPB) and the European Union Agency for Cybersecurity (ENISA) was also reviewed to incorporate the latest interpretive trends and best practices.\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eJurisprudence and Verification\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eThe jurisprudential analysis focused on identifying and interpreting key rulings from the CJEU that have a direct bearing on the use of smart contracts in DPPs. Case law was retrieved from the CURIA database, covering judgments up to October 2025. The analysis of the SCHUFA case (C-634/21) (CJEU, 2023), for instance, was crucial in delineating the boundaries of automated decision-making under Article 22 of the GDPR, particularly the \u0026ldquo;heavy reliance\u0026rdquo; test and the definitional scope of \u0026ldquo;decisions\u0026rdquo; affecting individuals. Regulatory guidance from the EDPB, including the April 2025 blockchain guidelines (EDPB, 2025), and ENISA (ENISA, 2023) was also reviewed to incorporate current interpretive trends. While the analysis is grounded in established jurisprudence such as SCHUFA, the application of GDPR Article 22 to smart contracts remains a developing area of law, and empirical data on large-scale DPP implementations is still limited to pilot initiatives.\u003c/p\u003e"},{"header":"Results","content":"\u003cp\u003eThe legal-doctrinal analysis reveals a complex, multi-layered regulatory framework governing DPP smart contracts. This architecture comprises eight interconnected instruments, creating opportunities and tensions. The study systematically maps this architecture, identifying provisions directly relevant to smart contract automation.\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eESPR and the DPP Framework\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eThe Ecodesign for Sustainable Products Regulation (EU) 2024/1781 establishes the foundational framework for DPPS (European Union, 2024a). Notably, the ESPR does not define \u0026ldquo;digital product passport\u0026rdquo; explicitly; instead, it empowers the Commission to require, via delegated acts, that products be accompanied by a \u0026ldquo;product passport\u0026rdquo; containing specified information (Article 8).\u003c/p\u003e\n\u003cp\u003e- Core DPP Elements: Article 8 authorizes the Commission to mandate passports containing product identification, composition, repairability, and end-of-life handling information (European Union, 2024). Article 10 requires passports to be accessible via data carriers - typically QR codes compliant with ISO/IEC 18004 (CEN/CENELEC, 2025) - affixed to products. Unique product identifiers must follow ISO/IEC 15459 standards (CEN/CENELEC, 2025). These technical standards are vital for interoperability.\u003c/p\u003e\n\u003cp\u003e- \u003cstrong\u003eData Carrier and Registry\u003c/strong\u003e: Article 10 requires each product passport to be accessible through a data carrier affixed to the product, while Article 12 establishes a Commission-managed registry as the legal infrastructure for storing passport information. The registry links physical products and unique identifiers to corresponding digital records, assigning data-entry duties to economic operators and regulated access to authorized actors. This centralized model embeds traceability and oversight within EU law, distinguishing it from decentralized blockchain architectures premised on distributed governance.\u003c/p\u003e\n\u003cp\u003e- \u003cstrong\u003eDifferentiated Access Rights\u003c/strong\u003e: Article 13 frames access to product-passport data according to user roles and regulatory functions, leaving the specific tiers to be detailed in delegated acts. In practice, access may range from public information (e.g., product identifiers), to restricted data for economic operators, to authority-only layers for market surveillance and customs. This graded model underpins legal interoperability with the GDPR and the Data Act, requiring smart contracts to authenticate identity and role before enabling compliant data exchange.\u003c/p\u003e\n\u003cp\u003e- Interoperability Requirements: Article 12 establishes a Union-wide registry for product-passport data, forming the legal basis for interoperability across Member States and sectors. Standardisation efforts are underway to operationalize this framework, with CEN/CENELEC (ISO, 2024; CEN/CENELEC, 2025) developing common data formats, identifiers, and interface protocols, and ISO/IEC (ISO, 2024) contributing to global alignment and cross-sector compatibility.\u003c/p\u003e\n\u003cp\u003e- Customs Integration: Article 13 grants customs authorities access to the product-passport registry to verify that imported products correspond to valid passport entries. This mechanism embeds DPP verification within border-control procedures, turning customs clearance into an operational compliance checkpoint. It also creates a potential use case for automated conformity checks and smart contract-based validation of import compliance (European Union, 2024).\u003c/p\u003e\n\u003cp\u003e- Battery Regulation as First Implementation: Regulation (EU) 2023/1542 on batteries provides the first sector-specific implementation of a digital product passport framework (European Union, 2023b). Chapter IX, supported by Annex XIII, defines the battery-passport structure and data requirements. The obligation applies from 18 February 2027, positioning batteries as the initial testing ground for DPP automation and traceability.\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eData Act and Smart Contract Regulation\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eRegulation (EU) 2023/2854 (Data Act) provides the first EU regulation specifically addressing smart contracts (European Union, 2023c). Article 2(39) defines smart contracts in technology-neutral terms, covering blockchain and conventional implementations.\u003c/p\u003e\n\u003cp\u003e- Article 36 Essential Requirements: Article 36 sets essential requirements for smart contracts used in Data Act data-sharing agreements, including robustness and access control, safe termination and interruption, data archiving and continuity, and consistency with the terms of the data-sharing agreement (European Union, 2023). These provisions aim to mitigate risks arising from blockchain immutability, irreversible execution, and limited human oversight (Dwivedi et al., 2021).\u003c/p\u003e\n\u003cp\u003e- \u003cstrong\u003eScope Limitation\u003c/strong\u003e: Article 36 applies only to smart contracts used in Data Act data sharing agreements (Chapter III), not broadly. This creates a regulatory gap: DPP smart contracts outside Data Act sharing agreements are not subject to Article 36. ESPR delegated acts could incorporate similar requirements for DPP smart contracts; and this study recommends that they do so.\u003c/p\u003e\n\u003cp\u003e- Termination and Modification: Article 36(1)(b) requires mechanisms for the safe termination and interruption of smart-contract execution to prevent unintended or irreversible outcomes (European Union, 2023). This provision directly addresses concerns about blockchain immutability and the absence of human oversight, which in practice may be mitigated through safeguards such as multi-signature controls, time-locks, or circuit-breaker functions.\u003c/p\u003e\n\u003cp\u003e- Archiving and Auditability: Article 36(1)(c) requires preserving smart-contract transaction data to ensure continuity, auditability, and accountability (European Union, 2023). This provision supports the creation of verifiable audit trails and enables ex post review of automated execution.\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eGDPR and Automated Decision-Making\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eRegulation (EU) 2016/679 (GDPR) imposes comprehensive data protection requirements on DPP systems (European Union, 2016a). Two provisions are especially relevant: Article 22 on automated decision-making and Articles 13-14 on transparency.\u003c/p\u003e\n\u003cp\u003e- Article 22 Prohibition: Article 22(1) prohibits decisions based solely on automated processing that produce legal effects or similarly significant impacts on individuals (European Union, 2016). Exceptions under Article 22(2) are permitted only where appropriate safeguards are in place, including human oversight, the right to contest decisions, and mechanisms ensuring explainability as required by Article 22(3).\u003c/p\u003e\n\u003cp\u003e- SCHUFA Case Interpretation: The CJEU\u0026rsquo;s December 2023 SCHUFA ruling (Joined Cases C-634/21 and C-26/22) clarified that preparatory acts may constitute \u0026ldquo;decisions\u0026rdquo; under Article 22 where automated results are heavily relied upon by human decision-makers (CJEU, 2023). The Court confirmed that Article 22 safeguards cannot be circumvented through nominal human review lacking genuine, independent assessment.\u003c/p\u003e\n\u003cp\u003e- Application to DPP Smart Contracts: The SCHUFA ruling has direct implications for DPP smart contracts. Where automated execution determines outcomes that significantly affect individuals, such as restricting access to repair documentation or triggering customs holds, Article 22 GDPR is likely to apply (CJEU, 2023).\u003c/p\u003e\n\u003cp\u003e- EDPB Blockchain Guidelines: The EDPB\u0026rsquo;s April 2025 Guidelines 02/2025 on blockchain technologies emphasise that organisations cannot rely on blockchain immutability to bypass GDPR obligations (EDPB, 2025). While they do not explicitly state that \u0026ldquo;smart contract execution\u0026rdquo; always constitutes automated decision-making under Article 22, the guidance underscores that any automated process producing significant effects must be designed with data-protection safeguards in mind.\u003c/p\u003e\n\u003cp\u003e- Transparency Obligations: GDPR Articles 13-14 require controllers to inform data subjects about automated decision-making, including \u0026ldquo;meaningful information about the logic involved\u0026rdquo; and \u0026ldquo;the significance and envisaged consequences\u0026rdquo; (European Union, 2016a). These apply to DPP smart contracts processing personal data, necessitating explainability mechanisms to ensure transparency and accountability.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e\u0026nbsp;\u003c/strong\u003e\u003cem\u003eCyber Resilience Act and Product Safety\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eRegulation (EU) 2024/2847 establishes horizontal cybersecurity requirements for \u0026ldquo;products with digital elements\u0026rdquo; (European Union, 2024c). While the legislation does not explicitly list DPP systems or smart contracts, many implementations of these - when constituted as software or combined hardware-software modules made available on the EU market and connected to networks - may fall within its scope. Whether they qualify will depend on the concrete classification of the product or service under the Cyber Resilience Act (CRA).\u003c/p\u003e\n\u003cp\u003e- Essential Cybersecurity Requirements: Annex I requires products to be delivered without known exploitable vulnerabilities, to minimise attack surfaces, and to ensure secure default configurations, data protection, and reliable update mechanisms (European Union, 2024). Smart contracts containing known vulnerabilities would be incompatible with these essential requirements.\u003c/p\u003e\n\u003cp\u003e- Vulnerability Handling: Article 11 requires manufacturers to find, record, and fix security weaknesses throughout a product\u0026rsquo;s life (European Union, 2024). For blockchain-based smart contracts, this means including ways to update the code, such as using proxy systems or carefully managed redeployments, so that flaws can be corrected even though the blockchain itself cannot be changed.\u003c/p\u003e\n\u003cp\u003e- Conformity Assessment: Articles 24-30 establish conformity assessment procedures, requiring third-party evaluation by notified bodies for products classified as critical under the Cyber Resilience Act (European Union, 2024). DPP implementations that meet this threshold would therefore undergo independent conformity checks.\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eProduct Liability and Consumer Protection\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eThe revised Product Liability Directive (EU) 2024/2853 broadens strict liability to cover defective products with digital elements, including software and updates (European Commission, 2024). Article 6 defines a defect as a failure to provide the safety that the public is entitled to expect. For DPP smart contracts, such defects may arise from security vulnerabilities, coding errors, or breaches of regulatory requirements.\u003c/p\u003e\n\u003cp\u003e- Liability Allocation: Article 7 makes manufacturers, importers, and other economic operators liable for damage caused by defective products (European Commission, 2024). In the context of DPP smart contracts, liability questions arise where third-party developers, deployers, or registry operators are involved. The directive anticipates situations of shared responsibility, with multiple actors potentially liable depending on contractual roles and fault attribution.\u003c/p\u003e\n\u003cp\u003e- Consumer Protection: The Directives on unfair commercial practices (European Commission, 2024) and unfair contract terms (European Union, 1993) apply to DPP systems that engage consumers. Smart contracts embedding unfair terms or misleading practices may be deemed unenforceable under EU consumer-protection law.\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eTrade Secrets and Confidentiality\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eDirective (EU) 2016/943 protects trade secrets from unlawful acquisition, use, or disclosure (European Commission, 2024). DPP systems must balance transparency obligations with the protection of confidential business information. Smart-contract logic itself may qualify as a trade secret, creating tension with legal requirements for transparency and explainability.\u003c/p\u003e\n\u003cp\u003e- Differentiated Access: Article 13 establishes role-based access to product-passport data, balancing confidentiality and transparency. Access may range from public to restricted and authority-only tiers, which smart contracts must enforce precisely.\u003c/p\u003e\n\u003cp\u003e- Confidentiality Obligations: Data Act Article 5 prohibits unauthorized use or disclosure of trade secrets in data sharing (European Union, 2023). Smart contracts must enforce safeguards such as encryption and access controls. The tension between transparency and trade secret protection remains unresolved.\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eeIDAS and Electronic Signatures\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eRegulation (EU) No 910/2014 (eIDAS) establishes a legal framework for electronic identification and trust services (European Union, 2011). DPP systems rely on electronic signatures and seals to authenticate data sources and ensure integrity.\u003c/p\u003e\n\u003cp\u003e- Electronic Signatures: Article 25 confirms that electronic signatures cannot be denied legal effect solely because they are electronic. Smart contracts verifying signatures for access control or data validation must recognize eIDAS-compliant signatures.\u003c/p\u003e\n\u003cp\u003e- Qualified Electronic Seals: Articles 35-36 establish qualified electronic seals for legal entities, providing high assurance of data origin and integrity. Smart contracts could verify seals before accepting data into DPP registries, enabling automated authenticity verification.\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eInternational Legal Frameworks\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003e- UNCITRAL Model Law on Automated Contracting (MLAC): Adopted July 2024, MLAC provides a functional equivalence approach, ensuring contracts formed or performed via automated systems are not denied legal effect solely for that reason (UNCITRAL, 2024). This supports legal certainty for DPP smart contracts in adopting jurisdictions.\u003c/p\u003e\n\u003cp\u003e- UNIDROIT Digital Assets Principles (DAPL): Adopted May 2023, DAPL establishes frameworks for proprietary rights in digital assets (UNIDROIT, 2023). While DPP data is typically informational rather than a \u0026ldquo;digital asset,\u0026rdquo; DAPL\u0026rsquo;s treatment of control as equivalent to possession informs DPP data governance.\u003c/p\u003e\n\u003cp\u003e- UNCITRAL Model Law on Electronic Transferable Records (MLETR): Adopted July 2017, MLETR provides functional equivalence for electronic transferable records (UNCITRAL, 2017). Its approach to control and transfer informs mechanisms for transferring DPPs alongside products.\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eAutomated Access Control\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eSmart contracts can automate access control to DPP data based on requester identity, role, and purpose. For example, when a repairer requests technical documentation, the smart contract verifies credentials against ESPR Article 13\u0026rsquo;s access tiers and grants or denies access automatically. This automation eliminates manual verification, enabling real-time access at scale for scenarios like customs clearance or consumer QR code scans (European Union, 2024). However, wrongful denial risks violating legal rights, for instance, denying a repairer access required under the Right to Repair Directive infringes their rights. If such denial significantly impacts business, GDPR Article 22 applies, requiring human review and contestability. Five essential safeguards emerge: clear access control rules aligned with ESPR Article 13; logging of access decisions; human review for contested denials; explanation functionality; and secure authentication using eIDAS-compliant mechanisms (European Union, 2011).\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eAutomated Supply Chain Data Aggregation\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eSmart contracts can automatically update DPP records as products move through supply chains, adding data such as carbon footprints or material composition. This reduces manual entry and errors while enabling real-time tracking across complex multi-tier networks, as shown in Global Battery Alliance pilots (Global Battery Alliance, 2024). Legal risks include data-quality and verification issues: incorrect inputs can propagate through the chain, creating uncertainty over liability among data providers, deployers, and technology vendors (European Commission, 2024). Trade-secret protection and GDPR compliance add further complexity. Safeguards include role-based access control consistent with ESPR Article 13, audit logging, human review for contested entries, explanation functions, and eIDAS-compliant authentication.\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eAutomated Compliance Verification\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eSmart contracts can verify DPP data against regulatory requirements, flagging non-compliance, for example, checking battery passport completeness per Annex XIII (European Union, 2023b). This enables real-time compliance enforcement, reducing market-surveillance burdens and allowing economic operators to correct issues before market entry. However, false positives or negatives carry serious consequences, including denial of market access or regulatory failure. Where automated decisions have significant effects, GDPR Article 22 may apply, requiring human oversight and contestability (CJEU, 2023; EDPB, 2025). The CRA (European Union, 2024) mandates robust cybersecurity for products with digital elements to prevent manipulation. Safeguards include data validation, human review, confidentiality protections, clear GDPR role allocations, and comprehensive audit trails.\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eAutomated Circular Transactions\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eSmart contracts can automate circular economy transactions such as deposit-return schemes, extended producer responsibility payments, and recycling incentives. For instance, upon verified product return, a smart contract could refund deposits or credit incentives. This automation reduces administrative overhead and enables instant settlements, potentially boosting participation (European Parliament, 2024). Legal risks include payment errors and contract law questions about whether smart contracts constitute binding contracts or mere performance mechanisms (UNCITRAL, 2024). Consumer protection laws apply, and product liability may arise from malfunctions (European Commission, 2024). Safeguards include human review before enforcement, explanations with regulatory references, appeal mechanisms, logic validation, and cybersecurity measures.\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eAutomated Lifecycle Event Recording\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eSmart contracts can record lifecycle events - repairs, refurbishments, ownership transfers, end-of-life processing - updating DPPs with event details, timestamps, and actor identities. This supports real-time enforcement and shifts market surveillance from ex-post penalties to ex-ante prevention (European Union, 2024). Legal risks mirror those in compliance verification. Integration with eIDAS electronic signatures ensures authenticity and non-repudiation (European Union, 2011). GDPR compliance requires careful handling of personal data, possibly necessitating off-chain storage with on-chain hashes (EDPB, 2025). Safeguards include transparent logic, dispute resolution mechanisms, consumer protection compliance, secure payment infrastructure, and liability insurance.\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eAccountability Framework for DPP Smart Contracts\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e\u0026nbsp;\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eGDPR Articles 13-14 require controllers to provide data subjects with \u0026ldquo;meaningful information about the logic involved\u0026rdquo; in automated decision-making (European Union, 2016a). For DPP smart contracts processing personal data, this creates explainability obligations. However, the precise level of detail required remains uncertain. Must controllers disclose actual code, or is a high-level description sufficient? The Data Act\u0026rsquo;s Article 36 requires legal consistency but does not explicitly mandate explainability (European Union, 2023), leaving a gap for DPP smart contracts outside GDPR\u0026rsquo;s scope.\u003c/p\u003e\n\u003cp\u003eTechnical complexity and proprietary trade secrets complicate explanations. To balance transparency and confidentiality, the study proposes explainability mechanisms such as plain language summaries of logic and criteria, decision logs recording inputs, outputs, and intermediate steps, visualization tools, documentation of external data sources, and version control to track updates.\u003c/p\u003e\n\u003cp\u003eGDPR Article 22(3) mandates data subjects\u0026rsquo; rights to human intervention, to express views, and to contest decisions (European Union, 2016a). The SCHUFA case stresses that human review must be meaningful, not nominal (CJEU, 2023). Furthermore, the EDPB\u0026rsquo;s April 2025 blockchain guidelines emphasize that blockchain immutability does not excuse non-compliance: controllers remain responsible even after smart contract execution (EDPB, 2025). Therefore, DPP smart contracts must incorporate contestability mechanisms from the outset.\u003c/p\u003e\n\u003cp\u003eDesign patterns enabling contestability include pause mechanisms before final execution; override functions for authorized actors; dispute resolution smart contracts; off-chain appeals with on-chain recording; and time delays allowing human review. Human oversight should be proportional: low-stakes decisions may require minimal oversight, while high-stakes decisions demand robust mechanisms.\u003c/p\u003e\n\u003cp\u003eThe revised Product Liability Directive (EU) 2024/2853 holds manufacturers and economic operators liable for defective products, including digital elements (European Commission, 2024). When DPP smart contracts malfunction, liability questions arise among developers, deployers, registry operators, and blockchain providers. The Directive does not clarify liability allocation in multi-party smart contract systems.\u003c/p\u003e\n\u003cp\u003eContract law principles apply to breaches of contractual obligations implemented by smart contracts, but allocation among multiple parties remains unclear. Liability gaps and regulatory silence on smart contract failures create uncertainty that may deter investment. Insurance could mitigate financial risks, but markets for smart contract risks are nascent. Standardized risk assessments and actuarial data are needed. Liability should be allocated according to control and responsibility: developers would be liable for code defects; deployers for configuration errors and misuse; registry operators for infrastructure failures; and blockchain providers would bear limited liability similar to that of internet service providers. Clear contractual arrangements are essential.\u003c/p\u003e\n\u003cp\u003eOpen standards are vital for interoperability, security, and accountability. Standards should cover smart contract interfaces, security practices, explainability formats, audit trails, testing, and conformity assessment. CEN/CENELEC Joint Technical Committee 24 is developing DPP standards (CEN/CENELEC, 2025); smart contract standards should integrate into this work to avoid fragmentation. Moreover, ISO\u0026rsquo;s ongoing work on DPP principles (ISO/PWI 25534-1) (ISO, 2024) supports global interoperability. Also, the Cyber Resilience Act mandates conformity assessments for products with digital elements (European Union, 2024). Critical DPP smart contracts may require third-party assessment. Voluntary certification schemes could promote high-quality smart contracts, covering compliance with Data Act Article 36, GDPR safeguards, cybersecurity, explainability, and security audits.\u003c/p\u003e\n\u003cp\u003eThis depicts the integrated structure of technical, legal, and governance components across six distinct layers. Each layer represents a critical dimension of accountability, illustrating their interconnections to ensure comprehensive governance and compliance within smart contract operations. Accordingly, this framework highlights the multi-faceted approach necessary to maintain transparency, responsibility, and trust in DPP ecosystems. This framework integrates legal requirements with technical and governance processes to ensure DPP smart contracts are accountable, transparent, and lawful.\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eCase Studies from Battery, Textile, and Electronics Sectors\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eThe Global Battery Alliance\u0026rsquo;s 2024 pilots involved 10 consortia representing 80% of global EV battery manufacturing capacity (Global Battery Alliance, 2024). These pilots tested battery passport data collection, aggregation, and sharing across multi-tier supply chains. Data collection proved more challenging than expected. Tier 2 and 3 suppliers often lack digital infrastructure, making manual data entry error-prone and time-consuming. Data quality and verification remain critical challenges, indicating that smart contracts cannot assume input data accuracy and that validation mechanisms are essential. Verification and trust require robust mechanisms. Pilots explored third-party audits, blockchain tamper-evidence, and cross-validation. No single approach sufficed, suggesting verification must be tailored to data types and risks. Governance and access control proved complex. Economic operators expressed concerns about confidential information disclosure. Clear governance frameworks specifying access conditions are essential (Pohlmann et al., 2020). Smart contracts automating access control must implement these precisely to avoid violating trade secrets or legal rights. These lessons underscore that automated data aggregation via smart contracts is feasible but demands careful design, validation, human oversight, and governance frameworks, aligning with GDPR, Data Act, and trade secret requirements.\u003c/p\u003e\n\u003cp\u003eA 2024 European Parliament study involving 81 stakeholders proposed a three-phase textile DPP deployment (European Parliament, 2024). Textile supply chains are highly fragmented, with numerous tiers and frequent sourcing changes, complicating automated data aggregation. Each added tier increases risks of data errors and verification challenges. Consumer privacy concerns are prominent. Textile DPPs may include purchasing behavior and preferences. Stakeholders agree on strong privacy protections, requiring careful data structuring and access controls. Smart contracts must prevent inadvertent personal data disclosure, aligning with GDPR principles of data minimization and purpose limitation (European Union, 2016a). The phased deployment, minimal DPP by 2027, advanced by 2030, and full circular by 2033, allows learning and risk reduction, consistent with the proportionality principle. These insights suggest smart contract deployment should start with low-stakes use cases (e.g., public information access) before advancing to high-stakes automation (e.g., compliance verification). Privacy-by-design principles must be embedded from the start, echoing EDPB blockchain guidelines (EDPB, 2025).\u003c/p\u003e\n\u003cp\u003eElectronics DPPs support right to repair by providing independent repairers access to technical documentation, spare parts, and diagnostics. Smart contracts can automate access control, balancing repairer needs with manufacturers\u0026rsquo; intellectual property protection, directly reflecting the automated access control use case. E-waste management benefits from DPPs by supplying recyclers with composition data, disassembly instructions, and recovery guidance. Smart contracts could automate recycling incentive payments, enhancing collection rates - a circular transaction use case with significant potential. Data security is critical. Electronics DPPs may contain sensitive information like software versions and vulnerability disclosures. Unauthorized access risks exploitation. Smart contracts must enforce robust authentication and authorization, complying with Cyber Resilience Act security requirements (European Union, 2024). This sector highlights that DPP automation is not only a data governance challenge but also a cybersecurity imperative.\u003c/p\u003e"},{"header":"Discussion","content":"\u003cp\u003eThis section interprets findings from sections 4-7, focusing on three themes: the tension between automation efficiency and legal accountability, the adequacy of existing EU legal frameworks, and the path forward for responsible DPP smart contract deployment.\u003c/p\u003e\n\u003cp\u003eThe findings reveal a fundamental tension: while smart contracts enhance efficiency by processing millions of transactions without human intervention, they also diminish oversight, increase the risk of error propagation, and challenge contestability when decisions are automatic and irreversible. This suggests that while automation can streamline circular economy processes, it simultaneously introduces risks that could undermine trust and legal compliance if not carefully managed.\u003c/p\u003e\n\u003cp\u003eThis tension is not unique to DPPs but reflects broader algorithmic governance challenges in credit scoring, employment screening, and content moderation. The EU\u0026rsquo;s approach prioritizes accountability, emphasizing human oversight, contestability, and rights protection over pure efficiency. The implications extend beyond DPPs, highlighting a governance paradigm that insists on embedding human judgment within automated systems to safeguard fundamental rights.\u003c/p\u003e\n\u003cp\u003eThe SCHUFA case (CJEU, 2023) and EDPB blockchain guidelines (EDPB, 2025) make clear that technical constraints like blockchain immutability cannot justify legal non-compliance. Critically, this reveals that technological design must be subordinate to legal and ethical norms, reinforcing the primacy of accountability in sustainability governance. Consequently, DPP smart contracts must be designed from the outset to enable contestability, human review, and data subject rights-even if this reduces efficiency or complicates technical design. Practically, developers must balance speed and cost optimization with explainability, contestability, and human oversight. This dual optimization is technically demanding but legally essential. This suggests that innovation in the circular economy must incorporate legal safeguards as integral design parameters rather than afterthoughts.\u003c/p\u003e\n\u003cp\u003eThe integration of automation through DPP smart contracts in sustainability governance introduces complex cultural and ethical trust considerations that shape stakeholder acceptance within the EU circular economy. Consumers may exhibit skepticism toward algorithmic decision-making absent transparent, culturally sensitive frameworks that affirm data integrity and equitable outcomes. Producers face ethical imperatives to ensure that automated compliance mechanisms do not obscure accountability or marginalize artisanal practices incompatible with rigid coding. Regulators must balance technological efficiency with inclusivity, fostering trust by embedding normative values that resonate across diverse cultural contexts. Ultimately, the ethical legitimacy of automated DPP smart contracts hinges on their capacity to align with shared sustainability goals while respecting pluralistic stakeholder perspectives, thereby reinforcing trust as a foundational pillar of circular economy governance.\u003c/p\u003e\n\u003cp\u003eStrengths include the Data Act\u0026rsquo;s Article 36 essential requirements addressing robustness and access control (European Union, 2023), GDPR Article 22\u0026rsquo;s protections against harmful automated decisions (European Union, 2016a), the Cyber Resilience Act\u0026rsquo;s cybersecurity requirements (European Union, 2024), and the revised Product Liability Directive\u0026rsquo;s extension to digital elements (European Commission, 2024). Together, these create a multi-layered protective framework that reflects the EU\u0026rsquo;s commitment to embedding sustainability and rights protection within digital governance.\u003c/p\u003e\n\u003cp\u003eTable 2. Analysis of Legal Gaps and Recommended Mitigations for DPP Smart Contracts.\u003c/p\u003e\n\u003ctable border=\"1\" cellspacing=\"0\" cellpadding=\"0\"\u003e\n \u003ctbody\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 156px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003eLegal Gap\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 125px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003eCurrent Status\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 156px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003eImpact\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 187px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003eRecommended Mitigation\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 156px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003e1. Limited Scope of Data Act Article 36\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 125px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003eApplies only to smart contracts used in Data Act data sharing agreements, not DPP smart contracts generally\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 156px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003eEconomic operators uncertain whether Article 36 requirements apply to their DPP smart contracts\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 187px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003eESPR delegated acts should extend Data Act Article 36 essential requirements to all DPP smart contracts\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 156px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003e2. Unclear Article 22 Application\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 125px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003eGDPR Article 22 prohibits automated decision-making with legal/significant effects, but application to specific DPP use cases unclear\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 156px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003eRisk of non-compliance or over-cautious avoidance of beneficial automation\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 187px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003eCommission guidance clarifying when DPP smart contracts trigger Article 22 and specifying required safeguards\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 156px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003e3. Lack of Explainability Requirements\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 125px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003eNeither Data Act nor GDPR explicitly requires explainability for smart contracts\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 156px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003eTransparency obligations uncertain; risk of opaque automated systems\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 187px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003eESPR delegated acts should mandate explainability mechanisms (plain-language descriptions, decision logs, audit trails)\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 156px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003e4. Uncertain Liability Allocation\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 125px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003eProduct Liability Directive extends to digital elements but does not clearly allocate liability for smart contract failures in multi-party systems\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 156px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003eDeters investment; leaves affected parties without clear remedies\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 187px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003eCommission guidance on liability allocation, clarifying developer, deployer, and data provider responsibilities\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 156px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003e5. Absence of Conformity Assessment\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 125px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003eNo conformity assessment requirements for DPP smart contracts, unlike Cyber Resilience Act\u0026apos;s framework for products with digital elements\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 156px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003eNo independent verification of compliance with legal and technical requirements\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 187px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003eESPR delegated acts should establish conformity assessment for high-risk DPP smart contracts (compliance verification, safety-critical access control)\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 156px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003e6. Blockchain-GDPR Tension\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 125px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003eEDPB confirms blockchain immutability not an excuse for non-compliance, but technical solutions for GDPR rights (erasure, rectification) on blockchain unclear\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 156px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003eRisk of non-compliance or avoidance of blockchain solutions\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 187px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003eTechnical standards for GDPR-compliant blockchain architectures; guidance on permissioned blockchains and off-chain data storage\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 156px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003e7. Trade Secret Protection Gaps\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 125px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003eDPP access requirements may conflict with trade secret protection; no clear guidance on balancing transparency and confidentiality\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 156px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003eRisk of excessive disclosure or insufficient transparency\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 187px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003eESPR delegated acts should specify criteria for restricting access to confidential business information while ensuring necessary transparency\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 156px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003e8. Lack of SME Support\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 125px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003eComplex legal and technical requirements may disadvantage SMEs lacking resources for compliance\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 156px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003eMarket concentration; reduced SME participation in circular economy\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 187px;\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003cp\u003eCommission and Member State technical assistance, guidance, and financial support for SME DPP smart contract compliance\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003c/tbody\u003e\n\u003c/table\u003e\n\u003cp\u003eNote: This table synthesizes findings from sections 4-6 of the article, identifying critical legal gaps where existing EU law provides insufficient guidance for DPP smart contract deployment and proposing concrete mitigations.\u003c/p\u003e\n\u003cp\u003eSource: Authors\u0026apos; analysis based on EU legal framework review.\u003c/p\u003e\n\u003cp\u003eHowever, gaps persist. Article 36 applies only to Data Act sharing agreements, excluding broader DPP smart contracts; ESPR delegated acts should extend these requirements. Neither the Data Act nor GDPR explicitly mandates explainability for smart contracts, creating transparency uncertainty. Liability allocation for smart contract failures remains unclear, deterring investment. Conformity assessment requirements for DPP smart contracts are absent, unlike the Cyber Resilience Act\u0026rsquo;s framework.\u003c/p\u003e\n\u003cp\u003eThis suggests that while the EU legal architecture is robust in principle, its fragmented and partial application risks regulatory uncertainty that could slow circular economy innovation. Comparatively, the UNCITRAL Model Law on Automated Contracting (UNCITRAL, 2024) adopts a functional equivalence approach, removing barriers but leaving substantive regulation to domestic law. The EU\u0026rsquo;s prescriptive approach embeds values like data protection and fundamental rights into technology governance. The UNIDROIT Digital Assets Principles (UNIDROIT, 2023) focus on proprietary rights but offer limited guidance for DPP governance. Neither international instrument addresses DPP automation challenges in circular economy contexts. The implications extend beyond the EU, as this prescriptive model may serve as a benchmark for other jurisdictions grappling with digital sustainability governance, emphasizing the integration of rights and accountability in automated systems.\u003c/p\u003e\n\u003cp\u003eA key policy challenge is balancing innovation incentives with regulatory protection. Overly prescriptive rules risk stifling innovation and delaying circular economy benefits; insufficient regulation risks harmful automation, undermining trust and creating liability. This suggests that regulatory frameworks must be adaptive and calibrated to evolving technological and market realities. The textile sector\u0026rsquo;s phased deployment model (European Parliament, 2024) offers a way to manage this balance, starting with low-stakes use cases to enable learning before high-stakes automation. Regulatory sandboxes could facilitate controlled testing under supervision, generating evidence to inform regulation. This approach reflects a pragmatic governance strategy that fosters innovation while safeguarding sustainability goals.\u003c/p\u003e\n\u003cp\u003eStandards and certification are critical. Open standards promote interoperability and reduce costs; certification differentiates high-quality implementations. Accelerated, well-resourced standardization by CEN/CENELEC (ISO, 2024; CEN/CENELEC, 2025) and ISO (ISO, 2024) is essential. Without standards, DPP smart contracts risk becoming proprietary silos, undermining ESPR\u0026rsquo;s interoperability goals. This reveals that governance mechanisms extending beyond law, such as technical standardization, are vital for realizing circular economy ambitions.\u003c/p\u003e\n\u003cp\u003e- Policymakers: Urgent legal clarity is needed. With battery passports mandatory from February 2027 (European Union, 2023b), guidance on Article 22 application, liability, and conformity assessment is critical. Priorities include clarifying Article 22\u0026rsquo;s scope, incorporating Data Act Article 36 into ESPR delegated acts, establishing liability frameworks, and supporting standardization. Delay risks legal uncertainty and slows circular economy progress. This suggests that proactive, coordinated policymaking is essential to avoid bottlenecks in DPP deployment.\u003c/p\u003e\n\u003cp\u003e- \u003cstrong\u003eEconomic Operators\u003c/strong\u003e: Early adopters face uncertainty but also opportunities. They should conduct Data Protection Impact Assessments (DPIAs), implement human-in-the-loop for high-stakes decisions, adopt secure development and audits, clarify contractual liability, and engage in standardization. Proactive compliance can confer competitive advantage. This implies that responsible innovation can be a market differentiator in sustainability transitions.\u003c/p\u003e\n\u003cp\u003e- \u003cstrong\u003eTechnology Providers\u003c/strong\u003e: Significant market opportunities exist for legally compliant, user-friendly smart contract solutions. Prioritizing explainability, contestability, and security will be key. Legal expertise must be integrated from design onward. This reveals a growing demand for interdisciplinary collaboration between technologists and legal experts.\u003c/p\u003e\n\u003cp\u003e- \u003cstrong\u003eStandard-Setting Bodies\u003c/strong\u003e: Developing open standards for smart contract interfaces, explainability, and audit trails is vital. Multi-stakeholder participation, including SMEs, civil society, and consumer representatives, is essential to ensure diverse perspectives and avoid dominance by large providers. This suggests that inclusive governance mechanisms are critical to equitable and sustainable circular economy outcomes.\u003c/p\u003e\n\u003cp\u003eThe DPP smart contract challenge exemplifies broader digital governance issues. As automation, AI, and algorithmic decision-making proliferate, societies must address accountability, transparency, and balancing efficiency with human oversight. The EU\u0026rsquo;s approach - emphasizing legal compliance, data protection, contestability, and human rights - offers a model for responsible automation applicable beyond DPPs. By requiring technical systems to conform to legal and ethical norms, the EU charts a distinctive digital governance path. This suggests that sustainability governance increasingly demands integrated socio-technical frameworks that reconcile innovation with rights protection.\u003c/p\u003e\n\u003cp\u003eCritics argue this imposes compliance costs and reduces competitiveness. Yet, unchecked automation risks undermining trust, enabling discrimination, and triggering liability crises. The EU judges that long-term trust and sustainability require upfront accountability investment. The implications transcend legal compliance, shaping the legitimacy and social acceptance of circular economy technologies. Success depends on timely guidance, adequate resources for standardization and conformity assessment, economic operators\u0026rsquo; compliance investment, and effective enforcement. The 2025-2027 period is critical. Successful battery passport deployment could catalyze broader adoption; failure could delay progress and erode confidence. Achieving success demands coordinated action: policymakers clarifying law, operators investing in compliance, providers prioritizing accountability, and standard-setters accelerating interoperability. DPP smart contract deployment is a collective challenge requiring sustained cooperation. This reveals that governance of circular economy technologies must be multi-actor and multi-level, integrating legal, technical, and social dimensions.\u003c/p\u003e"},{"header":"Conclusions","content":"\u003cp\u003eThis article has examined the legal implications of automating DPP systems with smart contracts in the EU circular economy. The analysis reveals a complex, evolving legal landscape with significant opportunities and challenges.\u003c/p\u003e \u003cp\u003eThe ESPR establishes a comprehensive DPP framework covering most EU product categories, with battery passports mandatory from February 2027 (European Union, \u003cspan citationid=\"CR30\" class=\"CitationRef\"\u003e2024a\u003c/span\u003e; European Union, \u003cspan citationid=\"CR28\" class=\"CitationRef\"\u003e2023b\u003c/span\u003e). DPPs aim to resolve information asymmetries by providing standardized, machine-readable product data throughout lifecycles. Smart contracts offer compelling automation solutions for data governance, supply chain sharing, compliance verification, and circular transactions.\u003c/p\u003e \u003cp\u003eThe Data Act introduces the first EU smart contract regulation via Article 36, setting essential requirements for robustness, termination, archiving, access control, and legal consistency (European Union, 2023). Yet critical gaps remain, especially regarding explainability, contestability, and liability allocation. GDPR Article 22 protections apply to smart contracts making legally significant determinations, requiring human intervention and appeal mechanisms (CJEU, 2023; EDPB, 2025). EDPB blockchain guidelines confirm that blockchain immutability does not excuse non-compliance with data subject rights (EDPB, 2025). This suggests that while the legal framework is pioneering, it requires refinement to fully address the unique challenges posed by DPP automation in the circular economy.\u003c/p\u003e \u003cp\u003eThe analysis has identified five critical legal gaps where existing EU law provides insufficient guidance for deploying DPP smart contracts: the unclear application of GDPR Article 22 to DPP use cases, the lack of explainability and contestability requirements in Data Act Article 36, uncertain liability allocation when multiple parties deploy shared smart contracts, the absence of conformity assessment for DPP smart contracts, and the unresolved tension between blockchain immutability and GDPR rights. The research has developed a six-layer accountability framework addressing explainability, contestability, liability, standards, certification, and governance. Drawing on battery, textile, and electronics case studies, the study has distilled practical lessons on data quality, phased deployment, and human oversight. These findings inform the 10-point policy checklist (Section 9.3), offering concrete recommendations for legislators, standard-setters, and operators to ensure DPP smart contracts are developed to be accountable, contestable, and lawful.\u003c/p\u003e"},{"header":"Declarations","content":"\u003cp\u003e\u003cstrong\u003eFunding\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThis research received no external funding.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eData Availability Statement\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFunding\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThis research received no external funding.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eData Availability Statement\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThis study is a legal‑doctrinal and comparative analysis based exclusively on publicly available EU legislation, official guidance, and case law. No new datasets were generated or analysed. A reproducibility package is provided as Supplementary Data 1 (\u0026ldquo;Data and Materials Package\u0026rdquo;), including: (i) a table of all primary sources used with stable direct URLs (EUR‑Lex/ELI, Curia, and EDPB); (ii) the operational definitions used to code legal requirements (e.g., accountability, contestability, termination, auditability); and (iii) the provision‑to‑framework mapping matrix underpinning the Results and Discussion. Primary sources are accessible via the direct URLs listed in Supplementary Data 1 and here for convenience: ESPR Regulation (EU) 2024/1781 (https://eur-lex.europa.eu/eli/reg/2024/1781/oj/eng); Data Act Regulation (EU) 2023/2854 (https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=OJ%3AL_202302854); GDPR Regulation (EU) 2016/679 (https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32016R0679); EDPB Guidelines 02/2025 on blockchain technologies (https://www.edpb.europa.eu/system/files/2025-04/edpb_guidelines_202502_blockchain_en.pdf); and CJEU judgment C‑634/21 SCHUFA (https://curia.europa.eu/juris/document/document.jsf?docid=280426\u0026amp;doclang=EN).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eConflicts of Interest\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThe author declares no conflicts of interest.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eEthics approval and consent to participate\u003c/strong\u003e: Not applicable. This study is based on doctrinal and comparative analysis of publicly available legal texts, regulations, policy documents, and secondary literature. It did not involve human participants, animals, or the collection of personal data.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eConflicts of Interest\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThe author declares no conflicts of interest.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eEthics approval and consent to participate\u003c/strong\u003e: Not applicable. This study is based on doctrinal and comparative analysis of publicly available legal texts, regulations, policy documents, and secondary literature. It did not involve human participants, animals, or the collection of personal data\u003cstrong\u003e.\u003c/strong\u003e\u003c/p\u003e"},{"header":"References","content":"\u003col\u003e\n \u003cli\u003eAbedi, F., Saari, U., Hakola, L., 2024. Implementation and Adoption of Digital Product Passports: A Systematic Literature Review. Tampere University, Tampere, Finland.\u003c/li\u003e\n \u003cli\u003eAdisorn, T., Tholen, L., G\u0026ouml;tz, T., 2021. Towards a Digital Product Passport Fit for Contributing to a Circular Economy. Energies, 14(8), 2289. https://doi.org/10.3390/en14082289.\u003c/li\u003e\n \u003cli\u003eAgrawal, T.K., Kumar, V., Pal, R., Wang, L., Chen, Y., 2021. Blockchain-based framework for supply chain traceability: A case example of textile and clothing industry. Computers \u0026amp; Industrial Engineering, 154, 107130. https://doi.org/10.1016/j.cie.2021.107130.\u003c/li\u003e\n \u003cli\u003eAllen, D.W.E., Lane, A.M., Poblet, M., 2019. The Governance of Blockchain Dispute Resolution. Harvard Negotiation Law Review, 25, 75\u0026ndash;114.\u003c/li\u003e\n \u003cli\u003eCaro, M.P., Ali, M.S., Vecchio, M., Giaffreda, R., 2018. Blockchain-based traceability in Agri-Food supply chain management: A practical implementation. Proceedings of the 2018 IoT Vertical and Topical Summit on Agriculture - Tuscany (IOT Tuscany), pp. 1-4. https://doi.org/10.1109/IOT-TUSCANY.2018.8373021.\u003c/li\u003e\n \u003cli\u003eCEN/CENELEC, 2025c. JTC 24 - Digital Product Passport: Framework and System (Work item under development), CEN/CENELEC, Brussels, Belgium.\u003c/li\u003e\n \u003cli\u003eCEN/CENELEC, 2025a. Digital Product Passport for Printed Circuit Boards Assemblies (Draft CWA), CEN/CENELEC, Brussels, Belgium.\u003c/li\u003e\n \u003cli\u003eCEN/CENELEC, 2025b. Guidelines to Create a Digital Product Passport \u0026ndash; Draft CWA. Draft published February 2025. CEN/CENELEC, Brussels, Belgium.\u003c/li\u003e\n \u003cli\u003eCommission Nationale de l\u0026rsquo;Informatique et des Libert\u0026eacute;s, 2018. Blockchain and the GDPR: Solutions for a Responsible Use of the Blockchain in the Context of Personal Data. CNIL, Paris, France.\u003c/li\u003e\n \u003cli\u003eCourt of Justice of the European Union, 2023. Case C-634/21, SCHUFA Holding AG v Finanzamt Wiesbaden, Judgment of 7 December 2023, ECLI:EU:C:2023:957.\u003c/li\u003e\n \u003cli\u003eDhillon, V., Metcalf, D., Hooper, M., 2017. Blockchain Enabled Applications: Understand the Blockchain Ecosystem and How to Make it Work for You. Apress, Berkeley, CA. DOI: 10.1007/978-1-4842-3081-7.\u003c/li\u003e\n \u003cli\u003eDjurovic, M., Janssen, A., 2018. The Formation of Blockchain-Based Smart Contracts in the Light of Contract Law. European Review of Private Law, 26(6), 753-771.\u003c/li\u003e\n \u003cli\u003eDwivedi, V., Norta, A., Wulf, A., Leiding, B., Saxena, S., Udokwu, C., 2021. A Formal Specification Smart-Contract Language for Legally Binding Decentralized Autonomous Organizations. IEEE Access, 9, 76069-76082. https://doi.org/10.1109/ACCESS.2021.3081926.\u003c/li\u003e\n \u003cli\u003eEuropean Commission, 2019. The European Green Deal. COM(2019) 640 final. European Commission, Brussels, Belgium.\u003c/li\u003e\n \u003cli\u003eEuropean Commission, 2020. A New Circular Economy Action Plan. COM(2020) 98 final. European Commission, Brussels, Belgium.\u003c/li\u003e\n \u003cli\u003eEuropean Commission, 2022. Impact Assessment Accompanying the Proposal for a Regulation of the European Parliament and of the Council Establishing a Framework for Setting Ecodesign Requirements for Sustainable Products and Repealing Directive 2009/125/EC. SWD(2022) 82 final. European Commission, Brussels, Belgium, 30 March 2022.\u003c/li\u003e\n \u003cli\u003eEuropean Commission, 2025. Ecodesign for Sustainable Products and Energy Labelling Working Plan 2025-2030. Communication COM(2025) 187 final \u0026amp; Staff Working Document SWD(2025) 112 final. European Commission, Brussels, Belgium, 16 April 2025.\u003c/li\u003e\n \u003cli\u003eEuropean Data Protection Board, 2020. Guidelines 4/2019 on Article 25 - Data Protection by Design and by Default. Version 2.0. EDPB, Brussels, Belgium, October 2020.\u003c/li\u003e\n \u003cli\u003eEuropean Data Protection Board \u0026amp; European Data Protection Supervisor, 2022. Joint Opinion 2/2022 on the Proposal for a Regulation of the European Parliament and of the Council on harmonised rules on fair access to and use of data (Data Act). EDPB-EDPS, Brussels, Belgium, 4 May 2022.\u003c/li\u003e\n \u003cli\u003eEuropean Data Protection Board, 2025. Guidelines 02/2025 on the Processing of Personal Data Through Blockchain Technologies. Adopted 14 April 2025. EDPB, Brussels, Belgium. Available at: https://www.edpb.europa.eu/our-work-tools/documents/public-consultations/2025/guidelines-022025-processing-personal-data_en (accessed 29 October 2025).\u003c/li\u003e\n \u003cli\u003eEuropean Parliament, 2024. Digital Product Passport for Textiles. Study for the IMCO Committee. PE 757.808. European Parliament, Brussels, Belgium.\u003c/li\u003e\n \u003cli\u003eEuropean Union, 1993. Council Directive 93/13/EEC of 5 April 1993 on unfair terms in consumer contracts (Unfair Terms Directive). Off. J. Eur. Communities 1993, L 95, pp. 29-34.\u003c/li\u003e\n \u003cli\u003eEuropean Union, 2005. Directive (EU) 2005/29/EC of the European Parliament and of the Council of 11 May 2005 concerning unfair business-to-consumer commercial practices in the internal market. Off. J. Eur. Union 2005, L 149, 22-39.\u003c/li\u003e\n \u003cli\u003eEuropean Union, 2016a. Directive (EU) 2016/943 of the European Parliament and of the Council of 8 June 2016 on the protection of undisclosed know-how and business information (trade secrets). Off. J. Eur. Union 2016, L 157, 1-18.\u003c/li\u003e\n \u003cli\u003eEuropean Union, 2016b. Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation, GDPR). Official Journal of the European Union, L 119, 1\u0026ndash;88.\u003c/li\u003e\n \u003cli\u003eEuropean Union, 2019. Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019 on ENISA and on information and communications technology cybersecurity certification (Cybersecurity Act). Off. J. Eur. Union 2019, L 151, 15-69.\u003c/li\u003e\n \u003cli\u003eEuropean Union, 2023a. Regulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assets (MiCA). Off. J. Eur. Union 2023, L 150, 40-205.\u003c/li\u003e\n \u003cli\u003eEuropean Union, 2023b. Regulation (EU) 2023/1542 of the European Parliament and of the Council of 12 July 2023 concerning batteries and waste batteries, repealing Directive 2006/66/EC and Regulation (EU) No 2019/1020 as regards market surveillance. Off. J. Eur. Union 2023, L 191, 1-135.\u003c/li\u003e\n \u003cli\u003eEuropean Union, 2023c. Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data (Data Act). Off. J. Eur. Union 2023, L 305, 1-88.\u003c/li\u003e\n \u003cli\u003eEuropean Union, 2024a. Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products (Product Liability Directive). Off. J. Eur. Union 2024, L 2853, 1-22.\u003c/li\u003e\n \u003cli\u003eEuropean Union, 2024b. Regulation (EU) 2024/1781 of the European Parliament and of the Council of 13 June 2024 establishing a framework for setting ecodesign requirements for sustainable products (ESPR). Off. J. Eur. Union 2024, L, 1-106.\u003c/li\u003e\n \u003cli\u003eEuropean Union, 2024c. Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) No 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act). Off. J. Eur. Union 2024, L 2847, 1-115.\u003c/li\u003e\n \u003cli\u003eEuropean Union Agency for Cybersecurity, 2023. Baseline Security Recommendations for IoT in the context of Critical Information Infrastructures. ENISA, Athens, Greece, November 2017.\u003c/li\u003e\n \u003cli\u003eEuropean Union Agency for Cybersecurity, 2023. Good Practices for Security of IoT \u0026ndash; Secure Software Development Lifecycle. ENISA, Athens, Greece, 19 November 2019. Available at: https://www.enisa.europa.eu/publications/good-practices-for-security-of-iot-1 (accessed 2 November 2025).\u003c/li\u003e\n \u003cli\u003eEuropean Union Agency for Cybersecurity, 2023. Good Practices for Supply Chain Cybersecurity. ENISA, Athens, Greece, 13 June 2023. Available at: https://www.enisa.europa.eu/publications/good-practices-for-supply-chain-cybersecurity (accessed 2 November 2025).\u003c/li\u003e\n \u003cli\u003eEuropean Union Agency for Cybersecurity, 2023. Artificial Intelligence Cybersecurity Challenges - Threat Landscape for AI. ENISA, Athens, Greece. Available at: https://www.enisa.europa.eu/publications/artificial-intelligence-cybersecurity-challenges (accessed 2 November 2025).\u003c/li\u003e\n \u003cli\u003eEuropean Union Agency for Cybersecurity, 2025. Technical Implementation Guidance \u0026ndash; NIS2 Directive. ENISA, Athens, Greece, 26 June 2025. Available at: https://www.enisa.europa.eu/publications/nis2-technical-implementation-guidance (accessed 2 November 2025).\u003c/li\u003e\n \u003cli\u003eGerman Data Protection Conference (DSK). Guidance on the Use of Artificial Intelligence and Compliance with Data Protection Law. DSK, Germany, 6 May 2024.\u003c/li\u003e\n \u003cli\u003eGlobal Battery Alliance, 2024. Battery Passport 2024 Pilots: Progress Report. GBA, Geneva, Switzerland.\u003c/li\u003e\n \u003cli\u003eGoldenfein, J., Leiter, A., 2018. Legal Engineering on the Blockchain: \u0026ldquo;Smart Contracts\u0026rdquo; as Legal Conduct. Law Crit., 29(2), 141\u0026ndash;149. https://doi.org/10.1007/s10978-018-9224-0.\u003c/li\u003e\n \u003cli\u003eG\u0026ouml;tz, T., Berg, H., Jansen, M., Adisorn, T., Cembrero, D., Markkanen, S., Chowdhury, T., 2022. Digital Product Passport: The Ticket to Achieving a Climate Neutral and Circular European Economy? Wuppertal Institute: Wuppertal, Germany.\u003c/li\u003e\n \u003cli\u003eInternational Organization for Standardization (ISO), 2024. ISO/PWI 25534-1 \u0026ndash; Digital Product Passport: Overview and Fundamental Principles (Work item under development). Geneva, Switzerland, April 2025.\u003c/li\u003e\n \u003cli\u003eInternational Organization for Standardization (ISO), 2014. ISO/IEC 15459-1:2014 - Information technology - Automatic identification and data capture techniques - Unique identification - Part 1: Individual transport units. Geneva, Switzerland.\u003c/li\u003e\n \u003cli\u003eInternational Organization for Standardization (ISO), 2015. ISO/IEC 18004:2015 - Information technology - Automatic identification and data capture techniques - QR Code bar code symbology specification. International Organization for Standardization, Geneva, Switzerland.\u003c/li\u003e\n \u003cli\u003eKumar, N.M., Chopra, S.S., 2022. Leveraging Blockchain and Smart Contract Technologies to Overcome Circular Economy Implementation Challenges. Sustainability, 14(5), 9492. https://doi.org/10.3390/su14159492.\u003c/li\u003e\n \u003cli\u003eLevy, K.E., 2017. Book-Smart, Not Street-Smart: Blockchain-Based Smart Contracts and the Social Workings of Law. Engag. Sci. Technol. Soc., 3, 1-15. https://doi.org/10.17351/ests2017.107.\u003c/li\u003e\n \u003cli\u003ePohlmann, C.R., Scavarda, A.J., Alves, M.B., Korzenowski, A.L., 2020. The role of the focal company in sustainable development goals: A Brazilian food poultry supply chain case study. J. Clean. Prod., 245, 118798. https://doi.org/10.1016/j.jclepro.2019.118798.\u003c/li\u003e\n \u003cli\u003eRaskin, M., 2017. The Law and Legality of Smart Contracts. Georgetown Law Technology Review, 1, 305-341.\u003c/li\u003e\n \u003cli\u003eEuropean Union, 2014. Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 July 2014 on electronic identification and trust services for electronic transactions in the internal market (eIDAS Regulation). Off. J. Eur. Union 2014, L 257, 73-114.\u003c/li\u003e\n \u003cli\u003eRizos, V., Urban, P., 2024. Implementing the EU Digital Battery Passport: Opportunities and Challenges for Battery Circularity. CEPS In-Depth Analysis, 05. Centre for European Policy Studies, Brussels, Belgium. Available at: https://www.ceps.eu/ceps-publications/implementing-the-eu-digital-battery-passport/ (accessed 3 November 2025).\u003c/li\u003e\n \u003cli\u003eSopha, B.M., Purnamasari, D.M., Ma\u0026rsquo;mun, S. Barriers and Enablers of Circular Economy Implementation for Electric-Vehicle Batteries: From Systematic Literature Review to Conceptual Framework. Sustainability, 14(10), 6359. https://doi.org/10.3390/su14106359.\u003c/li\u003e\n \u003cli\u003eUK Jurisdiction Taskforce (UKJT). Legal Statement on Cryptoassets and Smart Contracts. LawTech Delivery Panel, London, UK, 18 November 2019.\u003c/li\u003e\n \u003cli\u003eUNCITRAL, 2017. Model Law on Electronic Transferable Records (MLETR). United Nations Commission on International Trade Law, Vienna, Austria, 13 July 2017.\u003c/li\u003e\n \u003cli\u003eUNCITRAL, 2025. Model Law on Automated Contracting. United Nations Commission on International Trade Law, Vienna, Austria, 11 July 2024.\u003c/li\u003e\n \u003cli\u003eUNIDROIT, 2023. Principles on Digital Assets and Private Law. International Institute for the Unification of Private Law, Rome, Italy.\u003c/li\u003e\n \u003cli\u003eUnited Nations Economic Commission for Europe (UNECE) \u0026amp; International Organization for Standardization (ISO). Joint Initiative on Digital Product Passport (launch announcement). UNECE, Geneva, Switzerland, 08 April 2025. Available at: https://unece.org/digitalization/news/unece-and-iso-launch-joint-initiative-digital-product-passport-advance (accessed 29 October 2025).\u003c/li\u003e\n \u003cli\u003eVon Hafe, F., Wagle, Y., Guede-Fern\u0026aacute;ndez, F., Giordano, A.P., Silva, L., Azevedo, S., 2025. Legal Frameworks for Blockchain Applications: A Comparative Study with Implications for Innovation in Europe. Frontiers in Blockchain, 8, 1655230. https://doi.org/10.3389/fbloc.2025.1655230.\u003c/li\u003e\n \u003cli\u003eWalden, J., Steinbrecher, A., Marinkovic, M., 2021. Digital Product Passports as Enabler of the Circular Economy. Sustainability, 93(11), 1717-1727. https://doi.org/10.1002/cite.202100121.\u003c/li\u003e\n \u003cli\u003eWicaksono, H., Mengistu, A., Bashyal, A., Fekete, T., 2025. Digital Product Passport (DPP) Technological Advancement and Adoption Framework: A Systematic Literature Review. Procedia Comput. Sci., 253, 2980-2989. https://doi.org/10.1016/j.procs.2025.02.022.\u003c/li\u003e\n\u003c/ol\u003e"}],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":true,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":false,"hideJournal":false,"highlight":"","institution":"","isAcceptedByJournal":false,"isAuthorSuppliedPdf":false,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":false,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"
[email protected]","identity":"humanities-and-social-sciences-communications","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":false,"externalIdentity":"palcomms","sideBox":"Learn more about [Humanities \u0026 Social Sciences Communications](http://www.nature.com/palcomms/)","snPcode":"41599","submissionUrl":"https://submission.springernature.com/new-submission/41599/3","title":"Humanities and Social Sciences Communications","twitterHandle":"","acdcEnabled":true,"dfaEnabled":true,"editorialSystem":"stoa","reportingPortfolio":"Nature AJ","inReviewEnabled":true,"inReviewRevisionsEnabled":false},"keywords":"digital product passports, smart contracts, circular economy, GDPR, Data Act, EU law, sustainability, automated governance","lastPublishedDoi":"10.21203/rs.3.rs-8397708/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-8397708/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"\u003cp\u003eThe European Union\u0026rsquo;s 2050 climate neutrality target relies heavily on circular economy strategies, with the newly introduced Ecodesign for Sustainable Products Regulation (ESPR) establishing Digital Product Passports (DPPs) as a key tool to close information gaps in product lifecycles. Despite the regulatory momentum, the scalability of DPPs across diverse sectors - such as batteries by 2027 and textiles by 2030 - poses significant challenges for data management and compliance verification. Methodologically, the study applies a multi-layered doctrinal-comparative framework triangulating EU law, CJEU jurisprudence, and industry pilot projects. This approach reveals that smart contracts, as automated executors of predefined conditions, can effectively govern DPP data, enhancing transparency and operational efficiency. Pilot initiatives by the Global Battery Alliance and textile industry experiments demonstrate the practical viability of blockchain-enabled smart contract automation for sustainability data collection, supplier verification, and regulatory compliance. The findings underscore the transformative potential of integrating legal frameworks with emerging digital technologies to support circular economy objectives. However, the study also highlights unresolved legal complexities concerning data access, liability, and regulatory oversight. These insights inform policymakers and industry stakeholders on designing robust, scalable, and legally compliant DPP systems, advancing the EU\u0026rsquo;s sustainability agenda through innovative digital governance mechanisms.\u003c/p\u003e","manuscriptTitle":"Automating Accountability: Smart Contracts and the Legal Future of Digital Product Passports in the EU Circular Economy","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2026-01-16 05:34:25","doi":"10.21203/rs.3.rs-8397708/v1","editorialEvents":[{"type":"communityComments","content":0},{"type":"decision","content":"Revision requested","date":"2026-04-22T07:22:26+00:00","index":"","fulltext":""},{"type":"editorInvitedReview","content":"","date":"2026-03-17T14:32:49+00:00","index":"hide","fulltext":""},{"type":"editorInvitedReview","content":"","date":"2026-03-11T19:06:15+00:00","index":"hide","fulltext":""},{"type":"editorInvitedReview","content":"","date":"2026-02-18T15:19:24+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"263022360269787378934892702469755297694","date":"2026-02-02T07:46:58+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"274841312527902418624496032053304041478","date":"2026-01-26T13:37:49+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"195456060752751685670091047721202599598","date":"2026-01-26T13:19:21+00:00","index":"hide","fulltext":""},{"type":"reviewersInvited","content":"","date":"2026-01-13T10:40:01+00:00","index":"","fulltext":""},{"type":"editorAssigned","content":"","date":"2026-01-13T10:38:10+00:00","index":"","fulltext":""},{"type":"editorInvited","content":"","date":"2026-01-13T10:15:21+00:00","index":"","fulltext":""},{"type":"checksComplete","content":"","date":"2026-01-08T18:56:24+00:00","index":"","fulltext":""},{"type":"submitted","content":"Humanities and Social Sciences Communications","date":"2026-01-08T18:51:12+00:00","index":"","fulltext":""}],"status":"published","journal":{"display":true,"email":"
[email protected]","identity":"humanities-and-social-sciences-communications","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":false,"externalIdentity":"palcomms","sideBox":"Learn more about [Humanities \u0026 Social Sciences Communications](http://www.nature.com/palcomms/)","snPcode":"41599","submissionUrl":"https://submission.springernature.com/new-submission/41599/3","title":"Humanities and Social Sciences Communications","twitterHandle":"","acdcEnabled":true,"dfaEnabled":true,"editorialSystem":"stoa","reportingPortfolio":"Nature AJ","inReviewEnabled":true,"inReviewRevisionsEnabled":false}}],"origin":"","ownerIdentity":"da38466b-1bf7-40fd-9bbe-286b025d84d8","owner":[],"postedDate":"January 16th, 2026","published":true,"recentEditorialEvents":[],"rejectedJournal":[],"revision":"","amendment":"","status":"under-review","subjectAreas":[{"id":61186291,"name":"Business and commerce/Information systems and information technology"},{"id":61186292,"name":"Social science/Science technology and society"}],"tags":[],"updatedAt":"2026-05-11T13:09:56+00:00","versionOfRecord":[],"versionCreatedAt":"2026-01-16 05:34:25","video":"","vorDoi":"","vorDoiUrl":"","workflowStages":[]},"version":"v1","identity":"rs-8397708","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-8397708","identity":"rs-8397708","version":["v1"]},"buildId":"XKTyCvWXoU3ODBz1xrDgd","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}
Text is read by the "Ask this paper" AI Q&A widget below.
Extraction quality varies by source — PMC NXML preserves structure
cleanly, OA-HTML may include some navigation residue, and OA-PDF can
have broken hyphenation. The publisher copy
(via DOI)
is the canonical version.