DPP vs CSDDD — What's the Difference?
Different layers of the same push. The Corporate Sustainability Due Diligence Directive (CSDDD, 2024/1760) is company-level conduct law: very large companies must identify, prevent and remedy human-rights and environmental harms across their chains of activities. The Digital Product Passport (ESPR, 2024/1781) is product-level data law: a verifiable record per product. A garment factory is rarely in CSDDD scope itself — but its buyers are, and they discharge their duties through the supply chain.
Written by Nazrul Islam, Founder, DPPLive · Last updated: 16 July 2026
Where the two laws meet is evidence. A buyer under CSDDD must show it knows its chain; a product under ESPR must carry its own verified data. The factory that runs one clean data pipeline — materials, origin, substances, certifications, footprint — hands its buyer due-diligence evidence and hands the product its passport, from the same records. Commission-backed model contractual clauses (Article 18) mean supplier contracts will keep formalising exactly these data flows; see our guide to DPP clauses in buyer contracts.
Quick Answers
Go Deeper
- Directive (EU) 2024/1760 (CSDDD) — full text on EUR-Lex — Articles 2, 5–16, 18, 27 (as amended by the 2025–2026 Omnibus package)
- Regulation (EU) 2024/1781 (ESPR) — full text on EUR-Lex
- European Commission — Corporate sustainability due diligence
Your Buyer's Law. Your Data.
CSDDD never names your factory — it names your buyer, and your buyer names you in the contract. The factories that thrive under due-diligence law are the ones whose data answers questions before auditors ask them. That data layer is what DPPLive operates.