Access rights · 27 August 2026 update

Battery Passport: operational rules for legitimate-interest access are now indicated for Q4 2026.

Article 77(9) of Regulation (EU) 2023/1542 set 18 August 2026 for the implementing act on persons with a legitimate interest. The Commission’s public DPP roadmap now places the Implementing Act for Batteries access rights in Q4 2026.

At a glance

  • Article 77(9) set 18 August 2026 as the date for the implementing act.
  • The Commission roadmap now indicates Q4 2026 for the Batteries access-rights act.
  • The act must specify who has a legitimate interest, which information they can access and the extent to which they may download, share, publish or reuse it.
  • Current projects should therefore use configurable policies rather than hard-coded permissions.

What the Regulation already establishes

Article 77 separates public information, information for notified bodies/market surveillance authorities/the Commission, and information available to natural or legal persons with a legitimate interest for the purposes specified by the Regulation.

What the implementing act must clarify

  • which persons qualify as having a legitimate interest;
  • which Annex XIII information they may access;
  • the extent to which they may download, share, publish or reuse that information;
  • how commercially sensitive information is limited to the minimum necessary.

A roadmap date is not an automatic legal obligation

Q4 2026 is an indicative Commission timeline and remains subject to adoption and publication procedures. Access rules should therefore remain configurable.

Architecture controls to implement now

ControlWhy it matters
Role- and purpose-based accessSeparates public, authority, verifier and authorised-party views.
Versioned policiesAllows rules to change when the act is adopted.
Audit logRecords who viewed, changed or authorised information.
Data minimisationLimits exposure of commercially sensitive information.
Separate permissionsViewing does not automatically imply downloading, sharing or reuse.

The NexusDpp approach

NexusDpp treats access rights as a policy layer separate from the data. The same field can exist in the passport while visibility and permitted use change by role, purpose and regulatory version, avoiding duplicated data sets.

Official sources

The NexusDpp response

Update permissions without duplicating the passport.

Roles, purposes and rights to view, download and reuse can be versioned so the policy layer can absorb the final implementing act.