NexusDPP data governance

The DPP makes the right information visible while protecting trade secrets.

NexusDPP separates public data from restricted technical information and confidential company content. Each party accesses only the information relevant to its role.

Public dataFor the market and stakeholders
Restricted dataFor authorised partners
Confidential dataFor authorised roles only
NexusDPP dashboard with role-based access and public, restricted and confidential data
Role-based accessGranular and controlled permissions
Classified dataClear separation of public and restricted information
Selective sharingOnly with authorised parties
Complete audit trailActions and changes remain traceable
Information classification

Three distinct levels governed by the same platform.

Protection begins before publication: every field, document and item of evidence is assigned a visibility level and authorised recipients.

01
Public data

Information customers can access through QR or NFC, such as product identity, instructions, shareable materials information and service content.

02
Restricted data

Technical evidence, certificates, supply-chain documents and information visible only to authorised operators, partners or authorities.

03
Confidential data

Formulas, drawings, price lists, margins, proprietary processes, supplier lists and other information protected from the public view.

NexusDPP dashboard for managing public, restricted and confidential protection levels with role-based access controls
How data is protected

Minimum access, complete control and traceable operations.

The NexusDPP architecture applies the principle of least privilege: no user automatically sees all product or organisational data.

Access by role and scope

Importers, manufacturers, suppliers, verifiers, authorities and end users receive different permissions limited to the assigned product and process.

Separation between organisations

Data is segregated by company and operational context, preventing suppliers or partners from viewing unrelated archives.

Selective sharing

Only the fields or evidence required for a specific request are shared, keeping access to the technical file limited.

Evidence archive

Documents and attachments remain associated with the correct DPP, with controls on uploads, permissions and restricted access.

Versions and audit trail

Submissions, revisions, approvals and changes are recorded to reconstruct who acted, on which data and at what time.

Protected transmission

The design provides encrypted connections, secure credential management, tokenised invitations, controlled uploads and protected storage.

Blockchain and notarisation

Proving integrity while protecting the content.

The approach chosen to protect trade secrets prevents documents, formulas or commercial data from being written in clear text to a public blockchain.

  • The restricted document remains in the platform’s protected archive.
  • Where required, only a digital fingerprint of the file is recorded together with date, version and integrity evidence.
  • The fingerprint makes it possible to prove content integrity while keeping the content restricted to authorised parties.
  • Electronic signatures and qualified timestamps can be integrated into workflows requiring stronger evidential value.
Protected data

The content remains confidential. The evidence remains verifiable.

NexusDPP separates business data from proof of its existence, version and integrity.

Suppliers and verifiers

Collaborate while retaining full control of the archive.

External parties work in defined spaces with access proportionate to their role and specific activity.

Non-EU manufacturer or supplier

Receives a secure invitation and completes only the fields requested for the assigned product. It can view only the assigned product and information.

Independent verifier

Accesses only the DPP, evidence and authorised verification request. It can issue a signed opinion while preserving ownership and the final passport version.

End user

Views the public experience configured by the brand, while technical documents and internal data remain protected.

Authorities and authorised parties

May receive a dedicated information level, separate from the public view, according to their role and the applicable scope.

Company control

Transparency and confidentiality work together.

The company defines which data is public, which is shared with qualified parties and which remains confined within its own perimeter.

The DPP makes the product verifiable while protecting the company’s information assets.

NexusDPP design principle