Guide

Annex XIII access tiers: who sees what

Annex XIII defines four audiences for passport data: the public, holders of a legitimate interest, market-surveillance authorities, and the European Commission. Each field is exposed only to its permitted tier, enforced server-side.

Last updated 1 June 2026

Not all passport data is public. Annex XIII assigns each data point to one of four audiences, and a compliant passport must enforce these distinctions in code — not by hoping nobody looks.

TierAudienceExample data
PublicAnyone scanning the QRIdentity, chemistry, capacity, carbon class
Legitimate interestRepairers, refurbishers, recyclersDisassembly, hazardous substances
AuthoritiesMarket surveillance, customsConformity, due-diligence records
CommissionEuropean CommissionReserved data
The frequent failure mode is leaking restricted fields onto the public page. Tier enforcement must be server-side and field-level.

Related in Guides

Explore related across the site

Get compliant

Create your first battery passport.

Self-serve, no sales call. Compliant by 18 February 2027.