product-guide

Will the Battery Passport Expose Our BOM and Trade Secrets to Competitors?

No — the passport model has public and restricted attribute tiers, with role-based access for regulators and recyclers. Here's what's actually visible to whom, and how evidence stays confidential.

The short answer

No. The passport framework was designed by people who anticipated exactly this fear: it distinguishes public attributes (accessible to anyone scanning the code) from non-public attributes (requiring authentication, held under strict business confidentiality), with access defined by role — consumers, recyclers, and regulators each see what's relevant to their needs. Your detailed BOM, supplier list, and process data are not part of the public tier.

What's actually public

The consumer-facing tier is closer to an enhanced label than an engineering disclosure: manufacturer identity, manufacturing location and country of production, the declared carbon footprint, chemistry class and critical raw material shares, recycled content, and end-of-life instructions. Broad-brush by design — "contains cobalt from responsibly sourced supply chains," not "cathode supplier X, plant Y, line Z."

What's restricted, and to whom

Deeper tiers open only to authenticated roles:

  • Regulators and market surveillance — due-diligence report references, conformity documentation, the compliance trail.
  • Recyclers and second-life operators — disassembly-relevant composition detail and per-unit state-of-health data that would be commercially sensitive in public but is essential to safely process the battery.
  • You — everything, including the full version history of what was published and when.

The mechanism that keeps evidence confidential

The cleverest part of the model (visible in the W3C Verifiable Credential implementations of the battery passport) is the separation of claim from evidence. The passport states a declared value — say, GHG emissions intensity — alongside a link to an external certificate held by the certifier, plus a SHA-256 hash of that document. Anyone entitled to verify can confirm the evidence exists and hasn't been tampered with; nobody gets the document itself unless you or your certifier grants access. Proof without disclosure.

The same logic extends across the supply chain: the passport is a graph of linked records in which each manufacturer controls its own node and its own access rules. Your cell supplier's node protects their secrets from you, and yours protects your integration know-how from your OEM customer.

The fear worth keeping

One disclosure is real and intentional: public claims become checkable. A carbon figure, an origin statement, a recycled-content percentage — once published at unit level, these can be compared across competitors and revisited by journalists and buyers. Companies whose marketing has been running ahead of their data will find that gap visible. The answer isn't resisting the passport; it's making sure your claims are the ones that survive scrutiny — a sales asset, if your numbers are real.

What this means for your team

Classify your passport fields into public / restricted / internal before publishing anything, and involve whoever owns commercial confidentiality in that one meeting. The framework gives you the tiers; the only real risk is not deciding deliberately which fields go where.

Frequently asked questions

Ready to see how this applies to your product line?

Talk to us about building a Digital Product Passport pipeline that scales across every category you sell into.

Get in touch