Skip to content

docs: correct the access-control model against the primary text - #10

Open
LKSNDRTMLKV wants to merge 1 commit into
mainfrom
docs/access-control-primary-text
Open

docs: correct the access-control model against the primary text#10
LKSNDRTMLKV wants to merge 1 commit into
mainfrom
docs/access-control-primary-text

Conversation

@LKSNDRTMLKV

Copy link
Copy Markdown
Member

What

The published docs site carried a false regulatory claim on a customer-facing page.

regulatory/access-control.mdx was titled "Access Control (Art. 10)" and opened:

"ESPR Article 10 establishes that a Digital Product Passport carries three categories of information with different access rules… an implementation that does not enforce them is not compliant."

Verified against the OJ text (dpp-docs/reference/legal/OJ_L_202401781_EN_TXT.pdf):

  • Article 10 is titled "Requirements for the digital product passport" and establishes no access categories.
  • ESPR fixes no access tiers at all. Art. 11(b) requires access "based on their respective access rights set out in the applicable delegated act adopted pursuant to Article 4", and Art. 9(2)(f) delegates the actor-to-data mapping per product group. No such delegated act has been adopted for any ESPR sector.
  • The Public / Restricted / Private model was the superseded ordinal scheme, and "Private = commercially confidential to the operator" is not a regulatory category in any instrument.

So the page asserted a compliance obligation that does not exist, and two other pages linked to it — one describing the model as applying "across all sectors".

What replaces it

  • What ESPR actually says, quoting Art. 11(b) in full
  • Where a specified model does exist — Battery Reg. (EU) 2023/1542 Art. 77(2), and why it is a lattice, not a ranking (an authority does not get Annex XIII point 4; a recycler does not get point 3)
  • The constraints common to every regime: free of charge, no registration or password for consumers, and multi-year retention surviving insolvency
  • Why durable artefacts are keyed by disclosure class rather than audience name

The credential-vs-API-keys argument was sound and survives — strengthened, since ESPR Art. 11 explicitly empowers implementing acts on "digital credentials of economic operators and other relevant actors that have access rights", and the toy and detergent regulations both defer to that same provision.

Also

Fixed the two inbound links, and replaced residual "access tier" phrasing in core-concepts, engine/architecture and what-odal-can-and-cannot-see with the disclosure-class vocabulary.

No sign-up or paywall copy was found anywhere — the site was already clean on that point.

ESPR Article 10 is Requirements for the digital product passport and defines no tiers; access is Art. 11(b), free of charge, with the actor-to-data mapping delegated per product group under Art. 9(2)(f) and no such act adopted yet, so the public Public/Restricted/Private tier page was wrong at its premise and is replaced by the Battery Art. 77(2) lattice plus the constraints common to every regime.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant