How do you collect DPP data from tier 2 and tier 3 suppliers?
Passport data starts in spinning mills, dye houses and fabric mills that most brands never contract directly. A practical method for mapping, requesting, verifying and maintaining upstream supplier data.
KEY TAKEAWAYS Summary by the editors
- Digital Product Passport data on materials and origin mostly sits with tier 2 and tier 3 suppliers such as fabric mills, dye houses and spinners, which brands rarely contract directly.
- In a 2025 Oritain and Sourcing Journal survey of more than 450 fashion professionals, 56 percent of businesses had no traceability plan in place or were not actively tracing goods.
- The same survey found that 46 percent of cotton-dominant businesses had visibility to tier 4, but only 44 percent always or often verified supplier data.
- Collecting upstream data works best through tier 1 suppliers, using shared facility identifiers such as Open Supply Hub IDs and a small, stable request template per material.
- AI can extract and check data from certificates and transaction documents, but it cannot replace physical or documentary verification of origin claims.
You collect Digital Product Passport data from tier 2 and tier 3 suppliers by working through your tier 1 manufacturers, asking for a small set of standardised facts per material, linking each fact to evidence such as certificates and transaction documents, and verifying a risk-based sample. The hard part is not the software but the relationships: most brands have no contract with the mills and spinners that hold the data.
Why is tier 2 and tier 3 data so hard to get?
A garment's passport will be built largely from upstream facts: fibre composition and origin, recycled content, the facilities that spun, knitted, wove, dyed and finished the material, and the chemicals and certificates associated with them. These sit with suppliers two or three steps removed from the brand. Tier 1 garment factories buy fabric from mills, which buy yarn from spinners, which buy fibre from traders or producers.
Industry data shows the gap between intent and practice. In the 2025 Future of Fashion Traceability report by Oritain and Sourcing Journal, based on more than 450 industry professionals, nearly 40 percent of businesses said they were fully or almost fully committed to end-to-end traceability, yet 56 percent had no traceability plan or were not actively tracing goods. Among cotton-dominant businesses, 46 percent reported visibility to tier 4, but only 44 percent always or often verified supplier data.
Typical obstacles include:
- No contractual leverage: upstream suppliers owe the brand nothing and may see data requests as a cost or a commercial risk.
- Many small buyers: a mill serves dozens of brands, each sending a different questionnaire.
- Batch mixing: fibre lots are blended, which breaks simple one-to-one tracing.
- Inconsistent naming: the same facility appears under several names and addresses.
What data should you request from upstream suppliers?
The final textile data list will be set by the ESPR delegated act, which is still pending. A sensible starting point is the data that almost any version of the passport, and any due diligence process, will need. Keep the template short and stable so suppliers can reuse answers across customers.
| Tier | Typical supplier | Core data | Evidence |
|---|---|---|---|
| Tier 1 | Garment factory | Facility identity, products made, subcontractors used | Facility ID, purchase orders, subcontracting declaration |
| Tier 2 | Fabric mill, dye house, finisher | Fabric composition, processes, chemicals management, facility identity | Test reports, chemical inventory or certification, invoices to tier 1 |
| Tier 3 | Spinner, yarn supplier | Yarn composition, fibre sources, blend ratios | Transaction certificates, yarn invoices, lot records |
| Tier 4 | Fibre producer, ginner, recycler | Fibre type, country or region of origin, recycled or certified share | Scope or transaction certificates, origin documents, test results |
How do you run an upstream data collection step by step?
- Prioritise: start with the materials and countries that carry the highest volume or the highest risk, for example cotton from high-risk regions, rather than the whole assortment.
- Map through tier 1: ask garment factories to name their fabric and trim suppliers per style or per order, and make this a contractual requirement in new supplier agreements.
- Use shared identifiers: record facilities with a persistent ID. Open Supply Hub, an open supply chain mapping platform, assigns OS IDs to facilities with names and addresses, which reduces duplicates. The new EN 18219 standard also covers unique identifiers for operators and facilities.
- Request once, reuse often: send a short template per material, accept existing certificates and test reports, and avoid bespoke questionnaires.
- Link data to transactions: connect each claim to an order, invoice or transaction certificate so that it describes the goods you actually bought, not the supplier in general.
- Verify by risk: check a sample of claims with document audits, site visits or physical testing, weighted towards high-risk materials.
- Maintain: set review dates, because suppliers, certificates and blends change every season.
How can you verify that upstream data is true?
Self-declared data is a starting point, not proof. The OECD Due Diligence Guidance for Responsible Supply Chains in the Garment and Footwear Sector, published in 2018, describes a risk-based approach in which companies identify where risks are most severe and focus their efforts there. The same logic applies to passport data: not every attribute needs the same level of assurance.
Physical methods can complement documents. C&A, for example, works with Haelixa, which applies DNA markers to organic cotton at ginning and tests them along the chain with forensic PCR tests; the companies announced a three-year agreement in December 2024 after a pilot that began in 2022. Such methods confirm that a specific marked material is present, but they do not on their own document every processing step.
Where does AI help in supplier data collection?
Upstream data arrives as PDFs, spreadsheets, photographs of certificates and emails in several languages. AI is well suited to this layer:
- Extracting certificate numbers, validity dates, facility names and material shares from documents.
- Matching facility names to existing identifiers and flagging likely duplicates.
- Checking consistency, for example whether fibre shares add up or whether a certificate has expired before the shipment date.
- Translating and summarising supplier responses for sourcing teams.
Human review remains essential. A model can misread a scanned certificate or match two different mills with similar names. Keep a clear record of which values were extracted automatically and which were confirmed, and never let a model fill gaps with estimates presented as supplier data.
What makes suppliers willing to share data?
Suppliers respond to predictability and reuse. Brands that align on common templates and identifiers, give reasonable lead times, share the purpose of the request and offer something back, such as longer order commitments or help with certification, tend to get better answers. Treat data as part of the sourcing relationship, discussed in the same meetings as price and lead time, rather than as a separate compliance exercise.
Start now even though the textile delegated act is not final. The mapping, identifiers and evidence habits built today will serve due diligence and forced-labour rules as much as the passport.
Frequently asked questions
What is the difference between tier 1, tier 2 and tier 3 suppliers in fashion?
Tier 1 suppliers make the finished product, usually garment factories. Tier 2 suppliers provide materials and processing such as fabric mills, dye houses and finishers. Tier 3 suppliers are typically spinners and yarn producers, with fibre producers and ginners often called tier 4.
Do brands need tier 2 and tier 3 data for the Digital Product Passport?
Very likely, because passport information on materials and origin is produced upstream. The exact data list will be set by the textile delegated act under ESPR, which is tentatively planned for adoption in 2027, so brands should prepare for upstream data without knowing every final field.
How can a brand get data from suppliers it does not contract directly?
Usually through tier 1 suppliers, by making supplier disclosure part of purchasing contracts and asking factories to pass on standard requests. Shared facility identifiers, common templates and acceptance of existing certificates make it easier for upstream suppliers to respond.
Can AI verify supplier sustainability data?
AI can check documents for consistency, extract data and flag anomalies, but it cannot confirm that a physical material came from where a document says. Verification still needs audits, transaction records and, for high-risk materials, physical testing.
One edition every weekday morning. Read in five minutes. Free for industry professionals.
SOURCES
- Oritain: 5 key insights from the 2025 Future of Fashion Traceability report
- OECD: Due Diligence Guidance for Responsible Supply Chains in the Garment and Footwear Sector
- Open Supply Hub: About
- Renewable Carbon News: Haelixa enhances organic cotton traceability with C&A partnership
- WIoT Group: CEN-CENELEC publishes six EU DPP standards