Eugenia Vitali
26 Aug 2026
Brands that fight counterfeiting deploy authentication. Brands that manage grey market diversion deploy traceability. Brands that want regulatory compliance deploy digital product passports. They are buying three solutions to problems that share one infrastructure. This guide explains what each capability does, how they are connected, and what becomes possible when they are treated as a unified system rather than separate investments.
Authentication was a brand protection problem, owned by legal or security teams, addressed by holograms, serial codes, and eventually NFC chips. Traceability was a supply chain problem, owned by operations, addressed by logistics scanning and ERP records that tracked units through distribution. Digital product identity is a newer concept, emerging from the intersection of regulatory pressure (the EU Digital Product Passport), consumer engagement, and the commercial value of post-sale product data.
Because these capabilities developed separately, organisations frequently deploy them separately — and pay three times for what is fundamentally one infrastructure. The NFC chip that authenticates the product is the same data carrier the DPP regulation mandates. The custody chain that traceability tracks is the same record that grey-market detection reads. The product identity record is the foundation of all three.
The practical cost of treating them separately: A brand that deploys NFC authentication for brand protection, a logistics scanning system for traceability, and a compliance data record for DPP is operating three systems that all start with the same thing, a unique identifier for each physical unit. If those identifiers are not the same one, the brand has created data silos that cannot talk to each other. Consumer authentication events are invisible to the supply chain team. Custody records are invisible to the compliance team. The commercial intelligence that would emerge from combining them does not exist.
The shared dependency: All four capabilities depend on the same starting point a unique identifier for each physical unit, linked to a cloud record, accessible via a data carrier on the product. Authentication validates the identifier cryptographically. Traceability records events against it. Digital product identity is the record itself. The DPP is the regulatory expression of what that record must contain. One identifier. One record. Four outputs.
An NFC chip implementing AES-128 challenge-response authentication is embedded in the product during production — not applied afterward. Each chip is encoded with a unique serialised identifier (SGTIN-compliant) and linked to the brand’s cloud platform. The chip’s secret key cannot be read externally; authentication requires the physical chip. This is the property that makes authentication a product-level security guarantee rather than a packaging-level one.
The connection between authentication, traceability, and digital product identity is not just architectural it produces specific commercial capabilities that neither authentication nor traceability delivers in isolation.
When authentication, traceability, and digital product identity are unified, the combined system produces outputs across brand protection, supply chain intelligence, consumer engagement, and regulatory compliance from the same per-unit NFC deployment.
Why this matters for investment decisions: A brand considering NFC authentication as a brand protection investment is also, from the same deployment, acquiring grey-market detection capability, consumer engagement infrastructure, secondary market intelligence, and a DPP compliance foundation. These are not add-ons, they are outputs of the same chip and record, differentiated only by which questions the platform is configured to answer. The cost of the infrastructure is constant; the decision to use it for one purpose or five is a configuration decision, not an infrastructure cost decision.
Authentication, traceability, grey-market intelligence, consumer engagement, and DPP compliance from a single NFC deployment — built for luxury, spirits, beauty, and fashion brands.
A digital product identity is a unique record in a brand’s cloud platform, linked to a specific physical product unit via a data carrier — typically an NFC chip embedded in the product. It is created at manufacture, when the chip is encoded with a unique identifier and paired with a product record storing the unit’s model, batch, production date, and allocated distribution territory. Everything that happens thereafter: distribution scans, authentication events, ownership transfers, service events, is appended to this record as it occurs. The identity persists for the product’s full lifetime, regardless of how many times it changes hands.
Authentication alone detects fakes. Traceability alone shows where genuine products go. Brand protection requires both because the two most commercially significant threats require different detection mechanisms. A counterfeit product fails authentication. A grey-market product is genuine and passes authentication; detecting it requires knowing where the product is relative to where it was allocated. Without traceability, a brand knows a product is genuine but not whether it is in the right market. Without authentication, it cannot distinguish genuine from fake. Together, through a shared product identity record, they cover the full brand protection problem.
The EU Digital Product Passport (DPP) under the Ecodesign for Sustainable Products Regulation requires brands to attach a digital data carrier to each product linking to a record of material composition, environmental footprint, repairability, and end-of-life guidance. The NFC chip used for product authentication is the same data carrier the DPP mandates, and the product identity record created for authentication is the foundation of the DPP compliance record. Brands deploying NFC authentication now are simultaneously building DPP compliance infrastructure. The authentication deployment is the DPP deployment.
Connected product technology delivers all three simultaneously from the same per-unit NFC chip. The chip provides authentication (cryptographic challenge-response at consumer tap), traceability (each custody event logged against the chip’s identifier), and identity (the persistent cloud record that accumulates all lifecycle data). Each consumer tap, each distribution scan, each ownership transfer is both a data event for the brand and an interaction point for the consumer. The infrastructure is deployed once; authentication, traceability, identity, compliance, and consumer engagement are generated continuously from every subsequent interaction.
Talk to our team