[{"data":1,"prerenderedAt":860},["ShallowReactive",2],{"legal-en-biber-dpp\u002Fexit\u002Fv1.1":3},{"id":4,"title":5,"body":6,"description":847,"extension":848,"meta":849,"metaDescription":850,"metaTitle":851,"navigation":852,"path":853,"seo":854,"slug":855,"stem":856,"updated":857,"version":858,"__hash__":859},"legal_en\u002Fen\u002Flegal\u002Fbiber-dpp\u002Fexit-v1-1.md","Exit and Migration Concept",{"type":7,"value":8,"toc":822},"minimark",[9,13,28,33,36,39,52,56,124,128,163,167,226,229,233,238,310,313,316,320,349,352,356,359,363,413,416,420,431,435,446,450,453,529,532,535,539,542,574,577,581,586,603,608,622,625,629,643,646,650,687,692,696,699,702,706],[10,11,12],"p",{},"Biber DPP – software-as-a-service platform for digital product passports",[10,14,15,16,19,20,22,23],{},"Published by: BCCM Inkubator GmbH (Biberware brand), Bahnhofstraße 32, 09648 Mittweida, Germany",[17,18],"br",{},"\nResponsible: Lucas Johns",[17,21],{},"\nContact: ",[24,25,27],"a",{"href":26},"mailto:info@biberware.com","info@biberware.com",[29,30,32],"h2",{"id":31},"_1-purpose-and-scope","1 Purpose and scope",[10,34,35],{},"This concept describes how customers of Biber DPP can extract their data and their published digital product passports (DPP) from the Platform completely, securely and without depending on Biberware. They can then continue to run the data and passports with another provider or on their own infrastructure.",[10,37,38],{},"It applies to all Biber DPP service packages. Services designated as beta, preview or test environment are excluded under Section 4(3) of the Terms.",[10,40,41,42,46,47,51],{},"This concept gives effect to the provisions on data export, provider switching and deletion in Section 10 of the ",[24,43,45],{"href":44},"\u002Fen\u002Flegal\u002Fbiber-dpp\u002Fagb\u002Fv1.1","general terms and conditions"," (the \"Terms\") and supplements the ",[24,48,50],{"href":49},"\u002Fen\u002Flegal\u002Fbiber-dpp\u002Favv\u002Fv1.1","data processing agreement"," (the \"DPA\") for Biber DPP. Where mandatory requirements of Regulation (EU) 2023\u002F2854 (Data Act) provide for more extensive rights, those prevail.",[29,53,55],{"id":54},"_2-reference-framework","2 Reference framework",[57,58,59,72],"table",{},[60,61,62],"thead",{},[63,64,65,69],"tr",{},[66,67,68],"th",{},"Basis",[66,70,71],{},"Relevance for this concept",[73,74,75,84,92,100,108,116],"tbody",{},[63,76,77,81],{},[78,79,80],"td",{},"Regulation (EU) 2023\u002F2854 (Data Act), Chapter VI",[78,82,83],{},"Switching between data processing services: notice period, transition and retrieval period, exportable data, deletion, switching charges",[63,85,86,89],{},[78,87,88],{},"ISO\u002FIEC 27001:2022",[78,90,91],{},"Requirements for cloud services, information transfer, deletion, continuity (mapped in Annex A)",[63,93,94,97],{},[78,95,96],{},"GDPR and the Biber DPP DPA",[78,98,99],{},"Return and deletion of personal data after the contract ends (clause 10 DPA)",[63,101,102,105],{},[78,103,104],{},"Regulation (EU) 2024\u002F1781 (ESPR) and Regulation (EU) 2023\u002F1542 (Batteries Regulation)",[78,106,107],{},"Obligation of the economic operator to keep product passports available for a defined period",[63,109,110,113],{},[78,111,112],{},"EN 18221:2026 (Digital product passport – Data storage, archiving, and data persistence)",[78,114,115],{},"European standard under the ESPR: archiving of historical passport versions and persistence of passports, including beyond the existence of the economic operator and including replication to backup operators",[63,117,118,121],{},[78,119,120],{},"Biber DPP Terms, version 1.1",[78,122,123],{},"Term, termination, data export and continuity of published product passports (Sections 9, 10)",[29,125,127],{"id":126},"_3-guiding-principles","3 Guiding principles",[129,130,131,139,145,151,157],"ul",{},[132,133,134,138],"li",{},[135,136,137],"strong",{},"The customer owns the data."," All product and passport data belongs to the customer. Biberware acquires no rights in it (Section 11(2) of the Terms).",[132,140,141,144],{},[135,142,143],{},"Export at any time."," Throughout the term of the contract the customer may request a full export at any time and access its data directly via the API at any time.",[132,146,147,150],{},[135,148,149],{},"Open, documented formats."," Exports are provided in structured, commonly used and machine-readable formats with published schemas: JSON, W3C Verifiable Credentials and original files.",[132,152,153,156],{},[135,154,155],{},"Customer-controlled identifiers."," Data carriers on products point to a domain the customer controls. Switching provider therefore requires no change to products already placed on the market.",[132,158,159,162],{},[135,160,161],{},"Traceability."," Every export contains a manifest with checksums. Every deletion is confirmed in text form on request.",[29,164,166],{"id":165},"_4-exit-scenarios","4 Exit scenarios",[57,168,169,182],{},[60,170,171],{},[63,172,173,176,179],{},[66,174,175],{},"Scenario",[66,177,178],{},"Description",[66,180,181],{},"Covered in",[73,183,184,195,205,216],{},[63,185,186,189,192],{},[78,187,188],{},"Ordinary termination",[78,190,191],{},"The customer stops using the service and takes the data over itself or no longer needs it.",[78,193,194],{},"Chapter 7",[63,196,197,200,203],{},[78,198,199],{},"Switching to another DPP provider",[78,201,202],{},"The customer transfers data and published passports to another provider or to its own infrastructure.",[78,204,194],{},[63,206,207,210,213],{},[78,208,209],{},"Discontinuation of the service or insolvency of Biberware",[78,211,212],{},"Biberware discontinues Biber DPP as planned or cannot continue operations.",[78,214,215],{},"Chapter 8",[63,217,218,221,224],{},[78,219,220],{},"Insolvency of the customer",[78,222,223],{},"The customer can no longer keep its passports available itself; the statutory availability obligation continues.",[78,225,215],{},[10,227,228],{},"The backup copy with an independent service provider required by law is also covered in chapter 8.",[29,230,232],{"id":231},"_5-exportable-data-and-formats","5 Exportable data and formats",[234,235,237],"h3",{"id":236},"_51-scope","5.1 Scope",[57,239,240,253],{},[60,241,242],{},[63,243,244,247,250],{},[66,245,246],{},"Data category",[66,248,249],{},"Content",[66,251,252],{},"Format",[73,254,255,266,277,288,299],{},[63,256,257,260,263],{},[78,258,259],{},"Product passports",[78,261,262],{},"All published passports of the workspace including their complete version history",[78,264,265],{},"JSON, conforming to the published JSON schemas",[63,267,268,271,274],{},[78,269,270],{},"Verifiable Credentials",[78,272,273],{},"All issued credentials in the signed form in which they were issued",[78,275,276],{},"W3C Verifiable Credentials (JSON-LD)",[63,278,279,282,285],{},[78,280,281],{},"Documents",[78,283,284],{},"All uploaded files (e.g. certificates, data sheets)",[78,286,287],{},"Original files, unchanged",[63,289,290,293,296],{},[78,291,292],{},"DID document",[78,294,295],{},"Public DID document of the workspace with all current and historical verification keys",[78,297,298],{},"JSON (W3C DID Core)",[63,300,301,304,307],{},[78,302,303],{},"Manifest",[78,305,306],{},"Index of all exported objects with the mapping of passports to documents, timestamps and SHA-256 checksums",[78,308,309],{},"JSON",[10,311,312],{},"Further data, such as drafts and user and supplier lists, is provided by Biberware on request in a commonly used format (JSON or CSV).",[10,314,315],{},"The export does not include the Platform software and its source code (Section 2(2) of the Terms), internal operational and security logs, authentication data such as passwords, or operational backups. Private signing keys are released only under chapter 6.3.",[234,317,319],{"id":318},"_52-export-routes","5.2 Export routes",[57,321,322,331],{},[60,323,324],{},[63,325,326,329],{},[66,327,328],{},"Route",[66,330,178],{},[73,332,333,341],{},[63,334,335,338],{},[78,336,337],{},"Self-service export",[78,339,340],{},"Request for a full export via the Platform; provided as a ZIP archive containing all data under 5.1.",[63,342,343,346],{},[78,344,345],{},"REST API",[78,347,348],{},"Programmatic access to passports, versions, credentials and documents at any time, documented via OpenAPI. Suitable for regular backups of your own and for direct transfer by a target provider.",[10,350,351],{},"The export package is available for download no later than seven calendar days after the request. Only administrative users of the customer can download it, and only over authenticated, TLS-encrypted connections.",[29,353,355],{"id":354},"_6-identifiers-resolvers-and-credentials","6 Identifiers, resolvers and credentials",[10,357,358],{},"The critical point in any DPP provider switch is the data carrier (QR code, data matrix, RFID) on the product. It is applied once and points to the same address permanently. Biber DPP is therefore designed so that this address is under the customer's control.",[234,360,362],{"id":361},"_61-addressing-published-passports","6.1 Addressing published passports",[57,364,365,378],{},[60,366,367],{},[63,368,369,372,375],{},[66,370,371],{},"Variant",[66,373,374],{},"How it works",[66,376,377],{},"Use",[73,379,380,391,402],{},[63,381,382,385,388],{},[78,383,384],{},"Customer domain",[78,386,387],{},"Passports are published under a subdomain of the customer (e.g. dpp.customer.com) that points to Biber DPP via DNS.",[78,389,390],{},"Standard for all production passports",[63,392,393,396,399],{},[78,394,395],{},"GS1 Digital Link resolver",[78,397,398],{},"Data carriers point to the GS1 resolver. The customer maintains the redirect target there.",[78,400,401],{},"Alternative to the customer domain (Business package)",[63,403,404,407,410],{},[78,405,406],{},"Biberware domain",[78,408,409],{},"Passports are served under an address on biberware.com.",[78,411,412],{},"Only for tests, demos and products not placed on the market",[10,414,415],{},"In both production variants the redirect is under the customer's control. The customer can switch the target to another provider or to its own infrastructure at any time and without any involvement of Biberware.",[234,417,419],{"id":418},"_62-cutover-when-switching","6.2 Cutover when switching",[129,421,422,425,428],{},[132,423,424],{},"The target provider or the customer serves the transferred passports under the same paths. The manifest contains the mapping of public address to passport and version for that purpose.",[132,426,427],{},"The customer changes the DNS record of its subdomain or the target in the GS1 resolver.",[132,429,430],{},"Biber DPP continues to serve the passports unchanged during the transition period and the retrieval period. The customer decides when to switch the redirect; public retrieval is not interrupted in the process.",[234,432,434],{"id":433},"_63-verifiable-credentials-and-keys","6.3 Verifiable Credentials and keys",[129,436,437,440,443],{},[132,438,439],{},"Each workspace has its own key pair. The issuer identity is maintained as a DID on the customer domain (did:web). After a switch, the customer or the target provider can therefore serve the DID document.",[132,441,442],{},"Credentials already issued remain verifiable as long as the DID document with the previous verification key can be retrieved. For new credentials, the target provider adds a key of its own. The private key does not have to be transferred for this.",[132,444,445],{},"On express request in text form, Biberware releases the workspace's private key in encrypted form to a body named by the customer. Once the exit is complete, the key is deleted at Biberware.",[29,447,449],{"id":448},"_7-procedure-on-termination-and-provider-switching","7 Procedure on termination and provider switching",[10,451,452],{},"Every termination follows the same procedure, regardless of whether the customer or Biberware gives notice and whether the customer switches to another provider, takes the data over itself or no longer needs it.",[57,454,455,471],{},[60,456,457],{},[63,458,459,462,465,468],{},[66,460,461],{},"Phase",[66,463,464],{},"Duration",[66,466,467],{},"Biberware",[66,469,470],{},"Customer",[73,472,473,487,501,515],{},[63,474,475,478,481,484],{},[78,476,477],{},"1 Switching or termination notice",[78,479,480],{},"Notice period under Section 9 of the Terms (customer: 30 days to the end of a month)",[78,482,483],{},"Confirms receipt within two working days, names the contact person and provides the export documentation",[78,485,486],{},"Gives notice in text form or via the Platform, states the goal (switching provider, self-hosting or deletion) and whether a transition period is requested",[63,488,489,492,495,498],{},[78,490,491],{},"2 Transition period",[78,493,494],{},"At the customer's request, up to 30 calendar days, extendable once by the customer; contract and remuneration continue",[78,496,497],{},"Continues to operate the Platform unchanged, provides the export package no later than seven calendar days after the request and supports the switch",[78,499,500],{},"Imports the data at the target provider, switches DNS or resolver and the DID document, and verifies the transfer",[63,502,503,506,509,512],{},[78,504,505],{},"3 Retrieval period",[78,507,508],{},"30 calendar days from the end of the contract, at no charge",[78,510,511],{},"Keeps export and public retrieval of the passports available",[78,513,514],{},"Completes verification and cutover, requests confirmation of deletion where required",[63,516,517,520,523,526],{},[78,518,519],{},"4 Deletion",[78,521,522],{},"After the retrieval period expires",[78,524,525],{},"Deletes the data under chapter 10 and confirms this on request",[78,527,528],{},"–",[10,530,531],{},"If switching within 30 calendar days is technically not feasible, Biberware notifies the customer within 14 working days of the notice and gives reasons. Biberware states an alternative transition period of no more than seven months. The service continues to run during that time. The contract ends on expiry of the transition period; where there is no transition period it ends on the termination date and the retrieval period begins immediately.",[10,533,534],{},"On request, Biberware coordinates the technical procedure directly with the target provider, for example for a transfer via the API.",[29,536,538],{"id":537},"_8-discontinuation-of-the-service-insolvency-and-backup-copy","8 Discontinuation of the service, insolvency and backup copy",[10,540,541],{},"Biber DPP addresses the risk of Biberware not continuing operations primarily by technical means. Contractual commitments are only enforceable to a limited extent in an insolvency.",[129,543,544,550,556,562,568],{},[132,545,546,549],{},[135,547,548],{},"The redirect stays with the customer."," Production passports run via the customer domain or the GS1 resolver (chapter 6.1). The customer can point retrieval at another source without any involvement of Biberware.",[132,551,552,555],{},[135,553,554],{},"Verifiability stays with the customer."," The DID document is part of every export and is hosted on the customer domain. Credentials remain verifiable as soon as the customer serves it itself.",[132,557,558,561],{},[135,559,560],{},"A full data set can be held by the customer."," Via export and API (chapter 5.2) the customer can obtain a complete data set at any time and hold it itself. Another provider, or the customer on its own infrastructure, can continue to operate from that data set.",[132,563,564,567],{},[135,565,566],{},"Planned discontinuation."," Biberware announces a planned discontinuation of Biber DPP in text form with at least three months' notice (Section 9(2) of the Terms). The procedure under chapter 7 applies in that case too, including the transition and retrieval periods.",[132,569,570,573],{},[135,571,572],{},"Insolvency of the customer."," The obligation to keep product passports available for the period laid down by law also continues where the economic operator itself no longer exists. The backup copy with an independent service provider is intended for that purpose.",[10,575,576],{},"For the backup copy with an independent service provider required by law, Biberware is preparing a shared solution for all customers so that each customer does not have to commission a service provider of its own. Its design will follow the legal acts still pending and the European standard EN 18221:2026. Independently of that, the customer's own domain, the complete export and the DID document already secure the continuation of the passports today.",[29,578,580],{"id":579},"_9-costs","9 Costs",[10,582,583],{},[135,584,585],{},"Free of charge",[129,587,588,591,594,597,600],{},[132,589,590],{},"Self-service and API export throughout the term and during the transition and retrieval periods",[132,592,593],{},"Complete export package including documents, credentials and the DID document",[132,595,596],{},"Export documentation and published schemas",[132,598,599],{},"Information about the switching process and coordination with the target provider",[132,601,602],{},"Deletion and confirmation of deletion",[10,604,605],{},[135,606,607],{},"Charged on a time and materials basis",[129,609,610,613,616,619],{},[132,611,612],{},"Transformation of the data into a target provider's proprietary formats",[132,614,615],{},"Support with import and mapping in the target system",[132,617,618],{},"Individual interfaces or special exports",[132,620,621],{},"Continued operation of published passports beyond the retrieval period (Section 10(7) of the Terms)",[10,623,624],{},"Services charged on a time and materials basis are quoted in advance and billed at the daily rates agreed. Biberware does not charge switching charges for the switching steps required by the Data Act.",[29,626,628],{"id":627},"_10-deletion-on-completion","10 Deletion on completion",[129,630,631,634,637,640],{},[132,632,633],{},"After the retrieval period expires, Biberware deletes all data of the workspace from the database and object storage, including the private signing key.",[132,635,636],{},"Backup copies are deleted on their regular expiry, and no later than 90 days after the contract ends (clause 10(2) DPA).",[132,638,639],{},"Excluded is data subject to statutory retention obligations or required for the establishment, exercise or defence of legal claims, such as contract and billing records. Processing of such data is restricted.",[132,641,642],{},"Biberware confirms the deletion in text form on request.",[10,644,645],{},"Biberware cannot retrieve credentials already published or issued to third parties from those third parties (clause 2(8) DPA).",[29,647,649],{"id":648},"_11-roles-and-responsibilities","11 Roles and responsibilities",[57,651,652,662],{},[60,653,654],{},[63,655,656,659],{},[66,657,658],{},"Role",[66,660,661],{},"Tasks",[73,663,664,672,680],{},[63,665,666,669],{},[78,667,668],{},"Exit contact (Lucas Johns)",[78,670,671],{},"Receipt of switching and termination notices, coordination with the customer and the target provider, quotes for services charged on a time and materials basis",[63,673,674,677],{},[78,675,676],{},"Information security officer (Quinten Stampa)",[78,678,679],{},"Secure provision of exports, release and deletion of keys, carrying out and documenting deletion",[63,681,682,684],{},[78,683,470],{},[78,685,686],{},"Timely notice, cutover of DNS or resolver and the DID document, ensuring the statutory availability of its product passports",[10,688,689,690],{},"Contact for all exit enquiries: ",[24,691,27],{"href":26},[29,693,695],{"id":694},"_12-review","12 Review",[10,697,698],{},"The export function is part of the Platform's automated tests. At least annually, a test workspace is used to check whether a full export is complete. This includes importing the data and verifying the credentials outside Biber DPP.",[10,700,701],{},"This concept is reviewed at least annually and whenever the Platform or the legal requirements change materially, and is adjusted where necessary.",[29,703,705],{"id":704},"annex-a-mapping-to-isoiec-270012022","Annex A: Mapping to ISO\u002FIEC 27001:2022",[57,707,708,721],{},[60,709,710],{},[63,711,712,715,718],{},[66,713,714],{},"Control",[66,716,717],{},"Title",[66,719,720],{},"Implementation in this concept",[73,722,723,734,745,756,767,778,789,800,811],{},[63,724,725,728,731],{},[78,726,727],{},"A.5.14",[78,729,730],{},"Information transfer",[78,732,733],{},"Authenticated, encrypted export, manifest with checksums (5.1, 5.2)",[63,735,736,739,742],{},[78,737,738],{},"A.5.19 \u002F A.5.20",[78,740,741],{},"Information security in supplier relationships and in supplier agreements",[78,743,744],{},"Exit provisions as part of the customer agreement (1, 7)",[63,746,747,750,753],{},[78,748,749],{},"A.5.23",[78,751,752],{},"Information security for use of cloud services",[78,754,755],{},"Documented exit strategy, open formats, support with switching (3–7)",[63,757,758,761,764],{},[78,759,760],{},"A.5.30",[78,762,763],{},"ICT readiness for business continuity",[78,765,766],{},"Safeguards on discontinuation or insolvency (8)",[63,768,769,772,775],{},[78,770,771],{},"A.5.31",[78,773,774],{},"Legal, statutory, regulatory and contractual requirements",[78,776,777],{},"Implementation of the Data Act, GDPR, ESPR and the Batteries Regulation (2, 7)",[63,779,780,783,786],{},[78,781,782],{},"A.5.33",[78,784,785],{},"Protection of records",[78,787,788],{},"Complete version history and credentials in the export (5.1)",[63,790,791,794,797],{},[78,792,793],{},"A.5.34",[78,795,796],{},"Privacy and protection of PII",[78,798,799],{},"Return and deletion under the DPA (10)",[63,801,802,805,808],{},[78,803,804],{},"A.8.10",[78,806,807],{},"Information deletion",[78,809,810],{},"Deletion periods and confirmation of deletion (10)",[63,812,813,816,819],{},[78,814,815],{},"A.8.24",[78,817,818],{},"Use of cryptography",[78,820,821],{},"Key handling, release and deletion (6.3)",{"title":823,"searchDepth":824,"depth":824,"links":825},"",2,[826,827,828,829,830,835,840,841,842,843,844,845,846],{"id":31,"depth":824,"text":32},{"id":54,"depth":824,"text":55},{"id":126,"depth":824,"text":127},{"id":165,"depth":824,"text":166},{"id":231,"depth":824,"text":232,"children":831},[832,834],{"id":236,"depth":833,"text":237},3,{"id":318,"depth":833,"text":319},{"id":354,"depth":824,"text":355,"children":836},[837,838,839],{"id":361,"depth":833,"text":362},{"id":418,"depth":833,"text":419},{"id":433,"depth":833,"text":434},{"id":448,"depth":824,"text":449},{"id":537,"depth":824,"text":538},{"id":579,"depth":824,"text":580},{"id":627,"depth":824,"text":628},{"id":648,"depth":824,"text":649},{"id":694,"depth":824,"text":695},{"id":704,"depth":824,"text":705},"Exportable data, formats and switching steps for Biber DPP, version 1.1, in force from 24 September 2026.","md",{},"Which data can be exported in which formats, how switching to another provider works and when data is deleted.","Exit and Migration Concept (version 1.1)",true,"\u002Fen\u002Flegal\u002Fbiber-dpp\u002Fexit-v1-1",{"title":5,"description":847},"biber-dpp\u002Fexit\u002Fv1.1","en\u002Flegal\u002Fbiber-dpp\u002Fexit-v1-1","2026-09-24","1.1","zBAGrkl9GIsk1BZLPT7EPoNK2COocGAljipXRvBv2Vk",1790327504614]