- Regulation (EU) 2023/1114 — MiCA
- Regulation (EU) 2016/679 — GDPR, Article 27
- Directive (EU) 2015/849 — anti-money laundering
- Regulation (EU) 2023/1113 — transfer of funds and crypto-assets
- Directive (EU) 2015/2366 — PSD2 where payment services are provided
Who has to appoint one
Providers established outside the Union offering crypto-asset services or payment functionality to people in the EU. Two different questions arise: the data question, answered by an Article 27 representative, and the licensing question, which cannot be answered by a representative at all — MiCA requires authorisation of an entity established in a member state, and reverse solicitation is interpreted narrowly.
Thresholds and exemptions
MiCA thresholds depend on the service and the asset type, with heavier rules for significant asset-referenced and e-money tokens. GDPR has no threshold.
What must appear on the label
Not physical. The representative's identity in the privacy notice, plus the extensive MiCA disclosure obligations: the white paper for certain tokens, risk warnings, complaint procedures and the authorisation status of the entity providing the service.
Marketplace fields
App stores require financial services apps to evidence authorisation in the markets targeted, and remove crypto apps that cannot. Payment providers and banks conduct their own due diligence and decline unlicensed operators.
Documentation you must hold
Article 30 records covering identity verification, transaction monitoring and support. The Article 27 designation. Data protection impact assessment, since KYC processing involves identity documents and, where biometric verification is used, special-category data. Retention schedule reconciling GDPR minimisation with AML retention duties. On the regulatory side, the MiCA authorisation file, governance arrangements and the AML programme.
Standards and testing
Not applicable, though biometric identity verification systems raise accuracy and bias questions that a data protection impact assessment must address, and the AI Act may apply to the verification system itself.
Language requirements
Disclosures, risk warnings and complaint procedures in the language of each member state where services are offered.
When it applies
The representative before processing begins. MiCA has applied to crypto-asset service providers since 30 December 2024, with national transitional arrangements that have largely expired.
How long records are kept
AML records for at least five years after the relationship ends, which is a longer retention than GDPR minimisation would suggest and must be documented as a legal obligation rather than assumed.
What happens if you do not comply
GDPR fines up to €20 million or 4%. MiCA penalties are set nationally and include prohibition of activity, which is existential rather than financial. Operating without authorisation is a criminal offence in several member states.
Who enforces it
Data protection authorities, national financial supervisors and ESMA or the EBA depending on the service, and financial intelligence units for AML.
Where the boundary lies
An Article 27 representative does not make an unauthorised service lawful. This is the most consequential misunderstanding in the sector: appointing a representative satisfies the GDPR and nothing else, while offering regulated services into the Union without authorisation exposes the operator to enforcement that a data appointment cannot mitigate.
Questions we are asked
- Does a GDPR representative let us serve EU customers?
- No. It satisfies Article 27 only. Offering crypto-asset services in the Union requires authorisation under MiCA of an entity established in a member state.
- Is reverse solicitation a way in?
- It is interpreted very narrowly: a genuinely unsolicited approach by a client, with no marketing, no localisation and no EU-facing promotion. Regulators treat claimed reverse solicitation with scepticism.
Who signs for you
EU representative Europe Services, SE — Na Čečeličce 425/4, Smíchov, 150 00 Praha 5, Czech Republic
UK representative REP27 LTD — Unit 82a James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom