← HomeREP27All categories

Crypto, wallets and fintech apps

Data protection

In short
Article 27 GDPR representative, and for crypto-asset services an authorised entity established in the Union

Who has to appoint one

Providers established outside the Union offering crypto-asset services or payment functionality to people in the EU. Two different questions arise: the data question, answered by an Article 27 representative, and the licensing question, which cannot be answered by a representative at all — MiCA requires authorisation of an entity established in a member state, and reverse solicitation is interpreted narrowly.

Thresholds and exemptions

MiCA thresholds depend on the service and the asset type, with heavier rules for significant asset-referenced and e-money tokens. GDPR has no threshold.

What must appear on the label

Not physical. The representative's identity in the privacy notice, plus the extensive MiCA disclosure obligations: the white paper for certain tokens, risk warnings, complaint procedures and the authorisation status of the entity providing the service.

Marketplace fields

App stores require financial services apps to evidence authorisation in the markets targeted, and remove crypto apps that cannot. Payment providers and banks conduct their own due diligence and decline unlicensed operators.

Documentation you must hold

Article 30 records covering identity verification, transaction monitoring and support. The Article 27 designation. Data protection impact assessment, since KYC processing involves identity documents and, where biometric verification is used, special-category data. Retention schedule reconciling GDPR minimisation with AML retention duties. On the regulatory side, the MiCA authorisation file, governance arrangements and the AML programme.

Standards and testing

Not applicable, though biometric identity verification systems raise accuracy and bias questions that a data protection impact assessment must address, and the AI Act may apply to the verification system itself.

Language requirements

Disclosures, risk warnings and complaint procedures in the language of each member state where services are offered.

When it applies

The representative before processing begins. MiCA has applied to crypto-asset service providers since 30 December 2024, with national transitional arrangements that have largely expired.

How long records are kept

AML records for at least five years after the relationship ends, which is a longer retention than GDPR minimisation would suggest and must be documented as a legal obligation rather than assumed.

What happens if you do not comply

GDPR fines up to €20 million or 4%. MiCA penalties are set nationally and include prohibition of activity, which is existential rather than financial. Operating without authorisation is a criminal offence in several member states.

Who enforces it

Data protection authorities, national financial supervisors and ESMA or the EBA depending on the service, and financial intelligence units for AML.

Where the boundary lies

An Article 27 representative does not make an unauthorised service lawful. This is the most consequential misunderstanding in the sector: appointing a representative satisfies the GDPR and nothing else, while offering regulated services into the Union without authorisation exposes the operator to enforcement that a data appointment cannot mitigate.

Questions we are asked

Does a GDPR representative let us serve EU customers?
No. It satisfies Article 27 only. Offering crypto-asset services in the Union requires authorisation under MiCA of an entity established in a member state.
Is reverse solicitation a way in?
It is interpreted very narrowly: a genuinely unsolicited approach by a client, with no marketing, no localisation and no EU-facing promotion. Regulators treat claimed reverse solicitation with scepticism.
EU representative · from €290 / year

Who signs for you
EU representative Europe Services, SE — Na Čečeličce 425/4, Smíchov, 150 00 Praha 5, Czech Republic
UK representative REP27 LTD — Unit 82a James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom

Talk to usCheck your category