- Regulation (EU) 2016/679 — GDPR, Articles 10, 14 and 27
- Directive (EU) 2015/849 — anti-money laundering
- Regulation (EU) 2024/1689 — AI Act
- Regulation (EU) 2022/2065 — DSA where reports are hosted
Who has to appoint one
Providers established outside the Union that build due diligence reports, screening results or investigation dossiers about people in the EU: OSINT platforms, adverse media and sanctions screening vendors, background checking services, and investigation firms selling to banks, law firms and corporates. The obligation attaches whether the subject is a customer of your client or a third party never in contact with anyone: the test is whether you process personal data of people in the Union, not whether they asked you to.
Thresholds and exemptions
No threshold. What changes the analysis is the role: a vendor that only executes the client's search on the client's instructions can be a processor, but the moment you build entity graphs across clients, retain collected material beyond delivery, or use reports to train or improve your models, you are a controller for those purposes and need a representative in your own right.
What must appear on the label
Not a physical label. What must be published is the representative's identity and contact details in the privacy notice, together with the information required by Article 14 for people whose data you obtained from sources other than themselves — which in this sector is nearly everyone.
Marketplace fields
Banks, law firms and regulated institutions run vendor due diligence before onboarding, and the data protection answers decide contracts. Several national supervisory authorities have investigated screening and adverse media vendors, and the findings have concerned retention, accuracy and the absence of Article 14 notice rather than the searching itself.
Documentation you must hold
Article 30 records mapping every source, every enrichment step and every output. The Article 27 designation with a scope that expressly covers Article 10 data if you process it. A data protection impact assessment, which is mandatory here: profiling, systematic monitoring and large-scale special-category or criminal-offence data are all on the Article 35(3) list. Documentation of the Article 14(5) exemption you rely on and of the reasoning behind it. Accuracy and rectification procedures, including how a wrong match is corrected across delivered reports. Retention schedules per data category. Transfer documentation. Where an AI system is used, the technical documentation and classification against the AI Act.
Standards and testing
Not product testing, but two evidence-based checks decide enforcement outcomes. Accuracy: false positives in screening cause real harm, so the matching logic, its error rate and the human review step must be documented. And bias evaluation where the system profiles or scores people, which the AI Act requires for high-risk systems and which discrimination law requires regardless.
Language requirements
The privacy notice, the Article 14 information and any communication with data subjects in the language of the person concerned. Reports themselves are business documents and follow the client's language.
When it applies
The representative before processing begins. Article 14 information within a reasonable period and at the latest within one month of obtaining the data, unless an exemption applies. AI Act high-risk obligations from 2 August 2026 where the system falls in Annex III.
How long records are kept
This is the sharpest point in the category. Reports and the underlying collected material may be kept only as long as necessary, and the client's AML retention obligation is the client's, not yours: retaining dossiers indefinitely because they might be useful later has no lawful basis. Where you act as processor, deletion on the client's instruction must be real and demonstrable.
What happens if you do not comply
Up to €20 million or 4% of total worldwide annual turnover. The exposure in this sector is compounded because subjects who discover a report exercise access rights aggressively, and an access request reveals the whole processing: sources, inferences, retention and recipients. Defamation and rectification claims run in parallel through national courts, on shorter timescales than a supervisory investigation.
Who enforces it
Data protection authorities in any member state where subjects are located, since a controller without an EU establishment has no lead authority. Financial supervisors where the client is a regulated institution. AI Act market surveillance authorities from 2026. National courts for accuracy and reputation claims.
Where the boundary lies
Article 10 is the wall. Processing of personal data relating to criminal convictions and offences may be carried out only under the control of official authority or when authorised by Union or member state law providing appropriate safeguards. A private company screening for criminal records needs that national authorisation, and it differs by member state: some permit it for AML-obliged entities, others do not permit it for commercial vendors at all. Sanctions and PEP lists are a different matter and are generally lawful, but adverse media routinely contains allegations of criminal conduct, which brings Article 10 back in through the side door. A representative mandate that does not expressly cover this is worthless in an investigation.
Questions we are asked
- We only search public sources — is that still processing?
- Yes. Collecting, structuring and analysing publicly available information about identifiable people is processing, and the fact that a source is public does not create a legal basis or remove the Article 14 duty.
- Do we have to tell the subject we profiled them?
- Article 14 requires it, with exemptions in Article 14(5) including where notification would be impossible or involve disproportionate effort, or where it would render impossible or seriously impair the objectives of the processing. Those exemptions must be documented and assessed case by case, not assumed for the whole business.
- Are we a controller or a processor?
- If the client defines the subject and the purpose and you only execute, processor is arguable. If you enrich across clients, retain material afterwards, or improve your models with it, you are a controller for those purposes whatever the contract says.
- Is our system high-risk under the AI Act?
- It depends on the use. Systems evaluating creditworthiness or access to essential services are Annex III. Systems used by law enforcement for risk assessment are too. A tool sold only to private compliance teams may sit outside, but the classification must be documented, not assumed.
Who signs for you
EU representative Europe Services, SE — Na Čečeličce 425/4, Smíchov, 150 00 Praha 5, Czech Republic
UK representative REP27 LTD — Unit 82a James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom