- Regulation (EU) 2016/679 — GDPR, Articles 27 and 28
- Directive 2014/24/EU on public procurement
- Regulation (EU) 2022/2554 — DORA for financial supervisors
- Regulation (EU) 2023/2841 on cybersecurity in Union entities
Who has to appoint one
Vendors outside the Union selling software or services to public authorities, hospitals or schools in the EU. The legal minimum is an Article 27 representative; the practical requirement imposed by procurement is usually far more, including EU data residency, EU-based support and contractual guarantees against third-country access.
Thresholds and exemptions
No legal threshold. Procurement thresholds determine which tender procedure applies, but the data requirements attach at any contract size.
What must appear on the label
Not physical. The representative in the privacy notice and in the tender documentation, together with the subprocessor list, the data location statement and the transfer analysis.
Marketplace fields
This is where compliance decides revenue: several member states have excluded or restricted US-based cloud services in public health and education after transfer assessments, and tender questionnaires now ask directly about third-country access to data, including under foreign surveillance laws.
Documentation you must hold
Article 30 records, Article 28 terms meeting the standard clauses many public buyers impose, the Article 27 designation, a transfer impact assessment addressing government access in the vendor's home jurisdiction, subprocessor list with change notification, audit rights, exit and data return plans, and security certifications the buyer requires.
Standards and testing
Security audits and penetration testing are contractual requirements in most public tenders, and some member states require specific national certifications.
Language requirements
Documentation and support in the language of the contracting authority, which is a hard requirement in most public tenders.
When it applies
Before responding to a tender, since the documentation is evaluated as part of the bid rather than after award.
How long records are kept
Per the contract and the authority's retention rules, with verified deletion at exit, which buyers increasingly require to be demonstrable.
What happens if you do not comply
Exclusion from procurement, contract termination, and GDPR fines. Reputationally, a public authority terminating a contract over data protection is reported and affects every subsequent bid.
Who enforces it
Data protection authorities, contracting authorities and national supervisory bodies, and in health the sectoral regulators.
Where the boundary lies
The Article 27 representative is necessary but nowhere near sufficient for this market. What decides tenders is data residency, the transfer impact assessment and whether the vendor is subject to third-country laws compelling disclosure. Vendors that treat it as a paperwork exercise lose the deals.
Questions we are asked
- Is an EU representative enough to sell to public buyers?
- Legally it satisfies Article 27. Commercially, public buyers usually require EU data residency, EU support and a defensible transfer impact assessment as well.
- Does EU hosting solve the transfer problem?
- It helps but does not settle it. If the parent company is subject to laws compelling disclosure of data it can access, the assessment must address that, and several authorities have found EU hosting alone insufficient.
Who signs for you
EU representative Europe Services, SE — Na Čečeličce 425/4, Smíchov, 150 00 Praha 5, Czech Republic
UK representative REP27 LTD — Unit 82a James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom