- Regulation (EU) 2016/679 — GDPR, Articles 27 and 28
- Directive (EU) 2022/2555 — NIS2
- Regulation (EU) 2022/2065 — DSA for hosting services
- Regulation (EU) 2023/2854 — Data Act, switching provisions
Who has to appoint one
Providers established outside the Union that host data or provide software services to customers in the EU. As a processor you need your own Article 27 representative if Article 3(2) applies to you. As a hosting service you need an Article 13 DSA legal representative. If you are a cloud computing, data centre, CDN or managed service provider above the size thresholds, NIS2 adds a third appointment.
Thresholds and exemptions
GDPR has no threshold. NIS2 generally catches entities with at least 50 staff or €10 million turnover, but certain digital infrastructure providers are covered regardless of size. The DSA representative applies to any intermediary offering services in the Union.
What must appear on the label
Publication rather than labelling: the DSA requires the legal representative's name, address, email and telephone to be published in an easily accessible part of the service and notified to the Digital Services Coordinator. The GDPR representative goes in the privacy notice and in the customer-facing data processing terms.
Marketplace fields
Enterprise procurement is the real enforcement here. EU customers require the Article 28 processing terms, the subprocessor list with notification rights, the transfer mechanism, and increasingly evidence of NIS2 registration before signing.
Documentation you must hold
Article 30(2) records for processors. Data processing agreements with every customer and every subprocessor. The Article 27 designation and the DSA representative designation. Standard contractual clauses with transfer impact assessments. NIS2 risk management measures, incident procedures and registration. For the Data Act, the contractual terms on switching and the removal of egress charges within the transition timetable.
Standards and testing
Not product testing, but audit exposure: customers exercise audit rights under Article 28, and NIS2 allows authorities to impose security audits on essential entities. ISO 27001 and SOC 2 do not discharge the legal duties but are what customers ask for first.
Language requirements
Customer-facing terms and the published representative details in the languages of the markets served. NIS2 incident reports in the language accepted by the CSIRT concerned.
When it applies
GDPR representative before processing begins. DSA obligations applicable since 17 February 2024. NIS2 reporting deadlines: early warning within 24 hours, incident notification within 72 hours, final report within one month. Data Act switching provisions phased from September 2025 with egress charges withdrawn from January 2027.
How long records are kept
Processing records for the life of the service. Incident records per NIS2. Customer data only for the contracted period plus the deletion window promised in the processing terms.
What happens if you do not comply
GDPR: up to €10 million or 2% for the missing representative, more for unlawful processing. NIS2: up to €10 million or 2% for essential entities, with management accountability in several member states. DSA: up to 6% of worldwide turnover, ordered by the Digital Services Coordinator.
Who enforces it
Data protection authorities, the CSIRT and competent authority under NIS2, and the Digital Services Coordinator of the member state where the representative is established.
Where the boundary lies
These are three separate appointments with three separate legal bases, and a single provider can hold all three but must be designated for each. The most common gap is a company that appointed an Article 27 representative years ago and assumes it covers the DSA and NIS2, which it does not.
Questions we are asked
- We are only a processor — do we need our own representative?
- Yes, if Article 3(2) applies to your own processing activities. Your customer's representative does not cover you.
- Does ISO 27001 satisfy NIS2?
- No. It is strong evidence toward the risk management measures but does not discharge the registration, reporting or governance duties.
Who signs for you
EU representative Europe Services, SE — Na Čečeličce 425/4, Smíchov, 150 00 Praha 5, Czech Republic
UK representative REP27 LTD — Unit 82a James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom