← HomeREP27All categories

Hosting, cloud and B2B SaaS providers

Digital and connected products

In short
Article 27 GDPR representative, an Article 13 DSA legal representative for hosting, and a NIS2 representative where in scope

Who has to appoint one

Providers established outside the Union that host data or provide software services to customers in the EU. As a processor you need your own Article 27 representative if Article 3(2) applies to you. As a hosting service you need an Article 13 DSA legal representative. If you are a cloud computing, data centre, CDN or managed service provider above the size thresholds, NIS2 adds a third appointment.

Thresholds and exemptions

GDPR has no threshold. NIS2 generally catches entities with at least 50 staff or €10 million turnover, but certain digital infrastructure providers are covered regardless of size. The DSA representative applies to any intermediary offering services in the Union.

What must appear on the label

Publication rather than labelling: the DSA requires the legal representative's name, address, email and telephone to be published in an easily accessible part of the service and notified to the Digital Services Coordinator. The GDPR representative goes in the privacy notice and in the customer-facing data processing terms.

Marketplace fields

Enterprise procurement is the real enforcement here. EU customers require the Article 28 processing terms, the subprocessor list with notification rights, the transfer mechanism, and increasingly evidence of NIS2 registration before signing.

Documentation you must hold

Article 30(2) records for processors. Data processing agreements with every customer and every subprocessor. The Article 27 designation and the DSA representative designation. Standard contractual clauses with transfer impact assessments. NIS2 risk management measures, incident procedures and registration. For the Data Act, the contractual terms on switching and the removal of egress charges within the transition timetable.

Standards and testing

Not product testing, but audit exposure: customers exercise audit rights under Article 28, and NIS2 allows authorities to impose security audits on essential entities. ISO 27001 and SOC 2 do not discharge the legal duties but are what customers ask for first.

Language requirements

Customer-facing terms and the published representative details in the languages of the markets served. NIS2 incident reports in the language accepted by the CSIRT concerned.

When it applies

GDPR representative before processing begins. DSA obligations applicable since 17 February 2024. NIS2 reporting deadlines: early warning within 24 hours, incident notification within 72 hours, final report within one month. Data Act switching provisions phased from September 2025 with egress charges withdrawn from January 2027.

How long records are kept

Processing records for the life of the service. Incident records per NIS2. Customer data only for the contracted period plus the deletion window promised in the processing terms.

What happens if you do not comply

GDPR: up to €10 million or 2% for the missing representative, more for unlawful processing. NIS2: up to €10 million or 2% for essential entities, with management accountability in several member states. DSA: up to 6% of worldwide turnover, ordered by the Digital Services Coordinator.

Who enforces it

Data protection authorities, the CSIRT and competent authority under NIS2, and the Digital Services Coordinator of the member state where the representative is established.

Where the boundary lies

These are three separate appointments with three separate legal bases, and a single provider can hold all three but must be designated for each. The most common gap is a company that appointed an Article 27 representative years ago and assumes it covers the DSA and NIS2, which it does not.

Questions we are asked

We are only a processor — do we need our own representative?
Yes, if Article 3(2) applies to your own processing activities. Your customer's representative does not cover you.
Does ISO 27001 satisfy NIS2?
No. It is strong evidence toward the risk management measures but does not discharge the registration, reporting or governance duties.
EU representative · from €290 / year

Who signs for you
EU representative Europe Services, SE — Na Čečeličce 425/4, Smíchov, 150 00 Praha 5, Czech Republic
UK representative REP27 LTD — Unit 82a James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom

Talk to usCheck your category