- Regulation (EU) 2016/679 — GDPR, Articles 27 and 22
- Directive (EU) 2016/97 — insurance distribution
- Regulation (EU) 2024/1689 — AI Act, Annex III for life and health risk pricing
- Regulation (EU) 2022/2554 — DORA for financial entities
Who has to appoint one
Providers outside the Union offering insurance technology, claims handling or distribution services to EU customers. The data obligations attach to any processing of EU policyholders' data. The insurance activity itself requires authorisation or registration in a member state, which no representative provides.
Thresholds and exemptions
No GDPR threshold. Under the AI Act, systems used for risk assessment and pricing in life and health insurance are high-risk under Annex III, with obligations from August 2026.
What must appear on the label
Not physical. The representative in the privacy notice, the pre-contractual information required by the distribution Directive, and where automated decisions are made, information about the logic involved under Article 22 GDPR.
Marketplace fields
Insurers procuring technology require DORA-ready contractual terms including exit plans and audit rights, since financial entities must manage third-party ICT risk. This has become the gating factor for vendors selling into the sector.
Documentation you must hold
Article 30 records, Article 28 terms, the Article 27 designation, a data protection impact assessment covering profiling and any special-category data such as health, retention schedules aligned to claim limitation periods, the transfer mechanism, and for high-risk AI the technical documentation and conformity assessment.
Standards and testing
Bias and accuracy evaluation for pricing and claims models, and for DORA-relevant vendors, participation in the financial entity's resilience testing.
Language requirements
Policyholder-facing information in the language of the member state where the risk is situated.
When it applies
The representative before processing begins. DORA has applied since 17 January 2025. AI Act high-risk obligations from 2 August 2026.
How long records are kept
Claims data for the limitation period applicable to the claim, which is long, but health data within it must be minimised and access-controlled rather than kept openly.
What happens if you do not comply
GDPR fines up to 4% of turnover, supervisory action from insurance regulators including prohibition of distribution, and AI Act penalties up to €15 million or 3%.
Who enforces it
Data protection authorities, national insurance supervisors and EIOPA, and AI Act market surveillance authorities.
Where the boundary lies
Automated claim refusal without human involvement engages Article 22 GDPR, and pricing life or health cover using an AI system is high-risk under Annex III. Health data in claims is special-category data requiring an Article 9 condition, which for insurance is usually explicit consent or a national derogation.
Questions we are asked
- Does an EU representative let us sell insurance in the EU?
- No. Distribution requires registration or authorisation of an entity in a member state. The representative satisfies data protection only.
- Is claims triage high-risk under the AI Act?
- Risk assessment and pricing for life and health insurance is listed in Annex III. Other claims automation may not be, but Article 22 GDPR still applies to decisions without human involvement.
Who signs for you
EU representative Europe Services, SE — Na Čečeličce 425/4, Smíchov, 150 00 Praha 5, Czech Republic
UK representative REP27 LTD — Unit 82a James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom