- Directive (EU) 2018/1972 — European Electronic Communications Code
- Regulation (EU) 2016/679 — GDPR, Article 27
- Directive 2002/58/EC — ePrivacy for traffic and location data
- Directive (EU) 2022/2555 — NIS2
- Regulation (EU) 2024/2847 — CRA for modules
Who has to appoint one
Providers outside the Union supplying connectivity to devices in the EU. Providing an electronic communications service requires notification to the national regulatory authority of each member state where the service is offered, which is a separate obligation from data protection and cannot be met by a representative.
Thresholds and exemptions
NIS2 catches providers of public electronic communications networks or services regardless of size in several member states. Notification duties depend on the national implementation.
What must appear on the label
Not physical. What must be published is the provider identity, the contract terms required by the Communications Code including the contract summary, and the representative's identity in the privacy notice.
Marketplace fields
Enterprise IoT buyers require evidence of notification in the target countries, the data protection documentation and, increasingly, NIS2 registration. Device makers rely on the connectivity provider's compliance for their own product claims.
Documentation you must hold
Article 30 records covering subscriber, traffic and location data, the Article 27 designation, transfer documentation, notification confirmations from each national regulator, lawful interception readiness where required nationally, and NIS2 risk management and incident procedures.
Standards and testing
Not applicable, but permanent roaming arrangements are scrutinised by regulators in several member states and can be restricted, which is a commercial risk for IoT deployments.
Language requirements
Contract summaries and terms in the language of the member states served, as required by the Communications Code.
When it applies
Notification before offering the service. The GDPR representative before processing begins. NIS2 reporting deadlines of 24 hours, 72 hours and one month apply once in scope.
How long records are kept
Traffic and location data only for the periods permitted, which are set nationally and are contested since the data retention case law. Indefinite retention is not available.
What happens if you do not comply
Sanctions from national regulators including prohibition of the service, GDPR fines up to 4% of turnover, and NIS2 penalties up to €10 million or 2% for essential entities.
Who enforces it
National regulatory authorities for electronic communications, data protection authorities, and NIS2 competent authorities and CSIRTs.
Where the boundary lies
Permanent roaming is the practical trap: SIMs from one country permanently attached to networks in another are restricted or prohibited in several member states, and deployments are disconnected without warning. This is a licensing and contractual matter that no data appointment addresses.
Questions we are asked
- Do we need to notify in every country?
- Where you provide an electronic communications service, notification is generally required in each member state where it is offered, under that state's implementation of the Code.
- Is permanent roaming allowed?
- It is restricted in several member states and depends on the host operator's agreements. Deployments have been terminated with little notice, so it must be checked per country.
Who signs for you
EU representative Europe Services, SE — Na Čečeličce 425/4, Smíchov, 150 00 Praha 5, Czech Republic
UK representative REP27 LTD — Unit 82a James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom