← HomeREP27All categories

Mobile apps and games on the EU stores

Data protection

In short
Representative in the Union under Article 27 GDPR

Who has to appoint one

Any developer or publisher established outside the Union whose app is available to users in the EU and that processes their personal data. Offering the app in EU storefronts, pricing in euros, localising it or serving ads to EU users all point to targeting. An SDK provider that determines its own purposes — an ad network, an analytics vendor — is a controller in its own right and needs its own representative.

Thresholds and exemptions

No revenue or download threshold. The narrow Article 27(2) exemption for occasional processing does not fit an app with an install base, persistent identifiers and analytics. Free apps are fully in scope: monetisation through advertising is processing, not an exemption.

What must appear on the label

Not physical. The identity and contact details of the EU representative must appear in the privacy policy linked from the store listing and inside the app, in a place a user can actually find. Apple and Google both require a working privacy policy URL and accurate data-safety disclosures, and inconsistencies between the declared data collection and the SDKs actually present are checked.

Marketplace fields

App Store and Google Play require privacy labels or data-safety declarations that match reality. Google Play additionally requires developers outside the EU to publish trader information for consumer-facing apps in the EU under the DSA-adjacent transparency rules, and removes apps whose declarations are incomplete. Ad SDKs that transmit identifiers without consent are the most common reason an app fails a store privacy review.

Documentation you must hold

The written Article 27 designation. The Article 30 records of processing, listing every SDK, its purpose and its transfers. A consent management flow for non-essential storage and tracking, with proof of consent per user. Data protection impact assessment where profiling, children's data or large-scale tracking is involved. Standard contractual clauses and a transfer impact assessment for data going to the United States or elsewhere. Data processing agreements with each SDK vendor that is a processor.

Standards and testing

Not applicable in the testing sense. What is examined is the consent flow: whether identifiers are read or written before consent, whether refusing is as easy as accepting, and whether the store declarations match the network traffic. Regulators and NGOs both run traffic analyses, and that is how most enforcement in this category starts.

Language requirements

Privacy information in the language of the users targeted. An app localised into German or French with an English-only consent flow is a transparency failure under Article 12.

When it applies

The designation must exist before the app is made available in EU storefronts. Consent must be obtained before any non-essential SDK reads or writes to the device, which means at first launch and before the analytics call, not after.

How long records are kept

Processing records for the life of the app plus evidence of past periods. Consent records for as long as the processing continues, since the burden of proving consent lies with the controller.

What happens if you do not comply

Up to €10 million or 2% of turnover for failing to designate a representative, and up to €20 million or 4% for unlawful processing. National ePrivacy fines are separate and are imposed by some authorities without needing to prove GDPR harm. Store removal is the faster commercial risk: Apple and Google act on privacy declaration mismatches within days.

Who enforces it

Any EU supervisory authority where users are located, since there is no one-stop-shop for controllers outside the Union. National ePrivacy enforcement sits with the data protection authority in most member states and with the telecoms regulator in a few.

Where the boundary lies

Apps for children bring stricter rules: profiling for advertising is effectively prohibited under the DSA for minors on platforms, and consent from a child under the national age of digital consent — between 13 and 16 depending on the member state — requires parental authorisation. Apps hosting user-generated content also fall under the DSA and need an Article 13 legal representative, which is a separate appointment from Article 27.

Questions we are asked

We only use Firebase and AdMob — do we still need a representative?
Yes. Those SDKs process personal data of EU users on your behalf and for their own purposes, and you are targeting the EU by publishing in EU storefronts.
Is the App Store our data controller?
No. The store is a distribution channel and a controller for its own processing. You remain the controller for what your app collects.
Does an EU-based publisher solve it?
If a company established in the Union is the actual controller for the processing, Article 27 does not apply to it. A nominal publisher that does not determine purposes and means will not survive scrutiny.
EU representative · from €290 / year

Who signs for you
EU representative Europe Services, SE — Na Čečeličce 425/4, Smíchov, 150 00 Praha 5, Czech Republic
UK representative REP27 LTD — Unit 82a James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom

Talk to usCheck your category