- Regulation (EU) No 910/2014 — eIDAS as amended by Regulation (EU) 2024/1183
- Regulation (EU) 2016/679 — GDPR, Article 27
- Regulation (EU) 2024/1689 — AI Act for biometric verification
Who has to appoint one
Providers established outside the Union offering signature, seal, timestamp or identity verification services to users in the EU. The data side needs a representative. The trust service side is different: qualified status requires establishment in the Union and supervision by a national body, and cannot be obtained through a representative.
Thresholds and exemptions
Non-qualified trust services can be provided without prior authorisation but remain subject to the security and notification duties. Qualified status requires a conformity assessment and inclusion on a member state's trusted list.
What must appear on the label
Not physical. What must be published is the terms of service, the certification practice statement where certificates are issued, and the identity of the supervisory body. The GDPR representative goes in the privacy notice.
Marketplace fields
Enterprise buyers and public sector procurement in the Union require qualified status for many use cases, and the EU Digital Identity Wallet framework is expanding the situations where qualified electronic signatures are expected.
Documentation you must hold
Article 30 records covering identity documents, biometric templates and signature logs. The Article 27 designation. Data protection impact assessment, since identity verification processes special-category biometric data. Retention schedule balancing evidentiary value against minimisation. For trust services, the conformity assessment report, the security policy and the incident notification procedures.
Standards and testing
Conformity assessment by an accredited body for qualified services. For biometric verification, accuracy and bias testing, since the AI Act treats remote biometric identification as high-risk and requires declared performance levels.
Language requirements
Terms, certificate policies and user information in the languages of the markets served.
When it applies
The representative before processing begins. Trust service obligations from the moment services are offered. The amended eIDAS framework phases in the European Digital Identity Wallet through 2026 and 2027.
How long records are kept
Signature and certificate evidence must be retained long enough to support verification years later, which is a legal obligation that overrides simple minimisation, and must be documented as such. Biometric templates should be deleted once verification is complete unless a specific basis justifies retention.
What happens if you do not comply
GDPR fines up to €20 million or 4%, and supervisory action under eIDAS including removal from the trusted list, which ends the commercial proposition immediately.
Who enforces it
Data protection authorities, national supervisory bodies for trust services, and AI Act market surveillance authorities for biometric systems.
Where the boundary lies
Providing a signature service is not the same as providing a qualified one, and only the latter carries the legal presumption of equivalence to a handwritten signature. Selling a non-qualified service into a market that legally requires a qualified signature is the most common commercial failure in this sector.
Questions we are asked
- Can a non-EU provider offer qualified signatures?
- Not directly. Qualified status requires establishment in the Union and supervision by a member state body, or recognition through an international agreement.
- Is biometric identity verification high-risk under the AI Act?
- Remote biometric identification systems are listed in Annex III, so yes, with obligations applying from August 2026 including an authorised representative for non-EU providers.
Who signs for you
EU representative Europe Services, SE — Na Čečeličce 425/4, Smíchov, 150 00 Praha 5, Czech Republic
UK representative REP27 LTD — Unit 82a James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom