← HomeREP27All categories

Smart locks, access control and alarms

Digital and connected products

In short
Article 4 economic operator for the device, plus an Article 27 GDPR representative for the app and cloud

Who has to appoint one

Manufacturers outside the Union placing connected locks, alarms and access control on the EU market. Access logs identify who entered and when, which is personal data, and video intercoms process images, so the data obligations are as substantial as the product ones.

Thresholds and exemptions

None. Both the product and the data obligations apply from the first unit sold to an EU user.

What must appear on the label

CE marking, manufacturer and EU representative details, model and serial number, radio parameters, battery markings, and from December 2027 the CRA support period and vulnerability contact point. The privacy notice must name the Article 27 representative.

Marketplace fields

Marketplaces require the EU responsible person and, since August 2025, evidence that the cybersecurity requirements are met. Locks with weak default credentials or unencrypted Bluetooth pairing have been publicly broken and delisted.

Documentation you must hold

EU declaration of conformity, technical file, radio and safety test reports, EN 18031 cybersecurity documentation, and from 2026 the CRA vulnerability handling process and SBOM. On the data side, the Article 30 record, the Article 27 designation, retention rules for access logs and video, and the transfer mechanism.

Standards and testing

Radio and EMC testing, EN 18031 for the cybersecurity requirements, mechanical security testing under EN 1303 or EN 12209 for the lock itself, and battery testing. Penetration testing is the practical evidence for the security requirements.

Language requirements

Instructions and warnings in the national language, and privacy information in the language of the users.

When it applies

Product documentation before placing on the market, cybersecurity requirements applicable since August 2025, CRA reporting from September 2026, and the GDPR representative before EU users' data is processed.

How long records are kept

Ten years for technical documentation or the support period if longer. Access logs and video only as long as necessary, with a defined retention period rather than an indefinite default.

What happens if you do not comply

Product withdrawal and marketplace removal, and separately data protection fines up to €20 million or 4%. A lock that fails open on firmware error, or a cloud breach exposing access logs, engages both regimes at once.

Who enforces it

Market surveillance authorities and radio regulators, CSIRTs for CRA reporting, and data protection authorities.

Where the boundary lies

Mechanical security ratings and cybersecurity are separate: a lock can hold a high mechanical grade and still be trivially bypassed over Bluetooth. Insurers increasingly ask for both, and the CRA will make the software side a legal requirement rather than a market expectation.

Questions we are asked

Are access logs personal data?
Yes. They record who entered and when, which identifies individuals, and retention must be limited and justified.
What happens if our cloud goes down?
Design for it: a lock that cannot be opened without the cloud raises safety questions, and authorities have criticised designs where the user loses access to their own home.
Art. 4 economic operator + EU representative · from €290 / year

Who signs for you
EU representative Europe Services, SE — Na Čečeličce 425/4, Smíchov, 150 00 Praha 5, Czech Republic
UK representative REP27 LTD — Unit 82a James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom

Talk to usCheck your category