← HomeREP27All categories

Continuous glucose monitors and connected therapy devices

Health products

In short
Authorised representative under Article 11 MDR or IVDR, plus an Article 27 GDPR representative

Who has to appoint one

Manufacturers outside the Union placing connected medical devices on the EU market. Three regimes overlap: device conformity, health data protection and, from 2027, cybersecurity for the connected element.

Thresholds and exemptions

None. These devices are Class IIb or III typically, requiring notified body involvement and clinical evidence.

What must appear on the label

CE marking with the notified body number, manufacturer and EC REP details, UDI and Basic UDI-DI, lot or serial number, and the instructions for use. The app and cloud carry the Article 27 representative in the privacy notice.

Marketplace fields

Reimbursement bodies require the device registration and clinical evidence, and hospital procurement adds security requirements that exceed the regulatory minimum.

Documentation you must hold

MDR or IVDR technical documentation, clinical or performance evaluation, risk management, post-market surveillance and PSUR, EUDAMED registration, the Article 11 mandate, and on the data side the Article 30 record, the Article 9 condition for health data, a data protection impact assessment and the transfer mechanism.

Standards and testing

IEC 60601 series for electrical medical equipment, IEC 62304 for software life cycle, IEC 62366 for usability, analytical and clinical performance for measuring devices, and cybersecurity testing under the device guidance and, from 2027, the CRA.

Language requirements

Instructions for use and app content in the language required by each member state, which for patient-facing devices is mandatory.

When it applies

Certification and registration before placing on the market. CRA vulnerability reporting from September 2026 applies to the connected elements not excluded by the sectoral carve-out.

How long records are kept

Ten years under the MDR, fifteen for implantables. Health data only as long as necessary, with the clinical retention justified separately.

What happens if you do not comply

Withdrawal, certificate suspension, and GDPR fines up to 4% for the health data. A vulnerability in a therapy device is a patient safety event as well as a security one.

Who enforces it

Medical device competent authorities, notified bodies, data protection authorities and CSIRTs.

Where the boundary lies

Devices already covered by MDR cybersecurity requirements are largely carved out of the CRA to avoid duplication, but the app and cloud around them may not be. Health data is special-category data even where the device is prescribed, and explicit consent is usually not the right basis in a clinical context.

Questions we are asked

Do we need both an MDR representative and a GDPR one?
For a connected device with a cloud service, effectively yes: they are different roles under different regulations with different liabilities.
Is the app a medical device too?
If it drives or influences treatment, yes, and it is assessed as part of the device or as a device in its own right.
Not offered for MDR — EU representative for the data side

Who signs for you
EU representative Europe Services, SE — Na Čečeličce 425/4, Smíchov, 150 00 Praha 5, Czech Republic
UK representative REP27 LTD — Unit 82a James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom

Talk to usCheck your category