- Regulation (EU) 2017/745 — MDR
- Regulation (EU) 2017/746 — IVDR for measuring devices
- Regulation (EU) 2016/679 — GDPR, Articles 9 and 27
- Regulation (EU) 2024/2847 — CRA
- Directive 2014/53/EU
Who has to appoint one
Manufacturers outside the Union placing connected medical devices on the EU market. Three regimes overlap: device conformity, health data protection and, from 2027, cybersecurity for the connected element.
Thresholds and exemptions
None. These devices are Class IIb or III typically, requiring notified body involvement and clinical evidence.
What must appear on the label
CE marking with the notified body number, manufacturer and EC REP details, UDI and Basic UDI-DI, lot or serial number, and the instructions for use. The app and cloud carry the Article 27 representative in the privacy notice.
Marketplace fields
Reimbursement bodies require the device registration and clinical evidence, and hospital procurement adds security requirements that exceed the regulatory minimum.
Documentation you must hold
MDR or IVDR technical documentation, clinical or performance evaluation, risk management, post-market surveillance and PSUR, EUDAMED registration, the Article 11 mandate, and on the data side the Article 30 record, the Article 9 condition for health data, a data protection impact assessment and the transfer mechanism.
Standards and testing
IEC 60601 series for electrical medical equipment, IEC 62304 for software life cycle, IEC 62366 for usability, analytical and clinical performance for measuring devices, and cybersecurity testing under the device guidance and, from 2027, the CRA.
Language requirements
Instructions for use and app content in the language required by each member state, which for patient-facing devices is mandatory.
When it applies
Certification and registration before placing on the market. CRA vulnerability reporting from September 2026 applies to the connected elements not excluded by the sectoral carve-out.
How long records are kept
Ten years under the MDR, fifteen for implantables. Health data only as long as necessary, with the clinical retention justified separately.
What happens if you do not comply
Withdrawal, certificate suspension, and GDPR fines up to 4% for the health data. A vulnerability in a therapy device is a patient safety event as well as a security one.
Who enforces it
Medical device competent authorities, notified bodies, data protection authorities and CSIRTs.
Where the boundary lies
Devices already covered by MDR cybersecurity requirements are largely carved out of the CRA to avoid duplication, but the app and cloud around them may not be. Health data is special-category data even where the device is prescribed, and explicit consent is usually not the right basis in a clinical context.
Questions we are asked
- Do we need both an MDR representative and a GDPR one?
- For a connected device with a cloud service, effectively yes: they are different roles under different regulations with different liabilities.
- Is the app a medical device too?
- If it drives or influences treatment, yes, and it is assessed as part of the device or as a device in its own right.
Who signs for you
EU representative Europe Services, SE — Na Čečeličce 425/4, Smíchov, 150 00 Praha 5, Czech Republic
UK representative REP27 LTD — Unit 82a James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom