- Directive 2014/53/EU — Radio Equipment
- Delegated Regulation (EU) 2022/30 — cybersecurity
- Regulation (EU) 2016/679 — GDPR, Article 27 and Article 9
- Regulation (EU) 2017/745 — MDR where a medical purpose is claimed
- Regulation (EU) 2024/2847 — CRA
Who has to appoint one
Manufacturers outside the Union selling wearables to EU consumers. This category almost always triggers two separate appointments at once: one for the hardware placed on the market, and one for the personal data processed through the companion app, because health and biometric data of EU users is processed by the vendor's cloud.
Thresholds and exemptions
No threshold for either obligation. What changes the picture entirely is the claim: a step and sleep tracker is a consumer product, whereas a device claiming to detect atrial fibrillation, measure blood pressure or diagnose sleep apnoea is a medical device requiring a notified body.
What must appear on the label
CE marking, manufacturer and EU representative details, model and serial number, frequency bands and maximum transmitted power in the instructions, the WEEE symbol, and battery markings. In the app and privacy notice, the identity and contact details of the Article 27 representative.
Marketplace fields
Marketplaces require the EU responsible person and, for wireless devices, the declaration of conformity on challenge. App stores require a privacy contact and check health-claim language, and reject apps whose descriptions promise diagnosis without a device registration.
Documentation you must hold
For the hardware: EU declaration of conformity, technical file, radio and safety test reports, cybersecurity documentation under EN 18031, battery and WEEE registrations. For the data side: the Article 30 record of processing, the Article 27 designation, a lawful basis for processing health data under Article 9 — in practice explicit consent — a data protection impact assessment, and the transfer mechanism for data leaving the Union.
Standards and testing
EN 300 328 and the relevant radio standards, EN IEC 62368-1 for safety, EN 55032 and EN 55035 for EMC, IEC 62133 for the cell, skin sensitisation testing for materials in prolonged contact, and where a medical claim exists, clinical evaluation under the MDR.
Language requirements
Device instructions and safety information in the national language of each member state. The privacy notice and consent flows in the language of the user, since Article 12 GDPR requires intelligible information.
When it applies
Hardware documentation before placing on the market; the GDPR representative before processing of EU users' data begins, which in practice means before the app is downloadable in the Union. CRA vulnerability reporting applies from 11 September 2026.
How long records are kept
Technical documentation ten years. Processing records for the life of the processing plus evidence of the period. Health data must not be kept longer than necessary, and an indefinite retention default is itself an infringement.
What happens if you do not comply
Two parallel exposures. On the product side: withdrawal, customs refusal, marketplace removal and national fines. On the data side: up to €20 million or 4% of turnover for unlawful processing of health data, and up to €10 million or 2% for failing to designate a representative. Wearables have attracted authority attention precisely because health data is special-category data processed at scale.
Who enforces it
Market surveillance authorities and radio regulators for the device, data protection authorities for the processing, and medical device competent authorities where a medical claim is made.
Where the boundary lies
The claim decides which regime applies to the same hardware. 'Tracks your activity' is a consumer product. 'Detects irregular heart rhythm' is a medical device, usually Class IIa, requiring a notified body and clinical evidence. Sellers frequently write medical claims in marketing while declaring a consumer product in the technical file, and that inconsistency is exactly what an authority looks for.
Questions we are asked
- Do we need both a GPSR responsible person and a GDPR representative?
- For a connected wearable, effectively yes: one for the device placed on the market and one for the personal data processed through the app. They are different legal roles under different regulations.
- Is heart rate data health data under the GDPR?
- Data revealing information about health status is special-category data under Article 9. Continuous heart rate, sleep and stress metrics are routinely treated that way by authorities, which means explicit consent and a higher standard throughout.
- Can we rely on legitimate interests for the analytics?
- For special-category data, no. Article 9 requires a separate condition, and for a consumer wearable that is explicit consent, freely given and separable from the purchase.
Who signs for you
EU representative Europe Services, SE — Na Čečeličce 425/4, Smíchov, 150 00 Praha 5, Czech Republic
UK representative REP27 LTD — Unit 82a James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom