
REP27 · Software · App developers
Article 3(2) · mobile apps · App Store and Google Play
Publishing an app that people in the Union can install is the fastest way for a small company to fall under Article 3(2) without noticing. It is rarely the app's features that do it: it is the analytics SDK, the crash reporter and the ad network that came with the template. The store forms you filled in are not a designation, and passing DSA trader verification satisfies a different law entirely. This page separates the three.
iOSAndroidAnalytics SDKAd networksCrash reportingPush segmentation
Developers usually assume the trigger is selling something to European users. In practice it is the identifiers travelling out of the app, and those arrive with dependencies rather than decisions.

This is where most of the confusion lives. Filling in the store forms creates a strong feeling of compliance and satisfies none of Article 27.

| Form | Comes from | Satisfies Article 27? |
|---|---|---|
| App Store trader contact details | Digital Services Act | No |
| Google Play verified developer address | Store policy and the DSA | No |
| Data safety / privacy nutrition labels | Store policy | No |
| Privacy notice naming the representative | Article 13(1)(a) GDPR | Yes, with a signed designation behind it |
A mandate accepted by Europe Services, SE in Prague, dated and countersigned, which is the document a supervisory authority asks for.
The exact Article 13(1)(a) wording naming the representative, ready to paste into the notice linked from both store listings.
A German user writing in German gets an answer in German. Most solo developers cannot offer that, and it is a common source of complaints.
The record of processing activities held by the representative and available to authorities, which almost no first-time app publisher has prepared.
List every dependency that sends anything off-device. Analytics, ads, crash reporting, push, attribution. This is your processing map and it takes an afternoon.
One form, signed within 24 hours, valid for data subjects in all 27 Member States.
Update the privacy notice linked from the App Store and Google Play listings, and the copy inside the app if you ship one.
Keep trader details, data safety answers and the privacy notice consistent. Divergence between them is what triggers review.
This is the only part of the exercise that takes real work, and it pays for itself because the same list feeds the store data safety form, the privacy notice and the Article 30 records.
| Dependency | What it sends | Where it has to appear |
|---|---|---|
| Analytics | Device or user identifier, events, session length | Privacy notice, data safety form, records |
| Crash reporting | Device identifier, stack traces, sometimes logs | Privacy notice, records |
| Advertising | Advertising identifier, in-app behaviour | Privacy notice, data safety form, consent flow |
| Attribution | Install source, device fingerprint | Privacy notice, records |
| Push | Push token, segmentation attributes | Privacy notice, records |
| Support chat | Messages, email address, device data | Privacy notice, records, processor list |
Most developers who write to us are one to five people, and they are looking for a reason not to do this. There are two honest ways out and neither is size.
No accounts, no analytics, no ads, no crash reporting, nothing leaving the device. Then Article 3(2) is not engaged and no designation is needed.
Irreversibly aggregated counts with no per-device identifier are not personal data. Almost no standard SDK works that way out of the box.
If you develop under a publisher who determines purposes and means, the obligation may sit with them. Check the contract rather than assume it.
Designate. It costs less than a week of ad spend and removes a category of problem entirely.
The stores enforce their own policies about tracking permission. The Union enforces a different set of rules about consent, and passing the first has never satisfied the second.
| Layer | Who imposes it | What it governs |
|---|---|---|
| App tracking permission prompt | Platform policy | Access to the device advertising identifier |
| Consent for storing and reading on the device | ePrivacy rules, national law | SDKs writing identifiers, before any data leaves |
| Lawful basis for the processing | GDPR Article 6 | What you then do with the data |
| Identity of the representative | GDPR Article 13(1)(a) | Who a user in the Union can address |
You are offering services and, through the SDKs, monitoring behaviour. There is no argument left about whether the regulation reaches you.
Transaction records live for years for accounting reasons, which turns a light processing profile into a substantial one.
Payment providers, fraud scoring, receipts, support tools. Each belongs in the record of processing activities the representative holds.
Trader identification, withdrawal rights and dispute channels are separate obligations, and the store trader fields exist because of them.
None of that changes the designation itself: it is the same form, the same 24 hours and the same certificate. It changes how much the designation is worth to you when someone finally writes in.


No. Those come from the Digital Services Act and identify you as a trader. Article 27 needs a written designation of a representative established in the Union, published in your privacy notice.
When it assigns a per-user or per-device identifier and builds behaviour over time, yes. Aggregate, irreversible statistics normally do not.
No. Offering services does not require payment, and monitoring is a separate trigger. Free apps monetised by ads are the clearest case of all.
No. Article 27 has no employee or turnover threshold. The Article 27(2) exemption is for genuinely occasional processing, which an app with returning users does not meet.
In the privacy notice reachable from the store listing and inside the app, under Article 13(1)(a), next to your own identity as controller.
The representative is the contact point and logs and forwards everything to you. The substantive decision on each request stays with you as controller.
Only that you are also offering goods or services under Article 3(2), so both limbs apply rather than one. The designation is identical.
If people in the Union are installing it and identifiers are leaving their devices, the analysis is the same as for a public release. Being in beta is not an exemption.
Check the SDKs before concluding anything. Ad mediation and attribution libraries in a free game are usually the strongest monitoring signal of all, accounts or not.
It appears in the privacy notice that the listing links to, which is what Article 13(1)(a) requires. The store's own trader fields stay as they are.
One form, then a signed designation within 24 hours, with the privacy notice paragraph and a verifiable certificate issued together.
No. The designation covers the controller, so every app you publish under the same legal entity is covered by one mandate.
Then the question is who decides the purposes of the processing. If the publisher decides, it is the controller and needs its own designation; if you decide, the obligation is yours regardless of whose name is on the listing.
Related: the same problem for SaaS · the exact privacy notice wording
One form, a signed designation within 24 hours, the privacy notice paragraph ready to paste, and a certificate with a verification code anyone can check.
See the plans