Appoint us
Mobile application development team reviewing EU data protection obligations

REP27 · Software · App developers

Article 3(2) · mobile apps · App Store and Google Play

EU representative for app developers.

Publishing an app that people in the Union can install is the fastest way for a small company to fall under Article 3(2) without noticing. It is rarely the app's features that do it: it is the analytics SDK, the crash reporter and the ad network that came with the template. The store forms you filled in are not a designation, and passing DSA trader verification satisfies a different law entirely. This page separates the three.

iOSAndroidAnalytics SDKAd networksCrash reportingPush segmentation

See the plans   Ask a question

What triggers Article 3(2) in a mobile app

Developers usually assume the trigger is selling something to European users. In practice it is the identifiers travelling out of the app, and those arrive with dependencies rather than decisions.

Which app behaviours count as monitoring under Article 3(2) GDPR and which do not
Which app behaviours count as monitoring under Article 3(2) GDPR and which do not
If your app ships an advertising identifier to a network, the question of whether you meant to monitor anyone is not the one that gets asked.

Three different forms, three different laws

This is where most of the confusion lives. Filling in the store forms creates a strong feeling of compliance and satisfies none of Article 27.

Store trader details, data safety forms and the Article 27 designation compared
Store trader details, data safety forms and the Article 27 designation compared
FormComes fromSatisfies Article 27?
App Store trader contact detailsDigital Services ActNo
Google Play verified developer addressStore policy and the DSANo
Data safety / privacy nutrition labelsStore policyNo
Privacy notice naming the representativeArticle 13(1)(a) GDPRYes, with a signed designation behind it

What a designated app developer actually holds

A signed designation

A mandate accepted by Europe Services, SE in Prague, dated and countersigned, which is the document a supervisory authority asks for.

The privacy notice paragraph

The exact Article 13(1)(a) wording naming the representative, ready to paste into the notice linked from both store listings.

A request desk in eight languages

A German user writing in German gets an answer in German. Most solo developers cannot offer that, and it is a common source of complaints.

Article 30 records

The record of processing activities held by the representative and available to authorities, which almost no first-time app publisher has prepared.

Getting it in place before the store asks

  1. Inventory your SDKs

    List every dependency that sends anything off-device. Analytics, ads, crash reporting, push, attribution. This is your processing map and it takes an afternoon.

  2. Designate in writing

    One form, signed within 24 hours, valid for data subjects in all 27 Member States.

  3. Publish the representative

    Update the privacy notice linked from the App Store and Google Play listings, and the copy inside the app if you ship one.

  4. Point the store forms at it

    Keep trader details, data safety answers and the privacy notice consistent. Divergence between them is what triggers review.

The SDK inventory, done properly once

This is the only part of the exercise that takes real work, and it pays for itself because the same list feeds the store data safety form, the privacy notice and the Article 30 records.

DependencyWhat it sendsWhere it has to appear
AnalyticsDevice or user identifier, events, session lengthPrivacy notice, data safety form, records
Crash reportingDevice identifier, stack traces, sometimes logsPrivacy notice, records
AdvertisingAdvertising identifier, in-app behaviourPrivacy notice, data safety form, consent flow
AttributionInstall source, device fingerprintPrivacy notice, records
PushPush token, segmentation attributesPrivacy notice, records
Support chatMessages, email address, device dataPrivacy notice, records, processor list
Anything in the right-hand column that is missing from your published notice is a discrepancy a reviewer can see without contacting you.

Small studios, and the two questions that actually decide it

Most developers who write to us are one to five people, and they are looking for a reason not to do this. There are two honest ways out and neither is size.

Is the app genuinely offline?

No accounts, no analytics, no ads, no crash reporting, nothing leaving the device. Then Article 3(2) is not engaged and no designation is needed.

Are the statistics truly anonymous?

Irreversibly aggregated counts with no per-device identifier are not personal data. Almost no standard SDK works that way out of the box.

Is a publisher acting as controller?

If you develop under a publisher who determines purposes and means, the obligation may sit with them. Check the contract rather than assume it.

Everything else

Designate. It costs less than a week of ad spend and removes a category of problem entirely.

Consent, and where the store rules end

The stores enforce their own policies about tracking permission. The Union enforces a different set of rules about consent, and passing the first has never satisfied the second.

LayerWho imposes itWhat it governs
App tracking permission promptPlatform policyAccess to the device advertising identifier
Consent for storing and reading on the deviceePrivacy rules, national lawSDKs writing identifiers, before any data leaves
Lawful basis for the processingGDPR Article 6What you then do with the data
Identity of the representativeGDPR Article 13(1)(a)Who a user in the Union can address
A store prompt is not consent under Union law, and a consent banner is not a designation. Four layers, four separate pieces of work, and only the last one is a single form.

What changes when your app takes payments

Both limbs of Article 3(2)

You are offering services and, through the SDKs, monitoring behaviour. There is no argument left about whether the regulation reaches you.

Longer retention

Transaction records live for years for accounting reasons, which turns a light processing profile into a substantial one.

More processors

Payment providers, fraud scoring, receipts, support tools. Each belongs in the record of processing activities the representative holds.

Consumer law arrives too

Trader identification, withdrawal rights and dispute channels are separate obligations, and the store trader fields exist because of them.

None of that changes the designation itself: it is the same form, the same 24 hours and the same certificate. It changes how much the designation is worth to you when someone finally writes in.

Request desk handling a data subject request arriving from an app user in the Union
Request desk handling a data subject request arriving from an app user in the Union
Request desk answering an app user writing from the Union in their own language

Questions we are actually asked

Do the store trader details count as a designation?

No. Those come from the Digital Services Act and identify you as a trader. Article 27 needs a written designation of a representative established in the Union, published in your privacy notice.

Does an analytics SDK count as monitoring?

When it assigns a per-user or per-device identifier and builds behaviour over time, yes. Aggregate, irreversible statistics normally do not.

The app is free. Does that change anything?

No. Offering services does not require payment, and monitoring is a separate trigger. Free apps monetised by ads are the clearest case of all.

I am one person. Is there a size exemption?

No. Article 27 has no employee or turnover threshold. The Article 27(2) exemption is for genuinely occasional processing, which an app with returning users does not meet.

Where does the representative go?

In the privacy notice reachable from the store listing and inside the app, under Article 13(1)(a), next to your own identity as controller.

Who answers user requests?

The representative is the contact point and logs and forwards everything to you. The substantive decision on each request stays with you as controller.

We are a games studio with in-app purchases. Anything different?

Only that you are also offering goods or services under Article 3(2), so both limbs apply rather than one. The designation is identical.

Do we need one if the app is only on TestFlight?

If people in the Union are installing it and identifiers are leaving their devices, the analysis is the same as for a public release. Being in beta is not an exemption.

Our app is a game with no accounts.

Check the SDKs before concluding anything. Ad mediation and attribution libraries in a free game are usually the strongest monitoring signal of all, accounts or not.

Does the representative appear in the App Store listing?

It appears in the privacy notice that the listing links to, which is what Article 13(1)(a) requires. The store's own trader fields stay as they are.

How long does it take?

One form, then a signed designation within 24 hours, with the privacy notice paragraph and a verifiable certificate issued together.

Do we need one representative per app?

No. The designation covers the controller, so every app you publish under the same legal entity is covered by one mandate.

What if we use a publisher?

Then the question is who decides the purposes of the processing. If the publisher decides, it is the controller and needs its own designation; if you decide, the obligation is yours regardless of whose name is on the listing.

Related: the same problem for SaaS · the exact privacy notice wording

Designated before your next release

One form, a signed designation within 24 hours, the privacy notice paragraph ready to paste, and a certificate with a verification code anyone can check.

See the plans