Companies outside the EU that make connected products available or offer services in the Union, and that fall within the scope of the Data Act, need a legal representative in a Member State under Article 37(11). Engage Compliance provides it directly from our EU establishment.

The short answer: if you are within the scope of Regulation (EU) 2023/2854, you make connected products available or offer services in the Union, and you are not established in the Union, Article 37(11) requires you to designate a legal representative in one of the Member States. That representative is mandated to be addressed by competent authorities on all matters related to you, and your company is then treated as falling under the competence of the Member State where the representative is located.

Engage Compliance holds this appointment for you directly. We are established in the EU, so we do not need a separate local entity in each country you sell into, and Article 37(11) does not require the representative to sit in a Member State where you offer services.

Key takeaways

  • The obligation is Article 37(11) of the EU Data Act, Regulation (EU) 2023/2854, inside Chapter IX on competent authorities.
  • Engage Compliance provides the Data Act legal representative directly from our EU establishment, with the mandate to be addressed by competent authorities on your behalf.
  • It catches any in-scope entity that makes connected products available or offers services in the Union and has no EU establishment.
  • The placement rule is the most permissive of any EU representative regime: the representative can be in any Member State, not only one where you offer services.
  • Appointing the representative fixes your regulator, because you are treated as falling under the competence of the Member State where the representative sits.
  • The Data Act has applied since 12 September 2025, so this is a live obligation, not a future deadline.

Who needs one

Article 37(11) applies to any entity within the scope of the Data Act that makes connected products available or offers services in the Union and is not established in the Union. If you are in scope and you have no EU establishment, you have to designate a legal representative in one of the Member States.

The part that catches vendors off their own expectations is the reach of “in scope”. The Data Act defines a data processing service in Article 2(8) as, in short, a digital service giving on-demand access to a shared pool of configurable computing resources. That wording covers infrastructure, platform, and software delivered as a service, so IaaS, PaaS, and ordinary SaaS all sit inside the definition. Through the Chapter VI obligations on switching between cloud services, a non-EU SaaS vendor offering services in the Union can be within scope of the Regulation. So this is not only a rule for makers of connected hardware. A software company with no factory and no device can be squarely inside it.

Who is exempt

The Data Act does carry a small-enterprise exemption, and it does not reach this duty. Article 7(1) exempts microenterprises and small enterprises, but it opens with “the obligations of this Chapter”, and Article 7 sits in Chapter II on business-to-consumer and business-to-business data sharing. The representative duty is Article 37(11), in Chapter IX on implementation and enforcement, so the Article 7(1) exemption does not touch it.

Article 37(11) itself carries no size carve-out. It reads on “any entity falling within the scope of this Regulation that makes connected products available or offers services in the Union, and which is not established in the Union”. If you are in scope and have no EU establishment, the duty applies whatever your headcount or turnover.

When it applies from

The Data Act has applied since 12 September 2025. The representative obligation is live now, not a date you are working toward. If you are in scope with no EU establishment, the appointment is already due, and many in-scope vendors have not made it yet.

Where the representative must be established

Article 37(11) requires the representative to be “in one of the Member States”. This is the most permissive placement rule of any of the EU representative regimes. There is no requirement that the representative sit in a Member State where you actually make products available or offer services, unlike several of the other mandates, which tie the representative to a country where you operate.

That matters in practice. Because Engage Compliance is established in the EU, we can hold the appointment directly, with no need to spin up a local entity per country. And Article 37(13) provides that you are treated as falling under the competence of the Member State in which your legal representative is located. So choosing where the representative sits is, in effect, choosing which national authority has competence over you for the Data Act. That is a decision worth making on purpose rather than by default, and we walk through it with you before the appointment.

What the penalty is

Penalties for the Data Act are left to the Member States under Article 40, which requires them to be effective, proportionate, and dissuasive. There is no harmonized EU ceiling for the representative duty. The GDPR-level fines that Article 40(4) allows a supervisory authority to impose reach only infringements of Chapters II, III, and V of the Regulation, and the representative obligation sits in Chapter IX. So for this duty it is national penalties only, with no EU-level cap, and in some Member States the specific penalty rules are still being settled.

We do not lead with the fine, because it is a weaker reason to act than the rest. The appointment is a legal obligation that is already in force, competent authorities can be pointed at you only through the representative, and the appointment is what fixes your regulator under Article 37(13). Those are the reasons that hold up.

What Engage delivers

  • The appointment itself, with a mandate to be addressed by competent authorities on all issues related to your company, as Article 37(12) requires.
  • A named contact point in the EU, so an authority reaching for you has a real address to use.
  • Handling of authority correspondence, with the substance passed to your named internal owner within one business day.
  • A view on which Member State to place the appointment in, since that choice sets the competent authority for you under Article 37(13).
  • A scope review, so we confirm you are actually in scope and have no EU establishment before you pay for something you may not need.

A written mandate is not expressly required by the text of Article 37. In practice a contract is still how the appointment is evidenced, so we put it in writing regardless, and it is the document that proves the representative is in place. The Data Act does not put any record-keeping duty on the representative, so this is a contact-point and coordination role rather than a document-custody one.

What it costs

The appointment is €550 a year at the smallest band, for a company with 1 to 10 people, under €2m revenue, and under 5,000 people in the EU and UK whose data you hold, charged once, up front, with no setup fee. Whichever of headcount, revenue or the number of people whose data you hold puts you highest sets the band.

Company sizeData Act Legal Representative
1 to 10 people, under €2m revenue, and under 5,000 people in the EU and UK whose data you hold€550
11 to 50 people, or €2m to €10m revenue, or 5,000 or more people in the EU and UK whose data you hold€790
51 to 250 people, or €10m to €50m revenue€1,830
251 or more people, or over €50m revenueFrom €3,590

The smallest band is for very small organizations only: 1 to 10 people, under €2m in global annual revenue, and under 5,000 people in the EU and UK whose personal data you hold. All three must be true. If any one of them is not, the next band up applies.

Commercial pricing bands based on familiar market-size and market-pricing thresholds. They are not a statutory size test.

Every appointment you hold is a separate mandate, and only the highest-priced one in the basket is charged in full. Every other appointment is charged at a share of its own price, and for this one that share is half its own price. So adding this to an appointment you already hold costs €275 at band 0, €395 at band 1, €915 at band 2, €1,795 at band 3, rather than a second full price.

Two extras are optional, and each is charged once per order rather than once per appointment. Higher-risk processing, which covers special category data and criminal offense data, is €250 at band 0, €500 at band 1, €750 at band 2, €1,000 at band 3. Same-business-day response is a service level on authority and data subject correspondence rather than substantive advice, and is €1,200 a year.

Every band is published and buyable, so you can see your price and appoint online without talking to anyone first. The full table for every mandate is on representative services.

The appointment issues in seconds. After payment you answer a short form about your company and who we should send correspondence to, about three minutes of typing, and the appointment document, the certificate, the public verification link and the wording you need all issue automatically at that moment. Nobody at Engage has to approve anything.

Sources and references

Representative mandates

These mandates stack rather than replace each other. One company selling into Europe can be caught by several at once, each is a separate appointment with its own published contact point, and an EU representative does not cover the UK. Engage Compliance holds them together so you have one point of contact across the set.

  • Same-business-day response
  • Professional indemnity and cyber insurance
  • Named DPO notified to the supervisory authority

FAQ

Frequently asked questions

Who needs an EU Data Act representative?

Any entity within the scope of the Data Act that makes connected products available or offers services in the Union, and that is not established in the Union, has to designate a legal representative in one of the Member States. That comes from Article 37(11) of Regulation (EU) 2023/2854. The representative is mandated to be addressed by competent authorities on all issues related to the entity, and the entity is then treated as falling under the competence of the Member State where the representative sits.

Does a non-EU SaaS company need a Data Act representative?

Often yes, and this surprises people. The Data Act defines a data processing service in Article 2(8) in terms broad enough to cover infrastructure, platform, and software as a service, so IaaS, PaaS, and SaaS are all inside the definition. Through the Chapter VI cloud switching obligations, an ordinary non-EU SaaS vendor offering services in the Union can be within scope of the Regulation, and once inside scope with no EU establishment the Article 37(11) representative duty applies.

When did the EU Data Act representative obligation start?

The Data Act has applied since 12 September 2025, so the representative obligation is live now. It is not a future deadline you are preparing for. If you are in scope and have no EU establishment, the appointment is already due.

Where must a Data Act legal representative be established?

In one of the Member States. Article 37(11) is the most permissive placement rule of any of the EU representative regimes: there is no requirement that it be a Member State where you actually offer services. Because Engage Compliance is established in the EU, we can hold this appointment directly, without needing a local entity in each country you sell into.

What is the penalty for not appointing a Data Act representative?

Penalties for the Data Act are set by each Member State under Article 40 and have to be effective, proportionate, and dissuasive, but there is no harmonized EU ceiling for this obligation. The GDPR-style fines in Article 40(4) reach only infringements of Chapters II, III, and V, and the representative duty sits in Chapter IX, so it is national penalties only, with no EU-level cap. The stronger reasons to appoint are that it is a legal obligation, that authorities can address you only through the representative, and that the appointment fixes which regulator has competence over you.

Can Engage Compliance act as our Data Act representative and our DPO?

Where you need both the Data Act representative and a DPO, we offer both as separate products and scope them together. Where you only need the Data Act representative, we provide it directly from our EU establishment.