---
title: "Data Act Representative | Article 37(11)"
url: "https://www.engagecompliance.co/data-act-representative"
type: "service"
date: "2026-08-27"
---

# EU Data Act legal representative under Article 37(11)

Companies outside the EU that make connected products available or offer services in the Union, and that fall within the scope of the Data Act, need a legal representative in a Member State under Article 37(11). Engage Compliance provides it directly from our EU establishment.

**The short answer: if you are within the scope of Regulation (EU) 2023/2854, you make connected products available or offer services in the Union, and you are not established in the Union, Article 37(11) requires you to designate a legal representative in one of the Member States.** That representative is mandated to be addressed by competent authorities on all matters related to you, and your company is then treated as falling under the competence of the Member State where the representative is located.

Engage Compliance holds this appointment for you directly. We are established in the EU, so we do not need a separate local entity in each country you sell into, and Article 37(11) does not require the representative to sit in a Member State where you offer services.

## Key takeaways

- The obligation is Article 37(11) of the EU Data Act, Regulation (EU) 2023/2854, inside Chapter IX on competent authorities.
- Engage Compliance provides the Data Act legal representative directly from our EU establishment, with the mandate to be addressed by competent authorities on your behalf.
- It catches any in-scope entity that makes connected products available or offers services in the Union and has no EU establishment.
- The placement rule is the most permissive of any EU representative regime: the representative can be in any Member State, not only one where you offer services.
- Appointing the representative fixes your regulator, because you are treated as falling under the competence of the Member State where the representative sits.
- The Data Act has applied since 12 September 2025, so this is a live obligation, not a future deadline.

## Who needs one

Article 37(11) applies to any entity within the scope of the Data Act that makes connected products available or offers services in the Union and is not established in the Union. If you are in scope and you have no EU establishment, you have to designate a legal representative in one of the Member States.

The part that catches vendors off their own expectations is the reach of "in scope". The Data Act defines a data processing service in Article 2(8) as, in short, a digital service giving on-demand access to a shared pool of configurable computing resources. That wording covers infrastructure, platform, and software delivered as a service, so IaaS, PaaS, and ordinary SaaS all sit inside the definition. Through the Chapter VI obligations on switching between cloud services, a non-EU SaaS vendor offering services in the Union can be within scope of the Regulation. So this is not only a rule for makers of connected hardware. A software company with no factory and no device can be squarely inside it.

## Who is exempt

Article 37 carries no exemption. There is no size, turnover, or headcount carve-out written into the representative duty itself. If you are within the scope of the Regulation and have no EU establishment, the duty applies.

## When it applies from

The Data Act has applied since 12 September 2025. The representative obligation is live now, not a date you are working toward. If you are in scope with no EU establishment, the appointment is already due, and the honest position is that many in-scope vendors have not made it yet.

## Where the representative must be established

Article 37(11) requires the representative to be "in one of the Member States". This is the most permissive placement rule of any of the EU representative regimes. There is no requirement that the representative sit in a Member State where you actually make products available or offer services, unlike several of the other mandates, which tie the representative to a country where you operate.

That matters in practice. Because Engage Compliance is established in the EU, we can hold the appointment directly, with no need to spin up a local entity per country. And Article 37(13) provides that you are treated as falling under the competence of the Member State in which your legal representative is located. So choosing where the representative sits is, in effect, choosing which national authority has competence over you for the Data Act. That is a decision worth making on purpose rather than by default, and we walk through it with you before the appointment.

## What the penalty is

Penalties for the Data Act are left to the Member States under Article 40, which requires them to be effective, proportionate, and dissuasive. There is no harmonized EU ceiling for the representative duty. The GDPR-level fines that Article 40(4) allows a supervisory authority to impose reach only infringements of Chapters II, III, and V of the Regulation, and the representative obligation sits in Chapter IX. So for this duty it is national penalties only, with no EU-level cap, and in some Member States the specific penalty rules are still being settled.

We do not lead with the fine, because it is a weaker reason to act than the rest. The appointment is a legal obligation that is already in force, competent authorities can be pointed at you only through the representative, and the appointment is what fixes your regulator under Article 37(13). Those are the reasons that hold up.

## What Engage delivers

- **The appointment itself**, with a mandate to be addressed by competent authorities on all issues related to your company, as Article 37(12) requires.
- **A named contact point in the EU**, so an authority reaching for you has a real address to use.
- **Handling of authority correspondence**, with the substance passed to your named internal owner and a recommended response.
- **A view on which Member State to place the appointment in**, since that choice sets the competent authority for you under Article 37(13).
- **A scope review**, so we confirm you are actually in scope and have no EU establishment before you pay for something you may not need.

A written mandate is not expressly required by the text of Article 37. In practice a contract is still how the appointment is evidenced, so we put it in writing regardless, and it is the document that proves the representative is in place. The Data Act does not put any record-keeping duty on the representative, so this is a contact-point and coordination role rather than a document-custody one.

## What it costs

Pricing is scoped to the mandate rather than fixed, because it turns on your footprint and on whether you also need one of the other representative appointments. [Talk to us](/contact) and we will give you a quote against your actual situation.

If your obligations run wider than the Data Act, it is common to pair this with the [GDPR Article 27 EU representative service](/eu-representative-service) or the [NIS2 representative](/nis2-representative), and the [EU representative providers compared](/eu-representative-providers-compared) page sets out how the mandates differ.

## Sources and references

- [Regulation (EU) 2023/2854 (the Data Act)](https://eur-lex.europa.eu/eli/reg/2023/2854/oj), EUR-Lex

## Frequently asked questions

### Who needs an EU Data Act representative?

Any entity within the scope of the Data Act that makes connected products available or offers services in the Union, and that is not established in the Union, has to designate a legal representative in one of the Member States. That comes from Article 37(11) of Regulation (EU) 2023/2854. The representative is mandated to be addressed by competent authorities on all issues related to the entity, and the entity is then treated as falling under the competence of the Member State where the representative sits.

### Does a non-EU SaaS company need a Data Act representative?

Often yes, and this surprises people. The Data Act defines a data processing service in Article 2(8) in terms broad enough to cover infrastructure, platform, and software as a service, so IaaS, PaaS, and SaaS are all inside the definition. Through the Chapter VI cloud switching obligations, an ordinary non-EU SaaS vendor offering services in the Union can be within scope of the Regulation, and once inside scope with no EU establishment the Article 37(11) representative duty applies.

### When did the EU Data Act representative obligation start?

The Data Act has applied since 12 September 2025, so the representative obligation is live now. It is not a future deadline you are preparing for. If you are in scope and have no EU establishment, the appointment is already due.

### Where must a Data Act legal representative be established?

In one of the Member States. Article 37(11) is the most permissive placement rule of any of the EU representative regimes: there is no requirement that it be a Member State where you actually offer services. Because Engage Compliance is established in the EU, we can hold this appointment directly, without needing a local entity in each country you sell into.

### What is the penalty for not appointing a Data Act representative?

Penalties for the Data Act are set by each Member State under Article 40 and have to be effective, proportionate, and dissuasive, but there is no harmonized EU ceiling for this obligation. The GDPR-style fines in Article 40(4) reach only infringements of Chapters II, III, and V, and the representative duty sits in Chapter IX, so it is national penalties only, with no EU-level cap. The stronger reasons to appoint are that it is a legal obligation, that authorities can address you only through the representative, and that the appointment fixes which regulator has competence over you.

### Can Engage Compliance act as our Data Act representative and our DPO?

Where we hold a monitoring role such as DPO for the same company, we keep it separate from the representative role and arrange one of the two through a partner entity, so the person who monitors your compliance is not also the person a regulator is addressed through. Where you only need the Data Act representative, we provide it directly from our EU establishment.
