The Data Governance Act only asks for a legal representative from two narrow groups: data intermediation services providers under Article 11(3), and recognized data altruism organizations under Article 19(3). Most companies are not caught by it at all. Where you are, Engage Compliance acts as your representative directly from its EU establishment.
The short answer: Regulation (EU) 2022/868 imposes no general representative duty. It reaches only a non-EU data intermediation services provider offering the Article 10 services in the Union (Article 11(3)), and a non-EU entity that meets the Article 18 data altruism requirements (Article 19(3)). If your business is neither, the Data Governance Act does not require a representative from you, and we will tell you so. Where you are one of the two, Engage Compliance takes the appointment from its EU establishment and holds the compliance file behind it.
Key takeaways
- The Data Governance Act, Regulation (EU) 2022/868, has required a legal representative from just two groups since it came into force on 24 September 2023.
- Engage Compliance acts as that representative directly from its EU establishment, so no local partner sits in the chain for a Data Governance Act mandate.
- Article 11(3) catches a data intermediation services provider that is not established in the Union but offers the Article 10 services in the Union.
- Article 19(3) catches an entity that meets the Article 18 data altruism requirements but is not established in the Union.
- There is no general duty on ordinary businesses. If your company is neither an intermediation provider nor a data altruism organization, the Data Governance Act asks nothing of you here.
- Appointing the representative settles your regulator, because jurisdiction attaches where the representative is located, so it is a decision worth taking deliberately.
Who needs a Data Governance Act representative
Two duties, and they are separate from each other.
Duty A, Article 11(3): data intermediation services providers. A data intermediation services provider that is not established in the Union, but which offers the data intermediation services referred to in Article 10 within the Union, must designate a legal representative in one of the Member States in which those services are offered. Article 10 covers the services that sit between data holders and data users to set up commercial data-sharing. If that is your business and you have no EU establishment, this is your duty.
Duty B, Article 19(3): data altruism organizations. An entity that meets the requirements of Article 18 but is not established in the Union must designate a legal representative in one of the Member States. This is the recognized data altruism route, for organizations that collect and make data available for the general interest.
These are the only two triggers in the Act. If you fall inside one of them, the representative is required; if you do not, it is not.
Who is not caught
The Data Governance Act does not put a general representative obligation on ordinary businesses, and this gets misread more than anything else about it. A normal SaaS company, an e-commerce seller, a fintech, an app, a marketplace that is not itself a data intermediation service in the Article 10 sense, none of these needs a Data Governance Act representative just for reaching customers in the EU. That is a real difference from GDPR Article 27, which does reach a broad range of companies. The great majority of prospects are not caught by the DGA at all, and we would rather say that plainly than sell you a mandate you do not need.
If you already have an EU establishment that carries out the intermediation or altruism activity, the Article 11(3) and Article 19(3) duties do not bite, because both are aimed at entities that are not established in the Union.
When it applies from
The Data Governance Act has been in force since 24 September 2023. The representative duties under Articles 11(3) and 19(3) are live now for the two groups they cover, so there is no future start date to wait for.
Where the representative must be established
Placement differs between the two duties. For a data intermediation services provider under Article 11(3), the representative must sit in a Member State where the services are offered. For a data altruism organization under Article 19(3), it can be in any Member State.
Either way, the choice carries weight, because jurisdiction attaches where the representative is located. Appointing the representative therefore also settles which Member State’s competent authority you deal with. GDPR does not work like this, so people who assume a representative is purely administrative are often surprised. Here it is not.
Engage Compliance is established in the EU, so for a Data Governance Act mandate we act as your representative from that establishment directly. There is no local intermediary to coordinate and no partner to introduce.
What the mandate involves
For Article 11(3), the representative is mandated to be addressed, in addition to or instead of the provider, by the competent authorities and by data subjects and data holders on all issues related to the data intermediation services. The representative also has to cooperate with the competent authorities and, on request, comprehensively demonstrate the actions taken and the provisions the provider has put in place to comply with the Regulation.
That last duty is more than a mailbox. Demonstrating the actions taken, on request and comprehensively, is a substantive evidence-production duty, and in practice it means the representative has to hold your compliance file rather than just forward letters. That is how we run the role: we keep the file current so that a request from the authority can be answered rather than scrambled for.
Neither Article 11(3) nor Article 19(3) expressly requires the mandate to be in writing. We put it in writing anyway, because when the law does not spell out a form, the contract becomes the only evidence that the appointment exists and what it covers.
What the penalty is
The Data Governance Act leaves penalties to the Member States. Article 34(1) requires each Member State to lay down the penalties for infringements, including infringements of Article 11, which contains the intermediation representative duty. Those penalties have to be effective, proportionate and dissuasive, and the Regulation sets no EU-level ceiling, so the actual exposure depends on the Member State whose authority you fall under. This is a factual backstop, not the reason to appoint. The reason to appoint is that it is a legal obligation for the two groups it covers, and that authorities and counterparties can ask about it.
What Engage delivers
- The appointment itself, in writing, meeting the Article 11(3) or Article 19(3) requirement rather than a nameplate.
- A named EU point of contact for the competent authority, data subjects and data holders, published where it needs to be.
- The compliance file held and kept current, so the Article 11(3) duty to demonstrate the actions taken can actually be met on request.
- Handling of authority correspondence, passed to you with the substance within one business day.
- A scoping check first. If it turns out you are not caught by either duty, we say so and stop, rather than selling you a mandate you do not need.
Because Engage Compliance is EU-established, all of this is delivered directly, with no local partner in the chain for a Data Governance Act mandate.
What it costs
Each of these appointments is €550 a year at the smallest band, for a company with 1 to 10 people, under €2m revenue, and under 5,000 people in the EU and UK whose data you hold, charged once, up front, with no setup fee. Whichever of headcount, revenue or the number of people whose data you hold puts you highest sets the band.
| Company size | DGA Data Intermediation Representative | DGA Data Altruism Representative |
|---|---|---|
| 1 to 10 people, under €2m revenue, and under 5,000 people in the EU and UK whose data you hold | €550 | €550 |
| 11 to 50 people, or €2m to €10m revenue, or 5,000 or more people in the EU and UK whose data you hold | €790 | €790 |
| 51 to 250 people, or €10m to €50m revenue | €1,830 | €1,830 |
| 251 or more people, or over €50m revenue | From €3,590 | From €3,590 |
The smallest band is for very small organizations only: 1 to 10 people, under €2m in global annual revenue, and under 5,000 people in the EU and UK whose personal data you hold. All three must be true. If any one of them is not, the next band up applies.
Commercial pricing bands based on familiar market-size and market-pricing thresholds. They are not a statutory size test.
Every appointment you hold is a separate mandate, and only the highest-priced one in the basket is charged in full. Every other appointment is charged at a share of its own price, and for these that share is half its own price. So adding one of these to an appointment you already hold costs €275 at band 0, €395 at band 1, €915 at band 2, €1,795 at band 3, rather than a second full price.
Two extras are optional, and each is charged once per order rather than once per appointment. Higher-risk processing, which covers special category data and criminal offense data, is €250 at band 0, €500 at band 1, €750 at band 2, €1,000 at band 3. Same-business-day response is a service level on authority and data subject correspondence rather than substantive advice, and is €1,200 a year.
Every band is published and buyable, so you can see your price and appoint online without talking to anyone first. The full table for every mandate is on representative services.
Both appointments issue in seconds. After payment you answer a short form about your company and who we should send correspondence to, about three minutes of typing, and the appointment document, the certificate, the public verification link and the wording you need all issue automatically at that moment. Nobody at Engage has to approve anything.
Sources and references
Representative verification register
Representative mandates
These mandates stack rather than replace each other. One company selling into Europe can be caught by several at once, each is a separate appointment with its own published contact point, and an EU representative does not cover the UK. Engage Compliance holds them together so you have one point of contact across the set.
- EU GDPR Article 27 representative
- UK GDPR Article 27 representative
- Swiss FADP Article 14 representative
- DSA Article 13 legal representative
- EU AI Act GPAI authorised representative
- EU AI Act high-risk authorised representative
- NIS2 representative
- Data Act legal representative
- Data Governance Act representative
- e-Evidence legal representative
- Terrorist Content Online representative
- GPSR responsible person
- CE-marking authorised representative
- Non-EU regimes (China, Korea, Turkey, Thailand)