Two different EU laws use the phrase authorized representative for two different roles. One is a data protection appointment under GDPR Article 27. The other is a product compliance appointment under the Medical Device Regulation and its siblings. Companies routinely appoint the wrong one.
The short answer: if you are looking for the data protection role, you want a GDPR Article 27 representative, established in a member state where your data subjects are and mandated in writing to be addressed by supervisory authorities and data subjects. If you are looking for the role that lets a device or product be placed on the Union market, that is a different appointment under product law and this page will tell you so rather than sell you the wrong one.
Engage Compliance provides the GDPR Article 27 appointment. We do not provide the product-law authorized representative role, and we say so plainly because sending a manufacturer down the wrong path costs them a market entry.
Key takeaways
- GDPR Article 27 and the Medical Device Regulation both use the word representative, for unrelated purposes.
- The Article 27 role is about data protection contact: supervisory authorities, data subjects, and the record of processing.
- The product-law role is about market access: the manufacturer’s mandate, technical documentation, and market surveillance.
- A connected medical device sold into the EU by a non-EU manufacturer usually needs both, from different providers.
- The Article 27 representative goes into your privacy notice; an unpublished appointment achieves nothing.
- Engage Compliance turns the product-law appointment down rather than taking it, so a manufacturer never ends up with a data protection firm on a device file.
What the GDPR role is
Article 27 requires a controller or processor not established in the Union, but caught by Article 3(2), to designate in writing a representative in the Union.
The mandate is that the representative is addressed, in addition to or instead of the controller or processor, by supervisory authorities and data subjects on all issues relating to processing. Three things follow from that in practice.
The representative is named and contactable. The identity and contact details go into your privacy notice under Articles 13 and 14, so a person in the EU has somewhere to write.
The representative holds the record. Article 30(1) puts the obligation to maintain a record of processing activities on the representative as well as the controller, and to make it available to a supervisory authority on request.
The representative receives correspondence. Rights requests, complaints, and supervisory authority contact arrive there and route to you.
The appointment does not move accountability. Recital 80 says the representative should be subject to enforcement proceedings in the event of non-compliance by the controller or processor, while leaving the controller or processor responsible for the processing. Anyone selling the role as a liability shield is selling something the regulation does not contain.
Who needs the GDPR appointment
Three conditions, all of which have to hold: no establishment in the EU, targeting or monitoring people in the EU under Article 3(2), and no exemption under Article 27(2). The exemption requires occasional processing, no large-scale special category data, no criminal conviction data, and low risk to rights and freedoms, all at once, and processing that is part of how your product works is not occasional.
The full applicability test, with the exemptions and the five answers companies reach for that do not work, is set out in do I need an EU representative.
How it differs from the product-law role
This is where the phrase does the damage, so it is worth setting out side by side.
Under the Medical Device Regulation (EU) 2017/745, Article 11 says that where the manufacturer of a device is not established in a member state, the device may only be placed on the Union market if the manufacturer designates a sole authorized representative. The designation is the mandate, valid only when accepted in writing, and the representative provides a copy of the mandate to the competent authority on request. Parallel roles exist across the In Vitro Diagnostic Regulation, the Machinery Regulation, and other CE-marking regimes.
The differences that matter:
- Purpose. Article 27 exists so people and regulators can reach you about data. The product-law role exists so a product can lawfully be placed on the market and be traceable afterwards.
- Number. The Medical Device Regulation requires a sole authorized representative for the Union. Article 27 requires establishment in one of the member states where the data subjects are, and does not use the word sole.
- What the representative holds. Technical documentation and the declaration of conformity in one case; the record of processing activities in the other.
- Who addresses them. Competent authorities for market surveillance in one case; supervisory authorities and data subjects in the other.
- Trigger. Placing a product on the market, against processing the personal data of people in the Union.
A non-EU manufacturer of a connected medical device typically needs both: an authorized representative under the device regulation for the device, and an Article 27 representative for the personal data the device and its companion app collect. Sponsors running trials in the EU meet a third, separate appointment again, the legal representative of the sponsor under the Clinical Trials Regulation, which is covered on DPO for clinical trials.
What we do
- Article 27 appointment in writing, with a mandate that meets the regulation rather than a letter of comfort.
- A published EU contact point, in wording you can paste into your privacy notice.
- Record of processing, held and produced to supervisory authorities on request, and built where you do not have one.
- Data subject contact handling, routed to your named owner with the statutory clock flagged.
- Supervisory authority correspondence, with the substance passed to you and a recommended response.
- Annual review, because the appointment goes stale the moment your processing footprint changes.
Where you need the UK appointment as well, that is the separate UK representative service, and where the wider question is what EU market entry requires, US to EU privacy compliance covers the sequence.
What it costs
The Article 27 appointment is From €59 per month, scaling with company size. Companies taking both the EU and the UK appointment take two mandates, with the second priced as an addition.
The DPO role is priced separately and starts From €1,000 per month for DPO Foundation, because it is a different job. Whether you need it as well is decided by Article 37, not by Article 27.
Why Engage Compliance
Experience across 100+ startups and enterprises including Amazon, Coinbase, and Robinhood. The same senior privacy expert stays on your account, so the person who scoped the appointment is the one who reads the first regulator letter.
We keep the representative and the DPO roles independent, on the European Data Protection Board’s reasoning about the conflict between a role that can be addressed on the company’s behalf and a role that monitors that same company. Where you need both, one comes from us and the other from a partner entity, and we tell you which in writing. Every engagement carries professional indemnity and cyber insurance.