EU authorised representative names two entirely different roles under two different laws. One is a data protection appointment under GDPR Article 27. The other is a product-side appointment that lets goods be placed on the EU market. Companies routinely appoint the wrong one, so this page sends you to the right one. Both spellings, authorised and authorized, point at the same two roles.
The short answer: if you need people and regulators in the EU to be able to reach you about personal data, you want the GDPR Article 27 representative. If you need a physical product to be lawfully placed on the EU market, you want the product-side role, a GPSR responsible person for general consumer products or an EU authorised representative for CE-marked goods. Engage Compliance provides all three. The one product role we do not take is the medical device representative, and we say so rather than send a manufacturer down the wrong path.
Key takeaways
- Two unrelated EU laws use authorised representative: GDPR Article 27 for data protection, and product law for placing goods on the EU market.
- The GDPR role is about contact: supervisory authorities, data subjects, and the record of processing. Engage provides it, from the EU Representative service.
- The product role is about market access: a responsible operator established in the Union, holding the conformity file. Engage provides it, as a GPSR responsible person and an EU authorised representative for CE-marked goods.
- The one product-side role Engage does not take is the medical device representative under the MDR and IVDR, which is referred to a partner.
- A non-EU manufacturer of a connected device can need two of these at once, from the right specialists for each.
- The spelling, authorised or authorized, changes nothing. Both are used for both roles.
The two roles, side by side
The phrase does its damage because the two roles feel similar and are not. Here is the split.
The GDPR Article 27 data protection representative. Required where a controller or processor outside the EU is caught by Article 3(2), meaning it offers goods or services to people in the EU or monitors their behaviour, and has no EU establishment. The representative is established in one of the member states where the data subjects are, which for a pan-EU service is satisfied by a single Netherlands appointment, is named and contactable in the privacy notice under Articles 13 and 14, holds a copy of the record of processing under Article 30, and receives correspondence from supervisory authorities and data subjects. It exists so people and regulators can reach you about data.
The product-side responsible operator. Required where a physical product is placed on the EU market and there is no economic operator established in the Union responsible for it. Under Article 4 of Regulation (EU) 2019/1020, that operator keeps the declaration of conformity and technical documentation available, answers market surveillance authorities, flags risks, and cooperates on corrective action, and its contact details go on the product. It exists so a product can lawfully reach the market and stay traceable. For general consumer products this is the GPSR responsible person under Regulation (EU) 2023/988; for CE-marked goods it is the EU authorised representative under Decision 768/2008.
They differ on purpose, on what the representative holds (the record of processing against the technical file), on who addresses them (data subjects and data protection authorities against market surveillance authorities), and on the trigger (processing personal data against placing a product on the market). One does not satisfy the other.
If you need the data protection role
You are looking for the GDPR Article 27 representative. Three conditions all have to hold: no EU establishment, targeting or monitoring people in the EU under Article 3(2), and no exemption under Article 27(2), where the exemption requires occasional processing, no large-scale special category data, no criminal conviction data, and low risk, all at once. The full applicability test is in do I need an EU representative.
Engage provides this appointment in writing, with a published EU contact point for your privacy notice, the record of processing held and produced to authorities on request, data subject and authority correspondence handled, and an annual review. It costs €690 a year at the smallest band, for a company with 1 to 10 people, under €2m in global revenue and under 5,000 EU and UK data subjects, charged once, up front, with no setup fee, and €990, €2,290 or €4,490 for the three larger bands, which are set out in full on the EU Representative service. Where you need the UK appointment too, that is the separate UK representative service at €550, €790, €1,830 or €3,590, and buying both charges the second appointment at 75 percent of its own price rather than in full, so the pair is €1,103 a year at the smallest band.
If you need the product-side role
You are looking for the responsible operator that lets your goods be placed on the EU market. Which one depends on the product:
- General consumer products point to the GPSR responsible person under the General Product Safety Regulation, Regulation (EU) 2023/988 Article 16.
- CE-marked products under a harmonised regime, such as toys, electronics, radio equipment or personal protective equipment, point to the EU authorised representative for CE-marked goods under Regulation (EU) 2019/1020 Article 4 and Decision 768/2008.
Both are held from our EU establishment, both carry the ten-year document-custody obligation that outlives an annual contract, and one appointment can also cover Northern Ireland. Pricing for these is scoped to the mandate rather than published, because it depends on your product range. If you want to see how the field lines up, the product-safety representative providers compared page sets it out. Tell us what you place on the EU market and we will confirm which role applies before you appoint anyone.
The one product role we do not take
We do not act as an authorised representative under the Medical Device Regulation (EU) 2017/745 or the In Vitro Diagnostic Regulation (EU) 2017/746. That is deliberate: MDR Article 15 requires a person responsible for regulatory compliance with defined qualifications, and MDR Article 11(5) makes the representative jointly and severally liable with the manufacturer for defective devices. It is a different role with a different risk profile, and we route those enquiries to a partner rather than take a device file we are not set up for. We also do not act under the Carbon Border Adjustment Mechanism, which requires authorisation as an indirect customs representative, and we do not currently offer a Great Britain product-side service.
A non-EU manufacturer of a connected medical device can end up needing several appointments at once: a medical device representative for the device, a GPSR or CE responsible operator for any non-medical goods, and an Article 27 representative for the personal data the device and its app collect. We take the ones we are the right firm for and name the ones we are not.
Why Engage Compliance
Experience across 100+ startups and enterprises including Amazon, Coinbase, and Robinhood. The same expert stays on your account, so the person who scoped the appointment is the one who handles the first regulator letter. For the Article 27 and DPO engagements, every engagement carries professional indemnity and cyber insurance, and we can offer both the representative and the DPO as separate products where you need them, scoping them together.
Get the right appointment
If you are not sure which role you need, the GDPR Article 27 data protection representative, the GPSR or CE product-side operator, or the medical device role we refer out, tell us your setup and we will confirm which obligation applies before you commit to anything.