Two different EU laws use the phrase authorized representative for two different roles. One is a data protection appointment under GDPR Article 27. The other is a product compliance appointment under the Medical Device Regulation and its siblings. Companies routinely appoint the wrong one.

The short answer: if you are looking for the data protection role, you want a GDPR Article 27 representative, established in a member state where your data subjects are and mandated in writing to be addressed by supervisory authorities and data subjects. If you are looking for the role that lets a device or product be placed on the Union market, that is a different appointment under product law and this page will tell you so rather than sell you the wrong one.

Engage Compliance provides the GDPR Article 27 appointment. We do not provide the product-law authorized representative role, and we say so plainly because sending a manufacturer down the wrong path costs them a market entry.

Key takeaways

  • GDPR Article 27 and the Medical Device Regulation both use the word representative, for unrelated purposes.
  • The Article 27 role is about data protection contact: supervisory authorities, data subjects, and the record of processing.
  • The product-law role is about market access: the manufacturer’s mandate, technical documentation, and market surveillance.
  • A connected medical device sold into the EU by a non-EU manufacturer usually needs both, from different providers.
  • The Article 27 representative goes into your privacy notice; an unpublished appointment achieves nothing.
  • Engage Compliance turns the product-law appointment down rather than taking it, so a manufacturer never ends up with a data protection firm on a device file.

What the GDPR role is

Article 27 requires a controller or processor not established in the Union, but caught by Article 3(2), to designate in writing a representative in the Union.

The mandate is that the representative is addressed, in addition to or instead of the controller or processor, by supervisory authorities and data subjects on all issues relating to processing. Three things follow from that in practice.

The representative is named and contactable. The identity and contact details go into your privacy notice under Articles 13 and 14, so a person in the EU has somewhere to write.

The representative holds the record. Article 30(1) puts the obligation to maintain a record of processing activities on the representative as well as the controller, and to make it available to a supervisory authority on request.

The representative receives correspondence. Rights requests, complaints, and supervisory authority contact arrive there and route to you.

The appointment does not move accountability. Recital 80 says the representative should be subject to enforcement proceedings in the event of non-compliance by the controller or processor, while leaving the controller or processor responsible for the processing. Anyone selling the role as a liability shield is selling something the regulation does not contain.

Who needs the GDPR appointment

Three conditions, all of which have to hold: no establishment in the EU, targeting or monitoring people in the EU under Article 3(2), and no exemption under Article 27(2). The exemption requires occasional processing, no large-scale special category data, no criminal conviction data, and low risk to rights and freedoms, all at once, and processing that is part of how your product works is not occasional.

The full applicability test, with the exemptions and the five answers companies reach for that do not work, is set out in do I need an EU representative.

How it differs from the product-law role

This is where the phrase does the damage, so it is worth setting out side by side.

Under the Medical Device Regulation (EU) 2017/745, Article 11 says that where the manufacturer of a device is not established in a member state, the device may only be placed on the Union market if the manufacturer designates a sole authorized representative. The designation is the mandate, valid only when accepted in writing, and the representative provides a copy of the mandate to the competent authority on request. Parallel roles exist across the In Vitro Diagnostic Regulation, the Machinery Regulation, and other CE-marking regimes.

The differences that matter:

  • Purpose. Article 27 exists so people and regulators can reach you about data. The product-law role exists so a product can lawfully be placed on the market and be traceable afterwards.
  • Number. The Medical Device Regulation requires a sole authorized representative for the Union. Article 27 requires establishment in one of the member states where the data subjects are, and does not use the word sole.
  • What the representative holds. Technical documentation and the declaration of conformity in one case; the record of processing activities in the other.
  • Who addresses them. Competent authorities for market surveillance in one case; supervisory authorities and data subjects in the other.
  • Trigger. Placing a product on the market, against processing the personal data of people in the Union.

A non-EU manufacturer of a connected medical device typically needs both: an authorized representative under the device regulation for the device, and an Article 27 representative for the personal data the device and its companion app collect. Sponsors running trials in the EU meet a third, separate appointment again, the legal representative of the sponsor under the Clinical Trials Regulation, which is covered on DPO for clinical trials.

What we do

  • Article 27 appointment in writing, with a mandate that meets the regulation rather than a letter of comfort.
  • A published EU contact point, in wording you can paste into your privacy notice.
  • Record of processing, held and produced to supervisory authorities on request, and built where you do not have one.
  • Data subject contact handling, routed to your named owner with the statutory clock flagged.
  • Supervisory authority correspondence, with the substance passed to you and a recommended response.
  • Annual review, because the appointment goes stale the moment your processing footprint changes.

Where you need the UK appointment as well, that is the separate UK representative service, and where the wider question is what EU market entry requires, US to EU privacy compliance covers the sequence.

What it costs

The Article 27 appointment is From €59 per month, scaling with company size. Companies taking both the EU and the UK appointment take two mandates, with the second priced as an addition.

The DPO role is priced separately and starts From €1,000 per month for DPO Foundation, because it is a different job. Whether you need it as well is decided by Article 37, not by Article 27.

Why Engage Compliance

Experience across 100+ startups and enterprises including Amazon, Coinbase, and Robinhood. The same senior privacy expert stays on your account, so the person who scoped the appointment is the one who reads the first regulator letter.

We keep the representative and the DPO roles independent, on the European Data Protection Board’s reasoning about the conflict between a role that can be addressed on the company’s behalf and a role that monitors that same company. Where you need both, one comes from us and the other from a partner entity, and we tell you which in writing. Every engagement carries professional indemnity and cyber insurance.

Sources and references

  • Same-business-day response
  • Professional indemnity and cyber insurance
  • Named DPO notified to the supervisory authority

FAQ

Frequently asked questions

What is an EU authorized representative?

Under GDPR Article 27 it is a person or company established in a member state, mandated in writing by a controller or processor outside the EU, to be addressed by supervisory authorities and data subjects on all issues relating to processing. Under the Medical Device Regulation the same phrase means something else: a sole representative designated by a non-EU manufacturer so a device can be placed on the Union market. They are separate appointments under separate laws and one does not cover the other.

Is an authorized representative the same as an EU representative?

For data protection purposes, yes. Article 27 uses the word representative, and authorized representative, EU representative, GDPR representative, and EU rep are all names people use for the same appointment. The confusion only starts when the phrase is used in a product regulation sense, where it means a manufacturer's representative for CE marking and market surveillance.

Do we need a data protection representative and a product one?

If you are a non-EU manufacturer of a regulated product that also processes personal data of people in the EU without an EU establishment, then yes, both, and they are usually different providers. A medical device manufacturer selling a connected device into the EU is the standard case: an authorized representative under the Medical Device Regulation for the device, and an Article 27 representative for the data the device and its app collect.

Can one company hold both appointments?

In principle nothing forbids it, and in practice they call for different capabilities and different registrations, so they usually sit with different providers. A product-compliance representative is set up for technical documentation and market surveillance; a data protection representative is set up for supervisory authority correspondence and data subject contact.

Which member state should the Article 27 representative be in?

One of the member states where your data subjects are, under Article 27(3). Where you serve several, you choose among them. That differs from the medical device rule, which requires a sole authorized representative for the Union rather than a state-by-state choice.

Does the representative take on our liability?

The representative can be subject to enforcement proceedings in the event of non-compliance, which Recital 80 makes explicit, but the controller or processor remains responsible for the processing. The representative is a point of contact and a holder of the record, not an insurer.

What has to be published once we appoint one?

The representative's identity and contact details go into your privacy notice under Articles 13 and 14, alongside your own. An appointment that exists only in a contract does not do the job, because the entire purpose of the role is that a person in the EU can find someone to write to.