---
title: "EU Authorised Representative: The Two Roles"
url: "https://www.engagecompliance.co/eu-authorized-representative"
type: "service"
date: "2026-08-28"
---

# EU authorised representative

EU authorised representative names two entirely different roles under two different laws. One is a data protection appointment under GDPR Article 27. The other is a product-side appointment that lets goods be placed on the EU market. Companies routinely appoint the wrong one, so this page sends you to the right one. Both spellings, authorised and authorized, point at the same two roles.

**The short answer: if you need people and regulators in the EU to be able to reach you about personal data, you want the GDPR Article 27 representative. If you need a physical product to be lawfully placed on the EU market, you want the product-side role, a GPSR responsible person for general consumer products or an EU authorised representative for CE-marked goods. Engage Compliance provides all three. The one product role we do not take is the medical device representative, and we say so rather than send a manufacturer down the wrong path.**

## Key takeaways

- Two unrelated EU laws use authorised representative: GDPR Article 27 for data protection, and product law for placing goods on the EU market.
- The GDPR role is about contact: supervisory authorities, data subjects, and the record of processing. Engage provides it, from the [EU Representative service](/eu-representative-service).
- The product role is about market access: a responsible operator established in the Union, holding the conformity file. Engage provides it, as a [GPSR responsible person](/gpsr-responsible-person) and an [EU authorised representative for CE-marked goods](/ce-marking-authorised-representative).
- The one product-side role Engage does not take is the medical device representative under the MDR and IVDR, which is referred to a partner.
- A non-EU manufacturer of a connected device can need two of these at once, from the right specialists for each.
- The spelling, authorised or authorized, changes nothing. Both are used for both roles.

## The two roles, side by side

The phrase does its damage because the two roles feel similar and are not. Here is the split.

**The GDPR Article 27 data protection representative.** Required where a controller or processor outside the EU is caught by Article 3(2), meaning it offers goods or services to people in the EU or monitors their behaviour, and has no EU establishment. The representative is established in one of the member states where the data subjects are, which for a pan-EU service is satisfied by a single Netherlands appointment, is named and contactable in the privacy notice under Articles 13 and 14, holds a copy of the record of processing under Article 30, and receives correspondence from supervisory authorities and data subjects. It exists so people and regulators can reach you about data.

**The product-side responsible operator.** Required where a physical product is placed on the EU market and there is no economic operator established in the Union responsible for it. Under Article 4 of Regulation (EU) 2019/1020, that operator keeps the declaration of conformity and technical documentation available, answers market surveillance authorities, flags risks, and cooperates on corrective action, and its contact details go on the product. It exists so a product can lawfully reach the market and stay traceable. For general consumer products this is the [GPSR responsible person](/gpsr-responsible-person) under Regulation (EU) 2023/988; for CE-marked goods it is the [EU authorised representative](/ce-marking-authorised-representative) under Decision 768/2008.

They differ on purpose, on what the representative holds (the record of processing against the technical file), on who addresses them (data subjects and data protection authorities against market surveillance authorities), and on the trigger (processing personal data against placing a product on the market). One does not satisfy the other.

## If you need the data protection role

You are looking for the GDPR Article 27 representative. Three conditions all have to hold: no EU establishment, targeting or monitoring people in the EU under Article 3(2), and no exemption under Article 27(2), where the exemption requires occasional processing, no large-scale special category data, no criminal conviction data, and low risk, all at once. The full applicability test is in [do I need an EU representative](/do-i-need-an-eu-representative).

Engage provides this appointment in writing, with a published EU contact point for your privacy notice, the record of processing held and produced to authorities on request, data subject and authority correspondence handled, and an annual review. It costs €690 a year at the smallest band, for a company with 1 to 10 people, under €2m in global revenue and under 5,000 EU and UK data subjects, charged once, up front, with no setup fee, and €990, €2,290 or €4,490 for the three larger bands, which are set out in full on the [EU Representative service](/eu-representative-service). Where you need the UK appointment too, that is the separate [UK representative service](/uk-representative-service) at €550, €790, €1,830 or €3,590, and buying both charges the second appointment at 75 percent of its own price rather than in full, so the pair is €1,103 a year at the smallest band.

## If you need the product-side role

You are looking for the responsible operator that lets your goods be placed on the EU market. Which one depends on the product:

- **General consumer products** point to the [GPSR responsible person](/gpsr-responsible-person) under the General Product Safety Regulation, Regulation (EU) 2023/988 Article 16.
- **CE-marked products** under a harmonised regime, such as toys, electronics, radio equipment or personal protective equipment, point to the [EU authorised representative for CE-marked goods](/ce-marking-authorised-representative) under Regulation (EU) 2019/1020 Article 4 and Decision 768/2008.

Both are held from our EU establishment, both carry the ten-year document-custody obligation that outlives an annual contract, and one appointment can also cover Northern Ireland. Pricing for these is scoped to the mandate rather than published, because it depends on your product range. If you want to see how the field lines up, the [product-safety representative providers compared](/gpsr-responsible-person-providers-compared) page sets it out. Tell us what you place on the EU market and we will confirm which role applies before you appoint anyone.

## The one product role we do not take

We do not act as an authorised representative under the Medical Device Regulation (EU) 2017/745 or the In Vitro Diagnostic Regulation (EU) 2017/746. That is deliberate: MDR Article 15 requires a person responsible for regulatory compliance with defined qualifications, and MDR Article 11(5) makes the representative jointly and severally liable with the manufacturer for defective devices. It is a different role with a different risk profile, and we route those enquiries to a partner rather than take a device file we are not set up for. We also do not act under the Carbon Border Adjustment Mechanism, which requires authorisation as an indirect customs representative, and we do not currently offer a Great Britain product-side service.

A non-EU manufacturer of a connected medical device can end up needing several appointments at once: a medical device representative for the device, a GPSR or CE responsible operator for any non-medical goods, and an Article 27 representative for the personal data the device and its app collect. We take the ones we are the right firm for and name the ones we are not.

## Why Engage Compliance

Experience across 100+ startups and enterprises including Amazon, Coinbase, and Robinhood. The same expert stays on your account, so the person who scoped the appointment is the one who handles the first regulator letter. For the Article 27 and DPO engagements, every engagement carries professional indemnity and cyber insurance, and we can offer both the representative and the DPO as separate products where you need them, scoping them together.

## Get the right appointment

If you are not sure which role you need, the GDPR Article 27 data protection representative, the GPSR or CE product-side operator, or the medical device role we refer out, [tell us your setup](/contact) and we will confirm which obligation applies before you commit to anything.

## Sources and references

- [Regulation (EU) 2016/679 (GDPR), Article 27](https://eur-lex.europa.eu/eli/reg/2016/679/oj), EUR-Lex
- [Regulation (EU) 2023/988 (General Product Safety Regulation), Article 16](https://eur-lex.europa.eu/eli/reg/2023/988/oj), EUR-Lex
- [Regulation (EU) 2019/1020 (Market Surveillance Regulation), Article 4](https://eur-lex.europa.eu/eli/reg/2019/1020/oj), EUR-Lex

## Frequently asked questions

### Can Engage also act as our DPO?

Yes. Engage supports both Data Protection Officer work and Article 27 representative work, as two separate products scoped to what you need. See [DPO Services](/outsourced-dpo-services).

### What is an EU authorised representative?

The phrase names two different roles under two different laws. Under GDPR Article 27 it is a person or company established in a member state, mandated in writing by a controller or processor outside the EU, to be addressed by supervisory authorities and data subjects on all issues relating to processing. In product law it is an economic operator established in the Union, holding a written mandate from a manufacturer, who is responsible for a product on the EU market and holds its conformity file. They are separate appointments under separate laws, and one does not cover the other. The spelling, authorised or authorized, makes no difference to either.

### Which one do I need, the data protection role or the product one?

If your concern is that people in the EU and their regulators can reach you about personal data, you need the GDPR Article 27 data protection representative. If your concern is that a physical product can lawfully be placed on the EU market and stay traceable, you need the product-side role: a GPSR responsible person for general consumer products, or an EU authorised representative for CE-marked goods. A connected device sold by a non-EU manufacturer can need both, and they are different appointments. Engage provides the GDPR role and the GPSR and CE product roles.

### Is authorised representative the same as EU representative?

For data protection purposes, yes. Article 27 uses the word representative, and authorised representative, authorized representative, EU representative, GDPR representative and EU rep all name the same appointment. The word only means something else when it is used in a product-law sense, where it is the manufacturer's representative for goods on the EU market.

### Does Engage offer the medical device authorised representative role?

No. The authorised representative under the Medical Device Regulation (EU) 2017/745 and the In Vitro Diagnostic Regulation (EU) 2017/746 is a different role that we do not take, because MDR Article 15 requires a person responsible for regulatory compliance with defined qualifications and MDR Article 11(5) makes the representative jointly and severally liable with the manufacturer for defective devices. We route those to a partner. We do provide the GDPR Article 27 role, and the GPSR responsible person and CE-marking authorised representative roles for non-medical goods.

### Which member state should the Article 27 representative be in?

One of the member states where your data subjects are, under Article 27(3). Where you serve several, you choose among them. The product-side role is different: under Article 4 of Regulation (EU) 2019/1020 the responsible operator is established in the Union, and one appointment can also cover Northern Ireland.

### Does the representative take on our liability?

For the GDPR role, the representative can be subject to enforcement proceedings in the event of non-compliance, which Recital 80 makes explicit, but the controller or processor stays responsible for the processing. The representative is a point of contact and a holder of the record, not an insurer.
