Hosting providers whose main establishment sits outside the EU need a legal representative in the Union under Article 17 of the Terrorist Content Online Regulation. Engage Compliance takes that role from its EU establishment, with a staffed escalation path for the one-hour removal clock, not a mailbox.
The short answer: if you run a hosting service that offers services in the Union and disseminates information to the public, and your main establishment is outside the EU, Article 17 of Regulation (EU) 2021/784 requires you to designate a legal representative in the Union in writing. That representative receives removal orders on your behalf, and those orders carry a one-hour deadline to act. Engage Compliance provides the role from its EU establishment. Be clear-eyed about what that clock means: we pass a removal order to your named contact immediately on receipt rather than within any working-day window, and the hour to actually remove the content is yours. This is the one appointment where your own out-of-hours cover matters as much as ours.
Key takeaways
- Engage Compliance acts as your Article 17 legal representative in the Union, appointed in writing and performed from our EU establishment, with the details made public as the Regulation requires.
- The trigger is your main establishment being outside the Union, not the absence of any EU presence. A provider with a small EU subsidiary but its head office abroad is still caught. This is a wider trigger than the DSA, and it is almost never drawn correctly in the market.
- The representative is the designated recipient of removal orders, and Article 3(3) gives a hosting provider one hour to remove or disable access after an order is received. We forward an order to your named contact immediately on receipt. The removal itself is yours to do, inside that hour, which is why this mandate needs a contact who is actually reachable.
- There is no exemption and no size threshold. If you are a hosting provider that disseminates information to the public and offers services in the Union, the obligation applies.
- The obligation has been in force since 7 June 2022, so this is a current duty, not a future one.
Who needs a TCO legal representative
Article 17(1) requires a hosting service provider which does not have its main establishment in the Union to designate, in writing, a natural or legal person as its legal representative in the Union, for the receipt of, compliance with and enforcement of removal orders and decisions issued by the competent authorities.
The scope in Article 1(2) reaches hosting service providers offering services in the Union, whatever their place of main establishment, insofar as they disseminate information to the public. Offering services in the Union means enabling people in one or more Member States to use the service where there is a substantial connection to those Member States, which can come from a significant number of users in a Member State or from targeting activity at one.
So you are in scope when both of these hold: you host content that is disseminated to the public, and you offer that service to people in the EU. If both are true and your main establishment is outside the Union, you need the appointment.
How this differs from the DSA (the trap most providers miss)
This is the point worth getting right, because the wording looks similar and the effect is not.
The DSA Article 13 duty catches a provider that has no establishment in the Union at all. The TCO duty in Article 17 catches a provider whose main establishment is outside the Union, even if it has an EU subsidiary. The gap between those two tests is real: a company that opens a small Dublin office moves out of the DSA representative duty, because it now has an EU establishment, and stays inside the TCO one, because its main establishment is still abroad.
The practical consequence is that a hosting provider can need a TCO representative and a DSA representative for overlapping but not identical reasons, and clearing one does nothing for the other. We size both separately rather than treating them as one appointment.
Who is exempt
Nobody, by design. Article 17 carries no exemption and no carve-out, and there is no turnover, headcount or user-count threshold. If your service meets the scope test in Article 1(2), the duty applies whatever your size.
When it applies from
7 June 2022, under Article 24. The obligation is live now, and Member States had to have their penalty rules in place from the same date. If you have been offering a public hosting service into the EU from outside the Union and have never appointed a representative, the duty has already applied to you for some time.
Where the representative must be established
Under Article 17(2), the legal representative must reside or be established in one of the Member States where the hosting service provider offers its services. The provider also has to give the representative the powers and resources needed to comply with removal orders and decisions and to cooperate with the competent authorities.
Engage Compliance performs this role from its EU establishment. For a provider that offers services in the Netherlands, we act directly, with no local partner in the middle. Under Article 17(4) the provider notifies the competent authority and makes the representative’s details public, and we give you the wording to do that.
The one-hour clock, and why the appointment has to work
This is where a TCO mandate is different in kind from a quieter representative role. Article 3(3) requires a hosting provider to remove terrorist content, or disable access to it in all Member States, as soon as possible and in any event within one hour of receiving a removal order. The legal representative is the designated recipient of that order, so the hour starts when the order reaches the representative.
A one-hour deadline running to an inbox that nobody watches around the clock is not a compliance arrangement, it is exposure with a contact name on it. We run the mandate with a defined escalation path into your team, so an incoming order reaches the person who can act on it and the clock is treated as the emergency it is. Any TCO appointment sold as a plain forwarding address is mis-sold.
What the penalty is
Member States lay down the penalties under Article 18(1). Article 18(3) then sets a specific ceiling for the removal duty: a systematic or persistent failure to comply with the one-hour obligation in Article 3(3) is subject to financial penalties of up to 4% of the provider’s global turnover for the preceding business year.
Read that ceiling carefully. The 4% figure is tied to the Article 3(3) removal obligation, not to the appointment in Article 17. Failing to appoint a representative is punishable under whatever national penalty regime a Member State has adopted, rather than under the 4% ceiling. The 4% is the reason the appointment has to be operational rather than nominal: it is the removal clock, not the paperwork, that carries the heavy penalty, and the representative is the point the clock runs to.
One more thing to know about the role’s own risk. Under Article 17(3), the legal representative may be held liable for infringements of the Regulation, without prejudice to any liability of, or legal action against, the hosting provider itself. So the representative is not a purely passive letterbox in the eyes of the law, which is another reason to run the mandate properly.
What Engage delivers
- Appointment in writing that meets the Article 17(1) requirement, performed from our EU establishment.
- A published contact point for the competent authorities, in a form you can use to meet the notification and publication duty in Article 17(4).
- Immediate forwarding of removal orders to your named contact, rather than the next-working-day window that applies to ordinary correspondence, because Article 3(3) runs a one-hour clock and a working-day window would consume it. Give us a contact route that is reachable out of hours, because the removal is yours to perform.
- Handling of correspondence from the competent authorities, routed to your named internal owner with the deadline flagged.
- Annual review, because the appointment stops being accurate the moment your service footprint or establishment changes.
There is no record-keeping duty on the representative under the TCO Regulation, so this is a receipt-and-response mandate rather than a document-custody one. That keeps it lean, but it is exactly why the response side has to be fast.
What it costs
The appointment is €690 a year at the smallest band, for a company with 1 to 10 people, under €2m revenue, and under 5,000 people in the EU and UK whose data you hold, charged once, up front, with no setup fee. Whichever of headcount, revenue or the number of people whose data you hold puts you highest sets the band.
| Company size | TCO Legal Representative |
|---|---|
| 1 to 10 people, under €2m revenue, and under 5,000 people in the EU and UK whose data you hold | €690 |
| 11 to 50 people, or €2m to €10m revenue, or 5,000 or more people in the EU and UK whose data you hold | €990 |
| 51 to 250 people, or €10m to €50m revenue | €2,290 |
| 251 or more people, or over €50m revenue | From €4,490 |
The smallest band is for very small organizations only: 1 to 10 people, under €2m in global annual revenue, and under 5,000 people in the EU and UK whose personal data you hold. All three must be true. If any one of them is not, the next band up applies.
Commercial pricing bands based on familiar market-size and market-pricing thresholds. They are not a statutory size test.
Every appointment you hold is a separate mandate, and only the highest-priced one in the basket is charged in full. Every other appointment is charged at a share of its own price, and for this one that share is half its own price. So adding this to an appointment you already hold costs €345 at band 0, €495 at band 1, €1,145 at band 2, €2,245 at band 3, rather than a second full price.
Two extras are optional, and each is charged once per order rather than once per appointment. Higher-risk processing, which covers special category data and criminal offense data, is €250 at band 0, €500 at band 1, €750 at band 2, €1,000 at band 3. Same-business-day response is a service level on authority and data subject correspondence rather than substantive advice, and is €1,200 a year.
Every band is published and buyable, so you can see your price and appoint online without talking to anyone first. The full table for every mandate is on representative services.
The appointment issues in seconds. After payment you answer a short form about your company and who we should send correspondence to, about three minutes of typing, and the appointment document, the certificate, the public verification link and the wording you need all issue automatically at that moment. Nobody at Engage has to approve anything.
Sources and references
Representative verification register
Representative mandates
These mandates stack rather than replace each other. One company selling into Europe can be caught by several at once, each is a separate appointment with its own published contact point, and an EU representative does not cover the UK. Engage Compliance holds them together so you have one point of contact across the set.
- EU GDPR Article 27 representative
- UK GDPR Article 27 representative
- Swiss FADP Article 14 representative
- DSA Article 13 legal representative
- EU AI Act GPAI authorised representative
- EU AI Act high-risk authorised representative
- NIS2 representative
- Data Act legal representative
- Data Governance Act representative
- e-Evidence legal representative
- Terrorist Content Online representative
- GPSR responsible person
- CE-marking authorised representative
- Non-EU regimes (Swiss, China, Korea, Turkey)