Short answer: a non-EU company appoints an EU representative by signing a written mandate with a person or company established in an EU Member State, naming it where the law requires, and notifying the competent authority. Five EU regimes impose such a duty, all five already apply, and only one further AI Act duty follows later.
That later duty is Article 22 AI Act for high-risk systems: 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
- Scope check across the five regimes.
- Choose a permitted Member State.
- Sign the written mandate.
- File notifications and registrations.
- Publish the representative’s details.
Do you have to appoint an EU representative at all?
Most often the trigger is Article 27 GDPR: if you offer goods or services to people in the EU, or monitor their behavior there, and Article 3(2) GDPR applies, you must designate a representative in writing, unless the narrow exemption in Article 27(2) applies. Four further duties — DSA, AI Act, NIS2 and the Data Act — can apply in parallel.
Article 27(1) GDPR ties the duty to Article 3(2), not to nationality: what counts is that you target people in the Union or monitor their behavior there. Processors are caught too; the exemption in Article 27(2)(a) is cumulative and narrow. The other duties have their own triggers:
| Regime | Provision | Who must appoint, and since when |
|---|---|---|
| GDPR | Art. 27 (exemption: Art. 27(2)) | Controllers and processors caught by Art. 3(2) — since 25 May 2018 |
| DSA | Art. 13 | Providers of intermediary services with no EU establishment; no size threshold — since 17 February 2024 |
| AI Act | Art. 54 (exemption: Art. 54(6)); Art. 22 | Providers of general-purpose AI models — since 2 August 2025. Art. 22 (high-risk) from 2 December 2027 / 2 August 2028 |
| NIS2 | Arts. 2(1)–(4), 26(1)(b), 26(3), 41(1); in Germany § 60(3) BSIG | Listed entity types (see below) — EU-wide since 18 October 2024, in Germany since 6 December 2025 |
| Data Act | Art. 37(11) | Entities within the scope of the Regulation that make connected products available or offer services in the Union — since 12 September 2025 |
NIS2 entity types — as a rule medium-sized and above (Art. 2(1)), but regardless of size for TLD registries and DNS providers (Art. 2(2)(a)), domain name registration services (Art. 2(4)), entities identified as critical under Directive (EU) 2022/2557 (Art. 2(3)) and the further cases of Art. 2(2)(b) to (f):
- DNS service providers, TLD name registries, domain name registration services (registrars)
- cloud computing, data center and content delivery services
- managed service providers, managed security service providers
- online marketplaces, search engines, social networking platforms
The full side-by-side: EU representative duties compared. By business model: do you need an EU representative?
Which EU Member State should the representative be in — and why Germany?
Article 27(3) GDPR requires the representative to sit in a Member State where the data subjects are; the DSA and NIS2 require a Member State in which you offer services, so the choice is constrained. Only the AI Act and the Data Act leave it open. Where NIS2 applies, a German seat makes the BSI the competent authority.
Germany has one structural particularity: under Article 26(3) NIS2 jurisdiction follows the representative’s seat, and § 60(3) sentence 3 BSIG makes the Federal Office for Information Security (BSI) competent. The DSA notification under Article 13(4) goes to the Digital Services Coordinator at the representative’s seat — in Germany the Koordinierungsstelle für digitale Dienste at the Bundesnetzagentur in Bonn (§§ 12, 14 DDG) — the same route in every Member State.
Article 27(3) GDPR, by contrast, requires only that data subjects are in that Member State; as good practice the EDPB recommends establishing the representative in the Member State where a significant proportion of them are. A German Article 27 mandate has to hold up against that, even where the DSA and NIS2 mandates sit here.
What must the written mandate contain?
Only two regimes spell it out: Article 54(3)(a)–(d) AI Act today, and Article 22(3)(a)–(e) from 2 December 2027 (Annex III) and 2 August 2028 (Annex I). The GDPR has no catalog: Article 27(1) requires written designation, Article 30(1) adds the record of processing activities, subject to the small-enterprise derogation in Article 30(5). The DSA demands powers and resources.
Under the GDPR the mandate must make the representative addressable “in addition to or instead of” you by supervisory authorities and data subjects (Article 27(4)).
The AI Act is the opposite case: Article 22(3) — binding only from 2 December 2027 / 2 August 2028 — obliges the authorised (US: authorized) representative to verify the EU declaration of conformity and the technical documentation, keep them ten years, answer reasoned requests and handle Article 49(1) registration; Article 54(3) sets a shorter catalog towards the AI Office.
The DSA mandate covers receipt of, compliance with and enforcement of decisions, and Article 13(2) sentence 2 requires “necessary powers and sufficient resources”. Under Article 37(12) Data Act the representative must “comprehensively demonstrate” what you have put in place.
How do you appoint an EU representative in five steps?
Run a scope check for all five regimes; choose a Member State the applicable regime allows; sign a written mandate with the tasks that regime requires; file the notifications; then publish the representative’s name and address where the law requires it.
- Scope check, regime by regime: Article 3(2) GDPR targeting, DSA intermediary service, AI Act general-purpose model, NIS2 entity type, Data Act connected products or services offered in the Union.
- Choose the seat that satisfies every applicable rule; Article 27(3) GDPR is the binding constraint.
- Sign the written mandate: one document per regime, with its task catalog, the authority addressed and response times.
- File the notifications. DSA: the representative’s name, postal address, email and telephone number to the Digital Services Coordinator (Article 13(4)). NIS2 in Germany: BSI registration within three months (§§ 33(1), 34(1) nos. 3, 4 BSIG).
- Publish: in the privacy notice (Articles 13(1)(a), 14(1)(a) GDPR) and, under Article 13(4) sentence 2 DSA, publicly and kept up to date — in practice usually in the imprint, which § 5 DDG itself does not require.
The representative function itself is carried out by the representative service of Regingada UG (haftungsbeschränkt), Bamberg.
Where must the representative be named?
In up to five places: in your privacy notice under the GDPR; publicly on your service and in a notification to the Digital Services Coordinator under the DSA; in the registration file under NIS2; and towards the competent authority under the AI Act and the Data Act.
| Regime | Where the representative must appear | Provision |
|---|---|---|
| GDPR | Privacy notice; no duty to notify the supervisory authority | Arts. 13(1)(a), 14(1)(a); EDPB Guidelines 3/2018, p. 25 |
| DSA | Publicly on the service, and notified to the Digital Services Coordinator at the representative’s seat | Art. 13(4) |
| AI Act | Today: contact point towards the AI Office for GPAI models. Later: the registration entry for high-risk systems | Art. 54(3), (4); from 2 December 2027 / 2 August 2028: Art. 22(3)(e) with Art. 49(1) |
| NIS2 (Germany) | In the BSI registration — address and contact details of the representative | § 34(1) nos. 3, 4 BSIG |
| Data Act | Towards the competent authorities, on request | Art. 37(12) |
Which deadlines are already running?
Five clocks are already running: Article 27 GDPR since 25 May 2018, Article 13 DSA since 17 February 2024, the national NIS2 measures since 18 October 2024, Article 54 AI Act since 2 August 2025, and Article 37(11) Data Act since 12 September 2025. Germany transposed NIS2 late: the new BSIG applies since 6 December 2025.
Only one duty lies ahead. Article 22 AI Act, on authorized representatives for high-risk systems, was postponed by Regulation (EU) 2026/1744 (Official Journal of 24 July 2026, in force 27 July 2026): 2 December 2027 for Annex III systems, 2 August 2028 for Annex I systems — not before.
Germany was late by Article 41(1) NIS2, and one transitional date has passed: entities covered there on 6 December 2025 had to register with the BSI by 6 March 2026 (§§ 33(1), 34(1) BSIG).
What happens if you don’t appoint one?
The Dutch supervisory authority fined Locatefamily.com EUR 525,000 for having no EU representative (published 12 May 2021) and ordered designation subject to a penalty payment of EUR 20,000 per two weeks, capped at EUR 120,000. Article 83(4)(a) GDPR caps fines at EUR 10 million or 2 % of worldwide annual turnover, whichever is higher. Other regimes: EU representative fines by regime.
Can one representative cover all five duties — and what should you check?
Yes. One person or company can hold several mandates, and the EDPB confirms that a representative may act for several non-EU controllers. But the mandates stay legally separate — one per regime, each with its own task catalog — and the liability profiles differ, so check what the representative can actually carry.
Article 13(3) DSA allows the legal representative itself to be held liable for the provider’s non-compliance. The GDPR does not go that far: the EDPB states that it “does not establish a substitutive liability of the representative” — but authorities may address corrective measures and fines to it, and its own direct liability covers Articles 30 and 58(1)(a). Under Article 99(4)(b) AI Act the Article 22 representative — from 2 December 2027 / 2 August 2028 — can itself be the addressee of a fine, while Article 99(4)(b) does not cover the Article 54 representative. The frameworks in figures: fines for not appointing an EU representative.
Two questions follow: does the mandate name each regime’s tasks, or only “EU representation” in the abstract? And are the “necessary powers and sufficient resources” of Article 13(2) DSA there? See the DSA Article 13 legal representative and NIS2 in Germany.
Appointing a representative, or checking whether you need one
If designation is the next step, the representative service handles the mandate; whether a duty applies at all is a legal assessment for the law firm.
Appoint a representative through Regingada UG → Discuss a borderline case with the attorney →Replies within one business day · CET/CEST (UTC+1/+2)
Appointment itself is handled by Regingada UG (haftungsbeschränkt), a legally separate company owned by the attorney: it provides the representative function and the software, not legal advice. Legal assessment is a separate mandate with the law firm. Two contracts, billed separately; neither requires the other, and no referral commissions are paid. Only the law firm is bound by professional secrecy (§ 43a BRAO).
Questions and answers
Is appointing a representative the same as establishing a branch in the EU?
No. Article 13(5) DSA states expressly that the designation of a legal representative “shall not constitute an establishment in the Union”. For the GDPR, the EDPB takes the same line: the presence of the representative in the Union does not constitute an establishment of the controller or processor for the purposes of Article 3(1).
Our data protection officer is in the EU. Is that the same thing?
No. The two roles answer different questions, they are triggered by different provisions, and the EDPB does not consider them compatible in one person. The comparison is set out in EU representative vs. data protection officer.
We are a US company with no EU users. Do we need a representative?
Generally not. Article 3(2) GDPR turns on targeting people in the Union or monitoring their behavior there. The DSA needs a “substantial connection” — targeting, or recipient numbers significant for a Member State’s population (Art. 3(d), (e)); mere technical accessibility is not enough (recital 8). See when a representative is required — and when not.
We only sell through a marketplace. Does the duty still apply?
It can. Selling through a marketplace does not shift your own controller position under the GDPR, so whether Article 27 applies to you is assessed on your processing, not the platform’s. The DSA duty in Article 13 is different: it addresses providers of intermediary services, which is the marketplace, not the seller on it.
Our SaaS only has business customers in the EU. Does Article 27 GDPR apply?
Often yes, but it is a question of fact. Article 3(2)(a) GDPR asks whether you envisage offering the service to individuals in the Union — normally so where your users sit in the EU, even under a contract with their employer. Article 27 covers processors too. Test by business model: does a representative duty apply to your business model.
Our general-purpose AI model is open source. Does Article 54 apply?
It depends on how open the release really is. The exemption in Article 54(6) is narrower than it is usually quoted: it requires a free and open-source licence allowing access, use, modification and distribution, and publicly available parameters including the weights, the model architecture information and the information on model usage — and it falls away if the model presents systemic risks.
How long does it take to appoint a representative?
The designation itself is a written mandate; the timeline is set by the scope check across the regimes and the downstream work: updating the privacy notice, the DSA notification to the Digital Services Coordinator, and the BSI registration where NIS2 applies.
Can we change representatives later?
Yes, and the law anticipates it: under Article 54(5) AI Act the authorized representative must itself terminate the mandate if it has reason to consider the provider to be in breach, and inform the AI Office. The same duty will apply under Article 22(4) for high-risk systems from 2 December 2027 (Annex III) and 2 August 2028 (Annex I). On a change, the privacy notice, the DSA notification under Article 13(4) and the German registration data under § 34(2) BSIG have to be updated.
GDPR — Regulation (EU) 2016/679, Arts. 3(2), 27, 30(1), 30(5), 83(4)(a): data.europa.eu/eli/reg/2016/679/oj
DSA — Regulation (EU) 2022/2065, Art. 3(d), (e), Art. 13(1)–(5), Art. 93(2), Recital 8: data.europa.eu/eli/reg/2022/2065/oj
AI Act — Regulation (EU) 2024/1689, Arts. 22, 49(1), 54, 99(4), 113: data.europa.eu/eli/reg/2024/1689/oj
Digital Omnibus on AI — Regulation (EU) 2026/1744 of 8 July 2026, OJ of 24 July 2026, in force 27 July 2026 (postponement of Chapter III Sections 1–3): data.europa.eu/eli/reg/2026/1744/oj
NIS2 — Directive (EU) 2022/2555, Arts. 2(1), 2(2)(a), 2(4), 26(1)(b), 26(3), 41: data.europa.eu/eli/dir/2022/2555/oj
Data Act — Regulation (EU) 2023/2854, Arts. 37(11)–(13), 40, 50: data.europa.eu/eli/reg/2023/2854/oj
BSIG (German NIS2 implementation, in force 6 December 2025) — §§ 33, 34, 60(3), 65: gesetze-im-internet.de/bsig_2025/
DDG (German Digital Services Act implementation) — §§ 5, 12, 14, 33: gesetze-im-internet.de/ddg/
EDPB — Guidelines 3/2018 on the territorial scope of the GDPR, version 2.1 (7 January 2020), section 4: edpb.europa.eu
Autoriteit Persoonsgegevens — fine of EUR 525,000 on Locatefamily.com, published 12 May 2021: autoriteitpersoonsgegevens.nl