Legal Analysis · Enforcement

Fines for Not Appointing an EU Representative: What the Record Shows

The five EU regimes covered here each require a representative, and the penalty figure most often quoted for a missing one — 6% of worldwide turnover — comes from a provision that does not cover it in Germany. This page separates the documented cases from the statutory ceilings, with the date and the authority for each.

Published 12 September 2026
Last reviewed 12 September 2026
Scope GDPR · DSA · AI Act · NIS2 · Data Act
Short answer

One publicly documented European decision has turned on a missing representative alone: the Dutch supervisory authority fined Locatefamily.com EUR 525,000 in a decision published on 12 May 2021. Everywhere else there is a statutory framework but no precedent — and the German figures are far lower than the 6% DSA ceiling usually quoted.

Each figure below traces to an official decision or a penalty provision. Where no case exists, this page says so — absence of enforcement is not a safe harbor.

Has anyone actually been fined for not appointing an EU representative?

Direct answer

One documented decision, and it is a GDPR case: the Autoriteit Persoonsgegevens fined Locatefamily.com EUR 525,000 for failing to designate a representative in the Union, published on 12 May 2021. It added a penalty payment of EUR 20,000 for every two weeks without one, capped at EUR 120,000.

The company had until 18 March 2021; the missing representative in the Union was itself the breach.

The case usually cited alongside it belongs elsewhere. The Italian Garante ordered Clearview AI on 10 February 2022 to designate a representative in the European Union within thirty days (Article 58(2)(d) GDPR); its fine answered several infringements together, as did the Dutch decision against the same company of 16 May 2024. Neither is a figure for Article 27.

Documented, regime by regime · as at 12 September 2026
RegimeProvisionStatutory rangeDocumented caseDate (decision / applicability)Source
GDPRArt. 27; fine under Art. 83(4)(a)up to EUR 10 m or 2% of turnoverLocatefamily.com, EUR 525,000 + penalty paymentdecision 10 December 2020 · published 12 May 2021Autoriteit Persoonsgegevens (NL)
GDPR (order)Art. 58(2)(d)designation within 30 daysClearview AI — order (IT); Art. 27 also among several infringements in the Dutch decision10 February 2022 · 16 May 2024Garante (IT) · AP (NL)
DSA (Germany)Art. 13; § 33(5) no. 2, (6) no. 2(b), (8) DDGup to EUR 100,000; 1% above EUR 10 mnone publishedDSA 17 February 2024 · DDG 14 May 2024DDG
AI ActArt. 22; fine under Art. 99(4)(b)up to EUR 15 m or 3% of turnovernone publishedfrom 2 December 2027 / 2 August 2028Reg. (EU) 2024/1689, 2026/1744
NIS2 (Germany)Art. 26(3); § 60(3), §§ 33, 34, 65 BSIGup to EUR 500,000 (registration)none publishedsince 6 December 2025BSIG
Data ActArt. 37(11)–(13); Art. 40national; no EU ceilingnone publishedsince 12 September 2025Reg. (EU) 2023/2854

How high can a GDPR fine for a missing representative go?

Direct answer

Article 83(4)(a) GDPR covers, among others, infringements of Articles 25 to 39, and Article 27 sits inside that range. The ceiling is EUR 10 million, or 2% of the total worldwide annual turnover of the preceding financial year, whichever is higher. That is a ceiling, not a tariff.

The amount follows the Article 83(2) criteria.

What does Germany impose for a missing DSA representative?

Direct answer

Up to EUR 100,000; where total turnover exceeds EUR 10 million, up to 1% of it instead. The offence is section 33(5) no. 2 of the German implementing act (Digitale-Dienste-Gesetz, DDG), read with section 33(6) no. 2(b) and section 33(8). The 6% figure from Article 52 DSA does not apply to it.

Article 52(3) DSA does set a 6% ceiling for DSA infringements, and section 33(7) DDG implements it — but its list of covered cases does not include the missing representative.

No published decision has yet turned on Article 13 alone. The notification duty in Article 13(4), backed by section 33(5) no. 4 DDG, makes the gap visible to the Digital Services Coordinator (Koordinierungsstelle für digitale Dienste) at the Bundesnetzagentur in Bonn. There is no size threshold — see duties and liability under Article 13 DSA.

Can the representative itself be fined under the AI Act?

Direct answer

Yes, but not yet. Article 99(4)(b) makes the Article 22 obligations of authorised (US: authorized) representatives a fineable infringement, at up to EUR 15 million or 3% of worldwide annual turnover — from 2 December 2027 (Annex III) and 2 August 2028 (Annex I). Article 99(4) sets no ceiling for Article 54.

The deferral comes from Regulation (EU) 2026/1744. Once Article 22 applies, the representative becomes an addressee in its own right. The Article 54 duty for general-purpose AI has applied since 2 August 2025, but Article 99(4) lists no ceiling for it; Chapter V is enforced by the Commission alone (Article 88(1)), which since 2 August 2026 can fine the provider up to EUR 15 million or 3% of worldwide turnover (Article 101).

What happens under NIS2 and the Data Act?

Direct answer

Under NIS2 the fine ceilings in Article 34(4) and (5) attach to Articles 21 and 23, not to the representative duty in Article 26(3). German law penalizes the registration instead: sections 33(1) and 34(1) BSIG, with a ceiling of EUR 500,000 under section 65. Under the Data Act, competence simply spreads.

In force since 6 December 2025, the BSIG requires registration within three months; section 34(1) nos. 3 and 4 put the representative’s address in that filing. Section 60(3) is a lever, not a penalty: appoint in Germany and the BSI becomes competent.

Article 37(13) of the Data Act is blunter: until a representative is designated, the entity falls under the competence of all Member States, and any may impose penalties set nationally (Article 40) — unless another competent authority is already proceeding on the same facts. Applies since 12 September 2025.

What is the real exposure of not appointing one?

Direct answer

For most companies it is not the fine. Without a representative there is no address in the Union for an authority to use, the Data Act opens all 27 Member States, NIS2 hands jurisdiction to every Member State you serve, and the DSA notification duty leaves a visible gap.

Whether any of them applies to you: which EU representative duty applies to your business. The steps: how to appoint an EU representative.

Close the gap, or have the exposure assessed

Have Regingada UG act as your EU representative →

Appointment itself is handled by Regingada UG (haftungsbeschränkt), a legally separate company owned by the attorney; legal assessment is a separate mandate with the law firm.

Already contacted by an authority? Discuss the case with the attorney.

Replies within one business day · CET/CEST (UTC+1/+2)

Frequently asked

Is the 6% of global turnover figure wrong?

Not as a description of the DSA in general — Article 52(3) DSA does set that ceiling for DSA infringements. It is wrong for this particular breach in Germany: section 33 DDG puts the missing legal representative in the EUR 100,000 bracket, with 1% of total turnover above EUR 10 million.

Was Clearview AI fined for not having an EU representative?

No. The Italian Garante ordered Clearview AI on 10 February 2022 to designate a representative in the European Union within thirty days. The fine in that decision covered several infringements together. It should not be quoted as the figure for a missing Article 27 representative.

Can a fine be sent to the representative instead of to us?

Under the GDPR the European Data Protection Board takes the view that corrective measures and fines imposed on the non-EU controller can be addressed to the representative, while the representative’s own direct liability is limited to Articles 30 and 58(1)(a). The DSA goes further: Article 13(3) allows the representative to be held liable in its own right.

Does a fine end the obligation?

No. The Dutch decision attached a penalty payment of EUR 20,000 for every two weeks without a representative, capped at EUR 120,000, which is the usual construction: the fine answers the past, a periodic penalty answers the continuing failure.

We have no EU entity. Does appointing a representative create one?

No — Article 13(5) DSA says so expressly, and the European Data Protection Board takes the same view for the GDPR; whether a duty reaches you at all is set out in which EU representative duty applies to your business.

Do we need a data protection officer as well?

Possibly, but the triggers are unrelated. The two roles are compared in EU representative vs. data protection officer.

Sources