Regingada
Playbook · Representation

EU Representative Compass — five appointment duties, none interchangeable

Deliverable · Source: Funk corpus (CELEX/ELI-anchored) · Status: 2026-08

A company without an establishment in the Union that nevertheless serves the EU market can be required to appoint a representative under as many as five separate regimes. The functions look alike — point of contact, receiving agent, designated contact person — but they sit in different legal acts with different triggers. An appointment under one norm therefore does not discharge the duty under another. This compass places the five duties side by side so it becomes visible which of them a given footprint actually activates.

  • GDPR · Art. 27
  • DSA · Art. 13
  • AI Act · Art. 22 · 54
  • NIS2 · Art. 26(3)
  • Data Act · Art. 37

Curated for orientation, produced with the Regingada deliverables pipeline. Not legal advice, not a legal assessment of your case.

1 · The five duties

Five regimes, five appointments

Appointment duties by regime

Regime & norm Who is caught What the representative does Practice note
GDPR · Art. 27 Controllers and processors without an establishment in the Union that offer goods or services to data subjects in the EU or monitor their behaviour (exemptions: Art. 27(2)) Point of contact for supervisory authorities and data subjects; contributes to the record of processing activities The appointment belongs in the privacy policy
DSA · Art. 13 Intermediary services without an establishment in the Union that have a substantial connection to the Union Receiving and cooperation point for communications from authorities and courts; the details must be notified and made publicly available The representative role carries a liability dimension of its own — the choice is not a formality
AI Act · Art. 22 (high-risk) and Art. 54 (GPAI) Providers without an establishment in the Union that make high-risk AI systems or GPAI models available in the Union Written mandate; keeps conformity and documentation evidence available, cooperates with authorities, contributes to the registration The authorised representative of Art. 22 AI Act shares nothing but the number with Art. 22 GDPR
NIS2 · Art. 26(3) Certain digital services without an establishment in the Union (among others DNS, TLD name registries, cloud, data centres, CDN, managed services, managed security services, online marketplaces, search engines, social networks) A representative in a Member State in which the services are offered; anchors jurisdiction Supervisory jurisdiction follows the seat of the representative — the choice has consequences
Data Act · Art. 37 Providers of connected products and related services without an establishment in the Union Designated contact person for the competent authorities The youngest member of the series — applicable since 12 September 2025

The table names what the norms provide for. Whether a concrete company is caught, and by which of the five, depends on its own facts — that determination is a legal assessment and belongs to a mandate, not to a table.

2 · Separation

Why one appointment does not settle the next

The five duties pursue separate legislative purposes: data-protection supervision, communication with authorities and courts, product conformity, cybersecurity jurisdiction and data access.

They address separate groups of addressees and attach to separate liability consequences.

Bundling them with the same service provider is possible and often practical — but it does not replace the formal individual appointment under each regime.

3 · Sequence

The order in practice

  1. Clarify the footprint

    Which services, products and processing operations actually reach the Union, and through which connecting factor: offering, monitoring, substantial connection, making available on the market?

  2. Determine the regime scope per service

    It is not the group that is caught but the individual role per service or product. Only then is it clear which of the five norms fire at all and which exemptions apply.

  3. Appoint formally per regime and disclose it

    Each appointment needs its own basis — a mandate or an engagement — and must be disclosed where the respective norm requires it: in the privacy policy, in the publicly available information, in the registration, towards the competent authority.

4 · Next step

Where the software stops

This compass is orientation drawn from a public corpus and readable back to its sources. Which appointment duty a concrete company owes, and how the appointment has to be documented and disclosed, is a legal assessment under a separate mandate by the law firm Theo Funk. Regingada UG (haftungsbeschränkt) builds the software and takes on appointed EU-representative functions; the firm does the legal work.

Get this playbook by e-mail

We send this playbook once to the address below — as a document, no list, no follow-up. Fastest path stays Save as PDF above.

One-off use: we use your address to answer this request and for nothing else — no list, no marketing. Transmission details and your rights: privacy policy.

Disclaimer

Orientation, not legal advice

This playbook and the suite provide orientation and information only. They are not legal advice. Individual-case advice is provided exclusively by the law firm Theo Funk under a separate mandate. Regingada UG (haftungsbeschränkt) — the software company and appointed EU representative — and the law firm are strictly separated.