EU Representative Compass — five appointment duties, none interchangeable
A company without an establishment in the Union that nevertheless serves the EU market can be required to appoint a representative under as many as five separate regimes. The functions look alike — point of contact, receiving agent, designated contact person — but they sit in different legal acts with different triggers. An appointment under one norm therefore does not discharge the duty under another. This compass places the five duties side by side so it becomes visible which of them a given footprint actually activates.
- GDPR · Art. 27
- DSA · Art. 13
- AI Act · Art. 22 · 54
- NIS2 · Art. 26(3)
- Data Act · Art. 37
Curated for orientation, produced with the Regingada deliverables pipeline. Not legal advice, not a legal assessment of your case.
https://www.regingada.com/playbooks/vertreter-kompass.html
Five regimes, five appointments
Appointment duties by regime
| Regime & norm | Who is caught | What the representative does | Practice note |
|---|---|---|---|
| GDPR · Art. 27 | Controllers and processors without an establishment in the Union that offer goods or services to data subjects in the EU or monitor their behaviour (exemptions: Art. 27(2)) | Point of contact for supervisory authorities and data subjects; contributes to the record of processing activities | The appointment belongs in the privacy policy |
| DSA · Art. 13 | Intermediary services without an establishment in the Union that have a substantial connection to the Union | Receiving and cooperation point for communications from authorities and courts; the details must be notified and made publicly available | The representative role carries a liability dimension of its own — the choice is not a formality |
| AI Act · Art. 22 (high-risk) and Art. 54 (GPAI) | Providers without an establishment in the Union that make high-risk AI systems or GPAI models available in the Union | Written mandate; keeps conformity and documentation evidence available, cooperates with authorities, contributes to the registration | The authorised representative of Art. 22 AI Act shares nothing but the number with Art. 22 GDPR |
| NIS2 · Art. 26(3) | Certain digital services without an establishment in the Union (among others DNS, TLD name registries, cloud, data centres, CDN, managed services, managed security services, online marketplaces, search engines, social networks) | A representative in a Member State in which the services are offered; anchors jurisdiction | Supervisory jurisdiction follows the seat of the representative — the choice has consequences |
| Data Act · Art. 37 | Providers of connected products and related services without an establishment in the Union | Designated contact person for the competent authorities | The youngest member of the series — applicable since 12 September 2025 |
The table names what the norms provide for. Whether a concrete company is caught, and by which of the five, depends on its own facts — that determination is a legal assessment and belongs to a mandate, not to a table.
Why one appointment does not settle the next
The five duties pursue separate legislative purposes: data-protection supervision, communication with authorities and courts, product conformity, cybersecurity jurisdiction and data access.
They address separate groups of addressees and attach to separate liability consequences.
Bundling them with the same service provider is possible and often practical — but it does not replace the formal individual appointment under each regime.
The order in practice
-
Clarify the footprint
Which services, products and processing operations actually reach the Union, and through which connecting factor: offering, monitoring, substantial connection, making available on the market?
-
Determine the regime scope per service
It is not the group that is caught but the individual role per service or product. Only then is it clear which of the five norms fire at all and which exemptions apply.
-
Appoint formally per regime and disclose it
Each appointment needs its own basis — a mandate or an engagement — and must be disclosed where the respective norm requires it: in the privacy policy, in the publicly available information, in the registration, towards the competent authority.
Where the software stops
This compass is orientation drawn from a public corpus and readable back to its sources. Which appointment duty a concrete company owes, and how the appointment has to be documented and disclosed, is a legal assessment under a separate mandate by the law firm Theo Funk. Regingada UG (haftungsbeschränkt) builds the software and takes on appointed EU-representative functions; the firm does the legal work.
Orientation, not legal advice
This playbook and the suite provide orientation and information only. They are not legal advice. Individual-case advice is provided exclusively by the law firm Theo Funk under a separate mandate. Regingada UG (haftungsbeschränkt) — the software company and appointed EU representative — and the law firm are strictly separated.
https://www.regingada.com/playbooks/vertreter-kompass.html