Many EU and UK rules require a business based elsewhere to name someone established here. REP27 takes that role under a written mandate, signs it, and gives you a certificate anyone can verify.
Europe Services SEPrague, with a network of partner law firms, since 2014
REP27 LTDEngland and Wales, company no. 17385889, for UK appointmentsEach site does one job well. Same companies, same signatures, same way of working.
Representatives and responsible persons for GDPR, products, cosmetics, NIS2, Data Act, CRA, AI Act and EUDR.
Accessibility records under the European Accessibility Act, UK rules and Ontario's AODA, tested by people and verifiable online.
Product labels ready for EU marketplaces, with the safety information and responsible person in all 24 EU languages.
Every document is signed by a company established where the law applies. Tap or hover a card to see what it signs.
Choose one and the services that can apply to you stay highlighted.
14 services shown

Your contact point for EU data protection authorities and for the people whose data you process.
Signed by REP27 LTD in England, for businesses outside the UK that serve UK customers.
Two separate duties covered together, with two certificates and two verification codes.
For Norway, Iceland and Liechtenstein, and how the appointment works there.

The name and address marketplaces ask for on your label, with unlimited products on every plan.
For skincare, make-up and perfume brands placing products on the EU or UK market.
The EU economic operator required for CE-marked products such as toys, electronics and PPE.
A written mandate for manufacturers of machinery sold into the EU from outside it.

We receive vulnerability reports all year round and help you notify the authorities in time.
Required for non-EU cloud, DNS, CDN and managed service providers, marketplaces and social platforms.
For non-EU makers of connected products and related services that hold user data.
For online intermediaries without an EU establishment that offer services to EU users.

Transparency kit, AI register, and the EU representative for general-purpose and high-risk AI.
For coffee, cocoa, timber, rubber, soy, cattle and palm oil placed on the EU market.



81 answers, grouped by topic. Pick a topic or search for a word.
REP27 acts as the legal representative or responsible person that EU and UK rules require from businesses established elsewhere. We sign a written mandate, receive requests from authorities and the public, and give you a certificate anyone can verify.
Europe Services SE, a company registered in Prague and active since 2014, signs EU appointments. REP27 LTD, company no. 17385889 in England and Wales, signs UK appointments.
No. Europe Services SE coordinates a network of partner law firms, but REP27 itself does not give legal advice or represent you in court. We perform the representative and responsible person roles the regulations describe.
Several EU laws only work if authorities and consumers have a contact inside the Union. When the business itself has no establishment there, the law asks it to name one, and that is the role we take.
Yes. The same company can hold, for example, a GDPR representative mandate and a GPSR responsible person mandate. Each one is a separate designation with its own certificate.
Mostly from the United States, the United Kingdom, Canada, Asia, Latin America and the Middle East, plus EU companies that sell into the UK. Any business that offers goods or services to people in the EU or UK from abroad can use us.
Usually not for the GDPR: an establishment in the Union normally removes the Article 27 duty. For products it depends on who places them on the market, so check each regulation separately.
Use the free check on gdprrepresentative.com or write to us. A person reviews what you sell and to whom, and tells you which obligations apply and which do not.
It is the person or company established in the EU that a non-EU controller or processor must name when the GDPR applies to it under Article 3(2). Authorities and data subjects can contact the representative on all data protection matters.
When you have no establishment in the EU and you offer goods or services to people in the EU, or monitor their behaviour there, for example through tracking or profiling on your website or app.
Yes, for processing that is occasional, does not involve large-scale special categories or criminal data, and is unlikely to create a risk for people. Public authorities are also exempt. Most online businesses that sell to EU customers regularly do not meet this exemption.
The representative must be in one of the member states where the people whose data you process are. Our EU appointments are signed by Europe Services SE in the Czech Republic, which covers clients with customers across the Union.
No. A data protection officer advises and monitors compliance, often from inside the company. The representative is a contact point in the EU and does not replace a DPO if you need one.
No. Appointing a representative does not transfer the controller's or processor's responsibility. You remain responsible for complying with the GDPR.
The name and contact details of your EU representative. After approval you receive a ready-made line to paste into your privacy notice.
Failing to designate one can lead to fines of up to 10 million euros or 2% of worldwide annual turnover, whichever is higher. Authorities have already fined non-EU companies for this.
Yes, a processor that is not established in the EU and falls under Article 3(2) also needs one. This often concerns SaaS companies that process data for EU customers.
The representative must be able to provide the record of processing activities to authorities. During onboarding you give us the information we need for that record.
Yes, if you have no UK establishment and the UK GDPR applies to you. Since Brexit the EU and UK duties are separate, and one representative in the EU does not cover the UK.
REP27 LTD, a company registered in England and Wales, number 17385889. UK designations show only UK details.
Yes. You receive two designations, two certificates and two verification codes, and one line for each in your privacy notice.
If you offer goods or services to people in the UK or monitor them, and you have no UK establishment, generally yes. The UK GDPR has the same test as the EU text.
Yes, for products sold into Great Britain. You can choose EU, UK or both in the checkout of the product service.
The UK representative is the contact point for the Information Commissioner's Office and for UK data subjects, and forwards their requests to you.
For data protection, Northern Ireland follows the UK GDPR. For products, some EU rules still apply in Northern Ireland, so ask us about your specific goods.
Yes, a company based only in the UK that sells to or monitors people in the EU needs an Article 27 representative in the Union.
Under the General Product Safety Regulation (EU) 2023/988, most consumer products sold in the EU need an economic operator established in the Union. Its name and contact details must appear on the product, its packaging or an accompanying document.
Since 13 December 2024. Marketplaces now ask sellers for the responsible person before listings stay online.
Most non-food consumer products placed on the EU market, including clothing, toys, jewellery, homeware and electronics. Some sectors, such as cosmetics or medical devices, follow their own rules.
The name, postal address and electronic address of the responsible person. After approval we give you the exact text to print.
Enter the responsible person details we provide in the product safety fields of your seller account. Each marketplace has its own form, and the data are the same.
All plans cover unlimited products, with no charge per SKU.
We can share them so you can prepare your artwork, but our name may only be printed on products once you have paid and the designation is active.
You can pay now and have the designation start on the day your goods are first shipped, within a maximum date. The 12 months run from that day.
Yes. Under Regulation (EC) 1223/2009 every cosmetic product placed on the EU market needs a responsible person established in the Union, whose name and address appear on the label.
It keeps the product information file available at the address on the label, checks that the safety assessment and notification are in place, and is the contact for authorities.
Each product needs a cosmetic product safety report signed by a qualified assessor before it is placed on the market. You can appoint us while the reports are being prepared.
Products must be notified in the EU Cosmetic Products Notification Portal before sale. During onboarding you tell us who handles the notification.
Yes, perfumes and fragrances are cosmetic products under the regulation.
From 690 euros a year for 1 to 5 products and 1,490 euros for 6 to 20. Above 20 products the price is 150 euros per product.
Yes. Great Britain requires its own responsible person, and we offer EU, UK or both.
A new formula usually means an updated safety report and notification. Tell us before the change reaches the market so the file stays consistent.
Providers not established in the EU that offer cloud, data centre, content delivery, DNS, top-level domain, managed or managed security services, online marketplaces, search engines or social networks in the Union.
In one of the member states where the services are offered. The provider is then treated as falling under that country's jurisdiction.
Data holders established outside the EU that offer connected products or related services in the Union must designate a legal representative there. The Data Act applies from 12 September 2025.
Micro and small enterprises are largely exempt from the data sharing obligations, though not from everything. Check your case before deciding.
From 11 September 2026 manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents: an early warning within 24 hours, a notification within 72 hours and a final report later.
No, it is optional under Article 18. What matters in practice is that, for a manufacturer outside the EU, the authorised representative helps determine which national CSIRT is competent for its reports.
A channel where researchers and users can report vulnerabilities in your products all year round. We receive the reports and help you notify the authorities within the deadlines.
The full obligations apply from 11 December 2027. Reporting obligations started earlier, on 11 September 2026.
A transparency kit for Article 50, an AI register together with transparency, and the EU authorised representative for providers of general-purpose AI models and high-risk systems established outside the Union.
Transparency towards people: telling them when they interact with an AI system and marking AI-generated or manipulated content in the cases the regulation lists.
Providers established outside the EU that place general-purpose AI models or high-risk AI systems on the EU market must appoint one in the Union by written mandate.
Deployers have fewer duties than providers, but transparency obligations can still apply, for example when you publish AI-generated content. Tell us how you use AI and we will say what applies.
290, 590 and 1,490 euros for the first year, depending on the service, and 240, 490 and 1,190 euros on renewal.
Not at the moment. The checkout explains why when you select the option.
The obligations for providers of general-purpose AI models apply from 2 August 2025.
We tell you which category your system is likely to fall into based on what you describe, but a formal legal assessment should come from a lawyer.
The EU Deforestation Regulation (EU) 2023/1115. It requires operators to prove that certain commodities and products were not produced on land deforested after 31 December 2020.
Cattle, cocoa, coffee, oil palm, rubber, soya and wood, and many products made from them, such as chocolate, leather or furniture.
From 30 December 2026 for medium and large companies and from 30 June 2027 for micro and small companies.
It acts on behalf of an operator outside the EU for the tasks the regulation allows, including submitting due diligence statements, and is a contact for the authorities.
The deadlines for applying the regulation have been postponed, but the 31 December 2020 cut-off date has not changed.
No, printed products were removed from the scope by the 2025 amendment.
No. After the 2025 amendment most downstream operators no longer file their own statement and keep only the reference number received from upstream.
No. We act as authorised representative. Geolocation data and due diligence on your suppliers remain your responsibility or that of a specialised provider.
You choose the service and pay online, receive a receipt with an access link, fill in the onboarding form, and a person checks your file and signs the designation.
A person reviews your file within 24 working hours after you complete the form.
From 290 euros a year for the EU. EU and UK together start at 390 euros a year.
From 190 euros a year, with unlimited products on every plan.
Online by card and the other methods offered in the checkout, in several currencies.
The receipt arrives right after payment. The invoice is issued once your designation has been approved.
Appointments last one year. You receive reminders 30, 7 and 1 day before the renewal date.
Yes. You appoint us, update your privacy notice or labels, and then end the old mandate. We guide you through the order to avoid gaps.
Some services offer a 7-day free trial. The checkout shows whether it is available for the one you choose.
A signed designation letter, a certificate with a QR code and a verification code, plus the text for your privacy notice or label.
On the verification page of gdprrepresentative.com, by entering the code or scanning the QR code on the certificate.
The company name, the service, the status and the validity dates. It does not show your internal data.
Yes. Anyone, including a marketplace or an authority, can check that the designation exists and is active.
The verification page shows it as expired, so renew before the date to keep the status active.
We receive the request, forward it to you promptly with a copy of the original, and keep a record of the exchange.
No question matches. Try another word or ask us directly.

Run the free check on your website, or write to us and a person will tell you which obligations you actually have, including the ones you don't.