If your US company manufactures connected products that are sold or distributed in the European Union, and your company has no establishment — no subsidiary, branch office, or other registered legal presence — in the EU, the Data Act imposes a specific obligation: you must designate an EU legal representative before your products are placed on the EU market. This requirement is found in Article 5 of Regulation (EU) 2023/2854, and it is not optional or advisory. It is a hard legal requirement with enforcement consequences.
This page explains who must designate an EU legal representative under the Data Act, what that representative does, how to choose one, what liability they face, how this obligation differs from the similar but distinct requirement under the GDPR, and the practical steps US manufacturers should take to satisfy this requirement.
Who Must Designate an EU Legal Representative
The legal representative obligation under Article 5 of the Data Act applies to manufacturers of connected products who have no establishment in the EU but who place connected products on the EU market. An “establishment” in EU regulatory terminology generally means a stable arrangement for carrying on economic activity in the EU — a subsidiary company, a branch office, or a permanent place of business. A US company that sells products through independent EU distributors, without maintaining any EU entity of its own, typically does not have an EU establishment for these purposes.
The obligation also applies to providers of related services who have no EU establishment but whose services are connected to connected products placed on the EU market. A US SaaS company that operates a cloud platform used by EU customers to manage their connected devices — and has no EU office, subsidiary, or other legal presence — must designate a representative just as the hardware manufacturer must.
Companies that do have EU establishments — typically companies that operate through a European subsidiary — are generally not required to designate a separate representative, because the EU establishment itself serves as the point of contact and legal presence. However, the analysis requires examining what the EU entity actually does: if the European subsidiary is purely a sales entity with no operational authority over the connected product or its data infrastructure, there may be questions about whether the parent company has obligations beyond the subsidiary’s scope. When in doubt, it is worth consulting EU-qualified legal counsel to assess the corporate structure carefully.
What the EU Legal Representative Does
The EU legal representative under the Data Act serves as the point of contact between the non-EU manufacturer and EU national authorities. The representative must be established in one of the EU member states where the connected product is made available. In practical terms, this means the representative must have a genuine presence in the EU — not just a registered address — and must be capable of receiving and responding to communications from national market surveillance authorities, data protection authorities, and other enforcement bodies.
The representative’s core function is to act as the manufacturer’s proxy for Data Act compliance purposes. National authorities that need to contact the manufacturer about compliance questions, user complaints, or enforcement investigations can reach the representative rather than attempting to serve notices or commence proceedings against a foreign entity. The representative is authorized to take the steps necessary to bring the manufacturer into compliance, and can be held directly responsible by the authorities if compliance obligations are not met.
The representative is required to maintain a copy of the declaration of conformity — a document the manufacturer must issue confirming that the connected product meets Data Act requirements — and must make this declaration available to authorities on request. The representative must also maintain sufficient information about the manufacturer’s products and data practices to respond meaningfully to authority inquiries. This is not a passive letterbox function; it requires a genuine working relationship between the manufacturer and the representative, with the representative having access to current information about the product and its data systems.
In addition to serving as the authority contact point, the representative plays an important role in the Data Act’s user access rights framework. When EU users exercise their right to access data generated by connected products, the manufacturer must be able to respond. If the manufacturer cannot be directly reached by EU users or authorities, the representative becomes the practical conduit for these interactions. US manufacturers should ensure that their representatives are operationally equipped to handle data access requests and escalate them appropriately to the manufacturer’s technical and legal teams.
Liability Implications for the EU Legal Representative
The EU legal representative’s liability exposure under the Data Act is a critical issue for both the representative and the manufacturer. The regulation provides that the representative can be held responsible by national authorities for the manufacturer’s compliance with the Data Act’s obligations. This means that if a manufacturer fails to meet its Chapter II obligations — for example, by consistently failing to provide users with access to their data, or by placing products on the market without the required declaration of conformity — the authorities can pursue enforcement action against the representative as well as, or instead of, the manufacturer.
This liability exposure means that professional EU legal representative services — law firms, compliance service companies, and similar professional service providers — take their engagement terms seriously. They will require detailed contractual protections from the manufacturer, including indemnification for liabilities arising from the manufacturer’s non-compliance, accurate and complete disclosure of product and data practices, prompt notification of any changes to the product or its data systems, and cooperation with authority inquiries. A representative that discovers it has been misled about the manufacturer’s compliance posture has grounds to terminate the engagement.
For the manufacturer, the liability structure means that appointing a representative does not eliminate the manufacturer’s own compliance obligations. The representative is a compliance conduit and a local point of contact, not an insulation layer that absorbs the manufacturer’s legal risk. If a manufacturer remains non-compliant with the Data Act, authorities can pursue both the manufacturer and the representative, and can require the product to be withdrawn from the EU market. The legal representative system is designed to make enforcement more practical, not to give manufacturers a liability escape route.
How to Choose an EU Legal Representative
Selecting the right EU legal representative requires attention to several factors. First, the representative must be established in an EU member state where your products are placed on the market. If your products are sold across multiple EU member states — which for most manufacturers means throughout the EU single market — a representative established in any EU member state can serve for the whole EU, as long as the representative is genuinely accessible to authorities in any member state that might seek to make contact.
Second, the representative must have the practical capacity to perform the role. This means having adequate staff to receive and process authority inquiries, having legal or regulatory expertise relevant to the Data Act, having a working relationship with the manufacturer’s compliance team, and having the organizational stability to serve as a reliable long-term contact. A fly-by-night registered address service is not appropriate for this role. Given the liability exposure the representative takes on, credible representatives will themselves be selective about the engagements they accept.
Third, consider the representative’s language capabilities and regulatory network. EU market surveillance authorities communicate in their national languages, and enforcement actions may be initiated in any member state where the product is sold. A representative based in Germany and operating primarily in German may not be optimally positioned to handle matters arising in France, Spain, or Poland. Larger compliance service providers with multi-country EU presence and multilingual capability are better suited to serve manufacturers with broad EU market exposure.
Fourth, the contractual terms of the representative engagement must be carefully negotiated. The agreement should define precisely what services the representative will and will not provide, how authority inquiries are handled and escalated to the manufacturer, what information the manufacturer must keep the representative current on, what the indemnification and liability allocation looks like, how the engagement terminates and what happens to the manufacturer’s compliance posture if it does, and what confidentiality obligations apply to both parties. This is a serious commercial contract, not a simple service order.
Many US manufacturers that already operate in the EU under GDPR Article 27 representative arrangements will find that some of the same service providers who offer GDPR representation also offer Data Act representation, or are developing that capacity. This can create efficiencies, but it is important not to assume that a GDPR representative automatically satisfies the Data Act requirement. The two roles have different legal bases, different functional requirements, and may require different contractual terms.
How the Data Act Representative Requirement Differs from GDPR Article 27
US businesses that already comply with the GDPR will be familiar with the Article 27 representative requirement: non-EU controllers and processors who process personal data of EU individuals and are not established in the EU must designate an EU representative in writing. The GDPR representative must be established in a member state where the data subjects are located and must be available to supervisory authorities and data subjects for inquiries about processing.
The Data Act legal representative requirement has important similarities to GDPR Article 27 but is a distinct obligation with its own scope, legal basis, and functional requirements. The most important distinction is regulatory scope: the GDPR representative exists to facilitate data protection law enforcement and data subject rights, while the Data Act representative exists to facilitate market surveillance enforcement and user data access rights under the Data Act. These are different regulatory regimes with different enforcement authorities.
In practice, this means a US company needs separate representative designations for each regulation. The same individual or organization can serve as both GDPR Article 27 representative and Data Act Article 5 representative, but only if there is a clear contractual basis for each role and each role’s specific obligations are addressed. A GDPR representative that has not agreed to serve as a Data Act representative does not automatically serve in that capacity.
The triggering conditions also differ. GDPR Article 27 is triggered by the processing of personal data of EU individuals. The Data Act representative requirement is triggered by placing connected products on the EU market. A US manufacturer that sells connected products generating only non-personal data (for example, a purely industrial sensor monitoring anonymous equipment performance with no linkage to identifiable individuals) would need a Data Act representative but might not need a GDPR representative. A US software company that processes personal data in the EU without being connected to any connected products needs a GDPR representative but no Data Act representative. Many US manufacturers need both.
The enforcement authority contact is also different. GDPR representatives field inquiries from EU data protection authorities — bodies like Germany’s BfDI, France’s CNIL, or Ireland’s DPC. Data Act representatives field inquiries from national market surveillance authorities, which are different agencies with different mandates. In some member states these may be the same agency; in others they will be separate bodies. Representatives need to have the right regulatory contacts and expertise for each role.
The Declaration of Conformity
The EU legal representative’s documentation obligations under the Data Act include maintaining the manufacturer’s declaration of conformity. This document, which the manufacturer must draw up, confirms that the connected product meets the requirements of the Data Act and any other applicable EU regulations. The declaration must contain specific information: the manufacturer’s name and contact details, the representative’s name and contact details, identification of the connected product, a statement of conformity, and the date and place of issue.
US manufacturers need to understand that the declaration of conformity is a legal document, not a marketing statement. Issuing a false or inaccurate declaration has legal consequences. The declaration should be reviewed and approved by legal counsel, should be updated whenever the product is modified in a way that affects its Data Act compliance status, and should be maintained in the representative’s records. National authorities can request to see it at any time.
Practical Steps for US Manufacturers
US manufacturers that are currently selling connected products in the EU without an EU establishment should take the following steps to address the legal representative requirement.
Begin by confirming whether your company has any EU establishment that could satisfy the requirement. If you have a European subsidiary that is actively involved in placing products on the market and has operational knowledge of the product and its data systems, that subsidiary may function as the relevant establishment. If your European entity is purely a sales office with no authority over product or data matters, it may not satisfy the requirement, and you should confirm this with EU-qualified counsel.
If no adequate EU establishment exists, identify candidate representative service providers. Look for providers with EU-wide coverage, demonstrated experience with product compliance regulations (not just GDPR), multilingual capability, and financial stability. Request their standard engagement terms and assess whether those terms are workable given your business’s size, product complexity, and compliance posture.
Prepare the information package that the representative will need. This includes a full description of each connected product sold in the EU, the data each product generates, how that data is communicated and where it is stored, what technical mechanisms currently exist for users to access their data, and your current contract terms with EU distributors and customers. The representative cannot perform their role without this information, and gathering it also forces your organization to conduct the compliance assessment that the Data Act requires.
Draft and execute a representative agreement that clearly allocates responsibilities and liabilities, and simultaneously draft the declaration of conformity for each relevant product. Notify your EU distributors and customers of the representative’s contact information. And critically, do not treat the appointment of a representative as the completion of compliance — it is one element of a broader compliance program that also requires product design changes, data access mechanisms, and contract revisions.
