DATA ACT LEGAL REPRESENTATIVE

Data Act Legal Representative
in the European Union

Article 37 representation for organisations within the scope of the Data Act that make connected products available or offer services in the Union without an establishment in the European Union.

DATA ACT
ARTICLE
37EU LEGAL REPRESENTATION

OSTRAI provides Data Act Legal Representative services for eligible international organisations.

Our service combines Article 37 scope and jurisdiction assessment, formal appointment, regulatory contact infrastructure, competent-authority communications, evidence coordination and continuing representation within a specialist European technology-regulation practice.

Not sure whether your products, services or Data Act role trigger Article 37? Start with the scope assessment.

ARTICLE 37 / CURRENT LAW

The route to
an EU representative.

The Data Act applies since 12 September 2025.

  1. Does the entity fall within the scope of the Data Act?

    If no: no Article 37 representative requirement.

    If yes
  2. Does the entity:

    Make connected products available in the Union

    OR

    Offer services in the Union?

    If no: no Article 37(11) representative trigger.

    If yes
  3. Is the entity established in the Union?

    If yes: Article 37(11) representative requirement does not arise on the basis of absence of EU establishment.

    If no

EU Legal Representative required

The representative may be designated in one of the Member States.

Not sure whether Article 37 applies to your organisation?

Request an Article 37 scope assessment

ARTICLE 37 SCOPE

The representative rule
is broader than IoT alone.

Article 37 applies to an entity falling within the scope of the Data Act that makes connected products available or offers services in the Union and is not established in the Union.

The Commission FAQ confirms that services include, but are not limited to, related services.

NON-EXHAUSTIVE EXAMPLES

Connected products

Organisations making connected products available in the Union.

Connected vehicles · Smart-home products · Medical and fitness devices · Industrial and agricultural machinery · Consumer electronics

Related services

Providers of digital services linked to the operation of connected products where the relevant Data Act conditions are met.

Product operation · Related service data

Data processing services

Providers of data processing services, including cloud services and potentially IaaS, PaaS and SaaS where the Data Act definition and relevant conditions are satisfied.

Infrastructure · Platforms · Software

Other in-scope services

Other entities within the scope of the Regulation that offer services in the Union and meet Article 37(11).

Role · Activity · Entity

The representative analysis is role-specific, activity-specific and entity-specific.

Request an Article 37 scope assessment

CONNECTED PRODUCTS

What counts as
a connected product?

A connected product is an item that obtains, generates or collects data concerning its use or environment and is able to communicate product data through an electronic communications service, physical connection or on-device access. Its primary function is not the storing, processing or transmission of data on behalf of a party other than the user.

Connected cars · Smart-home appliances · Consumer electronics · Industrial machinery · Medical devices · Agricultural machinery

Whether a particular product falls within Data Act scope depends on the statutory definitions and market-placement rules.

ProductUse / performance / environment data

RELATED SERVICES

Not every digital service linked to a product is a related service.

Commission guidance identifies two basic conditions for a digital service connected to the operation of a connected product to qualify as a related service:

Connectivity, power supply and ordinary aftermarket services are not automatically related services merely because they interact commercially with the connected product.

DATA PROCESSING SERVICES

Cloud, PaaS and SaaS
can also fall within
the Data Act.

The Data Act contains a separate framework for data processing services. Commission guidance explains that the statutory concept covers IaaS, PaaS and SaaS where the service displays the characteristics in the Data Act definition.

Whether Article 37 representation is required depends on the entity's Data Act role, the services offered in the Union and its EU establishment position.

IaaSPaaSSaaS

EU REPRESENTATIVE

One Member State
is sufficient for the
Article 37 appointment.

Article 37(11) requires the legal representative to be designated in one of the Member States.

Unlike some EU representative regimes, Article 37 does not require the representative to be located in a Member State where the relevant connected product or service is offered.

OSTRAI Limited is established in Cyprus.

An eligible organisation can therefore consider OSTRAI for appointment without Cyprus being its principal or a specific target market, subject to the applicable Article 37 conditions, OSTRAI's onboarding process and relevant national implementation requirements.

A REGULATORY ROLE

The representative must be able to demonstrate the compliance structure.

Article 37 gives the legal representative a direct role in the enforcement architecture.

Competent authorities may address the representative in addition to or instead of the represented entity.

On request, the representative must cooperate and comprehensively demonstrate the actions taken and arrangements put in place by the entity to comply with the Data Act.

Effective representation therefore depends on access to the organisation's compliance structure, evidence and responsible teams.

THE REGULATORY INTERFACE

Authority, representative
and organisation.

Member State
competent authorities

Including Data Coordinator where applicable

DATA ACT LEGAL REPRESENTATIVE

OSTRAI

  • Regulatory contact
  • Authority communications
  • Evidence interface
  • Escalation
  • Mandate coordination

Represented entity

  • Product / service compliance
  • Data-access arrangements
  • Contracts
  • Technical implementation
  • Compliance evidence

Authorities may address OSTRAI in addition to or instead of the entity. Underlying compliance remains with the represented entity.

YOUR REPRESENTATION SERVICE

A functioning Article 37
regulatory interface.

Formal Article 37 appointment

Written designation of OSTRAI Limited as legal representative within the agreed mandate.

Designated regulatory channel

A monitored OSTRAI electronic channel for communications connected with the representative mandate.

Designated lead

A defined OSTRAI contact coordinates the representative relationship and material regulatory escalations.

Competent-authority communications

Receipt and coordination of communications directed to OSTRAI in its representative capacity.

Regulatory cooperation

Administrative cooperation with competent authorities within the scope of the representative mandate.

Evidence request coordination

Coordination of requests requiring the entity to demonstrate actions and arrangements put in place for Data Act compliance.

Escalation protocol

Defined client contacts and procedures for urgent, material or time-sensitive regulatory matters.

Mandate maintenance

Review of material changes affecting the represented entity, relevant products or services, EU establishment position and representative mandate.

Need to appoint a Data Act Legal Representative?

Discuss the mandate with OSTRAI

THE EVIDENCE INTERFACE

From the request
to the arrangements
behind it.

Article 37(12) connects the authority's request with the organisation's compliance evidence.

Evidence coordination does not constitute independent certification or a full compliance audit under the standard mandate.

  1. Competent authority request
  2. OSTRAI
  3. Identify relevant obligation
  4. Request client evidence
  5. Coordinate product / legal / data / technical teams
  6. Demonstrate actions & arrangements
  7. Regulatory follow-up

Need to understand what evidence the representative will require?

Discuss representation readiness

REGULATORY COMMUNICATIONS

From authority contact
to coordinated response.

  1. Receive
  2. Log
  3. Triage authority / issue / deadline
  4. Escalate
  5. Obtain information and instructions
  6. Coordinate
  7. Relay / facilitate
  8. Record

The represented entity remains responsible for the substantive accuracy of information, underlying compliance decisions and technical implementation.

Where a matter requires substantive Data Act advice or regulatory-response work outside the representative mandate, that work can be separately scoped.

MEMBER STATE COMPETENCE

Appointment establishes the Member State interface.

Under Article 37(13), an entity subject to the legal-representative rule is considered to be under the competence of the Member State in which its representative is located.

OSTRAI Limited is established in Cyprus. This makes the representative appointment part of the entity's Data Act enforcement architecture.

CYPRUS

A European appointment through a Cyprus-established representative.

Under Article 37(13), an eligible entity appointing OSTRAI is considered to fall under Cyprus competence for Data Act purposes, subject to the allocation of powers under the Regulation.

OSTRAI monitors the Cyprus enforcement framework and relevant national implementation arrangements as they develop.

RESPONSIBILITY

Representation does not transfer Data Act compliance.

Designation of a legal representative does not remove the represented entity's liability or prevent legal action against it.

The Commission's Data Act FAQ explains that the representative's liability is limited to its own obligations as representative under the Data Act.

Represented entity

Underlying Data Act obligations

  • Product / service compliance
  • Data sharing
  • Contracts
  • Cloud / switching obligations
  • Technical implementation

OSTRAI

DATA ACT LEGAL REPRESENTATIVE

Regulatory interface · Cooperation · Evidence coordination

ENFORCEMENT

What happens if
no representative
is appointed?

Until an entity subject to Article 37(11) designates a legal representative, Article 37(13) places it under the competence of all Member States, where applicable, for application and enforcement of the Data Act.

A competent authority may exercise that competence, subject to the Regulation's restriction on another authority enforcing the same facts.

CONTROLLED ACCEPTANCE

We assess the mandate before accepting the role.

Before accepting a Data Act Legal Representative mandate, OSTRAI reviews the entity, its Data Act role, relevant products and services, EU market or service activity, establishment position, regulatory history, compliance structure and operational readiness.

Where scope, classification, jurisdiction or underlying Data Act obligations require substantive legal analysis, that assessment is scoped separately before the representative mandate.

The regulatory position and readiness of the organisation determine whether the mandate can proceed.

Discuss whether OSTRAI can accept the mandate

ONBOARDING

The information behind
an effective appointment.

Entity
Correct legal entity to be represented
EU establishment
Whether the relevant entity has an establishment in the Union
Data Act role
Manufacturer · Provider · Data holder · Data processing service provider · Other relevant role
Connected products
Products made available in the Union where relevant
Services
Related services · Data processing services · Other in-scope services
Applicable Data Act framework
Which Data Act obligations are relevant to the organisation
Evidence structure
Where compliance evidence is held and who owns it internally
Regulatory history
Existing complaints, authority communications or enforcement matters
Regulatory contacts
Primary · Legal · Product · Data · Technical
Escalation
Contacts and procedures for material or time-sensitive regulatory communications
GDPR / personal data
Identification of relevant personal-data intersections where applicable
Start Data Act representative onboarding

OPERATIONAL READINESS

A representative needs access to the organisation behind the mandate.

Article 37 representation depends on the entity being able to provide accurate and current information, instructions and evidence when competent-authority communications arise.

  • Primary regulatory contact
  • Internal legal contact
  • Data governance contact
  • Product / engineering contact
  • Privacy / DPO contact where relevant
  • Cloud / infrastructure contact where relevant
  • Emergency / escalation contact
  • External counsel where relevant

SCOPE

Representation and
Data Act implementation
are distinct.

Standard representative mandate

  • Formal Article 37 appointment
  • Designated regulatory channel
  • Authority communications
  • Routine regulatory cooperation
  • Evidence-request coordination
  • Escalation
  • Mandate maintenance

Separately scoped support

  • Article 37 applicability assessment
  • Data Act role mapping
  • Connected-product analysis
  • Related-service analysis
  • Data-holder / user / third-party mapping
  • Article 3 transparency obligations
  • Articles 4 and 5 data-access and sharing arrangements
  • Trade-secret protections
  • Safety and security restrictions
  • B2B data-sharing terms
  • Data-processing service / cloud switching obligations
  • IaaS / PaaS / SaaS analysis
  • Article 32 third-country government access
  • Interoperability requirements
  • Data spaces
  • Smart-contract requirements
  • Public-sector data requests
  • GDPR / Data Act interaction
  • Regulatory-response work
  • Contract review and implementation

CONTRACTS & IMPLEMENTATION

Data Act compliance
often reaches the contract.

The Commission has published non-binding Model Contractual Terms for data access and use and Standard Contractual Clauses for cloud computing contracts. These tools are voluntary and may be adapted to the parties' needs.

OSTRAI can separately support data-holder / user contracts, data-holder / data-recipient arrangements, user / data-recipient arrangements and voluntary data-sharing terms, as well as cloud switching and exit clauses, termination, security and business continuity, and liability provisions.

MCTs

Data access & use

SCCs

Cloud computing contracts

Voluntary tools. Context-specific implementation.

DATA PROCESSING SERVICES

Representation can sit alongside wider cloud compliance support.

Separately scoped support can address switching and exit, contract requirements, open interfaces, exportable data and digital assets, interoperability, switching / egress charges, and security and business continuity.

The applicable requirements depend on the service, including the relevant IaaS, PaaS and SaaS distinctions.

Explore Digital Regulation

PERSONAL DATA

The Data Act and GDPR can apply at the same time.

GDPR continues to apply to personal-data processing within the Data Act framework. The Data Act does not replace GDPR requirements.

Where Data Act rights or obligations involve personal data, the applicable GDPR legal basis, controller responsibilities and data-subject protections must also be considered.

See Privacy & Data

INTEROPERABILITY

The Data Act also develops through standards and technical specifications.

The Data Act includes interoperability requirements for data spaces and data processing services. European harmonised standards and, where applicable, common specifications can become relevant to implementation.

OSTRAI's broader standards and regulatory practice supports interpretation of those technical requirements as they develop.

See Standards & Standardisation

DATA REGULATION PRACTICE

Representation backed by substantive Data Act capability.

OSTRAI's Data Act Legal Representative service sits within a specialist European technology-regulation practice with substantive legal, data-governance, product and implementation expertise.

Our wider work can address connected products, data access and sharing, data-holder governance, contracts, cloud switching, interoperability, privacy, cybersecurity and market-facing regulatory obligations.

This means regulatory communications reaching the representative can be understood within their broader legal and operational context.

WHY OSTRAI

Why OSTRAI for
Data Act representation

OSTRAI combines Article 37 representation infrastructure with regulatory judgement, evidence readiness, controlled acceptance and direct access to the team handling the mandate.

Article 37 focus

Representation structured around the actual legal-representative role.

EU appointment flexibility

Article 37 requires designation in one Member State and does not tie the representative's location to a Member State where the relevant product or service is offered.

Regulatory depth

Representation backed by substantive Data Act and technology-regulation capability.

Evidence readiness

A representation model designed around the Article 37 requirement to cooperate and demonstrate compliance arrangements.

Defined escalation

Clear routes for competent-authority communications and evidence requests.

Cross-regulatory view

Ability to identify intersections with GDPR, cybersecurity, connected-product regulation, cloud regulation and standards.

QUESTIONS & ANSWERS

Before
appointment.

Article 37(11) requires an entity within the scope of the Data Act that makes connected products available or offers services in the Union, and is not established in the Union, to designate a legal representative in one of the Member States. The role, activity and establishment position must be assessed together.

No. The entity must fall within the scope of the Data Act, make connected products available or offer services in the Union, and have no establishment in the Union. Location outside the EU alone does not establish a representative requirement.

Article 37(11) requires designation in one of the Member States. It does not state that the representative must be located in a Member State where the relevant product or service is offered.

No. Article 37(11) requires an EU legal representative in one of the Member States but does not tie the representative's location to the Member State in which the connected product or service is offered. OSTRAI is established in Cyprus and can be considered for appointment by an eligible organisation subject to Article 37 and OSTRAI's onboarding process.

Potentially, yes. Where the entity falls within the Data Act, makes connected products available in the Union and is not established there, Article 37(11) requires a legal representative. The particular product, activity and entity must be assessed.

Potentially, yes. Data processing services are within the Data Act framework. Commission guidance explains that IaaS, PaaS and SaaS can meet the statutory definition where the relevant characteristics are present. Article 37 must then be assessed against the entity's establishment and EU service offering; not every software service meets the definition.

Under Article 37(12), competent authorities may address the representative in addition to or instead of the entity. The representative must cooperate and comprehensively demonstrate, on request, the actions and arrangements the entity has put in place for Data Act compliance. The mandate therefore involves an authority interface, communications and evidence coordination.

Article 37 preserves the represented entity's liability and legal action against it. The Commission's non-binding Data Act FAQ additionally explains that the representative's liability is limited to its own obligations as representative. Appointment does not transfer the entity's underlying compliance responsibilities.

Until it designates a representative, Article 37(13) places the entity under the competence of all Member States, where applicable, for Data Act application and enforcement. A competent authority may exercise competence subject to the Regulation's restriction on another authority enforcing the same facts.

GDPR continues to apply to personal-data processing. The Data Act does not replace it. Where data access or sharing involves personal data, the applicable legal basis, controller responsibilities and data-subject protections must also be considered.

Still unsure whether Article 37 applies?

Discuss your position with OSTRAI

DATA ACT LEGAL REPRESENTATIVE

Put the right Article 37
representation structure
in place.

OSTRAI supports eligible organisations without an establishment in the Union from Article 37 scope and jurisdiction assessment through onboarding, authority interface, evidence coordination and continuing Data Act representation.