Connected products
Organisations making connected products available in the Union.
Connected vehicles · Smart-home products · Medical and fitness devices · Industrial and agricultural machinery · Consumer electronics
DATA ACT LEGAL REPRESENTATIVE
Article 37 representation for organisations within the scope of the Data Act that make connected products available or offer services in the Union without an establishment in the European Union.
OSTRAI provides Data Act Legal Representative services for eligible international organisations.
Our service combines Article 37 scope and jurisdiction assessment, formal appointment, regulatory contact infrastructure, competent-authority communications, evidence coordination and continuing representation within a specialist European technology-regulation practice.
Not sure whether your products, services or Data Act role trigger Article 37? Start with the scope assessment.
ARTICLE 37 / CURRENT LAW
The Data Act applies since 12 September 2025.
If no: no Article 37 representative requirement.
Make connected products available in the Union
OROffer services in the Union?
If no: no Article 37(11) representative trigger.
If yes: Article 37(11) representative requirement does not arise on the basis of absence of EU establishment.
The representative may be designated in one of the Member States.
Not sure whether Article 37 applies to your organisation?
Request an Article 37 scope assessmentARTICLE 37 SCOPE
Article 37 applies to an entity falling within the scope of the Data Act that makes connected products available or offers services in the Union and is not established in the Union.
The Commission FAQ confirms that services include, but are not limited to, related services.
NON-EXHAUSTIVE EXAMPLES
Organisations making connected products available in the Union.
Connected vehicles · Smart-home products · Medical and fitness devices · Industrial and agricultural machinery · Consumer electronics
Providers of digital services linked to the operation of connected products where the relevant Data Act conditions are met.
Product operation · Related service data
Providers of data processing services, including cloud services and potentially IaaS, PaaS and SaaS where the Data Act definition and relevant conditions are satisfied.
Infrastructure · Platforms · Software
Other entities within the scope of the Regulation that offer services in the Union and meet Article 37(11).
Role · Activity · Entity
The representative analysis is role-specific, activity-specific and entity-specific.
Request an Article 37 scope assessmentCONNECTED PRODUCTS
A connected product is an item that obtains, generates or collects data concerning its use or environment and is able to communicate product data through an electronic communications service, physical connection or on-device access. Its primary function is not the storing, processing or transmission of data on behalf of a party other than the user.
Connected cars · Smart-home appliances · Consumer electronics · Industrial machinery · Medical devices · Agricultural machinery
Whether a particular product falls within Data Act scope depends on the statutory definitions and market-placement rules.
RELATED SERVICES
Commission guidance identifies two basic conditions for a digital service connected to the operation of a connected product to qualify as a related service:
Connectivity, power supply and ordinary aftermarket services are not automatically related services merely because they interact commercially with the connected product.
DATA PROCESSING SERVICES
The Data Act contains a separate framework for data processing services. Commission guidance explains that the statutory concept covers IaaS, PaaS and SaaS where the service displays the characteristics in the Data Act definition.
Whether Article 37 representation is required depends on the entity's Data Act role, the services offered in the Union and its EU establishment position.
EU REPRESENTATIVE
Article 37(11) requires the legal representative to be designated in one of the Member States.
Unlike some EU representative regimes, Article 37 does not require the representative to be located in a Member State where the relevant connected product or service is offered.
OSTRAI Limited is established in Cyprus.
An eligible organisation can therefore consider OSTRAI for appointment without Cyprus being its principal or a specific target market, subject to the applicable Article 37 conditions, OSTRAI's onboarding process and relevant national implementation requirements.
A REGULATORY ROLE
Article 37 gives the legal representative a direct role in the enforcement architecture.
Competent authorities may address the representative in addition to or instead of the represented entity.
On request, the representative must cooperate and comprehensively demonstrate the actions taken and arrangements put in place by the entity to comply with the Data Act.
Effective representation therefore depends on access to the organisation's compliance structure, evidence and responsible teams.
THE REGULATORY INTERFACE
DATA ACT LEGAL REPRESENTATIVE
Authorities may address OSTRAI in addition to or instead of the entity. Underlying compliance remains with the represented entity.
YOUR REPRESENTATION SERVICE
Written designation of OSTRAI Limited as legal representative within the agreed mandate.
A monitored OSTRAI electronic channel for communications connected with the representative mandate.
A defined OSTRAI contact coordinates the representative relationship and material regulatory escalations.
Receipt and coordination of communications directed to OSTRAI in its representative capacity.
Administrative cooperation with competent authorities within the scope of the representative mandate.
Coordination of requests requiring the entity to demonstrate actions and arrangements put in place for Data Act compliance.
Defined client contacts and procedures for urgent, material or time-sensitive regulatory matters.
Review of material changes affecting the represented entity, relevant products or services, EU establishment position and representative mandate.
Need to appoint a Data Act Legal Representative?
Discuss the mandate with OSTRAITHE EVIDENCE INTERFACE
Article 37(12) connects the authority's request with the organisation's compliance evidence.
Evidence coordination does not constitute independent certification or a full compliance audit under the standard mandate.
Need to understand what evidence the representative will require?
Discuss representation readinessREGULATORY COMMUNICATIONS
The represented entity remains responsible for the substantive accuracy of information, underlying compliance decisions and technical implementation.
Where a matter requires substantive Data Act advice or regulatory-response work outside the representative mandate, that work can be separately scoped.
MEMBER STATE COMPETENCE
Under Article 37(13), an entity subject to the legal-representative rule is considered to be under the competence of the Member State in which its representative is located.
OSTRAI Limited is established in Cyprus. This makes the representative appointment part of the entity's Data Act enforcement architecture.
CYPRUS
Under Article 37(13), an eligible entity appointing OSTRAI is considered to fall under Cyprus competence for Data Act purposes, subject to the allocation of powers under the Regulation.
OSTRAI monitors the Cyprus enforcement framework and relevant national implementation arrangements as they develop.
RESPONSIBILITY
Designation of a legal representative does not remove the represented entity's liability or prevent legal action against it.
The Commission's Data Act FAQ explains that the representative's liability is limited to its own obligations as representative under the Data Act.
Underlying Data Act obligations
DATA ACT LEGAL REPRESENTATIVE
Regulatory interface · Cooperation · Evidence coordination
ENFORCEMENT
Until an entity subject to Article 37(11) designates a legal representative, Article 37(13) places it under the competence of all Member States, where applicable, for application and enforcement of the Data Act.
A competent authority may exercise that competence, subject to the Regulation's restriction on another authority enforcing the same facts.
CONTROLLED ACCEPTANCE
Before accepting a Data Act Legal Representative mandate, OSTRAI reviews the entity, its Data Act role, relevant products and services, EU market or service activity, establishment position, regulatory history, compliance structure and operational readiness.
Where scope, classification, jurisdiction or underlying Data Act obligations require substantive legal analysis, that assessment is scoped separately before the representative mandate.
The regulatory position and readiness of the organisation determine whether the mandate can proceed.
Discuss whether OSTRAI can accept the mandateONBOARDING
OPERATIONAL READINESS
Article 37 representation depends on the entity being able to provide accurate and current information, instructions and evidence when competent-authority communications arise.
SCOPE
CONTRACTS & IMPLEMENTATION
The Commission has published non-binding Model Contractual Terms for data access and use and Standard Contractual Clauses for cloud computing contracts. These tools are voluntary and may be adapted to the parties' needs.
OSTRAI can separately support data-holder / user contracts, data-holder / data-recipient arrangements, user / data-recipient arrangements and voluntary data-sharing terms, as well as cloud switching and exit clauses, termination, security and business continuity, and liability provisions.
Data access & use
Cloud computing contracts
Voluntary tools. Context-specific implementation.
DATA PROCESSING SERVICES
Separately scoped support can address switching and exit, contract requirements, open interfaces, exportable data and digital assets, interoperability, switching / egress charges, and security and business continuity.
The applicable requirements depend on the service, including the relevant IaaS, PaaS and SaaS distinctions.
Explore Digital RegulationPERSONAL DATA
GDPR continues to apply to personal-data processing within the Data Act framework. The Data Act does not replace GDPR requirements.
Where Data Act rights or obligations involve personal data, the applicable GDPR legal basis, controller responsibilities and data-subject protections must also be considered.
See Privacy & DataINTEROPERABILITY
The Data Act includes interoperability requirements for data spaces and data processing services. European harmonised standards and, where applicable, common specifications can become relevant to implementation.
OSTRAI's broader standards and regulatory practice supports interpretation of those technical requirements as they develop.
See Standards & StandardisationDATA REGULATION PRACTICE
OSTRAI's Data Act Legal Representative service sits within a specialist European technology-regulation practice with substantive legal, data-governance, product and implementation expertise.
Our wider work can address connected products, data access and sharing, data-holder governance, contracts, cloud switching, interoperability, privacy, cybersecurity and market-facing regulatory obligations.
This means regulatory communications reaching the representative can be understood within their broader legal and operational context.
WHY OSTRAI
OSTRAI combines Article 37 representation infrastructure with regulatory judgement, evidence readiness, controlled acceptance and direct access to the team handling the mandate.
Representation structured around the actual legal-representative role.
Article 37 requires designation in one Member State and does not tie the representative's location to a Member State where the relevant product or service is offered.
Representation backed by substantive Data Act and technology-regulation capability.
A representation model designed around the Article 37 requirement to cooperate and demonstrate compliance arrangements.
Clear routes for competent-authority communications and evidence requests.
Ability to identify intersections with GDPR, cybersecurity, connected-product regulation, cloud regulation and standards.
QUESTIONS & ANSWERS
Article 37(11) requires an entity within the scope of the Data Act that makes connected products available or offers services in the Union, and is not established in the Union, to designate a legal representative in one of the Member States. The role, activity and establishment position must be assessed together.
No. The entity must fall within the scope of the Data Act, make connected products available or offer services in the Union, and have no establishment in the Union. Location outside the EU alone does not establish a representative requirement.
Article 37(11) requires designation in one of the Member States. It does not state that the representative must be located in a Member State where the relevant product or service is offered.
No. Article 37(11) requires an EU legal representative in one of the Member States but does not tie the representative's location to the Member State in which the connected product or service is offered. OSTRAI is established in Cyprus and can be considered for appointment by an eligible organisation subject to Article 37 and OSTRAI's onboarding process.
Potentially, yes. Where the entity falls within the Data Act, makes connected products available in the Union and is not established there, Article 37(11) requires a legal representative. The particular product, activity and entity must be assessed.
Potentially, yes. Data processing services are within the Data Act framework. Commission guidance explains that IaaS, PaaS and SaaS can meet the statutory definition where the relevant characteristics are present. Article 37 must then be assessed against the entity's establishment and EU service offering; not every software service meets the definition.
Under Article 37(12), competent authorities may address the representative in addition to or instead of the entity. The representative must cooperate and comprehensively demonstrate, on request, the actions and arrangements the entity has put in place for Data Act compliance. The mandate therefore involves an authority interface, communications and evidence coordination.
Article 37 preserves the represented entity's liability and legal action against it. The Commission's non-binding Data Act FAQ additionally explains that the representative's liability is limited to its own obligations as representative. Appointment does not transfer the entity's underlying compliance responsibilities.
Until it designates a representative, Article 37(13) places the entity under the competence of all Member States, where applicable, for Data Act application and enforcement. A competent authority may exercise competence subject to the Regulation's restriction on another authority enforcing the same facts.
GDPR continues to apply to personal-data processing. The Data Act does not replace it. Where data access or sharing involves personal data, the applicable legal basis, controller responsibilities and data-subject protections must also be considered.
Still unsure whether Article 37 applies?
Discuss your position with OSTRAIDATA ACT LEGAL REPRESENTATIVE
OSTRAI supports eligible organisations without an establishment in the Union from Article 37 scope and jurisdiction assessment through onboarding, authority interface, evidence coordination and continuing Data Act representation.