For a non-EU provider entering the European digital market, the Digital Services Act can create a regulatory presence requirement even where the provider has no establishment in the European Union.
Article 13 of the Digital Services Act requires providers of intermediary services that do not have an establishment in the Union, but offer services in the Union, to designate in writing a legal or natural person to act as their legal representative. The representative must be established or reside in a Member State in which the provider offers its services.
The appointment is sometimes described as though it were simply a requirement to maintain a regulatory contact address in Europe. In practice, the role is more significant: the legal representative can be addressed, in addition to or instead of the provider, by Member State competent authorities, the European Commission and the European Board for Digital Services in relation to decisions issued under the DSA.
The representative must also be given the powers and resources necessary to cooperate efficiently and promptly with those authorities. Article 13 also expressly provides that it must be possible for the representative to be held liable for non-compliance with DSA obligations, without prejudice to the liability of the provider itself.
For non-EU providers, the first question should therefore not simply be:
“Who can act as our representative?”
It should be:
Does Article 13 apply to us, what exactly are we appointing the representative to do, and how will that mandate operate in practice?
Who needs a DSA legal representative?
Article 13 applies where two threshold conditions are met:
-
the provider does not have an establishment in the European Union; and
-
the provider offers intermediary services in the Union.
Both elements require analysis. The obligation does not apply simply because an organisation has a website accessible from Europe. Nor should a company assume that it falls outside Article 13 merely because its headquarters are outside the EU.
Before appointment, the provider should identify:
- the legal entity providing the relevant service;
- whether that service is an intermediary service under the DSA;
- whether the service is offered in the Union;
- whether the provider has an EU establishment for DSA purposes; and
- whether any EU subsidiary, branch, personnel presence or group arrangement affects that establishment analysis.
The provider should also determine which Member States its services are offered in, because the representative must be appointed in a Member State where the provider offers its services.
Which intermediary services can fall within Article 13?
The DSA applies to providers of intermediary services. These include the principal intermediary categories of:
- mere conduit;
- caching; and
- hosting services.
The wider DSA framework also applies specific obligations to categories within or connected to those services, including online platforms and online search engines.
Depending on the service model, this can include businesses such as:
- internet infrastructure and access services;
- hosting and cloud-related services;
- online marketplaces;
- social-media platforms;
- app stores;
- collaborative platforms;
- search services; and
- other digital services falling within the DSA intermediary-service framework.
Classification matters because the DSA does not impose identical obligations on every service. A provider should therefore map each service separately rather than assume that an entire corporate group or technology portfolio falls into one DSA category.
What Article 13 actually requires
The designation must be made in writing. The provider must mandate the representative so that competent authorities, the European Commission and the European Board for Digital Services can address the representative, in addition to or instead of the provider, on matters concerning the receipt, compliance with and enforcement of DSA decisions.
The provider must give the representative:
- the necessary powers; and
- sufficient resources
to enable effective and timely cooperation with the relevant authorities and compliance with their decisions.
The provider must also notify the representative’s:
- name;
- postal address;
- email address; and
- telephone number
to the Digital Services Coordinator in the Member State where the representative is established or resides.
That information must also remain publicly available, easily accessible, accurate and up to date.
What does the representative do in practice?
The practical mandate should create a reliable regulatory interface between the provider and the European authorities capable of addressing the representative under the DSA.
A representative arrangement will typically need processes for:
- receiving regulatory communications;
- receiving decisions and orders addressed to the representative;
- forwarding communications promptly to the provider;
- transmitting responses or information where appropriately authorised;
- maintaining a monitored regulatory communication channel;
- escalating urgent matters internally;
- maintaining the information necessary to perform the mandate;
- coordinating routine administrative liaison with the relevant authorities; and
- maintaining or updating required representative information.
The provider should have identified internal legal, regulatory and operational contacts capable of responding quickly when a regulatory communication is received. A representative cannot cooperate effectively if the provider does not supply information, instructions and resources within the relevant regulatory timeframe.
The representative does not replace the provider
Appointment of a legal representative does not transfer the provider’s substantive DSA obligations to the representative. The provider remains responsible for the obligations applicable to its services.
Depending on the relevant service and DSA classification, those obligations may include matters such as:
- notice-and-action mechanisms;
- statements of reasons;
- content-moderation governance;
- transparency reporting;
- internal complaint handling;
- trader traceability;
- advertising requirements;
- recommender-system obligations;
- protection of minors;
- active-recipient calculations;
- risk assessments;
- audits; and
- other operational DSA requirements.
The representative can form part of the regulatory interface. It is not automatically the operator of the provider’s DSA compliance programme.
Representation creates a regulatory interface. It does not outsource the provider’s substantive DSA responsibility.
Legal representative and DSA contact points are not the same thing
The DSA contains several different contact and representation concepts that should not be conflated.
Article 11 requires providers of intermediary services to designate a single point of contact enabling direct electronic communication with Member State authorities, the European Commission and the Board.
Article 12 separately requires a point of contact through which recipients of the service can communicate with the provider.
Article 13 concerns the legal representative of a provider that is not established in the Union but offers services there.
These functions may interact operationally. But appointment as an Article 13 legal representative does not, by itself, automatically appoint that person to perform the provider’s Article 11 authority-contact function or Article 12 recipient-contact function. If a provider wants the same service provider to perform several functions, the scope should be clearly identified and separately operationalised.
Why the representative’s Member State matters
The location of the legal representative has regulatory consequences. Under Article 56 of the DSA, where a provider has no establishment in the Union, supervisory and enforcement competence is connected to the Member State where its legal representative resides or is established, subject to the allocation of powers to the European Commission, particularly in relation to Very Large Online Platforms and Very Large Online Search Engines.
The choice of representative is therefore not simply an administrative question. It affects the provider’s regulatory interface in the Union.
If a provider that is required to appoint a legal representative fails to do so, Article 56 provides for significantly broader enforcement competence across Member States and, where applicable, the Commission. The provider should therefore understand the supervisory consequences of the Member State in which its representative is established before making the appointment.
Article 13 includes liability exposure
Article 13(3) provides that it must be possible for the designated legal representative to be held liable for non-compliance with DSA obligations, without removing liability from the provider itself. This creates an unusual regulatory position because the representative may face exposure connected with the provider’s non-compliance even though many of the underlying operational obligations remain within the provider’s own systems and control.
For that reason, information flow, escalation, cooperation and mandate design are not merely administrative matters. A representative accepting the role needs sufficient access to the information and resources necessary to perform the mandate and manage the regulatory position created by the appointment.
Regulatory orders require a functioning escalation process
The DSA gives authorities powers that can result in orders and requests being addressed to providers.
Examples include:
- Article 9 orders to act against illegal content; and
- Article 10 orders to provide information.
Where a representative receives such a communication, the provider needs an internal process capable of responding within the applicable regulatory timeframe.
The representative may receive and relay the communication, but the provider remains responsible for the substantive legal, technical and operational decisions required to comply with an order. The mandate should therefore establish a reliable escalation route between the representative and the provider’s internal legal, regulatory and operational teams, with contacts capable of supplying instructions, supporting materials and operational action within the relevant regulatory timeframe.
Some obligations remain firmly with the provider
The distinction becomes especially clear with operational obligations such as Article 18. Article 18 requires hosting service providers, in specified circumstances, to notify relevant law-enforcement or judicial authorities where they become aware of information giving rise to a suspicion of a serious criminal offence involving a threat to the life or safety of persons.
The determination whether such a notification is required belongs to the provider. An Article 13 representative does not automatically become the organisation responsible for detecting relevant content, investigating user activity or making the underlying operational assessment.
Similar distinctions apply across other DSA obligations. The provider needs to understand which obligations fall on it directly and which functions have actually been included within the representative’s mandate.
Article 13 representation through Cyprus
Cyprus adopted its national DSA implementation framework in 2025. The Cyprus legislation designates the Cyprus Digital Services Coordinator and allocates responsibilities among the national competent authorities responsible for implementation of different DSA provisions.
Where a non-EU provider designates a legal representative established in Cyprus, that appointment sits within both:
- the directly applicable EU DSA framework; and
- the national implementation structure established in Cyprus.
For OSTRAI’s Article 13 mandates, this requires the appointment to be operationalised through the applicable Cyprus regulatory and administrative framework, including the representative notifications and filings falling within the agreed mandate. The provider must nevertheless remain responsible for determining that Article 13 applies to it and that the factual basis for appointment remains valid.
What should be agreed before appointing a representative?
A robust Article 13 appointment should address more than the identity of the representative. Before the mandate begins, the provider and representative should have a clear understanding of the following matters.
PROVIDER ENTITY
Identify the legal entity that actually provides each intermediary service covered by the appointment.
COVERED SERVICES
Define the websites, platforms, applications or other intermediary services that fall within the representative mandate.
DSA CLASSIFICATION
Record how each covered service has been classified under the DSA and ensure that the mandate reflects the relevant provider and service structure.
EU SERVICE OFFERING
Identify the Member States in which the relevant services are offered. Where services are offered in several Member States, this also establishes the Member States in which an Article 13 representative may potentially be located.
ESTABLISHMENT ANALYSIS
Assess whether the provider has an establishment in the Union and whether any subsidiary, branch, personnel presence, group entity or other EU presence affects the Article 13 analysis.
AUTHORITY COMMUNICATIONS AND ESCALATION
Agree how regulatory communications, orders, requests and decisions will be received, escalated and handled within the relevant regulatory deadlines.
INTERNAL CONTACTS AND RESOURCES
Identify the legal, regulatory, technical and operational contacts who can provide the representative with instructions, information and resources when required.
CONTACT-POINT ALLOCATION
Confirm separately how the provider will satisfy any Article 11 and Article 12 contact-point requirements and whether any of those functions have been separately entrusted to the representative.
CHANGE MANAGEMENT
Agree how changes affecting the provider, its services, DSA classification, EU presence or representative information will be communicated and reflected in regulatory filings.
TERMINATION AND TRANSITION
Define how the mandate will end and how representative information will be removed or replaced in regulatory filings and public-facing information.
A practical Article 13 appointment sequence
For a non-EU provider, the process can be approached in the following sequence:
-
Identify the provider entity
Determine which legal entity provides the relevant intermediary service.
-
Classify the service
Assess whether the service is mere conduit, caching, hosting, an online platform, search service or another relevant DSA category.
-
MAP THE EU SERVICE OFFERING
Determine whether the relevant intermediary service is offered in the Union and identify the Member States in which it is offered.
-
ASSESS EU ESTABLISHMENT
Determine whether the provider has an establishment in the Union that affects the Article 13 requirement.
-
CHOOSE AN ELIGIBLE REPRESENTATIVE MEMBER STATE
Where Article 13 applies, the representative must be established or reside in one of the Member States in which the provider offers the relevant service.
If the provider offers its services in several Member States, it may select one of those Member States for the Article 13 appointment.
The provider does not need to appoint a separate Article 13 representative in every Member State where the service is offered.
The selected Member State is nevertheless important because the representative’s location has consequences for the allocation of supervisory and enforcement competence under Article 56, subject to the powers allocated to the European Commission under the DSA.
-
Define the mandate
Document powers, responsibilities, communication processes and resources.
-
Set escalation contacts
Identify internal regulatory, legal and emergency contacts.
-
Complete notification and publication requirements
Notify the competent Digital Services Coordinator and make the required representative information publicly available.
-
Operationalise the relationship
Establish monitored channels, authority-response procedures and change-notification processes.
-
Review the appointment over time
Reassess the mandate if services, group structure, EU presence, classification or regulatory status changes.
Need an EU legal representative under Article 13?
Explore OSTRAI’s DSA Representative service →
Article 13 representation is part of market-entry governance
For non-EU intermediary service providers, Article 13 representation should not be treated as a box to tick immediately before entering the European market. The appointment sits within a wider DSA governance framework.
The provider needs to understand:
- why Article 13 applies;
- which services are covered;
- where those services are offered;
- which Member State will become relevant for supervision;
- what powers and resources the representative needs;
- which contact-point functions remain separate; and
- how regulatory communications will be handled in practice.
A well-designed representative mandate creates a functioning interface between a non-EU provider and the European regulatory system. It does not replace the provider’s substantive DSA compliance obligations; rather, it establishes the regulatory presence through which those obligations can be supervised and enforced in the Union.

