Newsletter Anmeldung

Bleiben Sie mit dem Newsletter immer up to date.

Request
arrow-to-top
HomeMandatesRepresentative positionsExternal EU representative under the Data Act
Dimitri Korostylev
Head of Legal & Data Privacy Consulting
request

The external EU representative under the Data Act

To fulfil your data and access obligations in the EU – even without your own establishment

The Data Act (Regulation (EU) 2023/2854) establishes uniform rules for fair access to and use of data in the EU, in particular data generated by connected products (e.g. IoT devices, machines, vehicles) and associated services.

It covers, among others:

  • manufacturers and providers of connected products and associated services,
  • data owners who must grant users or third parties access to usage data,
  • data processing services (e.g. cloud and edge services) that must ensure interoperability and portability.

For companies not established in the EU that fall within the scope of the Data Act and offer products or services in the EU, the following also applies:

  • The company is not established in the EU,
  • but makes connected products available in the EU or offers services covered by the Regulation in the EU, and
  • falls within the material scope of the Data Act as a manufacturer/supplier of connected products, as a data controller or as a data processing service.

In such cases, pursuant to Article 37 of the Data Act, a legal representative must be appointed in an EU Member State. This representative acts as the official point of contact for the competent authorities and must be able to demonstrate to them the measures the company has implemented to comply with the Data Act.

Our role as your external EU representative under the Data Act

Our specialists in information security, data protection and digital regulatory law will act as your external EU representative under the Data Act. We ensure that requirements and enquiries from the EU are coordinated, dealt with in a timely manner and in your best interests.

Among other things, we offer you:

  • Acting as the official point of contact in the EU for competent authorities under Article 37 of the Data Act through our subsidiary, Swiss Infosec (Deutschland) GmbH, based in Berlin, Germany
  • Receipt, coordination and forwarding of official correspondence, requests for information and orders in connection with the Data Act
  • Support with documenting and presenting your compliance measures (policies, processes, technical and organisational measures) to the authorities
  • Pragmatic recommendations for action regarding key Data Act obligations, e.g.
    • Access and disclosure rights for usage data from connected products,
    • fair contract drafting for B2B data usage,
    • protection of trade secrets and intellectual property despite data access obligations,
    • rules on switching data processing services (cloud/edge services) and on interoperability
  • Support in aligning the Data Act with existing frameworks such as the GDPR, Data Governance Act, NIS-2, ISO 27001 and others
  • A reliable point of contact who understands your business model, your data flows and your technical environment, and translates legal requirements into clear, actionable steps

This allows you to maintain your focus on your product and service business in the EU market. We take care of the operational implementation of the representative role and professional communication with the authorities.

Why choose Swiss Infosec as your Data Act representative in the EU?

  • Combined expertise in data protection, information security and digital regulation (including GDPR, Data Governance Act, NIS-2, Data Act)
  • Practical, risk-based advice rather than purely formal checklist compliance
  • In-depth understanding of connected products, IoT ecosystems, platform business models, and cloud and data processing services typically affected by the Data Act
  • Structured process models for implementing Data Act-compliant processes relating to data access, data use, contract drafting and technical interfaces
  • Clear responsibilities and short lines of communication – from initial assessment through ongoing representation to support during audits and enforcement proceedings

Our goal: to design Data Act compliance in such a way that you remain legally compliant whilst maintaining business flexibility.

Next steps

Contact us for a no-obligation initial consultation. Together, we will clarify:

  • Whether and in what capacity your company falls within the scope of the Data Act (e.g. as a manufacturer of connected products, data controller, data recipient or provider of data processing services), and
  • how we can efficiently integrate the role of the EU Data Act representative into your existing governance, compliance and IT processes.

Let us take care of the role of the EU representative under the Data Act, so that you can provide your data-driven products and services in the EU market fairly, securely and in compliance with the law.

Dimitri Korostylev
Head of Legal & Data Privacy Consulting
request

Non-binding enquiry

© Swiss Infosec AG 2026