
Common Questions
Frequently Asked Questions
Answers on representatives, cross-border mandates, and the European compliance frameworks organisations ask us about most.

Common Questions
Answers on representatives, cross-border mandates, and the European compliance frameworks organisations ask us about most.
General
A representative acts as your formal local contact point for supervisory authorities and data subjects. The role typically includes receiving correspondence, forwarding rights requests and authority communications, maintaining key records interfaces, and ensuring there is a clear escalation route for time-sensitive matters.
Q&A
Privacy & Data Protection
If your organisation is not established in the EU but offers goods or services to individuals there, or monitors their behaviour, you may be required to appoint an EU representative under Article 27 GDPR. This applies to both controllers and processors, subject to limited exemptions - including where processing is occasional, does not include large-scale processing of sensitive or criminal-offence data, and is unlikely to result in risk to individuals' rights and freedoms. That exemption should be assessed carefully rather than assumed.
Usually, yes. The UK GDPR is a separate legal regime. If your organisation is not established in the UK but targets individuals there or monitors their behaviour, you may need a UK representative even if you already have an EU GDPR representative.
Yes. Many organisations appoint the same provider for both mandates, provided that provider has the required establishment in each jurisdiction. Lionheart coordinates both under one engagement - consistent procedures, aligned escalation paths and unified records.
No. Your organisation remains responsible for its substantive GDPR compliance obligations as controller or processor. The representative is a statutory contact point and support function, not a substitute controller, processor or outsourced compliance owner. A UK court decision confirmed that GDPR Recital 80 does not create representative liability for a client's breach - a representative's liability is fault-based and does not extend to the controller's or processor's substantive breaches. [Rondon v LexisNexis Risk Solutions UK Ltd [2021] EWHC 1427 (QB)]
If your organisation acts as a data controller, is not established in Switzerland, and regularly offers goods or services to individuals there - or monitors their behaviour - you are likely required to designate a representative under Article 14 of the FADP. Note: the obligation applies to controllers only. If your organisation acts solely as a data processor, the FADP representative requirement does not apply - unlike GDPR Article 27 which covers both.
This is worth taking specific legal advice on. Article 14 FADP refers to organisations not established in Switzerland - not organisations outside the EU or EEA. A data controller established in Germany, France or Norway but not in Switzerland could fall within scope if it regularly processes Swiss residents' personal data. Lionheart can provide a preliminary assessment.
Not automatically. The FADP requires a representative established in Switzerland - an EU-based representative does not satisfy this requirement. A firm with entities in both the EU and Switzerland - as Lionheart does - can hold both mandates under a coordinated arrangement, which is the most practical solution for organisations subject to both obligations.
If your organisation is not established in Serbia but offers goods or services to individuals there, or monitors their behaviour, you may need to designate a representative under Article 44 of Serbia's Personal Data Protection Law. Serbia's law was drafted in close alignment with the GDPR model, including the concept of a local representative for certain non-Serbian organisations.
Digital Services Act
If you provide intermediary services into the EU and are not established in the EU, you may need to designate a legal representative under Article 13 DSA. The DSA covers intermediary services, including hosting, caching and mere conduit, and in practice often captures online platforms, marketplaces, app stores, hosting providers, search tools and other online intermediaries.
For many providers, Ireland offers an English-language legal and regulatory environment, a strong international business base, and an effective location for managing authority communications. Coimisiun na Mean (the Irish Media Commission) is the Irish Digital Services Coordinator.
AI Act
No. The requirement depends on your role and the type of AI offering. The AI Act specifically provides for authorised representatives for providers of high-risk AI systems (Article 22) and for providers of general-purpose AI models (Article 54) in the circumstances set out by the Act.
Yes, provided it has the right establishment and mandate structure. For many technology providers, that is the most practical model because AI, privacy, platform and cybersecurity obligations often overlap operationally.
EU NIS2 / UK NIS
Yes. The UK NIS representative obligation and the EU NIS2 representative obligation are entirely separate legal requirements under distinct legal frameworks. Lionheart can hold both mandates - our UK entity covers UK NIS designation, while our Irish entity covers EU NIS2.
Our UK CSR representative service will be available after the Cyber Security Resilience Bill receives Royal Assent, expected late 2026. Contact us to register your interest.
TCOR
Under Article 17 TCOR, hosting service providers must remove or disable access to terrorist content within one hour of receiving a removal order from a competent authority. Lionheart acts as your EU representative to receive these orders and ensure they are immediately escalated to the right person in your organisation.
These are separate obligations under separate regulations. GDPR Article 27 covers data protection. TCOR Article 17 covers the hosting of terrorist content. Both can be held by the same representative - Lionheart can cover both under a single coordinated mandate.
Get started
Use the guided self-check tool to map which representative obligations may apply to your organisation.
Open the checkerNext step
See the formal designation steps, mandate structure and operational setup Lionheart expects for representative appointments.
View the process