Common Questions

Frequently Asked Questions

Answers on representatives, cross-border mandates, and the European compliance frameworks organisations ask us about most.

General

What does a representative actually do?

A representative acts as your formal local contact point for supervisory authorities and data subjects. The role typically includes receiving correspondence, forwarding rights requests and authority communications, maintaining key records interfaces, and ensuring there is a clear escalation route for time-sensitive matters.

Q&A

Frequently asked questions by framework

Privacy & Data Protection

Do we need an EU GDPR representative?

If your organisation is not established in the EU but offers goods or services to individuals there, or monitors their behaviour, you may be required to appoint an EU representative under Article 27 GDPR. This applies to both controllers and processors, subject to limited exemptions - including where processing is occasional, does not include large-scale processing of sensitive or criminal-offence data, and is unlikely to result in risk to individuals' rights and freedoms. That exemption should be assessed carefully rather than assumed.

Do we need a separate UK GDPR representative after Brexit?

Usually, yes. The UK GDPR is a separate legal regime. If your organisation is not established in the UK but targets individuals there or monitors their behaviour, you may need a UK representative even if you already have an EU GDPR representative.

Can one provider hold both our EU and UK GDPR mandates?

Yes. Many organisations appoint the same provider for both mandates, provided that provider has the required establishment in each jurisdiction. Lionheart coordinates both under one engagement - consistent procedures, aligned escalation paths and unified records.

Does appointing a GDPR representative transfer our compliance obligations to the representative?

No. Your organisation remains responsible for its substantive GDPR compliance obligations as controller or processor. The representative is a statutory contact point and support function, not a substitute controller, processor or outsourced compliance owner. A UK court decision confirmed that GDPR Recital 80 does not create representative liability for a client's breach - a representative's liability is fault-based and does not extend to the controller's or processor's substantive breaches. [Rondon v LexisNexis Risk Solutions UK Ltd [2021] EWHC 1427 (QB)]

Do you need a Swiss FADP representative?

If your organisation acts as a data controller, is not established in Switzerland, and regularly offers goods or services to individuals there - or monitors their behaviour - you are likely required to designate a representative under Article 14 of the FADP. Note: the obligation applies to controllers only. If your organisation acts solely as a data processor, the FADP representative requirement does not apply - unlike GDPR Article 27 which covers both.

We are an EU or EEA company. Does Swiss FADP Article 14 still apply to us?

This is worth taking specific legal advice on. Article 14 FADP refers to organisations not established in Switzerland - not organisations outside the EU or EEA. A data controller established in Germany, France or Norway but not in Switzerland could fall within scope if it regularly processes Swiss residents' personal data. Lionheart can provide a preliminary assessment.

Can our EU GDPR representative also act as our Swiss FADP representative?

Not automatically. The FADP requires a representative established in Switzerland - an EU-based representative does not satisfy this requirement. A firm with entities in both the EU and Switzerland - as Lionheart does - can hold both mandates under a coordinated arrangement, which is the most practical solution for organisations subject to both obligations.

Do we need a Serbian representative?

If your organisation is not established in Serbia but offers goods or services to individuals there, or monitors their behaviour, you may need to designate a representative under Article 44 of Serbia's Personal Data Protection Law. Serbia's law was drafted in close alignment with the GDPR model, including the concept of a local representative for certain non-Serbian organisations.

Digital Services Act

Do we need a DSA legal representative?

If you provide intermediary services into the EU and are not established in the EU, you may need to designate a legal representative under Article 13 DSA. The DSA covers intermediary services, including hosting, caching and mere conduit, and in practice often captures online platforms, marketplaces, app stores, hosting providers, search tools and other online intermediaries.

Why appoint a DSA representative in Ireland?

For many providers, Ireland offers an English-language legal and regulatory environment, a strong international business base, and an effective location for managing authority communications. Coimisiun na Mean (the Irish Media Commission) is the Irish Digital Services Coordinator.

AI Act

Do all AI providers need an EU authorised representative?

No. The requirement depends on your role and the type of AI offering. The AI Act specifically provides for authorised representatives for providers of high-risk AI systems (Article 22) and for providers of general-purpose AI models (Article 54) in the circumstances set out by the Act.

Can the same provider act as our AI Act representative and our GDPR/DSA representative?

Yes, provided it has the right establishment and mandate structure. For many technology providers, that is the most practical model because AI, privacy, platform and cybersecurity obligations often overlap operationally.

EU NIS2 / UK NIS

If we already have a UK NIS representative, do we need a separate EU NIS2 representative?

Yes. The UK NIS representative obligation and the EU NIS2 representative obligation are entirely separate legal requirements under distinct legal frameworks. Lionheart can hold both mandates - our UK entity covers UK NIS designation, while our Irish entity covers EU NIS2.

When will Lionheart's UK CSR representative service be available?

Our UK CSR representative service will be available after the Cyber Security Resilience Bill receives Royal Assent, expected late 2026. Contact us to register your interest.

TCOR

What is the one-hour removal obligation under TCOR?

Under Article 17 TCOR, hosting service providers must remove or disable access to terrorist content within one hour of receiving a removal order from a competent authority. Lionheart acts as your EU representative to receive these orders and ensure they are immediately escalated to the right person in your organisation.

Do I need a TCOR representative if I already have an EU GDPR representative?

These are separate obligations under separate regulations. GDPR Article 27 covers data protection. TCOR Article 17 covers the hosting of terrorist content. Both can be held by the same representative - Lionheart can cover both under a single coordinated mandate.