Glossary

What Europe is actually asking for.

22 terms that decide what a company outside the EU owes inside it, across compliance, data protection, employment and corporate law. Definitions first, with the provision they come from — what we sell about them is a link at the end, not the point.

EU GDPR representativeArticle 27 representative · Art. 27 rep

A person or company established in the EU, appointed in writing to act as the point of contact for data protection authorities and individuals on behalf of a company that has no EU establishment.

Article 27 GDPR applies to any organisation outside the EU that offers goods or services to people in the EU, or monitors their behaviour. If anyone in the EU can sign up, buy, or load a cookie on your site, and you have no entity there, the obligation is engaged — targeting the EU deliberately is not the test.

The representative is named in your privacy policy and mandated in writing. Supervisory authorities and data subjects address it in place of you, and it must be established in a member state where the people whose data you process are located.

It is not a Data Protection Officer, and appointing one does not satisfy the other.

Data Protection OfficerDPO

An independent role responsible for advising on and monitoring an organisation's own compliance with data protection law, reporting to the highest level of management.

A DPO is required where an organisation's core activities involve regular and systematic monitoring of people on a large scale, or large-scale processing of special-category data. The role can be filled by an employee or contracted externally.

The distinction people get wrong: a DPO looks inward and advises the organisation, while an Article 27 representative looks outward and receives contact on its behalf. One is an internal oversight function; the other is a point of contact for people outside. A company can need both, and neither substitutes for the other.

DSA legal representativeArticle 13 representative

A named legal representative in the EU for providers of intermediary services established outside it, acting as the contact point for the Commission, national authorities and Digital Services Coordinators.

The Digital Services Act reaches any hosting service, online platform or intermediary that offers services to users in the EU, regardless of where it is established. If EU users can post, list, buy or sell on your product, the DSA applies.

The representative can be held liable for non-compliance, which is why the appointment is filed rather than merely declared, and why it sits alongside the other Article obligations — a notice-and-action endpoint, statements of reasons, and transparency reporting.

Employer of RecordEOR

A company that becomes the legal employer of your hire in their country, taking on the employment contract, payroll, tax withholding and statutory benefits, while the person works day to day for you.

An EOR lets a company employ someone in a country where it has no entity. The employment relationship is real and local: a contract under national law, payroll in local currency with tax remitted, and the statutory benefits that country requires.

It is the usual alternative to two worse options — incorporating before you know whether the market works, or engaging someone as a contractor when the working relationship is really employment, which is what misclassification means and what it costs.

Worker misclassification

Engaging someone as an independent contractor when the substance of the relationship is employment, which exposes the engaging company to back taxes, social contributions and penalties.

European authorities look at how the relationship actually works, not what the contract says it is. Full-time hours, direction over how the work is done, integration into the team, and exclusivity all point toward employment regardless of the paperwork.

The exposure is retrospective. A finding of misclassification typically means unpaid employer social contributions and income tax for the whole engagement, plus interest and penalties — which is why the risk grows with every month it continues.

NIS 2 representativeArticle 26 representative · NIS2 rep

A representative designated in an EU member state by a provider of in-scope digital services established outside the EU, acting as the contact point for national cybersecurity authorities.

Article 26(3) requires the designation for in-scope services offered into the EU from outside it, in a member state where those services are offered. The structure mirrors the GDPR's Article 27 representative, but the authority on the other side is a cybersecurity regulator or CSIRT rather than a data protection one.

Scope catches digital infrastructure — cloud, DNS, CDN, data centres, managed IT, online marketplaces, search and social — regardless of company size. In other sectors the obligation starts at the medium-entity threshold of 50 staff or €10 million turnover.

An EU-established entity does not need a representative, but still carries the registration, risk-management and incident-reporting duties itself.

Significant incidentNIS 2 incident reporting · 24/72-hour report

Under NIS 2, an incident that causes or is capable of causing severe operational disruption, financial loss, or material damage to others — triggering a reporting clock that starts when you become aware of it.

The clock has three stages: an early warning within 24 hours, a full incident notification within 72 hours, and a final report within one month. Each goes to the national CSIRT or competent authority, and the stages are cumulative rather than alternatives.

Availability outages affecting users across borders almost always qualify. Because the threshold turns on capability to cause harm, an incident can be reportable before anyone has measured actual damage.

The judgement call is classification at intake, not drafting. Deciding an incident is not significant is itself a decision a regulator can review later, so it is worth recording the reasoning.

AI Act authorised representativeArticle 22 representative · AI Act rep

A representative established in the EU, appointed in writing by a non-EU provider of a high-risk AI system or a general-purpose AI model, to hold the documentation and deal with market surveillance authorities.

Providers of high-risk systems outside the EU appoint a representative under Article 22 before the system is placed on the market. Providers of general-purpose AI models appoint one under Article 54, which bites even where the deployment itself is low risk.

The representative keeps the technical documentation and the declaration of conformity available to authorities, verifies that the provider's obligations have been carried out, and can terminate the mandate if it believes the provider is acting contrary to the Act.

It is a documentation and contact role, not an approval body. A notified body, where one is needed, is a separate step.

High-risk AI systemAnnex III system

An AI system used in one of the contexts the EU AI Act lists as high-risk — among them employment screening, creditworthiness, education admission, law enforcement and access to essential services.

Annex III is the definitive list. The ones that catch startups most often are hiring and candidate screening, credit decisions, admission to education, and access to essential public or private services. The test is the context the system is used in, not how sophisticated it is.

High-risk status brings a risk-management system, technical documentation, logging, human oversight and a conformity assessment. Most systems qualify for self-assessment; biometric identification and products already covered by sector safety law are the usual exceptions, where a notified body is involved.

Below high-risk sit limited-risk uses such as chatbots, deepfakes and emotion-detection interfaces, which carry transparency duties rather than the full regime.

General-purpose AI modelGPAI · foundation model

A model trained on broad data that can be adapted to many tasks — a foundation model — carrying its own obligations under the EU AI Act regardless of the risk level of any one deployment.

If you train or serve a general-purpose model and you are established outside the EU, Article 54 requires an authorised representative in the Union even where the downstream use is low risk.

Obligations centre on documentation: what the model is, how it was trained, its capabilities and limitations, and the information downstream providers need to meet their own duties.

Deploying somebody else's model does not make you its provider. Fine-tuning or placing it on the market under your own name can.

Responsible PersonGPSR responsible person · Article 16 responsible person

An economic operator established in the EU whose name and address appear on a consumer product or its packaging, without which the product may not be placed on the EU market.

The General Product Safety Regulation applies to all consumer products, including those that carry no CE marking. Selling to EU customers through a marketplace counts: Amazon's EU stores block listings that lack responsible-person details, and other marketplaces have followed.

The Responsible Person keeps the technical documentation available, cooperates with market surveillance authorities, and handles corrective action and recalls when a product turns out to be unsafe.

Pure software and digital content are out of scope. Connected devices and products with embedded firmware are in scope, and may also trigger sector rules such as RED or EMC.

Authorised representative (market surveillance)Article 4 representative · Regulation (EU) 2019/1020 representative

The representative required under Regulation (EU) 2019/1020 for CE-marked products in specific sectors — a narrower role than the GPSR Responsible Person, and often held by the same party.

Article 4 of the market surveillance regulation applies to products covered by particular sector directives, such as Low Voltage, EMC and Machinery. GPSR, by contrast, applies to consumer products generally, including those without CE marking.

The practical consequence is that a company selling CE-marked consumer electronics can be caught by both, and a company selling unregulated consumer goods only by GPSR.

The tasks overlap heavily: keep the declaration of conformity and technical file, respond to authorities, and act when a product is non-compliant.

UK Responsible PersonUKCA responsible person

The United Kingdom's equivalent of the EU Responsible Person, required for most consumer products placed on the UK market after Brexit.

An EU appointment does not cover Great Britain and a UK appointment does not cover the EU. A company selling into both needs two valid addresses, each in its own market.

The UK regime attaches to UKCA marking, the UK's counterpart to CE, and the duties follow the same shape: documentation available, cooperation with regulators, action on unsafe products.

Notice-and-actionArticle 16 notice · illegal content notice

The mechanism every hosting service must offer so that anyone can report content they consider illegal, and which obliges the provider to decide and respond.

Article 16 of the Digital Services Act requires a notice channel that is easy to find and use, accepts electronic submissions, and confirms receipt. A sufficiently precise notice gives the provider actual knowledge of the content, which is what moves liability.

Once a decision is made — removal, demotion, restriction or leaving it up — the provider owes a statement of reasons to the affected user and a response to the reporter.

Trusted flaggers' notices must be handled with priority. Repeated misuse of the channel can itself be acted on.

Statement of reasonsSoR · Article 17 statement

The explanation a platform owes a user whenever it restricts their content or account, setting out what was done, on what ground, and how to challenge it.

Article 17 requires the statement to name the restriction, the facts relied on, whether automated means were used, the legal or contractual ground, and the routes to redress — internal complaint, out-of-court settlement, or court.

Statements of reasons are also submitted to the Commission's public Transparency Database, which makes moderation decisions auditable across platforms.

The obligation applies to decisions taken on your own initiative as well as those following a notice.

Data-subject requestDSR · DSAR · subject access request

A request from an individual to exercise a right over their personal data — access, deletion, correction, portability, restriction or objection — which must be answered within a statutory window.

Under the GDPR the window is one month, extendable by two further months for complex requests, and the extension itself must be communicated. Other laws set their own: 45 days under the CCPA, 15 under Brazil's LGPD.

The clock starts on receipt, not on identification of the requester, so verification has to happen inside the window. A request sent to any public channel counts, which is why a single intake point matters.

Answering means searching every system that holds the person's data, not only the main one. That is usually the hard part, rather than the reply itself.

Records of processing activitiesRoPA · Article 30 records

The internal register of what personal data an organisation processes, why, who receives it, where it goes and how long it is kept — produced to a supervisory authority on request.

Article 30 requires records from controllers and processors alike. The small-organisation exemption is narrow: it falls away where processing is not occasional, is likely to risk people's rights, or involves special-category data, which covers most software businesses.

A record is maintained rather than written once. New tools, new vendors and new purposes each change it, which is why it is usually the first document an authority asks for.

Data protection impact assessmentDPIA · Article 35 assessment

A structured assessment carried out before processing that is likely to result in a high risk to people, describing the processing, the necessity for it, the risks and the measures that address them.

Article 35 names three clear triggers: systematic and extensive automated evaluation producing legal or similarly significant effects, large-scale processing of special-category data, and large-scale systematic monitoring of a public area. National authorities publish their own lists on top.

Where the assessment still shows high residual risk, the authority must be consulted before the processing starts.

The value is the record of the reasoning. An assessment finished after launch is evidence of the wrong thing.

Sub-processoronward processor

A vendor engaged by your processor to carry out part of the processing on your behalf — your hosting provider's own suppliers, for example — and whose use requires your authorisation.

Article 28 lets a processor engage a sub-processor only with the controller's prior authorisation, general or specific, and requires the processor to impose the same data protection terms down the chain. The processor stays liable for the sub-processor's failures.

In practice this is run as a published list plus advance notice of change, which gives customers the window to object that the Article contemplates.

Keeping the list current is also the quickest way to answer a security review, since the question is asked in every one.

Contractor of RecordCoR · AoR · agent of record

A company that contracts with an independent contractor on a business-to-business basis on your behalf, handling the contract, invoicing and payment, and carrying the misclassification risk.

The difference from an Employer of Record is the status of the person. An EOR becomes the legal employer of an employee, runs payroll and provides statutory benefits. A CoR contracts with someone who remains self-employed, and the engagement is structured against the local classification test — IR35 in the UK, Scheinselbstständigkeit in Germany, the présomption de salariat in France.

Payment flows through one counterparty: you pay the CoR, the CoR pays the contractor in their own currency, and you receive a single invoice rather than making cross-border payments yourself.

If the relationship drifts toward employment — more hours, more control, more integration — the clean answer is to convert the person to employment rather than to document around it.

Resident directornominee director · local director

A director resident in the country of incorporation, required by some member states before a company can be registered there.

Ireland, Luxembourg, Cyprus and Malta are the jurisdictions that most often require one. Other member states, including the Netherlands, Germany and Estonia, do not, which is part of why founders choose between them on more than tax.

The role is a statutory officer position with real duties and exposure, which is why the appointment normally comes with directors' and officers' cover. It does not hand over control of the company: shareholding and day-to-day management stay where they are.

A resident director is not a substitute for a representative mandate under GDPR, DSA, NIS 2, the AI Act or GPSR. They answer different questions.

EU subsidiaryEU entity · local entity

A company incorporated in a member state and owned by your existing company — the step that turns you from a non-EU company selling into the Union into one established inside it.

Establishment changes which rules apply to you. Representative mandates under GDPR Article 27, DSA Article 13, NIS 2 Article 26, the AI Act and GPSR exist for companies without an EU establishment; a subsidiary can remove the need for them while adding corporate, tax and filing duties of its own.

Jurisdiction choice is a trade-off rather than a ranking. Estonia is the lightest to run and fully digital; Ireland pairs a 12.5% corporate rate with English-language common law; the Netherlands and Germany take longer because incorporation runs through a notary.

A bank account is a separate process from incorporation and runs at the bank's pace, typically a few weeks after the company exists.