The EU Digital Services Act (DSA), which came into force earlier this year, applies to many EU digital services businesses, including a number of SaaS companies, providing ‘intermediary services’ such as platforms that enable users to store, manage or share content. Please see here for more information on the DSA, who it applies to and what you need to do to comply.
Like many current EU regulations, the DSA also applies to companies outside the EU who have a ‘substantial connection’ to the EU, e.g. your services are targeting EU users. Even if you don’t have a physical presence in the EU, you may be caught. Targeting is broadly interpreted under the DSA so it’s important to assess whether your activities are such that the DSA applies. When considering whether you have a ‘substantial connection’ to the EU, please bear in mind that if you have determined for GDPR purposes that you need to appoint an EU data representative because of your business activities in the EU, it may be difficult to justify coming to a different conclusion about your need to appoint an EU rep under the DSA where the DSA applies to your business activities.
Where the DSA applies to companies outside the EU, it requires them to appoint an EU-based legal representative. The representative should be established in a relevant EU country – good practice is to appoint them in the EU country where you do the most business; if none stands out, the most convenient EU country in which you do business, e.g. based on time zone and language spoken, is likely to be acceptable. And put in place a written agreement appointing your representative.
Although the legal representative requirement under the DSA is similar to the representative obligations under GDPR, they are not the same. And if you have a GDPR rep, they will not automatically pick up the DSA service. A couple of key differences include:
1. Notifying the EU Digital Services Coordinator
Companies must inform the Digital Services Coordinator in the relevant EU country about their appointment of a legal representative, including the representative’s contact details. This makes it easier for EU authorities to enforce the DSA, as they can quickly see which companies have appointed a legal representative and which have not, helping identify those that are not complying.
2. Representative’s Liability for DSA Fines:
Under the DSA, the appointed legal representative can be held responsible for their client’s non-compliance with DSA obligations, including fines. This is different from the GDPR, where the representative’s liability is less clear. The DSA explicitly allows legal actions against the representative, in addition to any actions that can be taken against the company itself.
The appointment of an EU representative is becoming an increasingly common theme in EU regulations; including with such regs as:
- the Terrorist Content Online Regulation (TCOR, which will apply to most organisations deemed a “platform provider” under the DSA),
- the Network & Information Security Directive 2 (NIS2, relating to cyber security of significantly important services)
- the Data Governance Act (DGA, for companies which – over-simplifying – gather information and distribute it)
- the (upcoming) Data Act
- the AI Act
So, it’s important to keep abreast of the regulations and their requirements.
Next steps
Firstly, talk to us/ your legal advisors about whether the DSA applies to your business and its activities. If it does, take steps to ensure your compliance (see our blog here for recommended next steps) – including appointing a legal representative if you need to. If you do, then appoint one in writing and notify the appointment of the representative to the EU Digital Services Coordinator.
Lastly, monitor other EU regulations to check if they require other appointments and whether you need to complete a full registration with a relevant authority (e.g. the DGA) or to simply notify the appointment of the representative (e.g. the DSA and TCOR).
Get in touch:
We can help you with your DSA compliance and help you to put in place the right processes to ensure continued compliance.
We work with DataRep who are a leading provider of the EU/ EEA and UK Representative services. They have a network of contact locations in all 27 EU countries, Norway and Iceland in the EEA and the UK. If you want to discuss any of your data protection requirements, including if you need a Representative, please get in touch.
