Digital Services Act Representative Requirements for Non-EU Companies

Who Needs a Digital Services Act Representative in the EU?

For non-EU providers, the Digital Services Act is not a theoretical EU rule. It is a live compliance framework that can apply as soon as intermediary services are offered to recipients in the Union. Where Article 13 applies, appointing an EU legal representative is not optional. It is a core compliance requirement.

If your business offers covered intermediary services in the EU and has no establishment there, you may need to appoint a legal representative in writing in one of the Member States where those services are offered. That representative provides an EU-based legal contact for authorities and supports a more reliable compliance process for notice handling, escalation, and regulatory communication.

Many companies underestimate how wide the DSA’s reach can be. The regulation is not limited to very large platforms. It can also affect hosting providers, marketplaces, SaaS businesses, social and creator platforms, and other intermediary services made available to EU users. For many non-EU providers, the Digital Services Act representative question should be assessed as soon as DSA scope is on the table.

This guide explains what the DSA covers, when Article 13 applies, how Articles 11, 12, and 13 differ, what a representative actually does, and how the role compares with GDPR representation.

What the Digital Services Act Covers

The Digital Services Act is the EU’s main framework for intermediary services in the digital economy. It is designed to make online environments safer, more transparent, and more accountable. In practice, it sets rules around contactability, notices, transparency, content handling, platform governance, and user-facing responsibilities.

The purpose of the DSA

At a high level, the DSA updates the rules for online intermediaries active in the EU market. It creates a layered compliance framework, with lighter obligations for some services and more demanding duties for online platforms, marketplaces, and very large online platforms and search engines.

The key point for non-EU businesses is simple. The law focuses on services offered into the EU, not only on where the company is incorporated.

A compliance-focused graphic showing Digital Services Act service categories in the EU, including hosting services, onli

 

The types of services covered

The DSA applies to intermediary services. These are commonly grouped into several categories:

  • Mere conduit services, which transmit information through networks

  • Caching services, which temporarily store information to support more efficient transmission

  • Hosting services, which store information provided by users

  • Online platforms, which are a subset of hosting services that disseminate user information to the public

  • Online marketplaces, which often trigger additional operational obligations within the platform category

These distinctions matter because the DSA does not apply the same burden to every provider. The more user-facing and public the intermediation function is, the more detailed the compliance expectations usually become.

Why the DSA Matters for Non-EU Providers

A business does not need to be established in the EU to fall within the DSA. If it offers intermediary services to recipients located in the EU, the regulation may still apply.

For non-EU companies, this has a practical consequence. Once the service is in scope, the business needs a reliable way to manage regulator contact, user-facing channels, internal escalation, and formal legal representation where required.

The territorial trigger

The core question is whether the service is offered to recipients in one or more EU Member States. This is not only about server location or company headquarters. It is about real market activity and whether the service is directed to the EU.

Indicators that a service targets the EU

No single factor decides the issue on its own, but common indicators can include:

  • offering services in EU languages

  • showing prices in euros

  • allowing onboarding for EU users

  • shipping or servicing customers in EU countries

  • running ads that target EU audiences

  • referring to EU users or EU markets in commercial materials

  • maintaining local terms, support, or help content for EU markets

The more deliberate the EU market strategy appears, the stronger the case for DSA scope.

Why being based outside Europe is not a defense

Many companies still assume that lacking an office, staff, or incorporation in Europe keeps them outside the DSA. That assumption is risky. The regulation is designed to reach providers that serve the EU market from abroad.

If your business benefits commercially from EU users or customers, the safer approach is to assess DSA scope directly instead of relying on geography as a shield.

When a DSA Representative Is Required

For many non-EU companies, Article 13 is the most important threshold issue after scope is confirmed.

The core rule for non-EU providers

Under Article 13 of Regulation (EU) 2022/2065, a provider of intermediary services that does not have an establishment in the EU but offers services in the EU must appoint, in writing, a natural or legal person established in one of the Member States where it offers services as its legal representative.

The Official text of the Digital Services Act on EUR-Lex is the core legal source for this requirement.

This should be treated as part of your operating model, not as last-minute paperwork. The representative is part of how a non-EU company manages legal contact and enforcement exposure inside the Union.

A diagram showing a non-EU digital service provider appointing an EU Digital Services Act representative as a regulatory

 

Who typically needs to appoint one

The issue commonly arises for:

  • non-EU hosting providers

  • SaaS businesses with EU users

  • online marketplaces

  • content-sharing platforms

  • app-based digital services

  • cloud or infrastructure services with EU-facing offerings

Not every company in these categories will automatically need a representative, but these are common profiles where the Article 13 question should be assessed early.

Situations that need closer legal review

Some businesses sit in a grey area and need more careful analysis. Examples include:

  • services accessible from the EU but not clearly marketed there

  • B2B services with limited public visibility

  • corporate groups with partial EU presence but unclear service ownership

  • sales through resellers, local partners, or intermediaries

These are the cases where delayed review can become expensive.

Which Services Most Often Need One

The representative requirement tends to matter most for services that host, distribute, rank, facilitate access to information, or connect users and traders.

Hosting and platform services

Hosting providers and online platforms are among the clearest examples. If users upload content, publish information, list products, share media, or interact through your service, the DSA analysis becomes much more concrete.

These services often need notice handling, transparency measures, and internal governance. A representative supports that broader compliance framework by creating an EU-based legal contact point.

Marketplaces and ecommerce intermediaries

Marketplaces face especially visible compliance risk because they sit between traders and consumers. Issues involving trader traceability, illegal listings, complaint handling, and authority communication can move quickly.

A compliance mapping diagram showing overlap between the Digital Services Act, GDPR, consumer protection rules, and plat

For non-EU marketplace operators, the representative role is often best understood as part of the company’s EU operating model.

Social, community, and creator platforms

Social and community services also sit close to the center of DSA obligations. If the platform disseminates user content to the public, then moderation governance, transparency, complaints, and user communication become central issues.

Infrastructure and hybrid digital services

Some companies assume they are too technical or too upstream to worry about the DSA. That can be a mistake. Hybrid services that combine hosting, collaboration, publishing, app distribution, or customer-facing infrastructure can still raise DSA questions.

That is why the analysis should follow actual service function, not internal branding.

What a Digital Services Act Representative Actually Does

A DSA representative does not make a company compliant by appointment alone. The role is to create a reliable EU-based legal interface for DSA-related contact and accountability.

Regulatory contact function

At a practical level, the representative serves as a point of contact for authorities in relation to the provider’s DSA obligations. This can include receiving communications and helping ensure that notices reach the right internal owners quickly.

For cross-border companies, that matters because fragmented inboxes and unclear ownership often create the first compliance failures.

Operational role in practice

A useful representative also supports process discipline. The role can connect with internal legal, compliance, privacy, security, trust and safety, and operations teams to help maintain continuity in how requests are received, escalated, documented, and answered.

That does not mean the representative takes over your internal obligations. It means the provider has an EU-facing legal structure that works under pressure.

What the representative does not do

European Commission overview of the regulatory framework

It is just as important to understand the limits of the role:

  • the representative does not replace the provider’s own compliance responsibility

  • the representative does not eliminate the need for product and legal governance

  • the representative does not absorb all liability for the provider

  • the representative does not fix scope or classification mistakes after the fact

A weak internal process cannot be solved by a name on paper.

A compliance checklist graphic for an EU Digital Services Act representative, showing authority communication, notice in

 

Articles 11, 12, and 13 DSA, Different Functions

One of the most common DSA mistakes is treating every contact requirement as if it were the same thing. It is not. Regulation (EU) 2022/2065 separates three distinct functions.

In simple terms:

  • Article 11 = regulatory contact channel

  • Article 12 = user or recipient contact channel

  • Article 13 = EU legal representative

A business can satisfy one of these obligations without satisfying the others.

What Article 11 DSA requires

Under Article 11 of Regulation (EU) 2022/2065, providers of intermediary services must designate a single electronic point of contact that allows EU Member State authorities, the European Commission, and the European Board for Digital Services to communicate directly with the provider.

This is the provider’s regulatory contact channel. In practice, it is often managed internally by legal, compliance, regulatory, or public policy teams through a dedicated inbox or intake process.

What Article 12 DSA requires

Under Article 12 of Regulation (EU) 2022/2065, providers must make available a point of contact for recipients of the service so that users, customers, or other recipients can communicate directly and rapidly with the provider.

This is different from Article 11 and different again from Article 13. In practice, it often sits with support, trust and safety, marketplace operations, or user operations.

The key point is that Article 12 is not just a generic support label. It is a statutory DSA contact mechanism that should be easy to find and connected to teams that can respond.

What Article 13 DSA requires

Under Article 13 of Regulation (EU) 2022/2065, a provider of intermediary services that has no EU establishment but offers services in the EU must appoint an EU-based legal representative.

This is the formal legal representation requirement under the DSA. It cannot usually be satisfied simply by publishing an internal email address.

The representative must have the powers and resources needed to cooperate with authorities in relation to DSA compliance.

The provider must notify the name, postal address, email address and telephone number of its legal representative to the Digital Services Coordinator in the Member State where the representative is established. These contact details must also be made publicly available, easily accessible, accurate and kept up to date.

Article 11, Article 12, and Article 13 side-by-side

DSA provision Who the contact is for Purpose Who provides it Can it normally be handled internally? Is an EU establishment required? Is a formal written appointment required? Typical examples
Article 11 EU Member State authorities, the European Commission, and the European Board for Digital Services Regulatory communication with the provider The provider of the intermediary service Yes, usually through legal, compliance, or regulatory teams No No, not in the same formal sense as Article 13 legal@company.com, regulatory portal, compliance inbox
Article 12 Users, customers, and other recipients of the service Direct and rapid communication between users and the provider The provider of the intermediary service Yes, usually through support, customer service, trust and safety, or operations No No, not in the same formal sense as Article 13 Help center contact flow, support channel, trust and safety route
Article 13 Competent authorities, via the provider’s formally designated EU representative Legal representation for DSA compliance and enforcement where the provider has no EU establishment A natural or legal person established in an EU Member State, appointed by the non-EU provider No, not unless the company already has a qualifying EU establishment that changes the analysis Yes Yes An EU-based provider such as DilicheckRep acting as the provider’s Article 13 DSA representative

 

Practical example for a non-EU provider

A US SaaS platform offering services to EU users could use legal@company.com as its Article 11 regulatory contact, its existing customer support function for Article 12, while separately appointing an EU-based provider such as DilicheckRep as its Article 13 legal representative.

Why this distinction matters in practice

This distinction helps avoid a common and costly mistake. A non-EU provider cannot assume that publishing a support inbox satisfies Article 13. Just as importantly, appointing a DSA legal representative does not outsource the provider’s own Article 11 and Article 12 obligations.

Need an EU Legal Representative under Article 13 DSA?
DilicheckRep supports non-EU intermediary service providers that need to appoint an EU-based legal representative under the Digital Services Act.

DSA Representative vs GDPR Representative

Many companies already know the idea of an EU representative from data protection law. That helps, but it also creates confusion.

Where the roles overlap

Both DSA and GDPR representative structures give non-EU businesses a contact point in the Union. Both can matter when a company serves the EU market from abroad. Both also support communication with authorities and a more organized compliance posture.

That is why companies often review DSA representation alongside their GDPR representative service or broader GDPR compliance services.

Where they differ

The overlap should not hide the legal differences. The DSA and GDPR are different regimes with different triggers, different obligations, and different operating teams. A DSA representative supports digital service compliance. A GDPR representative supports data protection contact obligations.

One appointment does not automatically satisfy the other.

How To Appoint a DSA Representative

If your company likely needs a representative, the appointment should be handled as an operating decision, not just a legal formality.

Internal preparation before appointment

Before naming a representative, the company should:

  • identify which services are offered into the EU

  • classify the relevant service type under the DSA

  • confirm whether an EU establishment already exists

  • assign internal owners across legal and operations

  • define an escalation workflow for authority contact

  • prepare supporting documentation and service descriptions

If these basics are missing, the appointment may exist on paper while the process still fails in practice.

What to look for

A strong representative should offer:

  • clear EU presence

  • reliable notice intake

  • documented escalation procedures

  • experience with EU digital regulation

  • disciplined recordkeeping

  • practical coordination mechanisms

The right partner is not just forwarding messages. It is supporting a structured compliance interface.

Contract points to define

The appointment should clearly set out:

  • the scope of the mandate

  • which services and markets are covered

  • who receives authority requests internally

  • expected response times

  • recordkeeping responsibilities

  • limits of the representative’s role

Ambiguity in the contract tends to become visible only when something urgent arrives.

Common Mistakes Non-EU Companies Make

Several mistakes appear repeatedly in DSA planning:

  • assuming the law only matters for the largest platforms

  • waiting until an authority contact or market issue appears, instead of building a proactive compliance process early

  • confusing DSA representation with GDPR representation

  • appointing a representative without building an internal response process

  • failing to map the service properly

If the business misunderstands whether it is acting as a hosting service, platform, marketplace, or hybrid intermediary, the rest of the analysis becomes unstable. In practice, the stronger approach is to prepare before scrutiny starts, not after. That is where due diligence readiness can matter. Firms such as Oyster Shield and platforms like DiliCheck AI focus on legal operations and due diligence readiness, which can help non-EU companies organize documentation, ownership, and escalation processes before a regulator, partner, or investor asks for them.

Compliance Steps To Take Now

If your business offers digital services into the EU, a practical response starts with scope, ownership, and process.

1. Confirm scope

Begin with the basics:

  • inventory the services offered to EU recipients

  • identify the Member States involved

  • assess whether the service falls into a DSA intermediary category

  • determine whether the company has an EU establishment

  • confirm whether a representative is required

2. Separate Articles 11, 12, and 13

Make sure the company does not collapse these requirements into one inbox or one owner.

  • assign the Article 11 regulatory contact

  • make the Article 12 user contact easy to find and use

  • confirm whether Article 13 requires a formal EU representative

3. Build internal ownership

Then move into governance:

  • align legal, product, privacy, and trust and safety teams

  • define authority response workflows

  • centralize key records and service documentation

  • connect DSA readiness with other EU compliance duties

  • review whether a consolidated representation structure makes sense

For many non-EU businesses, the smartest move is to treat representation as part of a broader EU compliance system. If you need a practical starting point, review the Digital Services Act representative offering alongside related GDPR and AI compliance structures such as the EU AI Act authorised representative and the EU Data Act representative.

Final Takeaway

The DSA representative requirement is not just a formal designation for non-EU companies. It is part of the structure that supports EU regulatory access, notice handling, and compliance continuity.

If your business offers covered intermediary services to recipients in the EU and lacks an EU establishment, this issue should be reviewed early. The real risk is not only failing to appoint a representative when needed. It is failing to build the process around that role.

The companies that handle this well confirm scope early, separate Articles 11, 12, and 13 clearly, assign ownership, and make sure the EU contact structure works before pressure arrives.

Need help with DSA representation?

If you are assessing whether your business needs an EU representative, it helps to review the requirement before a regulator, platform issue, or market expansion creates urgency. A structured setup can reduce response delays and make your EU compliance model easier to manage.

Explore the Digital Services Act representative service, or review the GDPR representative service if you are aligning multiple EU obligations.

Related resources