The photo shows a woman with long blond hair, wearing a white suit and smiling friendly into the camera.

CRA – Authorized Representative

As an Authorized Representative under Article 18 of the Cyber Resilience Act (Regulation (EU) 2024/2847 [CRA]), we represent non-EU manufacturers of products with digital elements vis-à-vis the market surveillance authorities in the EU. We act as their contact point in the Union, forward official communications and cooperate with the authorities. We offer representative service out of various EU member states.

Arrange your free consultation appointment:

info@dp-dock.com

Book free online consultation

Go to contact form

Seal - iapp Bronze Member

Function

Role & Responsibilities of the Authorized Representative

Wave as graphic
Two ladies are sitting in front of a laptop, which is placed on a glass desk, and are discussing.

Based on the written mandate, the Authorized Representative:

  • keeps the EU declaration of conformity (Art. 28 CRA) and the technical documentation (Art. 31 CRA) at the disposal of the market surveillance authorities for at least 10 years after the product has been placed on the market or for the support period, whichever is longer
  • provides a market surveillance authority, upon its request, with all information and documentation necessary to demonstrate the conformity of the product
  • cooperates with the market surveillance authorities, at their request, on any action taken to eliminate the risks posed by the product

The Representative may also be subject to penalties under the CRA if it fails to fulfil its tasks.

Target Audience

Who is Subject to the Obligations under the CRA?

Wave as graphic

The CRA applies to manufacturers of products with digital elements – which basically entails hardware and software with a direct or indirect data connection to a device or network, i.e. ‘connected’ hardware, such as IoT products, or software that communicates with a server – that are made available on the EU market. Manufacturers established outside the EU may appoint, in writing, an Authorized Representative in the Union.

Schedule an online consultation now

Penalties and Enforcement

Infringements of the CRA may result in corrective measures, such as the withdrawal or recall of products from the EU market, and significant administrative fines. Non-compliance with the essential cybersecurity requirements or the manufacturer obligations (e.g. reporting obligations) can result in fines of up to €15 million or 2.5% of the company’s worldwide annual turnover, whichever is higher.

Two ladies are sitting in front of a laptop, which is placed on a glass desk, and are discussing.

Why a Representative Makes Sense

Wave as graphic

Under the CRA, a non-EU manufacturer reports to the CSIRT of the Member State where its authorized representative is located. Without a representative, it can be difficult to assess which authority is in charge/the responsibility of a number of authorities could be triggered at the same time.

A representative therefore provides clarity, a stable point of contact with EU authorities, as a one-stop-shop for incident notifications is created when appointing a representative. That doesn't shift the manufacturer's core responsibility for product security, but it makes meeting that responsibility more easily manageable.

Feedback

Client testimonies about our data protection services

Wave as graphic
The view of the Port of Hamburg from above is breathtaking with the Elbphilharmonie in the background and a beautiful blu
Logo - Redbubble

Customer
(Data Protection Officer: DPO)
Redbubble Inc., 111 Sutter Street, 17th Floor, San Francisco, CA 94104, USA

„DP-Dock brings real value to privacy compliance with their professionalism, responsiveness and depth of experience advising global tech companies operating in Europe.”

Logo - Universal Tennis

Customer
(Data Protection Officer: DPO)
Universal Tennis, LLC, 525 University Avenue, Palo Alto, CA 94301, USA

„DP-Dock is our designated Art. 27 GDPR representative for many years – more recently they are, in addition, our external DPO: a decision we’ve been happy with. Their understanding of global trends in data privacy is remarkable – including the provision of awareness trainings for our employees across the globe.“

Logo - ottobock

Customer
(Data Protection Officer: DPO)
Ottobock SE & Co. KGaA, Max-Näder-Strasse 15, 37115 Duderstadt, Germany

„DP-Dock is our external data protection officer. They work with us in a targeted and trustworthy manner in an environment where we have many locations around the world. We are fully satisfied with their service. They are pragmatic, solution-oriented, qualified and fast when needed."

Contact information

Schedule a free first consultation appointment
with our data protection experts

Wave as graphic
A man in a blue suit and pink shirt holds a smartphone to his ear and smiles. He has his gaze slightly downward. On the left, a large, slanted skylight.

DP-DOCK GmbH
Ballindamm 39
20095 Hamburg

Privacy settings

We use cookies on our website. Some of them are essential, while others help us improve this website and your experience.

In this overview you can select and deselect individual cookies of a category or entire categories. You will also receive more information about the cookies available.
Group essential
Name Matomo
Technical name
Provider
Expire in days 72
Privacy policy /en/privacy-policy
Use Use without cookies
Allowed
Group external media
Name Calendly
Technical name __cf_bm,__cfruid,OptanonConsent
Provider Calendly LLC
Expire in days 365
Privacy policy /en/privacy-policy
Use To arrange appointments via the provider Calendly
Allowed
Name Contao CSRF Token
Technical name csrf_contao_csrf_token
Provider Contao
Expire in days 0
Privacy policy /en/privacy-policy
Use Serves to protect the website from cross-site request forgery attacks. After closing the browser, the cookie is deleted again.
Allowed
Name Contao HTTPS CSRF Token
Technical name csrf_https_contao_csrf_token
Provider Contao
Expire in days 0
Privacy policy /en/privacy-policy
Use Serves to protect the encrypted website (HTTPS) against falsification of cross-site requests. After closing the browser the cookie is deleted again
Allowed
Name PHP SESSION ID
Technical name PHPSESSID
Provider Contao
Expire in days 0
Privacy policy /en/privacy-policy
Use PHP cookie (programming language), PHP data identifier. Contains only a reference to the current session. There is no information in the user's browser saved and this cookie can only be used by the current website. This cookie is used all used in forms to increase usability. Data entered in forms will be e.g. B. briefly saved when there is an input error by the user and the user receives an error message receives. Otherwise all data would have to be entered again
Allowed