CRA – Authorized Representative
As an Authorized Representative under Article 18 of the Cyber Resilience Act (Regulation (EU) 2024/2847 [CRA]), we represent non-EU manufacturers of products with digital elements vis-à-vis the market surveillance authorities in the EU. We act as their contact point in the Union, forward official communications and cooperate with the authorities. We offer representative service out of various EU member states.
Arrange your free consultation appointment:
Function
Role & Responsibilities of the Authorized Representative
Based on the written mandate, the Authorized Representative:
- keeps the EU declaration of conformity (Art. 28 CRA) and the technical documentation (Art. 31 CRA) at the disposal of the market surveillance authorities for at least 10 years after the product has been placed on the market or for the support period, whichever is longer
- provides a market surveillance authority, upon its request, with all information and documentation necessary to demonstrate the conformity of the product
- cooperates with the market surveillance authorities, at their request, on any action taken to eliminate the risks posed by the product
The Representative may also be subject to penalties under the CRA if it fails to fulfil its tasks.
Target Audience
Who is Subject to the Obligations under the CRA?
Why a Representative Makes Sense
Under the CRA, a non-EU manufacturer reports to the CSIRT of the Member State where its authorized representative is located. Without a representative, it can be difficult to assess which authority is in charge/the responsibility of a number of authorities could be triggered at the same time.
A representative therefore provides clarity, a stable point of contact with EU authorities, as a one-stop-shop for incident notifications is created when appointing a representative. That doesn't shift the manufacturer's core responsibility for product security, but it makes meeting that responsibility more easily manageable.
Feedback
Client testimonies about our data protection services
Customer
(Data Protection Officer: DPO)
Redbubble Inc., 111 Sutter Street, 17th Floor, San Francisco, CA 94104, USA
„DP-Dock brings real value to privacy compliance with their professionalism, responsiveness and depth of experience advising global tech companies operating in Europe.”
Customer
(Data Protection Officer: DPO)
Universal Tennis, LLC, 525 University Avenue, Palo Alto, CA 94301, USA
„DP-Dock is our designated Art. 27 GDPR representative for many years – more recently they are, in addition, our external DPO: a decision we’ve been happy with. Their understanding of global trends in data privacy is remarkable – including the provision of awareness trainings for our employees across the globe.“
Customer
(Data Protection Officer: DPO)
Ottobock SE & Co. KGaA, Max-Näder-Strasse 15, 37115 Duderstadt, Germany
„DP-Dock is our external data protection officer. They work with us in a targeted and trustworthy manner in an environment where we have many locations around the world. We are fully satisfied with their service. They are pragmatic, solution-oriented, qualified and fast when needed."
Contact information
Schedule a free first consultation appointment
with our data protection experts