Menu

DPP Grid guide

GPSR Authorised Representative: Mandate Checklist for Non-EU Exporters

If you manufacture consumer products outside the EU and sell into it, you need an EU-established authorised representative unless another economic operator (an importer or EU-based branch) already covers those duties under a written mandate. Get the mandate drafted with explicit tasks mapped to Article 10, confirm the representative can actually respond to authorities in their language, and make sure their contact…

By DPP Grid Editorial reviewed by DPP Grid editorial review published 2026-09-03 Updated 2026-09-03 12 min

Overview

GPSR authorised representative mandate checklist title card

If you manufacture consumer products outside the EU and sell into it, you need an EU-established authorised representative unless another economic operator (an importer or EU-based branch) already covers those duties under a written mandate. Get the mandate drafted with explicit tasks mapped to Article 10, confirm the representative can actually respond to authorities in their language, and make sure their contact details are ready to go on your packaging or product listing.


TL;DR:

  • An authorized representative must have a mandate explicitly covering tasks like document access, information response, and safety notifications, with clear language and regular testing.
  • Most non-EU manufacturers selling directly to EU consumers or through marketplaces without an EU importer need an AR unless they have an EU branch or subsidiary capable of handling compliance duties internally.
  • The minimum duties for an AR under Article 10 include providing documentation upon request, reporting dangers, filing safety notifications, and cooperating on risk elimination, all in a specific, clear manner.
  • Centralized digital tools like product passports can speed compliance by storing and linking technical files behind QR codes, reducing delays during market surveillance requests.
  • The appointment process should involve a detailed, process-oriented mandate and a practical test of AR capabilities before full onboarding.

Table of Contents

What GPSR Means by "Authorised Representative"

Under Regulation (EU) 2023/988, an authorised representative is any natural or legal person established in the EU who has received a written mandate from a manufacturer to act on their behalf. The regulation is specific about scope: the representative can only perform the tasks named in that mandate. Nothing more.

That single detail changes how you should think about the paperwork. A mandate isn't a formality you sign and forget. It's the legal ceiling on what your representative is allowed to do when a market surveillance authority comes knocking. If the mandate doesn't mention document retrieval, your representative has no legal footing to hand over technical files, even if they wanted to help.

This is where a lot of first-time exporters get tripped up. They treat the mandate like a generic agency agreement, borrowed from a template with vague language about "representing the company's interests in the EU." That phrasing means nothing to a market surveillance officer standing at a warehouse door asking for a risk assessment.

A properly drafted mandate should cover:

  • Explicit authority to receive and respond to information requests from national authorities
  • The right to access, hold, and transmit your technical documentation
  • Authority to file Safety Business Gateway notifications on your behalf when required
  • A requirement that the representative produce the mandate itself on request, since authorities can ask to see it

Skip any of these, and you've created a gap that only surfaces during an actual incident, which is the worst possible time to discover it.

Who Actually Needs One (and Who Might Not)

Every non-EU manufacturer placing consumer products on the EU market must have a responsible person established within the EU. An authorised representative is one route to satisfy that requirement, but not the only one.

You likely need to appoint an AR if you fall into one of these categories:

  • You manufacture products outside the EU and sell directly to EU consumers through your own website
  • You sell on marketplaces without a registered EU importer taking on responsible-person duties
  • You have no EU branch, subsidiary, or in-house team based in a member state

The chain of economic operators matters here. If a genuine importer, meaning a company established in the EU that brings your product in and places it on the market, is already handling GPSR obligations, you may not need a separate AR. Some fulfilment providers also take on responsible-person duties, though most explicitly avoid it because of the liability attached.

Manufacturers with an actual EU branch sometimes skip the AR altogether and designate an internal employee instead. That works, provided the branch has the administrative capacity to handle the same duties an external AR would. The test isn't who holds the title. It's who can actually produce documentation and respond to a national authority within a reasonable window.

What Article 10 Actually Requires an AR to Do

GPSR Article 10 sets four minimum duties for every authorised representative, and they're worth understanding individually rather than as a vague bundle of "compliance tasks."

  1. Provide documentation on reasoned request. When a market surveillance authority asks for proof that a product is safe, the AR must supply it in a language that authority understands. This usually means technical files, test reports, risk assessments, and supplier declarations, not just a cover letter.
  2. Inform the manufacturer of suspected danger. If the AR has reason to believe a product poses a risk, they're obligated to tell you. This duty runs both directions. It's not a passive mailbox role.
  3. File Safety Business Gateway notifications when the manufacturer hasn't. If you've missed a reporting deadline or are unreachable, the AR is expected to step in and notify the relevant national authority directly.
  4. Cooperate on risk-elimination actions. This includes recalls, corrective notices, or any measure an authority orders to address a dangerous product already on the market.

Pro Tip: Ask a candidate AR to walk you through exactly what they'd need from you to satisfy duty one. If their answer is vague, that's a preview of how they'll perform during an actual authority request.

The documentation authorities typically request includes technical construction files, conformity declarations, batch or lot traceability records, and supplier safety declarations. If your files are scattered across email threads and supplier PDFs, your AR is only as fast as your worst filing system.

The Safety Business Gateway and When Reporting Kicks In

The Safety Business Gateway is the EU's designated web portal for notifying market surveillance authorities about dangerous products and product-related accidents. It's not optional infrastructure. It's the legally required channel.

Here's how the reporting responsibility actually splits: the manufacturer is the primary reporter. You are expected to notify authorities first if you become aware your product poses a risk. The AR's obligation is a backstop. If you haven't reported and the AR has reason to believe a product is dangerous, they must file the notification themselves.

A useful notification typically includes:

  • Product identification (model, batch, SKU, or other traceable identifiers)
  • A description of the risk and how it was identified
  • Corrective measures already taken or planned
  • Contact details for follow-up from the authority

The practical challenge is coordination timing. If your AR discovers a safety issue from a customer complaint before you do, they need a clear channel to reach you immediately, and you need a channel to confirm whether you've already filed. Building that coordination loop before an incident happens, rather than improvising during one, is what separates a functional AR relationship from a liability.

How to Appoint an AR: The Mandate and Onboarding Checklist

Draft the mandate as a task checklist, not a legal formality. Each clause should map directly to an Article 10 obligation, so there's no ambiguity about what your AR is authorized to do when a real request arrives.

  1. Task mapping. Spell out each duty (documentation access, notification authority, cooperation on corrective actions) rather than using broad language like "represent the manufacturer's interests."
  2. Document access rights. Specify what formats you'll provide (PDFs, structured data, physical samples) and how the AR retrieves them.
  3. Notification authority. State explicitly that the AR can file Safety Business Gateway notifications on your behalf, including the conditions under which they're expected to act without waiting for your sign-off.
  4. Language and translation responsibilities. Clarify who translates documents if the AR needs to submit them in a language other than English.
  5. Term and termination. Set a clear duration and exit process, since gaps in AR coverage leave your products technically noncompliant.
  6. Liability and indemnity. Address who bears cost exposure if a notification is filed late or documentation is incomplete.

Once the mandate is signed, test it before you need it. Run a simulated "reasoned request," ask your AR to produce a specific technical document within a set window, and see how they perform. Confirm their translation workflow actually works rather than assuming it does. Verify they have secure access to your traceability identifiers, not just a folder of outdated PDFs.

Pro Tip: Put the product contact address on your packaging or listing only after your AR confirms they're actively monitoring that inbox or line. A stale contact point is worse than none, because it signals a company that isn't paying attention.

What Good Operational Capacity Actually Looks Like

Commission guidance is direct about this: an authorised representative needs formal competence on paper and the practical, administrative capacity to actually use it. Language ability with the specific national authority you're dealing with matters as much as the legal appointment itself.

Before signing anyone, ask for:

  • A sample response to a mock authority request, so you can judge turnaround speed and clarity
  • Stated response-time commitments, even if informal, so you know what "prompt" means to them
  • Confirmation of which languages their team communicates in fluently, not just which they claim to support
  • Their preferred document formats, so you're not scrambling to convert files during a live request

Design your escalation workflow now: who at your company decides a product is dangerous, and who at the AR's office actually files the Safety Business Gateway notification. Pro Tip: Write this down as a one-page flowchart both teams keep on hand. Incidents move fast, and nobody reads a 40-page onboarding document while a recall clock is running.

Authorised Representative vs. Responsible Person: Where the Line Sits

An authorised representative is one specific role. A "responsible person" is the broader legal concept: whoever within the EU ensures the product complies with safety obligations, whether that's an importer, an EU-based manufacturer branch, or the AR themselves.

A manufacturer can designate their AR as the full responsible person, but that expands the AR's obligations well beyond the Article 10 minimums, sometimes into areas like conformity assessment coordination or broader market-surveillance liaison work.

Before assuming your AR covers everything a responsible person would, confirm in the mandate:

  • Whether the AR is only handling Article 10 duties or has accepted full responsible-person status
  • What additional liability or scope that expanded role creates for them, and for you
  • Whether their pricing and capacity actually match the broader responsibility they've agreed to

Where Digital Product Passports Fit Into AR Response Time

A reasoned request from a market surveillance authority is only as fast as your worst filing system. This is where centralized product data changes the equation. DPP Grid lets manufacturers store technical files, test reports, and supplier declarations against a specific product identifier, then publish that record behind a QR code that carries a permanent, traceable link.

Evidence documents organized into product record

When your AR needs a document, they're pulling from one organized source instead of chasing an email thread. Persistent product identifiers also make batch-level traceability far less painful during an incident. That said, DPP Grid organizes and centralizes your evidence. It doesn't replace the AR appointment itself, and it makes no claim to certify legal compliance on its own.

What I'd Prioritize if I Were Appointing an AR Today

Skip the boilerplate agency contract entirely. Rewrite the mandate as a checklist tied line by line to Article 10, and don't sign until every duty has a named process attached to it.

Before you commit, run one real test: a simulated reasoned request with a tight deadline. Watch how the candidate handles it. Slow or vague responses during a test are a preview of what happens during a genuine market surveillance inquiry, when the stakes are considerably higher.

Language coverage matters more than most manufacturers expect going in. An AR who covers only English is a liability the moment a request lands from an authority that expects correspondence in its own national language. And make sure your product's contact details and traceability identifiers are correct on day one, not fixed retroactively after a complaint. Keep the lines of responsibility between you and your AR explicit, in writing, before you need them in a crisis.

— Vytautas

A Practical Way to Speed Up Every AR Interaction

There are other paths to GPSR readiness. Some manufacturers rely purely on spreadsheets and shared drives, others lean entirely on their AR to chase down documents supplier by supplier when a request lands. Both work until volume or urgency exposes the cracks.

DDP Grid

DPP Grid takes a different approach: instead of your AR hunting through scattered files during a reasoned request, your technical documentation, supplier declarations, and safety records live in one place, tied to a specific product identifier and published behind a scannable QR code. When you're importing product data from Shopify, CSV, or API and using AI-assisted extraction to organize supplier documents, your AR gets a single, traceable source instead of a chain of email attachments. Human reviewers still approve every record before it publishes, so nothing goes live unverified.

If you're preparing for GPSR obligations alongside broader EU traceability expectations, start by reviewing DPP Grid's product passport platform and see how it maps to the documentation your authorised representative will eventually need to produce.

Primary Sources Worth Bookmarking

The rules covering authorised representatives sit across a handful of official documents, and it's worth reading them directly rather than relying on secondhand summaries.

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

Sources

Who is considered an authorized representative under GPSR?

An authorized representative is any EU-established natural or legal person who has received a written mandate from a non-EU manufacturer to carry out specific GPSR duties, limited strictly to what that mandate names.

Who is the responsible person for GPSR compliance?

The responsible person is whichever EU-based economic operator, an importer, an EU branch of the manufacturer, or the authorised representative, has accepted the obligation to ensure the product meets GPSR safety requirements.

Who can be appointed as an EU authorised representative?

Any natural or legal person established within the EU with the administrative capacity and language ability to handle documentation requests and notifications can be appointed, provided the appointment is formalized through a written mandate.

Does GPSR apply in the UK?

GPSR is EU legislation and governs products placed on the EU market; the UK has separate but related product safety rules, and Gov explains how the frameworks interact, particularly for Northern Ireland.

This article is operational guidance, not legal advice or certification.