DGA-RDAO Legal Representative (Article 19(3))

Service Overview

Are you a non-EU not-for-profit organisation seeking recognition as a data altruism organisation in the European Union?

Article 19(3) of the EU Data Governance Act requires recognised data altruism organisations (RDAOs) not established in the European Union but offering services within it to designate, in writing, a legal representative in one of the Member States where they collect data on the basis of data altruism. The legal representative is the formal counterparty for the national competent authority that supervises RDAOs in the Member State of designation, and the contact details published in the relevant national public register of RDAOs are those of the representative.

Data altruism, as defined in the DGA, is the voluntary sharing of data by data subjects (in respect of personal data) or data holders (in respect of non-personal data), without seeking or receiving a reward beyond compensation related to the costs of making the data available, for objectives of general interest — such as scientific research, healthcare, or addressing public emergencies. RDAO recognition is an opt-in regulatory status: an organisation must apply for recognition through the national competent authority and must remain a not-for-profit legal entity that processes data exclusively for general-interest purposes.

Service Detail

What this service covers

Our focus

Established in Ireland for cross-border RDAO representation

Lionheart provides Article 19(3) representation through Lionheart Squared (Europe) Limited, our Dublin-based EU entity. Under Article 19(3) DGA, the legal representative's establishment determines which national competent authority supervises your RDAO for DGA purposes — Ireland in our case. Your contact details on the relevant national public RDAO register will reflect Lionheart's Dublin address, with a dedicated representative email address.

Built for the not-for-profit posture of data altruism

The RDAO category is structurally different from a commercial data intermediation business. RDAOs are not-for-profit by definition, and the regulatory expectation reflects that — recognition is a privilege granted by the competent authority, conditional on continuing compliance with the not-for-profit and general-interest requirements. Our service is calibrated to that reality, with pricing that reflects the not-for-profit profile and an approach to authority correspondence that supports the trust posture RDAOs need to maintain. Established in Ireland for cross-border RDAO representation Lionheart provides Article 19(3) representation through Lionheart Squared (Europe) Limited, our Dublin-based EU entity. Under Article 19(3) DGA, the legal representative's establishment determines which national competent authority supervises your RDAO for DGA purposes — Ireland in our case. Your contact details on the relevant national public RDAO register will reflect Lionheart's Dublin address, with a dedicated representative email address.

Built around the duties Article 19(3) actually imposes

As your legal representative, we accept that we may be addressed in addition to or instead of you by competent authorities on RDAO-related matters, and that we may receive written instructions from you on RDAO-related obligations and tasks. Our duties under the mandate are concrete: promptly inform you of correspondence received from competent authorities, cooperate with those authorities by providing copies of the mandate, the underlying agreement and related materials concerning your RDAO compliance, and permit you to disclose our appointment and approved contact details for publication.

Non-personal data transfer safeguards

RDAOs are required to fulfil the safeguards and equivalent measures determined by the European Commission for non-personal data transferred outside the Union — including any adequacy decisions and model contractual clauses adopted for non-EU recipients. The substantive obligation to fulfil these safeguards remains with you as RDAO; our role is to act as the formal addressee for any competent-authority correspondence concerning those safeguards, and to support the documentation flow that demonstrates compliance.

Forward-positioned for the Digital Omnibus

As with the DISP framework, the proposed Digital Omnibus for Data (COM(2025) 837) is expected to migrate the RDAO representative obligation from Article 19(3) DGA into Article 32e(2) of the amended Data Act, anticipated 2027 or 2028.

Our services include

Formal designation

Acting as your EU legal representative under Article 19(3) DGA (or Article 32e(2) of the Data Act once the Digital Omnibus is enacted), by written mandate, with clearly documented scope and procedures.

Ireland-based contact details

Lionheart's Dublin address and a dedicated representative email address, available for publication on the relevant national public RDAO register and for inclusion in your RDAO-facing disclosures.

Authority liaison

Acting as the formal contact point for the Irish competent authority designated for RDAO supervision under the DGA, and for cross-border cooperation with competent authorities in other Member States where you collect data.

Authority correspondence handling

Prompt receipt, logging and forwarding of regulatory correspondence; provision of mandate and agreement copies to competent authorities on request, in cooperation with you.

Registration support

Practical support with the contact-information component of your RDAO recognition application and registration on the relevant national public register, and acting as the formal addressee for the competent authority's correspondence on recognition.

Non-personal data safeguard correspondence

Acting as the formal addressee for competent-authority correspondence concerning non-personal data transfer safeguards under the DGA, supporting the documentation flow back to your organisation.

Coordinated mandates

Single-relationship handling where RDAO obligations sit alongside other Lionheart representative services — under one engagement and one coordinated escalation path.

Legal basis: Article 19(3), EU Data Governance Act (Regulation (EU) 2022/1724); transitional reference to Article 32e(2) of the Data Act under proposed Digital Omnibus COM(2025) 837.

Substantive obligations remain with you

The legal representative is a statutory contact point and support function, not a substitute for the RDAO itself. You remain responsible and accountable for fulfilling all RDAO obligations — including maintaining your not-for-profit status, processing data exclusively for general-interest purposes, fulfilling the non-personal data transfer safeguards determined by the European Commission, and registering with the relevant national public register of recognised data altruism organisations.

Recognition is an opt-in status

RDAO status is granted by application to the national competent authority and is conditional on continuing compliance. Loss of recognition removes both the regulatory benefits and the representative obligation — but does not retroactively affect mandates held during the period of recognition.

Penalty regime

Penalties for failure to comply with the DGA representative obligation are determined by Member State law under Article 45 DGA and have not been harmonised at EU level. The applicable Irish penalty framework is set out in the master representative services agreement, with the calibrated indemnity provisions disclosed before any mandate is signed.

Get started

Not sure if you are in scope?

Use the guided self-check tool to map which representative obligations may apply.