General Product Safety Regulation
The GPSR (Regulation (EU) 2023/988) requires an EU based responsible person for consumer products placed on the EU market, and marketplaces such as Amazon and eBay won’t let you list without one.
CE marking support, EU and GPSR representation, and secure technical documentation hosting for manufacturers selling into the EU.
Three instruments now shape market access for manufacturers outside the EU. Two are already in force, and both require someone established inside the Union. The third replaces the machinery regime in January 2027.
The GPSR (Regulation (EU) 2023/988) requires an EU based responsible person for consumer products placed on the EU market, and marketplaces such as Amazon and eBay won’t let you list without one.
Regulation (EU) 2019/1020, Article 4, requires an economic operator established in the EU for most CE marked goods. Sell directly from outside the Union and you must appoint an EU Authorised Representative.
Regulation (EU) 2023/1230 replaces the long standing Machinery Directive 2006/42/EC, a fresh conformity regime, with digital documentation and cybersecurity in scope. Plan the transition now.
EU law is clear: most products can only be placed on the EU market if there is an economic operator established in the Union who is responsible for them. A company based outside the EU doesn’t qualify.
So manufacturers outside the EU selling directly must appoint an EU Authorised Representative. Since the GPSR took effect, that EU presence requirement reaches almost every consumer product, not only CE marked goods, and online marketplaces now demand it before you can list.
Without an operator established in the Union, such a product cannot lawfully be placed on the EU market. Polararc is that fixed point.
Representation, compliance support and documentation hosting, under one accountable relationship.
We act under written mandate, named on your Declaration of Conformity and on your product, and your single point of contact with the authorities.
Learn more → 02Directive scoping, gap analysis, standards mapping, Declaration of Conformity drafting and technical file structure, giving the route to a defensible CE mark.
Learn more → 03Your DoC, technical file, test reports and risk assessments held in a secure, version controlled repository, retained and retrievable the moment an authority asks.
Learn more →Answer four questions about where you are established and what you place on the EU market, and get back the specific obligations that catch you, with the regulation and the date against each one. No sign up to see the result.
An Authorised Representative carries real legal responsibility. We treat it that way, reading your technical file, not just lending an address.
We read your technical file, not just your cover letter, and tell you what’s missing.
A single partner for representation, CE support and hosting, and one number for the authorities.
Documentation organised and retained the way market surveillance authorities expect to receive it.
GPSR today, Cyber Resilience Act reporting since September 2026, and the Machinery Regulation from January 2027.
Northern Ireland stays under EU rules through the Windsor Framework, so your EU appointment already reaches it. No separate arrangement needed.
When an authority comes calling, the clock matters. We answer, and we have the file ready.
Short notes on the rules that move EU market access, written for the people who have to act on them.
Since 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents under Article 14 of Regulation (EU) 2024/2847. The Single Reporting Platform opened on the same date, and one notification reaches both the CSIRT and ENISA.
The clock runs from the moment you become aware, so registering on the platform is a job for now rather than for the middle of an incident.
Regulation (EU) 2023/1230 takes over from Directive 2006/42/EC with no transitional period in which both apply. Digital documentation and cybersecurity come into scope, and some products move into the categories requiring notified body involvement.
Technical files built to the old directive need to be reworked before the date, not after it.
The remaining obligations of Regulation (EU) 2024/2847 apply from 11 December 2027, including the essential cybersecurity requirements, conformity assessment and CE marking for products with digital elements.
A product already carrying a CE mark on other grounds will need the cybersecurity requirements folded into the same technical file and the same Declaration of Conformity.
Manufacturing in the US, the UK, Asia or beyond and selling into the EU? Let’s set up your representation.