RED cybersecurity, the AI Act, the Cyber Resilience Act, GDPR and the new Toy Regulation: five separate deadlines, one liability — yours. We build the complete file, and we hold it at the disposal of the authorities in your name.
Two steps are already behind us. The next one is close.
If your brand is on the product, you are the manufacturer under EU law — even when the device ships from a factory in Shenzhen and the model runs on an Asian cloud.
The market surveillance authority calls you. Amazon or your distributor chases you. And your company carries the fine.
An internet-connected toy that talks, films or locates a child is class I. Self-assessment is only possible where harmonised standards cover the whole product. Otherwise a third party assesses it.
Every text provides for one role: the authorised representative established in the Union, appointed by written mandate, who keeps the declaration and the technical file at the disposal of the authorities for ten years and answers them. Its name goes on the product. That is the role we hold — with the file we built.
Factories supply EN 71, EN 62115, CE, RoHS, REACH, sometimes ASTM. Those documents cover the toy and its materials: mechanical safety, chemistry, flammability.
The gap is invisible when you place the order. It shows up the day a distributor, a marketplace or an authority asks for the Declaration of Conformity.
Where your product stands, law by law.
You have a written list of what's missing, sorted by deadline, with what each gap costs if left untreated.
The complete technical file: product and firmware analysis, factory documentation read including in Chinese, EN 18031 assessment, AI Act transparency, children's data, CRA readiness, EU Declaration of Conformity.
The file is complete and holds up — ready for a request from Amazon, a distributor or an authority.
Laboratory testing. We scope it, order it from a notified body, and fold the results into the file.
We become your EU authorised representative: your file kept at the disposal of the authorities for ten years, our name on your product, and CRA monitoring — from September 2026, an actively exploited vulnerability must be reported within 24 hours.
Surveillance of your product's components, a reporting procedure ready before you need it, answers to the authorities in your name, and a file kept current as your product and the texts evolve.
I build product compliance files for European sellers: general product safety, extended producer responsibility, marketplace account compliance. I read factory technical documentation in Chinese.
Not a law firm, not a test lab. The person who assembles the file, makes both ends of the chain talk to each other — the factory and the European text — and hands you a document that holds up under a request. Then holds it in your name, as your authorised representative.
If the answer is "nobody" or "I don't know", let's spend fifteen minutes on it.