The EU Terrorist Content Online Regulation is in force. Ensure your compliance within the hour.

Your official EU legal representative under Article 17, ready to receive removal orders and act on them inside the one-hour window the Regulation allows.
Regulation (EU) 2021/784 · Art. 17
1 hour
to act on a removal order
In force
applicable since 7 June 2022 — the clock is already running
4%
of global annual turnover, maximum penalty

A one-hour clock, and someone has to be watching it

Regulation (EU) 2021/784 lets a competent authority in any Member State order the removal of terrorist content from hosting services offered in the EU. Article 17 requires providers without a main establishment in the EU — the head office where principal financial functions and operational control are actually exercised — to designate, in writing, a legal representative equipped with the powers and the resources to receive and enforce those orders.

Who has to appoint a Legal Representative

Hosting service providers

You store information supplied by content providers at their request and make it available to the public — typically for remuneration, at a distance, by electronic means, per Directive (EU) 2015/1535.

No EU main establishment

Your head office, where principal financial functions and operational control are exercised, sits outside the EU.

Content disseminated for educational, journalistic, artistic or research purposes, or to prevent or counter terrorism, falls outside the definition of terrorist content. That shapes what an order can target — not whether you need a representative.

An unanswered removal order is a compliance failure.

Why you must act now: risks of non-compliance

TCOR combines the shortest response window in EU digital regulation with a formal, public designation duty — both have to be in place before the first order arrives.
4%

of the provider's global annual turnover — the maximum penalty for non-compliance.

1 hour

to act on a removal order.

In writing

the designation must be formal, registered with the competent authority and made public.

Three steps to a
compliant appointment

01

Initial consultation & assessment

We review how your hosting service is offered in the EU and confirm exactly what representation you need.

02

Official appointment

You sign a mandate agreement and complete onboarding digitally — your designation is registered with the competent authority.

03

Ongoing compliance & support

Removal orders are received and acted on inside the one-hour window, with documentation kept and forwarded to your team.

TCOR representation is delivered by EDSR, EDPO’s specialist entity

EDSR is EDPO’s Brussels-based sister company, dedicated to TCOR, DSA and e-Evidence representation. Same group, same standards — one contract, one point of contact for orders across the EU and EEA.
Brussels & Dublin FR · NL · EN

Onboarding, pricing and the full FAQ are handled on edsr.eu.

Your questions, answered

  • $The General Data Protection Regulation (GDPR) – EU & UK
  • $The Swiss Federal Act on Data Protection (FADP)
  • $The AI Act
  • $The NIS2 Directive (NIS2)
  • $The Data Governance Act (DGA)
  • $The Digital Services Act (DSA)

The Regulation on addressing the dissemination of terrorist content online — TCOR (referring strictly to EU Regulation 2021/784, and not Total Cost of Risk or other acronyms) — addresses the misuse of hosting services for terrorist purposes to ensure public security across the Union. In accordance with the Regulation, any identified terrorist content must be promptly removed within one hour on online platforms providing services in the EU.

To ensure full compliance with EU TCOR mandates, affected hosting service providers must fulfill the following statutory duties.

Mandatory Legal Representation: Non-EU hosting providers offering services in the EU must officially designate a legal representative in writing within an active Member State.

1-Hour Removal Enforcement: The designated representative must receive, process, and enforce official authority removal orders within the mandatory 1-hour deadline.

Audit-Ready Documentation: Providers must maintain detailed records of their compliance efforts to demonstrate transparency. A TCOR legal representative manages this documentation effectively, ensuring all correspondence and actions are audit-ready at any time.

Non-Compliance Penalties: Failure to comply carries severe financial risks of up to 4% of the provider’s global annual turnover.

The legal representative of hosting service providers ensures effective communication with Member States’ competent authorities, including receiving, complying with, and enforcing removal orders and decisions related to the TCOR. Hosting service providers must equip their legal representative with the necessary powers and resources for efficient cooperation and to comply with such orders and decisions.

While this role doesn’t create an establishment in the EU, designating a legal representative confers jurisdiction on the Member State where the representative is located. In cases where providers do not designate a legal representative, jurisdiction lies with all Member States.

Full FAQ, pricing and onboarding details are on EDSR’s TCOR page →

Still not sure whether you need to appoint a TCOR Legal Representative?