EU representative
An EU representative under Article 27 GDPR is a natural or legal person established in the Union that controllers and processors without an EU establishment must appoint in writing, so that data subjects and supervisory authorities have a contact point inside the EU.
The obligation follows from the marketplace principle in Article 3(2) GDPR: an organisation with no establishment in the Union that offers goods or services to people in the EU, or monitors their behaviour, falls under the GDPR – and must additionally appoint a representative in the Union under Article 27(1) GDPR. The representative has to be established in one of the Member States where the data subjects concerned are located (Article 27(3) GDPR), and the appointment must be made in writing (Article 27(4) GDPR), normally through a mandate agreement covering tasks, escalation paths, availability and liability. Article 27(2) GDPR provides narrow exemptions: processing that is occasional, does not include large-scale processing of special categories of data or of criminal conviction data, and is unlikely to result in a risk to rights and freedoms – plus a general carve-out for public authorities and bodies. The European Data Protection Board reads this exemption strictly in its Guidelines 3/2018 on the territorial scope: all three conditions must be met cumulatively.
The representative acts as the point of contact in addition to, or instead of, the controller or processor – both for supervisory authorities and for data subjects exercising their rights under Articles 15 et seq. GDPR (Article 27(4) GDPR). It must be genuinely reachable, usually in the language of the relevant Member State, and must cooperate with the controller in handling requests. It also carries a documentation duty of its own: under Article 30(1) and (2) GDPR the representative maintains a record of processing activities and makes it available to the supervisory authority on request. Identity and contact details of the representative must appear in the privacy information under Article 13(1)(a) and Article 14(1)(a) GDPR. A representative is not a data protection officer: the two roles differ in tasks, independence and conflict-of-interest rules, and should not be held by the same person.
On liability, Article 27(5) GDPR states that appointing a representative is without prejudice to legal action against the controller or processor themselves – the appointment discharges no one. Conversely, Recital 80 indicates that the representative may be subject to enforcement proceedings where the controller fails to comply, and the EDPB takes the view in Guidelines 3/2018 that this can include fining procedures. How far a representative's own exposure to fines or damages actually reaches remains contested in scholarship and practice and has not been conclusively settled by the courts, which is why well-drafted mandate agreements deal explicitly with indemnities and insurance. What is beyond doubt is that the duty itself is enforceable: an infringement of Article 27 GDPR falls under Article 83(4)(a) GDPR, with fines of up to 10 million euros or 2 % of total worldwide annual turnover. In practice, parallel obligations should be checked as well – the separate UK representative under Article 27 UK GDPR since Brexit, and representative duties for providers without a Union establishment under NIS2 and the Digital Services Act.
Legal Basis
Article 27 GDPR in conjunction with Articles 3(2), 13(1)(a), 14(1)(a), 30(1) and (2) and 83(4)(a) GDPR; Recitals 23, 24 and 80; EDPB Guidelines 3/2018 on the territorial scope of the GDPR
Practical Example
A US SaaS vendor sells a project management app with a German-language interface, euro pricing and behavioural usage tracking to customers in Germany, Austria and France, but has no EU establishment. The data protection coordinator at its German distributor concludes that Article 3(2) GDPR applies and that the Article 27(2) exemption is unavailable because monitoring is continuous rather than occasional. She therefore has a representative established in Germany – the Member State with the largest share of data subjects – appointed in writing, agrees response deadlines for forwarded data subject requests, a jointly maintained Article 30 record of processing activities and indemnity and insurance clauses, and adds the representative's identity and contact details to the privacy notice and to the data processing agreements. Twelve months later she tests whether the contact point actually works by sending a test request to the published representative address.