Skip to main content
Data Protection / GDPR

EU representative

An EU representative under Article 27 GDPR is a natural or legal person established in the Union that controllers and processors without an EU establishment must appoint in writing, so that data subjects and supervisory authorities have a contact point inside the EU.

The obligation follows from the marketplace principle in Article 3(2) GDPR: an organisation with no establishment in the Union that offers goods or services to people in the EU, or monitors their behaviour, falls under the GDPR – and must additionally appoint a representative in the Union under Article 27(1) GDPR. The representative has to be established in one of the Member States where the data subjects concerned are located (Article 27(3) GDPR), and the appointment must be made in writing (Article 27(4) GDPR), normally through a mandate agreement covering tasks, escalation paths, availability and liability. Article 27(2) GDPR provides narrow exemptions: processing that is occasional, does not include large-scale processing of special categories of data or of criminal conviction data, and is unlikely to result in a risk to rights and freedoms – plus a general carve-out for public authorities and bodies. The European Data Protection Board reads this exemption strictly in its Guidelines 3/2018 on the territorial scope: all three conditions must be met cumulatively.

The representative acts as the point of contact in addition to, or instead of, the controller or processor – both for supervisory authorities and for data subjects exercising their rights under Articles 15 et seq. GDPR (Article 27(4) GDPR). It must be genuinely reachable, usually in the language of the relevant Member State, and must cooperate with the controller in handling requests. It also carries a documentation duty of its own: under Article 30(1) and (2) GDPR the representative maintains a record of processing activities and makes it available to the supervisory authority on request. Identity and contact details of the representative must appear in the privacy information under Article 13(1)(a) and Article 14(1)(a) GDPR. A representative is not a data protection officer: the two roles differ in tasks, independence and conflict-of-interest rules, and should not be held by the same person.

On liability, Article 27(5) GDPR states that appointing a representative is without prejudice to legal action against the controller or processor themselves – the appointment discharges no one. Conversely, Recital 80 indicates that the representative may be subject to enforcement proceedings where the controller fails to comply, and the EDPB takes the view in Guidelines 3/2018 that this can include fining procedures. How far a representative's own exposure to fines or damages actually reaches remains contested in scholarship and practice and has not been conclusively settled by the courts, which is why well-drafted mandate agreements deal explicitly with indemnities and insurance. What is beyond doubt is that the duty itself is enforceable: an infringement of Article 27 GDPR falls under Article 83(4)(a) GDPR, with fines of up to 10 million euros or 2 % of total worldwide annual turnover. In practice, parallel obligations should be checked as well – the separate UK representative under Article 27 UK GDPR since Brexit, and representative duties for providers without a Union establishment under NIS2 and the Digital Services Act.

Legal Basis

Article 27 GDPR in conjunction with Articles 3(2), 13(1)(a), 14(1)(a), 30(1) and (2) and 83(4)(a) GDPR; Recitals 23, 24 and 80; EDPB Guidelines 3/2018 on the territorial scope of the GDPR

Practical Example

A US SaaS vendor sells a project management app with a German-language interface, euro pricing and behavioural usage tracking to customers in Germany, Austria and France, but has no EU establishment. The data protection coordinator at its German distributor concludes that Article 3(2) GDPR applies and that the Article 27(2) exemption is unavailable because monitoring is continuous rather than occasional. She therefore has a representative established in Germany – the Member State with the largest share of data subjects – appointed in writing, agrees response deadlines for forwarded data subject requests, a jointly maintained Article 30 record of processing activities and indemnity and insurance clauses, and adds the representative's identity and contact details to the privacy notice and to the data processing agreements. Twelve months later she tests whether the contact point actually works by sending a test request to the published representative address.

FAQ

Whenever a controller or processor without an establishment in the Union is caught by Article 3(2) GDPR – that is, when it offers goods or services to people in the EU or monitors their behaviour. Only public authorities and genuinely low-risk cases are exempt: processing that is occasional, involves no large-scale processing of special categories of data and is unlikely to result in a risk to data subjects. The EDPB requires all three conditions to be satisfied at the same time.
Article 27(5) GDPR makes clear that the appointment does not shield the controller or processor from legal action. Recital 80 and EDPB Guidelines 3/2018 go further and assume that the representative can itself be subject to enforcement measures. The precise scope of any personal exposure to fines or damages is still disputed, so mandate agreements should address indemnities, cooperation duties and insurance cover explicitly.
It is not advisable. Under Article 38(3) GDPR the data protection officer must act free from instructions and without conflicts of interest, whereas the representative acts on behalf of and in the interest of the controller and follows its instructions. The EDPB regards combining both roles in one person as problematic, so the two functions should be staffed separately and listed separately in the privacy notice.

How preeco supports you

Learn how our software supports you with this topic.

Learn more