
REP27 · Article 27 · Designation letter
Article 27(1) · the written mandate
Article 27(1) asks for the representative to be designated in writing, and that single phrase generates a steady traffic in templates. A template is fine as a starting structure and worthless as a compliance artefact, because the document is not the obligation: the acceptance is. A letter naming a company that never signed it designates nobody at all.
PartiesMandateScopeRecordsTerm

Most templates circulating online contain the first three and stop. The fourth is what a supervisory authority asks about after an incident, and the fifth is what protects you when a provider disappears or you decide to move.

| Clause | What to look for | Warning sign |
|---|---|---|
| Acceptance of the role | Explicit reference to Article 27(4) | "Services" language with no acceptance |
| Liability | Confirmation that Article 27(5) leaves it with you | A promise to assume your liability |
| Article 30 record | Who holds it and how it reaches authorities | No mention of records at all |
| Response times | A stated turnaround for forwarding requests | Best-efforts wording with no timeframe |
| Termination | Handover of requests and records | Silence, or automatic renewal without notice |
| Languages | Which languages the desk answers in | English only, with EU-wide claims |
Within 24 hours of a completed form, by Europe Services, SE in Prague, active since 2018.
Issued with a verification code that anyone can check on our site, including your clients and auditors.
You paste the supplied Article 13(1)(a) paragraph into your privacy notice. This is the step that makes the designation useful to a data subject.
Your Article 30 record is assembled from the onboarding form and kept available to authorities.
Requests arriving at the published address are logged, acknowledged and forwarded to you the same working day.
If you are drafting your own, this is the order that reads correctly to a supervisory authority and to a buyer's legal team.
Full legal names, registration numbers and addresses, and whether the appointing party acts as controller, as processor, or as both for different processing.
An express statement that the representative is designated under Article 27(1) and accepts the role of point of contact under Article 27(4).
The processing covered, the categories of data subjects, and the Member States in which they are located — which is what evidences Article 27(3).
Who maintains the Article 30 record, how it is made available, and the turnaround for forwarding requests.
Duration, renewal, notice period, and what happens to pending requests and records when it ends.
An express acknowledgement that Article 27(5) leaves proceedings against the controller or processor unaffected.
The mandate is private between the parties. What has to be public is narrower and specific, and confusing the two is how companies end up publishing a contract or publishing nothing at all.
The identity and contact details of the representative, in the privacy notice, under Article 13(1)(a). Name, postal address, and a working email is the practical minimum.
The signed mandate, the certificate and the record of processing activities. Produced on request, not posted on the website.
The certificate or its verification code, which is usually all a buyer or auditor actually wants.
Commercial terms and pricing. They tell a data subject nothing and tell your competitors everything.
Four appear repeatedly: a designation naming a brand rather than a legal entity; a scope so broad it covers processing the representative was never told about; no mention of the Article 30 record; and automatic renewal with no notice, which is how designations lapse without anyone deciding to end them.
Keep it. Continuity of designation is useful evidence, and there is no benefit in destroying the record of a period during which you were covered. When you move provider, sign and publish the new designation first, then terminate the old one, so the published contact point is never stale for a single day.
The mandate can be in any language the parties agree on, and there is no requirement to translate it for the Union. What does have to work in several languages is the published identity and the desk behind it: a data subject in Poland is entitled to address the representative in Polish, and the contract language has no bearing on that. Companies sometimes translate the mandate at expense and leave the desk operating in English only, which is precisely the wrong way round.
Whatever both parties read. English is normal and adds nothing to compliance.
In each language version of your privacy notice, with the same entity and address.
Ours answers in eight, which covers the markets most of our clients actually sell into.
Issued in English with a code that resolves regardless of the language of the person checking it.


Yes. Nothing requires a specific form or a specific drafter. What it requires is that an entity established in the Union signs it and accepts the role.
No. Article 27(1) asks for writing, not for notarisation, and no supervisory authority has required more.
No. Any language works between the parties. What has to be published, under Article 13(1)(a), is the identity and contact details of the representative.
Each controller or processor needs its own designation. A group letter listing entities is workable only if each entity is named as a party.
The same document, with the roles described accurately. Article 27 applies to processors and the mandate should say which processing it covers.
Specific enough for the representative to answer questions about it. Categories of data subjects, purposes and the Member States involved is the practical level.
It should identify the representative's registered address, which is what establishes compliance with Article 27(3).
No. There is no register. You keep it, publish the representative's identity, and produce the document if asked.
No, and a clause claiming to do so is void against Article 27(5). Its presence tells you what the rest of the agreement is worth.
A year, aligned with your renewal cycle. Anything shorter creates administrative noise; anything longer without a review tends to lapse unnoticed.
It terminates on its terms. Sign the new designation and publish it before terminating the old one, so there is never an uncovered day.
Yes. The UK GDPR is a separate instrument and requires its own designation with a UK-established representative.
Yes. Ask and we send the full text. A provider unwilling to show the mandate before signature is telling you something.
Related: how to verify a representative · the privacy notice wording
Countersigned within 24 hours, with a certificate carrying a verification code, the Article 30 record held for you and a request desk in eight languages.
See the plans