← HomeREP27All categories

Websites, apps and SaaS reaching people in the EU

Data protection

In short
Representative in the Union under Article 27 GDPR, designated in writing

Who has to appoint one

Any controller or processor not established in the Union whose processing falls under Article 3(2): offering goods or services to data subjects in the Union, whether or not payment is required, or monitoring their behaviour within the Union. Offering is judged on intention, shown by things like pricing in euros, an EU language, EU delivery options, EU-targeted advertising or naming member states. Monitoring covers analytics, advertising cookies, behavioural profiling, A/B testing and device fingerprinting of users located in the Union. Processors are caught in their own right: a US hosting company processing on behalf of an EU client needs its own representative if Article 3(2) applies to it.

Thresholds and exemptions

There is no turnover, headcount or volume threshold. The only exemption, in Article 27(2), is narrow and cumulative: the processing must be occasional, must not include large-scale processing of special-category or criminal-offence data, and must be unlikely to result in a risk to rights and freedoms. Regular website analytics on EU visitors is not occasional, so in practice the exemption almost never applies to an operating business. Public authorities and bodies are separately exempt.

What must appear on the label

Not a physical label. The obligation is transparency: the identity and contact details of the representative must be given to data subjects under Articles 13 and 14, which in practice means a clearly identified paragraph in the privacy notice with the representative's name, postal address and contact channel, and a statement that data subjects may address the representative on all issues relating to processing. Burying it in a PDF or naming only a generic email is what authorities criticise.

Marketplace fields

App stores require a privacy contact and several now check that an EU representative is named where the developer is outside the Union. Enterprise procurement questionnaires and security reviews routinely ask for the designation, and its absence delays deals. Some marketplaces have begun verifying the certificate against the provider's public register.

Documentation you must hold

The written designation or mandate, defining the scope of the representation and the processing covered. The records of processing activities under Article 30, which the representative must maintain and make available to the supervisory authority on request — this is the document authorities ask for first, and its absence is a separate infringement. Evidence of the transfer mechanism where data leaves the Union, such as the standard contractual clauses under Decision (EU) 2021/914 with a transfer impact assessment. The privacy notice as published, dated.

Standards and testing

Not applicable in the product-testing sense. What is assessed instead is documentation and demonstrable accountability: whether the record of processing is accurate, whether the legal bases hold, whether consent for cookies was collected before tracking began, and whether data subject requests are answered within one month.

Language requirements

Article 12 requires information to be provided in clear and plain language, and the EDPB expects the representative to be able to communicate with data subjects and authorities in the language of the member states where the data subjects are. A desk answering only in English is a weakness where the offering targets, say, France, Germany or Poland.

When it applies

The designation must be in place before the processing that triggers Article 3(2) begins. Appointing a representative after a complaint does not cure the earlier period, and supervisory authorities have imposed fines specifically for the period during which no representative existed. Data subject requests forwarded by the representative run on the Article 12(3) clock: one month from receipt by the controller, extendable by two months for complex requests if the data subject is told within the first month.

How long records are kept

The designation and the Article 30 records for as long as the representation lasts, plus evidence of the period covered afterwards, because a later investigation will ask when the mandate began and ended. Records of requests received and forwarded should be kept as proof that the representative did its job.

What happens if you do not comply

Up to €10 million or 2% of total worldwide annual turnover for failing to designate. The EDPB treats the absence of a representative as an infringement in its own right, independent of any other breach, and several authorities have fined on that basis alone. Beyond the fine, the practical exposure is that a complaint about anything else — cookies, a data subject request, a breach — surfaces the missing designation immediately, because the first thing an authority looks for is who it can address.

Who enforces it

The supervisory authority of any member state where the data subjects are located. There is no one-stop-shop for controllers outside the Union: any of the 27 authorities can act, which means a French complaint goes to the CNIL, a German one to the relevant Landesbeauftragte, and both can proceed in parallel.

Where the boundary lies

Appointing a representative satisfies one article; it does not make the rest of the processing lawful, and it does not shield the controller, because Article 27(5) preserves legal actions against the controller itself. A representative established in one member state covers the whole Union and the EEA states of Iceland, Norway and Liechtenstein. Article 27 GDPR, Article 13 DSA, Article 16 GPSR and the CRA representative are four separate appointments: holding one does not satisfy the others, even where the same provider holds them all. The UK requires its own representative under the UK GDPR, since Brexit, and an EU designation does not cover it.

Questions we are asked

Does the representative become liable for our processing?
The representative is the point of contact and can be addressed by authorities and data subjects in addition to, or instead of, the controller. Responsibility for the processing itself remains with the controller or processor under Article 27(5). What the representative is directly accountable for is maintaining the record of processing and cooperating with the authority.
We already have a DPO — is that enough?
No. They are different roles with different legal bases. A DPO advises and monitors internally and can be located anywhere; an Article 27 representative must be established in the Union and exists so that authorities and data subjects have someone to address there.
We only use Google Analytics on EU visitors — does that count?
Yes. Monitoring behaviour of data subjects in the Union brings you within Article 3(2), and analytics is the textbook example the EDPB gives. It also brings the ePrivacy consent requirement, which is a separate obligation from the GDPR one.
Can our EU law firm or reseller act as representative?
Anyone established in the Union can, provided they accept a written mandate and can actually perform the role: receive requests, hold the Article 30 records and cooperate with authorities. The risk with an ad hoc arrangement is that nobody is monitoring the mailbox when a supervisory authority writes.
EU representative · from €290 / year

Who signs for you
EU representative Europe Services, SE — Na Čečeličce 425/4, Smíchov, 150 00 Praha 5, Czech Republic
UK representative REP27 LTD — Unit 82a James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom

Talk to usCheck your category