Article 27 against Article 37
Data protection representative or DPO? They are not the same job
The two get mixed up constantly, including in contracts drafted by people who should know better. One is a contact point in Europe for a company that has none. The other is an internal adviser who watches how you handle data. You can need one, the other, both, or neither — and each combination is common.
What triggers each obligation
The confusion starts here, because the two triggers have nothing to do with each other. One is about where you are. The other is about what you do.
You need a representative when…
You are established outside the Union and you offer goods or services to people here, or monitor their behaviour. Size does not matter. A two-person company selling an app to Germany needs one; a thousand-person company selling only in Brazil does not.
You need a DPO when…
You are a public authority, or your core activity is large-scale regular monitoring, or you process special categories at scale. Location does not matter. A German hospital needs one; a German bakery does not.
Which is why the four combinations all exist in practice: a US analytics firm needs both, a US brochure site needs only a representative, a French insurer needs only a DPO, and a French bakery needs neither.
Side by side
| Representative (Art. 27) | DPO (Art. 37–39) | |
|---|---|---|
| Purpose | To be reachable in the Union | To advise and monitor compliance |
| Direction | Outward: authorities and individuals come to them | Inward: your staff go to them |
| Location | Must be established in a member state | Anywhere, including outside the EU |
| Independence | Acts on your mandate | Must not receive instructions on how to do the task |
| Conflict of interest | Not an issue: it is a contracted role | Cannot also decide the purposes of processing |
| Published where | Privacy notice, reachable by data subjects | Privacy notice, and notified to the authority |
| Notified to a regulator | No filing required | Contact details must be communicated |
| Can be the same person | Strongly discouraged: the representative may be addressed instead of you, which sits badly with the DPO’s independence | |
| Typical cost | A few hundred euros a year | Part of a salary, or a monthly retainer |
What each one actually does on a Tuesday
Descriptions from the regulation are abstract. Here is the ordinary week.
The representative
An email arrives from a person in Spain asking what data you hold. It arrives at the representative’s address because that is what the privacy notice says. The representative logs it, tells you the same day, keeps the record of processing available, and stays in the thread until the request is closed.
The DPO
Your product team wants to add session recording. The DPO asks what the lawful basis is, whether a balancing test exists, and whether the vendor is a processor. Then writes it down, because the point of the role is that someone can show the reasoning later.
The mistakes we see in real contracts
Buying a DPO to satisfy Article 27
A consultancy sells “an EU DPO” to a company outside the Union that had no DPO obligation at all, and the Article 27 gap stays open. Expensive, and it solves the wrong problem.
Naming the representative as DPO
It saves a line in the notice and creates a contradiction: the representative can be addressed instead of the controller, while the DPO must be independent of it.
Assuming a DPO covers presence
A DPO outside the EU is perfectly lawful and gives European authorities nobody to write to. The representative exists precisely to fill that hole.
How to word both in your privacy notice
They belong in the same section and must be distinguishable. The failure mode is a single line naming one person for both, which tells a reader nothing about who to write to.
EU representative under Article 27 GDPR: Europe Services SE, Na Cecelicce 425/4, Smichov, 150 00 Praha 5,
Czech Republic. Data subjects may contact the representative at info@gdprrepresentative.com regarding the
processing of their personal data.
Data protection officer: [name or role], [email]. Appointed under Article 37 GDPR.
If you have no DPO obligation, leave the second line out entirely. Naming one you do not have creates a duty you did not need, because once published, people rely on it.
Questions people send us
We have a DPO. Do we still need a representative?
Yes, if you are established outside the Union and target people here. The two obligations are independent and the DPO does not create an EU point of contact.
Can our representative also act as our DPO?
We do not offer it. The representative may be addressed in place of the controller, and the DPO must be free of instructions on how to perform the task. Combining them weakens both.
Does appointing a representative mean we must appoint a DPO?
No. The DPO test depends on your activity, not on where you are. Most companies that need a representative have no DPO obligation at all.
Do we have to tell an authority who our representative is?
There is no filing. The name goes in your privacy notice and is given on request. The DPO’s contact details, by contrast, must be communicated to the supervisory authority.
Can the DPO sit outside the EU?
Yes. Nothing in Article 37 requires establishment in the Union, which is exactly why it cannot substitute for the representative.
Need the representative, not the DPO?
That is the usual answer for a company outside the Union. From €290 for the first year, issued the same working day.
See the plans How the appointment works