Appoint us
Compliance team working out which data protection role their company needs

REP27 · Roles · Data protection representative

Article 27 · Articles 37-39 · terminology

Data protection representative: five roles, one name.

Nothing in the GDPR is called a data protection representative. The phrase is used in client questionnaires, procurement forms and job titles to mean at least five different things, and buying the wrong one costs both money and time. This page separates them, says who can lawfully hold each, and gives you a way to work out which one the person asking actually wants.

Article 27DPOUK representativeLegal representativeProcessor

See the plans   Ask a question

The five roles, side by side

Five roles that are all called a data protection representative, compared
Five roles that are all called a data protection representative, compared

Only the first and third are appointments a provider can sell you. The second is a function, the fourth belongs to company law and the fifth is a contract.

How to tell which one is being asked for

What the form saysWhat it almost always meansWhat to send
"EU representative under Article 27"The designationCertificate and privacy notice wording
"Data protection representative in the EU"The sameThe same
"Your DPO contact"The internal functionName and email of the DPO, if you have one
"Representative for the UK"UK GDPR appointmentThe UK certificate
"Legal representative"Who signs the contractCompany registration extract
"Authorised representative"Product safety, not dataThe Article 16 designation
When a questionnaire is ambiguous, answer with both: the Article 27 certificate and one sentence saying whether a DPO exists. It closes the thread in one exchange.

Article 27 representative and DPO: the real differences

Who must have one

The representative: controllers and processors outside the Union caught by Article 3(2). The DPO: organisations meeting the Article 37 criteria, wherever they are.

Where they sit

The representative is established in the Union by definition. The DPO can be anywhere and is often internal.

What they do

The representative receives and holds. The DPO advises, monitors and is the contact point for the authority on internal compliance.

Independence

The DPO must not receive instructions on the exercise of its tasks. The representative acts on your mandate.

Can one person do both

Not comfortably. The EDPB has warned about conflicts, and a DPO outside the Union cannot be the representative at all.

Both at once

Common. A US health-tech company with EU users usually needs a DPO and a representative.

The four questions in every first call

The four questions companies ask before appointing a data protection representative
The four questions companies ask before appointing a data protection representative

Who can lawfully hold each role

  1. Article 27 representative

    A natural or legal person established in a Member State where your data subjects are, who has accepted the mandate in writing.

  2. DPO

    Anyone with the professional qualities and expert knowledge required, internal or external, without a conflict of interest.

  3. UK representative

    A person established in the United Kingdom, appointed under the UK GDPR.

  4. Legal representative

    Determined by company law and your articles, not by data protection law at all.

  5. Processor

    Any organisation processing on your documented instructions under an Article 28 contract.

Who can hold each role, and who cannot

RoleCan beCannot be
Article 27 representativeA company or person established in a Member State that signs the mandateAn entity outside the Union, a mailbox, an unsigned arrangement
DPOInternal or external, with expert knowledge and no conflictSomeone who decides purposes and means, such as a CEO or head of marketing
UK representativeA company or person established in the United KingdomAn EU-established provider
Legal representativeWhoever your articles empower to bind the companyA data protection provider, by definition
ProcessorAny organisation acting on your documented instructionsA contact point for supervisory authorities on your behalf

Answering a procurement form in one email

Line one

Whether you are established in the Union. If not, say so plainly; hedging invites a second round.

Line two

The Article 27 representative, with name, address and the verification link.

Line three

Whether a DPO exists and, if so, the contact address. If not, one sentence on why Article 37 does not apply.

Line four

Where both are published, with a direct link to your privacy notice.

Line five

Who holds the Article 30 record and how quickly it can be produced.

Attachment

The certificate. Most reviewers stop reading once they can verify it themselves.

Where the confusion comes from

This is not carelessness on anyone's part. Four separate bodies of law use similar words for different things, and translations make it worse.

SourceTerm usedMeaning
GDPR Article 4(17)RepresentativeThe Article 27 contact point in the Union
GDPR Articles 37-39Data protection officerAn advisory and monitoring function
Product legislationAuthorised representativeActs for a manufacturer on product obligations
National company lawLegal representativeWhoever can bind the company
German, Dutch, Italian usageVertreter, vertegenwoordiger, rappresentanteAll four of the above, depending on context

The practical consequence: never answer a form on the strength of the word alone. Ask which regulation the question comes from, and the answer becomes obvious. If nobody can tell you, send the Article 27 certificate, because that is what nine questions out of ten are about.

When a company needs more than one

US health-tech with EU users

A DPO under Article 37 because of the data, and an Article 27 representative because it is outside the Union. Both, from day one.

UK agency serving EU clients

An EU representative as a processor, plus a UK representative if it also serves clients whose users are British and it is not established there.

Chinese manufacturer selling direct

An Article 27 representative for the buyer data and an Article 16 responsible person for the product. Two regulations, two designations.

EU company with no non-EU activity

Possibly a DPO, never an Article 27 representative. Establishment removes that question entirely.

Group with mixed entities

Each controller answers for itself. We issue separate designations per entity on a single invoice rather than pretending one covers the group.

Public authority

Article 27(2)(b) exempts public authorities and bodies. Private contractors serving them are not exempt.

What to do with a form you cannot decode

Some questionnaires are written by procurement teams copying a template. When the wording is ambiguous, this sequence resolves it without a phone call.

  1. Look for the regulation cited

    If Article 27 or the GDPR appears anywhere in the section, the answer is the designation.

  2. Look at what surrounds it

    Questions about breach notification and data subject rights point to the representative; questions about CE marking point to product law.

  3. Answer both if unclear

    Send the Article 27 certificate and one line on whether a DPO exists. Two sentences close almost every thread.

  4. Never invent a role

    Naming a representative you have not appointed in writing is worse than saying you do not have one yet.

The short version

Data protection representative is not a legal term, and that is the whole problem. In nine cases out of ten the person asking wants the Article 27 representative: a company established in the Union that has signed a mandate and is named in your privacy notice. In the tenth case they want your DPO, your UK representative or the person who signs your contracts, and one clarifying question separates them.

Send the certificate, name the DPO if you have one, and link the paragraph in your notice. That answer closes the thread whichever of the five roles the form actually meant.

Reviewing a client questionnaire that asks for a data protection representative
Reviewing a client questionnaire that asks for a data protection representative
Supervisory authority correspondence addressed to the designated representative

Questions we are actually asked

Is a data protection representative a legal term?

No. The GDPR uses representative, in Article 4(17) and Article 27. The longer phrase is common usage and covers several different roles.

Is it the same as a DPO?

No. The DPO advises and monitors under Articles 37-39. The representative is a contact point in the Union for a controller established outside it.

Can our DPO also be the representative?

Only if the DPO is established in the Union and signs the designation, and even then it creates a conflict the EDPB has warned about.

We are asked for a data protection representative in the EU. What do we send?

The Article 27 certificate and the paragraph published in your privacy notice. That is what the question means in nine cases out of ten.

Does the representative need data protection expertise?

It needs to receive, log, hold the record and cooperate. Advisory expertise is the DPO's job, not the representative's.

Can a law firm be our representative?

If it is established in the Union and accepts the mandate, yes. Many decline because the role carries a defined statutory duty and modest fees.

Do we need both roles?

Frequently. Needing a DPO under Article 37 and a representative under Article 27 are independent questions with independent answers.

Is the representative liable for our breaches?

Article 27(5) preserves proceedings against the controller or processor. Enforcement measures can be addressed to the representative, which is different from transferring your liability.

What about a UK representative?

A separate appointment under the UK GDPR with an entity established in the United Kingdom.

Is an authorised representative the same?

No. That belongs to product legislation, where it acts for a manufacturer. Different regulation entirely.

Can we appoint an individual employee in the EU?

Only if that person is genuinely established there and accepts the mandate. Most companies prefer a company because it survives staff turnover.

Does the representative attend audits?

It provides the designation, the record and the request log. Audit responses on the substance remain yours.

How is the representative published?

In the privacy notice under Article 13(1)(a), with identity and contact details, in the languages you publish in.

Can one representative serve several group entities?

Each controller designates. We issue separate designations per entity, on one invoice.

What if a client insists on a local representative in their country?

Article 27 does not require it and no supervisory authority does. A verifiable certificate usually ends the discussion.

How fast can we have the designation?

Within 24 hours of a completed form, with the certificate and the notice wording.

Related: what an EU rep is · when the requirement applies

The role your client is asking about

An Article 27 designation with Europe Services, SE in Prague, a certificate with a verification code, and one sentence you can paste into any questionnaire.

See the plans

See also