
REP27 · Roles · Data protection representative
Article 27 · Articles 37-39 · terminology
Nothing in the GDPR is called a data protection representative. The phrase is used in client questionnaires, procurement forms and job titles to mean at least five different things, and buying the wrong one costs both money and time. This page separates them, says who can lawfully hold each, and gives you a way to work out which one the person asking actually wants.
Article 27DPOUK representativeLegal representativeProcessor

Only the first and third are appointments a provider can sell you. The second is a function, the fourth belongs to company law and the fifth is a contract.
| What the form says | What it almost always means | What to send |
|---|---|---|
| "EU representative under Article 27" | The designation | Certificate and privacy notice wording |
| "Data protection representative in the EU" | The same | The same |
| "Your DPO contact" | The internal function | Name and email of the DPO, if you have one |
| "Representative for the UK" | UK GDPR appointment | The UK certificate |
| "Legal representative" | Who signs the contract | Company registration extract |
| "Authorised representative" | Product safety, not data | The Article 16 designation |
The representative: controllers and processors outside the Union caught by Article 3(2). The DPO: organisations meeting the Article 37 criteria, wherever they are.
The representative is established in the Union by definition. The DPO can be anywhere and is often internal.
The representative receives and holds. The DPO advises, monitors and is the contact point for the authority on internal compliance.
The DPO must not receive instructions on the exercise of its tasks. The representative acts on your mandate.
Not comfortably. The EDPB has warned about conflicts, and a DPO outside the Union cannot be the representative at all.
Common. A US health-tech company with EU users usually needs a DPO and a representative.

A natural or legal person established in a Member State where your data subjects are, who has accepted the mandate in writing.
Anyone with the professional qualities and expert knowledge required, internal or external, without a conflict of interest.
A person established in the United Kingdom, appointed under the UK GDPR.
Determined by company law and your articles, not by data protection law at all.
Any organisation processing on your documented instructions under an Article 28 contract.
| Role | Can be | Cannot be |
|---|---|---|
| Article 27 representative | A company or person established in a Member State that signs the mandate | An entity outside the Union, a mailbox, an unsigned arrangement |
| DPO | Internal or external, with expert knowledge and no conflict | Someone who decides purposes and means, such as a CEO or head of marketing |
| UK representative | A company or person established in the United Kingdom | An EU-established provider |
| Legal representative | Whoever your articles empower to bind the company | A data protection provider, by definition |
| Processor | Any organisation acting on your documented instructions | A contact point for supervisory authorities on your behalf |
Whether you are established in the Union. If not, say so plainly; hedging invites a second round.
The Article 27 representative, with name, address and the verification link.
Whether a DPO exists and, if so, the contact address. If not, one sentence on why Article 37 does not apply.
Where both are published, with a direct link to your privacy notice.
Who holds the Article 30 record and how quickly it can be produced.
The certificate. Most reviewers stop reading once they can verify it themselves.
This is not carelessness on anyone's part. Four separate bodies of law use similar words for different things, and translations make it worse.
| Source | Term used | Meaning |
|---|---|---|
| GDPR Article 4(17) | Representative | The Article 27 contact point in the Union |
| GDPR Articles 37-39 | Data protection officer | An advisory and monitoring function |
| Product legislation | Authorised representative | Acts for a manufacturer on product obligations |
| National company law | Legal representative | Whoever can bind the company |
| German, Dutch, Italian usage | Vertreter, vertegenwoordiger, rappresentante | All four of the above, depending on context |
The practical consequence: never answer a form on the strength of the word alone. Ask which regulation the question comes from, and the answer becomes obvious. If nobody can tell you, send the Article 27 certificate, because that is what nine questions out of ten are about.
A DPO under Article 37 because of the data, and an Article 27 representative because it is outside the Union. Both, from day one.
An EU representative as a processor, plus a UK representative if it also serves clients whose users are British and it is not established there.
An Article 27 representative for the buyer data and an Article 16 responsible person for the product. Two regulations, two designations.
Possibly a DPO, never an Article 27 representative. Establishment removes that question entirely.
Each controller answers for itself. We issue separate designations per entity on a single invoice rather than pretending one covers the group.
Article 27(2)(b) exempts public authorities and bodies. Private contractors serving them are not exempt.
Some questionnaires are written by procurement teams copying a template. When the wording is ambiguous, this sequence resolves it without a phone call.
If Article 27 or the GDPR appears anywhere in the section, the answer is the designation.
Questions about breach notification and data subject rights point to the representative; questions about CE marking point to product law.
Send the Article 27 certificate and one line on whether a DPO exists. Two sentences close almost every thread.
Naming a representative you have not appointed in writing is worse than saying you do not have one yet.
Data protection representative is not a legal term, and that is the whole problem. In nine cases out of ten the person asking wants the Article 27 representative: a company established in the Union that has signed a mandate and is named in your privacy notice. In the tenth case they want your DPO, your UK representative or the person who signs your contracts, and one clarifying question separates them.
Send the certificate, name the DPO if you have one, and link the paragraph in your notice. That answer closes the thread whichever of the five roles the form actually meant.


No. The GDPR uses representative, in Article 4(17) and Article 27. The longer phrase is common usage and covers several different roles.
No. The DPO advises and monitors under Articles 37-39. The representative is a contact point in the Union for a controller established outside it.
Only if the DPO is established in the Union and signs the designation, and even then it creates a conflict the EDPB has warned about.
The Article 27 certificate and the paragraph published in your privacy notice. That is what the question means in nine cases out of ten.
It needs to receive, log, hold the record and cooperate. Advisory expertise is the DPO's job, not the representative's.
If it is established in the Union and accepts the mandate, yes. Many decline because the role carries a defined statutory duty and modest fees.
Frequently. Needing a DPO under Article 37 and a representative under Article 27 are independent questions with independent answers.
Article 27(5) preserves proceedings against the controller or processor. Enforcement measures can be addressed to the representative, which is different from transferring your liability.
A separate appointment under the UK GDPR with an entity established in the United Kingdom.
No. That belongs to product legislation, where it acts for a manufacturer. Different regulation entirely.
Only if that person is genuinely established there and accepts the mandate. Most companies prefer a company because it survives staff turnover.
It provides the designation, the record and the request log. Audit responses on the substance remain yours.
In the privacy notice under Article 13(1)(a), with identity and contact details, in the languages you publish in.
Each controller designates. We issue separate designations per entity, on one invoice.
Article 27 does not require it and no supervisory authority does. A verifiable certificate usually ends the discussion.
Within 24 hours of a completed form, with the certificate and the notice wording.
Related: what an EU rep is · when the requirement applies
An Article 27 designation with Europe Services, SE in Prague, a certificate with a verification code, and one sentence you can paste into any questionnaire.
See the plans