
REP27 · Do I need one
Article 3(2) · Article 27 GDPR
Four questions decide it, and none of them are about your size, your turnover or how many European customers you have. The test is territorial: where your company is established, and whether what you do reaches people inside the Union. Read the diagram, then read why the exemption at the bottom almost never applies.
Establishment means a real and effective activity through stable arrangements — not where your company is registered on paper, and not where your servers sit.
A company incorporated in Delaware with a sales office in Dublin is established in the Union and needs no representative. A company incorporated in Ireland whose entire operation runs from São Paulo may still be caught. Recital 22 is explicit that legal form is not decisive: a single agent with sufficient stability can amount to an establishment, while a brass plate cannot.
If you have no branch, subsidiary, office or permanent staff in a Member State, treat yourself as outside and move to question two.
Not "do you have EU customers" — "is your offering directed at them". Intention is what counts, and it is judged on evidence.
Recital 23 lists the signals: using a language or a currency of a Member State, mentioning customers or users in the Union, offering shipping to European addresses, running an EU-specific domain, buying advertising targeted at European audiences. Any of these makes the offering directed. A single unsolicited order from a Belgian customer on an English-language site priced in dollars, with no EU shipping option, does not.
The offering does not have to be paid. A free app, a free trial, a free newsletter and a free web tool are all services in this sense.
This is the limb most companies miss, because it catches businesses that sell nothing in Europe at all.
Recital 24 defines monitoring as tracking people on the internet and then profiling them, particularly to take decisions or predict preferences and behaviour. In practice that includes advertising pixels, remarketing audiences, cross-site analytics with user identifiers, session recording and heatmaps, cookie-based personalisation, and app SDKs that report usage back to you.
Article 27(2)(a) exempts processing that is occasional, does not include large-scale special category or criminal data, and is unlikely to result in a risk to rights and freedoms. All three conditions must hold together.
| Situation | Occasional? | Exempt? |
|---|---|---|
| Online shop with a customer database | No — continuous | No |
| SaaS product with EU users | No — continuous | No |
| Website running analytics on EU visitors | No — continuous | No |
| Newsletter with European subscribers | No — ongoing storage | No |
| One-off conference badge scan, deleted after the event | Yes | Possibly |
EDPB Guidelines 3/2018 read "occasional" narrowly: processing that is not carried out regularly and happens outside the ordinary course of business. Anything sitting in a CRM by design fails it.
Incompatible under EDPB Guidelines 3/2018. The DPO must be independent; the representative acts on your instructions.
Possible in theory, but a conflict in practice: your processor cannot credibly answer an authority about your own compliance.
A mailbox or virtual office with nobody mandated is not a designation. Article 27(1) requires a party that accepts the role in writing.
The representative must be established in a Member State where your data subjects are. Post-Brexit, a UK company cannot represent you in the EU.

No. Article 27(1) requires a designation in writing naming a specific entity established in the Union. A paragraph saying you comply with the GDPR names nobody, so there is no representative and no contact point for data subjects.
It can. Article 3(2)(b) covers monitoring behaviour, and analytics, advertising pixels, session recording and remarketing aimed at people in the Union all count. Selling nothing does not exempt you if you are profiling European visitors.
Anyone established in the Union can be designated, including a law firm or a distributor, provided they accept the mandate in writing. In practice most decline: the role carries direct exposure to supervisory authorities and requires holding your Article 30 record.
No. EDPB Guidelines 3/2018 state the two roles are incompatible, because the DPO must act independently while the representative acts on the controller's instructions. One body cannot hold both.
Up to €10 million or 2% of worldwide annual turnover, whichever is higher, under Article 83(4)(a). It is a standalone infringement: authorities have fined companies for the missing designation alone, without any underlying data breach.
No, and this is the most common misreading. Adequacy governs whether data may be transferred to your country without extra safeguards. Article 27 governs whether someone inside the Union can be contacted. Japan, the United Kingdom, Canada and Switzerland all hold adequacy and their companies still need a representative.
Rarely. Article 27(2)(a) requires the processing to be occasional, low risk, free of special category data, and unlikely to result in a risk to rights and freedoms — all four at once. A shop with a customer database, a newsletter or analytics fails the first condition already.
Yes, if you target people in the UK. Since 2021 the UK GDPR is a separate regime with its own regulator, and a representative established in a Member State has no standing before it. The two designations are issued separately.
Related: what an Article 27 representative costs · GPSR responsible person for Amazon sellers
We read your public privacy notice and tell you in ten seconds whether a representative is already named. If one is, we say so and you close the tab.
Run the free check See pricing