
REP27 · EU representative · Australia
Article 27 GDPR · Australia
If your company is established in Australia and you offer goods or services to people in the European Union — or you monitor their behaviour — Article 27 of the GDPR requires you to designate, in writing, a representative inside the Union. We are that representative: named in your privacy notice, reachable by all 27 supervisory authorities, and verifiable by anyone holding the code on your certificate.
The Privacy Act 1988 and the Australian Privacy Principles run in parallel with the GDPR, not instead of it. Australian companies with EU customers fall under Article 3(2) exactly like any other third-country business.
€10 million or 2%Failing to designate is a standalone infringement under Article 83(4)(a) GDPR — whichever amount is higher. EDPB Guidelines 3/2018 confirm it is a breach in its own right, not a detail.
Sydney and Melbourne SaaS, education platforms with EU students, and brands selling into Europe through Shopify and Amazon.
Regulators read the site the way a customer would. Prices in euro, a shipping option to Ireland, a checkout in French: each one is evidence you envisaged the Union.
Store listings available in EU countries, telemetry from European devices and accounts held by people in the Union all bring you inside Article 3(2).
As a processor you are caught in your own right. Your client's designation covers your client, never you.
The Privacy Act 1988 and the Australian Privacy Principles apply to most Australian businesses over the turnover threshold. The OAIC enforces them domestically and has no role in the Union.
the Office of the Australian Information Commissioner. None of them can receive a request under Article 27(4) on your behalf, and none of them appears in your privacy notice for European purposes.
Australian companies reach the Union mostly through education platforms with European students, SaaS sold into the UK and Ireland, and premium food, wine and cosmetics shipped D2C into the EU.
One designation, published in your notice, verifiable by anyone with the code. Requests logged and forwarded within two business days, with the GDPR deadline already counted for you.
The exact Article 13(1)(a) and 14(1)(a) sentence, generated in each language your site uses, ready to paste. Most files stall here, so we remove the step.
Your certificate carries a code. Scanning it opens a page that reads the register live: active, under review, suspended, revoked or expired. Nothing to take on trust.
From the Standard plan we keep the records and produce them to a supervisory authority on request, telling you the same day it happened.
It is one of the reasons the representative exists. Requests arrive in Prague during European hours, are logged the same day and reach you with the GDPR deadline already counted, not with a week already lost.
It changes how you may transfer data, not whether you need a representative. The two questions are independent: Article 27 depends on where your customers are, Chapter V on where your servers are.
Only if they are established in the Union and sign the designation. A reseller agreement is a commercial contract; Article 27(1) wants a written designation accepting the role.
The designation letter and certificate are issued within 24 working hours of the form and payment, after a person reviews the file. Higher-risk sectors take up to five business days.
From €290 a year, billed annually in advance and renewing automatically until you cancel before the renewal date. No fee per request from the Standard plan up.
No. Under EDPB guidance one entity cannot be both. We are the contact point under Article 27(4): we receive, log and forward, hold your Article 30 records, and never answer on the merits or give legal advice.
Australia regulates privacy through the Privacy Act 1988 and the thirteen Australian Privacy Principles, overseen by the Office of the Australian Information Commissioner. The Act has been under sustained reform since the 2022 review, with the first tranche of amendments already passed and further changes expected, including narrowing the long-standing small business exemption.
That exemption is the single biggest source of surprise for Australian companies. A business with annual turnover under three million Australian dollars may fall outside the Privacy Act entirely, and many owners conclude they have no privacy obligations at all. The GDPR has no equivalent carve-out. A ten-person Australian company selling to European customers is fully within Article 3(2), and therefore within Article 27, even while it sits outside its own national law.
Australia has no adequacy decision. Transfers from the EU require Standard Contractual Clauses, and APP 8 imposes its own accountability rules on cross-border disclosure in the other direction, so Australian companies frequently end up managing obligations flowing both ways.
The businesses affected are usually ecommerce and DTC brands shipping to Europe, edtech and online course providers with EU learners, travel and tourism operators marketing to European visitors, and mining or engineering firms with EU-facing supplier and recruitment portals. The time zone gap makes the representative practically useful as well as legally required: a contact address in the Union answers within European business hours, which an address in Sydney cannot.
The Australian files we see most often come from education and wellness platforms, where European users arrive long before anyone plans for Europe.
Free check first: we read your public privacy notice and tell you in ten seconds whether a representative is named. If one is, we say so and you close the tab.
Run the free check