Appoint us
EU representative under Article 27 GDPR for companies established in Brazil

REP27 · EU representative · Brazil

Article 27 GDPR · Brazil

EU representative for Brazil companies, signed in 24 hours.

If your company is established in Brazil and you offer goods or services to people in the European Union — or you monitor their behaviour — Article 27 of the GDPR requires you to designate, in writing, a representative inside the Union. We are that representative: named in your privacy notice, reachable by all 27 supervisory authorities, and verifiable by anyone holding the code on your certificate.

€290Base — designation, certificate, live badge, 10 requests a year
€490Standard — unlimited requests, Article 30 records held, desk in 8 languages
€890Multi — Article 27 + GPSR responsible person + CE authorised representative

Get appointed in 24 hours   Check your privacy notice free

Why Brazilian companies fall under Article 27

The LGPD is modelled on the GDPR and requires its own representative in Brazil for foreign companies. It does not replace Article 27 for a Brazilian company selling into Europe.

Visible from outsideThis is the only GDPR duty a regulator can check without an investigation: the absence is written in your own privacy notice, on a page you publish yourself.

Who typically needs it here

Agritech and food exporters, fintech, marketplaces, and SaaS expanding from São Paulo into Portugal and Spain.

Any recurring European revenue

One sale might be occasional. A product that European customers can buy today, tomorrow and next month is not, and Article 27(2)(a) does not apply.

A European user base you did not plan for

Many files start with a product built for a home market that quietly acquired European users. Intent is not the test; the presence of the users is.

Being in someone else's supply chain

European controllers are audited on their processors. That is why the designation appears in questionnaires before it appears in enforcement.

Your regulator at home, and why it does not help here

The LGPD is modelled closely on the GDPR and requires foreign controllers processing Brazilian data to appoint a representative in Brazil. The ANPD enforces it. Brazil holds no adequacy decision with the Union.

Who supervises you locally

the Autoridade Nacional de Proteção de Dados. None of them can receive a request under Article 27(4) on your behalf, and none of them appears in your privacy notice for European purposes.

How EU customers reach you

Brazilian companies reach the Union through agritech and food exports, fintech, marketplaces, and SaaS expanding from São Paulo into Portugal and Spain — usually through Portugal first, because of language.

What actually changes

One designation, published in your notice, verifiable by anyone with the code. Requests logged and forwarded within two business days, with the GDPR deadline already counted for you.

What you receive

Designation, signed both ways

Your electronic signature and ours. Article 27(1) wants it in writing; a one-sided declaration is weaker than most companies assume.

Live badge for your site

One line of HTML that reads the register in real time: green while the designation is active, red the moment it lapses. Nobody can display a status they no longer hold.

Requests handled in eight languages

A Greek or Polish data subject writes in their own language. The desk reads it, logs it and forwards it with the deadline already counted.

Questions from Brazilian companies

We are opening a subsidiary in Portugal. Should we wait for it?

You need cover from the first EU customer, not from incorporation day. If the Portuguese entity later becomes the contracting party and the controller, we simply close the designation at renewal and you stop paying.

The LGPD already requires a representative. Is it reciprocal?

No. The LGPD representative sits in Brazil for foreign companies handling Brazilian data. Article 27 wants one in the Union for you. Same idea, opposite direction, two separate designations.

Our EU customers are almost all in Portugal. Does language matter?

For the designation, no. For the desk, yes: requests arrive in Portuguese and are handled in Portuguese, and the privacy notice wording is generated in Portuguese for your site.

How fast can we be covered?

The designation letter and certificate are issued within 24 working hours of the form and payment, after a person reviews the file. Higher-risk sectors take up to five business days.

What does it cost, and what happens at renewal?

From €290 a year, billed annually in advance and renewing automatically until you cancel before the renewal date. No fee per request from the Standard plan up.

Are you our data protection officer?

No. Under EDPB guidance one entity cannot be both. We are the contact point under Article 27(4): we receive, log and forward, hold your Article 30 records, and never answer on the merits or give legal advice.

LGPD, the ANPD, and why a Brazilian DPO is not an EU representative

Brazil's Lei Geral de Protecao de Dados came into force in 2020 and is enforced by the Autoridade Nacional de Protecao de Dados, which gained sanctioning powers in 2023. The LGPD is the closest non-European analogue to the GDPR, with the same extraterritorial logic and a comparable set of data subject rights. Article 5 of the LGPD requires a data protection officer, the encarregado, and this is where Brazilian companies most often go wrong.

The encarregado is not an EU representative. The roles look similar and are entirely distinct: the encarregado sits inside your organisation and answers to the ANPD, while the Article 27 representative is an external entity established in a Member State that answers to European supervisory authorities and to data subjects in the Union. Naming your encarregado in a European-facing privacy notice does not satisfy Article 27, and it is one of the first things a European client's legal team will flag.

Brazil has no adequacy decision. Transfers from the EU rely on Standard Contractual Clauses; the ANPD published its own model clauses for transfers out of Brazil in 2024, so companies operating both ways now manage two parallel sets.

The obligation typically arises for Brazilian software and fintech companies selling into Portugal and Spain, agribusiness exporters with EU commercial contacts, and marketplaces or delivery platforms with European corporate customers. Shared language with Portugal makes the European market unusually accessible for Brazilian companies, and unusually easy to enter without noticing the compliance threshold has been crossed.

Cover your EU customers from Brazil

Brazilian companies grasp this faster than most, because the LGPD taught them the same structure from the other side.

Free check first: we read your public privacy notice and tell you in ten seconds whether a representative is named. If one is, we say so and you close the tab.

Run the free check

See also