Appoint us
EU representative under Article 27 GDPR for companies established in Canada

REP27 · EU representative · Canada

Article 27 GDPR · Canada

EU representative for Canada companies, signed in 24 hours.

If your company is established in Canada and you offer goods or services to people in the European Union — or you monitor their behaviour — Article 27 of the GDPR requires you to designate, in writing, a representative inside the Union. We are that representative: named in your privacy notice, reachable by all 27 supervisory authorities, and verifiable by anyone holding the code on your certificate.

€290Base — designation, certificate, live badge, 10 requests a year
€490Standard — unlimited requests, Article 30 records held, desk in 8 languages
€890Multi — Article 27 + GPSR responsible person + CE authorised representative

Get appointed in 24 hours   Check your privacy notice free

Why Canadian companies fall under Article 27

PIPEDA compliance does not replace Article 27. Canada holds a partial adequacy decision for commercial organisations, which again concerns transfers, not representation. If you offer goods or services to people in the EU, the designation is still required.

Article 27(5)The designation does not shield you. Actions can still be brought against your company directly. Anyone selling a representative as protection is selling something the regulation does not contain.

Who typically needs it here

Toronto and Montreal SaaS, healthtech selling into Europe, and e-commerce shipping from Ontario and British Columbia.

You sell to people in the EU

Paid or free, physical or digital. Article 3(2)(a) looks at whether you envisage customers in the Union — a language option, a currency or EU shipping is usually enough.

You watch what they do

Analytics, profiling, advertising pixels or app telemetry on people located in the Union fall under Article 3(2)(b), even when you never sell to them.

You process for European clients

Processors are covered too. Naming a representative is increasingly a condition to pass vendor onboarding with EU customers.

Your regulator at home, and why it does not help here

PIPEDA governs commercial handling of personal data in Canada, with provincial regimes in Quebec, Alberta and British Columbia. The OPC supervises them; it has no role under the GDPR.

Who supervises you locally

the Office of the Privacy Commissioner of Canada. None of them can receive a request under Article 27(4) on your behalf, and none of them appears in your privacy notice for European purposes.

How EU customers reach you

Canadian companies typically meet European customers through SaaS sold from Toronto and Montreal, healthtech and edtech with EU institutional clients, and D2C brands shipping from Ontario into France and Germany.

What actually changes

One designation, published in your notice, verifiable by anyone with the code. Requests logged and forwarded within two business days, with the GDPR deadline already counted for you.

What you receive

Everything a regulator asks for

The designation letter, the records under Article 30(4), the log of every request received and when it was forwarded. Assembled as you go, not reconstructed under pressure.

A certificate that expires honestly

Valid until a date, verifiable by code, and it stops showing as active the day it lapses. That is what makes the status worth something.

One contract, three roles if you need them

Article 27 alone, or with the GPSR responsible person and the CE authorised representative on the Multi plan. One renewal date for all of it.

Questions from Canadian companies

Canada has an adequacy decision. Does that exempt us?

No. Adequacy means EU personal data may flow to Canadian commercial organisations without extra safeguards. It concerns transfers, not representation. Article 27 applies because your establishment is outside the Union while your customers are inside it.

Quebec's Law 25 already made us appoint someone. Is it the same role?

No. Law 25 requires a person in charge of the protection of personal information within your own organisation — closer to a DPO than to a representative. Article 27 wants a separate entity established in the Union.

We are a processor for European SaaS companies. Whose duty is it?

Yours, under Article 27, and separately your client's as controller. Canadian processors increasingly attach the designation certificate to their security questionnaires because it removes a whole round of questions.

How fast can we be covered?

The designation letter and certificate are issued within 24 working hours of the form and payment, after a person reviews the file. Higher-risk sectors take up to five business days.

What does it cost, and what happens at renewal?

From €290 a year, billed annually in advance and renewing automatically until you cancel before the renewal date. No fee per request from the Standard plan up.

Are you our data protection officer?

No. Under EDPB guidance one entity cannot be both. We are the contact point under Article 27(4): we receive, log and forward, hold your Article 30 records, and never answer on the merits or give legal advice.

Partial adequacy, PIPEDA, and what Article 27 still requires

Canada's position is unusual and often misread. The Commission's adequacy decision dates from 2001 and covers only personal data transferred to recipients subject to PIPEDA, the Personal Information Protection and Electronic Documents Act. It is partial adequacy: organisations outside PIPEDA's commercial scope, and provincial regimes in Quebec, British Columbia and Alberta with their own private-sector statutes, sit outside it. Quebec's Law 25 in particular has introduced obligations closer to the GDPR, including data protection officers and breach reporting to the Commission d'acces a l'information.

None of that touches Article 27. Adequacy, whether full or partial, concerns the lawfulness of transferring data into the country. Article 27 concerns having someone inside the Union who can be addressed. The Office of the Privacy Commissioner of Canada handles PIPEDA complaints; it does not act as your contact point for a French or Italian data subject exercising GDPR rights.

The Canadian companies that need a representative are typically SaaS and fintech businesses selling into Europe, universities and training providers recruiting EU students, and consumer brands shipping across the Atlantic. Because so many Canadian companies serve both the United States and Europe from a single platform, the EU-facing side of the business is easy to overlook until a European client's procurement questionnaire asks who the representative is.

If your company is subject to PIPEDA and relies on adequacy for inbound transfers, keep the two questions separate in your documentation. Adequacy goes in your transfer records; the representative goes in your privacy notice, with a named entity and a working address in the Union.

Cover your EU customers from Canada

Canadian files are usually the cleanest we see: PIPEDA habits translate well into Article 30 records.

Free check first: we read your public privacy notice and tell you in ten seconds whether a representative is named. If one is, we say so and you close the tab.

Run the free check