
REP27 · EU representative · Canada
Article 27 GDPR · Canada
If your company is established in Canada and you offer goods or services to people in the European Union — or you monitor their behaviour — Article 27 of the GDPR requires you to designate, in writing, a representative inside the Union. We are that representative: named in your privacy notice, reachable by all 27 supervisory authorities, and verifiable by anyone holding the code on your certificate.
PIPEDA compliance does not replace Article 27. Canada holds a partial adequacy decision for commercial organisations, which again concerns transfers, not representation. If you offer goods or services to people in the EU, the designation is still required.
Article 27(5)The designation does not shield you. Actions can still be brought against your company directly. Anyone selling a representative as protection is selling something the regulation does not contain.
Toronto and Montreal SaaS, healthtech selling into Europe, and e-commerce shipping from Ontario and British Columbia.
Paid or free, physical or digital. Article 3(2)(a) looks at whether you envisage customers in the Union — a language option, a currency or EU shipping is usually enough.
Analytics, profiling, advertising pixels or app telemetry on people located in the Union fall under Article 3(2)(b), even when you never sell to them.
Processors are covered too. Naming a representative is increasingly a condition to pass vendor onboarding with EU customers.
PIPEDA governs commercial handling of personal data in Canada, with provincial regimes in Quebec, Alberta and British Columbia. The OPC supervises them; it has no role under the GDPR.
the Office of the Privacy Commissioner of Canada. None of them can receive a request under Article 27(4) on your behalf, and none of them appears in your privacy notice for European purposes.
Canadian companies typically meet European customers through SaaS sold from Toronto and Montreal, healthtech and edtech with EU institutional clients, and D2C brands shipping from Ontario into France and Germany.
One designation, published in your notice, verifiable by anyone with the code. Requests logged and forwarded within two business days, with the GDPR deadline already counted for you.
The designation letter, the records under Article 30(4), the log of every request received and when it was forwarded. Assembled as you go, not reconstructed under pressure.
Valid until a date, verifiable by code, and it stops showing as active the day it lapses. That is what makes the status worth something.
Article 27 alone, or with the GPSR responsible person and the CE authorised representative on the Multi plan. One renewal date for all of it.
No. Adequacy means EU personal data may flow to Canadian commercial organisations without extra safeguards. It concerns transfers, not representation. Article 27 applies because your establishment is outside the Union while your customers are inside it.
No. Law 25 requires a person in charge of the protection of personal information within your own organisation — closer to a DPO than to a representative. Article 27 wants a separate entity established in the Union.
Yours, under Article 27, and separately your client's as controller. Canadian processors increasingly attach the designation certificate to their security questionnaires because it removes a whole round of questions.
The designation letter and certificate are issued within 24 working hours of the form and payment, after a person reviews the file. Higher-risk sectors take up to five business days.
From €290 a year, billed annually in advance and renewing automatically until you cancel before the renewal date. No fee per request from the Standard plan up.
No. Under EDPB guidance one entity cannot be both. We are the contact point under Article 27(4): we receive, log and forward, hold your Article 30 records, and never answer on the merits or give legal advice.
Canada's position is unusual and often misread. The Commission's adequacy decision dates from 2001 and covers only personal data transferred to recipients subject to PIPEDA, the Personal Information Protection and Electronic Documents Act. It is partial adequacy: organisations outside PIPEDA's commercial scope, and provincial regimes in Quebec, British Columbia and Alberta with their own private-sector statutes, sit outside it. Quebec's Law 25 in particular has introduced obligations closer to the GDPR, including data protection officers and breach reporting to the Commission d'acces a l'information.
None of that touches Article 27. Adequacy, whether full or partial, concerns the lawfulness of transferring data into the country. Article 27 concerns having someone inside the Union who can be addressed. The Office of the Privacy Commissioner of Canada handles PIPEDA complaints; it does not act as your contact point for a French or Italian data subject exercising GDPR rights.
The Canadian companies that need a representative are typically SaaS and fintech businesses selling into Europe, universities and training providers recruiting EU students, and consumer brands shipping across the Atlantic. Because so many Canadian companies serve both the United States and Europe from a single platform, the EU-facing side of the business is easy to overlook until a European client's procurement questionnaire asks who the representative is.
If your company is subject to PIPEDA and relies on adequacy for inbound transfers, keep the two questions separate in your documentation. Adequacy goes in your transfer records; the representative goes in your privacy notice, with a named entity and a working address in the Union.
Canadian files are usually the cleanest we see: PIPEDA habits translate well into Article 30 records.
Free check first: we read your public privacy notice and tell you in ten seconds whether a representative is named. If one is, we say so and you close the tab.
Run the free check