
REP27 · EU representative · China
Article 27 GDPR · China
If your company is established in China and you offer goods or services to people in the European Union — or you monitor their behaviour — Article 27 of the GDPR requires you to designate, in writing, a representative inside the Union. We are that representative: named in your privacy notice, reachable by all 27 supervisory authorities, and verifiable by anyone holding the code on your certificate.
PIPL and the GDPR both apply to a Chinese company selling into Europe, and both require a representative: PIPL Article 53 for foreign entities handling Chinese data, GDPR Article 27 for you in the Union. Meeting one says nothing about the other.
€10 million or 2%Failing to designate is a standalone infringement under Article 83(4)(a) GDPR — whichever amount is higher. EDPB Guidelines 3/2018 confirm it is a breach in its own right, not a detail.
Cross-border e-commerce, consumer electronics brands, marketplace sellers on Amazon and eBay Europe, and hardware makers shipping CE-marked goods.
A campaign targeted at European users, a European language on the landing page, a local phone number: the test is whether you envisaged those customers, not whether you meant to.
Behavioural analytics on people in the Union is monitoring under Article 3(2)(b). This route catches companies with no European revenue at all.
Tickets, RMA forms and warranty registrations from European customers are personal data you process. B2B does not change that.
PIPL, in force since November 2021, requires foreign handlers of Chinese personal data to establish a dedicated entity or appoint a representative in China, and the CAC supervises cross-border transfers. That duty mirrors Article 27 in structure and satisfies none of it.
the Cyberspace Administration of China. None of them can receive a request under Article 27(4) on your behalf, and none of them appears in your privacy notice for European purposes.
Chinese companies reach the Union above all through marketplaces — Amazon, eBay, Cdiscount, Allegro — through own-brand e-commerce shipping from Shenzhen and Yiwu, and through consumer electronics and hardware carrying CE marking.
One designation, published in your notice, verifiable by anyone with the code. Requests logged and forwarded within two business days, with the GDPR deadline already counted for you.
The exact Article 13(1)(a) and 14(1)(a) sentence, generated in each language your site uses, ready to paste. Most files stall here, so we remove the step.
Your certificate carries a code. Scanning it opens a page that reads the register live: active, under review, suspended, revoked or expired. Nothing to take on trust.
From the Standard plan we keep the records and produce them to a supervisory authority on request, telling you the same day it happened.
No. A marketplace is a sales channel. It will not receive a request from a supervisory authority for you, and it will not appear in your privacy notice. Marketplaces increasingly require sellers to name a representative themselves, both under the GDPR and under the GPSR.
No. The PIPL representative sits in China and answers to the CAC. Article 27 wants one established in an EU member state, reachable by the 27 European authorities.
It is a separate duty and often needed at the same time: Regulation (EU) 2019/1020 requires an authorised representative in the Union for many CE-marked goods, and Article 16 GPSR requires a responsible person. Our Multi plan covers all three roles under one contract.
The designation letter and certificate are issued within 24 working hours of the form and payment, after a person reviews the file. Higher-risk sectors take up to five business days.
From €290 a year, billed annually in advance and renewing automatically until you cancel before the renewal date. No fee per request from the Standard plan up.
No. Under EDPB guidance one entity cannot be both. We are the contact point under Article 27(4): we receive, log and forward, hold your Article 30 records, and never answer on the merits or give legal advice.
The Personal Information Protection Law took effect on 1 November 2021 and is enforced by the Cyberspace Administration of China. PIPL was drafted with the GDPR visibly in mind and shares much of its structure, including a lawful basis requirement, data subject rights and breach notification. It also contains its own mirror-image obligation: a foreign company processing the personal information of people in China must appoint a local representative or establish a dedicated body there. Chinese companies operating in Europe face the reverse duty under Article 27.
Similar wording does not mean interchangeable compliance. A PIPL representative in China has no standing before an EU supervisory authority, and a designation under PIPL will not be accepted as satisfying Article 27. The obligations run in opposite directions and both have to be met.
China has no adequacy decision, and transfers out of the EU require Standard Contractual Clauses plus a transfer impact assessment that accounts for state access powers under the National Intelligence Law and the Cybersecurity Law. European clients increasingly ask about this during procurement, and a named EU representative is one of the first things their legal teams look for in a privacy notice.
The companies most affected are cross-border ecommerce sellers on European marketplaces, hardware and consumer electronics manufacturers with EU-facing support portals, and mobile app developers whose apps are downloaded in the EU. Marketplace listings and app store pages both count as offering goods or services to people in the Union, which is the test in Article 3(2).
For Chinese sellers the designation is rarely about the fine: it is about not being delisted by a marketplace that checks the listing before the regulator does.
Free check first: we read your public privacy notice and tell you in ten seconds whether a representative is named. If one is, we say so and you close the tab.
Run the free check