Appoint us
EU representative under Article 27 GDPR for companies established in China

REP27 · EU representative · China

Article 27 GDPR · China

EU representative for China companies, signed in 24 hours.

If your company is established in China and you offer goods or services to people in the European Union — or you monitor their behaviour — Article 27 of the GDPR requires you to designate, in writing, a representative inside the Union. We are that representative: named in your privacy notice, reachable by all 27 supervisory authorities, and verifiable by anyone holding the code on your certificate.

€290Base — designation, certificate, live badge, 10 requests a year
€490Standard — unlimited requests, Article 30 records held, desk in 8 languages
€890Multi — Article 27 + GPSR responsible person + CE authorised representative

Get appointed in 24 hours   Check your privacy notice free

Why Chinese companies fall under Article 27

PIPL and the GDPR both apply to a Chinese company selling into Europe, and both require a representative: PIPL Article 53 for foreign entities handling Chinese data, GDPR Article 27 for you in the Union. Meeting one says nothing about the other.

€10 million or 2%Failing to designate is a standalone infringement under Article 83(4)(a) GDPR — whichever amount is higher. EDPB Guidelines 3/2018 confirm it is a breach in its own right, not a detail.

Who typically needs it here

Cross-border e-commerce, consumer electronics brands, marketplace sellers on Amazon and eBay Europe, and hardware makers shipping CE-marked goods.

Marketing that reaches the Union

A campaign targeted at European users, a European language on the landing page, a local phone number: the test is whether you envisaged those customers, not whether you meant to.

Cookies and pixels on EU visitors

Behavioural analytics on people in the Union is monitoring under Article 3(2)(b). This route catches companies with no European revenue at all.

Support and warranty data

Tickets, RMA forms and warranty registrations from European customers are personal data you process. B2B does not change that.

Your regulator at home, and why it does not help here

PIPL, in force since November 2021, requires foreign handlers of Chinese personal data to establish a dedicated entity or appoint a representative in China, and the CAC supervises cross-border transfers. That duty mirrors Article 27 in structure and satisfies none of it.

Who supervises you locally

the Cyberspace Administration of China. None of them can receive a request under Article 27(4) on your behalf, and none of them appears in your privacy notice for European purposes.

How EU customers reach you

Chinese companies reach the Union above all through marketplaces — Amazon, eBay, Cdiscount, Allegro — through own-brand e-commerce shipping from Shenzhen and Yiwu, and through consumer electronics and hardware carrying CE marking.

What actually changes

One designation, published in your notice, verifiable by anyone with the code. Requests logged and forwarded within two business days, with the GDPR deadline already counted for you.

What you receive

The wording for your notice

The exact Article 13(1)(a) and 14(1)(a) sentence, generated in each language your site uses, ready to paste. Most files stall here, so we remove the step.

A status page anyone can read

Your certificate carries a code. Scanning it opens a page that reads the register live: active, under review, suspended, revoked or expired. Nothing to take on trust.

Your Article 30 records, held for you

From the Standard plan we keep the records and produce them to a supervisory authority on request, telling you the same day it happened.

Questions from Chinese companies

We sell through Amazon EU. Is the marketplace our representative?

No. A marketplace is a sales channel. It will not receive a request from a supervisory authority for you, and it will not appear in your privacy notice. Marketplaces increasingly require sellers to name a representative themselves, both under the GDPR and under the GPSR.

We already appointed a PIPL representative in China. Does that count?

No. The PIPL representative sits in China and answers to the CAC. Article 27 wants one established in an EU member state, reachable by the 27 European authorities.

Our products carry CE marking. Is that connected?

It is a separate duty and often needed at the same time: Regulation (EU) 2019/1020 requires an authorised representative in the Union for many CE-marked goods, and Article 16 GPSR requires a responsible person. Our Multi plan covers all three roles under one contract.

How fast can we be covered?

The designation letter and certificate are issued within 24 working hours of the form and payment, after a person reviews the file. Higher-risk sectors take up to five business days.

What does it cost, and what happens at renewal?

From €290 a year, billed annually in advance and renewing automatically until you cancel before the renewal date. No fee per request from the Standard plan up.

Are you our data protection officer?

No. Under EDPB guidance one entity cannot be both. We are the contact point under Article 27(4): we receive, log and forward, hold your Article 30 records, and never answer on the merits or give legal advice.

How Article 27 interacts with China's PIPL

The Personal Information Protection Law took effect on 1 November 2021 and is enforced by the Cyberspace Administration of China. PIPL was drafted with the GDPR visibly in mind and shares much of its structure, including a lawful basis requirement, data subject rights and breach notification. It also contains its own mirror-image obligation: a foreign company processing the personal information of people in China must appoint a local representative or establish a dedicated body there. Chinese companies operating in Europe face the reverse duty under Article 27.

Similar wording does not mean interchangeable compliance. A PIPL representative in China has no standing before an EU supervisory authority, and a designation under PIPL will not be accepted as satisfying Article 27. The obligations run in opposite directions and both have to be met.

China has no adequacy decision, and transfers out of the EU require Standard Contractual Clauses plus a transfer impact assessment that accounts for state access powers under the National Intelligence Law and the Cybersecurity Law. European clients increasingly ask about this during procurement, and a named EU representative is one of the first things their legal teams look for in a privacy notice.

The companies most affected are cross-border ecommerce sellers on European marketplaces, hardware and consumer electronics manufacturers with EU-facing support portals, and mobile app developers whose apps are downloaded in the EU. Marketplace listings and app store pages both count as offering goods or services to people in the Union, which is the test in Article 3(2).

Cover your EU customers from China

For Chinese sellers the designation is rarely about the fine: it is about not being delisted by a marketplace that checks the listing before the regulator does.

Free check first: we read your public privacy notice and tell you in ten seconds whether a representative is named. If one is, we say so and you close the tab.

Run the free check