
REP27 · EU representative · Colombia
Article 27 GDPR · Colombia
If your company is established in Colombia and you offer goods or services to people in the European Union — or you monitor their behaviour — Article 27 of the GDPR requires you to designate, in writing, a representative inside the Union. We are that representative: named in your privacy notice, reachable by all 27 supervisory authorities, and verifiable by anyone holding the code on your certificate.
Law 1581 of 2012 and its decrees govern processing in Colombia. They grant no exemption from Article 27 for companies whose customers are in the European Union.
27 authorities, no shelterWithout an establishment in the Union you are outside the one-stop-shop. There is no lead authority to negotiate with: any of the 27 whose residents you reach can open a file on its own.
BPO and contact centres handling European client data, coffee and flower exporters, fintech, and software houses serving Spain.
One sale might be occasional. A product that European customers can buy today, tomorrow and next month is not, and Article 27(2)(a) does not apply.
Many files start with a product built for a home market that quietly acquired European users. Intent is not the test; the presence of the users is.
European controllers are audited on their processors. That is why the designation appears in questionnaires before it appears in enforcement.
Law 1581 of 2012 and its decrees govern processing in Colombia, with a national database register run by the SIC. It grants no exemption from Article 27.
the Superintendencia de Industria y Comercio. None of them can receive a request under Article 27(4) on your behalf, and none of them appears in your privacy notice for European purposes.
Colombian companies reach the Union through BPO and contact centres handling European client data, coffee and flower exports, fintech, and software houses serving Spain.
One designation, published in your notice, verifiable by anyone with the code. Requests logged and forwarded within two business days, with the GDPR deadline already counted for you.
Article 27(4) asks for someone a regulator can address. You get an address in Prague, an inbox and a form, with a person behind them during European hours.
Enterprise procurement asks for evidence. A verifiable certificate answers it in one line instead of three rounds of email.
Represented company, legal basis, territory, effective date, the processing you declared, both signatures. No template language hiding what was agreed.
Yours as a processor under Article 27, and separately your client's as controller. Buyers increasingly ask to see your designation during vendor onboarding, before the contract is signed.
The Registro Nacional de Bases de Datos is Colombian and held by the SIC. Article 27 wants an entity established in the Union that European authorities can address.
Yes, and it is squarely within Article 3(2). Voice recordings, ticket notes and CRM entries about people in the Union are personal data processed by you.
The designation letter and certificate are issued within 24 working hours of the form and payment, after a person reviews the file. Higher-risk sectors take up to five business days.
From €290 a year, billed annually in advance and renewing automatically until you cancel before the renewal date. No fee per request from the Standard plan up.
No. Under EDPB guidance one entity cannot be both. We are the contact point under Article 27(4): we receive, log and forward, hold your Article 30 records, and never answer on the merits or give legal advice.
Colombian BPOs are the clearest processor cases we see: European data, European deadlines, no European entity.
Free check first: we read your public privacy notice and tell you in ten seconds whether a representative is named. If one is, we say so and you close the tab.
Run the free check