
REP27 · EU representative · Hong Kong
Article 27 GDPR · Hong Kong
If your company is established in Hong Kong and you offer goods or services to people in the European Union — or you monitor their behaviour — Article 27 of the GDPR requires you to designate, in writing, a representative inside the Union. We are that representative: named in your privacy notice, reachable by all 27 supervisory authorities, and verifiable by anyone holding the code on your certificate.
The PDPO is considerably lighter than the GDPR and offers no equivalence. A Hong Kong company selling to European consumers is squarely inside Article 3(2), and the representative is required.
€525,000The Dutch supervisory authority fined Locatefamily.com €525,000 for failing to designate an EU representative, and added periodic penalties until the company complied. No other breach was needed.
Trading companies, consumer electronics, marketplace sellers and fintech serving European clients.
A campaign targeted at European users, a European language on the landing page, a local phone number: the test is whether you envisaged those customers, not whether you meant to.
Behavioural analytics on people in the Union is monitoring under Article 3(2)(b). This route catches companies with no European revenue at all.
Tickets, RMA forms and warranty registrations from European customers are personal data you process. B2B does not change that.
The PDPO is considerably lighter than the GDPR and offers no equivalence. The PCPD supervises it locally and has no relationship with European authorities.
the Privacy Commissioner for Personal Data. None of them can receive a request under Article 27(4) on your behalf, and none of them appears in your privacy notice for European purposes.
Hong Kong companies reach the Union through trading and sourcing houses, consumer electronics brands, marketplace selling, and fintech serving European clients.
One designation, published in your notice, verifiable by anyone with the code. Requests logged and forwarded within two business days, with the GDPR deadline already counted for you.
The written designation Article 27(1) requires, countersigned by Europe Services, SE and signed electronically under eIDAS, naming the member states covered.
A certificate with a QR code and a public verification page, so a regulator, a client or a buyer can confirm the designation is live at that moment.
A dedicated address, inbox and form. Every request from a data subject or an authority is logged and forwarded to you within two business days.
If you decide the purposes of the processing — the customer database, the warranty registrations, the app accounts — you remain the controller and the duty is yours, whoever resells the product.
Because the GDPR follows the person, not the company. Article 3(2) applies wherever you are established if the people whose data you process are in the Union.
Currency is one of the indications a regulator looks at, alongside language, shipping options and marketing. It is not decisive on its own, and it will not outweigh EU delivery or a European language on the site.
The designation letter and certificate are issued within 24 working hours of the form and payment, after a person reviews the file. Higher-risk sectors take up to five business days.
From €290 a year, billed annually in advance and renewing automatically until you cancel before the renewal date. No fee per request from the Standard plan up.
No. Under EDPB guidance one entity cannot be both. We are the contact point under Article 27(4): we receive, log and forward, hold your Article 30 records, and never answer on the merits or give legal advice.
The Ordinance dates from 1995 and predates the GDPR by two decades. Its cross-border transfer provision, section 33, has never been brought into force. The result is a mature regulator operating a framework that European buyers find unfamiliar, which makes the Article 27 designation a routine procurement question.
The Privacy Commissioner for Personal Data supervises you at home and has no standing before a supervisory authority in the Union.
Your domestic law protects people in Hong Kong. The GDPR protects people in the Union, wherever your company sits.
No adequacy decision: Standard Contractual Clauses for transfers, representative for contactability.
Hong Kong controllers often rely on the Ordinance's data user return scheme and its codes of practice. Neither instrument reaches a European data subject, and the Privacy Commissioner has no standing before a supervisory authority in the Union. The businesses this reaches are typically trading companies, electronics and toy exporters, and financial services firms with European counterparties.
Hong Kong trading companies often hold both roles at once: representative under Article 27 and responsible person under the GPSR. That is what the Multi plan exists for.
Free check first: we read your public privacy notice and tell you in ten seconds whether a representative is named. If one is, we say so and you close the tab.
Run the free check