
REP27 · EU representative · India
Article 27 GDPR · India
If your company is established in India and you offer goods or services to people in the European Union — or you monitor their behaviour — Article 27 of the GDPR requires you to designate, in writing, a representative inside the Union. We are that representative: named in your privacy notice, reachable by all 27 supervisory authorities, and verifiable by anyone holding the code on your certificate.
The Digital Personal Data Protection Act 2023 governs processing in India. It does not discharge Article 27: an Indian company serving EU customers still needs a representative established in the Union.
€10 million or 2%Failing to designate is a standalone infringement under Article 83(4)(a) GDPR — whichever amount is higher. EDPB Guidelines 3/2018 confirm it is a breach in its own right, not a detail.
IT services and BPO firms processing EU client data, SaaS out of Bengaluru and Hyderabad, and D2C brands exporting to Europe.
One sale might be occasional. A product that European customers can buy today, tomorrow and next month is not, and Article 27(2)(a) does not apply.
Many files start with a product built for a home market that quietly acquired European users. Intent is not the test; the presence of the users is.
European controllers are audited on their processors. That is why the designation appears in questionnaires before it appears in enforcement.
The Digital Personal Data Protection Act 2023 introduced consent managers and the Data Protection Board. Its rules are rolling out; none of them touches Article 27, which looks at your European customers.
the Data Protection Board of India. None of them can receive a request under Article 27(4) on your behalf, and none of them appears in your privacy notice for European purposes.
Indian companies reach the Union mostly as processors: IT services and BPO firms in Bengaluru, Hyderabad, Pune and Noida handling data for European controllers, plus a growing number of SaaS products sold directly into the EU.
One designation, published in your notice, verifiable by anyone with the code. Requests logged and forwarded within two business days, with the GDPR deadline already counted for you.
The exact Article 13(1)(a) and 14(1)(a) sentence, generated in each language your site uses, ready to paste. Most files stall here, so we remove the step.
Your certificate carries a code. Scanning it opens a page that reads the register live: active, under review, suspended, revoked or expired. Nothing to take on trust.
From the Standard plan we keep the records and produce them to a supervisory authority on request, telling you the same day it happened.
Yes. Article 27 covers controllers and processors alike when they fall under Article 3(2). For Indian IT services this is often the point that unblocks a European contract, because the client's own compliance team asks for it.
No. A designation names one company. Your client's representative represents your client, not you. If you are caught by Article 3(2) as a processor, the duty is yours.
They run in parallel. The DPDP Act governs data of people in India; the GDPR governs data of people in the Union. Complying with one says nothing about the other.
The designation letter and certificate are issued within 24 working hours of the form and payment, after a person reviews the file. Higher-risk sectors take up to five business days.
From €290 a year, billed annually in advance and renewing automatically until you cancel before the renewal date. No fee per request from the Standard plan up.
No. Under EDPB guidance one entity cannot be both. We are the contact point under Article 27(4): we receive, log and forward, hold your Article 30 records, and never answer on the merits or give legal advice.
India passed the Digital Personal Data Protection Act in August 2023, and its rules have been rolling out in phases since. The Act creates the Data Protection Board of India as the national supervisory body and uses its own vocabulary: what the GDPR calls a controller, the DPDP Act calls a Data Fiduciary, and a data subject is a Data Principal. Compliance with the DPDP Act does not satisfy Article 27. The two regimes apply in parallel, and neither substitutes the other.
India has no adequacy decision from the European Commission. That has two practical consequences for an Indian company handling EU personal data. First, any transfer of personal data from the EU to India needs a transfer mechanism, in practice the Standard Contractual Clauses together with a transfer impact assessment. Second, EU supervisory authorities have no counterpart in India they can route enquiries through, which is precisely why Article 27 requires a representative established inside the Union.
The trigger for Indian companies is almost always one of three situations: a SaaS or IT services provider whose product is used by staff at European client companies; a direct-to-consumer brand shipping to EU customers from an Indian warehouse or through a marketplace; or an outsourcing and BPO operation processing personal data on behalf of a European client. In the third case the Indian company is normally a processor, and Article 27 applies to processors on the same terms as controllers.
Being a processor does not remove the obligation. It changes what your representative holds: the record kept under Article 30(2), covering the categories of processing you carry out for each of your European clients, rather than a full controller record.
Indian processors that hold a designation get through European vendor onboarding weeks faster. That, more than the fine, is what makes it worth doing.
Free check first: we read your public privacy notice and tell you in ten seconds whether a representative is named. If one is, we say so and you close the tab.
Run the free check