Appoint us
EU representative under Article 27 GDPR for companies established in India

REP27 · EU representative · India

Article 27 GDPR · India

EU representative for India companies, signed in 24 hours.

If your company is established in India and you offer goods or services to people in the European Union — or you monitor their behaviour — Article 27 of the GDPR requires you to designate, in writing, a representative inside the Union. We are that representative: named in your privacy notice, reachable by all 27 supervisory authorities, and verifiable by anyone holding the code on your certificate.

€290Base — designation, certificate, live badge, 10 requests a year
€490Standard — unlimited requests, Article 30 records held, desk in 8 languages
€890Multi — Article 27 + GPSR responsible person + CE authorised representative

Get appointed in 24 hours   Check your privacy notice free

Why Indian companies fall under Article 27

The Digital Personal Data Protection Act 2023 governs processing in India. It does not discharge Article 27: an Indian company serving EU customers still needs a representative established in the Union.

€10 million or 2%Failing to designate is a standalone infringement under Article 83(4)(a) GDPR — whichever amount is higher. EDPB Guidelines 3/2018 confirm it is a breach in its own right, not a detail.

Who typically needs it here

IT services and BPO firms processing EU client data, SaaS out of Bengaluru and Hyderabad, and D2C brands exporting to Europe.

Any recurring European revenue

One sale might be occasional. A product that European customers can buy today, tomorrow and next month is not, and Article 27(2)(a) does not apply.

A European user base you did not plan for

Many files start with a product built for a home market that quietly acquired European users. Intent is not the test; the presence of the users is.

Being in someone else's supply chain

European controllers are audited on their processors. That is why the designation appears in questionnaires before it appears in enforcement.

Your regulator at home, and why it does not help here

The Digital Personal Data Protection Act 2023 introduced consent managers and the Data Protection Board. Its rules are rolling out; none of them touches Article 27, which looks at your European customers.

Who supervises you locally

the Data Protection Board of India. None of them can receive a request under Article 27(4) on your behalf, and none of them appears in your privacy notice for European purposes.

How EU customers reach you

Indian companies reach the Union mostly as processors: IT services and BPO firms in Bengaluru, Hyderabad, Pune and Noida handling data for European controllers, plus a growing number of SaaS products sold directly into the EU.

What actually changes

One designation, published in your notice, verifiable by anyone with the code. Requests logged and forwarded within two business days, with the GDPR deadline already counted for you.

What you receive

The wording for your notice

The exact Article 13(1)(a) and 14(1)(a) sentence, generated in each language your site uses, ready to paste. Most files stall here, so we remove the step.

A status page anyone can read

Your certificate carries a code. Scanning it opens a page that reads the register live: active, under review, suspended, revoked or expired. Nothing to take on trust.

Your Article 30 records, held for you

From the Standard plan we keep the records and produce them to a supervisory authority on request, telling you the same day it happened.

Questions from Indian companies

We are a processor working for European clients. Does Article 27 apply to us?

Yes. Article 27 covers controllers and processors alike when they fall under Article 3(2). For Indian IT services this is often the point that unblocks a European contract, because the client's own compliance team asks for it.

Our client says their designation covers us. Is that right?

No. A designation names one company. Your client's representative represents your client, not you. If you are caught by Article 3(2) as a processor, the duty is yours.

The DPDP Act already has obligations for us. Do they overlap?

They run in parallel. The DPDP Act governs data of people in India; the GDPR governs data of people in the Union. Complying with one says nothing about the other.

How fast can we be covered?

The designation letter and certificate are issued within 24 working hours of the form and payment, after a person reviews the file. Higher-risk sectors take up to five business days.

What does it cost, and what happens at renewal?

From €290 a year, billed annually in advance and renewing automatically until you cancel before the renewal date. No fee per request from the Standard plan up.

Are you our data protection officer?

No. Under EDPB guidance one entity cannot be both. We are the contact point under Article 27(4): we receive, log and forward, hold your Article 30 records, and never answer on the merits or give legal advice.

How Article 27 interacts with India's DPDP Act

India passed the Digital Personal Data Protection Act in August 2023, and its rules have been rolling out in phases since. The Act creates the Data Protection Board of India as the national supervisory body and uses its own vocabulary: what the GDPR calls a controller, the DPDP Act calls a Data Fiduciary, and a data subject is a Data Principal. Compliance with the DPDP Act does not satisfy Article 27. The two regimes apply in parallel, and neither substitutes the other.

India has no adequacy decision from the European Commission. That has two practical consequences for an Indian company handling EU personal data. First, any transfer of personal data from the EU to India needs a transfer mechanism, in practice the Standard Contractual Clauses together with a transfer impact assessment. Second, EU supervisory authorities have no counterpart in India they can route enquiries through, which is precisely why Article 27 requires a representative established inside the Union.

The trigger for Indian companies is almost always one of three situations: a SaaS or IT services provider whose product is used by staff at European client companies; a direct-to-consumer brand shipping to EU customers from an Indian warehouse or through a marketplace; or an outsourcing and BPO operation processing personal data on behalf of a European client. In the third case the Indian company is normally a processor, and Article 27 applies to processors on the same terms as controllers.

Being a processor does not remove the obligation. It changes what your representative holds: the record kept under Article 30(2), covering the categories of processing you carry out for each of your European clients, rather than a full controller record.

Cover your EU customers from India

Indian processors that hold a designation get through European vendor onboarding weeks faster. That, more than the fine, is what makes it worth doing.

Free check first: we read your public privacy notice and tell you in ten seconds whether a representative is named. If one is, we say so and you close the tab.

Run the free check

See also