Appoint us
EU representative under Article 27 GDPR for companies established in India

REP27 · EU representative · India

Article 27 GDPR · India

EU representative for India companies, signed in 24 hours.

If your company is established in India and you offer goods or services to people in the European Union — or you monitor their behaviour — Article 27 of the GDPR requires you to designate, in writing, a representative inside the Union. We are that representative: named in your privacy notice, reachable by all 27 supervisory authorities, and verifiable by anyone holding the code on your certificate.

€290Base — designation, certificate, live badge, 10 requests a year
€490Standard — unlimited requests, Article 30 records held, desk in 8 languages
€890Multi — Article 27 + GPSR responsible person + CE authorised representative

Get appointed in 24 hours   Check your privacy notice free

Why Indian companies fall under Article 27

The Digital Personal Data Protection Act 2023 governs processing in India. It does not discharge Article 27: an Indian company serving EU customers still needs a representative established in the Union.

€10 million or 2%Failing to designate is a standalone infringement under Article 83(4)(a) GDPR — whichever amount is higher. The Dutch supervisory authority fined Locatefamily.com €525,000 on this ground alone, adding periodic penalties until it complied.

Who typically needs it here

IT services and BPO firms processing EU client data, SaaS out of Bengaluru and Hyderabad, and D2C brands exporting to Europe.

You sell to people in the EU

Paid or free, physical or digital. Article 3(2)(a) looks at whether you envisage customers in the Union — a language option, a currency or EU shipping is usually enough.

You watch what they do

Analytics, profiling, advertising pixels or app telemetry on people located in the Union fall under Article 3(2)(b), even when you never sell to them.

You process for European clients

Processors are covered too. Naming a representative is increasingly a condition to pass vendor onboarding with EU customers.

What you receive

Signed designation letter

The written designation Article 27(1) requires, countersigned by Europe Services, SE and signed electronically under eIDAS.

Verifiable certificate

A certificate with a QR code and a public verification page, so a regulator, a client or a buyer can confirm the designation is live right now.

Request desk in Prague

A dedicated address, inbox and form. Every request from a data subject or an authority is logged and forwarded to you within two business days.

Questions from Indian companies

We are a processor working for European clients. Does Article 27 apply to us?

Yes. Article 27 covers controllers and processors alike when they fall under Article 3(2). European clients increasingly ask to see the designation before signing a data processing agreement.

How fast can we be covered?

The designation letter and certificate are issued within 24 working hours of the form and payment, after a person reviews the file. Higher-risk sectors take up to five business days.

What does it cost, and what happens at renewal?

From €290 a year, billed annually in advance and renewing automatically until you cancel before the renewal date. No fee per request from the Standard plan up.

Are you our data protection officer?

No. Under EDPB guidance one entity cannot be both. We are the contact point under Article 27(4): we receive, log and forward, hold your Article 30 records, and never answer on the merits or give legal advice.

Cover your EU customers from India

Free check first: we read your public privacy notice and tell you in ten seconds whether a representative is named. If one is, we say so and you close the tab.

Run the free check