Appoint us
EU representative under Article 27 GDPR for companies established in Israel

REP27 · EU representative · Israel

Article 27 GDPR · Israel

EU representative for Israel companies, signed in 24 hours.

If your company is established in Israel and you offer goods or services to people in the European Union — or you monitor their behaviour — Article 27 of the GDPR requires you to designate, in writing, a representative inside the Union. We are that representative: named in your privacy notice, reachable by all 27 supervisory authorities, and verifiable by anyone holding the code on your certificate.

€290Base — designation, certificate, live badge, 10 requests a year
€490Standard — unlimited requests, Article 30 records held, desk in 8 languages
€890Multi — Article 27 + GPSR responsible person + CE authorised representative

Get appointed in 24 hours   Check your privacy notice free

Why Israeli companies fall under Article 27

Israel holds an adequacy decision covering transfers to it. Article 27 is unaffected: a company established in Israel that offers services to people in the EU still designates a representative.

Visible from outsideThis is the only GDPR duty a regulator can check without an investigation: the absence is written in your own privacy notice, on a page you publish yourself.

Who typically needs it here

Cybersecurity and B2B SaaS, adtech and analytics, medtech, and consumer apps with large European user bases.

A euro price and EU delivery

Regulators read the site the way a customer would. Prices in euro, a shipping option to Ireland, a checkout in French: each one is evidence you envisaged the Union.

An app with European installs

Store listings available in EU countries, telemetry from European devices and accounts held by people in the Union all bring you inside Article 3(2).

A client who hands you EU data

As a processor you are caught in your own right. Your client's designation covers your client, never you.

Your regulator at home, and why it does not help here

The Privacy Protection Law 5741-1981, substantially amended in 2024, governs processing in Israel, and the PPA enforces it. Israel holds an adequacy decision with the Union, which concerns transfers into Israel.

Who supervises you locally

the Privacy Protection Authority. None of them can receive a request under Article 27(4) on your behalf, and none of them appears in your privacy notice for European purposes.

How EU customers reach you

Israeli companies reach the Union through cybersecurity and B2B SaaS sold to European enterprises, adtech and analytics operating on European visitors, medtech, and consumer apps with large European user bases.

What actually changes

One designation, published in your notice, verifiable by anyone with the code. Requests logged and forwarded within two business days, with the GDPR deadline already counted for you.

What you receive

Designation, signed both ways

Your electronic signature and ours. Article 27(1) wants it in writing; a one-sided declaration is weaker than most companies assume.

Live badge for your site

One line of HTML that reads the register in real time: green while the designation is active, red the moment it lapses. Nobody can display a status they no longer hold.

Requests handled in eight languages

A Greek or Polish data subject writes in their own language. The desk reads it, logs it and forwards it with the deadline already counted.

Questions from Israeli companies

Our product is analytics on website visitors. Does that count as monitoring?

Very likely yes. Article 3(2)(b) covers monitoring the behaviour of people in the Union, and behavioural analytics is the textbook example given by the EDPB. That route to Article 27 applies even if you never sell to an EU consumer.

We hold an adequacy decision. Isn't that stronger than a designation?

They answer different questions. Adequacy lets European data reach your servers. Article 27 gives European authorities and individuals someone to write to inside the Union. Regulators check both.

Our clients are European enterprises. They ask about this in every RFP.

That is the usual trigger. A verifiable certificate with a public status page answers the question in one line of an RFP instead of three rounds of email.

How fast can we be covered?

The designation letter and certificate are issued within 24 working hours of the form and payment, after a person reviews the file. Higher-risk sectors take up to five business days.

What does it cost, and what happens at renewal?

From €290 a year, billed annually in advance and renewing automatically until you cancel before the renewal date. No fee per request from the Standard plan up.

Are you our data protection officer?

No. Under EDPB guidance one entity cannot be both. We are the contact point under Article 27(4): we receive, log and forward, hold your Article 30 records, and never answer on the merits or give legal advice.

From Israel into the Union, step by step

Israel holds an adequacy decision from 2011, and Amendment 13 to the Privacy Protection Law took effect in 2025, raising enforcement powers substantially. The Commission has kept the decision under review, and adequacy has never removed the Article 27 duty for companies without an establishment in the Union.

Most affected: cybersecurity and defence technology vendors, medical device makers, and SaaS companies with European enterprise clients.

Cover your EU customers from Israel

Israeli adtech and analytics companies are the clearest Article 3(2)(b) cases we handle: no European sales, and still fully caught.

Free check first: we read your public privacy notice and tell you in ten seconds whether a representative is named. If one is, we say so and you close the tab.

Run the free check