
REP27 · EU representative · Japan
Article 27 GDPR · Japan
If your company is established in Japan and you offer goods or services to people in the European Union — or you monitor their behaviour — Article 27 of the GDPR requires you to designate, in writing, a representative inside the Union. We are that representative: named in your privacy notice, reachable by all 27 supervisory authorities, and verifiable by anyone holding the code on your certificate.
Japan holds an adequacy decision, which allows EU data to flow to Japan under the APPI. It does not remove Article 27: if you target people in the Union, the representative is still due.
Article 27(5)The designation does not shield you. Actions can still be brought against your company directly. Anyone selling a representative as protection is selling something the regulation does not contain.
Gaming and entertainment with EU players, electronics exporters, and B2B software firms with European subsidiaries or resellers.
A campaign targeted at European users, a European language on the landing page, a local phone number: the test is whether you envisaged those customers, not whether you meant to.
Behavioural analytics on people in the Union is monitoring under Article 3(2)(b). This route catches companies with no European revenue at all.
Tickets, RMA forms and warranty registrations from European customers are personal data you process. B2B does not change that.
The APPI governs processing in Japan and the PPC enforces it. Japan holds a mutual adequacy decision with the Union, which is about the free flow of data, not about who answers in Europe.
the Personal Information Protection Commission. None of them can receive a request under Article 27(4) on your behalf, and none of them appears in your privacy notice for European purposes.
Japanese companies meet the Union through gaming and entertainment with large European player bases, electronics and precision instruments, and B2B software sold through European resellers and subsidiaries.
One designation, published in your notice, verifiable by anyone with the code. Requests logged and forwarded within two business days, with the GDPR deadline already counted for you.
The designation letter, the records under Article 30(4), the log of every request received and when it was forwarded. Assembled as you go, not reconstructed under pressure.
Valid until a date, verifiable by code, and it stops showing as active the day it lapses. That is what makes the status worth something.
Article 27 alone, or with the GPSR responsible person and the CE authorised representative on the Multi plan. One renewal date for all of it.
No. Adequacy allows personal data to move between Japan and the Union without additional safeguards. Article 27 concerns the presence of a contact point inside the Union, and applies to any company established outside it under Article 3(2).
If the subsidiary is the controller for European customers, the group is established in the Union for that processing. If the Japanese parent decides purposes and means — the account system, the game servers, the analytics — the duty attaches to the parent.
Article 3(2)(b) covers monitoring behaviour, and game telemetry on European players is monitoring. That route to Article 27 exists even without a euro of European revenue.
The designation letter and certificate are issued within 24 working hours of the form and payment, after a person reviews the file. Higher-risk sectors take up to five business days.
From €290 a year, billed annually in advance and renewing automatically until you cancel before the renewal date. No fee per request from the Standard plan up.
No. Under EDPB guidance one entity cannot be both. We are the contact point under Article 27(4): we receive, log and forward, hold your Article 30 records, and never answer on the merits or give legal advice.
Japan holds an adequacy decision, adopted in January 2019 and reaffirmed after the periodic review, built on the Act on the Protection of Personal Information and on supplementary rules issued by the Personal Information Protection Commission. It is the most common source of confusion we see from Japanese companies: adequacy and Article 27 solve two different problems.
Adequacy governs transfers. It means personal data can move from the EU to Japan without Standard Contractual Clauses, which is a genuine and valuable simplification. Article 27 governs contactability. It requires a named point of contact established inside the Union for data subjects and supervisory authorities, and adequacy does nothing about that. A Japanese company that offers goods or services to people in the EU still needs a representative, exactly as a company in a non-adequate country would.
The PPC is the national authority and cooperates with EU supervisory authorities, but cooperation between regulators is not the same as a contact address that an individual in Spain or Poland can write to in their own language. That is what Article 27 is for, and it is why the designation has to be written and has to appear in your privacy notice.
In practice the obligation catches Japanese ecommerce brands shipping to Europe, games and app publishers with EU players, industrial and automotive suppliers running EU-facing recruitment or customer portals, and any company whose website sets analytics or advertising cookies for European visitors. Behavioural monitoring is a trigger in its own right under Article 3(2)(b), independently of whether you sell anything.
Japanese files tend to arrive with the Article 30 records already written. The APPI habit of documenting purposes translates directly.
Free check first: we read your public privacy notice and tell you in ten seconds whether a representative is named. If one is, we say so and you close the tab.
Run the free check