Appoint us
EU representative under Article 27 GDPR for companies established in Japan

REP27 · EU representative · Japan

Article 27 GDPR · Japan

EU representative for Japan companies, signed in 24 hours.

If your company is established in Japan and you offer goods or services to people in the European Union — or you monitor their behaviour — Article 27 of the GDPR requires you to designate, in writing, a representative inside the Union. We are that representative: named in your privacy notice, reachable by all 27 supervisory authorities, and verifiable by anyone holding the code on your certificate.

€290Base — designation, certificate, live badge, 10 requests a year
€490Standard — unlimited requests, Article 30 records held, desk in 8 languages
€890Multi — Article 27 + GPSR responsible person + CE authorised representative

Get appointed in 24 hours   Check your privacy notice free

Why Japanese companies fall under Article 27

Japan holds an adequacy decision, which allows EU data to flow to Japan under the APPI. It does not remove Article 27: if you target people in the Union, the representative is still due.

Article 27(5)The designation does not shield you. Actions can still be brought against your company directly. Anyone selling a representative as protection is selling something the regulation does not contain.

Who typically needs it here

Gaming and entertainment with EU players, electronics exporters, and B2B software firms with European subsidiaries or resellers.

Marketing that reaches the Union

A campaign targeted at European users, a European language on the landing page, a local phone number: the test is whether you envisaged those customers, not whether you meant to.

Cookies and pixels on EU visitors

Behavioural analytics on people in the Union is monitoring under Article 3(2)(b). This route catches companies with no European revenue at all.

Support and warranty data

Tickets, RMA forms and warranty registrations from European customers are personal data you process. B2B does not change that.

Your regulator at home, and why it does not help here

The APPI governs processing in Japan and the PPC enforces it. Japan holds a mutual adequacy decision with the Union, which is about the free flow of data, not about who answers in Europe.

Who supervises you locally

the Personal Information Protection Commission. None of them can receive a request under Article 27(4) on your behalf, and none of them appears in your privacy notice for European purposes.

How EU customers reach you

Japanese companies meet the Union through gaming and entertainment with large European player bases, electronics and precision instruments, and B2B software sold through European resellers and subsidiaries.

What actually changes

One designation, published in your notice, verifiable by anyone with the code. Requests logged and forwarded within two business days, with the GDPR deadline already counted for you.

What you receive

Everything a regulator asks for

The designation letter, the records under Article 30(4), the log of every request received and when it was forwarded. Assembled as you go, not reconstructed under pressure.

A certificate that expires honestly

Valid until a date, verifiable by code, and it stops showing as active the day it lapses. That is what makes the status worth something.

One contract, three roles if you need them

Article 27 alone, or with the GPSR responsible person and the CE authorised representative on the Multi plan. One renewal date for all of it.

Questions from Japanese companies

Does the EU-Japan adequacy decision cover this?

No. Adequacy allows personal data to move between Japan and the Union without additional safeguards. Article 27 concerns the presence of a contact point inside the Union, and applies to any company established outside it under Article 3(2).

Our European subsidiary handles sales. Do we still need a designation?

If the subsidiary is the controller for European customers, the group is established in the Union for that processing. If the Japanese parent decides purposes and means — the account system, the game servers, the analytics — the duty attaches to the parent.

Our players are in the EU but we do not sell to them directly. Does that matter?

Article 3(2)(b) covers monitoring behaviour, and game telemetry on European players is monitoring. That route to Article 27 exists even without a euro of European revenue.

How fast can we be covered?

The designation letter and certificate are issued within 24 working hours of the form and payment, after a person reviews the file. Higher-risk sectors take up to five business days.

What does it cost, and what happens at renewal?

From €290 a year, billed annually in advance and renewing automatically until you cancel before the renewal date. No fee per request from the Standard plan up.

Are you our data protection officer?

No. Under EDPB guidance one entity cannot be both. We are the contact point under Article 27(4): we receive, log and forward, hold your Article 30 records, and never answer on the merits or give legal advice.

Why adequacy does not remove the Article 27 duty for Japanese companies

Japan holds an adequacy decision, adopted in January 2019 and reaffirmed after the periodic review, built on the Act on the Protection of Personal Information and on supplementary rules issued by the Personal Information Protection Commission. It is the most common source of confusion we see from Japanese companies: adequacy and Article 27 solve two different problems.

Adequacy governs transfers. It means personal data can move from the EU to Japan without Standard Contractual Clauses, which is a genuine and valuable simplification. Article 27 governs contactability. It requires a named point of contact established inside the Union for data subjects and supervisory authorities, and adequacy does nothing about that. A Japanese company that offers goods or services to people in the EU still needs a representative, exactly as a company in a non-adequate country would.

The PPC is the national authority and cooperates with EU supervisory authorities, but cooperation between regulators is not the same as a contact address that an individual in Spain or Poland can write to in their own language. That is what Article 27 is for, and it is why the designation has to be written and has to appear in your privacy notice.

In practice the obligation catches Japanese ecommerce brands shipping to Europe, games and app publishers with EU players, industrial and automotive suppliers running EU-facing recruitment or customer portals, and any company whose website sets analytics or advertising cookies for European visitors. Behavioural monitoring is a trigger in its own right under Article 3(2)(b), independently of whether you sell anything.

Cover your EU customers from Japan

Japanese files tend to arrive with the Article 30 records already written. The APPI habit of documenting purposes translates directly.

Free check first: we read your public privacy notice and tell you in ten seconds whether a representative is named. If one is, we say so and you close the tab.

Run the free check

See also