Appoint us
EU representative under Article 27 GDPR for companies established in Kenya

REP27 · EU representative · Kenya

Article 27 GDPR · Kenya

EU representative for Kenya companies, signed in 24 hours.

If your company is established in Kenya and you offer goods or services to people in the European Union — or you monitor their behaviour — Article 27 of the GDPR requires you to designate, in writing, a representative inside the Union. We are that representative: named in your privacy notice, reachable by all 27 supervisory authorities, and verifiable by anyone holding the code on your certificate.

€290Base — designation, certificate, live badge, 10 requests a year
€490Standard — unlimited requests, Article 30 records held, desk in 8 languages
€890Multi — Article 27 + GPSR responsible person + CE authorised representative

Get appointed in 24 hours   Check your privacy notice free

Why Kenyan companies fall under Article 27

The Data Protection Act 2019 governs processing in Kenya and requires foreign controllers targeting Kenyans to have a local representative. Article 27 is the mirror duty for your European customers.

€10 million or 2%Failing to designate is a standalone infringement under Article 83(4)(a) GDPR — whichever amount is higher. EDPB Guidelines 3/2018 confirm it is a breach in its own right, not a detail.

Who typically needs it here

Fintech and mobile money, agricultural exporters, tourism, and outsourcing firms handling European client data.

You sell to people in the EU

Paid or free, physical or digital. Article 3(2)(a) looks at whether you envisage customers in the Union — a language option, a currency or EU shipping is usually enough.

You watch what they do

Analytics, profiling, advertising pixels or app telemetry on people located in the Union fall under Article 3(2)(b), even when you never sell to them.

You process for European clients

Processors are covered too. Naming a representative is increasingly a condition to pass vendor onboarding with EU customers.

Your regulator at home, and why it does not help here

The Data Protection Act 2019 governs processing in Kenya, with mandatory registration for many controllers and processors, supervised by the ODPC. Article 27 is the mirror duty for your European customers.

Who supervises you locally

the Office of the Data Protection Commissioner. None of them can receive a request under Article 27(4) on your behalf, and none of them appears in your privacy notice for European purposes.

How EU customers reach you

Kenyan companies reach the Union through fintech and mobile money, agricultural and flower exports, tourism, and outsourcing firms handling European client data from Nairobi.

What actually changes

One designation, published in your notice, verifiable by anyone with the code. Requests logged and forwarded within two business days, with the GDPR deadline already counted for you.

What you receive

The wording for your notice

The exact Article 13(1)(a) and 14(1)(a) sentence, generated in each language your site uses, ready to paste. Most files stall here, so we remove the step.

A status page anyone can read

Your certificate carries a code. Scanning it opens a page that reads the register live: active, under review, suspended, revoked or expired. Nothing to take on trust.

Your Article 30 records, held for you

From the Standard plan we keep the records and produce them to a supervisory authority on request, telling you the same day it happened.

Questions from Kenyan companies

We are a small company with a few hundred EU users. Are we exempt?

Article 27(2)(a) exempts occasional, low-risk processing without special categories of data — genuinely occasional, not merely small. A live product with European users does not qualify.

We are registered with the ODPC. Does that carry over?

It is a Kenyan register. What carries over is the discipline: the records you keep for the ODPC usually satisfy what we hold under Article 30(4).

Our flower exports are B2B. Is personal data involved?

Buyer contacts, auction accounts and logistics staff at European companies are personal data. B2B does not put you outside Article 3(2).

How fast can we be covered?

The designation letter and certificate are issued within 24 working hours of the form and payment, after a person reviews the file. Higher-risk sectors take up to five business days.

What does it cost, and what happens at renewal?

From €290 a year, billed annually in advance and renewing automatically until you cancel before the renewal date. No fee per request from the Standard plan up.

Are you our data protection officer?

No. Under EDPB guidance one entity cannot be both. We are the contact point under Article 27(4): we receive, log and forward, hold your Article 30 records, and never answer on the merits or give legal advice.

Cover your EU customers from Kenya

Kenyan files come mostly from fintech and outsourcing, and the ODPC registration habit makes the Article 30 records easy to produce.

Free check first: we read your public privacy notice and tell you in ten seconds whether a representative is named. If one is, we say so and you close the tab.

Run the free check