Appoint us
EU representative under Article 27 GDPR for companies established in Moldova

REP27 · EU representative · Moldova

Article 27 GDPR · Moldova

EU representative for Moldova companies, signed in 24 hours.

If your company is established in Moldova and you offer goods or services to people in the European Union — or you monitor their behaviour — Article 27 of the GDPR requires you to designate, in writing, a representative inside the Union. We are that representative: named in your privacy notice, reachable by all 27 supervisory authorities, and verifiable by anyone holding the code on your certificate.

€290Base — designation, certificate, live badge, 10 requests a year
€490Standard — unlimited requests, Article 30 records held, desk in 8 languages
€890Multi — Article 27 + GPSR responsible person + CE authorised representative

Get appointed in 24 hours   Check your privacy notice free

Why Moldovan companies fall under Article 27

Law 133/2011 governs processing in Moldova, and the country is aligning with the GDPR as part of accession work. Until that is complete, Moldova is a third country and Article 27 applies.

Article 27(5)The designation does not shield you. Actions can still be brought against your company directly. Anyone selling a representative as protection is selling something the regulation does not contain.

Who typically needs it here

IT outsourcing for European clients, wine exporters, agriculture, and logistics serving Romania and Poland.

Any recurring European revenue

One sale might be occasional. A product that European customers can buy today, tomorrow and next month is not, and Article 27(2)(a) does not apply.

A European user base you did not plan for

Many files start with a product built for a home market that quietly acquired European users. Intent is not the test; the presence of the users is.

Being in someone else's supply chain

European controllers are audited on their processors. That is why the designation appears in questionnaires before it appears in enforcement.

Your regulator at home, and why it does not help here

Law 133/2011 governs processing in Moldova, supervised by the NCPDP, and the country is aligning with the GDPR as part of accession work. Until that completes, Moldova is a third country.

Who supervises you locally

the National Center for Personal Data Protection. None of them can receive a request under Article 27(4) on your behalf, and none of them appears in your privacy notice for European purposes.

How EU customers reach you

Moldovan companies reach the Union through IT outsourcing for European clients, wine exports, agriculture, and logistics serving Romania, Poland and Italy.

What actually changes

One designation, published in your notice, verifiable by anyone with the code. Requests logged and forwarded within two business days, with the GDPR deadline already counted for you.

What you receive

Everything a regulator asks for

The designation letter, the records under Article 30(4), the log of every request received and when it was forwarded. Assembled as you go, not reconstructed under pressure.

A certificate that expires honestly

Valid until a date, verifiable by code, and it stops showing as active the day it lapses. That is what makes the status worth something.

One contract, three roles if you need them

Article 27 alone, or with the GPSR responsible person and the CE authorised representative on the Multi plan. One renewal date for all of it.

Questions from Moldovan companies

Most of our clients are in Romania. Does one country's designation cover us?

The designation is made in a member state where your data subjects are, and our desk covers all 27 from Prague. A customer in Italy or Germany is handled under the same contract.

Moldova is aligning with the GDPR. Does that anticipate anything?

Alignment is not membership. Until accession, Moldovan companies serving people in the Union designate a representative like any other third-country company.

Our IT clients are small European agencies. Do they check this?

Increasingly yes, and often through an automated questionnaire. A verifiable certificate answers it without a meeting.

How fast can we be covered?

The designation letter and certificate are issued within 24 working hours of the form and payment, after a person reviews the file. Higher-risk sectors take up to five business days.

What does it cost, and what happens at renewal?

From €290 a year, billed annually in advance and renewing automatically until you cancel before the renewal date. No fee per request from the Standard plan up.

Are you our data protection officer?

No. Under EDPB guidance one entity cannot be both. We are the contact point under Article 27(4): we receive, log and forward, hold your Article 30 records, and never answer on the merits or give legal advice.

Cover your EU customers from Moldova

Moldovan IT firms sit close to the Union commercially and outside it legally, which is exactly the gap Article 27 was written for.

Free check first: we read your public privacy notice and tell you in ten seconds whether a representative is named. If one is, we say so and you close the tab.

Run the free check