
REP27 · EU representative · Nigeria
Article 27 GDPR · Nigeria
If your company is established in Nigeria and you offer goods or services to people in the European Union — or you monitor their behaviour — Article 27 of the GDPR requires you to designate, in writing, a representative inside the Union. We are that representative: named in your privacy notice, reachable by all 27 supervisory authorities, and verifiable by anyone holding the code on your certificate.
The Nigeria Data Protection Act 2023 governs processing at home and requires foreign controllers to appoint a local representative. That duty runs in parallel with Article 27, it does not replace it.
27 authorities, no shelterWithout an establishment in the Union you are outside the one-stop-shop. There is no lead authority to negotiate with: any of the 27 whose residents you reach can open a file on its own.
Fintech and payments, software development for European clients, entertainment and streaming, and agricultural exporters.
A campaign targeted at European users, a European language on the landing page, a local phone number: the test is whether you envisaged those customers, not whether you meant to.
Behavioural analytics on people in the Union is monitoring under Article 3(2)(b). This route catches companies with no European revenue at all.
Tickets, RMA forms and warranty registrations from European customers are personal data you process. B2B does not change that.
The Nigeria Data Protection Act 2023 created the NDPC and requires foreign controllers targeting Nigerians to appoint a local representative. That duty runs in parallel with Article 27.
the Nigeria Data Protection Commission. None of them can receive a request under Article 27(4) on your behalf, and none of them appears in your privacy notice for European purposes.
Nigerian companies reach the Union through fintech and payments, software development for European clients, entertainment and streaming with diaspora audiences, and agricultural exports.
One designation, published in your notice, verifiable by anyone with the code. Requests logged and forwarded within two business days, with the GDPR deadline already counted for you.
Article 27(4) asks for someone a regulator can address. You get an address in Prague, an inbox and a form, with a person behind them during European hours.
Enterprise procurement asks for evidence. A verifiable certificate answers it in one line instead of three rounds of email.
Represented company, legal basis, territory, effective date, the processing you declared, both signatures. No template language hiding what was agreed.
No. The NDPA representative answers to the Nigeria Data Protection Commission in Abuja. Article 27 wants one established in an EU member state and published in your privacy notice.
Yes. Article 3(2) looks at where the people are, not at their nationality. A diaspora audience in London, Rome or Berlin is an audience in Europe — and for the UK, a separate UK duty.
It depends on who decides the purposes. Payment flows often create joint or separate controllership, and the designation attaches to each entity caught by Article 3(2) in its own right.
The designation letter and certificate are issued within 24 working hours of the form and payment, after a person reviews the file. Higher-risk sectors take up to five business days.
From €290 a year, billed annually in advance and renewing automatically until you cancel before the renewal date. No fee per request from the Standard plan up.
No. Under EDPB guidance one entity cannot be both. We are the contact point under Article 27(4): we receive, log and forward, hold your Article 30 records, and never answer on the merits or give legal advice.
Nigerian fintechs usually hold both duties at once, and the NDPA has made the concept familiar, which shortens the conversation.
Free check first: we read your public privacy notice and tell you in ten seconds whether a representative is named. If one is, we say so and you close the tab.
Run the free check