Appoint us
EU representative under Article 27 GDPR for companies established in Norway

REP27 · EU representative · Norway

Article 27 GDPR · Norway

EU representative for Norway companies, signed in 24 hours.

If your company is established in Norway and you offer goods or services to people in the European Union — or you monitor their behaviour — Article 27 of the GDPR requires you to designate, in writing, a representative inside the Union. We are that representative: named in your privacy notice, reachable by all 27 supervisory authorities, and verifiable by anyone holding the code on your certificate.

€290Base — designation, certificate, live badge, 10 requests a year
€490Standard — unlimited requests, Article 30 records held, desk in 8 languages
€890Multi — Article 27 + GPSR responsible person + CE authorised representative

Get appointed in 24 hours   Check your privacy notice free

Why Norwegian companies fall under Article 27

Norway is inside the EEA and applies the GDPR directly, so an established Norwegian company usually needs no representative at all. It becomes relevant when the contracting entity sits outside the EEA while the market is European.

Visible from outsideThis is the only GDPR duty a regulator can check without an investigation: the absence is written in your own privacy notice, on a page you publish yourself.

Who typically needs it here

Maritime and energy technology, seafood exporters, and SaaS with a non-EEA parent company.

Any recurring European revenue

One sale might be occasional. A product that European customers can buy today, tomorrow and next month is not, and Article 27(2)(a) does not apply.

A European user base you did not plan for

Many files start with a product built for a home market that quietly acquired European users. Intent is not the test; the presence of the users is.

Being in someone else's supply chain

European controllers are audited on their processors. That is why the designation appears in questionnaires before it appears in enforcement.

Your regulator at home, and why it does not help here

Norway is part of the European Economic Area and applies the GDPR directly. Datatilsynet is a supervisory authority in the same system as its EU counterparts, which is precisely why most Norwegian companies need no designation at all.

Who supervises you locally

Datatilsynet. None of them can receive a request under Article 27(4) on your behalf, and none of them appears in your privacy notice for European purposes.

How EU customers reach you

The question becomes real when the contracting entity sits outside the EEA — a US or UK parent, a holding in a third country — while the market and the customers are European.

What actually changes

One designation, published in your notice, verifiable by anyone with the code. Requests logged and forwarded within two business days, with the GDPR deadline already counted for you.

What you receive

Designation, signed both ways

Your electronic signature and ours. Article 27(1) wants it in writing; a one-sided declaration is weaker than most companies assume.

Live badge for your site

One line of HTML that reads the register in real time: green while the designation is active, red the moment it lapses. Nobody can display a status they no longer hold.

Requests handled in eight languages

A Greek or Polish data subject writes in their own language. The desk reads it, logs it and forwards it with the deadline already counted.

Questions from Norwegian companies

We are established in Norway. Do we really need an Article 27 representative?

Normally not. The EEA counts as inside the Union for this purpose, and a Norwegian establishment removes the duty. Tell us your structure and we will say plainly if the designation is unnecessary: we would rather refuse the fee than sell you something you do not need.

Our parent company is in the United States. Who is caught?

The entity that decides purposes and means. If the Norwegian company runs the service and holds the customer relationship, it is established in the EEA. If the US parent does, the duty attaches to the parent.

We are a processor for a US controller. Does that matter?

Your own establishment in Norway means Article 27 does not apply to you. It may well apply to your US client, and they will often ask you where to find a representative.

How fast can we be covered?

The designation letter and certificate are issued within 24 working hours of the form and payment, after a person reviews the file. Higher-risk sectors take up to five business days.

What does it cost, and what happens at renewal?

From €290 a year, billed annually in advance and renewing automatically until you cancel before the renewal date. No fee per request from the Standard plan up.

Are you our data protection officer?

No. Under EDPB guidance one entity cannot be both. We are the contact point under Article 27(4): we receive, log and forward, hold your Article 30 records, and never answer on the merits or give legal advice.

Cover your EU customers from Norway

Norway is the country where we most often tell people they do not need us. It is a short conversation and it saves both sides a year of paperwork.

Free check first: we read your public privacy notice and tell you in ten seconds whether a representative is named. If one is, we say so and you close the tab.

Run the free check

See also