
REP27 · EU representative · Peru
Article 27 GDPR · Peru
If your company is established in Peru and you offer goods or services to people in the European Union — or you monitor their behaviour — Article 27 of the GDPR requires you to designate, in writing, a representative inside the Union. We are that representative: named in your privacy notice, reachable by all 27 supervisory authorities, and verifiable by anyone holding the code on your certificate.
Law 29733 governs data protection in Peru. It does not replace Article 27 for a Peruvian company offering goods or services to people in the Union.
€10 million or 2%Failing to designate is a standalone infringement under Article 83(4)(a) GDPR — whichever amount is higher. EDPB Guidelines 3/2018 confirm it is a breach in its own right, not a detail.
Textile and apparel exporters, agro-exporters, tourism platforms selling to European travellers, and outsourcing firms.
A campaign targeted at European users, a European language on the landing page, a local phone number: the test is whether you envisaged those customers, not whether you meant to.
Behavioural analytics on people in the Union is monitoring under Article 3(2)(b). This route catches companies with no European revenue at all.
Tickets, RMA forms and warranty registrations from European customers are personal data you process. B2B does not change that.
Law 29733 and its regulations govern processing in Peru, supervised by the ANPD under the Ministry of Justice. It does not replace Article 27.
the Autoridad Nacional de Protección de Datos Personales. None of them can receive a request under Article 27(4) on your behalf, and none of them appears in your privacy notice for European purposes.
Peruvian companies reach the Union through textile and apparel exports, agro-exports, tourism platforms selling to European travellers, and outsourcing firms.
One designation, published in your notice, verifiable by anyone with the code. Requests logged and forwarded within two business days, with the GDPR deadline already counted for you.
The exact Article 13(1)(a) and 14(1)(a) sentence, generated in each language your site uses, ready to paste. Most files stall here, so we remove the step.
Your certificate carries a code. Scanning it opens a page that reads the register live: active, under review, suspended, revoked or expired. Nothing to take on trust.
From the Standard plan we keep the records and produce them to a supervisory authority on request, telling you the same day it happened.
If you decide the purposes of the processing — the customer database, the app, the accounts — you remain the controller and the duty stays with you, whoever distributes.
The GDPR follows the person: booking from Madrid or Milan brings the transaction inside Article 3(2)(a), whatever happens afterwards in Cusco.
It is a domestic register. The GDPR does not ask you to register anything; it asks you to designate someone in the Union and publish their details.
The designation letter and certificate are issued within 24 working hours of the form and payment, after a person reviews the file. Higher-risk sectors take up to five business days.
From €290 a year, billed annually in advance and renewing automatically until you cancel before the renewal date. No fee per request from the Standard plan up.
No. Under EDPB guidance one entity cannot be both. We are the contact point under Article 27(4): we receive, log and forward, hold your Article 30 records, and never answer on the merits or give legal advice.
Peruvian exporters usually discover the duty through a European buyer, not a regulator, which is the cheap way round.
Free check first: we read your public privacy notice and tell you in ten seconds whether a representative is named. If one is, we say so and you close the tab.
Run the free check