Appoint us
EU representative under Article 27 GDPR for companies established in Singapore

REP27 · EU representative · Singapore

Article 27 GDPR · Singapore

EU representative for Singapore companies, signed in 24 hours.

If your company is established in Singapore and you offer goods or services to people in the European Union — or you monitor their behaviour — Article 27 of the GDPR requires you to designate, in writing, a representative inside the Union. We are that representative: named in your privacy notice, reachable by all 27 supervisory authorities, and verifiable by anyone holding the code on your certificate.

€290Base — designation, certificate, live badge, 10 requests a year
€490Standard — unlimited requests, Article 30 records held, desk in 8 languages
€890Multi — Article 27 + GPSR responsible person + CE authorised representative

Get appointed in 24 hours   Check your privacy notice free

Why Singaporean companies fall under Article 27

The PDPA regulates processing in Singapore. It has no bearing on Article 27, which applies because your customers are in the Union and your establishment is not.

€10 million or 2%Failing to designate is a standalone infringement under Article 83(4)(a) GDPR — whichever amount is higher. EDPB Guidelines 3/2018 confirm it is a breach in its own right, not a detail.

Who typically needs it here

Regional SaaS headquarters, fintech and payments, logistics platforms, and holding companies serving European subsidiaries.

Any recurring European revenue

One sale might be occasional. A product that European customers can buy today, tomorrow and next month is not, and Article 27(2)(a) does not apply.

A European user base you did not plan for

Many files start with a product built for a home market that quietly acquired European users. Intent is not the test; the presence of the users is.

Being in someone else's supply chain

European controllers are audited on their processors. That is why the designation appears in questionnaires before it appears in enforcement.

Your regulator at home, and why it does not help here

The PDPA governs processing in Singapore and the PDPC enforces it. Singapore is a hub for regional headquarters, which makes the question of which entity contracts with EU customers the decisive one.

Who supervises you locally

the Personal Data Protection Commission. None of them can receive a request under Article 27(4) on your behalf, and none of them appears in your privacy notice for European purposes.

How EU customers reach you

Singaporean companies meet the Union through regional SaaS headquarters, fintech and payments, logistics platforms, and holding structures serving European subsidiaries.

What actually changes

One designation, published in your notice, verifiable by anyone with the code. Requests logged and forwarded within two business days, with the GDPR deadline already counted for you.

What you receive

The wording for your notice

The exact Article 13(1)(a) and 14(1)(a) sentence, generated in each language your site uses, ready to paste. Most files stall here, so we remove the step.

A status page anyone can read

Your certificate carries a code. Scanning it opens a page that reads the register live: active, under review, suspended, revoked or expired. Nothing to take on trust.

Your Article 30 records, held for you

From the Standard plan we keep the records and produce them to a supervisory authority on request, telling you the same day it happened.

Questions from Singaporean companies

We are a holding company with an EU subsidiary. Do we still need this?

It depends on who contracts with the customer. If the European entity is the controller, the group is established in the Union for that processing. If the Singapore entity signs the contracts and runs the platform, Article 27 applies to it.

Our servers are in Frankfurt. Does that make us established in the EU?

No. Establishment means stable arrangements and effective activity, not hardware. Servers in Frankfurt with no people or operations behind them do not create an establishment, and the designation is still required.

Does the PDPA's DPO requirement overlap with this?

No. The PDPA asks you to name a data protection officer inside your organisation. Article 27 asks for a separate entity established in the Union, and EDPB guidance says the two roles cannot be held by the same body.

How fast can we be covered?

The designation letter and certificate are issued within 24 working hours of the form and payment, after a person reviews the file. Higher-risk sectors take up to five business days.

What does it cost, and what happens at renewal?

From €290 a year, billed annually in advance and renewing automatically until you cancel before the renewal date. No fee per request from the Standard plan up.

Are you our data protection officer?

No. Under EDPB guidance one entity cannot be both. We are the contact point under Article 27(4): we receive, log and forward, hold your Article 30 records, and never answer on the merits or give legal advice.

PDPA, regional headquarters, and the Article 27 trigger

Singapore's Personal Data Protection Act, administered by the Personal Data Protection Commission, was substantially amended in 2020 to add mandatory breach notification, higher financial penalties and a data portability framework. It also requires every organisation to designate a Data Protection Officer, which, as with Brazil's encarregado, is frequently mistaken for an EU representative. It is not one: the DPO is an internal role answerable to the PDPC, while the Article 27 representative is an entity established in the Union.

Singapore has no adequacy decision, so transfers from the EU require Standard Contractual Clauses. The PDPA imposes its own transfer limitation obligation in the opposite direction, and Singapore participates in the Global CBPR system, which the European Commission does not treat as equivalent to adequacy.

What makes Singapore distinctive is its role as a regional headquarters. A great many companies incorporate in Singapore to serve Asia-Pacific while the operating business sits elsewhere, and the EU-facing activity is often run through the Singapore entity: European clients contract with it, European users register on its platform, European staff appear in its systems. Article 3(2) follows the entity that does the processing, so it is the Singapore company that needs the representative, even when nobody there thinks of the business as European-facing.

The sectors most affected are B2B SaaS, fintech and payments, logistics and freight forwarding with EU consignees, and holding companies running group-wide HR or CRM platforms that include European records.

Cover your EU customers from Singapore

Singapore files are usually decided by one question: which company on the invoice. Everything else follows from that.

Free check first: we read your public privacy notice and tell you in ten seconds whether a representative is named. If one is, we say so and you close the tab.

Run the free check

See also