Appoint us
EU representative under Article 27 GDPR for companies established in South Africa

REP27 · EU representative · South Africa

Article 27 GDPR · South Africa

EU representative for South Africa companies, signed in 24 hours.

If your company is established in South Africa and you offer goods or services to people in the European Union — or you monitor their behaviour — Article 27 of the GDPR requires you to designate, in writing, a representative inside the Union. We are that representative: named in your privacy notice, reachable by all 27 supervisory authorities, and verifiable by anyone holding the code on your certificate.

€290Base — designation, certificate, live badge, 10 requests a year
€490Standard — unlimited requests, Article 30 records held, desk in 8 languages
€890Multi — Article 27 + GPSR responsible person + CE authorised representative

Get appointed in 24 hours   Check your privacy notice free

Why South African companies fall under Article 27

POPIA is South Africa's own regime and does not discharge Article 27. Companies in Johannesburg or Cape Town serving European customers need a representative inside the Union.

27 authorities, no shelterWithout an establishment in the Union you are outside the one-stop-shop. There is no lead authority to negotiate with: any of the 27 whose residents you reach can open a file on its own.

Who typically needs it here

Fintech and insurtech, wine and food exporters, tourism platforms, and outsourcing firms handling European client data.

You sell to people in the EU

Paid or free, physical or digital. Article 3(2)(a) looks at whether you envisage customers in the Union — a language option, a currency or EU shipping is usually enough.

You watch what they do

Analytics, profiling, advertising pixels or app telemetry on people located in the Union fall under Article 3(2)(b), even when you never sell to them.

You process for European clients

Processors are covered too. Naming a representative is increasingly a condition to pass vendor onboarding with EU customers.

Your regulator at home, and why it does not help here

POPIA governs processing in South Africa and the Information Regulator enforces it, including a registration duty for information officers. It is South Africa's own regime and does not discharge Article 27.

Who supervises you locally

the Information Regulator. None of them can receive a request under Article 27(4) on your behalf, and none of them appears in your privacy notice for European purposes.

How EU customers reach you

South African companies reach the Union through fintech and insurtech, wine and food exports, tourism platforms selling to European travellers, and outsourcing firms handling European client data from Cape Town and Johannesburg.

What actually changes

One designation, published in your notice, verifiable by anyone with the code. Requests logged and forwarded within two business days, with the GDPR deadline already counted for you.

What you receive

A named contact, not a mailbox

Article 27(4) asks for someone a regulator can address. You get an address in Prague, an inbox and a form, with a person behind them during European hours.

Proof a buyer can check alone

Enterprise procurement asks for evidence. A verifiable certificate answers it in one line instead of three rounds of email.

A designation letter that says what it is

Represented company, legal basis, territory, effective date, the processing you declared, both signatures. No template language hiding what was agreed.

Questions from South African companies

We process on behalf of European clients only. Whose duty is it?

Yours as a processor under Article 27, and separately your client's as controller. For South African outsourcing firms the designation is often what clears the client's vendor onboarding.

POPIA required us to register an information officer. Is that the same?

No. The information officer sits inside your organisation and answers to the Information Regulator. Article 27 wants a separate entity established in the Union.

Our tourism customers book from Europe but travel to South Africa. Which applies?

Article 3(2)(a) looks at where the person is when the service is offered to them. Booking from Berlin brings you inside the GDPR regardless of where the safari happens.

How fast can we be covered?

The designation letter and certificate are issued within 24 working hours of the form and payment, after a person reviews the file. Higher-risk sectors take up to five business days.

What does it cost, and what happens at renewal?

From €290 a year, billed annually in advance and renewing automatically until you cancel before the renewal date. No fee per request from the Standard plan up.

Are you our data protection officer?

No. Under EDPB guidance one entity cannot be both. We are the contact point under Article 27(4): we receive, log and forward, hold your Article 30 records, and never answer on the merits or give legal advice.

What changes for a company established in South Africa

POPIA requires every organisation to register an information officer with the Regulator, and enforcement has grown steadily since 2021. The information officer is an internal accountable person under South African law; the Article 27 representative is an external entity established in the Union. Confusing the two is the most common error we see from South African controllers.

Local law

Protection of Personal Information Act, supervised by the Information Regulator.

Transfers

No adequacy decision: Standard Contractual Clauses for transfers, representative for contactability.

Who is caught

Mining and industrial suppliers, wine and fruit exporters, and fintech and insurtech companies serving european markets.

What the designation adds

A named entity in a Member State, reachable by data subjects and authorities.

POPIA's section 72 governs transfers out of South Africa, and South African companies build their programmes around it. Nothing in section 72 or elsewhere in the Act creates a contact point inside the Union.

Cover your EU customers from South Africa

South African outsourcing firms carry two compliance stories to every European meeting. Having the second one already documented shortens the meeting.

Free check first: we read your public privacy notice and tell you in ten seconds whether a representative is named. If one is, we say so and you close the tab.

Run the free check