Appoint us
EU representative under Article 27 GDPR for companies established in Thailand

REP27 · EU representative · Thailand

Article 27 GDPR · Thailand

EU representative for Thailand companies, signed in 24 hours.

If your company is established in Thailand and you offer goods or services to people in the European Union — or you monitor their behaviour — Article 27 of the GDPR requires you to designate, in writing, a representative inside the Union. We are that representative: named in your privacy notice, reachable by all 27 supervisory authorities, and verifiable by anyone holding the code on your certificate.

€290Base — designation, certificate, live badge, 10 requests a year
€490Standard — unlimited requests, Article 30 records held, desk in 8 languages
€890Multi — Article 27 + GPSR responsible person + CE authorised representative

Get appointed in 24 hours   Check your privacy notice free

Why Thai companies fall under Article 27

The Personal Data Protection Act B.E. 2562 governs processing in Thailand and requires foreign controllers to appoint a local representative. Article 27 is the equivalent duty for the European Union, and one does not satisfy the other.

€10 million or 2%Failing to designate is a standalone infringement under Article 83(4)(a) GDPR — whichever amount is higher. EDPB Guidelines 3/2018 confirm it is a breach in its own right, not a detail.

Who typically needs it here

Tourism and hospitality platforms, food and rubber exporters, e-commerce, and software development for European clients.

You sell to people in the EU

Paid or free, physical or digital. Article 3(2)(a) looks at whether you envisage customers in the Union — a language option, a currency or EU shipping is usually enough.

You watch what they do

Analytics, profiling, advertising pixels or app telemetry on people located in the Union fall under Article 3(2)(b), even when you never sell to them.

You process for European clients

Processors are covered too. Naming a representative is increasingly a condition to pass vendor onboarding with EU customers.

Your regulator at home, and why it does not help here

The Personal Data Protection Act B.E. 2562 governs processing in Thailand and requires foreign controllers to appoint a local representative. Article 27 is the equivalent duty for the Union, and one does not satisfy the other.

Who supervises you locally

the Personal Data Protection Committee. None of them can receive a request under Article 27(4) on your behalf, and none of them appears in your privacy notice for European purposes.

How EU customers reach you

Thai companies reach the Union through tourism and hospitality platforms selling to European travellers, food and rubber exports, e-commerce, and software development for European clients.

What actually changes

One designation, published in your notice, verifiable by anyone with the code. Requests logged and forwarded within two business days, with the GDPR deadline already counted for you.

What you receive

The wording for your notice

The exact Article 13(1)(a) and 14(1)(a) sentence, generated in each language your site uses, ready to paste. Most files stall here, so we remove the step.

A status page anyone can read

Your certificate carries a code. Scanning it opens a page that reads the register live: active, under review, suspended, revoked or expired. Nothing to take on trust.

Your Article 30 records, held for you

From the Standard plan we keep the records and produce them to a supervisory authority on request, telling you the same day it happened.

Questions from Thai companies

Thai PDPA already made us appoint a representative. Is that the same?

No. The Thai representative answers to the PDPC in Bangkok for foreign companies handling Thai data. The GDPR wants a representative established in a member state, reachable by all 27 authorities.

Our guests book from Europe and travel to Thailand. Which applies?

Article 3(2)(a) attaches at the moment the service is offered to a person in the Union. The booking, not the stay, is what brings you inside the GDPR.

Does Thailand have adequacy?

No. That governs transfers out of the Union, a separate question from representation. Thai hospitality groups usually need to think about both.

How fast can we be covered?

The designation letter and certificate are issued within 24 working hours of the form and payment, after a person reviews the file. Higher-risk sectors take up to five business days.

What does it cost, and what happens at renewal?

From €290 a year, billed annually in advance and renewing automatically until you cancel before the renewal date. No fee per request from the Standard plan up.

Are you our data protection officer?

No. Under EDPB guidance one entity cannot be both. We are the contact point under Article 27(4): we receive, log and forward, hold your Article 30 records, and never answer on the merits or give legal advice.

Cover your EU customers from Thailand

Thai hospitality files are the clearest example of a European obligation created entirely by a booking engine.

Free check first: we read your public privacy notice and tell you in ten seconds whether a representative is named. If one is, we say so and you close the tab.

Run the free check