
REP27 · EU representative · United Arab Emirates
Article 27 GDPR · United Arab Emirates
If your company is established in the United Arab Emirates and you offer goods or services to people in the European Union — or you monitor their behaviour — Article 27 of the GDPR requires you to designate, in writing, a representative inside the Union. We are that representative: named in your privacy notice, reachable by all 27 supervisory authorities, and verifiable by anyone holding the code on your certificate.
Federal Decree-Law 45 of 2021 and the DIFC and ADGM regimes govern the Emirates. None of them substitutes Article 27 for a company reaching people in Europe.
Visible from outsideThis is the only GDPR duty a regulator can check without an investigation: the absence is written in your own privacy notice, on a page you publish yourself.
Free-zone holding companies, luxury e-commerce, travel and hospitality platforms, and fintech serving European customers.
A campaign targeted at European users, a European language on the landing page, a local phone number: the test is whether you envisaged those customers, not whether you meant to.
Behavioural analytics on people in the Union is monitoring under Article 3(2)(b). This route catches companies with no European revenue at all.
Tickets, RMA forms and warranty registrations from European customers are personal data you process. B2B does not change that.
Federal Decree-Law 45 of 2021 governs the mainland, DIFC Data Protection Law 2020 governs the financial centre and ADGM has its own regime. Three layers at home, none of which reaches into the Union.
the UAE Data Office, with the DIFC Commissioner of Data Protection and the ADGM Registration Authority in the free zones. None of them can receive a request under Article 27(4) on your behalf, and none of them appears in your privacy notice for European purposes.
Emirati companies meet the Union through luxury e-commerce, travel and hospitality platforms selling to European travellers, free-zone holding companies with European operations, and fintech serving EU clients.
One designation, published in your notice, verifiable by anyone with the code. Requests logged and forwarded within two business days, with the GDPR deadline already counted for you.
Your electronic signature and ours. Article 27(1) wants it in writing; a one-sided declaration is weaker than most companies assume.
One line of HTML that reads the register in real time: green while the designation is active, red the moment it lapses. Nobody can display a status they no longer hold.
A Greek or Polish data subject writes in their own language. The desk reads it, logs it and forwards it with the deadline already counted.
No. DIFC rules govern processing inside the zone and are enforced by the DIFC Commissioner. The GDPR applies because of where your customers are, and it wants a representative inside the Union.
Yes, that is exactly Article 3(2)(a): offering services to people who are in the Union at the time. Where the service is delivered does not change where the customer was when they booked.
No. A designation does not create an establishment, a permanent establishment or any tax nexus. It names a contact point; nothing more, and the contract says so explicitly.
The designation letter and certificate are issued within 24 working hours of the form and payment, after a person reviews the file. Higher-risk sectors take up to five business days.
From €290 a year, billed annually in advance and renewing automatically until you cancel before the renewal date. No fee per request from the Standard plan up.
No. Under EDPB guidance one entity cannot be both. We are the contact point under Article 27(4): we receive, log and forward, hold your Article 30 records, and never answer on the merits or give legal advice.
A DIFC-licensed entity applies a regime modelled on the GDPR and may already have a data protection officer. The officer sits in Dubai, which is not a Member State, so the Article 27 designation remains outstanding.
The Emirates operate parallel regimes: the federal decree-law, plus separate data protection laws in the DIFC and ADGM free zones, the DIFC regime being the closest to the GDPR of the three. Which one applies depends on where the entity is licensed, and none of the three creates a contact point inside the Union.
Sectors where we see it most: trading and re-export companies, e-commerce platforms shipping to Europe, and hospitality and aviation groups.
UAE files often arrive from hospitality groups after a European guest exercises a deletion request and nobody knows who should answer it.
Free check first: we read your public privacy notice and tell you in ten seconds whether a representative is named. If one is, we say so and you close the tab.
Run the free check