Appoint us
EU representative under Article 27 GDPR for companies established in the United States

REP27 · EU representative · United States

Article 27 GDPR · United States

EU representative for United States companies, signed in 24 hours.

If your company is established in the United States and you offer goods or services to people in the European Union — or you monitor their behaviour — Article 27 of the GDPR requires you to designate, in writing, a representative inside the Union. We are that representative: named in your privacy notice, reachable by all 27 supervisory authorities, and verifiable by anyone holding the code on your certificate.

€290Base — designation, certificate, live badge, 10 requests a year
€490Standard — unlimited requests, Article 30 records held, desk in 8 languages
€890Multi — Article 27 + GPSR responsible person + CE authorised representative

Get appointed in 24 hours   Check your privacy notice free

Why US companies fall under Article 27

There is no EU adequacy decision that removes Article 27: the EU-US Data Privacy Framework covers transfers of data, not the duty to have someone in Europe answering for you. A DPF certification and an EU representative are separate obligations, and having one does not satisfy the other.

€10 million or 2%Failing to designate is a standalone infringement under Article 83(4)(a) GDPR — whichever amount is higher. The Dutch supervisory authority fined Locatefamily.com €525,000 on this ground alone, adding periodic penalties until it complied.

Who typically needs it here

SaaS platforms, e-commerce brands shipping to Europe, mobile apps with EU installs and marketplaces with EU sellers.

You sell to people in the EU

Paid or free, physical or digital. Article 3(2)(a) looks at whether you envisage customers in the Union — a language option, a currency or EU shipping is usually enough.

You watch what they do

Analytics, profiling, advertising pixels or app telemetry on people located in the Union fall under Article 3(2)(b), even when you never sell to them.

You process for European clients

Processors are covered too. Naming a representative is increasingly a condition to pass vendor onboarding with EU customers.

What you receive

Signed designation letter

The written designation Article 27(1) requires, countersigned by Europe Services, SE and signed electronically under eIDAS.

Verifiable certificate

A certificate with a QR code and a public verification page, so a regulator, a client or a buyer can confirm the designation is live right now.

Request desk in Prague

A dedicated address, inbox and form. Every request from a data subject or an authority is logged and forwarded to you within two business days.

Questions from US companies

We are already certified under the EU-US Data Privacy Framework. Is that enough?

No. The framework legitimises the transfer of personal data to your servers; Article 27 requires a named point of contact established inside the Union. Supervisory authorities check for both, and the second is the one visible in your privacy notice.

How fast can we be covered?

The designation letter and certificate are issued within 24 working hours of the form and payment, after a person reviews the file. Higher-risk sectors take up to five business days.

What does it cost, and what happens at renewal?

From €290 a year, billed annually in advance and renewing automatically until you cancel before the renewal date. No fee per request from the Standard plan up.

Are you our data protection officer?

No. Under EDPB guidance one entity cannot be both. We are the contact point under Article 27(4): we receive, log and forward, hold your Article 30 records, and never answer on the merits or give legal advice.

Cover your EU customers from United States

Free check first: we read your public privacy notice and tell you in ten seconds whether a representative is named. If one is, we say so and you close the tab.

Run the free check