Appoint us
EU representative under Article 27 GDPR for companies established in the United States

REP27 · EU representative · United States

Article 27 GDPR · United States

EU representative for United States companies, signed in 24 hours.

If your company is established in the United States and you offer goods or services to people in the European Union — or you monitor their behaviour — Article 27 of the GDPR requires you to designate, in writing, a representative inside the Union. We are that representative: named in your privacy notice, reachable by all 27 supervisory authorities, and verifiable by anyone holding the code on your certificate.

€290Base — designation, certificate, live badge, 10 requests a year
€490Standard — unlimited requests, Article 30 records held, desk in 8 languages
€890Multi — Article 27 + GPSR responsible person + CE authorised representative

Get appointed in 24 hours   Check your privacy notice free

Why US companies fall under Article 27

There is no EU adequacy decision that removes Article 27: the EU-US Data Privacy Framework covers transfers of data, not the duty to have someone in Europe answering for you. A DPF certification and an EU representative are separate obligations, and having one does not satisfy the other.

27 authorities, no shelterWithout an establishment in the Union you are outside the one-stop-shop. There is no lead authority to negotiate with: any of the 27 whose residents you reach can open a file on its own.

Who typically needs it here

SaaS platforms, e-commerce brands shipping to Europe, mobile apps with EU installs and marketplaces with EU sellers.

Marketing that reaches the Union

A campaign targeted at European users, a European language on the landing page, a local phone number: the test is whether you envisaged those customers, not whether you meant to.

Cookies and pixels on EU visitors

Behavioural analytics on people in the Union is monitoring under Article 3(2)(b). This route catches companies with no European revenue at all.

Support and warranty data

Tickets, RMA forms and warranty registrations from European customers are personal data you process. B2B does not change that.

Your regulator at home, and why it does not help here

There is no single federal privacy regulator in the United States: the FTC polices unfair practices, and each state law has its own attorney general behind it. None of them speaks to a European supervisory authority on your behalf, and none of them satisfies Article 27.

Who supervises you locally

the Federal Trade Commission, plus state regulators under the CCPA, CPRA, VCDPA and a dozen more. None of them can receive a request under Article 27(4) on your behalf, and none of them appears in your privacy notice for European purposes.

How EU customers reach you

Most US companies meet the Union through Stripe checkouts, Shopify stores shipping to Ireland and Germany, apps distributed through the App Store and Google Play, and SaaS trials taken by European staff of European employers. Any one of those routes is enough to trigger Article 3(2).

What actually changes

One designation, published in your notice, verifiable by anyone with the code. Requests logged and forwarded within two business days, with the GDPR deadline already counted for you.

What you receive

A named contact, not a mailbox

Article 27(4) asks for someone a regulator can address. You get an address in Prague, an inbox and a form, with a person behind them during European hours.

Proof a buyer can check alone

Enterprise procurement asks for evidence. A verifiable certificate answers it in one line instead of three rounds of email.

A designation letter that says what it is

Represented company, legal basis, territory, effective date, the processing you declared, both signatures. No template language hiding what was agreed.

Questions from US companies

We are certified under the EU-US Data Privacy Framework. Is that enough?

No. The framework, administered by the Department of Commerce, legitimises the transfer of personal data to your servers. Article 27 asks a different question: who, inside the Union, receives a request from a Dutch or Irish regulator. Certification and designation are two separate obligations.

Our privacy policy already lists a Delaware address. Does that count?

No. Article 27(3) requires the representative to be established in a member state where the data subjects are. A US address, however carefully drafted, is outside the Union and cannot receive a request under Article 27(4).

We are a startup with maybe 200 EU users. Is it proportionate?

Proportionality is not the test. Article 27(2)(a) exempts occasional, low-risk processing without special categories of data; a live product with paying European users is not occasional. The cost of the designation is a fraction of the minimum fine.

How fast can we be covered?

The designation letter and certificate are issued within 24 working hours of the form and payment, after a person reviews the file. Higher-risk sectors take up to five business days.

What does it cost, and what happens at renewal?

From €290 a year, billed annually in advance and renewing automatically until you cancel before the renewal date. No fee per request from the Standard plan up.

Are you our data protection officer?

No. Under EDPB guidance one entity cannot be both. We are the contact point under Article 27(4): we receive, log and forward, hold your Article 30 records, and never answer on the merits or give legal advice.

Cover your EU customers from United States

The United States is where most of our files come from, and the pattern repeats: the company finds out from a European client's procurement questionnaire, not from a regulator.

Free check first: we read your public privacy notice and tell you in ten seconds whether a representative is named. If one is, we say so and you close the tab.

Run the free check