
REP27 · Software · AI companies
Article 3(2) GDPR · AI Act · two different representatives
Two European laws now ask companies outside the Union to appoint someone inside it, and they are constantly confused. Article 27 GDPR wants a representative for personal data, triggered by your users. The AI Act wants an authorised representative for high-risk systems, triggered by what the system does. Most AI companies need the first long before the second, and almost none of them realise the first applies from their very first European sign-up.
Model providersFine-tuningAgentsAnalyticsPrompt logsEU users
They are not alternatives and one never satisfies the other. The GDPR one is cheap, immediate and applies to nearly everyone; the AI Act one applies by risk class and arrives in phases.


The recurring surprise is the third row. Teams accept that user accounts are personal data and then treat prompts as opaque text, when prompts are exactly where names, addresses, medical details and employment histories arrive in volume.
Pseudonymised logs with a session or account identifier are still personal data. True anonymisation is irreversible, and almost no production pipeline achieves it.
Infrastructure is not establishment. Recital 22 asks for effective and real activity through stable arrangements of your own.
Your customer's employees are individuals, and their prompts are processing. Being B2B changes the contract, not the analysis under Article 3(2)."
Article 27 applies to processors as well. It is one of the few obligations that does not shift with the role.
For AI vendors the commercial argument usually outruns the legal one. European procurement teams have added the representative to the standard questionnaire, alongside the data processing agreement and the sub-processor list.
Signed and dated, naming an entity with a real company number they can look up.
With a verification code the buyer can check without contacting you, which removes an email round trip from every deal.
Held by the representative and available to authorities, which is often the weakest document in an AI vendor's file.
Named in your privacy notice under Article 13(1)(a), where the buyer's legal team will look before asking you.
The record is the document that turns an abstract obligation into a working one, and for AI companies it is unusually revealing: it forces you to write down what happens to prompts.
| Processing | Categories of data | Typical retention question |
|---|---|---|
| Account and billing | Name, email, company, payment reference | How long after cancellation? |
| Prompt and completion logs | Whatever users type, which is unpredictable | Are they used for training, and can a user opt out? |
| Fine-tuning datasets | Customer content, sometimes special categories | Can a single record be removed after training? |
| Abuse and safety review | Flagged content, reviewer notes | Who reviews, in which country? |
| Product analytics | Identifiers, events, session data | Aggregated or per-user? |
The third row is the one that ends most conversations with European buyers. If the honest answer is that a record cannot be removed from a trained model, say so in the record and describe what you do instead; a documented limitation is defensible, a silent one is not.
One day. It is the only item on this list that is finished the moment it starts.
A week, mostly spent finding out what the logging actually does rather than what the documentation says it does.
Name the representative, describe prompt handling honestly, state retention periods you can actually meet.
Opt-in, opt-out or never. Whichever you choose, make the interface match the notice.
Risk classification, and only then conformity work. Doing this first is how companies spend six months and still have no representative.
If your product has European users, the designation is a fixed, small, immediate cost that removes an entire category of avoidable finding. It does not make you compliant, it does not audit your pipeline and it does not shift your liability. What it does is put a reachable name inside the Union next to yours, which is the minimum the regulation asks of a company that has decided to sell here.


It applies once you offer services to people in the Union or monitor their behaviour. Marketing aimed at Europe with a waiting list already involves processing personal data of people in the Union.
No. It is a separate role for providers of high-risk systems, with conformity assessment and registration duties. One designation cannot serve both regimes.
Public availability does not remove personal data from scope. If your training set contains data about people in the Union and you determine the purpose, you are processing it.
Yes, and they are usually the strongest evidence that the processing is continuous rather than occasional, which closes the Article 27(2)(a) exemption.
It reduces risk and is good practice. It does not remove the obligation, because the processing still happens during those 30 days.
Then there may be no processing by you at all, and no designation needed. This is one of the few genuinely clean cases.
No. Article 27(2)(b) exempts public authorities and bodies. Research use may affect lawful basis, never the designation.
Publishing weights is not by itself processing of EU personal data. The obligation follows your service, your API and your users.
No. A representative is precisely the mechanism for companies without one, and buyers accept it because the regulation does.
Only with a written designation and its acceptance of the role. A reseller agreement does not create one, and most resellers decline once they read the duties.
The framework concerns transfers to the United States. It does not touch Article 27, which applies regardless of transfer mechanism.
Within 24 hours of a completed form, with the privacy notice paragraph and a verifiable certificate supplied at the same time.
€290 a year for Base, €490 for Standard, €890 for Multi, which adds the GPSR responsible person for companies that also ship hardware.
Related: the SaaS version of this page · if you act as a processor
A signed Article 27 designation within 24 hours, a certificate with a verification code your buyers can check themselves, and a request desk in eight languages.
See the plans