Appoint us
Supervisory authority reviewing the processing of identity documents

REP27 · Regulated tech · Crypto

Article 27 GDPR · alongside MiCA and AML

EU representative for a crypto exchange or wallet.

Crypto businesses arriving in Europe budget for MiCA authorisation and AML programmes, and then discover a €290 obligation that has been outstanding since their first European user. Article 27 is the smallest line in the compliance file and the one with no lead time: it is also the one that cannot be argued away, because the KYC data you are legally required to keep is exactly what makes the processing continuous.

KYC filesWallet addressesTransaction historySupport ticketsMarketing

See the plans   Ask a question

Four obligations, one of them trivial to fix

European obligations facing a crypto business, mapped to their triggers and authorities
European obligations facing a crypto business, mapped to their triggers and authorities

Three of these require licences, programmes and months of work. The fourth is a signature and a paragraph in a privacy notice, which is why it is so often the one still missing when the others are underway.

Why "occasional processing" is not available to you

Why KYC and AML retention rules make crypto processing continuous under the GDPR
Why KYC and AML retention rules make crypto processing continuous under the GDPR
The exemption in Article 27(2)(a) requires processing that is occasional, does not involve special categories at scale and is unlikely to result in risk. An identity-document archive kept for years fails all three limbs at once.

The arguments we hear, and where they land

ArgumentWhere it goes
"We are decentralised, there is no controller"If a company runs the interface, holds KYC files and can freeze accounts, that company is a controller
"Wallet addresses are pseudonymous"Pseudonymous is not anonymous. Linked to a verified identity in your database, they are personal data
"Our users found us, we do not target the EU"A European language, euro pairs, EU payment rails or localised marketing all point the other way
"We geo-block the EU"Then Article 3(2) may not be engaged. Effective blocking, not a checkbox, is what matters
"MiCA authorisation covers it"MiCA is financial regulation. It says nothing about Article 27, and the authorities are different

What the designation gives a crypto business

  1. A named contact point in the Union

    Where data subjects and supervisory authorities write, in eight languages, with everything logged.

  2. The Article 30 record

    Held and made available to authorities — the document most exchanges have never assembled, and the first one asked for after an incident.

  3. A verifiable certificate

    Which banking partners and payment providers increasingly ask to see during onboarding.

  4. The privacy notice paragraph

    Article 13(1)(a) wording naming the representative, translated for the markets you serve.

Where the data actually sits in a crypto business

Exchanges tend to describe themselves as holding wallets. What they hold, from a European perspective, is one of the richest personal data files a private company can accumulate.

SystemWhat it holdsWhy it matters under the GDPR
KYC vendorIdentity documents, selfies, liveness checksBiometric processing and a third-country transfer in one step
Core ledgerBalances, transactions, linked addressesFinancial data tied to an identified person
Chain analyticsRisk scores on addresses and counterpartiesProfiling, with consequences for the user
Support deskTickets, attachments, screen recordingsThe least controlled system in most exchanges
Marketing stackEmails, segments, campaign engagementConsent state that has to be provable

The third row is the one European regulators find most interesting, because a risk score that freezes an account is a decision about a person, taken automatically, with real consequences.

Practical order of work

  1. Designate

    A day, and it removes the easiest finding an authority can make against you.

  2. Map the five systems above

    Owner, location, retention, and whether the vendor is inside or outside the Union.

  3. Write the retention table

    AML minimums and GDPR minimisation pull in opposite directions; the resolution has to be written down, not assumed.

  4. Document the automated decisions

    Freezes, refusals and risk scores. Article 22 asks for meaningful information about the logic and a route to human review.

  5. Then look at MiCA and the travel rule

    Long projects with their own timelines. Nothing in them substitutes for the four steps above.

What the designation does not do

It does not authorise you under MiCA, it does not satisfy AML registration, and it does not make automated account freezes lawful. It gives supervisory authorities and users a contact point inside the Union and keeps the record of processing available. Providers implying more than that are selling something the regulation does not contain.

Timing, for a business planning European entry

Designate before the marketing starts rather than after the first users arrive. The obligation attaches to the processing, so a launch that pulls thousands of European sign-ups in a week creates the gap at exactly the moment your public profile is highest.

Questions European banking partners ask

For crypto businesses the practical pressure rarely comes from a supervisory authority first. It comes from a payment provider or a banking partner running its own onboarding review, and the data protection section of those questionnaires has become noticeably longer.

Who is your EU representative?

A name, an address and ideally a code they can verify without contacting you.

Where is KYC data stored?

Country, vendor, and the transfer mechanism if it leaves the Union.

How long is it kept?

The answer has to reconcile AML minimums with a stated retention period, not simply assert both.

Who can freeze an account?

Automated, manual, or both — and what route a user has to human review.

Request desk handling a data subject request about an account holder in the Union
Request desk handling a data subject request about an account holder in the Union
Data protection authority building in the European Union

Questions we are actually asked

Does MiCA replace the Article 27 obligation?

No. MiCA governs crypto-asset services and is supervised by financial regulators. Article 27 governs personal data and is supervised by data protection authorities.

We are a non-custodial wallet. Are we outside?

Not necessarily. If your interface collects analytics, emails, support tickets or optional KYC from users in the Union, you process their personal data.

Our entity is in Dubai or the Cayman Islands.

Location is what makes the obligation apply, not what removes it. Article 27 exists precisely for companies established outside the Union.

Are wallet addresses personal data?

When they can be linked to an identified account holder, yes. In the hands of the exchange holding the KYC file, that link exists by design.

We geo-block European users.

Effective blocking can put you outside Article 3(2). A banner asking users to confirm they are not in the EU is not effective blocking.

How does this interact with the travel rule?

The travel rule forces you to transmit originator and beneficiary data, which is more processing of personal data, not less. It strengthens the case for a designation.

Can our EU law firm act as representative?

Only if it signs the designation as the representative entity and operates the contact point. Advising you is a different service.

What if we suffer a breach?

Notification duties fall on you as controller. The representative is the point of contact authorities can address and holds the record they will ask for.

Do we need one during a token sale?

If people in the Union can participate, yes. Sale periods are exactly when data volumes spike and complaints follow.

Does an EU entity in the group solve it?

If that entity is genuinely established and is the controller for the processing, Article 27 does not apply to it. Group presence alone does not transfer the obligation.

What is the exposure?

Article 83(4)(a) puts it in the tier up to €10 million or 2% of worldwide annual turnover, and in this sector the absence is easy to establish from a public privacy notice.

How fast can we be covered?

Within 24 hours of a completed form, with the certificate and notice wording supplied at the same time.

What does it cost?

€290 a year for Base, €490 for Standard, €890 for Multi. Against the rest of a crypto compliance budget, it is the smallest line in the file.

Related: the SaaS version · acting as a processor

The smallest line in your compliance budget

A signed Article 27 designation within 24 hours, a certificate with a verification code, the Article 30 record held for you, and a desk that answers in eight languages.

See the plans