
REP27 · Do we need one · Non-EU companies
Article 3(2) · Article 27(1) · Article 27(2)
The question is answered by four tests, in the order the regulation sets them out, and the answer almost never turns on the industry or the size of the company. It turns on whether a GDPR representative for a non-EU company is required at all: whether you are established in the Union, whether Article 3(2) reaches you, whether your processing is genuinely occasional, and whether you are a public authority. Everything else — where your servers are, whether you have a DPO, whether an adequacy decision applies — is noise that has been argued and lost.
United StatesUnited KingdomIndiaChinaHong KongCanadaAustraliaBrazil
Answering them out of order is how companies convince themselves they are exempt. The regulation asks about establishment first, and only then about what you do.

| Question | What counts | What does not |
|---|---|---|
| Established in the Union? | An office, staff, effective and real activity through stable arrangements | A cloud region, a 3PL warehouse, a reseller, a mailbox |
| Article 3(2) reached? | EU currency, language, shipping, targeted ads, EU domains | Being merely accessible from the Union |
| Processing occasional? | A one-off event with no retained records | A customer database, order history, a newsletter |
| Public authority? | Public bodies under Article 27(2)(b) | Private companies of any size |
Each of these has been argued by a company that later paid for it. They are worth reading as warnings rather than as theory.

The EU representative requirement is not satisfied by choosing a supplier. It is satisfied by a document with five properties.
To appoint an EU representative you need a mandate signed by both sides. A supplier who has not countersigned is not your representative, whatever your website says.
Article 27(3). Within the group of countries where your users sit, the choice is yours.
Article 13(1)(a) requires the identity of the representative in your privacy notice. An unpublished designation protects nobody.
The representative keeps the record of processing activities available to authorities, which is the part most first-time clients have never prepared.
An address that answers. Requests arriving at a dead inbox are treated as requests you failed to handle.
Enforcement involving Article 27 rarely starts with Article 27. It starts with a complaint about something else, and the missing representative is discovered while the file is being opened.
| How it starts | What gets checked | What is usually missing |
|---|---|---|
| A data subject access request ignored | Who the request should have reached | No contact point inside the Union |
| A cookie or tracker complaint | The privacy notice | No representative named under Article 13(1)(a) |
| A data breach notification | Article 30 records | No records held anywhere in the Union |
| A procurement or audit review | The designation itself | An unsigned or unverifiable document |
Usually a SaaS or ecommerce company that assumed an EU cloud region was enough, and that a DPO on the org chart covered the rest.
Post-Brexit, a third country like any other. Needs an EU representative, and its EU customers are often unaware the position changed.
Service exporters processing on behalf of EU clients. Processors, so Article 27 applies to them directly rather than through their customers.
Consumer goods sellers. Almost always need Article 16 as well, and discover both at the same time when a marketplace blocks them.
Outside the Union. Needs the EU designation for its EU customers, plus a separate Swiss arrangement that no EU provider can supply.
Article 27 and Article 30 together define the job, and it is narrower and more concrete than most first-time clients expect.
| Duty | Where it comes from | In practice |
|---|---|---|
| Act as the point of contact | Article 27(4) | Authorities and data subjects address the representative in addition to, or instead of, you |
| Maintain the record of processing | Article 30(1) and 30(2) | The record is held and made available to authorities on request |
| Cooperate with supervisory authorities | Article 31 | Requests are answered, logged and forwarded to you the same working day |
| Be reachable in the right language | Practice, not text | Eight languages, so a complaint does not become a second complaint |
Registered name, number and address in your own country. No apostille, no notarisation, no translation.
Someone able to bind the company. A director or an officer; a marketing manager will be questioned later.
What you collect, from whom in the Union, why, and who else touches it. A page is enough and it becomes your Article 30 record.
An inbox at your end that is actually read, because everything the desk receives is forwarded there.
So the published identity of the representative can be checked against the designation.
Companies expecting a month-long onboarding are usually thinking of a certification. This is a designation: one form, one countersignature, one published paragraph.


No. Recital 22 asks for effective and real activity through stable arrangements. Renting infrastructure is not that, and the argument has been run and rejected.
No. A DPO advises you under Article 37. A representative is a point of contact inside the Union under Article 27. Different roles, both possibly required.
Only a written designation, signed by an entity established in the Union, creates a representative. A commercial relationship does not, however close it is.
There is no threshold. A customer list plus an order history plus a newsletter is continuous processing and fails Article 27(2)(a) immediately, even at small volumes.
No. Adequacy governs transfers. It has no effect on Article 27, and companies in adequate countries designate on exactly the same terms.
Article 83(4)(a) puts it in the tier up to €10 million or 2% of worldwide annual turnover, and its absence is regularly treated as an aggravating factor in other proceedings.
It can be a natural or legal person established in the Union, but authorities and enterprise clients expect a company with a verifiable registration behind it.
Within 24 hours of a completed onboarding form. The certificate and the verification code are issued at the same time, so you can send proof to a client the same day.
No. One designation covers data subjects across all 27. What Article 27(3) governs is where the representative itself is established.
The signed designation, the privacy notice showing the representative under Article 13(1)(a), and the record of processing activities under Article 30. Those three, in that order.
If a group entity established in the Union carries out the processing as controller, the analysis changes entirely. If it merely exists while the non-EU parent decides everything, the parent still needs a representative.
Not for this. The obligation is triggered by offering services or monitoring behaviour, not by how long you keep the data afterwards.
It is the same idea in a separate statute. Serving both territories means two designations, one established in the Union and one in the United Kingdom.
Related: the short version of this test · a subsidiary instead of a representative
Europe Services, SE in Prague, active since 2018, as your Article 27 representative across all 27 Member States, with a certificate carrying a verification code and a request desk in eight languages.
See the plans