Appoint us
Request desk in the Union receiving a data subject request on behalf of a processor

REP27 · Processors

Article 27 GDPR · Processors

EU representative for processors and sub-processors.

Processors are covered by Article 27 on exactly the same terms as controllers, and almost none of them know it. The assumption is that the client's designation covers the supply chain. It does not: a designation covers the entity that signed it, so a hosting provider, a support desk, an analytics vendor or a BPO operation outside the Union needs one of its own.

Controller and processor compared: Article 30(1) record versus Article 30(2) record, and how data subject requests are routed
Both need a representative. What differs is the record it holds.

What actually differs for a processor

The obligation is identical; three practical things around it are not.

The record

Article 30(2) rather than 30(1): categories of processing per controller, transfers, and a general description of security measures.

The routing

Requests reaching you are passed to the controller under your Article 28 contract, not answered by you.

The notice

You appear in your client's privacy notice, not in your own consumer-facing one — which is why the obligation is so easy to overlook.

The buyer

Your client's procurement team, not a regulator, is usually the first to ask for the designation.

What happens when a request arrives

How a data subject or authority request is logged, referenced and routed when the representative acts for a processor
A post box with a log and a clock, not a decision maker.

Who this catches

Type of supplierRoleRepresentative needed
Cloud hosting outside the EUProcessorYes
Outsourced customer supportProcessorYes
Payroll or HR platformProcessorYes
Analytics vendor with user identifiersProcessor, sometimes joint controllerYes
Sub-processor of the aboveProcessorYes
Supplier that never touches personal dataNeitherNo

The supply chain question nobody asks

European controllers have spent years mapping their processors. What almost nobody has mapped is whether those processors are themselves within Article 3(2) and, if so, whether they have a designation of their own.

The chain is usually longer than the contract suggests. A European retailer uses a US e-commerce platform, which uses a Canadian search vendor, which uses an Indian support desk. Each of the three is a processor or sub-processor established outside the Union, each processes personal data of people in the Union, and each needs its own representative. The retailer's designation covers the retailer, and nothing else.

This is starting to surface in due diligence. Article 28(1) requires controllers to use only processors providing sufficient guarantees, and the more sophisticated questionnaires now ask not only for your representative but for confirmation that your own sub-processors have one. Being able to answer that quickly is becoming a differentiator among suppliers competing for the same European account.

For a sub-processor the calculation is simple. The designation costs less than the time spent explaining its absence during a single procurement cycle.

Questions from processors

Does Article 27 really apply to processors?

Yes. Article 27(1) refers to controllers and processors alike, and EDPB Guidelines 3/2018 confirm it. A processor established outside the Union that processes personal data of people in the Union, on behalf of any client, must designate a representative of its own.

Our client already has a representative. Can we rely on theirs?

No. A designation covers the entity that signed it. Your client's representative was mandated by your client, has no relationship with you, and cannot answer for your processing. This is the single most common mistake we correct on processor files.

Which record does our representative hold?

The record under Article 30(2): the categories of processing carried out on behalf of each controller, the transfers you make, and a general description of your security measures. Not the full controller record under Article 30(1).

What happens when a data subject writes to us directly?

The request is logged, referenced and forwarded to you, and you route it to the controller whose data it concerns under your Article 28 contract. Neither you nor the representative decides the outcome — the controller answers on the merits.

We are a sub-processor. Does that change anything?

Not in principle. Sub-processors are processors, and the territorial test in Article 3(2) is applied to your own activity. In practice sub-processors are often the last in the chain to appoint, which is why enterprise buyers now ask about them explicitly.

Does having a representative make us liable for our client's compliance?

No. Article 27(5) is explicit that designating a representative does not affect legal actions against the controller or processor itself. It creates a contact point, not a transfer of responsibility.

Will our clients ask for this?

Increasingly, yes. European controllers are required under Article 28 to use only processors providing sufficient guarantees, and their vendor questionnaires now include the representative's name and address as a line item.

Designation issued in your own name

With the Article 30(2) record held inside the Union, so your clients' questionnaires stop stalling.

Appoint us
Processor and its European clients, each with their own Article 30 record
Processor and its European clients, each with their own Article 30 record