Appoint us
European supervisory authority that may address a US company through its representative

REP27 · United States

Article 27 GDPR · United States

GDPR representative for US companies.

American companies rarely fail Article 27 out of indifference. They fail it because they have already done something that looks like compliance — self-certified under the Data Privacy Framework, signed Standard Contractual Clauses, built a CCPA programme — and reasonably assume the European box is ticked. It is not. Those instruments solve transfers and state law. Article 27 solves something else entirely.

The EU-US Data Privacy Framework solves data transfers while Article 27 GDPR solves contactability: two separate obligations for US companies
Two instruments, two problems. Self-certifying does not designate anybody in the Union.

Four things US companies mistake for a representative

DPF self-certification

Governs the lawfulness of moving data to your US servers. Contains no obligation to have a contact point inside the Union, and the Department of Commerce is not one.

Standard Contractual Clauses

A contract between you and your counterparty. A data subject in Portugal is not a party to it and cannot write to it.

A CCPA or state privacy programme

Built around residents of California, Virginia, Colorado and the rest. Different law, different subjects, different regulator.

A privacy policy that mentions the GDPR

Article 27(1) requires a designation in writing naming a specific entity. A paragraph promising compliance names nobody.

When it starts applying to you

Article 3(2) has no revenue floor and no minimum number of European customers. These are the moments US companies typically cross the line without noticing.

What changes once you are appointed

BeforeAfter
No contact point in the UnionA named entity in Prague, addressable in eight languages
Privacy notice silent on Article 27Wording naming the representative, generated for each language your site uses
Article 30 record held only in the USHeld inside the Union and produced to an authority on request
Vendor questionnaires stall on the representative questionA certificate with a code the buyer can verify without contacting you
Exposure under Article 83(4)(a)The standalone infringement removed

What we do not do

Worth saying plainly, because some US providers blur it. A representative does not give legal advice, does not answer requests on the merits, does not negotiate with an authority for you, and cannot serve as your data protection officer — EDPB guidance treats those two roles as incompatible. We are the point of contact the regulation requires, performed properly, and nothing more.

Request desk in the Union receiving a data subject request for a US company
Request desk in the Union receiving a data subject request for a US company

Questions from US legal and privacy teams

We are certified under the Data Privacy Framework. Is that enough?

No, and this is the most frequent misunderstanding among US companies. Self-certification with the Department of Commerce addresses transfers of personal data from the Union to the United States. Article 27 addresses whether someone inside the Union can be contacted by a data subject or an authority. Both apply independently.

Does CCPA or another state law compliance help?

Not at all. State privacy laws govern the personal information of residents of that state. The GDPR governs the personal data of people in the Union, and Article 27 asks for a representative established there. Programmes built for state law do not touch it.

We are a B2B SaaS company. Does it still apply?

Usually yes. Business contacts are personal data under the GDPR: names, work emails and phone numbers of employees at your European client companies all count. Being B2B changes who the data subjects are, not whether the regulation applies.

We have a subsidiary in Ireland. Do we still need a representative?

Probably not, if that subsidiary is a real establishment carrying out the processing. Article 27 applies only where you have no establishment in the Union. A registered shell with no staff and no activity does not qualify.

What does it cost to ignore it?

Up to $10 million equivalent or 2% of worldwide annual turnover under Article 83(4)(a), assessed against the group, not the US entity alone. In practice the more common cost is commercial: European buyers ask for the representative's name during vendor onboarding and stall the deal without it.

Does a US law firm or our EU distributor count?

Anyone established in the Union can be designated if they accept the mandate in writing. Most distributors decline, because the role carries direct exposure to supervisory authorities and requires holding your Article 30 record on their premises.

Which authority would contact us?

The one where the complaining individual lives, not the one where your representative sits. A complaint from a Spanish customer is handled by the Spanish AEPD, which writes to the representative in whatever language it chooses.

How long does the appointment take?

The designation is issued within 24 hours of a completed onboarding form. The wording for your privacy notice comes with it, so the public part of the obligation is satisfied the same day.

Related: the Article 3(2) test · selling into Britain too? · what it costs

Check what your US site says right now

We read your public privacy notice and tell you in ten seconds whether a representative is named. If one is, we say so and you close the tab.

Run the free check   See pricing