Appoint us
Supervisory authority reviewing whether a company met the Article 27 requirement

REP27 · Article 27 · The requirement

Article 3(2) · Article 27(1) · Article 27(2)

The EU representative requirement, tested properly.

Every provider tells you the requirement exists. Almost none tell you how it is tested, which is why companies buy a designation they did not need or skip one they did. The regulation asks four questions in a fixed order, and the answer to each is factual rather than a matter of opinion. This page runs them, then shows the five documents an authority actually asks for when it wants to know whether you complied.

Article 3(2)EstablishmentOccasionalPublic authorityWritten designation

See the plans   Ask a question

The four tests, in order

The four tests that decide whether the EU representative requirement applies
The four tests that decide whether the EU representative requirement applies

Order matters. Companies that start at test three convince themselves their processing is small, and never reach the question of whether they are established, which is the one that decides the case.

Test one: does Article 3(2) reach you

Two limbs, and only one has to be true. Offering goods or services to people in the Union, or monitoring their behaviour.

IndicatorWeighs towards reachOn its own, not enough
CurrencyPrices shown in euroA currency switcher nobody uses
LanguagePages in German, French, SpanishEnglish, which is spoken everywhere
ShippingEU destinations at checkoutWorldwide shipping, undifferentiated
MarketingAds targeted at EU countriesBeing accessible from the Union
TrackingAnalytics and ad identifiers per userAggregate, anonymous counts
Mere accessibility of a website from the Union has never been enough on its own. Everything else in the middle column has been.

Test two: are you established in the Union

What counts

Effective and real exercise of activity through stable arrangements: an office, staff, a branch that actually operates.

What does not

A cloud region, a third-party warehouse, a distributor, a reseller, a registered address with no activity behind it.

Why it decides everything

If you are established, Article 27 does not apply at all. If you are not, no amount of small volume saves you.

Group structures

An EU sister company does not cover the entity that actually sells, unless that entity is the controller.

Test three: is the processing genuinely occasional

Article 27(2)(a) is the only exemption most companies could realistically use, and almost none qualify. All three conditions must hold at once.

  1. Occasional

    Not repeated, not part of the ordinary course of business. A customer database fails here immediately.

  2. No special categories at scale

    Health, biometrics, political opinions and the rest, or criminal convictions data, processed on a large scale.

  3. Unlikely to result in risk

    Assessed against the nature, scope, context and purposes, taking into account the rights of the people affected.

  4. All three, together

    Failing any one of them ends the exemption. Most companies fail the first without needing to reach the others.

Proving the requirement is met

The five documents an authority asks for to prove the Article 27 requirement is met
The five documents an authority asks for to prove the Article 27 requirement is met

This is where the difference between providers appears. Having bought something is not the same as being able to show it on the day a letter arrives, in the language it arrived in, with the record of processing attached.

What non-compliance is worth

AspectPosition
Fine tierArticle 83(4)(a): up to €10 million or 2% of worldwide annual turnover
How it usually surfacesDuring a complaint about something else, when the authority looks for a contact point
Aggravating effectAbsence of a representative is regularly cited alongside the primary breach
Commercial effectEnterprise procurement and marketplace onboarding both ask for it
Fixing it laterPossible, but a designation dated after the complaint reads exactly as what it is

Two situations that look exempt and are not

These are the arguments we hear most often. Both have been run in front of authorities, and both failed.

ArgumentWhy it fails
"Our EU customers came to us, we never marketed there"Article 3(2) looks at whether you offer, not at who approached whom. Accepting orders, pricing in euro and shipping there is offering
"We only process business contact details"A named individual at a company is still a natural person. Names, work emails and phone numbers are personal data
"Everything is anonymised"Rarely true. If any identifier links back to a person, directly or through a third party, it is personal data
"Our EU entity signs the contracts"Then that entity may be the controller, which changes the answer entirely. Document who decides purposes and means
"We are B2B, not consumer"Article 3(2) does not distinguish. Selling software to European companies still processes the personal data of their staff

What to write down, whatever the answer

  1. Your conclusion, dated

    Whether the requirement applies, and on which of the four tests you relied. Half a page, kept with your records.

  2. The evidence behind it

    Screenshots of your checkout, the countries you ship to, the SDKs you run. The facts that supported the conclusion at the time.

  3. A review date

    Expansion into a new market or a new analytics tool changes the answer. An annual look is enough for most companies.

  4. The designation, if it applies

    Signed, published and verifiable. Everything above is preparation for this one document.

How authorities actually find the gap

Nobody audits Article 27 on its own. It surfaces during something else, and by then the absence of a representative is an aggravating fact rather than a technicality. These are the five routes we see.

Starting pointWhat gets checkedWhat is usually missing
An access request that went unansweredWhere the request should have arrivedNo contact point inside the Union at all
A cookie or tracking complaintThe privacy notice, line by lineNo representative named under Article 13(1)(a)
A personal data breach notificationThe Article 30 record and who holds itRecords that do not exist in the Union
A vendor assessment by an enterprise clientThe designation and how to verify itAn unsigned PDF, or a provider nobody can check
A marketplace or app store reviewPublished trader and privacy detailsInconsistency between the notice and the store listing

The pattern is worth internalising: the representative is never what draws attention, and it is always what determines how expensive the attention becomes. A company with a signed designation, a published paragraph and a record produced within days is treated as organised. A company that has to build all three after the letter arrives is treated as one that never intended to comply.

The five countries we are asked about most

United States

Usually SaaS or ecommerce, convinced that an EU cloud region or a DPO on the org chart covers the requirement. Neither does.

United Kingdom

A third country since 2021. The most common case, and the one where old documentation actively misleads.

India

Service exporters processing for European clients. Processors are caught directly, not through their customers' contracts.

China and Hong Kong

Consumer goods sellers, who normally need the Article 16 responsible person at the same time and discover both when a marketplace blocks them.

Switzerland

Outside the Union and outside the EEA. Needs the EU designation for its EU customers, plus a separate Swiss arrangement no EU provider can supply.

Everyone else

The test does not vary by country. Adequacy, free trade agreements and customs unions change other things and never this one.

One sentence to take away

If you are not established in the Union and you sell to or track people there in the ordinary course of business, the requirement applies, and the only question left is whether you can prove it was met on the day someone asked. Everything on this page exists to make that proof a two-minute exercise rather than a two-week scramble.

Working through the Article 27 requirement test with a company outside the Union
Working through the Article 27 requirement test with a company outside the Union
Request desk producing the evidence that the requirement is met

Questions we are actually asked

Is there a size threshold?

No. Article 27 has no employee, turnover or volume threshold. The only exemptions are establishment in the Union, the narrow occasional-processing case and being a public authority.

Does an EU cloud region satisfy the requirement?

No. Recital 22 asks for effective and real activity through stable arrangements. Hosting is infrastructure, not establishment.

We have a DPO. Is that enough?

No. Articles 37-39 create a different role with different duties. Both may be required at the same time.

Do processors need one?

Yes, on the same terms as controllers, whenever Article 3(2) reaches them.

Does an adequacy decision remove the requirement?

No. Adequacy concerns transfers of data, not the duty to be reachable inside the Union.

What if we only sell in English and ship worldwide?

Then look at the other indicators: currency, targeted marketing, EU shipping options, tracking. Accessibility alone has never been enough, but it rarely stands alone.

How occasional is occasional?

There is no number. Repeated processing in the ordinary course of business is not occasional, whatever its volume.

Which Member State should we choose?

One where your data subjects are. Within that group the choice is yours; a single designation covers the Union and the EEA.

Does the requirement cover the UK?

No. The UK GDPR requires a separate representative established in the United Kingdom.

Can our EU distributor be named?

Only if it is established in the Union and has signed a designation accepting the role. A commercial relationship is not an appointment.

What has to be published?

The identity and contact details of the representative, in your privacy notice, under Article 13(1)(a).

Who answers a data subject request?

The representative receives, logs and forwards it. The substantive decision stays with you as controller.

Does the representative take on our liability?

No. Article 27(5) states the designation is without prejudice to actions against the controller or processor.

How quickly can it be in place?

Within 24 hours of a completed form, with a certificate carrying a verification code.

What does it cost?

From €290 a year, €240 on renewal, and the same price if you are moving from another provider.

What if we later open an EU office?

Then you may no longer need the designation. Tell us and we terminate it rather than renewing something you have outgrown.

Related: the short version of this test · the same test for a non-EU company

Requirement met, in writing, in 24 hours

Europe Services, SE in Prague as your Article 27 representative across all 27 Member States and the EEA, with a verifiable certificate and the Article 30 record held for you.

See the plans