
REP27 · Article 27 · The requirement
Article 3(2) · Article 27(1) · Article 27(2)
Every provider tells you the requirement exists. Almost none tell you how it is tested, which is why companies buy a designation they did not need or skip one they did. The regulation asks four questions in a fixed order, and the answer to each is factual rather than a matter of opinion. This page runs them, then shows the five documents an authority actually asks for when it wants to know whether you complied.
Article 3(2)EstablishmentOccasionalPublic authorityWritten designation

Order matters. Companies that start at test three convince themselves their processing is small, and never reach the question of whether they are established, which is the one that decides the case.
Two limbs, and only one has to be true. Offering goods or services to people in the Union, or monitoring their behaviour.
| Indicator | Weighs towards reach | On its own, not enough |
|---|---|---|
| Currency | Prices shown in euro | A currency switcher nobody uses |
| Language | Pages in German, French, Spanish | English, which is spoken everywhere |
| Shipping | EU destinations at checkout | Worldwide shipping, undifferentiated |
| Marketing | Ads targeted at EU countries | Being accessible from the Union |
| Tracking | Analytics and ad identifiers per user | Aggregate, anonymous counts |
Effective and real exercise of activity through stable arrangements: an office, staff, a branch that actually operates.
A cloud region, a third-party warehouse, a distributor, a reseller, a registered address with no activity behind it.
If you are established, Article 27 does not apply at all. If you are not, no amount of small volume saves you.
An EU sister company does not cover the entity that actually sells, unless that entity is the controller.
Article 27(2)(a) is the only exemption most companies could realistically use, and almost none qualify. All three conditions must hold at once.
Not repeated, not part of the ordinary course of business. A customer database fails here immediately.
Health, biometrics, political opinions and the rest, or criminal convictions data, processed on a large scale.
Assessed against the nature, scope, context and purposes, taking into account the rights of the people affected.
Failing any one of them ends the exemption. Most companies fail the first without needing to reach the others.

This is where the difference between providers appears. Having bought something is not the same as being able to show it on the day a letter arrives, in the language it arrived in, with the record of processing attached.
| Aspect | Position |
|---|---|
| Fine tier | Article 83(4)(a): up to €10 million or 2% of worldwide annual turnover |
| How it usually surfaces | During a complaint about something else, when the authority looks for a contact point |
| Aggravating effect | Absence of a representative is regularly cited alongside the primary breach |
| Commercial effect | Enterprise procurement and marketplace onboarding both ask for it |
| Fixing it later | Possible, but a designation dated after the complaint reads exactly as what it is |
These are the arguments we hear most often. Both have been run in front of authorities, and both failed.
| Argument | Why it fails |
|---|---|
| "Our EU customers came to us, we never marketed there" | Article 3(2) looks at whether you offer, not at who approached whom. Accepting orders, pricing in euro and shipping there is offering |
| "We only process business contact details" | A named individual at a company is still a natural person. Names, work emails and phone numbers are personal data |
| "Everything is anonymised" | Rarely true. If any identifier links back to a person, directly or through a third party, it is personal data |
| "Our EU entity signs the contracts" | Then that entity may be the controller, which changes the answer entirely. Document who decides purposes and means |
| "We are B2B, not consumer" | Article 3(2) does not distinguish. Selling software to European companies still processes the personal data of their staff |
Whether the requirement applies, and on which of the four tests you relied. Half a page, kept with your records.
Screenshots of your checkout, the countries you ship to, the SDKs you run. The facts that supported the conclusion at the time.
Expansion into a new market or a new analytics tool changes the answer. An annual look is enough for most companies.
Signed, published and verifiable. Everything above is preparation for this one document.
Nobody audits Article 27 on its own. It surfaces during something else, and by then the absence of a representative is an aggravating fact rather than a technicality. These are the five routes we see.
| Starting point | What gets checked | What is usually missing |
|---|---|---|
| An access request that went unanswered | Where the request should have arrived | No contact point inside the Union at all |
| A cookie or tracking complaint | The privacy notice, line by line | No representative named under Article 13(1)(a) |
| A personal data breach notification | The Article 30 record and who holds it | Records that do not exist in the Union |
| A vendor assessment by an enterprise client | The designation and how to verify it | An unsigned PDF, or a provider nobody can check |
| A marketplace or app store review | Published trader and privacy details | Inconsistency between the notice and the store listing |
The pattern is worth internalising: the representative is never what draws attention, and it is always what determines how expensive the attention becomes. A company with a signed designation, a published paragraph and a record produced within days is treated as organised. A company that has to build all three after the letter arrives is treated as one that never intended to comply.
Usually SaaS or ecommerce, convinced that an EU cloud region or a DPO on the org chart covers the requirement. Neither does.
A third country since 2021. The most common case, and the one where old documentation actively misleads.
Service exporters processing for European clients. Processors are caught directly, not through their customers' contracts.
Consumer goods sellers, who normally need the Article 16 responsible person at the same time and discover both when a marketplace blocks them.
Outside the Union and outside the EEA. Needs the EU designation for its EU customers, plus a separate Swiss arrangement no EU provider can supply.
The test does not vary by country. Adequacy, free trade agreements and customs unions change other things and never this one.
If you are not established in the Union and you sell to or track people there in the ordinary course of business, the requirement applies, and the only question left is whether you can prove it was met on the day someone asked. Everything on this page exists to make that proof a two-minute exercise rather than a two-week scramble.


No. Article 27 has no employee, turnover or volume threshold. The only exemptions are establishment in the Union, the narrow occasional-processing case and being a public authority.
No. Recital 22 asks for effective and real activity through stable arrangements. Hosting is infrastructure, not establishment.
No. Articles 37-39 create a different role with different duties. Both may be required at the same time.
Yes, on the same terms as controllers, whenever Article 3(2) reaches them.
No. Adequacy concerns transfers of data, not the duty to be reachable inside the Union.
Then look at the other indicators: currency, targeted marketing, EU shipping options, tracking. Accessibility alone has never been enough, but it rarely stands alone.
There is no number. Repeated processing in the ordinary course of business is not occasional, whatever its volume.
One where your data subjects are. Within that group the choice is yours; a single designation covers the Union and the EEA.
No. The UK GDPR requires a separate representative established in the United Kingdom.
Only if it is established in the Union and has signed a designation accepting the role. A commercial relationship is not an appointment.
The identity and contact details of the representative, in your privacy notice, under Article 13(1)(a).
The representative receives, logs and forwards it. The substantive decision stays with you as controller.
No. Article 27(5) states the designation is without prejudice to actions against the controller or processor.
Within 24 hours of a completed form, with a certificate carrying a verification code.
From €290 a year, €240 on renewal, and the same price if you are moving from another provider.
Then you may no longer need the designation. Tell us and we terminate it rather than renewing something you have outgrown.
Related: the short version of this test · the same test for a non-EU company
Europe Services, SE in Prague as your Article 27 representative across all 27 Member States and the EEA, with a verifiable certificate and the Article 30 record held for you.
See the plans