
REP27 · Changing provider · Expired designation
Article 27 · lapse, renewal and re-designation
Designations rarely end in an argument. They end because an invoice arrived in a month nobody was watching, a card expired, or a provider stopped answering. The result is quieter and worse than a cancellation: your privacy notice keeps naming a representative, requests keep arriving at an address that no longer accepts them, and the gap is dated from the lapse rather than from the day you noticed it.
LapsedUnpaid invoiceProvider silentNotice out of dateSwitch price €240

Step three is the one that turns an administrative slip into a file. A data subject request that reaches a dead address still starts the one-month clock in Article 12(3), and the failure to answer it is a separate infringement from the failure to hold a designation.

Most providers renew at the first-year price, because the first year is where the acquisition cost sits and the second is where the margin does. Our renewal is €240 for Base, €390 for Standard and €690 for Multi, and a designation moved from another provider is priced as a switch rather than as a new appointment.
The end date on the old mandate, or the last invoice actually paid. Guessing here is worse than an uncomfortable exact answer.
Countersigned within 24 hours, valid for data subjects across all 27 Member States.
Until you do, your published contact point is false, which is its own problem under Article 13.
The previous provider should hand over requests received during the gap. Answer them, late and documented, rather than not at all.
A short note in the Article 30 record: lapse date, cause, correction date. Authorities treat a documented, corrected failure very differently from a discovered one.
If you hold both an EU and a UK designation, keep them on the same expiry so a single reminder covers both.
The most common cause of lapse is an invoice sent to somebody who left the company.
A code anyone can check tells you in seconds whether the designation is still live, without emailing the provider.
We write before expiry, not after, and a designation is never terminated silently for non-payment.
Almost never by the company that lapsed. These are the five routes, in the order we see them.
| Route | What happens | How much warning |
|---|---|---|
| A data subject request bounces | The sender complains to their national authority | None |
| A customer audit | A European buyer checks the certificate and finds it dead | Days, and a stalled deal |
| An unrelated investigation | The authority reviews the notice and the designation | None |
| A payment provider review | Compliance questionnaire at renewal | Weeks |
| An internal handover | Someone new reads the privacy notice properly | The best case: you found it yourself |
Article 83(2) lists the factors: the nature and duration of the infringement, whether it was negligent, what was done to mitigate it, and the degree of cooperation. A lapse touches every one of them, which is why the response matters more than the lapse.
Measured from the lapse date. A gap of weeks reads very differently from a gap of two years.
Re-designating and answering the pending requests, before anyone asked you to, is the clearest mitigation available.
An accurate timeline handed over on request beats a reconstruction produced under pressure.
A first lapse corrected quickly is administrative. A second one, after the first was noticed, is negligence.
The old mandate with its end date, the last certificate and its code, any correspondence with the previous provider, and the current text of your privacy notice. Those four documents let us date the gap precisely and produce a replacement that matches the entity your notice already names, which avoids a second correction a week later.
The useful way to think about the annual renewal is as the one moment each year when somebody reads the privacy notice, checks that the entity named there still exists and confirms that the desk still answers. Treated as an invoice it is a cost; treated as a control it is the cheapest review in the compliance calendar, and it is the reason a second lapse almost never happens to a company that has had a first one.
Does it still name the right entity, at the right address, in every language version of the site?
Verify your own certificate as an outsider would, from a browser with no session.
Confirm the inbox that receives forwarded requests is still read by somebody who works here.
Add anything new: a marketing tool, a new market, a new processor. Five minutes now, or a reconstruction later.


The mandate ends on its terms, so from that date you have no representative. There is no grace period in the regulation, only in practice.
It matters if a request arrives, if you are audited, or if another issue brings a supervisory authority to your file. The absence is dated and easy to establish.
Then you have a representative on paper that does not perform the role, which is worse than none: your notice points people at an address that ignores them. Re-designate.
No, and you should not try. A designation runs from the day it is signed. What you can do is document the gap and correct it visibly.
There is no notification duty for the lapse itself. If an unanswered request is discovered, the honest sequence of dates in your records is what protects you.
Ask the old provider to forward them and answer them now, noting the delay. A late answer is a much smaller problem than a silent one.
Within 24 hours of a completed form. The privacy notice update takes minutes once you have the wording.
No. The new designation is signed and published first; the old one is terminated afterwards, so there is never an uncovered day.
It should, and most do. Ask in writing; the record concerns your processing, not theirs.
€240 for Base, €390 for Standard, €690 for Multi, which is our renewal price rather than a new-appointment price.
The old one stops working when that designation ends. The new certificate carries a new code, which is what you publish from then on.
You can, but there is little point: one valid designation is enough, and two published contact points confuses data subjects.
Keep the old mandate and certificate. Continuity of designation is exactly the kind of evidence that turns a serious finding into a minor one.
Related: how to change provider · how to verify a designation is real
A new designation signed within 24 hours at the switch price, with the privacy notice wording and a certificate carrying a code anyone can verify.
Re-designate now