Appoint us
Supervisory authority reviewing a privacy notice for the Article 27 representative

REP27 · Enforcement

Article 83(4)(a) · Enforcement

What a missing EU representative actually costs.

Article 27 is unusual among GDPR obligations: it can be checked from outside, in a browser, in about ten seconds. There is no need to audit your systems or read your contracts — either your privacy notice names an entity established in the Union, or it does not. That visibility is why the missing designation turns up so often in enforcement, and why it is treated as a breach on its own.

Exposure under Article 83(4)(a) GDPR: 2% of worldwide annual turnover or 10 million euro, whichever is higher
Whichever is higher — turnover is assessed at group level.

What an authority can see before contacting you

What a supervisory authority checks first: whether a representative is named, whether it is established in the Union, whether there is a working contact route, whether the designation is active
Three of five checks are settled without ever contacting you.

This is the practical reason the wording on your site matters as much as the mandate behind it. A designation that exists but is not published is invisible to exactly the people it was created for.

How the amount is arrived at

Article 83(2) lists the factors. Four of them are directly affected by how quickly you act.

FactorWhat it means here
Nature and gravityWhether data subjects had any route to reach you at all
DurationHow long the processing ran with no designation in place
Intentional or negligentWhether the obligation was known and left unaddressed
Mitigating stepsAppointing promptly once identified counts here
CooperationAnswering through a working contact point rather than silence
Previous infringementsWhether the same gap was raised before
Duration is the factor most within your control today. Every month without a designation is a month added to it.

The cost that arrives first

In our experience the regulator is rarely the first consequence. A European enterprise buyer asks for the representative's name in a security questionnaire, the field comes back blank, and the file goes to legal. The deal does not die — it slips, and the slip is measured in quarters.

That is the argument that persuades finance teams: not the theoretical ceiling under Article 83, but the contract that stopped moving because of a missing line in a privacy notice.

Why this obligation gets enforced disproportionately

Supervisory authorities have limited resources and a large mandate. What they can act on cheaply, they act on more often — and Article 27 is the cheapest thing in the regulation to verify.

Establishing whether a company's security measures are appropriate under Article 32 takes an investigation, technical expertise and months. Establishing whether a privacy notice names a representative established in the Union takes a browser and a minute, in any language, without notifying anyone. An authority can survey a hundred non-EU websites serving its market in an afternoon.

That asymmetry shapes enforcement in a way worth understanding. The missing designation is rarely the reason an investigation starts, but it is very often the first thing recorded once one has, because it is already established before the first letter is sent. It also colours everything that follows: a company that never provided a contact point is harder to characterise as diligent on the other Article 83(2) factors.

The inverse is equally true. A designation published clearly, verifiable independently and in place from the beginning, is the cheapest evidence of good faith available in the entire regulation.

Questions about enforcement

Is failing to designate a representative really a separate infringement?

Yes. Article 83(4)(a) lists Article 27 among the provisions whose breach attracts the lower tier of fines, and EDPB Guidelines 3/2018 state that the absence of a designation is a breach in its own right. It does not need to accompany a data breach or any other failure.

What is the maximum?

Up to €10 million, or 2% of worldwide annual turnover of the preceding financial year, whichever is higher. Turnover is assessed at group level, not for the entity that happens to have signed the contract.

Have authorities actually fined for this alone?

Yes. Several supervisory authorities have issued penalties where the missing representative was among the infringements found, and it is a standard finding in investigations of non-EU websites. It is also one of the easiest things for an authority to establish: the privacy notice is public.

What triggers an investigation in practice?

Usually a complaint from a data subject who could not find anyone to write to, or a sweep by an authority reading privacy notices in its own market. Both start from what your site says publicly.

Does appointing one late fix the exposure?

It stops the ongoing breach, which matters: authorities weigh the duration of the infringement and the steps taken. It does not erase the period during which no designation existed.

Is the risk mainly regulatory?

For most companies the commercial cost arrives first. European buyers ask for the representative during vendor onboarding, and a missing answer stalls contracts long before any authority writes.

Does a small company face the same exposure?

The ceiling is proportionate, since 2% of a small turnover is a small number, but the €10 million alternative applies where it is higher. Authorities also consider cooperation and duration, which is why prompt appointment matters more than size.

Close the gap today, not next quarter

Designation signed within 24 hours, with the wording your notice needs and a certificate anyone can verify.

Appoint us   Check your notice first
Reviewing exposure under Article 83(4)(a) for a missing designation
Reviewing exposure under Article 83(4)(a) for a missing designation