
Article 26(3) NIS2 · Article 27 GDPR · comparison
The vocabulary is identical and the consequences are not. Both put a named entity inside the Union, both are signed in writing, both are addressed by authorities. But one of them is about the security of networks and information systems and decides which Member State supervises you, while the other is about personal data and creates a contact point without changing jurisdiction. Companies that hold one and assume it covers the other are the most common case we see, and the mistake surfaces at the worst possible moment.
Article 26(3)Article 27 GDPRJurisdictionRegistrationBoth

The line that matters most is the second on each side. NIS2 assigns jurisdiction: the Member State of your representative becomes your supervisory state. The GDPR designation does nothing of the sort, and a controller outside the Union has no lead authority at all.
| Company | NIS2 representative | Article 27 representative |
|---|---|---|
| US cloud provider with EU customers | Yes | Yes, as processor |
| Indian managed service provider | Yes | Yes, usually as processor |
| Non-EU online marketplace | Yes, Annex II | Yes, as controller |
| Non-EU ecommerce shop selling goods | No | Yes |
| Non-EU SaaS not in Annex I or II | No | Yes, if Article 3(2) reaches it |
| EU-established provider | No | No |
| Non-EU search engine | Yes, Annex II | Yes |
NIS2 is a directive transposed by each Member State; the GDPR is a regulation applying directly. Details vary in the first, not in the second.
NIS2: providing one of the listed services in the Union. GDPR: offering goods or services to people in the Union, or monitoring their behaviour.
NIS2 assigns it through the representative's Member State. Article 27 does not assign anything: every authority whose residents you reach may act.
NIS2 has one, under Article 27 of the directive. The GDPR has no registry of representatives anywhere in the Union.
NIS2: documentation at the authority's disposal. GDPR: the Article 30 record of processing activities.
NIS2 has hard deadlines, 24 and 72 hours, that stay with the entity. The GDPR has 72 hours for personal data breaches, also with the controller.
Essential entities under NIS2 face proactive inspection. Data protection authorities act on complaints and investigations.
NIS2: at least €10 million or 2% for essential entities. GDPR Article 83(4)(a): up to €10 million or 2% for a missing representative.

The saving is not the point. The point is one renewal date, one desk and one place where correspondence lands, because the two failures we see most often are a mandate lapsing quietly and a request bouncing between two providers.
Incident notifications under NIS2 and breach notifications under the GDPR stay with the entity. They depend on facts only you have.
Article 21 NIS2 and Article 32 GDPR are internal work: measures, controls, testing, training.
Article 27(5) GDPR says so expressly, and NIS2 keeps the entity accountable with management personally on the hook.
Where a national transposition adds requirements, you need a firm in that Member State. We say so before you buy, not after.
| Ask | If yes |
|---|---|
| Do we provide DNS, cloud, data centre, CDN, managed services, a marketplace, a search engine or a social platform in the Union? | NIS2 representative under Article 26(3) |
| Do we offer goods or services to people in the Union, or monitor their behaviour? | Article 27 GDPR representative |
| Both of the above? | Both mandates, ideally with one provider and one renewal date |
| Is the entity that does these things established in a Member State? | Neither, for that entity |
| Do we also sell physical products to consumers? | Add the Article 16 GPSR responsible person |
Companies comparing NIS2 with the GDPR usually discover that the same structural question has two more answers waiting behind it. Worth knowing now rather than during an audit.
| Mandate | Law | Who needs it | Where it appears |
|---|---|---|---|
| NIS2 representative | Directive (EU) 2022/2555 | Listed digital service providers outside the Union | The entity registration |
| Article 27 representative | Regulation (EU) 2016/679 | Controllers and processors reached by Article 3(2) | Your privacy notice |
| UK representative | UK GDPR | Companies outside the UK reaching people there | Your privacy notice |
| Article 16 responsible person | Regulation (EU) 2023/988 | Anyone placing consumer products on the EU market | The product label |
A company selling a hosted product and a piece of hardware can genuinely need all four. That sounds like an upsell and it is simply the shape of European law: four statutes, four different things being protected, four separate written designations. What is not necessary is four suppliers, four renewal dates and four inboxes.
Nine times out of ten it means Article 27. Send that certificate and the privacy notice paragraph.
It means the Article 26(3) mandate and, usually, your registration reference.
That is product legislation. Send the Article 16 designation if you have goods, or say plainly that it does not apply.
Send both certificates with one line each. Two sentences close the thread; a clarifying email costs a week.
Under NIS2, the authority of the Member State where your representative is established. Under the GDPR, any authority whose residents you reach.
Neither regime issues one. Send the designations and the description of your measures instead.
One law protects networks and information systems, the other protects personal data. The NIS2 mandate assigns jurisdiction and comes with a registration; the Article 27 designation creates a contact point and is published in your privacy notice. Neither reports incidents for you, neither implements security measures, neither moves your liability. Most companies that need one of them need the other, and holding both with one provider means one renewal date, one desk and one place where correspondence lands. That is the whole comparison, and everything above is the detail behind it.
Most companies arrive here holding the Article 27 designation and discovering NIS2, or the reverse. The order of work is different in each case.
| You already have | What to check first | Then |
|---|---|---|
| Article 27 GDPR designation | Whether any of your services appear in Annex I or II | Add the NIS2 mandate and align the renewal dates |
| NIS2 mandate | Whether Article 3(2) GDPR reaches you as controller or processor | Add the Article 27 designation and publish it in the notice |
| Both, with different providers | The two renewal dates and who answers what | Consolidate at the next renewal, taking the request logs with you |
| Neither, and unsure | Which entity provides which service, and where it is established | Run both tests on paper before buying anything |
The last row is the honest one. Buying a designation you do not need is waste, and we would rather tell you that on the intake call than sell it and have you discover it during an audit.
If your service appears in Annexes I or II of NIS2 you need the Article 26(3) mandate and a registration; if you reach people in the Union with goods, services or tracking you need the Article 27 designation published in your privacy notice; most companies that need one need the other, and the only thing worth optimising is that both live with one provider, on one renewal date, with one desk that answers.
In English, French, German, Italian and Spanish the same noun covers both roles, and translations of vendor questionnaires make it worse rather than better. Asking which regulation the question comes from resolves it in one message, and it is the single most useful habit in this area.
Article 27 became a live concern for many companies only when enforcement picked up, and NIS2 arrived while that was still settling. Teams reasonably assume the second is a version of the first, and then apply GDPR reflexes to a directive that works by sector and assigns jurisdiction.


No. Different law, different trigger, different consequences. One covers network and information security and assigns jurisdiction; the other covers personal data.
Yes, with two separate written designations. We issue both, each with its own certificate.
No, in either direction. Holding an Article 27 designation does nothing for NIS2 and the reverse is equally true.
NIS2. Under Article 26(3) you fall under the Member State where your representative is established.
NIS2, under Article 27 of the directive. The GDPR has no registry of representatives.
Almost certainly not: selling goods online is not one of the listed services. You do need the Article 27 GDPR representative.
If your service is provided as cloud computing, both. If it is not, usually only the GDPR designation.
They are similar in size. NIS2 sets at least €10 million or 2% for essential entities; the GDPR sets up to €10 million or 2% for a missing representative.
If it is the entity providing the service and the controller of the data, neither designation is needed for it. Check entity by entity.
NIS2 must be a state where you offer the services. The GDPR must be a state where your data subjects are. They can be the same, and usually should be.
The GDPR representative goes in your privacy notice under Article 13(1)(a). The NIS2 representative appears in the registration rather than on your website.
We do, procedurally and in the language it arrived in, then forward it to you the same working day. The substance is yours.
No. Certification and audits are separate work with separate providers.
Take one. Adding the second later takes 24 hours and we align the renewal dates.
€690 a year for the pair, against €490 and €290 taken separately.
The UK has its own regime and its own representative requirement under the UK GDPR. That is a third mandate, from REP27 LTD.
Both signed within 24 hours of a completed form and an intake call, with two certificates and one invoice.
Incident and breach reporting, security implementation, audits, certification, and legal advice on national transpositions.
Related: the NIS2 designation · the Article 27 test
Europe Services, SE in Prague as your NIS2 representative and your Article 27 GDPR representative, two certificates, one invoice, one desk in eight languages.
Request this service