Appoint us
Authorities that address a NIS2 or an Article 27 representative

REP27 · NIS2 · Compared

Article 26(3) NIS2 · Article 27 GDPR · comparison

NIS2 representative and Article 27 representative are not the same thing.

The vocabulary is identical and the consequences are not. Both put a named entity inside the Union, both are signed in writing, both are addressed by authorities. But one of them is about the security of networks and information systems and decides which Member State supervises you, while the other is about personal data and creates a contact point without changing jurisdiction. Companies that hold one and assume it covers the other are the most common case we see, and the mistake surfaces at the worst possible moment.

Article 26(3)Article 27 GDPRJurisdictionRegistrationBoth

Request this service   Ask a question

What differs, in one screen

The NIS2 representative and the Article 27 GDPR representative compared
The NIS2 representative and the Article 27 GDPR representative compared

The line that matters most is the second on each side. NIS2 assigns jurisdiction: the Member State of your representative becomes your supervisory state. The GDPR designation does nothing of the sort, and a controller outside the Union has no lead authority at all.

Who needs which

CompanyNIS2 representativeArticle 27 representative
US cloud provider with EU customersYesYes, as processor
Indian managed service providerYesYes, usually as processor
Non-EU online marketplaceYes, Annex IIYes, as controller
Non-EU ecommerce shop selling goodsNoYes
Non-EU SaaS not in Annex I or IINoYes, if Article 3(2) reaches it
EU-established providerNoNo
Non-EU search engineYes, Annex IIYes
Row four is the one that surprises people: an ordinary online shop is not a NIS2 entity at all. NIS2 is sector-based; the GDPR is activity-based. Different questions, different answers.

The eight differences worth knowing

  1. Source

    NIS2 is a directive transposed by each Member State; the GDPR is a regulation applying directly. Details vary in the first, not in the second.

  2. Trigger

    NIS2: providing one of the listed services in the Union. GDPR: offering goods or services to people in the Union, or monitoring their behaviour.

  3. Jurisdiction

    NIS2 assigns it through the representative's Member State. Article 27 does not assign anything: every authority whose residents you reach may act.

  4. Registration

    NIS2 has one, under Article 27 of the directive. The GDPR has no registry of representatives anywhere in the Union.

  5. What the representative holds

    NIS2: documentation at the authority's disposal. GDPR: the Article 30 record of processing activities.

  6. Reporting

    NIS2 has hard deadlines, 24 and 72 hours, that stay with the entity. The GDPR has 72 hours for personal data breaches, also with the controller.

  7. Supervision style

    Essential entities under NIS2 face proactive inspection. Data protection authorities act on complaints and investigations.

  8. Penalties

    NIS2: at least €10 million or 2% for essential entities. GDPR Article 83(4)(a): up to €10 million or 2% for a missing representative.

What holding both costs

Annual cost of holding the NIS2 and Article 27 mandates separately or together
Annual cost of holding the NIS2 and Article 27 mandates separately or together

The saving is not the point. The point is one renewal date, one desk and one place where correspondence lands, because the two failures we see most often are a mandate lapsing quietly and a request bouncing between two providers.

What neither of them does

Neither reports for you

Incident notifications under NIS2 and breach notifications under the GDPR stay with the entity. They depend on facts only you have.

Neither implements security

Article 21 NIS2 and Article 32 GDPR are internal work: measures, controls, testing, training.

Neither transfers liability

Article 27(5) GDPR says so expressly, and NIS2 keeps the entity accountable with management personally on the hook.

Neither is legal advice

Where a national transposition adds requirements, you need a firm in that Member State. We say so before you buy, not after.

How to decide in five minutes

AskIf yes
Do we provide DNS, cloud, data centre, CDN, managed services, a marketplace, a search engine or a social platform in the Union?NIS2 representative under Article 26(3)
Do we offer goods or services to people in the Union, or monitor their behaviour?Article 27 GDPR representative
Both of the above?Both mandates, ideally with one provider and one renewal date
Is the entity that does these things established in a Member State?Neither, for that entity
Do we also sell physical products to consumers?Add the Article 16 GPSR responsible person

The third and fourth mandates nobody mentions

Companies comparing NIS2 with the GDPR usually discover that the same structural question has two more answers waiting behind it. Worth knowing now rather than during an audit.

MandateLawWho needs itWhere it appears
NIS2 representativeDirective (EU) 2022/2555Listed digital service providers outside the UnionThe entity registration
Article 27 representativeRegulation (EU) 2016/679Controllers and processors reached by Article 3(2)Your privacy notice
UK representativeUK GDPRCompanies outside the UK reaching people thereYour privacy notice
Article 16 responsible personRegulation (EU) 2023/988Anyone placing consumer products on the EU marketThe product label

A company selling a hosted product and a piece of hardware can genuinely need all four. That sounds like an upsell and it is simply the shape of European law: four statutes, four different things being protected, four separate written designations. What is not necessary is four suppliers, four renewal dates and four inboxes.

Answering a vendor questionnaire that mixes them up

When it says "EU representative"

Nine times out of ten it means Article 27. Send that certificate and the privacy notice paragraph.

When it mentions NIS2 or network security

It means the Article 26(3) mandate and, usually, your registration reference.

When it says "authorised representative"

That is product legislation. Send the Article 16 designation if you have goods, or say plainly that it does not apply.

When it is ambiguous

Send both certificates with one line each. Two sentences close the thread; a clarifying email costs a week.

When it asks who supervises you

Under NIS2, the authority of the Member State where your representative is established. Under the GDPR, any authority whose residents you reach.

When it asks for a compliance certificate

Neither regime issues one. Send the designations and the description of your measures instead.

The short version

One law protects networks and information systems, the other protects personal data. The NIS2 mandate assigns jurisdiction and comes with a registration; the Article 27 designation creates a contact point and is published in your privacy notice. Neither reports incidents for you, neither implements security measures, neither moves your liability. Most companies that need one of them need the other, and holding both with one provider means one renewal date, one desk and one place where correspondence lands. That is the whole comparison, and everything above is the detail behind it.

What to do if you already hold one of them

Most companies arrive here holding the Article 27 designation and discovering NIS2, or the reverse. The order of work is different in each case.

You already haveWhat to check firstThen
Article 27 GDPR designationWhether any of your services appear in Annex I or IIAdd the NIS2 mandate and align the renewal dates
NIS2 mandateWhether Article 3(2) GDPR reaches you as controller or processorAdd the Article 27 designation and publish it in the notice
Both, with different providersThe two renewal dates and who answers whatConsolidate at the next renewal, taking the request logs with you
Neither, and unsureWhich entity provides which service, and where it is establishedRun both tests on paper before buying anything

The last row is the honest one. Buying a designation you do not need is waste, and we would rather tell you that on the intake call than sell it and have you discover it during an audit.

One sentence to take away

If your service appears in Annexes I or II of NIS2 you need the Article 26(3) mandate and a registration; if you reach people in the Union with goods, services or tracking you need the Article 27 designation published in your privacy notice; most companies that need one need the other, and the only thing worth optimising is that both live with one provider, on one renewal date, with one desk that answers.

Why the confusion is so common

The word is the same

In English, French, German, Italian and Spanish the same noun covers both roles, and translations of vendor questionnaires make it worse rather than better. Asking which regulation the question comes from resolves it in one message, and it is the single most useful habit in this area.

Both are new to most teams

Article 27 became a live concern for many companies only when enforcement picked up, and NIS2 arrived while that was still settling. Teams reasonably assume the second is a version of the first, and then apply GDPR reflexes to a directive that works by sector and assigns jurisdiction.

Comparing the NIS2 mandate with the Article 27 designation
Comparing the NIS2 mandate with the Article 27 designation
Prague office holding both the NIS2 and the Article 27 mandate

Questions we are actually asked

Is the NIS2 representative the same as the GDPR one?

No. Different law, different trigger, different consequences. One covers network and information security and assigns jurisdiction; the other covers personal data.

Can the same company hold both mandates?

Yes, with two separate written designations. We issue both, each with its own certificate.

Does one satisfy the other?

No, in either direction. Holding an Article 27 designation does nothing for NIS2 and the reverse is equally true.

Which one assigns jurisdiction?

NIS2. Under Article 26(3) you fall under the Member State where your representative is established.

Which one has a registration duty?

NIS2, under Article 27 of the directive. The GDPR has no registry of representatives.

We are an ecommerce shop. Do we need NIS2?

Almost certainly not: selling goods online is not one of the listed services. You do need the Article 27 GDPR representative.

We are a SaaS company. Which applies?

If your service is provided as cloud computing, both. If it is not, usually only the GDPR designation.

Do the fines differ?

They are similar in size. NIS2 sets at least €10 million or 2% for essential entities; the GDPR sets up to €10 million or 2% for a missing representative.

Can our EU subsidiary cover both?

If it is the entity providing the service and the controller of the data, neither designation is needed for it. Check entity by entity.

Which Member State should each be in?

NIS2 must be a state where you offer the services. The GDPR must be a state where your data subjects are. They can be the same, and usually should be.

Do both need to be published?

The GDPR representative goes in your privacy notice under Article 13(1)(a). The NIS2 representative appears in the registration rather than on your website.

Who answers an authority letter?

We do, procedurally and in the language it arrived in, then forward it to you the same working day. The substance is yours.

Does either help with certification?

No. Certification and audits are separate work with separate providers.

What if we only need one now?

Take one. Adding the second later takes 24 hours and we align the renewal dates.

Is there a discount for both?

€690 a year for the pair, against €490 and €290 taken separately.

What about the United Kingdom?

The UK has its own regime and its own representative requirement under the UK GDPR. That is a third mandate, from REP27 LTD.

How fast can both be in place?

Both signed within 24 hours of a completed form and an intake call, with two certificates and one invoice.

What is explicitly excluded from both?

Incident and breach reporting, security implementation, audits, certification, and legal advice on national transpositions.

Related: the NIS2 designation · the Article 27 test

Both mandates, one renewal date

Europe Services, SE in Prague as your NIS2 representative and your Article 27 GDPR representative, two certificates, one invoice, one desk in eight languages.

Request this service