GDPR Article 27
Do you need an EU representative under GDPR Article 27?
Article 27 GDPR requires organisations established outside the Union to designate a representative inside it. We act as EU representative from Brussels under written mandate.
Scope
You are likely in scope if all of these apply
- Your organisation is not established in the EU or the EEA
- You offer goods or services to people located in the EU — whether or not payment is required — or you monitor their behaviour in the EU through analytics, tracking, profiling or advertising
- Your processing is more than occasional, or it involves special categories of data on a large scale, or it is likely to result in a risk to the rights and freedoms of individuals
You are outside the obligation if
- You are a public authority or body
- Your processing is occasional, does not involve large-scale processing of special categories of data or of data relating to criminal convictions, and is unlikely to result in a risk to the rights and freedoms of individuals
The mandate in practice
What we do — and what we do not do
What the representative does
- Acts as the addressee for supervisory authorities and for data subjects on all questions relating to your processing
- Is mandated to be addressed in addition to, or instead of, the controller or processor
- Keeps a copy of your record of processing activities and makes it available to authorities on request
- Is designated in writing, in a Member State where the individuals concerned are located
- Is identified in your privacy notice, so that individuals can reach it
What we do not do
- We do not become your data protection officer. The two roles are distinct, and whether you need a DPO is answered separately under Article 37.
- We do not build or run your compliance programme. Your record of processing, your legal bases and your security measures remain yours.
- We do not answer for processing we were never told about. The mandate covers what is described in it.
- We do not provide tax or employment advice unless separately agreed.
What it is not: a data protection officer
The representative and the data protection officer are two distinct roles with distinct functions. Appointing one does not discharge the other obligation, and the two should not be held by the same person. The criteria for appointing a DPO are set out separately in Article 37.
If you do not designate one
Article 27 falls within the scope of the administrative fines regime, and supervisory authorities across the Union have taken decisions against organisations that failed to designate a representative. Beyond the fine, the absence of an EU point of contact tends to make every subsequent exchange with an authority harder.
Engagement
Our mandate
A written designation agreement. A Brussels address published as your EU point of contact. Correspondence from supervisory authorities and from data subjects handled and reported to you in English. Custody of a copy of your Article 30 record. An annual review of scope. Written notification to you if the mandate ends. Fixed annual fee, quoted in writing before engagement.
FAQ
Frequently Asked Questions
Timing
When to contact us
- Before you launch in the EU
- Before you sign with a European distributor
- When a European customer or a platform asks for your representative’s details
- During a funding round or due diligence
- After you receive a request from a regulator or a platform
- When you expand from one product or system to a catalogue
Discuss an Article 27 mandate
Schedule a 20-minute discovery call with our founding lawyer. No commitment.
Schedule a Call