EU GDPR · Article 27

Article 27 Representative: A Practical GDPR Guide

An Article 27 representative is a local EU contact for certain controllers and processors not established in the Union. The requirement depends on the GDPR territorial-scope assessment and statutory exceptions; it is not a blanket rule for every non-EU company.

By The Data Protection OfficersReading time: 7 min
Abstract bridge connecting city networks to a local privacy contact

What Article 27 does

Article 27 connects the GDPR's territorial-scope rules with a written local contact requirement. Where Article 3(2) applies to a controller or processor that is not established in the Union, the organisation must generally designate a representative in writing unless an Article 27(2) exception applies.

The representative is not the controller, processor, or automatic substitute for a Data Protection Officer. It is a contact point that can be addressed by supervisory authorities and data subjects on processing matters within the mandate. The organisation keeps responsibility for its processing, records, notices, security, rights responses, and decisions.

Start with Article 3(2) territorial scope

The first question is whether the processing of people in the Union relates to offering goods or services to them or monitoring their behaviour in the Union. Website accessibility alone is not enough to answer that question. Consider the product, target audience, marketing, ordering or account process, language and currency choices, customer evidence, analytics, profiling, and the actual processing activities.

Also identify the organisation's role. A non-EU company may be a controller for its own marketing, account, employee, or billing activities and a processor for customer data handled in a SaaS product. The representative assessment should cover the relevant roles and entities instead of assuming that one contractual label describes the entire business.

  • Which legal entity determines the purposes and means of the relevant processing?
  • Which people in the Union are affected and what activity reaches them?
  • Is the processing linked to an offer, monitoring, or another Article 3 route?
  • Are there EU establishments or other arrangements that change the analysis?

Understand the Article 27(2) exceptions

The main exception concerns processing that is occasional, does not include large-scale processing of special-category or criminal-conviction data, and is unlikely to create a risk to individuals' rights and freedoms when the nature, context, scope, and purposes are considered. Public authorities and bodies have a separate exception. These conditions should be assessed together rather than treated as a simple company-size test.

A business should record the facts behind an exception conclusion and review it if the processing becomes regular, expands in scale, introduces sensitive data, changes its targeting, or creates a different risk. An exception that was reasonable for a small pilot may not describe a recurring product or customer programme later.

What the appointment should make workable

The representative should be established in a Member State where the relevant data subjects are located and appointed through a written mandate. The mandate should explain the matters the representative may receive, the internal owners who provide facts, the escalation route, the communication channels, and any service boundaries. A public privacy notice should contain accurate representative details where the organisation is required to provide them.

The practical test is whether a request or authority communication can reach the representative, be logged, obtain an accurate response from the organisation, and move back through the right channel. An address that is not monitored, a mandate with no access to facts, or an internal team that does not recognise the route will not create reliable representation.

Article 27 representative versus external DPO

A representative is a local contact point for certain organisations outside the Union. A DPO is an independent oversight role with separate appointment criteria, tasks, access, and conflict-of-interest protections. One role does not automatically satisfy the other. Some organisations need both, while others need a representative, an external DPO, focused compliance work, or none of these after assessment.

When choosing support, explain the desired outcome precisely. A representative arrangement should make authority and data-subject communication workable. A DPO arrangement should provide independent advice and monitoring. A broader compliance programme may be needed for records, transparency, security, vendors, transfers, and operational implementation beyond either appointment.

Frequently asked questions

Who normally needs an Article 27 representative?

A controller or processor outside the Union may need one when its processing falls within Article 3(2), subject to the Article 27(2) exceptions. The conclusion depends on the actual offering, monitoring, processing, risk, and establishment facts.

Is an Article 27 representative a Data Protection Officer?

No. The representative is a local contact under Article 27. A DPO is an independent oversight role assessed under the DPO provisions. The roles can coexist but should not be combined without a careful independence and conflict assessment.

Does a representative take over our GDPR responsibility?

No. The controller or processor remains responsible for its processing and legal obligations. The representative creates a local route for communications within the written mandate.

Where should the EU representative be established?

The GDPR states that the representative should be established in a Member State where relevant data subjects are located. The appropriate location and scope should be assessed against the organisation's facts.

Keep researching

A practical next step

Make the next privacy decision clearer

Bring your organisation, processing, jurisdictions, current documents, internal owners, and deadline. We can help identify the right scope before an appointment or wider workstream begins.

This guide provides general information, not legal advice or a conclusion that a particular organisation is required to appoint a role. Final scope, responsibilities, capacity, and deliverables should be confirmed against the organisation's facts.

Sources: EUR-Lex: GDPR Articles 3 and 27, EDPB: Territorial scope guidance

Choose the Right Data Protection Service

Compare the role and scope that fit the jurisdictions and processing activities that matter to your business.

Find the Right Data Protection Service in Minutes

Select your jurisdictions, compare annual pricing, and continue with the service that fits your scope.

View Data Protection Services