Back to the hub

Do you need an EU representative under GDPR Article 27?

If the GDPR applies to your company through Article 3(2), Article 27 usually requires you to appoint a representative in the EU, in writing. The duty does not apply where your processing is occasional, low-risk, and free of large-scale sensitive data, or where you are a public authority. Most US SaaS firms need one.

Applies to: Controllers and processors not established in the EU whose processing falls under Article 3(2), unless their processing is occasional, low-risk, and free of large-scale special-category or criminal-offence data, or they are a public authority.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Founding 30% off with code FOUNDING until 15 August 2026

Of all the GDPR duties that catch non-EU companies off guard, appointing an EU representative is the most common. It is easy to miss because it has nothing to do with the size of your company and everything to do with whether the regulation reaches you at all. Once it does, the representative is one of the first concrete things you owe.

Who has to appoint an EU representative?

Article 27(1) is direct: where Article 3(2) applies, the controller or the processor shall designate in writing a representative in the Union. Article 3(2) is the territorial-scope test, so if the GDPR reaches you because you offer goods or services to, or monitor, people in the EU, the default is that you need a representative. This is separate from any question of headcount or revenue; a two-person company can owe a representative while a large EU-based firm does not, because the firm has an establishment in the Union instead.

When are you exempt?

Article 27(2) provides one narrow way out. The obligation does not apply where the processing is occasional, does not include large-scale processing of special categories of data under Article 9(1) or criminal-conviction data under Article 10, and is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account its nature, context, scope and purposes. It also does not apply to a public authority or body. The word doing the work is "occasional". Running a live customer base or ongoing analytics is not occasional, so most SaaS businesses in scope cannot rely on this exemption.

Where must the representative be, and what do they do?

Under Article 27(3) the representative must be established in one of the Member States where the people whose data you process, in connection with offering them goods or services or monitoring them, are located. The representative is mandated to be addressed, in addition to or instead of you, by supervisory authorities and by data subjects on all issues related to your processing. Practically, that means naming them and giving contact details where people can reach them, typically in your privacy notice.

Is a representative the same as a data protection officer?

No, and conflating the two is a frequent mistake. An Article 27 representative is a local contact point in the EU for a company that has no establishment there. A data protection officer under Article 37 is an internal advisory and oversight role with its own separate triggers. Depending on your processing you might need one, both, or neither, so treat them as distinct questions rather than a single box to tick.

Next step

The representative question turns entirely on whether Article 3(2) applies and whether your processing is genuinely occasional, and that is exactly where teams talk themselves into the wrong answer. The free 2-minute Obligation Scan checks your territorial-scope position and tells you whether Article 27 applies, alongside the record of processing, the 72-hour breach notification duty, and other obligations that come with being in scope. The GDPR compliance hub puts them in order, and GDPR fines and penalties shows the cost of getting them wrong.

Compliance checklist

  • Confirm whether the GDPR applies to you through Article 3(2), by offering goods or services to, or monitoring, people in the EU.
  • If it does, test the narrow Article 27(2) exemption: processing that is occasional, not large-scale special-category or criminal-offence data, and unlikely to result in a risk to people's rights.
  • If you are not exempt, appoint a representative in writing, established in an EU Member State where your data subjects are.
  • Mandate the representative to be addressed by supervisory authorities and data subjects, and publish their details, for example in your privacy notice.
  • Remember the representative does not absorb your liability; legal action can still be brought against your company directly.

Sources

Last verified: 2026-08-11

Informational, not legal advice.