Back to the hub

GDPR Article 27: representatives of controllers or processors not established in the Union

GDPR Article 27(1) requires a controller or processor caught by Article 3(2) to designate a representative in the Union in writing. Article 27(2) exempts processing that is occasional, excludes large-scale special category or criminal data, and is unlikely to risk people's rights, and exempts public authorities.

Applies to: Controllers and processors not established in the EU whose processing falls under Article 3(2), unless their processing is occasional, low-risk, and free of large-scale special-category or criminal-offence data, or they are a public authority.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Of all the GDPR duties that catch non-EU companies off guard, appointing an EU representative is the most common. It is easy to miss because it has nothing to do with the size of your company and everything to do with whether the regulation reaches you at all. Once it does, the representative is one of the first concrete things you owe.

Who has to appoint an EU representative?

Article 27(1) is direct: where Article 3(2) applies, the controller or the processor shall designate in writing a representative in the Union. Article 3(2) is the territorial-scope test, so if the GDPR reaches you because you offer goods or services to, or monitor, people in the EU, the default is that you need a representative. This is separate from any question of headcount or revenue; a two-person company can owe a representative while a large EU-based firm does not, because the firm has an establishment in the Union instead.

The official text of Article 27

This is the article as it appears in the consolidated text of Regulation (EU) 2016/679 on EUR-Lex, under the heading "Representatives of controllers or processors not established in the Union".

1. Where Article 3(2) applies, the controller or the processor shall designate in writing a representative in the Union.

2. The obligation laid down in paragraph 1 of this Article shall not apply to:

(a) processing which is occasional, does not include, on a large scale, processing of special categories of data as referred to in Article 9(1) or processing of personal data relating to criminal convictions and offences referred to in Article 10, and is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account the nature, context, scope and purposes of the processing; or

(b) a public authority or body.

3. The representative shall be established in one of the Member States where the data subjects, whose personal data are processed in relation to the offering of goods or services to them, or whose behaviour is monitored, are.

4. The representative shall be mandated by the controller or processor to be addressed in addition to or instead of the controller or the processor by, in particular, supervisory authorities and data subjects, on all issues related to processing, for the purposes of ensuring compliance with this Regulation.

5. The designation of a representative by the controller or processor shall be without prejudice to legal actions which could be initiated against the controller or the processor themselves.

Two things are easy to misread. Article 27(2)(a) is a single test with three limbs joined by "and", so occasional processing that is nonetheless risky does not qualify. And Article 27(5) means the representative absorbs correspondence, not liability.

When are you exempt?

Article 27(2) provides one narrow way out. The obligation does not apply where the processing is occasional, does not include large-scale processing of special categories of data under Article 9(1) or criminal-conviction data under Article 10, and is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account its nature, context, scope and purposes. It also does not apply to a public authority or body. The word doing the work is "occasional". Running a live customer base or ongoing analytics is not occasional, so most SaaS businesses in scope cannot rely on this exemption.

Where must the representative be, and what do they do?

Under Article 27(3) the representative must be established in one of the Member States where the people whose data you process, in connection with offering them goods or services or monitoring them, are located. The representative is mandated to be addressed, in addition to or instead of you, by supervisory authorities and by data subjects on all issues related to your processing. Practically, that means naming them and giving contact details where people can reach them, typically in your privacy notice.

Do you have to buy an Article 27 representative service?

Not necessarily, and it is worth understanding what you are buying if you do.

Article 27 does not require the representative to be a specialist firm. It requires a person or organisation, established in a qualifying Member State, mandated in writing to be addressed by supervisory authorities and data subjects on all issues related to your processing. A subsidiary, a group company, a law firm or a distributor in the right Member State can all serve, provided the mandate is genuine and the contact details are published.

What the commercial representative services sell is the address, the mandate paperwork and someone to receive and forward correspondence. That is legitimate and often the cheapest route for a company with no EU presence at all. What they cannot do is take on your liability, because Article 27(5) forecloses it, and they cannot make you compliant with anything else in the Regulation.

So the sequence matters. Establish whether Article 3(2) reaches you, then whether Article 27(2) exempts you, and only then go shopping. Buying a representative for processing that never triggered Article 3(2) is a common and avoidable expense.

Is a representative the same as a data protection officer?

No, and conflating the two is a frequent mistake. An Article 27 representative is a local contact point in the EU for a company that has no establishment there. A data protection officer under Article 37 is an internal advisory and oversight role with its own separate triggers. Depending on your processing you might need one, both, or neither, so treat them as distinct questions rather than a single box to tick.

Next step

The representative question turns entirely on whether Article 3(2) applies and whether your processing is genuinely occasional, and that is exactly where teams talk themselves into the wrong answer. The free 2-minute Obligation Scan checks your territorial-scope position and tells you whether Article 27 applies, alongside the record of processing, the 72-hour breach notification duty, and other obligations that come with being in scope. The GDPR compliance hub puts them in order, and GDPR fines and penalties shows the cost of getting them wrong.

Compliance checklist

  • Confirm whether the GDPR applies to you through Article 3(2), by offering goods or services to, or monitoring, people in the EU.
  • If it does, test the narrow Article 27(2) exemption: processing that is occasional, not large-scale special-category or criminal-offence data, and unlikely to result in a risk to people's rights.
  • If you are not exempt, appoint a representative in writing, established in an EU Member State where your data subjects are.
  • Mandate the representative to be addressed by supervisory authorities and data subjects, and publish their details, for example in your privacy notice.
  • Remember the representative does not absorb your liability; legal action can still be brought against your company directly.

Sources

Last verified: 2026-09-10

Informational, not legal advice.