Do You Need an EU GDPR Representative? Article 27 Explained

Do You Need an EU GDPR Representative? Article 27 Explained

If your company is based outside the European Union but sells products or services to customers in the EU, the GDPR may still apply to your business.

One requirement that international businesses sometimes overlook is Article 27 of the General Data Protection Regulation (GDPR). Under certain circumstances, a company without an EU establishment must formally appoint a representative within the European Union.

This can affect online shops, software companies, service providers, international brands and other businesses targeting European customers.

In this guide, we explain when an EU GDPR Representative may be required, what the representative does and how non-EU businesses can address this requirement.

What Is an EU GDPR Representative?

An EU GDPR Representative is a person or organisation established within the European Union that is formally designated by certain controllers or processors located outside the EU.

The representative provides an accessible point of contact within the EU for matters concerning the company's processing of personal data.

Article 27 requires the representative to be designated in writing. The representative must be established in an EU Member State where relevant individuals whose personal data are processed are located.

The representative can then be addressed by EU supervisory authorities and data subjects on matters related to the company's processing activities.

Why Can the GDPR Apply to a Company Outside the EU?

A common misconception is that the GDPR only applies to companies incorporated within the European Union.

That is not always the case.

Under Article 3(2) GDPR, the Regulation can also apply to certain processing activities of controllers and processors that are not established in the EU where those activities relate to:

  • offering goods to individuals in the EU;
  • offering services to individuals in the EU; or
  • monitoring the behaviour of individuals where that behaviour takes place within the EU.

This territorial scope is particularly relevant for international ecommerce.

Example: A US Online Shop Selling to Germany

Consider a company established in the United States with no EU office.

The company operates an online shop specifically serving German customers, accepts orders from Germany, ships products to Germany and processes customer information such as names, addresses, email addresses and order information.

The fact that the company itself is located in the United States does not automatically place those processing activities outside the GDPR.

If Article 3(2) applies, the business should then assess whether Article 27 requires it to appoint a representative within the European Union.

Who Needs an Article 27 GDPR Representative?

Article 27 generally requires a controller or processor falling within Article 3(2) GDPR to designate a representative in the European Union unless an exemption applies.

This means the requirement can potentially affect businesses based in countries such as:

  • United States;
  • United Kingdom;
  • Switzerland;
  • Canada;
  • Australia;
  • Japan;
  • China;
  • Singapore; and
  • other countries outside the EU.

It is the company's activities and processing operations, rather than simply its country of incorporation, that need to be assessed.

Is Every Non-EU Company Required to Appoint a Representative?

No.

Article 27 contains an exemption where the processing is occasional, does not include large-scale processing of special categories of personal data or personal data relating to criminal convictions and offences, and is unlikely to result in a risk to the rights and freedoms of individuals, taking into account the nature, context, scope and purposes of the processing.

Public authorities and bodies are also addressed separately under Article 27.

The exemption should therefore not be treated as a general small-business exemption. A business should consider its actual processing activities before concluding that no representative is required.

Where Must the EU Representative Be Located?

Under Article 27(3), the representative must be established in one of the EU Member States where the relevant data subjects are located.

For example, if a non-EU ecommerce company actively sells to consumers in Germany and processes their personal data in connection with those sales, a representative established in Germany may provide an appropriate EU contact point.

The European Data Protection Board (EDPB) also recommends, as a matter of good practice, locating the representative in the Member State where a significant proportion of the affected data subjects are located.

What Does an EU GDPR Representative Do?

The representative is more than an address that can simply be added to a privacy policy.

The role creates an EU contact point between the non-EU company, individuals in the EU and competent data protection authorities.

1. Acts as an EU Contact Point

The representative provides an identifiable contact within the European Union for GDPR matters relating to the represented company's processing activities.

2. Facilitates Communication With Data Subjects

EU data subjects must be able to contact the representative regarding relevant processing matters and the exercise of their rights under the GDPR.

The representative can receive relevant communications and coordinate them with the represented company.

3. Communicates With Supervisory Authorities

The representative must also be available to competent EU supervisory authorities regarding processing activities covered by the appointment.

This gives European authorities an accessible point of contact even though the controller or processor itself may be located outside the EU.

4. Supports Article 30 Processing Records

Article 30 GDPR requires controllers and, where applicable, their representatives to maintain records of processing activities.

Depending on the organisation and its role, these records can include information concerning:

  • the controller and representative;
  • purposes of processing;
  • categories of data subjects;
  • categories of personal data;
  • categories of recipients;
  • international transfers;
  • retention periods where possible; and
  • a general description of relevant technical and organisational security measures where possible.

These records must be available to the competent supervisory authority where required.

Is an EU GDPR Representative the Same as a Data Protection Officer?

No. An Article 27 Representative and a Data Protection Officer (DPO) are separate GDPR functions.

An EU Representative acts under a mandate from a non-EU controller or processor and serves as its representative within the European Union for relevant GDPR matters.

A DPO has a separate role under Articles 37 to 39 GDPR and must perform that role with the required independence.

The EDPB has specifically indicated that the role of an EU Representative is generally not compatible with simultaneously acting as the external DPO for the same organisation.

Does Appointing a Representative Transfer GDPR Responsibility?

No.

Appointing an EU Representative does not transfer the controller's or processor's GDPR obligations to the representative.

The non-EU business remains responsible for complying with the GDPR requirements applicable to its processing activities.

For example, the business may still need to address:

  • lawful bases for processing;
  • privacy information;
  • data-subject rights;
  • processor relationships;
  • international data transfers;
  • data retention;
  • security measures;
  • data breach obligations; and
  • other applicable GDPR requirements.

The EU Representative therefore forms one part of the organisation's wider GDPR compliance structure.

What Information Should Appear in Your Privacy Notice?

Where an EU Representative has been appointed, the organisation should ensure that the representative is appropriately identified in its GDPR information provided to data subjects.

This normally means providing the representative's identity and contact details so that individuals have an accessible European point of contact.

The details should be kept current for as long as the appointment remains in place.

EaseCert EU GDPR Representative Service

EaseCert now provides an EU GDPR Representative service under Article 27 GDPR for eligible businesses established outside the European Union.

EaseCert GmbH, established in Germany, can be formally appointed as your EU Representative and provide the European contact point required for the representative function.

The service includes:

  • EU GDPR Representation: appointment of EaseCert GmbH as your EU Representative under Article 27 GDPR;
  • EU Contact Point: communication point for EU data subjects and competent data protection authorities; and
  • Article 30 Records: setup and maintenance of your Record of Processing Activities based on information supplied by your organisation.

A One-Time Fee Instead of Another Annual Subscription

International businesses already face numerous recurring costs when entering the European market.

EaseCert therefore provides its standard EU GDPR Representative service using a simple one-time fee model.

There is no annual representative subscription for the standard service.

Need an EU GDPR Representative?

Appoint EaseCert GmbH as your EU Representative under Article 27 GDPR. Get a Germany-based EU contact point with a one-time fee and no annual subscription.

Appoint Your EU GDPR Representative →

One-time fee • EaseCert GmbH, Germany • No annual subscription

How the EaseCert Appointment Process Works

Step 1: Place Your Order

Order the EU GDPR Representative service and provide your company information.

Step 2: Provide Your Processing Information

We collect the information needed to understand your EU activities and the processing operations covered by the appointment.

Step 3: Review and Representative Mandate

EaseCert reviews the information provided and prepares the documentation required for the representative relationship.

Step 4: Formal Appointment

The written mandate formally designates EaseCert GmbH as your EU Representative under Article 27 GDPR.

Step 5: Update Your Privacy Information

We provide the relevant EaseCert representative details so that you can include your EU Representative in your privacy documentation.

Step 6: Maintain Your Information

Your organisation must keep EaseCert informed about material changes to the processing activities covered by the appointment so that the relevant representative records can remain current.

EU Product Compliance and Data Protection Under One Roof

For international ecommerce businesses, GDPR is often only one part of entering the European market.

Depending on the products and countries involved, businesses may also encounter requirements concerning product safety, EU Responsible Persons, authorised representatives, product labelling, technical documentation, Extended Producer Responsibility (EPR) and other market-access obligations.

EaseCert supports international businesses with practical EU compliance services from its German entity, allowing companies to coordinate multiple European compliance requirements through one provider.

Frequently Asked Questions

What is an EU GDPR Representative?

An EU GDPR Representative is a person or organisation established in the European Union that is formally appointed by certain non-EU controllers or processors under Article 27 GDPR. The representative serves as an EU contact point for data subjects and competent data protection supervisory authorities regarding relevant processing activities.

Who needs an EU GDPR Representative?

Businesses established outside the EU may need an EU Representative if the GDPR applies to them under Article 3(2), for example because they offer goods or services to individuals in the EU or monitor their behaviour within the EU. Article 27 contains certain exemptions, so the requirement should be assessed based on the company's actual activities and processing operations.

Does a US, UK, Swiss or Canadian company need an EU GDPR Representative?

Potentially, yes. The requirement is not determined simply by where a company is incorporated. A non-EU business that targets individuals in the EU and processes personal data in connection with those activities may fall within Article 3(2) GDPR and should assess whether Article 27 requires an EU Representative.

Can EaseCert GmbH act as my EU GDPR Representative?

Yes, for eligible businesses. EaseCert GmbH is established in Germany and can be formally appointed as your EU Representative under Article 27 GDPR following review of your company information and relevant processing activities.

Where is EaseCert's EU GDPR Representative located?

Your representative is EaseCert GmbH in Germany. Following formal appointment, we provide the appropriate company and contact information for inclusion in your privacy documentation.

What is included in the EaseCert EU GDPR Representative service?

The standard service includes the formal appointment of EaseCert GmbH as your Article 27 EU Representative, an EU contact point for relevant data-subject and supervisory-authority communications, and support with maintaining the relevant Article 30 Record of Processing Activities based on information provided by your organisation.

How much does the EU GDPR Representative service cost?

The EaseCert EU GDPR Representative service costs as a one-time fee. There is no annual representative subscription for the standard service.

Are there annual renewal fees?

No. EaseCert uses a one-time-fee model for its standard EU GDPR Representative service. The appointment remains subject to the representative mandate and applicable service terms.

How quickly can EaseCert be appointed?

For straightforward cases, the appointment can normally be completed within a few business days after EaseCert receives the required company information, processing information and signed documentation.

Can I add EaseCert to my privacy policy?

Yes. Once EaseCert GmbH has been formally appointed, we provide the appropriate representative details for inclusion in your privacy notice and other relevant GDPR information.

Does EaseCert become my Data Protection Officer (DPO)?

No. An Article 27 EU Representative and a Data Protection Officer are separate GDPR functions. The EaseCert service covers EU representation under Article 27 and does not constitute appointment as your DPO.

What is a Record of Processing Activities (RoPA)?

A Record of Processing Activities, commonly called a RoPA, documents relevant information about an organisation's personal-data processing. Depending on the applicable Article 30 requirements, this can include processing purposes, categories of data subjects and personal data, recipients, international transfers, retention information and relevant security measures.

Does EaseCert maintain my Article 30 Record of Processing Activities?

EaseCert supports the setup and maintenance of the relevant processing records for purposes of its representative function based on information supplied by your organisation. Your company remains responsible for providing complete, accurate and current information about its processing activities.

Do I need to tell EaseCert when my processing activities change?

Yes. You must inform EaseCert of material changes affecting the information maintained for your representative appointment, including significant changes to processing activities, categories of personal data, purposes, EU markets, recipients or international transfers.

Does appointing EaseCert make my company fully GDPR compliant?

No. Appointment of an EU Representative addresses the Article 27 representative requirement where applicable. Your organisation remains responsible for its wider GDPR obligations, including lawful processing, transparency, data-subject rights, security, processor relationships, international transfers and other requirements applicable to its activities.

Does EaseCert provide legal advice as part of the service?

No. The standard service provides the Article 27 representative function and related compliance support. It does not include legal representation, litigation, DPO services, regulatory defence or unlimited GDPR legal advice.

Can EaseCert receive communications from EU data protection authorities?

Yes. Acting as the appointed Article 27 Representative includes serving as an EU contact point for competent supervisory authorities regarding processing activities covered by the appointment.

Can EU customers contact EaseCert about their personal data?

Yes. Data subjects can contact the appointed EU Representative regarding relevant GDPR matters. EaseCert can receive the communication and coordinate it with the represented company, which remains responsible for fulfilling its applicable GDPR obligations.

Do I need an EU GDPR Representative before launching my EU online shop?

If Article 27 applies to your business, it is advisable to establish the representative appointment before launch so that the correct representative information can be included in your privacy documentation from the beginning.

How do I appoint EaseCert as my EU GDPR Representative?

Purchase the EU GDPR Representative (Article 27 GDPR) service and provide the requested company and processing information. EaseCert will review the information, prepare the representative documentation and provide the details required for your privacy documentation following formal appointment.

Prepare Before You Start Selling to EU Customers

If your business is established outside the European Union and intends to target customers in the EU, determine whether Article 27 applies before launching.

Where an EU Representative is required, establishing the appointment early means the appropriate representative details can be incorporated into your privacy documentation from the start.

EaseCert GmbH provides EU GDPR representation from Germany for eligible non-EU businesses for a one-time fee.

Get Your EU GDPR Representative

One-time fee. No annual subscription.

Official References

This article provides general information concerning the EU GDPR Representative requirement. Whether Article 27 applies depends on the circumstances of the individual organisation and its processing activities. EaseCert's Article 27 service is an EU representative service and does not constitute legal advice or DPO services.

Show more insights

Get in Touch with EaseCert