The EU Representative Requirement Under GDPR Article 27

What non-EU businesses subject to GDPR‘s extraterritorial reach must do, who is exempt, what the representative actually does, and why the appointment matters far more than most companies realize.

Regulation (EU) 2016/679, Art. 27  |  Recital 80  |  EDPB Guidelines 3/2018  |  Art. 83(4)(a)

Home › Practice Areas › Privacy & Data Protection › GDPR Article 27 Representative

Contents

  1. Introduction: What Article 27 Is and Why It Matters
  2. The Foundation: Article 3(2) and GDPR’s Extraterritorial Reach
  3. Who Must Appoint a Representative
  4. The Article 27(2) Exemptions: Three Cumulative Conditions
  5. Where the Representative Must Be Located
  6. Who Can Serve as the Representative
  7. What the Representative Does: Roles and Obligations
  8. The One-Stop-Shop Non-Availability: A Critical Misconception
  9. The Representative’s Liability: What It Is and What It Is Not
  10. Post-Brexit: The Dual Representative Requirement
  11. Article 27 Representative Versus Data Protection Officer
  12. Enforcement: Fines and Regulatory Consequences
  13. Practical Compliance Steps
  14. Key Statutory and Regulatory References

I. Introduction: What Article 27 Is and Why It Matters

Article 27 of the General Data Protection Regulation, Regulation (EU) 2016/679, requires businesses that are not established within the European Union but are nonetheless subject to the GDPR to designate, in writing, a representative established in an EU member state. The representative serves as a local contact point for both supervisory authorities and data subjects on all matters relating to the controller’s or processor’s processing activities. The obligation applies to a wide range of non-EU entities — U.S. corporations, UK companies following Brexit, businesses headquartered in Asia, Canada, Australia, and elsewhere — that offer goods or services to individuals located in the EU or that monitor the behavior of EU-located individuals, even without any physical presence on European soil.

The policy rationale behind Article 27 is straightforward and is explained in Recital 80 of the GDPR: where a controller or processor is not established in the Union but is nonetheless subject to GDPR, a representative should be designated to act on the controller’s or processor’s behalf with regard to the obligations imposed by the Regulation. Without such a mechanism, supervisory authorities would have no practical means of communicating with, investigating, or enforcing the law against entities that operate in EU markets while remaining physically beyond EU borders. The representative is the compliance infrastructure that makes GDPR accountability meaningful for non-EU actors.

Despite its importance, Article 27 is frequently overlooked. Many non-EU businesses that are aware of GDPR’s extraterritorial reach — and that have invested in privacy notices, data processing agreements, and breach notification protocols — have nonetheless failed to appoint a representative or have misunderstood what the obligation entails. This page explains the precise legal basis for the requirement, who is obligated and who is exempt, what the representative must do, where the representative must be located, how liability is allocated, and what the practical compliance steps look like. It also addresses two matters that generate recurring confusion in practice: the critical difference between designating a representative and having access to the GDPR’s one-stop-shop mechanism, and the equally important difference between an Article 27 representative and a Data Protection Officer.

II. The Foundation: Article 3(2) and GDPR’s Extraterritorial Reach

Article 27 does not operate independently. Its opening sentence provides that “[w]here Article 3(2) applies, the controller or the processor shall designate in writing a representative in the Union.” The representative obligation is therefore a consequence of GDPR’s extraterritorial scope — it applies only to entities that are already subject to the GDPR through the Article 3(2) targeting criterion and that lack an EU establishment of their own under Article 3(1).

Article 3(2) extends GDPR’s application to controllers and processors not established in the Union when they process personal data of “data subjects who are in the Union” in connection with either the offering of goods or services to those data subjects (irrespective of whether payment is required) or the monitoring of their behavior as far as that behavior takes place within the Union. The EDPB clarified in Guidelines 3/2018 that the targeting criterion requires that the individuals whose data is processed be physically present in the Union at the time the relevant activity — the offering or the monitoring — takes place. Nationality and domicile are not determinative; what matters is physical presence within EU territory at the material moment.

Before the Article 27 obligation is engaged, two threshold questions must be resolved. First, is the non-EU entity genuinely processing personal data of EU-located individuals? Second, does the processing relate to an offering of goods or services directed at those individuals, or to the monitoring of their behavior within the Union? The GDPR and Recital 23 provide guidance on the first question: indicators of a deliberate offering directed at EU individuals include the use of a language or currency of an EU member state, references to EU customers or users, and the possibility of delivery to EU addresses. Merely having a website that is accessible in the EU, without more, does not automatically constitute an offering directed at EU individuals. For the monitoring limb, behavioral advertising, location tracking, and online profiling of EU users are paradigmatic examples. EDPB Guidelines 3/2018, § 3.2.

Article 27 applies to both controllers and processors that are not established in the Union but fall within Article 3(2). A non-EU processor acting on behalf of a non-EU controller may independently be subject to Article 3(2) based on its own processing activities, in which case it bears its own Article 27 obligation, separate from any obligation of the controller. This matters in practice: each entity in a non-EU processing chain must assess its own GDPR exposure and its own representative obligation independently, rather than assuming that the controller’s representative satisfies the processor’s obligation, or vice versa.

The Article 27 Trigger in Plain Terms

If your business is established outside the EU, processes personal data of individuals physically located in the EU, and does so in connection with offering goods or services to those individuals or monitoring their behavior — and you have no EU establishment of your own — GDPR Article 27 requires you to appoint an EU representative before processing begins. The question is not whether you intend to target EU consumers; it is whether your actual processing activities, objectively assessed, bring you within the Article 3(2) targeting criterion.

III. Who Must Appoint a Representative

A. Both Controllers and Processors, Assessed Independently

Article 27(1) applies equally to controllers and to processors not established in the Union whose processing activities fall within Article 3(2). This parallel application reflects GDPR’s broader structure, in which controllers and processors carry distinct but related sets of obligations. A non-EU processor that processes personal data of EU-located individuals as part of its own commercially offered services — a U.S.-based cloud services provider or data analytics firm, for example, that markets its services to EU clients and processes the personal data of their EU end-users in that context — may independently trigger Article 3(2) with respect to its own processing activities, and must therefore appoint its own representative.

Controllers and processors should not assume that one party’s representative satisfies the other’s obligation. Where both a non-EU controller and a non-EU processor in the same engagement are subject to Article 3(2), each must independently satisfy Article 27. The same entity or individual may, in principle, be designated to serve as representative for both — provided the written mandate clearly covers both roles and is executed separately or jointly by each appointing party — but the obligation itself is separate and arises for each on independent grounds.

B. The Written Designation Requirement and Public Availability

Article 27(1) requires that the designation of the representative be made “in writing.” There is no prescribed form, but the written mandate should identify the representative unambiguously, specify the scope of the processing activities covered, and confer authority on the representative to act on behalf of the controller or processor in dealings with supervisory authorities and data subjects. The mandate is a private commercial contract between the appointing party and the representative, and its terms will govern the operational relationship between them, including information-sharing obligations, response time requirements, and commercial indemnification arrangements.

Article 27(3) further requires that the representative be made available to supervisory authorities and data subjects. In practice this means that the representative’s name and contact details must be publicly accessible — typically through the controller’s or processor’s privacy notice or privacy policy — so that data subjects who wish to exercise their rights under GDPR Chapter III and supervisory authorities conducting inquiries can readily identify and contact the representative without unreasonable difficulty.

IV. The Article 27(2) Exemptions: Three Cumulative Conditions

Article 27(2) provides two categories of exemption from the representative obligation. The first covers public authorities and bodies, which are exempt from Article 27 regardless of the nature or scale of their processing. The second — and more commercially significant — covers private entities whose processing meets three conditions simultaneously. All three conditions must be satisfied at the same time; failing even one disqualifies the entity from the exemption, regardless of how readily the other two are satisfied. Recital 80 confirms this cumulative structure.

Condition 1

Occasional Processing

The processing must be neither regular nor systematic — genuinely sporadic, one-off, or incidental rather than part of a recurring operational activity.

Condition 2

No Large-Scale Special Category or Criminal Data

The processing must not include, on a large scale, the Article 9(1) special categories or Article 10 criminal conviction and offence data.

Condition 3

Low Risk

The processing must be unlikely to result in a risk to the rights and freedoms of natural persons, assessed in light of its nature, context, scope, and purposes.

The first condition — occasional processing — draws a line between genuinely sporadic activity and recurring commercial operations. An academic researcher conducting a one-time study involving a limited number of EU participants, or a non-EU organization hosting a single conference for EU attendees and processing attendee data solely in connection with that event, may be able to invoke this condition. What it clearly does not encompass is any ongoing commercial offering directed at EU consumers: a business that maintains a website through which EU users regularly purchase goods, subscribe to services, or create accounts is engaged in systematic processing as a matter of course, regardless of whether each individual transaction could be characterized as “occasional.”

The second condition requires that the processing not include, on a large scale, the special categories of personal data defined in Article 9(1) — which include data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for purposes of uniquely identifying a natural person, health data, and data concerning a natural person’s sex life or sexual orientation — or data relating to criminal convictions and offences under Article 10. The phrase “on a large scale” is not defined in Article 27 itself, but the guidance developed in the context of the data protection officer obligation under Article 37(1)(b) provides useful reference: factors including the number of data subjects affected, the volume of data, the duration and permanence of the processing activity, and its geographic extent are all relevant. A non-EU health platform, a telemedicine provider, a background screening service, or a financial services firm handling credit or fraud data involving EU users will almost certainly fail this condition.

The third condition requires that the processing be unlikely to result in a risk to the rights and freedoms of natural persons. This is a substantive risk assessment informed by the criteria used elsewhere in GDPR — the risk of discrimination, identity theft, financial loss, reputational damage, loss of confidentiality, unauthorized reversal of pseudonymization, and other significant economic or social disadvantages. Any processing that involves large numbers of EU individuals, behavioral profiling, targeted advertising, employment-related data, or financial data carries a level of risk that will typically prevent this condition from being satisfied in combination with the first two. In practice, the Article 27(2) exemption is narrow and will rarely be available to commercial businesses that have concluded their processing falls within Article 3(2) in the first place: the very features that make Article 3(2) applicable — systematic engagement with EU consumers or users — are generally inconsistent with all three exemption conditions being simultaneously satisfied.

V. Where the Representative Must Be Located

Article 27(1) specifies that the representative must be established in “one of the Member States where the data subjects, whose personal data are processed in relation to the offering of goods or services to them, or whose behaviour is monitored, are.” This requirement ties the representative’s location directly to the geographic distribution of the data subjects affected by the processing. A non-EU business that offers goods or services to or monitors the behavior of individuals located in France, Germany, and Spain must designate a representative established in one of those three member states. A representative established in a member state where the business has no data subjects would not technically satisfy the geographic requirement of Article 27(1), even though it would be located within the EU generally.

Where a business has data subjects spread across multiple member states — as most consumer-facing businesses will — it may designate a single representative established in any one of those member states. There is no requirement to appoint a different representative in each member state where data subjects are located, and doing so would be both unnecessary and impractical. The single representative serves as the contact point for supervisory authorities and data subjects across all relevant member states.

The choice of member state carries strategic implications that counsel and clients should consider deliberately. Each EU supervisory authority has its own enforcement posture, staffing levels, linguistic resources, and track record in processing data subject complaints and conducting investigations. Some authorities are more proactive in enforcement and more demanding in their evidentiary expectations than others. Designating a representative in a member state where the supervisory authority has a strong record of engagement and accessible communication channels may serve the business’s interests better than a purely cost-driven selection. That said, the single most important limitation on member state selection is addressed in Section VIII: the choice of member state for the representative does not give the non-EU business access to GDPR’s one-stop-shop mechanism, and the misconception that it does has led many businesses to make member state choices based on a false assumption about how the GDPR’s cross-border enforcement structure operates.

VI. Who Can Serve as the Representative

Article 27 permits both natural persons and legal entities to serve as the representative, provided they are established in an EU/EEA member state. The representative cannot be the controller or processor itself — the obligation is precisely to designate a separate entity or individual with a distinct EU presence to act as the contact point. Beyond the requirement of EU establishment, the GDPR imposes no professional qualification, licensing, or expertise requirement for the representative role. Law firms, privacy consultancies, specialized representative services companies, and EU-based affiliates or subsidiaries of the appointing non-EU entity have all been used in practice, subject to the important caveat that a wholly owned subsidiary used purely as a formal representative without substantive operational capacity may face questions about whether it can genuinely discharge the representative’s obligations.

Whatever entity or individual is selected, the representative must have adequate access to the information and decision-making processes of the appointing controller or processor to function effectively. A representative that has no knowledge of the processing activities it nominally covers, has no access to the controller’s or processor’s records of processing activities, and has no protocol for receiving and responding to data subject requests or supervisory authority inquiries is a representative in name only and will not satisfy the substantive purpose of Article 27. Supervisory authorities that have pursued Article 27 enforcement actions have looked beyond the formal existence of a designation to assess whether the representative was operationally capable of performing its role.

The written mandate that documents the appointment should therefore address, at a minimum: the scope of the processing activities covered by the mandate; the obligation on the controller or processor to provide the representative with an up-to-date Article 30 record of processing activities; a protocol for forwarding data subject requests and supervisory authority communications to the representative and for the representative to transmit them to the controller or processor; the authority of the representative to respond on the controller’s or processor’s behalf within defined parameters; agreed response time targets consistent with GDPR’s statutory timelines; a mechanism for handling urgent matters such as data breaches; and indemnification provisions that protect the representative against costs and liabilities arising from its role as an administrative conduit for enforcement proceedings directed at the appointing entity. The commercial terms of these indemnification provisions are a matter of negotiation, but their existence is effectively non-negotiable: no reputable representative service provider will accept the role without them.

VII. What the Representative Does: Roles and Obligations

A. Point of Contact for Supervisory Authorities and Data Subjects — Article 27(4)

Article 27(4) is the operational heart of the representative obligation. It provides that the representative “shall be mandated by the controller or processor to be addressed in addition to or instead of the controller or the processor by, in particular, supervisory authorities and by data subjects, on all issues related to processing, for the purposes of ensuring compliance with this Regulation.” Three aspects of this provision deserve particular attention. First, the representative’s role covers “all issues related to processing” — it is not limited to specific categories of inquiry or to particular types of request. Second, the representative is addressable “in addition to or instead of” the controller or processor, meaning that the controller or processor is not released from its own accountability obligations by virtue of having a representative; the representative is an additional layer of EU-accessible compliance infrastructure, not a substitute for the underlying controller’s responsibility. Third, the mandate is specifically for the purpose of “ensuring compliance with this Regulation” — the representative’s role is substantive, not merely administrative.

In practice, the representative handles incoming data subject rights requests — requests for access under Article 15, rectification under Article 16, erasure under Article 17, restriction of processing under Article 18, data portability under Article 20, and objection under Article 21 — by receiving, logging, and transmitting them to the controller or processor for substantive response within the GDPR’s statutory timelines. The representative also receives supervisory authority correspondence: formal inquiries, information requests under Article 58(1)(a), notices of investigation, and communications regarding data subject complaints. The representative must have the operational capacity to triage and transmit these communications promptly, since response timelines under GDPR are measured from receipt of the communication, not from the date the controller or processor in the non-EU jurisdiction eventually becomes aware of it.

B. Maintaining Records of Processing Activities — Article 30(4)

Article 30(4) imposes an independent obligation on the representative: the representative of a controller or processor must maintain the record of processing activities on the controller’s or processor’s behalf, and must make that record available to the supervisory authority on request. This is an active compliance obligation that rests on the representative itself, not merely a delegation of the controller’s obligation under Article 30(1). The controller or processor is responsible for preparing the Article 30 record in the first instance and for keeping it accurate and current; it must provide the record to the representative and must notify the representative of any material changes to the processing activities it describes. The representative holds the record, ensures it is accessible, and produces it when a supervisory authority requests it under Article 58(1)(a).

A representative that fails to maintain an Article 30(4) record, or that is unable to produce the record when required by a supervisory authority, is in direct violation of GDPR. This creates a practical interdependency between the controller or processor and the representative: the representative can only fulfill its Article 30(4) obligation if the controller or processor fulfills its obligation to provide accurate and up-to-date information. The mandate should formalize this interdependency with clear information-sharing obligations and update protocols.

C. Cooperation with Supervisory Authorities — Article 58(1)

The representative must cooperate with supervisory authority exercises of investigative powers under Article 58(1). This includes providing the supervisory authority with any information it requires for the performance of its tasks, providing access to all personal data and information necessary for compliance inquiries, and cooperating with inspections and audits. Where a supervisory authority is investigating the processing activities of a non-EU controller or processor, the representative is the entity within the supervisory authority’s jurisdictional reach, and the supervisory authority will address its Article 58(1) requests to the representative. The representative’s failure to cooperate is itself a violation subject to fines under Article 83(4)(b).

D. Data Subject Complaints — Article 77(1)

Article 77(1) of the GDPR provides that data subjects have the right to lodge a complaint with a supervisory authority in the member state of their habitual residence, their place of work, or the place of the alleged infringement. Since the representative’s member state constitutes an EU address for the controller’s or processor’s processing activities, data subjects — particularly those located in the representative’s member state — may lodge complaints with the supervisory authority in that state relating to the controller’s or processor’s processing. This gives the choice of member state for the representative a practical dimension beyond the formal compliance requirement: the selection of the representative’s location will, to some degree, influence which supervisory authority first receives data subject complaints about the non-EU entity’s processing.

VIII. The One-Stop-Shop Non-Availability: A Critical Misconception

Among the most consequential misconceptions that non-EU businesses hold about the Article 27 representative is the belief that designating a representative in a particular member state is equivalent to choosing a “home” supervisory authority for GDPR purposes and that the business will thereafter deal primarily, or exclusively, with that authority. This belief is incorrect, and the compliance consequences of acting on it are serious.

The GDPR’s Article 56 one-stop-shop (OSS) mechanism allows controllers and processors that have a “main establishment” in the Union — defined in Article 4(16) as the place of central administration in the Union, or, where decisions about the purposes and means of processing are taken in a different establishment, the place of that establishment — to deal principally with the supervisory authority of that main establishment as the lead supervisory authority for cross-border processing. This mechanism significantly reduces compliance complexity for EU-established businesses operating across multiple member states, enabling them to engage primarily with a single supervisory authority rather than dealing simultaneously with the national DPA of every member state where their processing affects data subjects.

A non-EU business that designates an Article 27 representative does not gain access to this mechanism. The EDPB confirmed in Guidelines 3/2018 that when decisions regarding the purposes and means of processing activities are not taken within the Union, there is no main establishment within the meaning of Article 4(16) in the EU, and the OSS does not apply. The representative’s establishment in a member state is not a “main establishment” of the controller or processor; it is a designated contact point, not a decision-making center for the processing activities in question. The non-EU business therefore remains subject to the concurrent enforcement jurisdiction of supervisory authorities in every member state where its data subjects are located and where data subject complaints may be filed.

No One-Stop-Shop for Non-EU Businesses

Appointing a representative in Ireland does not mean you deal only with the Irish DPC. Appointing one in Germany does not limit your GDPR exposure to the German supervisory authorities. A non-EU business with data subjects across the EU faces potential concurrent enforcement action from national supervisory authorities in every member state where it operates, simultaneously. This is a fundamentally different compliance position from that of an EU-established business with a main establishment that can access the lead supervisory authority mechanism under Article 56.

The practical implication of OSS non-availability is significant for any non-EU business with substantial EU data subject populations. The business must be prepared to respond to inquiries, complaint investigations, and enforcement proceedings initiated by supervisory authorities in any of the member states where its data subjects are located. Its representative must be operationally capable of engaging with multiple supervisory authorities in different languages and jurisdictions. Privacy notices, complaint-handling procedures, and data subject rights response protocols must all be designed to function across the full range of EU member states involved, not merely in the state where the representative is established. Businesses for which this multi-jurisdictional exposure is commercially significant may wish to explore whether establishing a genuine EU subsidiary or branch with real operational responsibility for the relevant processing activities — rather than merely a representative — would provide access to the OSS and simplify the cross-border enforcement picture. That is a structural decision with corporate and commercial implications well beyond GDPR compliance, and it requires careful analysis; the GDPR does not permit a nominal EU entity that plays no genuine management role in the processing to serve as a “main establishment” for OSS purposes.

IX. The Representative’s Liability: What It Is and What It Is Not

A clear understanding of how liability is allocated between the non-EU controller or processor and its Article 27 representative is essential both for businesses selecting a representative and for entities considering whether to offer representative services. The GDPR’s liability framework in this context has two distinct components, and they are frequently conflated.

The first component is the representative’s own direct liability for its own GDPR obligations. The representative bears personal responsibility for fulfilling the specific obligations that Article 27 and the GDPR impose on it directly: maintaining the Article 30(4) record of processing activities and making it available to the supervisory authority on request, and cooperating with supervisory authority investigations under Article 58(1). If the representative fails to maintain the record, refuses to produce it, or fails to cooperate with a supervisory authority investigation, the representative itself has violated GDPR and may be subject to administrative fines under Article 83 for those specific violations. This direct liability is limited in scope but real, and representative service providers should not treat the role as purely administrative.

The second component is the supervisory authority’s power to address enforcement orders and administrative fines imposed on the controller or processor to the representative, as a practical mechanism for serving enforcement proceedings on a non-EU entity that would otherwise be beyond the supervisory authority’s physical reach. This power is an administrative convenience — it is the controller or processor that is the substantive violator and the legally liable party, not the representative. The GDPR does not establish substitutive liability of the representative in place of the controller or processor. An analysis of Article 27’s liability structure published by Bird & Bird in 2021 concluded that while supervisory authorities may route enforcement communications and fine notices to the representative’s address, the underlying fine or order is directed at and binding upon the foreign controller or processor, not the representative personally.

The practical significance of this distinction is that a representative could find itself served with enforcement orders and fine notices — including fines measured as a percentage of the worldwide annual turnover of the appointing controller or processor, which may greatly exceed the representative’s commercial fee — without being legally liable to pay those fines itself. The risks of being drawn into enforcement proceedings as a named addressee are nonetheless real: reputational risk, the cost of legal response, and the operational burden of cooperating with investigations can all fall on the representative. This is why market-standard representative agreements include substantial indemnification provisions. Controllers and processors appointing a representative should expect to indemnify the representative for costs, expenses, and liabilities arising from its role, including costs associated with supervisory authority proceedings in which the representative is addressed as the controller’s or processor’s EU contact point. Failure to include adequate indemnification is both commercially unreasonable and likely to make competent representative services unavailable.

X. Post-Brexit: The Dual Representative Requirement

The United Kingdom’s withdrawal from the European Union took full legal effect on January 1, 2021, from which date the EU GDPR and the UK GDPR — the latter being the EU GDPR as retained and adapted in UK domestic law by the Data Protection Act 2018, as amended by the European Union (Withdrawal) Act 2018 and its secondary legislation — became entirely separate legal frameworks. The UK GDPR contains a provision directly parallel to EU GDPR Article 27, requiring non-UK controllers and processors subject to the UK GDPR by virtue of the UK GDPR’s own targeting criterion to designate a representative established in the United Kingdom.

The critical consequence of this separation is that an EU Article 27 representative does not satisfy the UK GDPR representative requirement, and a UK representative does not satisfy the EU GDPR requirement. Each regime requires a representative established in the relevant jurisdiction: the EU representative must be established in an EU/EEA member state; the UK representative must be established in the United Kingdom. These are distinct appointments that must be made separately. A U.S. business that processes personal data of both EU-located individuals and UK-located individuals is, on this analysis, potentially required to make two separate Article 27 appointments: one EU representative and one UK representative, each operating under a separate written mandate, each engaging with the relevant supervisory authority (an EU DPA and the UK Information Commissioner’s Office respectively), and each maintaining the relevant records for its jurisdiction. The regulatory and commercial costs of operating in both markets should be assessed accordingly.

This dual requirement catches many non-EU businesses by surprise. Organizations that were previously relying on a single representative established in the United Kingdom for EU GDPR compliance — as was permissible prior to the end of the Brexit transition period — were required to transition to an EU-established representative for EU GDPR purposes. Businesses that have not reviewed their Article 27 arrangements since 2021 should do so promptly to confirm that their EU representative is established in an EU/EEA member state and that any UK-only representative has not been treated as satisfying the EU obligation.

XI. Article 27 Representative Versus Data Protection Officer: Key Distinctions

The Article 27 representative and the Article 37 data protection officer are two distinct roles with different legal bases, different functions, incompatible structural requirements, and different appointment thresholds. They are commonly confused by non-EU businesses encountering GDPR compliance for the first time, and the confusion can produce compliance failures in either or both directions — appointing only one where both are required, or attempting to have the same individual serve both functions when the roles are structurally incompatible.

Article 27

EU Representative

Externally-facing contact point for supervisory authorities and data subjects.

Operates under direct mandate and instructions from the controller or processor.

Required whenever Art. 3(2) applies and no exemption is available.

Obligations: hold Article 30(4) RoPA; cooperate with supervisory authority under Art. 58(1).

No independence requirement — acts as directed.

Must be established in an EU/EEA member state.

Article 37

Data Protection Officer

Internal compliance monitor, advisor, and point of contact with supervisory authority from the organization’s perspective.

Must perform tasks independently, without instructions on how to exercise the function. Art. 38(3).

Required only where Art. 37(1) conditions are met (public authority; large-scale systematic monitoring; large-scale special category/criminal data processing).

Obligations: inform and advise; monitor compliance; advise on DPIAs; cooperate with and act as contact point for supervisory authority. Art. 39.

Independence is mandatory — cannot receive instructions regarding DPO function. Art. 38(3).

No specific location requirement, but must be easily accessible.

The most important distinction for practical purposes is the independence requirement. A DPO must act independently in the exercise of the DPO function; the DPO cannot be instructed by the organization’s management on compliance matters and must be free to provide objective advice and monitoring. Article 38(3) is explicit: the DPO “shall not receive any instructions regarding the exercise of those tasks.” An Article 27 representative, by contrast, is defined by its mandate relationship — it acts precisely as instructed by the appointing controller or processor. These two roles are structurally incompatible, and the same individual or entity cannot serve simultaneously as both the Article 27 representative and the Article 37 DPO for the same organization. Where both are required, two separate appointments must be made.

Not every organization subject to Article 27 is also required to appoint a DPO. The DPO obligation under Article 37(1) is triggered only in three circumstances: where the processing is carried out by a public authority or body (with an exception for courts acting in their judicial capacity); where the core activities of the controller or processor consist of processing operations that require regular and systematic monitoring of data subjects on a large scale; or where the core activities consist of processing on a large scale of the special categories defined in Article 9 or of criminal data under Article 10. Many non-EU commercial businesses subject to Article 27 will not independently satisfy the Article 37(1) threshold — though those offering behavioral advertising, large-scale profiling, or health and financial services to EU users should analyze the Article 37(1) conditions carefully rather than assuming the DPO requirement does not apply.

XII. Enforcement: Fines and Regulatory Consequences

Failure to designate a representative under Article 27 when one is required is a violation of GDPR subject to administrative fines under Article 83(4)(a): up to €10,000,000, or in the case of an undertaking, up to 2% of the total worldwide annual turnover of the preceding financial year, whichever is higher. This is the lower of the GDPR’s two fine tiers, applicable to violations of organizational and procedural obligations rather than violations of the core data protection principles or data subject rights. The fine threshold is nonetheless substantial, and when calculated on the basis of a percentage of worldwide annual turnover, it can produce very significant sums for large technology and consumer companies.

Beyond the standalone Article 83(4)(a) exposure, the absence of an Article 27 representative operates as an aggravating factor in the assessment of fines for more serious violations under Article 83(5) and Article 83(6) — the higher tiers that can reach €20,000,000 or 4% of global annual turnover for violations of the core data protection principles, conditions for consent, data subjects’ rights, or the rules governing international transfers. Article 83(2)(k) directs supervisory authorities to take into account “any other aggravating or mitigating factors applicable to the circumstances of the case,” and the failure to establish the basic compliance infrastructure that Article 27 requires is consistently treated as an aggravating consideration. A non-EU business that has both failed to appoint a representative and committed substantive GDPR violations faces compounded exposure in enforcement proceedings.

Enforcement practice confirms that supervisory authorities are willing to pursue standalone Article 27 violations directly. In May 2021, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) imposed a fine of €525,000 on Locatefamily.com, a U.S.-based people-search website, specifically for failure to appoint an EU representative. The Dutch DPA’s investigation found that Locatefamily.com processed the personal data of individuals in the Netherlands — by publishing personal information scraped from public sources about Dutch residents — in a manner that triggered Article 3(2), but had taken no steps to comply with the resulting Article 27 obligation. This enforcement action was significant as one of the first standalone Article 27 fines and signaled clearly that supervisory authorities were prepared to pursue the representative obligation as an independent compliance requirement, not merely as an ancillary element of larger investigations.

Clearview AI’s enforcement history across multiple EU member states provides a further illustration of how the absence of a representative compounds broader GDPR exposure. The Italian Garante imposed a fine that included an Article 27 violation component as part of broader enforcement against Clearview AI’s collection and use of facial recognition data involving EU individuals. Across various national enforcement actions against Clearview AI, the company’s effective non-cooperation with supervisory authority investigations — a practical consequence of the absence of an accessible EU representative — was repeatedly identified as a concern. The representative obligation exists precisely to prevent this dynamic: a non-EU entity that processes EU personal data at scale but has no accessible EU contact point is, from a supervisory authority’s perspective, deliberately structured to evade the enforcement mechanisms the GDPR establishes.

XIII. Practical Compliance Steps

The following steps set out the core compliance actions for a non-EU business assessing its Article 27 obligations. Each step builds on the preceding analysis and corresponds to a specific legal requirement or sound practice judgment derived from GDPR, EDPB guidance, and enforcement experience.

  • 1 Determine whether Article 3(2) applies. Analyze the business’s processing activities for the offering of goods or services directed at EU-located individuals or the monitoring of their behavior within the Union. Apply the EDPB’s “manifest intention” indicators from Recital 23 and Guidelines 3/2018. Document the analysis in writing. If Article 3(2) does not apply, the Article 27 obligation is not engaged — but revisit the analysis whenever the business materially expands its EU-facing activities.
  • 2 Assess the Article 27(2) exemption. If Article 3(2) applies, determine whether all three conditions of the Article 27(2) exemption — occasional processing, no large-scale special category or criminal data, and low risk — are simultaneously satisfied. Document the exemption assessment. For most commercial businesses with ongoing EU consumer engagement, the exemption will not apply.
  • 3 Identify the member states where data subjects are located. Establish which EU/EEA member states contain the data subjects whose personal data is processed. This defines the pool of member states from which the representative’s member state must be selected.
  • 4 Select the representative and member state. Choose a natural person or legal entity established in one of the identified member states that has the operational capacity to perform the representative role. Consider the supervisory authority’s enforcement posture, linguistic accessibility, and responsiveness. Negotiate the mandate and indemnification terms carefully, and ensure the written designation covers the full scope of the processing activities for which Article 3(2) applies.
  • 5 Prepare and provide the Article 30 RoPA to the representative. Compile the record of processing activities in the form required by Article 30(1) (for controllers) or Article 30(2) (for processors) and provide it to the representative for maintenance under Article 30(4). Establish a protocol for updating the record when processing activities change and for communicating those updates to the representative promptly.
  • 6 Publish the representative’s contact details. Include the representative’s name and full contact details in the organization’s privacy notice or privacy policy, ensuring that data subjects and supervisory authorities can identify the representative without difficulty. Confirm that the representative’s contact information is also accessible in the way required by the supervisory authority of the chosen member state.
  • 7 Assess whether a DPO is separately required. Analyze the processing activities against the Article 37(1) conditions for mandatory DPO appointment. If both a representative and a DPO are required, appoint them as separate individuals or entities, as the two roles are incompatible.
  • 8 Address the post-Brexit dimension. If the business also processes personal data of individuals physically located in the United Kingdom in circumstances that trigger UK GDPR Article 3(2), assess whether a separate UK representative is required. An EU representative does not satisfy the UK GDPR requirement; a separate appointment of a UK-established representative must be made if the UK GDPR obligation is engaged.
  • 9 Establish periodic review. Schedule an annual review of the Article 27 arrangements to confirm that the representative’s appointment and contact details are current, that the Article 30 RoPA accurately reflects the processing activities, that no changes in supervisory guidance or the business’s operations affect the analysis, and that any post-Brexit obligations remain properly addressed.

Note on the One-Stop-Shop

None of the steps above give a non-EU business access to GDPR’s Article 56 one-stop-shop mechanism. If the volume and complexity of the business’s EU data subject processing make multi-supervisory-authority exposure a material operational and legal risk, the appropriate response is to assess whether to establish a genuine EU entity with real operational responsibility for the processing — not to attempt to use the representative’s member state as a proxy for a main establishment.

XIV. Key Statutory and Regulatory References

SourceCitationSubject and Key Point
GDPR Art. 27Regulation (EU) 2016/679Core representative obligation: applies where Art. 3(2) is engaged; designation must be in writing; representative must be established in a member state where data subjects are located; identifies the Art. 27(2) exemption and its three cumulative conditions; Art. 83(4)(a) fine tier for non-compliance.
GDPR Recital 80Regulation (EU) 2016/679Policy rationale: facilitates effective enforcement against non-EU entities by providing supervisory authorities and data subjects with an accessible EU contact point; confirms the cumulative nature of the Art. 27(2) exemption conditions.
GDPR Art. 3(2)Regulation (EU) 2016/679The threshold trigger for Art. 27: applies to non-EU controllers and processors processing personal data of individuals in the Union in connection with offering goods/services or monitoring behavior; physical presence in the Union at the time of the activity is required.
GDPR Recital 23Regulation (EU) 2016/679“Manifest intention” indicators for the offering of goods/services: language, currency, delivery options, and similar signals of deliberate targeting of EU consumers; accessibility of a website alone is not sufficient.
GDPR Art. 30(4)Regulation (EU) 2016/679Independent obligation on the representative to maintain the record of processing activities on behalf of the controller or processor and to make it available to the supervisory authority on request; the representative bears direct liability for this obligation.
GDPR Art. 37Regulation (EU) 2016/679DPO appointment obligation; three triggering conditions; mandatory independence; incompatible with the Art. 27 representative role; where both are required, separate appointments must be made.
GDPR Art. 38(3)Regulation (EU) 2016/679DPO independence: the DPO shall not receive any instructions regarding the exercise of the DPO function; the structural incompatibility with the Art. 27 representative mandate relationship.
GDPR Art. 56 / Art. 4(16)Regulation (EU) 2016/679One-stop-shop mechanism and the definition of “main establishment”; the Art. 27 representative’s member state does not constitute a main establishment; non-EU businesses cannot access the OSS through their representative.
GDPR Art. 58(1)Regulation (EU) 2016/679Supervisory authority investigative powers; the representative must cooperate with information requests, access requests, and inspections; failure to cooperate is itself a violation subject to Art. 83(4)(b) fines.
GDPR Art. 77(1)Regulation (EU) 2016/679Data subject right to lodge complaint with supervisory authority in member state of habitual residence, place of work, or place of alleged infringement; the representative’s member state is one of the possible complaint venues.
GDPR Art. 83(4)(a)Regulation (EU) 2016/679Fine tier for failure to appoint a representative: up to €10,000,000 or 2% of total worldwide annual turnover, whichever is higher; non-appointment is also an aggravating factor under Art. 83(2)(k) for higher-tier violations.
EDPB Guidelines 3/2018Final version, November 2019Territorial scope of GDPR: confirms Art. 27 is triggered by Art. 3(2); confirms that the representative’s establishment is not a “main establishment” and does not give access to the OSS; articulates the “manifest intention” test for the offering limb of Art. 3(2).
Dutch DPA v. Locatefamily.comMay 2021 — €525,000 fineFirst major standalone enforcement action under Art. 27; Dutch DPA imposed €525,000 fine on U.S.-based people-search website for failure to appoint an EU representative; confirmed supervisory authority willingness to pursue the representative obligation as an independent compliance requirement.
Clearview AI enforcementMultiple EU member states, 2022–2024Art. 27 violation component in Italian Garante enforcement; pattern of non-cooperation with supervisory authorities attributed in part to absence of an accessible EU representative; illustrates how non-appointment compounds broader enforcement exposure.
UK GDPR Art. 27Data Protection Act 2018 (UK); retained EU lawPost-Brexit parallel obligation: non-UK entities subject to UK GDPR targeting criterion must appoint a UK-established representative separately; an EU representative does not satisfy the UK requirement and vice versa.

See Also