As needed
EU representative under Article 27 GDPR
A contact point inside the Union for controllers and processors established outside it, where the GDPR applies to their processing.
If you are established outside the European Union and the GDPR applies to your processing, Article 27 requires you to designate a representative inside the Union. This page is about that role — what it is, what it is not, and how the arrangement works.
Who needs a representative
The GDPR reaches controllers and processors established outside the Union when they offer goods or services to people who are in the Union, or when they monitor the behaviour of people who are in the Union. Where it reaches you, a representative established in one of the Member States where those people are is part of the duty, not an optional extra.
Whether your processing falls inside that duty is settled by what you actually do, not by where your servers stand. The regulation also exempts some processing from the requirement; whether an exemption applies to you is the first thing to establish, and we look at it with you before anything is signed.
What the representative does
The representative is the address at which data subjects and supervisory authorities can reach you on all questions related to the processing — alongside you or instead of you, at their choice; the responsibility stays yours.
Answers at that address and passes on what arrives, with the context you need in order to act on it.
Keeps the record of processing activities available to the supervisory authority.
Helps set up the documentation the role requires, so that the address is not the only thing that exists.
How it works
We provide the EU representative service for controllers and processors from third countries to whom the GDPR applies. We provide a contact point for data subjects and supervisory authorities, help set up the documentation required, and support compliance with obligations under the GDPR. The arrangement is through a mandate contract under Article 27 GDPR.
What this is not
It is not legal representation. The representative is a contact point, not an attorney, and does not act for you in proceedings.
It is not the data protection officer. The two roles are separate: the officer advises and monitors compliance inside the organisation, the representative stands for the organisation towards data subjects and authorities outside it.
It does not move your responsibility. The controller remains the controller; designating a representative adds an address, it does not transfer a duty.
Legal position verified as of 25 September 2026.
Tell us where you process and who you reach
What you offer in the Union, which countries your customers are in, and what documentation exists today. Thirty minutes is usually enough to tell whether the duty applies to you at all.