If your business is based outside the European Union (EU) but you sell products to, provide services for, or monitor the behavior of individuals located within the EU, you are subject to the General Data Protection Regulation (GDPR). While many companies focus on consent banners and privacy policies, one critical—and heavily enforced—requirement often slips under the radar: Article 27.
Often dubbed the GDPR's "hidden obligation," Article 27 mandates that certain non-EU organizations must appoint a designated representative within the EU. Failing to do so isn't just a technicality; it's a direct violation that can result in hefty fines.
Here is everything you need to know about Article 27 and the good practices you should implement to ensure your business remains compliant.
What is GDPR Article 27 ?
In simple terms, Article 27 requires non-EU data controllers and processors to appoint a formal, local point of contact inside the EU.
Because European regulators and citizens cannot easily reach out to a company based in the US, Australia, or post-Brexit UK, the EU Representative bridges the geographical gap. They serve as the direct liaison for communications regarding data processing and GDPR compliance.
Does This Apply to Your Business ?
Article 27 applies to you if you meet both of the following criteria:
You do not have a physical establishment (like an office or branch) within the EU or EEA.
You process the personal data of individuals in the EU to either offer them goods and services or monitor their behavior (e.g., via website tracking cookies).
The Exceptions: You might be exempt from appointing a representative if your data processing is purely occasional, does not involve large-scale processing of highly sensitive data (like health or criminal records), and poses a low risk to individuals' rights. Public authorities are also exempt. However, if processing EU data is a core, repeated part of your business model, you must comply.
What Does an EU Representative Actually Do ?
Your EU Representative is not the same as a Data Protection Officer (DPO). While a DPO ensures internal compliance and strategy, an EU Representative is primarily a facilitator. Their core responsibilities include:
Serving as a Point of Contact: Acting as the designated contact for EU data protection authorities (DPAs) and European citizens who want to exercise their data rights (like the right to erasure or access).
Maintaining Documentation: Holding and providing access to your organization's Records of Processing Activities (RoPA) when requested by a supervisory authority.
Facilitating Communication: Ensuring that inquiries are handled promptly and translated appropriately, helping you navigate the local regulatory landscape.
Good Practices for Article 27 Compliance
Appointing a representative isn't just about picking a name out of a hat. Regulators are actively checking whether these appointments are legitimate and effective. Here are the best practices to follow:
1. Choose the Right Location
Your representative cannot be located just anywhere. They must be established in one of the EU Member States where the data subjects you interact with are located. If you sell heavily into France and Germany, your representative should be based in one of those two countries.
2. Formalize the Mandate in Writing
A verbal agreement or a casual email isn't enough. You must designate your EU Representative through a formal, written mandate (a legal contract) that explicitly outlines their authority to act on your behalf regarding GDPR obligations.
3. Update Your Privacy Policy
Transparency is a cornerstone of the GDPR. Once you have appointed an EU Representative, you must prominently display their name, physical address, and contact information (like a dedicated email address) in your external Privacy Notice. If a regulator visits your website and cannot easily find this information, you are immediately flagging yourself as non-compliant, a risk highlighted in the recent EDPB transparency sweep.
4. Arm Your Representative with the Right Data
Your representative can only help you if they have the right information. Ensure they have access to an up-to-date copy of your Article 30 Records of Processing Activities (RoPA). Keep lines of communication open so they can rapidly alert you if a data subject or regulator reaches out.
5. Don't Confuse the Role with a DPO
While a single entity can sometimes serve as both your DPO and your EU Representative, it is often discouraged due to potential conflicts of interest. The DPO is meant to act independently to monitor your internal compliance, whereas the Representative acts on your direct instructions as a point of contact. It is generally a good practice to keep these roles distinct, as outlined by guidance from the UK ICO and France's CNIL.
The Cost of Ignoring Article 27
Regulators are increasingly cracking down on overseas businesses that fail to designate a local contact, as seen among the biggest GDPR fines in Europe. Failure to appoint an EU Representative is a direct breach of the GDPR and can result in administrative fines of up to €10 million or 2% of your global annual turnover, whichever is higher. Beyond fines, non-compliance damages consumer trust and can lead to business interruptions if regulators decide to block your data flows.
For non-EU businesses, the message is clear: if you want to participate in the European market, you have to play by their rules. Appointing an EU Representative is a straightforward, manageable step that protects your business from unnecessary regulatory risk and shows your European customers that you take their privacy seriously.
Need help navigating Article 27 and broader EU compliance ? Contact our team to learn more about our compliance services, review our pricing, or check our FAQ page for common questions. You can also read more on our related blog post on GDPR Article 27 or explore how compliance requirements differ across markets, such as our Austria privacy law comparison, to see how our team at Complico Consulting can support your EU market entry.