EU Representative GDPR: When Article 27 Requires One
The EU representative GDPR requirement catches more US companies than almost any other GDPR duty. If your company has no office in the European Union but sells to, or tracks, people there, Article 27 says you must appoint a representative inside the EU in writing. Most companies that need one do not have one, usually because they confused it with a Data Protection Officer (DPO) or assumed a US company is out of reach.
This guide covers who Article 27 applies to, the narrow exemption, what the representative actually does, and how to appoint one. For the full list of GDPR duties this sits alongside, see the GDPR compliance checklist.
What Article 27 Actually Requires
Article 27(1) is one sentence. Where Article 3(2) applies, the controller or processor must designate in writing a representative in the Union.
The representative is a local stand-in. Under Article 27(4), regulators and individuals can contact it in addition to, or instead of, your company on any issue about how you process personal data. It is how an EU regulator reaches a company with no EU address.
The appointment does not shift your legal responsibility. Article 27(5) says legal action can still be brought against the controller or processor itself. You stay on the hook. The representative is an extra point of contact, not a shield.
Who Needs an EU Representative
Two conditions must both be true.
1. You Have No Establishment in the EU
If you already have an establishment in the EU, such as a subsidiary or branch involved in the processing, GDPR applies to you under Article 3(1) instead. In that case Article 27 does not apply to that processing, because regulators can reach your local entity directly.
An establishment means real, stable activity in the EU. A server hosted in Frankfurt is not an establishment. A sales office in Dublin with staff is.
2. Article 3(2) Brings You Into Scope
GDPR reaches companies outside the EU in two situations:
- Offering goods or services to people in the EU, whether or not they pay. Signs that you are targeting the EU include EU languages or currencies on your site, delivery to EU countries, EU-focused marketing, and EU customer references. Simply having a website that EU visitors can reach is not enough on its own.
- Monitoring the behavior of people in the EU, as far as that behavior takes place in the EU. Behavioral advertising, cross-site tracking, profiling, location tracking, and detailed product analytics tied to individuals can all count.
Processors are covered too. A US vendor processing data for a customer who targets the EU can fall under Article 3(2) through that customer's activity, and then needs its own representative.
Typical SaaS Scenarios
- B2B SaaS with EU customers and no EU entity. You offer services to EU businesses, and you process personal data about their employees and users. Representative required.
- Consumer app available in EU app stores with EU-language localization and EU pricing. Representative required.
- US-only product that EU residents occasionally sign up for, with no EU marketing, localization, or pricing. Probably not targeting the EU, but document the analysis.
- US parent with an EU subsidiary that runs the EU business. Generally covered under Article 3(1) through the subsidiary for that processing, so no representative for it.
The Exemption Is Narrow
Article 27(2) exempts two groups:
- Public authorities or bodies.
- Processing that meets all three conditions at once:
- It is occasional.
- It does not include large-scale processing of special category data (health, biometrics, religion, and the rest of Article 9) or criminal conviction data (Article 10).
- It is unlikely to result in a risk to people's rights and freedoms, considering the nature, context, scope, and purposes of the processing.
The word that decides most cases is "occasional." Regulators read it narrowly. A SaaS platform that processes EU user data every day as part of its core service is not processing occasionally, even if EU users are a small share of the total.
If you plan to rely on the exemption, write down why each of the three conditions is met. You will need that reasoning if a regulator asks.
What an EU Representative Does
The role is mostly administrative, but it carries real obligations.
- Receives inquiries. Supervisory authorities and data subjects can contact the representative about any processing issue. It passes those to you and helps you respond.
- Holds your record of processing activities. Articles 30(1) and 30(2) require the controller or processor, and its representative where one exists, to maintain the record. Article 30(4) requires it to be made available to the supervisory authority on request. Keep your record of processing activities current and share each update with the representative.
- Cooperates with regulators. Article 31 requires cooperation with the supervisory authority on request. Under Article 58(1)(a), a regulator can order the representative to provide information it needs.
- Appears in your privacy notice. Articles 13 and 14 require you to give people the identity and contact details of your representative. If you appoint one and leave it out of the notice, you have a second gap.
What the Representative Does Not Do
It does not give you independent compliance advice, monitor your program, or answer requests on your behalf without your input. It does not make you EU-established. It also does not give you access to the GDPR "one-stop-shop," the mechanism that lets companies with a main establishment in the EU deal with a single lead regulator. Without an EU establishment, any supervisory authority where affected users live can act against you.
Can the Representative Be Held Liable?
The European Data Protection Board's Guidelines 3/2018 on territorial scope say GDPR can be enforced against a non-EU company by way of its EU representative. In practice, that means a regulator can open proceedings through the representative rather than chasing you across borders. It is also why commercial representative services pay close attention to cooperation and indemnity terms in their contracts.
EU Representative vs Data Protection Officer
These two roles get confused constantly. They are different obligations with different triggers.
| EU Representative (Art. 27) | Data Protection Officer (Art. 37) | |
|---|---|---|
| Triggered by | No EU establishment + Article 3(2) scope | Core activities involve large-scale monitoring or large-scale special category data (or public authority) |
| Role | Local point of contact, acts on your mandate | Independent adviser and monitor of compliance |
| Independence | Takes instructions from you | Must not take instructions on how to do the job |
| Location | Must be in the EU | Must be easily accessible; EU location recommended |
Can one person hold both roles? The EDPB says an external DPO cannot also act as your representative, because the DPO's independence conflicts with acting on your mandate.
You may need one, both, or neither. Needing a DPO does not mean you need a representative, and the reverse is also true. We cover the DPO test in full in data protection officer requirements for SaaS, and the difference between a DPO and a US-style privacy lead in DPO vs privacy officer.
What Happens If You Skip It
Failing to appoint a representative falls under the lower tier of GDPR fines in Article 83(4). That is up to 10 million euros or 2% of worldwide annual turnover, whichever is higher.
This is not theoretical. In May 2021 the Dutch data protection authority fined Locatefamily.com 525,000 euros for failing to appoint an EU representative. It was the first fine of its kind, and it was driven by a practical problem. Individuals who wanted their data removed had no one in the EU to contact.
The bigger risk for most SaaS companies is commercial, not regulatory. EU enterprise customers check for a named representative during vendor due diligence. A missing representative in your privacy notice is an easy finding for their procurement team, and it makes the rest of your GDPR posture look less credible.
How to Appoint an EU Representative
1. Confirm You Are in Scope
Document your Article 3 analysis: whether you have an EU establishment, how you target or monitor people in the EU, and whether the Article 27(2) exemption could apply. File this with your other GDPR records.
2. Choose the Member State
Article 27(3) requires the representative to be established in one of the Member States where your users are. The EDPB recommends, as good practice, the Member State where a significant share of them are located. For most SaaS companies, that is the country where most EU customers are.
3. Choose the Type of Representative
Common options:
- A commercial representative service. The most common choice for SaaS companies. Many also offer a UK representative.
- A law firm in the chosen Member State.
- An EU-based affiliate or partner willing to take on the role. Check that the relationship does not make them an establishment of yours for other processing.
Do not use your external DPO, for the independence reasons above.
4. Sign a Written Mandate
Article 27(1) requires the designation to be in writing. The mandate should cover:
- The scope of processing covered
- How inquiries from regulators and individuals are passed to you, and how fast
- How you keep the representative's copy of the record of processing activities current
- Cooperation duties when a regulator makes contact
- Liability, indemnity, and termination terms
5. Update Your Documents
Add the representative's name and contact details to your privacy notice, your record of processing activities, and any customer-facing data processing agreements that list your representative. Your GDPR data processing agreement template is a good place to check.
6. Do Not Forget the UK
The UK GDPR has its own Article 27. If you target or monitor people in the UK and have no UK establishment, you need a UK representative too. An EU representative does not cover the UK.
For the rest of your EU obligations, see the GDPR compliance checklist, GDPR for SaaS, and the GDPR service page. If a DPO appointment is also on your list, see our DPO service page. Where your EU processing is high risk, the next step is a data protection impact assessment.
Frequently Asked Questions
What is an EU representative under GDPR? A person or company in the EU that a non-EU controller or processor appoints in writing under Article 27. It is the local contact point for regulators and individuals, and it holds a copy of your record of processing activities.
Who needs an EU representative? Any company with no EU establishment that offers goods or services to people in the EU or monitors their behavior there. The exemption covers only public authorities and processing that is occasional, low risk, and free of large-scale sensitive data. SaaS companies with ongoing EU users rarely qualify.
Can my Data Protection Officer also be my EU representative? The EDPB says an external DPO and a representative are incompatible. The DPO must be independent, while the representative acts on your mandate. Plan for two appointments if you need both.
Where must the EU representative be located? In a Member State where the people whose data you process are located. The EDPB recommends the Member State where a significant share of them are.
What is the fine for not appointing an EU representative? Up to 10 million euros or 2% of worldwide annual turnover, whichever is higher. The Dutch regulator fined Locatefamily.com 525,000 euros in 2021 for this failure alone.
Do I need a separate UK representative? Usually, yes. The UK GDPR has its own Article 27, and an EU representative does not cover the UK.
Need to Know Whether Article 27 Applies to You?
ShieldKey Solutions helps US SaaS companies with EU and UK users work out exactly which GDPR roles they need: representative, DPO, both, or neither. We document the scope analysis, set up the appointments, and update your privacy notice and records so they hold up in customer due diligence.