Skip to main content
Category: Controller & Processor Roles

Article 27 Representative

Also known as: GDPR Representative, EU Representative, Representative under Article 27 GDPR
Simply put

An Article 27 Representative is a person or organization based in the EU that certain controllers or processors located outside the EU must appoint to act as their local point of contact. Data protection authorities and individuals can reach out to the representative about the organization's data processing. The representative acts on behalf of the controller or processor but generally does not replace the organization's own legal responsibilities.

Formal definition

Under Article 27 of the GDPR, a controller or processor that falls within the Regulation's territorial scope but is not established in the EU is, subject to the exemptions set out in Article 27(2), required to designate in writing a representative in the Union. Per Article 27(3), the representative should be established in one of the member states where the relevant data subjects are located, and Article 27(3) does not otherwise prescribe additional location requirements. The representative acts on behalf of the controller or processor and may be addressed by any supervisory authority and by data subjects on matters relating to processing, in addition to or instead of the controller or processor. Designation of a representative is without prejudice to legal actions that could be initiated against the controller or processor itself, so the appointment does not transfer or diminish the organization's own liability. Note that the analogous obligation under the UK GDPR concerns a UK representative and is a distinct requirement; practitioners should verify the precise scope, exemptions, and any national implementing provisions against the current official text.

Why it matters

The Article 27 Representative provides a local point of contact within the EU for organizations that are subject to the GDPR's territorial scope but are not themselves established in the Union. Without such a presence, supervisory authorities and individuals could face practical difficulties in reaching an organization whose operations sit outside the EU. Appointing a representative helps close that accessibility gap, making it easier for authorities and data subjects to raise questions and concerns about the organization's processing activities.

Crucially, designating a representative does not transfer or reduce the appointing organization's own legal responsibilities. Article 27(3) provides that the designation is without prejudice to legal actions that could be initiated against the controller or processor itself, so the underlying organization remains accountable for its compliance obligations. The representative is best understood as a facilitator of communication and a local liaison, not a shield against liability or a substitute for the organization's own accountability.

Because the requirement is subject to the exemptions set out in Article 27(2), whether a given organization must appoint a representative depends on its specific circumstances and should be assessed against the current official text. Practitioners should also note that the analogous obligation under the UK GDPR concerns a distinct UK representative requirement, so an organization active in both the EU and the UK may need to consider each separately.

Who it's relevant to

Non-EU controllers and processors within GDPR scope
Organizations established outside the EU whose processing falls within the Regulation's territorial scope may be required to appoint an Article 27 Representative, subject to the Article 27(2) exemptions. These organizations should assess whether the obligation applies to them and, if so, ensure the designation is made in writing and the representative is located in a member state where relevant data subjects are situated.
Data protection officers and compliance leads
Those responsible for GDPR compliance need to determine whether a representative must be appointed, oversee the designation, and ensure the representative can be effectively contacted by authorities and data subjects. They should also keep the underlying organization's own responsibilities in view, since appointing a representative does not diminish the organization's accountability or its exposure to legal action.
Supervisory authorities and data subjects
Supervisory authorities and individuals benefit from having a local point of contact they can address on matters relating to an out-of-EU organization's processing. The representative may be addressed in addition to or instead of the controller or processor, though this does not prevent legal actions being brought against the organization itself.
Organizations active in both the EU and the UK
Because the UK GDPR contains a distinct UK representative obligation, organizations operating in both jurisdictions should consider each requirement separately and verify the applicable scope, exemptions, and national provisions against the current official texts rather than assuming a single appointment satisfies both.

Inside Article 27 Representative

Designated Representative in the EU
A natural or legal person established in the EU (or in the UK, for UK GDPR purposes) that a controller or processor not established in the relevant territory designates in writing to act on its behalf regarding its obligations under the Regulation. The representative is addressed by data subjects and supervisory authorities in addition to, or instead of, the controller or processor.
Triggering condition (extraterritorial scope)
The obligation to designate a representative generally arises where the controller or processor is not established in the EU but its processing is nonetheless caught by the Regulation's territorial scope, such as offering goods or services to individuals in the EU or monitoring their behaviour. The precise triggering criteria and any exemptions should be verified against the current text of the Regulation.
Location within the relevant territory
The representative should generally be established in a member state where the affected data subjects are located, or in the UK where the UK regime applies. Practitioners should confirm the applicable placement rule against the operative text.
Recognised exemptions
The Regulation typically provides limited exemptions from the designation requirement, for example for certain occasional processing that is low risk. Whether an exemption applies is subject to assessment of the specific processing activities, and the reader should verify the exact conditions in the current text and applicable guidance.
Point of contact function
The representative serves as a point of contact for supervisory authorities and data subjects on all issues related to processing, for the purposes of ensuring compliance. It typically maintains records and facilitates communication, but designation does not itself transfer the controller's or processor's own accountability.
Relationship to controller or processor liability
Designating a representative does not remove the legal responsibility or liability of the controller or processor. The extent to which a representative may itself face enforcement is an area subject to regulatory guidance and interpretation, and positions may differ between authorities.

Common questions

Answers to the questions practitioners most commonly ask about Article 27 Representative.

Does appointing an Article 27 representative make that representative liable for the controller's or processor's compliance failures?
No. Appointing a representative does not transfer the controller's or processor's own responsibilities or liability to the representative. The representative acts on behalf of the controller or processor and serves as a point of contact for supervisory authorities and data subjects, but the controller or processor generally remains accountable for compliance. There has been some debate and evolving regulatory guidance about the extent to which enforcement action may be directed at or through the representative, so readers should verify the current position against the applicable regulator's guidance and the Regulation text.
Is an Article 27 representative the same role as a Data Protection Officer?
No, these are distinct roles and should not be conflated. A representative under Article 27 is a person or entity established in the EU that acts as a local point of contact for organisations without an establishment in the Union but that fall within the GDPR's territorial scope. A Data Protection Officer performs an advisory and oversight function on data protection matters and is subject to separate requirements. The two roles have different purposes, and one person or entity holding both should be assessed carefully for any conflict; consult current guidance where this arises.
How do we determine whether our organisation is required to appoint an Article 27 representative?
The requirement generally arises where a controller or processor is not established in the Union but its processing falls within the GDPR's extraterritorial scope, subject to the exemptions set out in Article 27. Assessing this typically involves reviewing whether your processing relates to offering goods or services to individuals in the Union or monitoring their behaviour, and whether any exemption applies. This is a fact-specific assessment, and a separate representative may be needed for the UK GDPR position. Verify the exemption criteria against the current text and applicable national implementing rules.
In which member state should the representative be established?
The representative should generally be established in a member state where the relevant data subjects are located, in line with Article 27. Where individuals are spread across several member states, organisations typically consider factors such as where the main body of affected data subjects is, though the appropriate choice can be context dependent. Confirm the precise requirement against the current Regulation text and any relevant regulatory guidance, and note that a distinct arrangement applies for UK GDPR purposes.
What should be included in the mandate or agreement with an Article 27 representative?
The arrangement typically sets out that the representative is mandated to be addressed by supervisory authorities and data subjects on all issues related to processing, for the purpose of ensuring compliance. In practice, organisations commonly address how enquiries and requests are handled and escalated, cooperation with authorities, access to relevant records, and the scope of the mandate. The specific contents should reflect the requirements of Article 27 and be tailored to the organisation's processing; verify the mandate against the current Regulation text and applicable guidance.
How should the appointment of a representative be communicated to data subjects and authorities?
The identity and contact details of the representative are generally expected to be made available to data subjects and accessible to supervisory authorities. In most cases this is reflected in transparency information such as privacy notices. Organisations should ensure the representative's details are clearly discoverable by individuals who may wish to exercise their rights. Confirm the specific transparency and record-keeping expectations against the current Regulation text and any applicable regulatory guidance, which may evolve.

Common misconceptions

An Article 27 representative is the same role as a Data Protection Officer.
They are distinct roles. A DPO is an advisory and oversight function concerned with monitoring compliance, whereas the representative under this provision acts as the local point of contact for a controller or processor not established in the relevant territory. One person or entity should not be assumed to satisfy both roles, and combining them may raise conflict or independence concerns that should be assessed.
Appointing a representative shifts legal responsibility away from the controller or processor.
The controller or processor generally remains responsible and liable for compliance. The representative acts on the organisation's behalf as a contact and facilitation function; it does not absorb the underlying accountability. The scope of any independent exposure for the representative is subject to regulatory interpretation.
Every organisation outside the EU that touches EU data must appoint a representative.
The obligation depends on whether the processing falls within the Regulation's territorial scope and whether a recognised exemption applies. It is not a universal requirement, and whether it is triggered should be assessed against the specific processing activities and the current text.

Best practices

Assess whether your processing falls within the Regulation's extraterritorial scope and whether any exemption applies before concluding that a representative is or is not required; document that assessment.
Where required, designate the representative in writing and locate it in an appropriate member state (or in the UK for UK GDPR purposes), confirming the placement rule and any separate UK designation obligation against the current text.
Keep the roles of representative and DPO distinct in your governance documentation, and evaluate any conflict of interest before assigning both functions to the same person or entity.
Ensure the representative has access to the records and information needed to respond to data subjects and supervisory authorities, and define this in the mandate or contract.
Publish the representative's identity and contact details in privacy notices so data subjects and authorities can reach the correct point of contact.
Periodically review the designation as your processing activities, market presence, and the applicable transfer and scope rules evolve, verifying positions against the current official text and any updated regulatory guidance.