Article 27 Representative
An Article 27 Representative is a person or organization based in the EU that certain controllers or processors located outside the EU must appoint to act as their local point of contact. Data protection authorities and individuals can reach out to the representative about the organization's data processing. The representative acts on behalf of the controller or processor but generally does not replace the organization's own legal responsibilities.
Under Article 27 of the GDPR, a controller or processor that falls within the Regulation's territorial scope but is not established in the EU is, subject to the exemptions set out in Article 27(2), required to designate in writing a representative in the Union. Per Article 27(3), the representative should be established in one of the member states where the relevant data subjects are located, and Article 27(3) does not otherwise prescribe additional location requirements. The representative acts on behalf of the controller or processor and may be addressed by any supervisory authority and by data subjects on matters relating to processing, in addition to or instead of the controller or processor. Designation of a representative is without prejudice to legal actions that could be initiated against the controller or processor itself, so the appointment does not transfer or diminish the organization's own liability. Note that the analogous obligation under the UK GDPR concerns a UK representative and is a distinct requirement; practitioners should verify the precise scope, exemptions, and any national implementing provisions against the current official text.
Why it matters
The Article 27 Representative provides a local point of contact within the EU for organizations that are subject to the GDPR's territorial scope but are not themselves established in the Union. Without such a presence, supervisory authorities and individuals could face practical difficulties in reaching an organization whose operations sit outside the EU. Appointing a representative helps close that accessibility gap, making it easier for authorities and data subjects to raise questions and concerns about the organization's processing activities.
Crucially, designating a representative does not transfer or reduce the appointing organization's own legal responsibilities. Article 27(3) provides that the designation is without prejudice to legal actions that could be initiated against the controller or processor itself, so the underlying organization remains accountable for its compliance obligations. The representative is best understood as a facilitator of communication and a local liaison, not a shield against liability or a substitute for the organization's own accountability.
Because the requirement is subject to the exemptions set out in Article 27(2), whether a given organization must appoint a representative depends on its specific circumstances and should be assessed against the current official text. Practitioners should also note that the analogous obligation under the UK GDPR concerns a distinct UK representative requirement, so an organization active in both the EU and the UK may need to consider each separately.
Who it's relevant to
Inside Article 27 Representative
Common questions
Answers to the questions practitioners most commonly ask about Article 27 Representative.