Skip to main content
Category: Controller & Processor Roles

Representative in the Union

Also known as: EU Representative, GDPR Representative, Article 27 Representative
Simply put

A Representative in the Union is a person or organisation appointed to act on behalf of a controller or processor that is not established in the EU but is subject to the GDPR. This representative serves as a point of contact within the EU for individuals and supervisory authorities on matters relating to the organisation's data processing.

Formal definition

Under the GDPR, a Representative in the Union is a natural or legal person established in the EU, designated in writing by a non-EU controller or processor that falls within the extraterritorial scope of the Regulation, to represent the organisation with regard to its obligations. The representative is generally required to be established in a member state where the relevant data subjects are located, and is mandated to be addressed by supervisory authorities and data subjects in addition to (or instead of) the controller or processor. The designation obligation is subject to specified exemptions, and the precise conditions and any national-law variations should be verified against the current official text of the Regulation and relevant guidance.

Why it matters

The Representative in the Union addresses a structural gap created by the GDPR's extraterritorial reach: when a controller or processor with no EU establishment nonetheless falls within the scope of the Regulation, individuals and supervisory authorities need an accessible point of contact within the EU. Without a designated representative, data subjects seeking to exercise their rights and regulators seeking to engage on compliance matters would have to reach across borders to an entity outside their direct jurisdiction, undermining the practical enforceability of the Regulation.

For affected organisations, appointing a representative is generally a compliance obligation rather than an optional convenience, subject to specified exemptions. Failing to designate one where required can itself constitute a breach, independent of any underlying processing issue. Because the representative is mandated to be addressed by supervisory authorities and data subjects in addition to or instead of the organisation, the role directly shapes how accountability is channelled and how quickly complaints or regulatory queries can be actioned.

The precise scope triggers, exemptions, and any divergences under the UK GDPR or national implementing law can affect whether and where a representative must be appointed. Organisations should verify these conditions against the current official text of the Regulation and relevant guidance rather than relying on a general description, as the boundaries of the obligation are context dependent.

Who it's relevant to

Non-EU controllers and processors within GDPR scope
Organisations established outside the EU but subject to the Regulation are the primary parties on whom the designation obligation may fall. They need to assess whether they trigger the requirement, whether any exemption applies, and in which member state a representative should be established, verifying these points against the current official text.
Appointed EU representatives
Individuals or organisations established in the EU that take on this mandate act as the designated point of contact for supervisory authorities and data subjects. They should understand the written designation and the scope of matters on which they may be addressed on the organisation's behalf.
Supervisory authorities
Regulators rely on the representative as an accessible EU-based contact for engaging with non-EU organisations on compliance matters, which affects how they route queries and enforcement-related communications.
Data subjects
Individuals whose personal data is processed by an in-scope non-EU organisation may address the representative when exercising their rights, providing a contact point within the EU rather than having to reach the organisation directly abroad.
Compliance and legal advisers
Data protection officers, compliance leads, and legal counsel advising in-scope organisations need to determine whether appointment is required, identify the appropriate member state, and confirm exemptions and any UK GDPR or national-law divergences against authoritative current sources.

Inside Representative in the Union

Designation obligation
The requirement, under Article 27 GDPR, for certain controllers or processors not established in the EU to designate in writing a representative in the Union, where the GDPR applies to their processing by virtue of Article 3(2) (offering goods or services to, or monitoring the behaviour of, data subjects in the EU).
Location of the representative
The representative must generally be established in one of the member states where the data subjects whose personal data is processed are located, in connection with the offering of goods or services to them or the monitoring of their behaviour.
Point of contact function
The representative acts as an addressee for supervisory authorities and data subjects, in addition to or instead of the controller or processor, on all issues related to processing for the purposes of ensuring compliance with the GDPR.
Statutory exemption
Designation is not required where processing is occasional, does not include large-scale processing of special category data (Article 9) or criminal conviction and offence data (Article 10), and is unlikely to result in a risk to the rights and freedoms of natural persons, or where the controller or processor is a public authority or body. Whether an exemption applies is subject to assessment.
Relationship to the controller or processor
Designation of a representative is without prejudice to legal actions that could be initiated against the controller or processor themselves; the representative does not replace the accountability of the entity it represents.
UK GDPR counterpart
The UK GDPR contains a parallel concept of a representative for controllers or processors outside the UK that fall within its territorial scope; the EU and UK obligations are distinct and can apply separately depending on where data subjects are located.

Common questions

Answers to the questions practitioners most commonly ask about Representative in the Union.

Does appointing a Representative in the Union transfer legal responsibility for compliance away from the controller or processor?
No. Appointing a representative does not shift or diminish the controller's or processor's own responsibility and liability under the GDPR. The representative acts on behalf of the organisation and serves as a contact point, but the underlying compliance obligations remain with the controller or processor. In most cases the organisation continues to be directly accountable to supervisory authorities and data subjects, and the existence of a representative does not affect any enforcement action that could be taken against the organisation itself.
Is a Representative in the Union the same role as a Data Protection Officer?
No. These are distinct roles that should not be conflated. A representative addresses the situation where a controller or processor is established outside the EU but falls within the GDPR's territorial scope, acting as a locally based point of contact within the Union. A Data Protection Officer is a separate function with its own tasks, such as advising on obligations and monitoring compliance, and different conditions govern when each must be designated. An organisation may need one, both, or neither depending on its circumstances, and combining the roles in one person can raise conflict and independence considerations that should be assessed.
When is a controller or processor required to designate a Representative in the Union?
The requirement generally arises where a controller or processor is not established in the EU but is nonetheless subject to the GDPR because it offers goods or services to, or monitors the behaviour of, individuals in the Union. There are recognised exceptions to this obligation, so the position should be assessed against the current text and applicable regulatory guidance for the specific processing involved. Where the equivalent regime under the UK GDPR applies, a separate analysis is needed, and the requirements should be verified against the relevant national implementing framework.
Where should the Representative in the Union be located and how should it be documented?
The representative is typically established in a member state where the relevant individuals whose data is processed are located. Organisations generally document the designation through a written mandate defining the representative's tasks and the scope of its authority. In most cases the representative's identity and contact details should also be made available to data subjects and supervisory authorities, including where transparency information is provided. You should verify the specific documentation and disclosure expectations against the current official text and any applicable regulatory guidance.
What tasks does a Representative in the Union typically perform in practice?
In practice, the representative generally acts as the addressee for supervisory authorities and data subjects on matters relating to the organisation's processing, in addition to or instead of the controller or processor. It is commonly tasked with maintaining or having access to relevant records of processing so it can respond to enquiries. The precise scope should be set out in the mandate and aligned with the organisation's processing activities, and organisations should ensure the representative has adequate information and cooperation from the organisation to carry out these functions.
How should an organisation manage the relationship and information flow with its Representative in the Union?
Organisations typically establish clear internal processes so the representative can be reached, receive relevant documentation, and escalate communications from authorities or data subjects promptly. Because the organisation remains responsible, arrangements should ensure the representative is kept informed of changes to processing activities and can access necessary records. It is also advisable to keep the mandate under review so it continues to reflect the organisation's actual processing, and to confirm the arrangement against current regulatory expectations, which may evolve.

Common misconceptions

The representative bears the legal liability of the controller or processor and can be held responsible for their non-compliance.
The representative acts as a point of contact and facilitates communication with authorities and data subjects. Designation is without prejudice to actions against the controller or processor themselves, who retain their own accountability. The extent to which enforcement measures can be directed at the representative is an area where regulator interpretation and guidance may vary, so this should be verified against current official sources.
Every organisation outside the EU that processes any EU personal data must appoint a representative.
The obligation generally arises only where the GDPR applies under Article 3(2) and no statutory exemption applies. Processing that is occasional, not large-scale involving special category or criminal data, and unlikely to result in risk to individuals may fall within the exemption, subject to case-by-case assessment. Public authorities and bodies are also excluded.
A data protection officer and a representative in the Union are the same role and one can substitute for the other.
These are distinct functions with different legal bases and purposes. A representative is a point of contact for a non-EU entity within EU territory, while a DPO advises on and monitors compliance. An organisation may be required to have both, one, or neither depending on the circumstances.

Best practices

Assess whether the GDPR applies to your processing under Article 3(2) before concluding a representative is needed, and document that territorial scope analysis.
Where designation may be required, evaluate whether the Article 27 exemption applies to your processing (occasional processing, absence of large-scale special category or criminal data, low risk) and record the reasoning, treating the outcome as subject to reassessment.
Select a representative established in a member state where relevant data subjects are located, and formalise the appointment in writing with a clear mandate covering communications with supervisory authorities and data subjects.
Publish the identity and contact details of the representative in privacy notices and other appropriate channels so that data subjects and authorities can readily reach them.
Ensure the representative has access to the information and records needed to respond to enquiries, and put in place a workflow for escalating matters back to the controller or processor.
Separately assess UK GDPR representative obligations where your processing may fall within UK territorial scope, and verify current requirements against the applicable official texts and guidance, which can evolve.