An Article 27 representative is generally required when a controller or processor without an EU establishment is subject to the GDPR under Article 3(2). The representative is a local point addressed by supervisory authorities and individuals; it is not a substitute for the organisation’s compliance duties or an automatic DPO.
Apply the test in order
1. Is there an EU establishment?
Article 27 concerns controllers or processors not established in the Union. Analyse real arrangements, not only place of incorporation. An effective and real exercise of activity through stable arrangements can be relevant under the EDPB’s territorial-scope guidance.
2. Does Article 3(2) apply?
The relevant processing must relate to:
- offering goods or services to people in the EU, whether or not payment is required; or
- monitoring their behaviour so far as it takes place in the EU.
Do not infer targeting from mere website accessibility. Review product design, marketing, delivery, language/currency context and tracking activities.
3. Does the narrow exception apply?
No representative is required where the processing is occasional, does not include large-scale processing of Article 9 special-category data or Article 10 criminal-conviction data, and is unlikely to risk individuals’ rights and freedoms, taking account of its nature, context, scope and purposes. All elements must be satisfied. Public authorities and bodies have a separate exception.
Recurring provision of a digital service to EU users is unlikely to become “occasional” merely because the business is small. Document the facts and revisit them as the service grows.
Where and how to appoint
The representative must be established in one of the Member States where individuals whose data is processed in relation to the offering or monitoring are located. Designate the representative in writing and give enough authority and information to perform the role.
Articles 13 and 14 require the representative’s identity and contact details to be provided where applicable. Make contact details easy for individuals and authorities to find.
What the representative does
The role includes being addressed, in addition to or instead of the controller or processor, on issues related to processing for GDPR compliance. Article 30 also requires the representative to maintain the applicable record of processing activities and make it available to the supervisory authority on request.
A workable service needs:
- current contact and entity information;
- access to the relevant processing records;
- a verified route to the controller or processor;
- procedures for authority communications and individual enquiries;
- language and coverage matching relevant Member States; and
- incident, escalation, record-update and termination arrangements.
The representative does not determine the organisation’s purposes and means merely by holding the role. It should not be marketed as transferring liability away from the non-EU organisation; Article 27(5) expressly preserves enforcement against the controller or processor.
Representative, DPO and lead authority
| Role/concept | Function |
|---|---|
| Article 27 representative | EU contact for a non-EU organisation within Article 3(2) |
| DPO | Independent adviser and monitor where Article 37 or voluntary appointment applies |
| Processor | Processes personal data on documented controller instructions |
| Lead supervisory authority | Depends on the GDPR cooperation rules and establishment facts; a representative alone does not create a main establishment |
Do not bundle these concepts without separate role and conflict analysis.
Provider due diligence
Confirm the legal entity, establishment, countries and languages covered, security and confidentiality, response process, record-maintenance method, escalation targets, subcontractors, liability terms and exit handover. There is no official universal Article 27 price or accreditation; compare actual scope and capacity.
Vision Compliance offers an EU representative service with documented contact and escalation workflows. If the underlying programme also needs implementation support, scope data protection services separately.
Sources and review
- Regulation (EU) 2016/679, Articles 3, 13, 14, 27 and 30
- EDPB Guidelines 3/2018 on territorial scope and Article 27
Reviewed on 8 August 2026. The exception, establishment analysis and role limits are stated without assuming that every non-EU website needs a representative.
Ivana Ludiga, mag. iur., is an Associate at Vision Compliance focused on data protection, GDPR implementation, and regulatory advisory. She supports compliance projects for organizations across healthcare, financial services, and technology sectors.