HOME/SERVICES/EU Representative
SERVICE PRACTICE · EU REPRESENTATIVE

EU Representative under GDPR Art. 27.

Named EU contact for non-EU controllers and processors that offer goods or services to people in the European Union. Regulator liaison, data subject handling, Article 30 records and documentation in one annual fee.

EUREP.DESK · LAST 12 MONTHS● LIVE
Companies represented73
Data subject requests handled318
Supervisory authority enquiries12
Languages supportedAll 24 EU
Median response time to a DSR3 days
Annual GDPR record reviews73
TRUSTED BY 300+ EU ORGANISATIONS
RocheSiemensAstraZenecaInditexKončarOrbicoFortenova
FREE 30-MIN CONSULTATION

Talk to a senior advisor.

One business day reply. Clear next steps and indicative pricing.

1 BUSINESS DAY REPLYNDA ON REQUESTNO OBLIGATION
01 / PRIMER

Article 27 obligations.

WHO IS IN SCOPE

Non-EU companies offering goods or services in the EU.

If you process personal data of people in the EU, monitor their behaviour, or offer goods and services to them, Article 27 applies. Limited exemptions exist for occasional and low-risk processing.

WHAT THE REP DOES

Local contact for regulators and data subjects.

The representative is mandated in writing, named in the privacy notice and the Article 30 record, and responds to enquiries from supervisory authorities and individuals in EU languages.

WHERE THE REP SITS

In a Member State where data subjects are located.

We are established in Croatia and act for clients targeting the EU broadly. The representative address is published in your privacy notice and shared with supervisory authorities on request.

ADMINISTRATIVE FINES
Up to €10M or 2% of turnover
Failure to designate a representative attracts the lower tier of GDPR Article 83 fines. Repeated failures escalate.
ENFORCEMENT EXPOSURE
Regulator action against the controller
Authorities can act against the non-EU controller directly. The representative absorbs first-line contact and reduces escalation risk.
02 / WHERE IT BITES

Article 27 in detail.

REGIME · WHAT IT REQUIRES
ART. 27(1)Designation dutyNon-EU controllers and processors caught by Article 3(2) must designate a representative in the Union in writing.
ART. 27(3)Where the rep sitsIn one of the Member States where data subjects are located. We are established in Croatia.
ART. 27(4)Authority and contactMandate covers contact with supervisory authorities and data subjects on all matters related to processing.
ART. 27(5)Cooperation dutyDesignation does not affect any legal action that could be initiated against the controller or processor themselves.
REGIME · WHAT IT REQUIRES
ART. 30(2)(a)Records on fileRepresentative keeps the controller's record of processing activities and produces it on supervisory request.
ART. 13(1)(a)Privacy notice namingRepresentative identity and contact details listed in the privacy notice provided to data subjects.
ART. 33(3)(f)Breach notification contextRepresentative supports controller breach notifications to supervisory authorities and affected individuals.
GUIDELINES 03/2018EDPB targeting testPractical guidance from the EDPB on when Article 3(2) applies and when a representative must be appointed.
03 / ENGAGEMENT MODELS

Engagement models.

MODEL AANNUAL

EU representative service

Annual fixed fee. Mandate, address, inquiry handling, supervisory authority liaison, Article 30 record on file.

  • →Written mandate and appointment letter
  • →EU address and email published in your privacy notice
  • →Data subject request triage and response
  • →Annual record-of-processing review
MODEL BRETAINER

Representative + DPO retainer

EU rep service plus a senior privacy advisor on call. The combined retainer covers programme support and breach triage.

  • →Everything in Model A
  • →Senior privacy advisor on call
  • →Monthly programme support
  • →Breach triage and notification drafting
MODEL CREVIEW

Designation review

Independent assessment of whether Article 27 applies to your processing and what the appointment should look like.

  • →EDPB targeting test review
  • →Processing scope mapping
  • →Designation memo for the board
  • →Vendor and sub-processor implications
04 / SCOPE

Scope of work.

01 / 04

Appointment & paperwork

  • Written mandate and appointment letter
  • Privacy notice text and placement
  • Article 30 record on file
  • Supervisory authority directory listing
02 / 04

Data subject handling

  • Inbound inquiry triage in any EU language
  • Subject request (DSR) workflow with deadlines
  • Complaint handling and escalation
  • Audit trail of every interaction
03 / 04

Regulator liaison

  • First point of contact for supervisory authorities
  • Documentation production on request
  • Notification coordination for breaches
  • Cross-border enquiry handling
04 / 04

Ongoing programme support

  • Annual record-of-processing review
  • Update notifications when scope changes
  • Sub-processor and transfer changes flagged
  • Annual posture report
05 / IN PRACTICE

How we run the mandate.

The EU representative role only works if it is operational. We publish an email and a postal address, monitor both, log every inquiry and respond inside the GDPR timelines. Supervisory authorities get a real contact, not a forwarding address.

Inquiry triage median
1 day
DSR response median
3 days
Annual record review
12 months
Languages supported
All 24 EU
Appoint us30 MIN
CLIENT · MANDATE STATUSQ2 2026
Active inquiries0
DSRs in window100%
Authority enquiries open0
Record reviewedQ1 2026
Privacy notice updatedQ1 2026
Vision Compliance · EU representative practice
06 / SELECTED WORK

Recent appointments.

See all case studies →
EUR-12US SAAS

EU rep appointed before EU launch, no enforcement gap.

7 days
TIME
27
DSRS
0 open
AUTHORITY
SCOPEDesignation, privacy notice, DSR workflow, annual review
EUR-09UK FINTECH

Post-Brexit EU rep appointment for processing of EU residents.

EU-27
MARKETS
84
DSRS
100%
TIME-IN-WINDOW
SCOPEMandate, EU contact, multilingual DSR handling
EUR-05AUS HEALTH

Australian health app appointed EU rep for German clients.

DE primary
JURISDICTION
DE / EN
DSR LANGUAGE
0 open
AUTHORITY
SCOPEArticle 27 designation, DE supervisory contact, record review
07 / LANDSCAPE

EU Representative landscape.

60%
of non-EU companies offering to the EU still lack an appointed representative
€10M
upper limit of Article 83(4) fines for designation failures
24
EU languages in which a representative may receive inquiries
27
Member States where Article 3(2) targeting can trigger the duty
TREND 01

Cross-border enforcement is closer

EDPB and national authorities coordinate on cases involving non-EU controllers. The representative becomes the first point of contact in cross-border procedures.

TREND 02

AI Act adds an authorised representative

Non-EU AI providers also need an EU authorised representative for the AI Act regime. The two roles overlap but are governed by different obligations.

TREND 03

Privacy notices are read by regulators

Authorities check the representative line on the privacy notice as part of routine reviews. Missing or generic placeholders trigger follow-up.

08 / FAQ

Common questions.

01Who must appoint an EU representative?+

Non-EU controllers and processors that offer goods or services to people in the EU, or monitor the behaviour of people in the EU. The targeting test is the EDPB Guidelines 03/2018. Limited exemptions exist for occasional and low-risk processing.

02Can our EU subsidiary or law firm act as our representative?+

A subsidiary works only if it has operational capacity and authority. A law firm is legally permitted but rarely delivers the operational response a controller needs. A dedicated EU representative service is built for the role.

03What does the representative actually do day to day?+

Monitors the published EU address and email. Triages every inquiry from data subjects and supervisory authorities. Coordinates DSR responses inside the GDPR deadlines. Produces the Article 30 record on supervisory request. Flags scope changes that affect the appointment.

04How fast can we be appointed?+

The mandate, privacy notice text and Article 30 starter can be in place within 7 business days. Faster turnaround is possible where the existing privacy programme is already documented.

05Do we also need an EU authorised representative under the AI Act?+

If you are a non-EU provider of an AI system covered by the AI Act, yes. The AI Act introduces a separate authorised representative obligation. We cover both roles in one engagement where the same entity is providing AI systems and processing personal data.

06What is your fee structure?+

Annual fixed fee for the EU representative service, priced on the volume of inquiries expected and the breadth of EU markets you serve. We do not charge per request inside reasonable volumes. Higher-volume programmes use a tiered model.

09 / RESOURCES

Templates and guides.

10 / RELATED

Related practices.

11 / GET STARTED

Talk to a senior advisor.

Send the brief. We respond with a scoped agenda for the first call.