When Article 27 requires non-EU organisations to appoint an EU representative, how to choose one, and how to turn the mandate into an operational control.
Topics: GDPR, Article 27, EU Representative, Privacy Operations
A US software provider can launch in France, Germany and Spain without opening an EU office. It may still be targeting people in the Union, analysing their product behaviour and processing their personal data at scale. In that scenario, GDPR representation is not a formality added to a privacy notice. It is part of the organisation’s operating model for maintaining an effective point of contact in Europe.
For non-EU controllers and processors, an EU representative is often required under Article 27 of the GDPR. The requirement is straightforward in principle, but applying it correctly depends on the organisation’s processing activities, markets, data flows and internal ability to respond when an authority or individual makes contact.
What GDPR representation means in practice
An EU representative is a person or organisation established in the European Union and appointed in writing by a controller or processor that is not established in the EU. The representative acts as a local contact point for supervisory authorities and data subjects on matters relating to the processing of personal data.
The appointment does not move GDPR accountability away from the non-EU organisation. The controller or processor remains responsible for its compliance decisions, its vendors, its security arrangements and its handling of data subject rights. Nor is an Article 27 representative automatically a Data Protection Officer. These are separate functions with different statutory roles, although they need to work closely together where both are required.
A well-run representative mandate therefore needs more than a published address. The representative must be able to receive communications, understand the relevant processing context, obtain timely input from the right internal owners and manage a controlled response process.
When Article 27 GDPR representation is required
Article 27 can apply where a controller or processor is not established in the EU but processes personal data in connection with either offering goods or services to people in the Union, or monitoring their behaviour within the Union.
The test is not simply whether someone in Europe can access a website. Organisations should consider the evidence of their commercial and operational intent. Local currency, EU-focused advertising, country-specific delivery options, European language campaigns, regional support arrangements and the routine analysis of EU user activity can all be relevant indicators.
For a processor, the position should be assessed separately. A non-EU service provider processing EU personal data for customers may have its own Article 27 obligations, rather than relying on the controller’s arrangements.
There are limited exceptions, including for processing that is occasional, does not include large-scale processing of special category or criminal offence data, and is unlikely to create a risk to individuals’ rights and freedoms. These conditions are restrictive and should be considered together. A growing SaaS platform, life sciences business, financial services provider or AI-enabled technology company will often find that its processing is too regular, extensive or operationally significant for the exception to offer dependable coverage.
Public authorities and bodies are also outside the Article 27 requirement. Beyond that, organisations should avoid treating an exception as a permanent status. New product features, an expanded customer base, behavioural analytics or a centralised group data platform can change the analysis quickly.
Choosing the right location for an EU representative
The representative must be established in an EU Member State where the relevant data subjects are located. For businesses serving multiple markets, that does not necessarily mean appointing separate representatives in every country. It does mean selecting a location and service model that supports the real footprint of the processing.
Language capability, local business hours, accessibility for authorities and the ability to coordinate across multiple jurisdictions all matter. The representative’s details should also appear in the organisation’s privacy information, alongside the appropriate contact route.
EU, UK and Swiss representation should not be treated as interchangeable. The UK GDPR has a separate UK representative requirement for certain organisations outside the UK, while the Swiss nFADP has its own representative framework. A company operating across all three territories may need coordinated mandates, clear jurisdictional documentation and a single internal process for handling enquiries.
Turning an appointment into an operational control
The difference between a nominal representative and an effective one is usually found in the workflow behind the mandate. When a supervisory authority contacts the representative, the organisation should already know who owns the response, what information can be provided, how decisions are escalated and how deadlines are tracked.
At minimum, this requires a documented mandate, named contacts and an agreed incident and enquiry intake process. The representative should be able to reach the privacy lead, legal owner, security team and relevant business stakeholders without relying on an informal chain of emails across time zones.
Records of processing activities are particularly important. Article 27 representatives may be asked to make relevant records available to supervisory authorities, so the organisation needs current, accessible documentation rather than a static register created for a past audit. The same applies to privacy notices, processor agreements, data transfer information, data subject request procedures and impact assessments.
Response readiness should also be tested. A data subject access request may require information from customer support, product, HR, security and legal teams. A regulatory enquiry may raise questions about retention periods, international transfers or profiling. If the representative has no defined route into those teams, local representation cannot deliver its intended value.
GDPR representation and AI governance
AI deployment can make Article 27 assessments more complex. An organisation based outside the EU may offer an AI-enabled service to EU customers while collecting prompts, usage data, telemetry and inferred information about users. These activities can engage GDPR requirements even where the underlying model is hosted elsewhere.
The governance question is broader than whether an EU representative has been appointed. Organisations need a clear view of what personal data enters AI systems, which vendors process it, whether the use case involves profiling or sensitive data, and how individuals can exercise their rights. Data protection impact assessments, vendor risk assessments and a maintained AI system register can provide the operating evidence needed to support those decisions.
EU AI Act obligations may also apply depending on the organisation’s role and the AI system concerned. A GDPR representative should not be assumed to fulfil any separate EU AI Act authorised representative requirement. Keeping these roles distinct while coordinating the underlying governance evidence helps prevent gaps between privacy, product and compliance teams.
What to look for in a representative service
A suitable representative should provide more than a legal address. The provider needs a controlled method for receiving and triaging authority correspondence, practical knowledge of cross-border privacy operations, and the capacity to support time-sensitive matters without creating unnecessary friction for internal teams.
For organisations with complex data environments, the strongest model combines three capabilities: a Legal Team that understands regulatory obligations, a Privacy Team that translates those obligations into workable controls, and Technical Operations that can maintain records, workflows and evidence. This matters where GDPR representation connects with DSAR handling, breach response, DPIAs, vendor governance and AI risk management.
Coverage also matters. International groups should assess whether the service can support their wider expansion plan rather than solving for one market in isolation. Formiti combines representative services with privacy operations across 120+ countries and 100+ regulatory frameworks, allowing EU, UK, Swiss and other local requirements to be managed through coordinated compliance processes. Learn more about Formiti’s data privacy services.
Commercially, the right mandate is proportionate to the organisation’s risk profile. A business with a small and stable EU customer base may need a focused contact and escalation service. A high-growth platform processing substantial volumes of data across several markets may need ongoing operational support, maintained documentation and regular governance reviews. The point is to align the service with the reality of the processing, not simply to meet a registration-style requirement.
A representative appointment is most valuable when it gives the organisation a reliable route from external contact to internal action. Build that route before an authority or data subject needs to use it, and GDPR representation becomes a practical control for confident European operations rather than an address in the footer.