Every case below is one where a data protection authority actually found a failure to appoint or properly maintain a representative under GDPR Article 27. Engage Compliance compiled it against the authority decisions and press releases, and every row links to the deciding authority. Vendor and law firm write-ups were used to locate cases, never as the source for one.

The honest headline is the useful one: eight decisions in eight years across the whole EEA, two turned on the representative failure alone, and only one puts a figure on it. That is a finding, not a gap in our research. It means the reason to appoint a representative is not the size of a rare fine. It is that the obligation is real and easy to check, that regulators now police whether the appointment actually works, and that customers and partners ask for the representative’s details long before any regulator does.

The register: eight decisions

#CaseAuthorityDecidedFineArticle 27 finding
1Locatefamily.comNetherlands, Autoriteit Persoonsgegevens12 May 2021€525,000The only case where the representative failure is the sole sanctioned finding
2Clearview AI, Inc.Italy, Garante9 March 2022€20,000,000One of eight findings; no part of the fine attributed to Article 27
3Senseonics, Inc.Italy, Garante7 July 2022€45,000Late appointment still a breach; a medical device representative does not satisfy Article 27
4Clearview AI, Inc.Greece, Hellenic DPA13 July 2022€20,000,000Explicit Article 3(2)(b) reasoning; obliged to appoint and did not
5Clearview AI, Inc.Netherlands, Autoriteit Persoonsgegevens3 September 2024€30,500,000Article 27 one of several findings; no allocation to it
6Hangzhou DeepSeek Artificial Intelligence Co.Greece, Hellenic DPA21 May 2025noneArticle 27 the only substantive finding; interim ruling ordering an appointment, complied with in a week
7Tiger Media Inc.Spain, AEPD14 November 2025€120,000, reduced to €72,000The only decision that puts a figure on Article 27: €50,000 of the penalty
8Character Technologies, Inc.Italy, Garante3 July 2026€158,000Article 27(1) late designation upheld; the unreachable-link complaint under 27(4) not upheld, contact still worked via a published address and phone

1. Locatefamily.com, Dutch DPA, €525,000

The one case of its kind. The Dutch DPA fined Locatefamily.com €525,000 under Article 27(1) read with Article 3(2), and this is the only decision where the representative failure is the sole sanctioned finding. The authority placed it in Category III of its 2019 penalty policy, band €300,000 to €750,000, and applied the base amount with no adjustment. It also ordered the company to appoint in writing within 12 weeks or pay €20,000 per fortnight, capped at €120,000. The reasoning is the quotable part: the DPA framed practical reachability of a non-EU controller, by both data subjects and the authority, as fundamental to protecting rights. The company was contactable only at a Canadian address. Read the Dutch DPA decision.

2. Clearview AI, Italy, Garante, €20,000,000

A single undifferentiated fine covering eight findings under Articles 5, 6, 9, 12 to 15 and 27. The Garante also ordered Clearview to designate an EU representative. No part of the fine is attributed to Article 27, so the widely repeated “€600,000 Article 27 component” figure is wrong: it does not exist in the decision. Read the Garante decision.

3. Senseonics, Italy, Garante, €45,000

Two commercially useful holdings. First, the Garante rejected the argument that a medical device EU authorized representative satisfies Article 27, holding that a specific GDPR designation is separately required. Second, Senseonics did appoint a representative, on 29 June 2021, after the investigation opened, and the breach was still recorded for the preceding period. Late is still a breach. Read the Garante decision.

4. Clearview AI, Greece, Hellenic DPA, €20,000,000

The Article 27 reasoning here is explicit. The Hellenic DPA found Clearview falls within Article 3(2)(b), has no EU establishment, is obliged to appoint a representative, and did not. The fine is stated as a total with no allocation per violation. Read the Hellenic DPA decision.

5. Clearview AI, Netherlands, Dutch DPA, €30,500,000

Findings under Articles 6, 9, 12, 14, 15 and 27, plus orders with penalty payments up to €5,100,000. No allocation to Article 27. The Dutch DPA later began examining director liability, because Clearview had paid none of the fines levied against it across the EU, which is the deeper problem with enforcing this obligation against exactly the population it targets. Read the Dutch DPA decision.

6. DeepSeek, Greece, Hellenic DPA, no fine

The case that shows a regulator starting from Article 27 rather than arriving at it, and the one that shows what usually happens next. The Hellenic DPA opened an investigation on its own initiative in February 2025 into Hangzhou DeepSeek Artificial Intelligence Co., the Chinese company behind the DeepSeek assistant, and told it that it fell inside the GDPR on the targeting test in Article 3(2) and owed a written representative designation. DeepSeek denied offering services in the EU at all. The authority disagreed, and its reasoning is the part worth borrowing: the service was reachable in Greece over the web and through mobile apps, and the apps were published in Greek, so it was targeting people in the EU whatever the company said about its intentions. On 21 May 2025 the authority issued an interim ruling finding the Article 27 breach and ordering DeepSeek to appoint a representative in writing and tell the authority it had. DeepSeek did so a week later, notifying the appointment of a Vienna-based representative on 28 May, and the authority closed the investigation on 29 May. No fine at any point. That is the shape most representative enforcement takes: an order, complied with quickly, and no penalty. The ruling also confirms that where a controller is caught by the targeting test alone, each national authority is competent in its own territory, which is why one missing representative can be actioned in several Member States at once. Read the Hellenic DPA decisions register.

7. Tiger Media, Spain, AEPD, €120,000 reduced to €72,000

The one decision that prices the obligation. The AEPD investigated an adult advertising network placing cookies on Spanish users’ devices without consent and fined it on two counts: €50,000 for the Article 27 breach, plus €70,000 for processing without a valid legal basis under Article 6. That €50,000 is the only published figure attached to a representative failure anywhere in this tracker, and it is the number to quote when someone asks what the obligation is actually worth. The company then acknowledged liability and paid promptly, taking two cumulative 20% reductions under Spanish administrative law, which settled the penalty at €72,000. The Article 27 finding turned on placement rather than absence: Tiger Media had appointed a representative, but in Northern Ireland, and the AEPD held that a representative outside the Union does not satisfy Article 27 at all. Post-Brexit that is an easy trap to fall into, and this is what it costs. The authority also ordered the company to appoint a proper EU representative within three months. The decision was not appealed. Read the AEPD decision.

8. Character Technologies, Italy, Garante, €158,000

The most useful case in the tracker, and the most recent. Two Article 27 points came up and they went different ways. The service was offered in Italian from 8 April 2024, but VeraSafe Ireland Ltd was designated only on 31 May 2025, so the designation was late, and the Garante found that breach under Article 27(1). The privacy policy also carried a representative contact link that pointed to an unreachable page. The Garante examined the link and did not treat it as a breach: it accepted that this was a material error, promptly corrected, because the same page still published a physical address and a telephone number for the representative, so contact with the representative was never actually cut off. The separate complaint under Article 27(4) was not upheld. What it did reject was reliance on the Article 27(2) occasional-processing exemption, because the service was localized into Italian and the privacy policy addressed EEA users, which is why the late-designation finding stood. For how you publish, the read is straightforward: regulators do click the contact link, and what protects you when a link breaks is a second contact route on the same page, a real postal address alongside it. The fine followed the late appointment, not the dead link. Read the Garante decision.

Article 27 mentioned but not charged: two adjacent cases

These are not tracker entries, and we do not count them as Article 27 enforcement. They matter because they show the mechanism that actually moves buyers: the pressure arrives through the supply chain, not through a direct regulator action.

  • Sky Italia S.r.l., Garante, 12 September 2024, €842,062. Part of the finding was that Sky acquired marketing data from a non-EU list provider whose privacy notice gave no Article 27 representative contact, and proceeded anyway. An EU buyer was penalized in a case connected to its supplier’s missing representative. Read the Garante decision.
  • Noi Compriamo Auto S.r.l., Garante, 4 June 2025, €45,000. Same shape: a third-party portal’s notice showed neither an EU establishment nor an Article 27 designation, which supported findings on unlawful data handling. Read the Garante decision.

What the pattern actually shows

Only one of the traceable facts here is about the size of a fine, and it is a small one: the AEPD’s €50,000 for the Article 27 breach in Tiger Media. The obligation is real and has a published tariff, even though it is rarely enforced. Regulators now check whether the appointment actually works: in Character.AI the Garante clicked through to a dead representative link and still declined to fine on it, because a physical address and telephone number on the same page kept the representative reachable, and the fine there followed the late appointment instead. A medical device authorized representative does not satisfy Article 27, per Senseonics, and a representative in Northern Ireland does not satisfy it either, per Tiger Media, which is the version of the mistake most likely to be sitting in a privacy notice written before Brexit. And customers and partners ask for the representative’s contact details before regulators do, which is what Sky Italia shows from the buyer’s side.

If you need an Article 27 representative, the point is to have one that is real, published, and reachable, and to publish more than one way to reach it: a working link in your privacy notice and a postal address next to it, so a single broken link is a fixable error rather than a breach. That redundancy is what carried Character.AI on the link point, and late designation is the part that cost it.

FAQ

Frequently asked questions

How many GDPR Article 27 enforcement cases are there?

Eight, across the whole European Economic Area between 2020 and 2026. Two turned on the representative obligation alone: Locatefamily.com, the only standalone fine, and DeepSeek, where the Greek authority ordered an appointment without fining. In the other six it was one finding among several in a case the regulator was already bringing. Only one decision puts a figure on the Article 27 breach: the Spanish AEPD split its Tiger Media penalty into €70,000 for the Article 6 breach and €50,000 for the Article 27 breach.

What is the biggest risk if I do not appoint a representative?

In practice it is rarely the fine. Eight decisions in eight years is a low base rate, and only once has the representative failure carried a fine on its own. It is not quite true that no regulator ever starts there: the Hellenic DPA opened its DeepSeek investigation on its own initiative and Article 27 was the only substantive obligation it resolved, though it ordered an appointment rather than a fine. The real pressure still comes earlier than any of this: a customer security questionnaire, a data processing agreement, or a platform review asks for your Article 27 representative's contact details, and you cannot answer without appointing one. The Sky Italia case shows an EU buyer being fined over a supplier whose notice gave no representative contact.

Does a late appointment fix the problem?

Not for the period before it. In Senseonics the company did appoint a representative, but only after the investigation opened, and the breach was still recorded for the preceding period. In Character.AI the representative was appointed more than a year after the service launched in Italian, and that late designation under Article 27(1) was the Article 27 finding that stuck.

Can a broken representative contact link be a breach on its own?

Not where another contact route still works. In the Character.AI decision the Italian Garante looked at a representative contact link that pointed to an unreachable page, but it did not uphold that complaint under Article 27(4): it accepted the broken link as a material error, promptly corrected, because the same page still published a physical address and a telephone number for the representative. Regulators do check whether the appointment actually works, so the safe setup is more than one contact route: a working link and a postal address next to it. The finding that stuck against Character.AI was the late designation under Article 27(1), not the link.