Every case below is one where a data protection authority actually found a failure to appoint or properly maintain a representative under GDPR Article 27. Engage Compliance compiled it against the authority decisions and press releases, and every row links to the deciding authority. Vendor and law firm write-ups were used to locate cases, never as the source for one.
The honest headline is the useful one: eight decisions in eight years across the whole EEA, two turned on the representative failure alone, and only one puts a figure on it. That is a finding, not a gap in our research. It means the reason to appoint a representative is not the size of a rare fine. It is that the obligation is real and easy to check, that regulators now police whether the appointment actually works, and that customers and partners ask for the representative’s details long before any regulator does.
The register: eight decisions
| # | Case | Authority | Decided | Fine | Article 27 finding |
|---|---|---|---|---|---|
| 1 | Locatefamily.com | Netherlands, Autoriteit Persoonsgegevens | 12 May 2021 | €525,000 | The only case where the representative failure is the sole sanctioned finding |
| 2 | Clearview AI, Inc. | Italy, Garante | 9 March 2022 | €20,000,000 | One of eight findings; no part of the fine attributed to Article 27 |
| 3 | Senseonics, Inc. | Italy, Garante | 7 July 2022 | €45,000 | Late appointment still a breach; a medical device representative does not satisfy Article 27 |
| 4 | Clearview AI, Inc. | Greece, Hellenic DPA | 13 July 2022 | €20,000,000 | Explicit Article 3(2)(b) reasoning; obliged to appoint and did not |
| 5 | Clearview AI, Inc. | Netherlands, Autoriteit Persoonsgegevens | 3 September 2024 | €30,500,000 | Article 27 one of several findings; no allocation to it |
| 6 | Hangzhou DeepSeek Artificial Intelligence Co. | Greece, Hellenic DPA | 21 May 2025 | none | Article 27 the only substantive finding; interim ruling ordering an appointment, complied with in a week |
| 7 | Tiger Media Inc. | Spain, AEPD | 14 November 2025 | €120,000, reduced to €72,000 | The only decision that puts a figure on Article 27: €50,000 of the penalty |
| 8 | Character Technologies, Inc. | Italy, Garante | 3 July 2026 | €158,000 | Article 27(1) late designation upheld; the unreachable-link complaint under 27(4) not upheld, contact still worked via a published address and phone |
1. Locatefamily.com, Dutch DPA, €525,000
The one case of its kind. The Dutch DPA fined Locatefamily.com €525,000 under Article 27(1) read with Article 3(2), and this is the only decision where the representative failure is the sole sanctioned finding. The authority placed it in Category III of its 2019 penalty policy, band €300,000 to €750,000, and applied the base amount with no adjustment. It also ordered the company to appoint in writing within 12 weeks or pay €20,000 per fortnight, capped at €120,000. The reasoning is the quotable part: the DPA framed practical reachability of a non-EU controller, by both data subjects and the authority, as fundamental to protecting rights. The company was contactable only at a Canadian address. Read the Dutch DPA decision.
2. Clearview AI, Italy, Garante, €20,000,000
A single undifferentiated fine covering eight findings under Articles 5, 6, 9, 12 to 15 and 27. The Garante also ordered Clearview to designate an EU representative. No part of the fine is attributed to Article 27, so the widely repeated “€600,000 Article 27 component” figure is wrong: it does not exist in the decision. Read the Garante decision.
3. Senseonics, Italy, Garante, €45,000
Two commercially useful holdings. First, the Garante rejected the argument that a medical device EU authorized representative satisfies Article 27, holding that a specific GDPR designation is separately required. Second, Senseonics did appoint a representative, on 29 June 2021, after the investigation opened, and the breach was still recorded for the preceding period. Late is still a breach. Read the Garante decision.
4. Clearview AI, Greece, Hellenic DPA, €20,000,000
The Article 27 reasoning here is explicit. The Hellenic DPA found Clearview falls within Article 3(2)(b), has no EU establishment, is obliged to appoint a representative, and did not. The fine is stated as a total with no allocation per violation. Read the Hellenic DPA decision.
5. Clearview AI, Netherlands, Dutch DPA, €30,500,000
Findings under Articles 6, 9, 12, 14, 15 and 27, plus orders with penalty payments up to €5,100,000. No allocation to Article 27. The Dutch DPA later began examining director liability, because Clearview had paid none of the fines levied against it across the EU, which is the deeper problem with enforcing this obligation against exactly the population it targets. Read the Dutch DPA decision.
6. DeepSeek, Greece, Hellenic DPA, no fine
The case that shows a regulator starting from Article 27 rather than arriving at it, and the one that shows what usually happens next. The Hellenic DPA opened an investigation on its own initiative in February 2025 into Hangzhou DeepSeek Artificial Intelligence Co., the Chinese company behind the DeepSeek assistant, and told it that it fell inside the GDPR on the targeting test in Article 3(2) and owed a written representative designation. DeepSeek denied offering services in the EU at all. The authority disagreed, and its reasoning is the part worth borrowing: the service was reachable in Greece over the web and through mobile apps, and the apps were published in Greek, so it was targeting people in the EU whatever the company said about its intentions. On 21 May 2025 the authority issued an interim ruling finding the Article 27 breach and ordering DeepSeek to appoint a representative in writing and tell the authority it had. DeepSeek did so a week later, notifying the appointment of a Vienna-based representative on 28 May, and the authority closed the investigation on 29 May. No fine at any point. That is the shape most representative enforcement takes: an order, complied with quickly, and no penalty. The ruling also confirms that where a controller is caught by the targeting test alone, each national authority is competent in its own territory, which is why one missing representative can be actioned in several Member States at once. Read the Hellenic DPA decisions register.
7. Tiger Media, Spain, AEPD, €120,000 reduced to €72,000
The one decision that prices the obligation. The AEPD investigated an adult advertising network placing cookies on Spanish users’ devices without consent and fined it on two counts: €50,000 for the Article 27 breach, plus €70,000 for processing without a valid legal basis under Article 6. That €50,000 is the only published figure attached to a representative failure anywhere in this tracker, and it is the number to quote when someone asks what the obligation is actually worth. The company then acknowledged liability and paid promptly, taking two cumulative 20% reductions under Spanish administrative law, which settled the penalty at €72,000. The Article 27 finding turned on placement rather than absence: Tiger Media had appointed a representative, but in Northern Ireland, and the AEPD held that a representative outside the Union does not satisfy Article 27 at all. Post-Brexit that is an easy trap to fall into, and this is what it costs. The authority also ordered the company to appoint a proper EU representative within three months. The decision was not appealed. Read the AEPD decision.
8. Character Technologies, Italy, Garante, €158,000
The most useful case in the tracker, and the most recent. Two Article 27 points came up and they went different ways. The service was offered in Italian from 8 April 2024, but VeraSafe Ireland Ltd was designated only on 31 May 2025, so the designation was late, and the Garante found that breach under Article 27(1). The privacy policy also carried a representative contact link that pointed to an unreachable page. The Garante examined the link and did not treat it as a breach: it accepted that this was a material error, promptly corrected, because the same page still published a physical address and a telephone number for the representative, so contact with the representative was never actually cut off. The separate complaint under Article 27(4) was not upheld. What it did reject was reliance on the Article 27(2) occasional-processing exemption, because the service was localized into Italian and the privacy policy addressed EEA users, which is why the late-designation finding stood. For how you publish, the read is straightforward: regulators do click the contact link, and what protects you when a link breaks is a second contact route on the same page, a real postal address alongside it. The fine followed the late appointment, not the dead link. Read the Garante decision.
Article 27 mentioned but not charged: two adjacent cases
These are not tracker entries, and we do not count them as Article 27 enforcement. They matter because they show the mechanism that actually moves buyers: the pressure arrives through the supply chain, not through a direct regulator action.
- Sky Italia S.r.l., Garante, 12 September 2024, €842,062. Part of the finding was that Sky acquired marketing data from a non-EU list provider whose privacy notice gave no Article 27 representative contact, and proceeded anyway. An EU buyer was penalized in a case connected to its supplier’s missing representative. Read the Garante decision.
- Noi Compriamo Auto S.r.l., Garante, 4 June 2025, €45,000. Same shape: a third-party portal’s notice showed neither an EU establishment nor an Article 27 designation, which supported findings on unlawful data handling. Read the Garante decision.
What the pattern actually shows
Only one of the traceable facts here is about the size of a fine, and it is a small one: the AEPD’s €50,000 for the Article 27 breach in Tiger Media. The obligation is real and has a published tariff, even though it is rarely enforced. Regulators now check whether the appointment actually works: in Character.AI the Garante clicked through to a dead representative link and still declined to fine on it, because a physical address and telephone number on the same page kept the representative reachable, and the fine there followed the late appointment instead. A medical device authorized representative does not satisfy Article 27, per Senseonics, and a representative in Northern Ireland does not satisfy it either, per Tiger Media, which is the version of the mistake most likely to be sitting in a privacy notice written before Brexit. And customers and partners ask for the representative’s contact details before regulators do, which is what Sky Italia shows from the buyer’s side.
If you need an Article 27 representative, the point is to have one that is real, published, and reachable, and to publish more than one way to reach it: a working link in your privacy notice and a postal address next to it, so a single broken link is a fixable error rather than a breach. That redundancy is what carried Character.AI on the link point, and late designation is the part that cost it.