GDPR Article 27 requires most companies established outside the EU that target or monitor people inside it to appoint a representative in the Union. This guide runs the applicability test and its exemptions end to end, so you can decide without booking a call.
The short answer: if your company has no establishment in the EU, and you either offer goods or services to people in the EU or monitor their behavior there, you have to appoint an EU representative unless your processing is occasional, low risk, and free of special category data. The exemption is narrow and most companies that reach for it do not qualify.
Engage Compliance provides the Article 27 EU representative role for companies outside the Union, with a mandate in writing, a published contact point, and the Article 30 record held and made available to supervisory authorities on request.
Key takeaways
- Article 27 applies only where the company has no establishment in the EU. One genuine EU establishment involved in the processing takes you out of Article 27 and into Article 3(1).
- The trigger is Article 3(2): offering goods or services to people in the EU, or monitoring their behavior in the EU.
- The exemption in Article 27(2) requires occasional processing, no large-scale special category data, no criminal conviction data, and low risk to rights and freedoms. All four conditions have to hold at once.
- The representative must be established in a member state where your data subjects are, and mandated in writing.
- Non-appointment sits in the lower penalty tier, up to €10 million or 2 percent of worldwide annual turnover.
- Engage Compliance acts as the Article 27 representative for companies the test catches, and says so plainly where the test does not catch you.
The short answer
Three questions decide it, in order. Answer them honestly rather than optimistically, because the person who checks your answer later will be a supervisory authority reading your privacy notice.
- Do you have an establishment in the EU that is involved in this processing? If yes, stop. Article 27 does not apply to you and Article 3(1) does.
- Do you offer goods or services to people in the EU, or monitor their behavior in the EU? If no, stop. GDPR does not reach you at all and neither does Article 27.
- Does the Article 27(2) exemption cover your processing on all four of its conditions? If yes, you may skip the appointment. If any one condition fails, you have to appoint.
Everything below is the working behind those three.
The test, step by step
Step 1: do you have an EU establishment?
Article 27(1) opens with the words “where Article 3(2) applies”, and Article 3(2) only reaches controllers and processors “not established in the Union”. So establishment is the gate.
Establishment is a functional test rather than a legal-entity test. The Court of Justice has read it as any real and effective activity through stable arrangements, and a single representative with an office and a bank account has been enough in past cases. What matters for Article 27 is whether the establishment is involved in the processing in question. A sales office in Dublin that signs EU customers is involved. A dormant Luxembourg holding company that exists for tax reasons is not, and it will not carry your Article 27 obligation.
Companies get this wrong in both directions. Some assume an EU entity of any kind exempts them, and it does not. Others assume a remote contractor in Berlin creates an establishment, and it usually does not either.
Step 2: are you targeting or monitoring people in the EU?
Article 3(2)(a) covers offering goods or services, irrespective of whether payment is required. Recital 23 says mere accessibility of a website is not enough, and that the question is whether it is apparent the controller envisages offering services to data subjects in the Union. The factors that show intent are concrete:
- Pricing in euros or another member state currency.
- Language versions of a member state language, where that is not your home language.
- A country selector, EU shipping options, or an EU tax registration.
- Marketing spend directed at EU audiences, including paid search targeting.
- Mentions of EU customers or EU country names in your own materials.
- An EU top-level domain.
Article 3(2)(b) covers monitoring behavior that takes place in the EU. Recital 24 points at tracking on the internet, including profiling to predict preferences, behavior, and attitudes. That reaches ordinary analytics and advertising technology far more often than companies expect. Session recording, cross-site advertising pixels, device fingerprinting, product analytics that follow an identified user, fraud scoring on EU traffic, and location tracking all count.
Free products are inside the test. So is a beta. Payment is irrelevant to Article 3(2)(a) by its own words.
Step 3: does the exemption apply?
Article 27(2) is the only way out for a company that has cleared steps one and two, and it is drawn narrowly. It exempts processing that is:
- Occasional, and
- does not include, on a large scale, processing of special categories of data under Article 9, and
- does not include processing of criminal conviction and offense data under Article 10, and
- is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account the nature, context, scope, and purposes of the processing.
All four have to hold. The word doing the work is “occasional”. The European Data Protection Board reads occasional as processing that is not carried out regularly and happens outside the ordinary course of business. Any processing that is part of how the product functions is not occasional, however small the volume. A SaaS product with forty EU users processes their data every day, which is regular by definition, so the exemption is unavailable no matter how modest the number looks.
There is a separate exemption in Article 27(2)(b) for public authorities and bodies, which does not help a commercial company.
The exemptions, and what people get wrong about them
“We are too small.” There is no size threshold anywhere in Article 27. A two-person company with EU users is inside it and a thousand-person company with none is outside it.
“We only process business contact data.” Names, work emails, and job titles are personal data under Article 4(1). B2B does not create an exemption; it usually just lowers the risk, which is only one of the four conditions.
“Our processor is in the EU.” Using an EU cloud region or an EU-based subprocessor does not give you an establishment and does not transfer your obligation. Your processor may have its own Article 27 duty, separately from yours.
“We are covered by the Data Privacy Framework.” The framework is a transfer mechanism for moving data out of the EU. It says nothing about Article 27 and does not substitute for the appointment.
“We appointed our law firm.” That can work, provided the firm is established in a member state where your data subjects are and accepts the written mandate to be addressed by authorities and data subjects. Many firms will not accept that mandate, and an appointment nobody has agreed to in writing is not an appointment.
What happens if you get it wrong
Non-appointment is an Article 83(4) infringement, the lower of the two tiers, capped at €10 million or 2 percent of worldwide annual turnover, whichever is higher.
The realistic path to a penalty is rarely a proactive sweep. It is a data subject who cannot find anyone to contact, complains to their national authority, and the authority opens on the complaint and notices the missing appointment on the way through. At that point the omission is doing double damage: it is an infringement of its own, and it is evidence in an aggravating direction on whatever the original complaint was about.
There is a second cost that shows up sooner. Enterprise procurement questionnaires and investor diligence checklists both ask the Article 27 question directly, and “not applicable” is an answer a buyer’s counsel will test.
What to do next
If you cleared step one, you have nothing to do here. If you failed the exemption at step three, the appointment is a small, fixed piece of work: pick a member state where your data subjects are, mandate a representative in writing, publish the representative’s identity and contact details in your privacy notice as Articles 13 and 14 require, and make sure the representative holds a copy of your Article 30 record.
Our Article 27 representative service covers all of that, From €59 per month, scaling with company size. Companies working through the wider question of what EU entry requires should start with US to EU privacy compliance, and companies that also need to answer the DPO question should run the Article 37 test separately, because clearing one says nothing about the other.
One thing worth naming rather than discovering later: the European Data Protection Board takes the position that the same organization should not hold both the Article 27 representative role and the DPO role for one client, because the representative can be the subject of enforcement the DPO is supposed to monitor. Where we act as your DPO we arrange the representative through a partner entity, so the two stay independent. That trade-off is set out in full on EU representative vs DPO.
Sources and references
- Regulation (EU) 2016/679 (GDPR), Articles 3 and 27, EUR-Lex
- Guidelines, recommendations and best practices, European Data Protection Board, including Guidelines 3/2018 on the territorial scope of the GDPR