GDPR Article 27 requires most companies established outside the EU that target or monitor people inside it to appoint a representative in the Union. This guide runs the applicability test and its exemptions end to end, so you can decide without booking a call.

The short answer: if your company has no establishment in the EU, and you either offer goods or services to people in the EU or monitor their behavior there, you have to appoint an EU representative unless your processing is occasional, low risk, and free of special category data. The exemption is narrow and most companies that reach for it do not qualify.

Engage Compliance provides the Article 27 EU representative role for companies outside the Union, with a mandate in writing, a published contact point, and the Article 30 record held and made available to supervisory authorities on request.

Key takeaways

  • Article 27 applies only where the company has no establishment in the EU. One genuine EU establishment involved in the processing takes you out of Article 27 and into Article 3(1).
  • The trigger is Article 3(2): offering goods or services to people in the EU, or monitoring their behavior in the EU.
  • The exemption in Article 27(2) requires occasional processing, no large-scale special category data, no criminal conviction data, and low risk to rights and freedoms. All four conditions have to hold at once.
  • The representative must be established in a member state where your data subjects are, and mandated in writing.
  • Non-appointment sits in the lower penalty tier, up to €10 million or 2 percent of worldwide annual turnover.
  • Engage Compliance acts as the Article 27 representative for companies the test catches, and says so plainly where the test does not catch you.

The short answer

Three questions decide it, in order. Answer them honestly rather than optimistically, because the person who checks your answer later will be a supervisory authority reading your privacy notice.

  1. Do you have an establishment in the EU that is involved in this processing? If yes, stop. Article 27 does not apply to you and Article 3(1) does.
  2. Do you offer goods or services to people in the EU, or monitor their behavior in the EU? If no, stop. GDPR does not reach you at all and neither does Article 27.
  3. Does the Article 27(2) exemption cover your processing on all four of its conditions? If yes, you may skip the appointment. If any one condition fails, you have to appoint.

Everything below is the working behind those three.

The test, step by step

Step 1: do you have an EU establishment?

Article 27(1) opens with the words “where Article 3(2) applies”, and Article 3(2) only reaches controllers and processors “not established in the Union”. So establishment is the gate.

Establishment is a functional test rather than a legal-entity test. The Court of Justice has read it as any real and effective activity through stable arrangements, and a single representative with an office and a bank account has been enough in past cases. What matters for Article 27 is whether the establishment is involved in the processing in question. A sales office in Dublin that signs EU customers is involved. A dormant Luxembourg holding company that exists for tax reasons is not, and it will not carry your Article 27 obligation.

Companies get this wrong in both directions. Some assume an EU entity of any kind exempts them, and it does not. Others assume a remote contractor in Berlin creates an establishment, and it usually does not either.

Step 2: are you targeting or monitoring people in the EU?

Article 3(2)(a) covers offering goods or services, irrespective of whether payment is required. Recital 23 says mere accessibility of a website is not enough, and that the question is whether it is apparent the controller envisages offering services to data subjects in the Union. The factors that show intent are concrete:

  • Pricing in euros or another member state currency.
  • Language versions of a member state language, where that is not your home language.
  • A country selector, EU shipping options, or an EU tax registration.
  • Marketing spend directed at EU audiences, including paid search targeting.
  • Mentions of EU customers or EU country names in your own materials.
  • An EU top-level domain.

Article 3(2)(b) covers monitoring behavior that takes place in the EU. Recital 24 points at tracking on the internet, including profiling to predict preferences, behavior, and attitudes. That reaches ordinary analytics and advertising technology far more often than companies expect. Session recording, cross-site advertising pixels, device fingerprinting, product analytics that follow an identified user, fraud scoring on EU traffic, and location tracking all count.

Free products are inside the test. So is a beta. Payment is irrelevant to Article 3(2)(a) by its own words.

Step 3: does the exemption apply?

Article 27(2) is the only way out for a company that has cleared steps one and two, and it is drawn narrowly. It exempts processing that is:

  • Occasional, and
  • does not include, on a large scale, processing of special categories of data under Article 9, and
  • does not include processing of criminal conviction and offense data under Article 10, and
  • is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account the nature, context, scope, and purposes of the processing.

All four have to hold. The word doing the work is “occasional”. The European Data Protection Board reads occasional as processing that is not carried out regularly and happens outside the ordinary course of business. Any processing that is part of how the product functions is not occasional, however small the volume. A SaaS product with forty EU users processes their data every day, which is regular by definition, so the exemption is unavailable no matter how modest the number looks.

There is a separate exemption in Article 27(2)(b) for public authorities and bodies, which does not help a commercial company.

The exemptions, and what people get wrong about them

“We are too small.” There is no size threshold anywhere in Article 27. A two-person company with EU users is inside it and a thousand-person company with none is outside it.

“We only process business contact data.” Names, work emails, and job titles are personal data under Article 4(1). B2B does not create an exemption; it usually just lowers the risk, which is only one of the four conditions.

“Our processor is in the EU.” Using an EU cloud region or an EU-based subprocessor does not give you an establishment and does not transfer your obligation. Your processor may have its own Article 27 duty, separately from yours.

“We are covered by the Data Privacy Framework.” The framework is a transfer mechanism for moving data out of the EU. It says nothing about Article 27 and does not substitute for the appointment.

“We appointed our law firm.” That can work, provided the firm is established in a member state where your data subjects are and accepts the written mandate to be addressed by authorities and data subjects. Many firms will not accept that mandate, and an appointment nobody has agreed to in writing is not an appointment.

What happens if you get it wrong

Non-appointment is an Article 83(4) infringement, the lower of the two tiers, capped at €10 million or 2 percent of worldwide annual turnover, whichever is higher.

The realistic path to a penalty is rarely a proactive sweep. It is a data subject who cannot find anyone to contact, complains to their national authority, and the authority opens on the complaint and notices the missing appointment on the way through. At that point the omission is doing double damage: it is an infringement of its own, and it is evidence in an aggravating direction on whatever the original complaint was about.

There is a second cost that shows up sooner. Enterprise procurement questionnaires and investor diligence checklists both ask the Article 27 question directly, and “not applicable” is an answer a buyer’s counsel will test.

What to do next

If you cleared step one, you have nothing to do here. If you failed the exemption at step three, the appointment is a small, fixed piece of work: pick a member state where your data subjects are, mandate a representative in writing, publish the representative’s identity and contact details in your privacy notice as Articles 13 and 14 require, and make sure the representative holds a copy of your Article 30 record.

Our Article 27 representative service covers all of that, From €59 per month, scaling with company size. Companies working through the wider question of what EU entry requires should start with US to EU privacy compliance, and companies that also need to answer the DPO question should run the Article 37 test separately, because clearing one says nothing about the other.

One thing worth naming rather than discovering later: the European Data Protection Board takes the position that the same organization should not hold both the Article 27 representative role and the DPO role for one client, because the representative can be the subject of enforcement the DPO is supposed to monitor. Where we act as your DPO we arrange the representative through a partner entity, so the two stay independent. That trade-off is set out in full on EU representative vs DPO.

Sources and references

FAQ

Frequently asked questions

Do I need an EU representative if I only have a website?

It depends on whether the website targets people in the EU rather than merely being reachable from there. A site in English, priced in dollars, shipping only within the US, is not targeting the EU even if Europeans can load it. A site that offers euro pricing, names EU countries at checkout, runs ads to EU audiences, or translates into an EU language is targeting, and Article 27 then applies unless an exemption does.

Does an EU representative have to be a lawyer?

No. Article 27 requires an establishment in a member state where the affected data subjects are, mandated in writing to be addressed by supervisory authorities and data subjects. There is no qualification requirement in the text. What matters is that the representative is genuinely reachable, keeps the Article 30 record available, and can respond in the relevant language.

Can our EU subsidiary be our EU representative?

If you have an establishment in the EU that is involved in the processing, Article 3(1) usually applies to you directly and Article 27 does not, because the representative requirement only bites where the controller or processor has no Union establishment. A dormant holding entity with no role in the processing does not remove the requirement, so the answer turns on what the subsidiary actually does.

Does a UK company need an EU representative after Brexit?

Yes, where it targets or monitors people in the EU and has no EU establishment. The UK is a third country for GDPR purposes, so a UK company selling into the EU is in exactly the position Article 27 was written for. The mirror also holds: an EU company targeting the UK needs a UK representative under UK GDPR Article 27.

What is the penalty for not appointing one?

Failure to appoint falls under Article 83(4), the lower tier, capped at €10 million or 2 percent of worldwide annual turnover, whichever is higher. In practice the bigger exposure is that the omission surfaces during an unrelated investigation or a data subject complaint, and it tells the authority that the basics were not covered.

Do we need both an EU representative and a DPO?

They are separate requirements with separate tests, and plenty of companies need both. Article 27 is about having a contactable presence in the Union; Article 37 is about monitoring compliance. One does not satisfy the other, and the roles should not sit with the same provider, which is the position the European Data Protection Board takes on the conflict between them.

Which member state should the representative be in?

Article 27(3) says the representative must be established in one of the member states where the data subjects are. Where you serve several, you choose among them, and most companies pick the one carrying the largest share of their EU users or the one whose authority they would rather deal with. The choice does not create a lead supervisory authority; Article 27 explicitly leaves you answerable to every authority whose data subjects are affected.