The Article 27 representative and the Article 37 data protection officer are two different appointments, decided by two different tests, doing two different jobs. Companies conflate them constantly, usually because both roles get described as your privacy contact in Europe.

The short answer: the representative is an address in the Union for a company that has no establishment there, and the DPO is an independent monitor of compliance for any company whose core activities trigger Article 37. Neither test says anything about the other, so run both, and expect that quite often only one of them applies to you.

Engage Compliance takes one of the two roles for a client, never both. Where you need both, we act as your DPO and arrange the representative through a partner entity, so the two stay independent and neither is compromised.

Key takeaways

  • Article 27 turns on establishment. Article 37 turns on what your core activities do with personal data. The two are unrelated.
  • The representative is an address and a record-holder. The DPO is an independent monitor with reporting protections.
  • Needing one says nothing about needing the other, and a large number of companies need exactly one.
  • The same provider should not hold both roles for one client, because the representative can be the subject of enforcement the DPO is supposed to monitor.
  • Neither role moves accountability off the controller or processor.
  • Engage Compliance runs both tests before quoting, then takes whichever role you need and refers the other to a partner.

The short answer

Run the two tests separately and write down both answers.

Article 27 applies where you have no establishment in the EU, you offer goods or services to people in the EU or monitor their behavior there, and your processing is not occasional, low risk, and free of large-scale special category data.

Article 37 applies where you are a public authority, or your core activities are large-scale regular and systematic monitoring, or your core activities involve large-scale special category or criminal conviction data. It applies whether or not you are established in the EU.

Four outcomes are possible and all four are common. Neither. Representative only, which is the classic small non-EU company with EU customers. DPO only, which is the classic EU-established company with an analytics-driven product. Both, which is the non-EU company doing the same thing at scale.

The test, step by step

Step 1: run the Article 27 test

Do you have an establishment in the EU that is involved in this processing? If yes, Article 27 does not apply. If no, do you target or monitor people in the EU? If no, GDPR does not reach you. If yes, does the narrow Article 27(2) exemption cover you on all four of its conditions at once? If not, you have to appoint.

The full working, with the exemptions and the answers companies reach for that do not survive contact with the regulation, is in do I need an EU representative.

Step 2: run the Article 37 test, separately

Are you a public authority or body? Are your core activities large-scale regular and systematic monitoring of data subjects? Do your core activities involve large-scale processing of Article 9 special category data or Article 10 criminal conviction data?

Core activities means the processing that is inseparable from what you sell, not the HR and payroll processing every company does. National law adds triggers in some member states, most notably the German headcount threshold in Section 38 of the Bundesdatenschutzgesetz. The full test is in do I need a DPO.

Step 3: record both answers, with reasons

The answers are worth writing down whichever way they land, because a negative answer is a decision you may have to defend. A short memo naming the test, the facts you applied it to, and the date is the difference between a considered position and an omission.

Where the two roles differ

Purpose. The representative exists so supervisory authorities and data subjects can reach a company that is not in the Union. The DPO exists so the organization has an independent internal check on its own compliance.

Trigger. Absence of an EU establishment plus Article 3(2) reach, against the nature and scale of core activities.

Location. The representative must be established in a member state where the data subjects are, under Article 27(3). The DPO has no residency requirement at all and can sit outside the EU, which surprises people.

Independence. Article 38(2) and 38(3) give the DPO resources, freedom from instruction on how to perform the role, protection from dismissal or penalty for performing it, and a reporting line to the highest level of management. The representative has none of that. It acts on the company’s mandate.

What they hold. Both are tied to the Article 30 record, but differently. The representative maintains and produces the record on the company’s behalf under Article 30(1). The DPO monitors whether the record is accurate and whether the processing it describes is lawful.

Exposure. Recital 80 contemplates the representative being subject to enforcement proceedings in the event of the company’s non-compliance. The DPO is protected from penalty for doing the job.

That last pair is the reason for the separation rule. A single organization holding both is mandated to be addressed on the company’s behalf and exposed to enforcement for the company’s failures, while also being required to monitor those same failures independently and report them upward. The European Data Protection Board has warned about conflicts of this shape, and the cleanest answer is not to create one.

What happens if you get it wrong

Appointing a representative and assuming it covers the DPO obligation. The DPO gap stays open, and the omission shows up when a customer questionnaire asks for the DPO’s name and contact details, or when a supervisory authority reads your privacy notice and finds no Article 13(1)(b) disclosure.

Appointing a DPO and assuming it covers Article 27. Non-appointment is an Article 83(4) infringement, up to €10 million or 2 percent of worldwide annual turnover. It also leaves people in the EU without the contact point the regulation promises them, which is the sort of thing that turns a routine complaint into an inquiry with a wider scope.

Buying both from one provider because it was quoted as a bundle. Nothing goes wrong immediately, which is the problem. It goes wrong at the point where the representative’s exposure and the DPO’s duty to report pull in opposite directions, which is exactly the moment you needed the arrangement to hold.

What to do next

Run both tests, write both answers down, and then appoint what you actually need rather than what a single provider can conveniently supply.

If you need the representative, the Article 27 representative service covers the mandate, the published contact point, and the record, From €59 per month scaling with company size. If you are working out which of the two representative roles you are even looking for, because the phrase authorized representative also means something under product law, EU authorized representative sorts that out.

If you need the DPO, data protection officer services covers the appointment and the Article 39 tasks, From €1,000 per month for DPO Foundation.

If you need both, we take the DPO role and arrange the representative through a partner entity. We tell you which entity holds which mandate in writing, because an arrangement nobody can point at is not really a separation.

Sources and references

FAQ

Frequently asked questions

Is an EU representative the same as a DPO?

No. The Article 27 representative is a contact point in the Union for a company established outside it, so that supervisory authorities and data subjects have someone to address. The Article 37 DPO monitors the organization's compliance with GDPR and advises on it, wherever the organization is established. The tests are different, the duties are different, and the two are frequently needed at the same time.

Can our DPO also be our EU representative?

We do not do it, and we recommend against it. The representative can be addressed by supervisory authorities on the company's behalf and can be subject to enforcement proceedings for the company's non-compliance. The DPO's job is to monitor that same company's compliance independently and report to its highest management. Putting both in one organization asks it to supervise something it is also answerable for.

If we appoint a DPO, do we still need a representative?

Yes, if Article 27 applies to you. Appointing a DPO does not create an EU establishment and does not satisfy Article 27, even where the DPO is based in the EU. The DPO is your adviser; the representative is your address in the Union.

If we appoint a representative, do we still need a DPO?

Only if Article 37 applies to you, which is a completely separate question about your core activities. Many companies caught by Article 27 have no DPO obligation at all, and many companies with a DPO obligation have an EU establishment and so no Article 27 obligation. There is no correlation between the two tests.

Can a company need both?

Yes, and it is a common combination: a US SaaS company with no EU entity, running product analytics on EU users at scale. Article 27 applies because there is no establishment and the company targets and monitors people in the EU. Article 37 applies because large-scale regular and systematic monitoring is a core activity.

Does either role take on our liability?

Neither one moves accountability off the controller or processor. The representative can face enforcement proceedings in the event of the company's non-compliance, under Recital 80. The DPO is expressly protected from being penalized for performing the role, under Article 38(3), which only works because the organization stays responsible. Any provider offering either role as a liability transfer is describing something GDPR does not do.

Which do we appoint first?

Whichever one you are legally required to hold, and if both, the representative usually lands first because it is a fixed, small piece of work with a filing at the end, while the DPO appointment starts a program. In practice they run in parallel and the sequencing only matters when a customer questionnaire has a deadline attached.