The Article 27 representative and the Article 37 data protection officer are two different appointments, decided by two different tests, doing two different jobs. Companies conflate them constantly, usually because both roles get described as your privacy contact in Europe.
The short answer: the representative is an address in the Union for a company that has no establishment there, and the DPO is an independent monitor of compliance for any company whose core activities trigger Article 37. Neither test says anything about the other, so run both, and expect that quite often only one of them applies to you.
Engage Compliance takes one of the two roles for a client, never both. Where you need both, we act as your DPO and arrange the representative through a partner entity, so the two stay independent and neither is compromised.
Key takeaways
- Article 27 turns on establishment. Article 37 turns on what your core activities do with personal data. The two are unrelated.
- The representative is an address and a record-holder. The DPO is an independent monitor with reporting protections.
- Needing one says nothing about needing the other, and a large number of companies need exactly one.
- The same provider should not hold both roles for one client, because the representative can be the subject of enforcement the DPO is supposed to monitor.
- Neither role moves accountability off the controller or processor.
- Engage Compliance runs both tests before quoting, then takes whichever role you need and refers the other to a partner.
The short answer
Run the two tests separately and write down both answers.
Article 27 applies where you have no establishment in the EU, you offer goods or services to people in the EU or monitor their behavior there, and your processing is not occasional, low risk, and free of large-scale special category data.
Article 37 applies where you are a public authority, or your core activities are large-scale regular and systematic monitoring, or your core activities involve large-scale special category or criminal conviction data. It applies whether or not you are established in the EU.
Four outcomes are possible and all four are common. Neither. Representative only, which is the classic small non-EU company with EU customers. DPO only, which is the classic EU-established company with an analytics-driven product. Both, which is the non-EU company doing the same thing at scale.
The test, step by step
Step 1: run the Article 27 test
Do you have an establishment in the EU that is involved in this processing? If yes, Article 27 does not apply. If no, do you target or monitor people in the EU? If no, GDPR does not reach you. If yes, does the narrow Article 27(2) exemption cover you on all four of its conditions at once? If not, you have to appoint.
The full working, with the exemptions and the answers companies reach for that do not survive contact with the regulation, is in do I need an EU representative.
Step 2: run the Article 37 test, separately
Are you a public authority or body? Are your core activities large-scale regular and systematic monitoring of data subjects? Do your core activities involve large-scale processing of Article 9 special category data or Article 10 criminal conviction data?
Core activities means the processing that is inseparable from what you sell, not the HR and payroll processing every company does. National law adds triggers in some member states, most notably the German headcount threshold in Section 38 of the Bundesdatenschutzgesetz. The full test is in do I need a DPO.
Step 3: record both answers, with reasons
The answers are worth writing down whichever way they land, because a negative answer is a decision you may have to defend. A short memo naming the test, the facts you applied it to, and the date is the difference between a considered position and an omission.
Where the two roles differ
Purpose. The representative exists so supervisory authorities and data subjects can reach a company that is not in the Union. The DPO exists so the organization has an independent internal check on its own compliance.
Trigger. Absence of an EU establishment plus Article 3(2) reach, against the nature and scale of core activities.
Location. The representative must be established in a member state where the data subjects are, under Article 27(3). The DPO has no residency requirement at all and can sit outside the EU, which surprises people.
Independence. Article 38(2) and 38(3) give the DPO resources, freedom from instruction on how to perform the role, protection from dismissal or penalty for performing it, and a reporting line to the highest level of management. The representative has none of that. It acts on the company’s mandate.
What they hold. Both are tied to the Article 30 record, but differently. The representative maintains and produces the record on the company’s behalf under Article 30(1). The DPO monitors whether the record is accurate and whether the processing it describes is lawful.
Exposure. Recital 80 contemplates the representative being subject to enforcement proceedings in the event of the company’s non-compliance. The DPO is protected from penalty for doing the job.
That last pair is the reason for the separation rule. A single organization holding both is mandated to be addressed on the company’s behalf and exposed to enforcement for the company’s failures, while also being required to monitor those same failures independently and report them upward. The European Data Protection Board has warned about conflicts of this shape, and the cleanest answer is not to create one.
What happens if you get it wrong
Appointing a representative and assuming it covers the DPO obligation. The DPO gap stays open, and the omission shows up when a customer questionnaire asks for the DPO’s name and contact details, or when a supervisory authority reads your privacy notice and finds no Article 13(1)(b) disclosure.
Appointing a DPO and assuming it covers Article 27. Non-appointment is an Article 83(4) infringement, up to €10 million or 2 percent of worldwide annual turnover. It also leaves people in the EU without the contact point the regulation promises them, which is the sort of thing that turns a routine complaint into an inquiry with a wider scope.
Buying both from one provider because it was quoted as a bundle. Nothing goes wrong immediately, which is the problem. It goes wrong at the point where the representative’s exposure and the DPO’s duty to report pull in opposite directions, which is exactly the moment you needed the arrangement to hold.
What to do next
Run both tests, write both answers down, and then appoint what you actually need rather than what a single provider can conveniently supply.
If you need the representative, the Article 27 representative service covers the mandate, the published contact point, and the record, From €59 per month scaling with company size. If you are working out which of the two representative roles you are even looking for, because the phrase authorized representative also means something under product law, EU authorized representative sorts that out.
If you need the DPO, data protection officer services covers the appointment and the Article 39 tasks, From €1,000 per month for DPO Foundation.
If you need both, we take the DPO role and arrange the representative through a partner entity. We tell you which entity holds which mandate in writing, because an arrangement nobody can point at is not really a separation.
Sources and references
- Regulation (EU) 2016/679 (GDPR), Articles 27, 30, 37 to 39, EUR-Lex
- Guidelines on Data Protection Officers (WP243 rev.01), European Data Protection Board