Glossary | GDPR & Data Privacy
GDPR Article 27 Representative
What is a GDPR Article 27 Representative?
A GDPR Article 27 Representative is a natural or legal person established within the European Union who is formally appointed by a non-EU organisation to act as its point of contact for data protection obligations under Regulation (EU) 2016/679 (GDPR). The requirement is set out in Article 27 of the GDPR and applies to organisations outside the EU that are nonetheless subject to the regulation.
Why It Matters
The GDPR applies to organisations outside the EU that offer goods or services to EU residents or monitor their behaviour. Where no EU establishment exists, Article 27 requires that a representative be designated within the EU to ensure supervisory authorities and data subjects have an accessible point of contact.
Without a designated Article 27 Representative where required, an organisation may be in breach of the GDPR, exposing it to enforcement action by supervisory authorities, including significant fines. Supervisory authorities may also treat the absence of a representative as an aggravating factor in any investigation.
For non-EU businesses handling the personal data of EU residents, appointing an Article 27 Representative is a fundamental compliance obligation.

Key Requirements
Who Needs a GDPR Article 27 Representative?
An Article 27 Representative is required when:
- The organisation is established outside the EU, and
- The organisation offers goods or services to individuals in the EU, or monitors the behaviour of individuals in the EU.
This requirement applies under:
- Regulation (EU) 2016/679 – General Data Protection Regulation (GDPR), Article 27
Certain exemptions apply, including for organisations that process personal data only occasionally, at low risk, and not on a large scale. However, these exemptions are narrow and should be assessed carefully.
Responsibilities of a GDPR Article 27 Representative
While the Article 27 Representative does not carry the same legal liability as the organisation itself, their responsibilities commonly include:
- Acting as the primary point of contact for supervisory authorities in the EU
- Acting as a contact point for data subjects exercising their rights under the GDPR
- Maintaining a copy of or access to the organisation’s records of processing activities
- Facilitating communication between the organisation and EU supervisory authorities
- Being available to supervisory authorities and data subjects in the relevant EU member states
Article 27 Representative vs. Data Protection Officer
These are distinct roles with different obligations. An Article 27 Representative is an external contact point required specifically for non-EU organisations subject to the GDPR. A Data Protection Officer (DPO) is an internal or external role focused on advising on and monitoring data protection compliance within an organisation.
In some cases, the same entity may fulfil both roles, but this must be carefully assessed to avoid conflicts of interest and to ensure both sets of obligations are met independently.
Frequently Asked Questions
Not always. The requirement applies to non-EU organisations subject to the GDPR that do not benefit from a specific exemption. Organisations that process EU personal data only occasionally, at low risk, and not on a large scale may be exempt, but this should be assessed on a case-by-case basis.
The representative acts on behalf of the organisation but does not assume the organisation’s legal liability under the GDPR. However, supervisory authorities may contact and take action through the representative when engaging with a non-EU organisation.
No. These are separate roles under separate regulatory frameworks. The Article 27 Representative is a data protection role under the GDPR, while an EU Authorised Representative under the GPSR relates to product safety compliance. Businesses with obligations under both frameworks will need to address each requirement separately.
Need GDPR Representative Services?
Euverify provides EU Representative services for organisations outside the European Union that are subject to the GDPR. Our team supports regulatory communication, documentation, and ongoing compliance management.
Related Terms
Further Reading