Guide

EU Representative vs DPO: What Is the Difference?

Reviewed by our CNIL-designated DPO · 8 min read · Updated June 2026

The EU Representative and the Data Protection Officer are two of the most commonly confused roles under the GDPR, partly because both involve a named contact and both touch data protection compliance. But they answer different legal questions, are governed by different articles, and are triggered by different facts. The Article 27 representative is about your physical presence in the EU when you are based outside it; the Article 37-39 DPO is about the nature and scale of your data processing, wherever you are located. This guide sets out exactly what each role is, who needs which, whether the same firm can hold both, and when you need both at once.

Two roles, two articles: what each one actually is

The two functions sit in different parts of the GDPR and exist for different reasons.

  • EU Representative (Article 27). A natural or legal person established in the EU or EEA, designated in writing by a controller or processor based outside the Union. It acts as the local point of contact for supervisory authorities and data subjects, and is mandated to be addressed in addition to (or instead of) the company on all compliance matters. It also helps maintain the Article 30 record of processing.
  • Data Protection Officer (Articles 37-39). An expert who advises the organisation on its GDPR obligations, monitors internal compliance, and serves as the contact point with supervisory authorities and the EDPB.

The representative is about where you are; the DPO is about what you process.

Who needs which — and when you need both

The triggers are separate, so test each one independently.

QuestionEU RepresentativeDPO
Governing articleArticle 27Articles 37-39
What triggers itNo EU/EEA establishment and you target or monitor people in the EUPublic authority; large-scale regular & systematic monitoring; or large-scale special-category data
Core functionLocal contact & mailbox for authorities and individualsIndependent advisor & compliance monitor
IndependenceActs on the company's instructionsMust act independently; no instructions on tasks

A US or Canadian SaaS targeting the EU usually needs a representative. If it also profiles users at scale, it needs both. The obligations are cumulative.

Can the same firm be both? The most common confusions

This is where most businesses go wrong. The EDPB has stated clearly, in its Guidelines 3/2018 on territorial scope, that the same person cannot be both your EU Representative and your DPO. The reason is structural: a representative acts on the company's instructions, while a DPO must act independently and receive no instructions on the exercise of its tasks. Holding both would create a conflict of interest, especially in an enforcement context.

  • Confusion 1: assuming a DPO removes the need for a representative — it does not.
  • Confusion 2: thinking the representative absorbs your liability — designation does not transfer the controller's or processor's own responsibility.
  • Confusion 3: believing a UK representative covers the EU — it does not, and vice versa.

One organisation can provide both services through separate people and clear governance.

FAQ

Does appointing an EU Representative mean I no longer need a DPO?

No. The two obligations are independent and cumulative. The representative covers your lack of an EU establishment under Article 27, while the DPO requirement under Articles 37-39 depends on the nature and scale of your processing. You may need one, the other, or both.

Can the same person act as both my EU Representative and my DPO?

No. The EDPB confirms in its Guidelines 3/2018 that the roles are incompatible, because a representative acts on the company's instructions while a DPO must be independent and receive no instructions on its tasks. A single firm can provide both, but they must be different people.

I'm a US business with no EU office — which do I need?

If you offer goods or services to people in the EU, or monitor their behaviour, you almost certainly need an Article 27 EU Representative. You additionally need a DPO only if your processing meets one of the Article 37 thresholds, such as large-scale monitoring or large-scale processing of special-category data.

Work with a real DPO

Appoint an EU representative backed by genuine, verifiable expertise.

Get my quote →