EU Representative vs DPO: What Is the Difference?
Reviewed by our CNIL-designated DPO · 8 min read · Updated June 2026
The EU Representative and the Data Protection Officer are two of the most commonly confused roles under the GDPR, partly because both involve a named contact and both touch data protection compliance. But they answer different legal questions, are governed by different articles, and are triggered by different facts. The Article 27 representative is about your physical presence in the EU when you are based outside it; the Article 37-39 DPO is about the nature and scale of your data processing, wherever you are located. This guide sets out exactly what each role is, who needs which, whether the same firm can hold both, and when you need both at once.
Two roles, two articles: what each one actually is
The two functions sit in different parts of the GDPR and exist for different reasons.
- EU Representative (Article 27). A natural or legal person established in the EU or EEA, designated in writing by a controller or processor based outside the Union. It acts as the local point of contact for supervisory authorities and data subjects, and is mandated to be addressed in addition to (or instead of) the company on all compliance matters. It also helps maintain the Article 30 record of processing.
- Data Protection Officer (Articles 37-39). An expert who advises the organisation on its GDPR obligations, monitors internal compliance, and serves as the contact point with supervisory authorities and the EDPB.
The representative is about where you are; the DPO is about what you process.
Who needs which — and when you need both
The triggers are separate, so test each one independently.
| Question | EU Representative | DPO |
|---|---|---|
| Governing article | Article 27 | Articles 37-39 |
| What triggers it | No EU/EEA establishment and you target or monitor people in the EU | Public authority; large-scale regular & systematic monitoring; or large-scale special-category data |
| Core function | Local contact & mailbox for authorities and individuals | Independent advisor & compliance monitor |
| Independence | Acts on the company's instructions | Must act independently; no instructions on tasks |
A US or Canadian SaaS targeting the EU usually needs a representative. If it also profiles users at scale, it needs both. The obligations are cumulative.
Can the same firm be both? The most common confusions
This is where most businesses go wrong. The EDPB has stated clearly, in its Guidelines 3/2018 on territorial scope, that the same person cannot be both your EU Representative and your DPO. The reason is structural: a representative acts on the company's instructions, while a DPO must act independently and receive no instructions on the exercise of its tasks. Holding both would create a conflict of interest, especially in an enforcement context.
- Confusion 1: assuming a DPO removes the need for a representative — it does not.
- Confusion 2: thinking the representative absorbs your liability — designation does not transfer the controller's or processor's own responsibility.
- Confusion 3: believing a UK representative covers the EU — it does not, and vice versa.
One organisation can provide both services through separate people and clear governance.
FAQ
Does appointing an EU Representative mean I no longer need a DPO?
No. The two obligations are independent and cumulative. The representative covers your lack of an EU establishment under Article 27, while the DPO requirement under Articles 37-39 depends on the nature and scale of your processing. You may need one, the other, or both.
Can the same person act as both my EU Representative and my DPO?
No. The EDPB confirms in its Guidelines 3/2018 that the roles are incompatible, because a representative acts on the company's instructions while a DPO must be independent and receive no instructions on its tasks. A single firm can provide both, but they must be different people.
I'm a US business with no EU office — which do I need?
If you offer goods or services to people in the EU, or monitor their behaviour, you almost certainly need an Article 27 EU Representative. You additionally need a DPO only if your processing meets one of the Article 37 thresholds, such as large-scale monitoring or large-scale processing of special-category data.
Work with a real DPO
Appoint an EU representative backed by genuine, verifiable expertise.
Get my quote →