Guide

GDPR Article 27: requirements, exemptions and penalties

Reviewed by our CNIL-designated DPO · 8 min read · Updated June 2026

If your business is based outside the EU but you offer goods or services to people in the EU, or monitor their behaviour, GDPR Article 27 may require you to designate a representative inside the Union. The representative is the local point of contact that supervisory authorities and individuals can address directly. This guide explains who must appoint one, the narrow exemption that applies to low-risk processing, what the representative actually does, how to designate one correctly, and what happens if you do not.

Who must appoint a representative under Article 27

Article 27 applies when a controller or processor is not established in the EU but its processing falls under Article 3(2) of the GDPR. That is the case where you either offer goods or services to data subjects in the EU (paid or free), or monitor the behaviour of individuals taking place within the EU, such as online tracking or profiling.

Where this applies, you must designate a representative in writing, established in a Member State where the affected individuals are. This is a separate role from the DPO: a representative addresses the question of geographic reach, while a DPO concerns oversight of your processing. A US or Canadian company can need both, one, or neither, depending on its activities.

The exemption, the representative's duties, and how to designate one

Article 27(2) sets out a narrow exemption. You are not required to appoint a representative if your processing is occasional, does not include large-scale processing of special-category data (or criminal-conviction data), and is unlikely to result in a risk to individuals' rights and freedoms. All three conditions must be met, which is why most ongoing commercial or SaaS activity does not qualify. Public authorities are also outside scope.

The representative's core duties are to:

  • act as the point of contact for supervisory authorities and data subjects on all matters relating to your processing;
  • keep a copy of the records of processing required under Article 30, and make them available to authorities on request.

To designate, issue a written mandate and publish the representative's identity and contact details in your privacy notice, so they are accessible under Article 13/14.

Penalties and enforcement

Failing to designate a representative is a breach of Article 27 and falls under the lower fining tier of Article 83(4): up to EUR 10 million or 2% of total worldwide annual turnover, whichever is higher. Designating a representative does not shift your liability as controller or processor; you remain fully responsible for compliance.

Enforcement against non-EU companies is real. The Dutch supervisory authority fined Locatefamily.com EUR 525,000 for operating without an Article 27 representative. Authorities also treat the absence of a representative as a marker of wider non-compliance.

Legal basisArticle 27 GDPR
Fining tierArticle 83(4)
MaximumEUR 10M or 2% turnover

FAQ

Is an Article 27 representative the same as a DPO?

No. A representative is a local point of contact in the EU for organisations established outside it, addressing geographic reach under Article 3(2). A DPO is an advisory and oversight role that can be required regardless of where the organisation is established. The two functions are distinct and should not be combined in the same person, as their interests can conflict.

Does appointing a representative make them liable for our GDPR breaches?

Designating a representative does not transfer your responsibility or liability as controller or processor; you remain accountable. Supervisory authorities can address enforcement to the representative, but the underlying obligation, and any fine, remains with the non-EU business. The representative's own direct obligations are limited, mainly to maintaining the Article 30 records.

We are a US SaaS company with a few EU users. Do we still need one?

Probably yes. The exemption in Article 27(2) only applies where processing is occasional, low-risk, and excludes large-scale special-category data, all at once. A SaaS product that continuously serves and monitors EU users is generally not occasional, so a representative is usually required even with modest EU user numbers.

Work with a real DPO

Appoint an EU representative backed by genuine, verifiable expertise.

Get my quote →