How to appoint an EU representative: step by step
Reviewed by our CNIL-designated DPO · 8 min read · Updated June 2026
If your US or Canadian business handles the personal data of people in the EU, the GDPR may require you to appoint an EU representative under Article 27. The good news: the process is straightforward and entirely administrative once you understand the five moves. This guide walks you through each one in plain language, from confirming whether the obligation even applies to you, through choosing and formally mandating a representative, to publishing their details and wiring them into your day-to-day data handling. You will also find a sample designation letter you can adapt. None of this requires you to open an EU entity or hire local staff. It is about creating a documented point of contact inside the EEA so individuals and supervisory authorities can reach a controller or processor that otherwise sits outside their jurisdiction.
Steps 1 and 2: Confirm you need a representative, then choose one
Step 1 — Confirm the obligation applies. Article 27 bites when you are not established in the EU but you process the personal data of people who are in the EU, and that processing relates to either (a) offering goods or services to them (paid or free), or (b) monitoring their behaviour within the EU. Tracking website visitors, running EU-targeted ads, or accepting EU customers usually counts. There is a narrow exemption for occasional processing that is low-risk and involves no large-scale special-category data.
Step 2 — Choose a representative in the right place. Your representative must be established in an EU or EEA Member State where some of the affected individuals are. Many businesses pick a single state and use a specialised provider. Confirm the provider can act for both controllers and processors and is overseen by a qualified privacy lead, such as a CNIL-designated DPO.
Steps 3 and 4: Put it in writing, then publish the contact details
Step 3 — Put the appointment in writing. Article 27 requires a written mandate. A short designation letter or service agreement that names your company, the representative, the Member State of establishment, and the scope of authority is enough. Keep a signed copy on file; supervisory authorities may ask for it.
Here is a simple template you can adapt:
To whom it may concern,
[Your Company, Inc.], a company established at [full address, country], hereby designates [Representative Name], established at [EU/EEA address, Member State], as its representative in the Union pursuant to Article 27 of Regulation (EU) 2016/679 (GDPR).
The representative is mandated to be addressed by data subjects and supervisory authorities on all matters relating to our processing of personal data, in addition to or instead of us. This designation takes effect on [date] and remains valid until withdrawn in writing.
Signed, [Name, Title, Date].
Step 4 — Publish the details. Under Articles 13 and 14, your privacy notice must give the representative's identity and contact details so individuals can find them easily.
Step 5: Keep your Article 30 records and route requests
Step 5 — Operationalise the appointment. A representative is only useful if it is connected to your actual processes. Two obligations matter most here.
First, your representative must keep a copy of your Article 30 records of processing activities and make them available to a supervisory authority on request. So keep your record of processing current and share it with your representative whenever it changes.
Second, set up a clear path for inbound contact. When a data subject or a supervisory authority reaches the representative, that message needs to land with the right person on your side fast.
- Name an internal owner for representative correspondence.
- Agree response timelines that respect GDPR deadlines (for example, one month for data-subject rights).
- Log every request and your response for accountability.
Done well, the representative becomes a smooth bridge rather than a dead-end mailbox.
FAQ
Does appointing an EU representative make my company subject to the GDPR?
No. The appointment does not create new jurisdiction. If you target or monitor people in the EU, the GDPR already applies to that processing under Article 3; the representative is simply the local point of contact the law requires you to designate. Naming one does not expand the GDPR's reach beyond what your processing activities already trigger, and it does not make the representative liable for your compliance.
Can my EU representative be the same person as my DPO?
Generally no, and it is not advisable. The roles conflict: a DPO must act independently and advise on compliance, while a representative acts on the controller's or processor's mandate and can be held accountable by authorities for cooperation. EU guidance discourages combining them in the same person. Many businesses use a dedicated representative service that is separately overseen by a qualified DPO, keeping the two functions distinct.
What happens if I do not appoint one when required?
Failing to designate a representative when Article 27 applies is itself an infringement of the GDPR and can be sanctioned by supervisory authorities, including administrative fines. Just as importantly, the absence of a representative signals weak compliance overall and can complicate handling individuals' requests and authority inquiries, increasing your exposure. Appointing one is a low-cost, fast way to close that gap and demonstrate good faith.
Work with a real DPO
Appoint an EU representative backed by genuine, verifiable expertise.
Get my quote →