Guide

What happens if you do not appoint an EU representative?

Reviewed by our CNIL-designated DPO · 7 min read · Updated June 2026

If your US or Canadian business offers goods or services to people in the EU or EEA, or monitors their behaviour, GDPR Article 27 usually requires you to appoint an EU representative. Skipping that step is not a paperwork gap you can quietly carry. It is a standalone breach of the GDPR, it leaves regulators and data subjects without a local point of contact, and it has already cost non-EU companies real money. This guide walks through what actually happens when no representative is in place: the legal exposure, what supervisory authorities have done in practice, where liability lands, the operational damage of being unreachable, and how to close the gap quickly.

Failing to appoint is a breach in its own right

Article 27 is an obligation, not a recommendation. For organisations caught by Article 3(2), the absence of a representative is itself an infringement, independent of whether your underlying processing is otherwise lawful.

Supervisory authorities treat it that way. Under Article 83, infringements of Article 27 sit in the lower penalty tier, up to EUR 10 million or 2% of total worldwide annual turnover, whichever is higher. That is far from trivial, and it rarely travels alone. A missing representative is often the first thing a regulator notices, and it signals weak compliance elsewhere.

Two practical consequences follow:

  • The breach is provable on its face. A regulator does not need to litigate complex processing questions to establish it.
  • It compounds. Authorities pair the Article 27 finding with the higher-tier breaches it tends to accompany, pushing total exposure toward the GDPR maximum.

What enforcement has actually looked like

This is not theoretical. In June 2021 the Dutch supervisory authority fined the Canadian-operated site Locatefamily.com EUR 525,000 specifically for not appointing an EU representative under Article 27. It also ordered the company to appoint one or pay EUR 20,000 every two weeks, up to EUR 120,000.

The Article 27 breach also appears in larger, multi-authority cases. When Italian and Greek regulators each fined Clearview AI EUR 20 million, the failure to designate an EU representative was cited alongside the core unlawful-processing findings.

The broader GDPR ceiling matters too:

TierMaximum
Article 27 breachEUR 10m or 2% turnover
Core obligationsEUR 20m or 4% turnover

In short: regulators do act against non-EU companies, and the missing representative is part of the story.

Liability, unreachability, and fixing it fast

Appointing a representative does not shift responsibility. Liability stays squarely with you as the controller (or processor). The representative is your mandated point of contact in the EU, not a shield, and the GDPR is explicit that designation is without prejudice to actions against the controller itself.

The quieter risk is being unreachable. Without a representative, a regulator or data subject who tries to reach you has no local channel. Silence reads as non-cooperation, which is an aggravating factor under Article 83 and invites escalation, complaints, and orders.

Remediation is fast:

  1. Confirm whether Article 3(2) applies to your processing.
  2. Appoint a written-mandated representative in an EU or EEA Member State where your data subjects are.
  3. Name them in your privacy notice and record them in your Article 30 records.

Acting before a complaint lands is far cheaper than reacting to one.

FAQ

Is not appointing an EU representative really a separate breach?

Yes. If Article 3(2) applies to you, failing to designate a representative is an independent infringement of Article 27, regardless of whether the rest of your processing is compliant. A supervisory authority can act on that alone, and in the Locatefamily.com case the Dutch authority fined EUR 525,000 on exactly this basis. In practice it usually appears alongside other findings, which raises total exposure.

How large can the fine be?

Infringements of Article 27 sit in the GDPR lower tier, up to EUR 10 million or 2% of total worldwide annual turnover, whichever is higher. But the missing representative rarely stands alone. When paired with core breaches such as unlawful processing, total exposure can reach the GDPR maximum of EUR 20 million or 4% of global annual turnover. Clearview AI received EUR 20 million fines in several Member States.

Does appointing a representative reduce my legal responsibility?

No. Liability stays with you as the controller or processor. A representative is your designated EU contact point for regulators and data subjects, mandated in writing to act on your behalf, but it does not transfer or dilute your accountability. Its real value is practical: you become reachable, you can respond quickly, and you remove an easy, provable breach from any future investigation.

Work with a real DPO

Appoint an EU representative backed by genuine, verifiable expertise.

Get my quote →