
A regulator’s first question is rarely whether your company meant to comply. It is who, in the EU, can be contacted now. For non-EU businesses subject to the GDPR, privacy representative obligations are the answer to that practical enforcement question. They are not satisfied by adding a European mailing address to a privacy notice.
If your US company sells to people in the EU, markets to them, or monitors their behavior without an EU establishment, Article 27 may require you to appoint an EU Representative. That representative must be reachable by supervisory authorities and data subjects, able to handle the matters covered by the mandate, and prepared to support a real response when scrutiny arrives.
When privacy representative obligations apply
Article 27 applies to controllers and processors that are not established in the EU but fall within the GDPR’s extraterritorial scope under Article 3(2). The familiar triggers are offering goods or services to individuals in the EU or monitoring their behavior in the EU.
A US SaaS company that accepts EU customers, localizes pricing in euros, runs targeted EU ad campaigns, or tracks product behavior across EU users may be in scope. So may an eCommerce brand shipping to France or Germany, an app collecting location data from EU users, or a US vendor processing EU employee data for an EU-based client.
The requirement is not limited to large companies. A small startup can create Article 27 exposure as soon as it deliberately targets EU individuals and processes their personal data. Revenue, headcount, and good intentions do not remove the obligation.
There is a narrow exception where processing is occasional, does not include large-scale processing of special-category or criminal-offense data, and is unlikely to create a risk to individuals’ rights and freedoms. All of those conditions must be met. Businesses often overestimate this exception because their processing feels limited internally. Regular subscription activity, ongoing analytics, customer support, behavioral advertising, or a continuously available consumer app can make the “occasional” argument difficult to defend.
The core privacy representative obligations
An EU Representative is formally designated in writing by the non-EU controller or processor. The designation should clearly identify the parties, define the representative’s mandate, and confirm the scope of processing activities it covers. The representative’s identity and contact details must also appear in the company’s privacy notice where Article 27 applies.
The central function is external accountability. Supervisory authorities and data subjects may contact the representative on all issues related to GDPR compliance. The representative can be addressed in addition to, or instead of, the non-EU company. That language matters. A representative is not a passive mailbox that forwards a message days later without understanding the issue.
In practical terms, the representative should be able to receive, assess, route, and coordinate responses to authority correspondence and data subject requests. This requires current contacts at the company, access to relevant compliance documentation, and a defined escalation process. If a German authority asks about lawful basis, international transfers, retention, or security measures, the response cannot depend on an employee searching Slack for the right owner.
The appointment also connects to recordkeeping. Where required, controllers and processors must maintain records of processing activities under Article 30, and the representative has a role in making relevant records available to a supervisory authority. That does not mean handing a representative a one-time spreadsheet and forgetting about it. Records need updates when products, vendors, purposes, data categories, retention periods, or transfer arrangements change.
What the representative does not take over
Appointing an EU Representative does not transfer GDPR liability away from the company. The controller or processor remains responsible for lawful processing, transparency, security, vendor management, data subject rights, and breach decisions.
The representative is also not automatically your Data Protection Officer. A DPO has a distinct, independent advisory and monitoring role, with separate appointment criteria. One provider may be capable of supporting both functions in some circumstances, but the legal roles should not be blurred.
Nor does Article 27 representation create an EU establishment. That distinction can matter for lead supervisory authority analysis, local regulatory exposure, tax, employment, and commercial questions. A representative gives regulators and individuals a reliable EU contact point. It does not change the underlying structure of your business.
What happens when an authority contacts your representative
A credible Article 27 arrangement should operate like an incident-ready legal channel, not a forwarding rule. The representative receives the inquiry, identifies the deadline and jurisdiction, determines what information is needed, and coordinates with the right people inside the company. Legal privilege, investigation strategy, and the accuracy of statements all need consideration before a response is sent.
The timing can be unforgiving. A data subject access request generally requires a response within one month, subject to limited extensions. A personal data breach may require notification to the competent authority within 72 hours when the legal threshold is met. The representative cannot make missing facts appear, but it can prevent an already serious situation from becoming worse through delay, confusion, or an incoherent response.
This is where low-cost mailbox services create a material gap. A forwarding address may technically receive an email. It may not recognize a regulator’s request, distinguish a complaint from a formal investigation, protect sensitive communications, or help your team produce a defensible answer. For a company with EU customers, that difference is operational, legal, and commercial.
Building an Article 27 arrangement that will hold up
Start by documenting why the GDPR applies to your business and whether the Article 27 exception genuinely fits. Do not rely on a generic statement that you are “US-only” if your product, sales activity, or tracking tells a different story.
Next, appoint a representative in writing and publish accurate contact details in the privacy notice. Choose a representative established in an EU member state where your affected individuals are located, particularly where your highest-risk processing or largest EU customer base sits. The GDPR permits one representative for processing across the EU, but the representative must be able to support communication across all relevant jurisdictions.
Then establish the operating layer behind the appointment. Your representative should have named contacts for privacy, legal, security, engineering, and customer operations. It should know where your Article 30 records, privacy notices, data processing agreements, transfer assessments, subprocessor list, incident plan, and rights-request procedures are maintained.
A short intake process is useful, but it is not enough. Test it. Ask what happens if an authority letter arrives on a Friday afternoon, a French consumer sends an access request in French, or your security team identifies a potentially reportable breach. If the answer is “we will figure it out,” the company has not built a workable representation model.
For businesses that need immediate coverage, rep4eu provides Article 27 representation through licensed German attorneys, with formal designation documentation and substantive support for authority inquiries, data subject requests, and incident coordination. The point is not to create paperwork. It is to put a capable legal contact between your business and avoidable regulatory exposure.
Keep the mandate current as the business changes
Article 27 compliance is not a one-time onboarding exercise. A company that launches a new AI feature, begins profiling users, expands from B2B to direct consumer sales, adds a US-based analytics provider, or starts processing health-related data may materially change its risk profile.
Review your representative arrangement when those changes occur. Confirm that the privacy notice remains accurate, records of processing reflect reality, internal contacts are current, and the representative understands what has changed. Procurement teams and enterprise customers increasingly examine these details before signing. A listed representative that cannot answer basic follow-up questions can stall a deal just as quickly as an absent one.
The most useful test is simple: if an EU regulator or customer contacts the number in your privacy notice tomorrow, will they reach a legally credible team that can act? If not, the gap is visible, and it is time to close it before someone else identifies it for you.