All 27 EU member states · live coverage
Article 27 explained Backed by Cloudkasten GmbH · Erftstadt, DE
About Pricing Industries Article 27 Blog FAQ Contact
Check your risk — free See plans from €29/mo$40/mo£30/moCHF 33/moAED 149/moAUD 675/yearSGD 610/year
Article 27 representation by licensed German attorneys

GDPR Article 27 EU Representative Services for non-EU companies

If your company is established outside the EU and you sell to — or track — people inside it, GDPR Article 27 requires you to designate a representative in the Union in writing. rep4eu is that representative: a German law firm entity that answers supervisory authorities, takes in data subject requests, and holds the documentation proving the designation exists. One designation, all 27 member states, live in 24–48 hours.

27
EU member
states covered
24h
Typical time
to designation
2
Licensed EU
attorneys on file
Who actually signs your designation
Licensed German attorneysRechtsanwälte, bar admitted
Certified DPOTÜV SÜD
Cloudkasten GmbHGerman entity, Erftstadt
All 27 member statesOne written designation
Scope

Does Article 27 apply to your company?

The short answer: if you have no legal establishment in the EU, and your product, website or marketing reaches people who are in the EU, Article 27 almost certainly applies — and it binds processors as well as controllers. Company size, revenue and the number of EU customers are not part of the test.

Article 27 has no scope test of its own. It borrows one from Article 3(2), which extends the GDPR to controllers and processors outside the Union in exactly two situations. If either limb is true of you, the designation duty follows automatically.

Art. 3(2)(a)

You offer goods or services to people in the EU

Payment is explicitly irrelevant — a free tier, a trial and a newsletter all count. What authorities look for is evidence that the EU market was targeted, not merely reachable.

  • EU currencies, EU languages or EU-specific pricing at checkout
  • Shipping options, VAT handling or delivery terms for EU countries
  • Paid campaigns, SEO or landing pages aimed at EU markets
  • Named EU customers or EU logos on your site
  • An EU top-level domain, or an EU phone or support number

Recital 23: a website merely being accessible from the EU is not sufficient on its own. Evidence of intent to serve the EU market is.

Art. 3(2)(b)

You monitor the behaviour of people in the EU

Monitoring means tracking individuals online and then using that data to profile, predict or decide something about them — not any collection of any data.

  • Analytics, session recording or heatmaps covering EU visitors
  • Retargeting and advertising pixels
  • Behavioural scoring, churn prediction or lead scoring
  • Personalisation and recommendation engines
  • Device fingerprinting or cross-site identity resolution

This limb catches companies with no EU sales at all — a US-only product with EU web traffic and a retargeting pixel sits inside Article 3(2)(b).

The Article 27(2) exemption is narrower than it reads

It applies only where processing is occasional, does not include large-scale processing of special category (Art. 9) or criminal offence (Art. 10) data, and is unlikely to result in a risk to the rights and freedoms of natural persons — all three at the same time. A live product, a subscription, an account system, a mailing list or a persistent analytics tag is by definition not occasional. In practice this exemption is reached by isolated, one-off processing, not by small companies with ongoing EU users.

The six-question version

Tick anything true of your company today. Most non-EU SaaS and ecommerce businesses trigger three or more.

Select all that apply
Run the full 60-second check

Looking for the statutory framework rather than the service? Our Article 27 regulations guide sets out the text, the enforcement history and the adjacent EU representative duties. For sector detail, see SaaS, ecommerce, fintech and healthtech. On the B2B question specifically: does B2B SaaS trigger the GDPR?

The mandate

What an EU representative is actually mandated to do

Article 27(4) is the operative clause: the representative is mandated to be addressed in addition to or instead of you, by supervisory authorities and data subjects, on all issues related to your processing. Everything below follows from that one sentence.

Named point of contact in the Union

A real EU address and mailbox, published in your privacy notice under Art. 13(1)(a) / 14(1)(a) and monitored by the attorneys who signed your designation.

Supervisory authority correspondence

Inbound inquiries are authenticated, triaged against the article and deadline they cite, and answered in the language of the authority.

Data subject request intake

Requests under Art. 15–22 are received, classified, identity-checked and routed to your privacy owner with the Art. 12(3) deadline attached.

Article 30 record support

Art. 30(1) and (2) place the record duty on the representative too. We hold the record for your EU-facing processing and produce it on request under Art. 30(4).

Incident coordination

When a breach puts you on the Art. 33 clock — 72 hours from awareness — we coordinate the notification pathway to the relevant authority.

Designation upkeep

A refreshed designation letter on your plan's cadence, so procurement and security reviewers are never handed a document with a stale date on it.

Why the identity of the representative matters

Recital 80 states that the representative should be subject to enforcement proceedings in the event of non-compliance by the controller or processor, and Article 27(5) confirms that this sits alongside — never instead of — action against you. A party accepting that position is accepting real exposure. It is worth knowing whether the entity that signed your mandate is a law firm that can act on it, or a forwarding address that cannot.

Supervisory authority inquiries

What happens when a data protection authority writes

A supervisory authority letter arrives with a file reference, a legal basis and a deadline — often in the national language, and often triggered by a single complaint. The value of a representative is measured entirely in what happens in the days after it lands.

  1. 01

    Authenticate and log

    We verify the authority, the file reference and the addressee before anything else. Inquiries are timestamped into your correspondence log the day they arrive — and that log is part of your Article 5(2) accountability evidence.

  2. 02

    Legal triage

    Our attorneys identify what is actually being asked, under which article, and by when. A request for your Article 30 record is a different exercise from a complaint-driven inquiry into one individual's data, and conflating them is how deadlines get missed.

  3. 03

    Brief you in plain English

    You get a summary of the inquiry, the statutory deadline, the risk read and a precise list of what we need from your side — not a forwarded PDF in German with the clock already running. Acknowledgement follows your plan's support window: 48 hours on Business, 72 hours on Essential.

  4. 04

    Draft and file the response

    The reply is written by licensed German attorneys, in the authority's own language, in the register regulators expect — with the Article 30 record extract, the designation letter and supporting documentation attached.

  5. 05

    Escalate where it belongs

    If a matter moves beyond representation — a formal investigation, an enforcement notice, a cross-border breach — we say so immediately and coordinate with your counsel rather than absorbing the problem quietly.

There is no one-stop-shop for a company without an EU establishment

The one-stop-shop mechanism in Article 56 routes cross-border cases to a single lead authority — but it depends on having a main establishment in the Union. A representative is not an establishment. The practical consequence for a non-EU company: any member state's supervisory authority can act on a complaint from a person in its territory, and correspondence can arrive in any EU language, from any of 27 regulators, with no coordination on the regulator's side. That is the specific problem an attorney-led representative exists to absorb.

Further reading: handling a supervisory authority inquiry · responding to a regulator inquiry

Data subject request management

How data subject requests are received, triaged and routed

The short answer: your representative is the address individuals in the EU write to. We take the request in, verify it, classify it, and hand it to your named privacy owner with the deadline attached. The substantive answer stays with you, because only you hold the data — Article 27(5) keeps fulfilment with the controller.

The clock you are on

Article 12(3) requires information on the action taken to reach the individual without undue delay and in any event within one month of receipt. That period may be extended by two further months where necessary given the complexity and number of requests — but only if you inform the individual of the extension, and the reasons for it, within the first month. Missing that notification is itself the breach.

Two further mechanics matter in practice. Under Article 12(6), where there are reasonable doubts about the identity of the requester, you may ask for the additional information needed to confirm it. Under Article 12(5), a manifestly unfounded or excessive request — particularly a repetitive one — may attract a reasonable fee or be refused with reasons. Both are narrow, and both have to be documented.

Rights we triage against

  • Art. 15 Access — a copy of the data plus the surrounding information
  • Art. 16 Rectification of inaccurate or incomplete data
  • Art. 17 Erasure — the "right to be forgotten"
  • Art. 18 Restriction of processing
  • Art. 20 Portability in a structured, machine-readable format
  • Art. 21 Objection, including to direct marketing
  • Art. 22 Automated decision-making and profiling

What we do with each request

  1. Receive and timestamp. The clock starts on receipt, not on the day the request reaches your inbox — so the receipt date is recorded at the representative address the moment it arrives.
  2. Check the request is what it claims to be. Automated mass requests, competitor probes and requests routed through claims-farming platforms all reach EU representative addresses, and each is handled differently.
  3. Classify by right and by scope. "Send me everything you have" and an Article 17 erasure demand carry different obligations, different exceptions and different evidence requirements.
  4. Route to your named privacy owner with the classification, the deadline, the extension option and the identity-verification status attached.
  5. Log the outcome. Requests, dates and dispositions are recorded — that record is what you need when an authority asks how you handled the complaint that triggered its inquiry.

We do not have access to your production systems and do not claim to. What this removes is the part that actually goes wrong for non-EU companies: a request in Italian, sent to an address nobody monitors, discovered five weeks later. For the fulfilment side, see our guides to managing data subject requests and responding to access requests.

Boundaries

What an Article 27 representative is not

Compliance decisions get made badly when a designation is assumed to cover more than it does. These are the boundaries we state before you buy, not after.

Not a Data Protection Officer

A DPO under Art. 37–39 is an independent monitoring and advisory function. A representative acts on your mandate. The EDPB's position is that the two roles are incompatible in the same person, precisely because of that difference. If Art. 37 obliges you to appoint a DPO, this service does not discharge it. See Article 27 representative vs DPO.

Not an EU establishment

Designating a representative does not give you a main establishment, a lead supervisory authority, or one-stop-shop treatment under Art. 56. Your Article 3 position is unchanged. See representative vs EU establishment.

Not a transfer mechanism

Chapter V still governs how EU personal data reaches your infrastructure. Standard Contractual Clauses, transfer impact assessments and the EU–US Data Privacy Framework remain separate work.

Not a substitute for your own compliance

Art. 27(5) is explicit: designation is without prejudice to legal action against you. Legal bases, notices, retention, security and your processing agreements all remain yours.

Not UK or Swiss coverage

UK GDPR has its own Article 27, needing a separate UK representative. The revised Swiss FADP requires a representative in Switzerland where its conditions are met. Different designations — see UK and Switzerland.

Not DSA or AI Act representation

The Digital Services Act requires a legal representative from non-EU intermediary service providers, and the EU AI Act adds an authorised representative duty for non-EU providers of high-risk AI systems and general-purpose AI models. Adjacent regimes, separate appointments — talk to us if more than one applies.

Choosing a provider

Three ways to satisfy Article 27 — and what each one costs you

Every option below produces a technically valid designation. They differ entirely in what happens on the day a regulator writes.

What you actually get
Mailbox / forwarding provider
rep4eu
Valid Article 27 designation letter
Published EU address for authorities and data subjects
Authority inquiry answered substantively
forwarded to you
drafted by attorneys
Correspondence in the authority's own language
Data subject requests triaged and classified
relayed raw
by right and deadline
Article 30 record held on the representative side
Answering party is a regulated law firm entity
German Rechtsanwälte
Public, fixed pricing with no per-request billing
often quote-only

The third option — incorporating your own EU entity — does remove the Article 27 duty, because you are then established in the Union. It also brings company formation, a registered office, local directors, accounting, filings and corporate tax exposure in a new jurisdiction, and it changes your Article 3 position rather than simplifying it. For most companies it is the right answer only when the EU entity is wanted for commercial reasons anyway.

Comparing named providers? See the side-by-side pages for Prighter, DataRep, VeraSafe, EDPO and the full comparison index.

Who this is built for

SaaS, ecommerce and mid-size US companies

The obligation is identical across sectors. What differs is the trigger that puts you in scope, and the kind of correspondence that shows up afterwards.

SaaS & software

Usual trigger
EU users inside customer accounts, plus product analytics and lifecycle emails. In scope under both limbs of Art. 3(2), typically as controller and processor.
What arrives
Access and erasure requests from ex-users, plus security-review questionnaires from EU buyers asking for the designation letter by name.
What we do
Hold the processor-side Art. 30 record, route subject requests to your privacy owner, and give procurement a signed, current document.
SaaS GDPR representation in detail

Ecommerce & DTC

Usual trigger
Shipping to EU addresses, EU currency at checkout, and retargeting pixels on EU traffic. Art. 3(2)(a) and (b) at once.
What arrives
Erasure and marketing-objection requests at volume, and complaints about cookie banners or abandoned-cart email.
What we do
Absorb high-volume request intake at the representative address, triage by right, and keep the response log an authority may later ask to see.
Ecommerce GDPR representation in detail

Mid-size US companies

Usual trigger
A growing EU customer base with no EU entity, and a privacy programme built for CCPA that has no Article 27 line in it.
What arrives
Enterprise vendor questionnaires, DPA negotiations, and occasionally a supervisory authority letter in a language no one in-house reads.
What we do
Provide EU-side counsel on the record, so an inquiry becomes a managed matter with a deadline rather than an emergency.
EU representation for US companies
Designation process

How to designate an EU representative, start to finish

Article 27 requires the designation to be in writing. There is no register to file with and no authority approval to wait for — the mandate plus the published contact details are the compliance artefact.

§ 01~2 min

Confirm scope

Run the free assessment, or read the Art. 3(2) test above. If you are unsure whether the Art. 27(2) exemption reaches you, that is a question for counsel, and we will say so rather than sell you a plan.

§ 02~5 min

Choose a plan and check out

Fixed annual pricing published on the site. No sales call, no procurement cycle, no per-request billing surprises later.

§ 0324–48 h

Onboarding and written mandate

You give us the entity details, the categories of EU personal data you process, and one named privacy contact. Our attorneys issue the signed Article 27 designation.

§ 04Day 1

Publish and you are covered

Add the representative to your privacy notice and Article 30 records. From then on, authority and data subject correspondence arrives at us — across all 27 member states.

The clause you add to your privacy notice

Articles 13(1)(a) and 14(1)(a) require the identity and contact details of the representative to be given to data subjects. A block like this, in the "Who we are" section of your notice, discharges it. Your exact designated details are confirmed in your onboarding pack.

EU Representative (GDPR Article 27)

[Your legal entity] has designated the following representative in
the European Union pursuant to Article 27 GDPR:

  rep4eu — Cloudkasten GmbH
  Seestr. 20 G
  50374 Erftstadt
  Germany
  [email protected]

Individuals in the EU and supervisory authorities may contact our
EU representative on all issues related to the processing of
personal data, in addition to contacting us directly.

Also update: your records of processing under Article 30, your data protection addendum template, and any security-review or vendor questionnaire answer that asks whether you have an EU representative. More on the document itself: what a signed Article 27 designation letter contains.

Transparent pricing

Article 27 representation, priced in public

Every plan is full GDPR Article 27 representation across all 27 EU member states. Billed annually, cancel renewal at any time.

Essential
€29/mo$40/mo£30/moCHF 33/moAED 149/moAUD 675/yearSGD 610/year
Billed annually — €348$480£360CHF 396AED 1,788AUD 675SGD 610/year

Full Article 27 coverage for a single entity. The right plan for most SaaS and ecommerce companies getting compliant for the first time.

Get compliant now
  • Official EU Representative designation
  • All 27 EU member states covered
  • Signed designation letter
  • Authority & data subject correspondence handling
  • Email support — 72h response
Enterprise
Custom
Tailored to your structure

Multi-entity groups, higher-risk processing, or a documentation set that has to match an existing compliance programme.

Get a custom quote
  • Everything in Business, plus:
  • Dedicated account manager
  • Custom legal documentation
  • Quarterly designation letter refresh
  • Multi-entity support
Questions, answered

GDPR Article 27 representative FAQ

A person or company established in the EU that a non-EU controller or processor mandates in writing under Article 27(1) to be addressed by supervisory authorities and data subjects on all issues related to its processing. It is a contact and liaison function under Article 27(4) — it does not transfer your own responsibility, which Article 27(5) expressly preserves.
Usually yes. Article 3(2) is triggered by processing personal data of people who are in the EU, and the employees, administrators and end users inside a business customer are individuals. Selling to companies rather than consumers does not take that data out of scope. A US SaaS vendor with EU business customers is normally in scope both as a controller for its own account and marketing data, and as a processor for customer data.
No. One written designation is used across the EU. Article 27(3) says the representative must be established in one of the member states where the affected data subjects are; for a business with users spread across the EU, a single designation in one member state is the accepted market practice — ours is in Germany and covers all 27 member states.
Different roles, different legal bases. The representative under Article 27 is your external point of contact in the Union, acting on your mandate. A DPO under Articles 37–39 is an independent advisory and monitoring function. The EDPB's position is that the two are not compatible in the same person, precisely because one acts on the controller's mandate and the other must act independently. Appointing a representative does not satisfy a DPO obligation, and vice versa.
Recital 80 states that the representative should be subject to enforcement proceedings in the event of non-compliance by the controller or processor, and Article 27(5) makes clear that this sits in addition to — never instead of — action against you. A representative therefore carries real exposure, which is why the identity of the party accepting the mandate matters.
The inquiry is authenticated, legally triaged against the article and deadline it cites, and summarised for you in plain English with a precise list of what we need from your side. Our attorneys then draft the response in the language of the authority, produce the relevant Article 30 record extract, and log the exchange. Acknowledgement follows your plan's support window — 48 hours on Business, 72 hours on Essential.
We receive them, check the request is what it claims to be, classify it by right (Articles 15–22), and route it to your named privacy owner with the Article 12(3) deadline attached — one month from receipt, extendable by two further months for complex or numerous requests if you inform the individual within the first month. The substantive answer comes from you, because only you hold the data.
No. The one-stop-shop mechanism in Article 56 depends on having a main establishment in the Union, and a representative is not an establishment. A non-EU company therefore has no single lead authority: any member state's supervisory authority can act on a complaint from a person in its territory. That is the practical reason to have a representative able to correspond in more than one EU language.
Yes, where the processor itself falls under Article 3(2). Article 27(1) names controllers and processors equally, and Article 30(2) requires the processor's representative to hold the processor-side record. A non-EU SaaS vendor cannot rely on its customer's representative — that designation covers the customer, not the vendor. Enterprise buyers increasingly ask for the vendor's own designation letter during security review.
No. UK GDPR has its own Article 27 requiring a separate UK representative, and the revised Swiss Federal Act on Data Protection requires a representative in Switzerland under Article 14 where its conditions are met. Both are separate designations from your EU one. We cover the EU and can advise on the adjacent regimes.
Company size is not the test. Article 27(2)(a) exempts processing that is occasional, does not include large-scale special category or criminal offence data, and is unlikely to result in a risk to rights and freedoms — all three at once. A live product, a subscription, a mailing list or a persistent analytics tag is not occasional, so most SaaS and ecommerce businesses fail the first condition regardless of headcount or EU revenue.
Typically 24–48 hours from checkout. We need your legal entity details, the categories of EU personal data you process and why, and one named internal privacy contact for routing. You receive a signed designation letter to reference in your privacy notice and your Article 30 records.
Designate the new representative, update the contact details in your privacy notice and Article 30 records, then terminate the old mandate — in that order, so there is no window in which no representative is named. Keep the old provider's correspondence log; it is part of your accountability record under Article 5(2). We handle the sequencing during onboarding.
Primary sources

Where these statements come from

Official legal text and regulator guidance only. Everything asserted on this page can be checked below.

Written and reviewed by Christos Paloubis and Felix Gebhard, licensed German attorneys (Rechtsanwälte). Last reviewed 1 September 2026. This page is general information about the Article 27 designation duty, not legal advice on your specific processing — ask us if your situation is genuinely borderline.

Get your Article 27 designation this week.

One written designation, all 27 EU member states, signed by licensed German attorneys. Live in 24–48 hours, with the authority and data subject correspondence handled from day one.

24htypical setup
27member states
0sales calls required