Back to Blog
EU GDPRRepresentationCompliance

When Do You Need Article 27 Representation?

By Robert Healey · July 14, 2026

When Do You Need Article 27 Representation?

A US, UK or APAC business can enter the European market without opening a local office. That does not mean it can operate without a local regulatory contact point. The question, when do you need Article 27 representation, turns on where your organisation is established, what processing it performs, and whether that processing is connected to people in the EU.

For organisations expanding internationally, Article 27 is not simply an administrative appointment. It is a practical control that gives EU data subjects and supervisory authorities a recognised point of contact. Getting the scope right early can prevent a market-entry project, new digital service or AI deployment from creating an unowned compliance obligation.

What Article 27 representation means

Article 27 of the EU General Data Protection Regulation requires certain controllers and processors that are not established in the EU to designate a representative in the Union. The representative must be established in an EU Member State where the relevant data subjects are located.

This requirement is often misunderstood as a substitute for a Data Protection Officer. It is not. A DPO provides independent advice, oversight and monitoring where that role is required or appropriate. An Article 27 representative acts as a local contact point on behalf of a non-EU controller or processor for matters relating to GDPR compliance.

The representative’s details should be made available to relevant supervisory authorities and data subjects. They may receive communications, queries and regulatory correspondence, and must be able to support access to the organisation’s records of processing activities where required. The underlying controller or processor remains accountable for its own compliance. Appointing a representative does not transfer that responsibility or shield the organisation from regulatory action.

When do you need Article 27 representation?

The requirement generally applies where both of the following conditions are met. First, your organisation is not established in the EU. Secondly, your processing of personal data is related to offering goods or services to individuals in the EU, or monitoring their behaviour where that behaviour takes place in the EU.

Offering goods or services does not require payment. A free software platform, mobile application, clinical research portal, recruitment tool or online community may fall within scope if it is directed at people in the EU. The assessment should look beyond whether an individual happens to access a global website. Relevant indicators can include EU-focused marketing, local language or currency options, delivery to EU countries, country-specific product pages, or a clear intention to serve customers in the Union.

Monitoring behaviour is similarly broader than many organisations expect. It can include tracking individuals online to analyse or predict preferences, behaviour or location. Advertising technology, analytics programmes, connected products, fraud controls and certain AI-enabled profiling processes can all require careful assessment where they relate to people in the EU.

A technology company headquartered in Singapore, for example, may need an EU representative if it provides a platform to EU business users and processes the personal data of their employees or customers in that context. A US-based manufacturer may face the same requirement if its connected equipment app monitors usage patterns of EU-based users. The answer depends on the actual processing activity, not the organisation’s sector or the location of its servers.

Controllers and processors can both be in scope

Article 27 is not limited to companies deciding why and how personal data is used. A processor outside the EU can also need a representative when it processes personal data for an EU-facing client or service arrangement and has no EU establishment of its own.

This is particularly relevant to cloud service providers, software vendors, managed service providers and AI solution providers. Contract terms may allocate roles between customer and supplier, but they do not remove the need for each party to assess its own GDPR position. A processor’s representative obligation should be considered alongside its contractual, security, records-management and incident-response responsibilities.

The narrow exceptions need careful handling

Article 27 contains limited exemptions. Public authorities and bodies are excluded. There is also an exemption for processing that is occasional, does not include large-scale processing of special category data or criminal offence data, and is unlikely to result in a risk to the rights and freedoms of natural persons.

Those conditions apply together. A business should not assume that low data volumes automatically make processing occasional or low risk. Regular collection through a customer platform, ongoing employee data handling, continuous analytics or recurring marketing activity is difficult to characterise as occasional. Equally, a small dataset can still create meaningful risk if it contains health information, biometric data, detailed location data or other sensitive information.

The operational question is whether the activity is genuinely limited and exceptional, rather than a continuing part of the organisation’s service model. Where there is uncertainty, documenting the assessment is prudent. It creates a clear basis for the decision and helps teams revisit it when products, markets or data uses change.

EU, UK and Swiss representation are separate questions

An EU representative under Article 27 does not automatically meet obligations under the UK GDPR. Organisations without a UK establishment that target or monitor individuals in the UK may need a separate UK representative. The United Kingdom is no longer an EU Member State, so a single appointment should not be assumed to cover both territories.

Swiss privacy requirements also have their own territorial tests and representative provisions. For a business operating across Europe, the efficient approach is to map each market, entity, processing activity and data flow before selecting a representation model. This avoids gaps created by treating "Europe" as one regulatory jurisdiction.

A managed representative arrangement can be particularly valuable where an organisation is entering several markets without local offices. It should provide dependable local coverage while fitting into the organisation’s existing privacy governance, records and escalation procedures.

What an effective representative mandate looks like

A compliant appointment needs more than a name on a privacy notice. The mandate should be in writing and should clearly define how the representative will receive, assess and escalate communications from supervisory authorities and data subjects.

In practice, the representative needs accurate, current information. That includes the relevant legal entities, processing purposes, categories of data, processor arrangements, record of processing activities and the internal owners responsible for answering questions. A representative cannot perform effectively if material information sits across disconnected legal, security and product teams.

The strongest operating model also establishes response routes before an enquiry arrives. Identify who validates a request, who supplies supporting evidence, who approves communications and how urgent regulatory correspondence is escalated to senior decision-makers. These controls matter during routine queries, but they are especially valuable when an access request, incident or regulator contact requires coordinated action across jurisdictions.

For AI-enabled products, the mandate should connect with the organisation’s AI governance process rather than operate separately from it. Where an AI system profiles users, uses behavioural data, supports automated decisions or relies on third-party data providers, privacy teams should be able to trace the relevant data flows and risk assessments quickly. An AI system registry, vendor risk review and clear ownership structure make that possible.

Build representation into expansion planning

The best time to assess Article 27 is before launch, not after a complaint or supervisory authority enquiry. Include the assessment in product approvals, market-entry checklists, procurement reviews and AI governance gates. Review it whenever the organisation starts targeting a new territory, introduces behavioural analytics, acquires a business or changes the purpose for which personal data is used.

Formiti supports this work through its Legal Team, Privacy Team and Technical Operations Team, bringing representative coverage together with the practical workflows needed to keep records, requests and escalations under control across more than 120 countries and 100 regulatory frameworks.

The right moment to appoint an Article 27 representative is when your EU-facing processing moves from possibility to planned reality. Treating representation as part of operational readiness gives the business a clearer route into the market and a reliable structure for meeting its ongoing accountability obligations.

An Formiti representation and DPO service gives non-EU organisations a defensible, jurisdictionally aware operating model — not just a mailbox.

Related Services

Need help with AI governance or data privacy compliance?

Privacy-first website: We do not use tracking cookies, advertising pixels, or third-party analytics on this site. Read our Privacy Notice.