Back to Blog
GDPREU RepresentativeCross-Border Compliance

Who Needs an EU Representative Under GDPR?

By Rob Healey · September 5, 2026

Adviser meeting a client with an EU flag and glass globe on the desk beside a laptop

A US software provider launches a platform in Germany, France and Ireland without opening an EU office. Its privacy notice is translated, prices are shown in euros, and the service tracks user behaviour to improve product performance. This is precisely the type of scenario behind the question: who needs an EU representative? The answer depends less on where the organisation is incorporated than on how, and for whom, it processes personal data.

For non-EU organisations, appointing an EU representative under Article 27 of the GDPR is often a defined market-entry requirement, not an administrative afterthought. It creates a local point of contact for supervisory authorities and individuals, while helping the organisation demonstrate that cross-border privacy responsibilities have been assigned, documented and maintained.

Who needs an EU representative under Article 27?

An organisation generally needs an EU representative if it is not established in the European Union but is subject to the GDPR because it processes the personal data of people in the EU. This applies to both controllers and processors.

The central test is found in Article 3(2) of the GDPR. A non-EU organisation falls within scope where its processing relates to either offering goods or services to individuals in the EU, whether or not payment is required, or monitoring their behaviour as far as that behaviour takes place within the EU.

Offering a service to EU residents can be clearer than it first appears. A website that merely happens to be accessible from Europe does not necessarily target the EU. However, evidence such as EU-language campaigns, country-specific marketing, euro pricing, EU delivery options, local customer support, or a product designed for an EU market can point towards intentional offering.

Monitoring is equally broad in commercial practice. It may include behavioural advertising, location tracking, profiling, online identifiers used to analyse user actions, or analytics that build a detailed understanding of people in the EU. The relevant question is not whether the organisation considers itself a technology company, manufacturer or service provider. It is whether personal data processing supports an offer to, or observation of, individuals in the EU.

A processor based outside the EU can also require an EU representative. For example, an APAC-hosted platform that processes employee, customer or patient information for EU-based clients may have its own Article 27 assessment to complete. A customer’s EU presence does not automatically satisfy the processor’s obligations.

Situations where an EU representative may not be required

Article 27 includes narrow exceptions. A non-EU controller or processor may not need a representative where processing is occasional, does not include large-scale processing of special category data or criminal-offence data, and is unlikely to result in a risk to the rights and freedoms of natural persons. Public authorities and public bodies are also excluded from the requirement.

These conditions are cumulative. A business cannot rely on the exception simply because its data processing volume is currently modest. If it continuously serves EU customers, routinely handles workforce information, uses persistent analytics, or processes sensitive data, describing the activity as occasional will be difficult to support operationally.

The exception also needs reassessment as the business changes. A pilot programme can become a permanent EU product line. A limited business-to-business deployment can develop into a platform with thousands of end users. New AI features, data enrichment activities or expanded vendor arrangements may materially alter the processing profile. Article 27 should therefore be considered within launch governance and reviewed when the operating model changes.

What an EU representative actually does

An EU representative is not a nominal address or a mail-forwarding arrangement. The representative is appointed in writing to act on behalf of the controller or processor regarding GDPR obligations. Supervisory authorities and data subjects may contact the representative on matters related to processing.

In practice, an effective representative mandate supports accountable communications, maintains the right operational information, and ensures requests reach the people able to respond. This matters particularly when an organisation operates across time zones, has distributed product teams or relies on several processors.

The representative should be able to facilitate communications concerning matters such as privacy enquiries, data subject requests, regulatory correspondence and relevant records of processing activities. Article 30 records must be made available to supervisory authorities on request where required. That calls for a controlled process rather than a last-minute exercise in collecting spreadsheets from multiple departments.

Appointment of a representative does not transfer the controller’s or processor’s compliance responsibilities. It does not remove accountability for lawful processing, security measures, retention controls, data subject rights or vendor oversight. Nor does it create an EU establishment where none otherwise exists. It is a distinct statutory role designed to make a non-EU organisation reachable and accountable within the Union.

EU representative, DPO and local establishment: different roles

These roles are often confused, particularly by organisations scaling quickly into Europe.

A Data Protection Officer has an independent advisory and monitoring role under the GDPR. A DPO may advise on compliance, monitor governance arrangements, support impact assessments and act as a contact point for authorities. Not every organisation must appoint one, and a DPO does not automatically satisfy Article 27.

An EU representative is a local representative for a non-EU controller or processor caught by Article 3(2). The role is focused on representation and contactability. It must be established in an EU Member State where the relevant data subjects reside.

An EU establishment is a separate question. A branch, subsidiary, staffed office or stable arrangement may amount to an establishment depending on the facts. Having customers, a distributor or a virtual office alone does not necessarily establish an organisation in the EU. Businesses should avoid assuming that one role, address or commercial relationship resolves all three questions.

A practical way to assess Article 27 exposure

The most reliable assessment starts with the operating model, not a generic GDPR checklist. Map which legal entity determines the purposes and means of processing, which entities process data for others, where staff and systems are located, and which categories of people are in the EU.

Then examine the evidence of targeting and monitoring. Sales activity, product design, marketing channels, user analytics, mobile applications, cookies and SDKs, support arrangements, and contractual commitments can each be relevant. For processors, review client locations, instructions, hosting arrangements and the categories of data handled on their behalf.

The output should be a documented decision with clear ownership. If an EU representative is needed, the organisation should define the scope of the mandate, nominated internal contacts, escalation routes, service expectations and access to current processing records. If an exception is considered applicable, the rationale should be recorded and reviewed at a defined point, such as a new market launch or material product change.

For enterprise groups, the assessment should be completed entity by entity. A parent company’s EU representative appointment may not cover every overseas affiliate, controller or processor in the group. The written mandate and public-facing privacy information need to reflect the actual processing roles and legal entities involved.

AI services can increase the need for discipline

Organisations deploying AI systems should pay particular attention to the underlying data flows. An AI vendor outside the EU may process prompts, account information, usage telemetry or training-related datasets connected with individuals in the EU. Where those activities relate to offering a service in the EU or monitoring behaviour, Article 27 may be engaged.

This is not solely a privacy notice issue. AI governance should connect product approval, data classification, vendor risk assessment, system inventories, DPIAs where appropriate, records of processing and incident response. An EU representative works best when these controls are operationalised and can provide accurate, timely information when a query arises.

Selecting and managing the representative

The right provider should offer more than a registered address. Look for a representative service that can handle regulatory correspondence, communicate clearly with internal stakeholders, preserve appropriate records and escalate matters through agreed procedures. Coverage also matters for organisations managing obligations beyond the EU, including the UK, Switzerland and other markets.

Formiti combines legal, privacy and technical operations teams to support representation and wider compliance delivery across more than 120 countries and 100 regulatory frameworks. That three-team model is valuable where an Article 27 appointment needs to connect with real workflows, rather than sit separately from privacy operations.

Before appointing a representative, ensure the privacy notice identifies the correct representative and contact details, the written mandate is in place, internal teams know how to route enquiries, and processing documentation is current. Test the process with a realistic scenario, such as a data subject request or supervisory authority enquiry. A mandate that exists only in a contract folder is unlikely to provide the control a cross-border organisation needs.

For organisations entering or expanding in the EU, the useful question is not simply whether Article 27 applies at this moment. It is whether the business can show, with confidence, who is accountable for receiving, escalating and answering privacy matters as its EU-facing operations grow.

Related Services

Need help with AI governance or data privacy compliance?

Privacy-first website: We do not use tracking cookies, advertising pixels, or third-party analytics on this site. Read our Privacy Notice.