An Article 27 representative is a person or company established in the EU who acts as a contact point for supervisory authorities and data subjects on your behalf. You need one if the GDPR reaches you through Article 3(2), meaning you have no EU establishment but you offer goods or services to people in the Union or monitor their behaviour. The exemption in Article 27(2) exists but is cumulative and narrow.
This article covers who the obligation catches, what the exemption actually requires, what a representative does and does not do, how the UK equivalent differs, and how to tell whether the requirement has been met.
Who The Obligation Catches
Article 27(1) is short: where Article 3(2) applies, the controller or processor shall designate in writing a representative in the Union.
Everything therefore turns on Article 3(2), which brings non-EU organisations into scope where processing relates to offering goods or services to data subjects in the Union, irrespective of whether payment is required, or to monitoring their behaviour within the Union.
Two consequences follow that surprise people. A free product counts, because payment is expressly not the test. And behavioural monitoring is a low bar: analytics, session tracking and profiling of EU visitors all qualify.
If you have an establishment in the EU, Article 3(1) applies instead and Article 27 does not bite. This is why creating an EU subsidiary that actually performs the processing is a genuine alternative to appointing a representative, though it is a much larger commitment.
The Exemption Is Cumulative
Article 27(2)(a) disapplies the obligation for processing which is occasional, does not include large-scale processing of special category data under Article 9(1) or criminal offence data under Article 10, and is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account the nature, context, scope and purposes of the processing. Article 27(2)(b) exempts public authorities.
Read that carefully, because every condition must be satisfied. Failing any one of them defeats the exemption entirely.
"Occasional" is the condition that removes most SaaS companies. A product that processes EU user data continuously, as a normal part of its operation, is not processing occasionally. The EDPB has interpreted this narrowly and consistently, and a subscription service running every day is a poor candidate.
The honest position is that the exemption was written for genuinely sporadic processing, not for small companies. Being small is not the test. A two-person SaaS with EU customers processes personal data continuously and is caught, while a company that processes one EU applicant's CV a year may not be.
What A Representative Actually Does
The mandate must be in writing, and the representative must be established in a Member State where the data subjects whose data you process are located.
The representative acts as the addressee for supervisory authorities and data subjects on all issues relating to processing. In practice that means receiving correspondence from regulators, being reachable by individuals exercising their rights, and maintaining a copy of your record of processing activities so it can be produced on request.
Three things it is not. It is not a data protection officer: different role, different criteria, different independence requirements, and one person can hold both only if the conflicts work out. It is not a shield: designating a representative does not reduce your own responsibility or liability by any amount. And it is not a mailbox that can be left unattended, since the representative is exposed to enforcement action taken in respect of your processing.
The appointment also has to be visible. A representative nobody can find has not been effectively designated, which is why the details belong in your privacy information alongside your other contact details.
What the role costs is worth being realistic about. Specialist providers offer it as a subscription service, typically for a few hundred euros a year at the low end, and law firms offer it at professional rates. The cheap end is genuine as far as it goes, but read what is included: some packages cover the designation and a forwarding address and stop there, leaving you to handle any correspondence that arrives. Since the representative must hold a copy of your record of processing activities and produce it to a supervisory authority on request, an arrangement where nobody maintains that record is a designation in name only.
The UK Runs A Parallel Requirement
Since Brexit there are two regimes and two representative obligations, and companies routinely satisfy one while forgetting the other.
UK GDPR carries its own Article 27. A controller or processor outside the UK, caught by the UK equivalent of Article 3(2), needs a UK representative on materially the same terms. A US company selling to both markets therefore needs an EU representative and a UK representative, and they cannot be the same entity unless that entity is established in both.
The vendors examined for this blog show the pattern clearly. Zapier's documentation states it has both EU and UK representatives, and Calendly's addendum records representatives designated in the EEA and the UK, both checked 7 August 2026. When two US SaaS companies of very different sizes have independently concluded they need both, that is a reasonable signal for a company in the same position. The mechanics of what Zapier does with the rest of its transfer paperwork are covered in our look at whether Zapier is GDPR compliant.
The UK obligation sits alongside a separate and frequently confused one: paying the ICO's data protection fee, which is a different requirement with different criteria and is covered in our guide to ICO registration. The two get conflated constantly, and they are unrelated: one is a designation obligation under UK GDPR, the other an annual payment under the Data Protection Act 2018. Satisfying either does nothing for the other.
There is a further wrinkle worth checking before you assume symmetry. The EU representative must sit in a Member State where your data subjects are, so if your EU users are concentrated in Germany and your provider is established in Ireland, that is a question to put to them rather than assume. Where you have users spread across many Member States, any one of them can work, but the choice is not arbitrary and should be recorded with a reason.
Common Mistakes With EU Representatives
Assuming a free product is outside scope. Article 3(2)(a) applies irrespective of whether payment is required. A free tier, an open beta and a no-charge trial all count, a point examined further in whether GDPR applies to trial users.
Reading the exemption as a small-business carve-out. It is not about company size. It is about whether processing is occasional and low risk, and continuous product processing is neither.
Treating the representative as a DPO, or vice versa. They are separate roles with separate legal bases. Appointing a DPO does not discharge Article 27, and appointing a representative does not discharge Article 37.
Appointing an EU representative and stopping there. UK GDPR carries a parallel requirement. Serving both markets generally means two appointments.
Burying the appointment. The representative exists to be contacted. If the name and address are not in your privacy information, the designation is not doing the job the article requires.
FAQ
Do we need an EU representative if we only have a handful of EU users?
Probably yes. There is no minimum user threshold in Article 3(2), and the Article 27(2) exemption turns on whether processing is occasional and low risk rather than on volume. Continuous processing of a small number of EU users still fails the occasional test.
Can our EU-based law firm act as our representative?
Yes, a representative can be a natural or legal person, and law firms and specialist providers both offer the service. Check they are established in a Member State where your data subjects are, and that the written mandate covers regulator and data subject correspondence.
Does appointing a representative reduce our liability?
No. The GDPR is explicit that designation is without prejudice to legal actions against the controller or processor. The representative is an additional point of contact and an additional enforcement target, not a substitute for your own responsibility.
What happens if we do not appoint one?
Failure to designate is an infringement in its own right and has been fined. More practically, it removes the buffer between you and a supervisory authority, and it signals to regulators and enterprise buyers that other basics may also be missing.
Closing Thought
Article 27 has been called the GDPR's hidden obligation, and the description is fair. It attracted a fraction of the attention the data protection officer requirement received, despite catching far more companies, because it applies to organisations who by definition are not in Europe and were not reading European compliance guidance.
The uncomfortable part is that the exemption most companies assume covers them was written for something else entirely. If you run a product that processes EU user data every day, you are not processing occasionally, whatever your headcount. ComplyDog hosts a compliance portal on your own domain covering your DPA, subprocessor list, data subject request handling and security page, which is where a representative's contact details and your processing record sensibly live. It does not act as your representative, which has to be a real entity in the EU.