If your company is outside the EU and you have users, customers, or app installs inside it, Article 27 applies to you. No revenue threshold, no small-company exemption. One EU customer whose data you handle is enough.
The way this usually surfaces: an enterprise prospect sends a data protection questionnaire, one line asks who your EU representative is, and the deal stalls while somebody works out that the answer is nobody.
Establishment, not an address
The representative has to be established in a member state where your data subjects are, and the EDPB reads establishment as requiring genuine presence. A virtual office or a mail-forwarding arrangement is unlikely to hold up under scrutiny.
The other half of the problem arrives with the first real letter. The representative is the addressable party in the EU for anything concerning your processing. When an access request comes in, or a supervisory authority opens an enquiry, a forwarding service can pass it along. It cannot answer it, and by then you are hiring a lawyer under deadline pressure.
What you get
An assessment of whether Article 27 genuinely applies to you, documented before anything is signed. If you do not need a representative, I will tell you.
The designation executed properly and in writing, as Article 27(1) requires.
Your privacy notice updated so data subjects can actually find the representative.
Authority and data subject contact answered on substance, not forwarded to you with a covering note.
Transfers, retention, and sub-processor records addressed if they need it, rather than referred out.
Fees are a flat annual amount, scoped to the engagement and quoted after the first call.
The obligation, briefly
Article 27 requires controllers and processors with no EU establishment, caught by Article 3(2) because they offer goods or services to people in the EU or monitor their behaviour, to designate a representative in the Union in writing. Enforceable since 25 May 2018. Failure to designate falls under Article 83(4)(a), with fines up to EUR 10 million or two percent of worldwide annual turnover, whichever is higher.
Questions I get asked
Does the occasional-processing exemption cover us?
Almost certainly not. It exempts processing that is genuinely incidental, outside the core commercial purpose of the business. If you handle customer, user, or employee data as part of how the company runs, you are not exempt.
We have a subsidiary in Europe. Does that count?
Possibly, and this is worth getting right rather than guessing. If your processing is carried out in the context of an EU establishment's activities, you fall under Article 3(1) and no representative is required. The EDPB reads establishment broadly, so a genuine European entity can be enough. Where the subsidiary has nothing to do with the processing in question, the position is less clear. It is one of the few questions here that turns on your actual facts.
We already have a DPO. Isn't that the same thing?
No, and they cannot be the same provider. A DPO advises and monitors internally. A representative is an external contact point for regulators and data subjects. The EDPB has stated that an external DPO should not also act as representative for the same client, because the two roles conflict. You can need both, but not from one place.
We sell into the UK as well.
Then you need two appointments. An EU representative does not cover the UK, and a UK representative does not cover the EU.
If a customer has asked who your EU representative is and you do not yet have an answer, I'd be glad to hear what's on your desk. Book a 30-minute call
Reviewed August 2026.