GDPR Article 27: Representative of Controllers or Processors Not Established in the Union

Analysis — A comprehensive examination of jurisdictional accountability, enforcement mechanisms, and governance obligations for non-EU organisations processing personal data of EU individuals.

Overview

GDPR Article 27 establishes the obligation for certain non-EU/EEA controllers and processors to designate a representative within the European Union when they process personal data of individuals located in the EU under the territorial scope established by Article 3(2).

Failure to appoint a representative does not remove GDPR applicability. GDPR obligations continue to apply — the absence of a representative merely creates an additional compliance violation.

Core Functions of Article 27

Legal Nexus

Creates an enforceable legal nexus between non-EU organisations and EU supervisory authorities.

Regulatory Oversight

Ensures practical regulatory oversight where a controller or processor lacks physical EU establishment.

Enforcement Bridge

Facilitates enforcement, communication, investigations, and data subject rights exercise.

Textual Structure of Article 27

1

Article 27(1): Core Appointment Requirement

Controllers and processors not established in the Union must designate a representative where Article 3(2) applies. The representative must be established in one of the Member States where affected data subjects are located.

2

In-Scope Practical Example

A U.S.-based SaaS provider offers services to German, French, and Dutch customers with no EU offices. The website accepts Euros and EU customers are actively targeted. GDPR applies under Article 3(2)(a) — Article 27 representative required.

3

Out-of-Scope Practical Example

A U.S. university website is publicly accessible globally with no EU targeting, no EU marketing, no EU admissions campaigns, and no EU student recruitment activities. Mere accessibility does not trigger Article 3(2) — Article 27 representative not required.

This determination flow guides practitioners through the Article 27 applicability analysis, ensuring that the threshold question of territorial scope is resolved before the representative obligation is assessed.

Article 27(2): Exceptions

Article 27 contains a narrow exemption. All elements must generally be satisfied simultaneously for the exemption to apply.

Occasional Processing

Processing must be genuinely occasional — not systematic, regular, or continuous in nature.

No Large-Scale Special Category Data

Must not include large-scale processing of special category data under Article 9.

No Large-Scale Criminal Data

Must not include large-scale processing of criminal offence data under Article 10.

Low Risk to Rights

Processing must be unlikely to result in a risk to the rights and freedoms of natural persons.

Potentially Exempt

Small Consultancy Example

A small U.S. engineering consultancy receives personal data from one EU customer once per year — minimal employee contact information, no profiling, no large-scale processing. A potential exemption may apply.

Representative Required

HR Technology Platform Example

A U.S.-based HR technology platform processes employee performance records, serves multiple EU organisations, and engages in ongoing data collection. The exemption does not apply — a representative is required.

Articles 27(3), 27(4) & 27(5): Mandate, Contact Point & Enforcement

Article 27(3): Written Mandate

The representative must be designated in writing. The mandate should define authority, communication responsibilities, record maintenance obligations, supervisory authority interaction responsibilities, data subject interaction responsibilities, and escalation processes.

Article 27(4): Contact Point Function

The representative serves as a contact point for supervisory authorities, data subjects, investigations, and compliance inquiries. The representative does not replace the controller or processor — liability remains primarily with the controller or processor.

Article 27(5): Enforcement

Appointment of a representative does not affect enforcement actions against the controller or processor. Supervisory authorities may pursue the representative, controller, processor, or multiple parties simultaneously.

Primary GDPR Articles Intersecting with Article 27

Foundational Intersections

Article 3 – Territorial Scope

Article 3 determines whether GDPR applies; Article 27 determines whether a representative is required. Inseparable in analysis.

Article 4 – Definitions

Personal data, processing, controller, processor, and establishment are all foundational to Article 27 applicability.

Article 5 – Principles

The representative becomes the practical interface for demonstrating compliance with all nine processing principles including accountability.

Article 6 – Lawful Basis

Representative inquiries often concern legal basis documentation, consent evidence, and legitimate interest assessments.

Data Subject Rights (Articles 12–23)

The representative frequently receives requests regarding all data subject rights:

Access

Article 15 requests routed through the representative.

Rectification

Article 16 correction requests.

Erasure

Article 17 right to be forgotten.

Restriction

Article 18 processing restriction.

Portability

Article 20 data portability.

Objection

Article 21 right to object.

Extended GDPR Article Intersections

01

Article 24 – Controller Responsibility

Accountability framework — the representative operationalises the controller's accountability obligations in the EU jurisdiction.

02

Article 25 – Privacy by Design

Demonstration of privacy engineering maturity is often channelled through the representative during supervisory engagement.

03

Article 28 – Processor Obligations

Closely linked where a non-EU processor requires representation alongside its processor agreement obligations.

04

Article 30 – Records of Processing

Representatives frequently maintain or facilitate access to records of processing activities on behalf of the controller or processor.

05

Articles 33 & 34 – Breach Notification

Supervisory authority engagement for breach notification is frequently routed through the representative channel.

06

Article 35 – DPIAs

High-risk processing inquiries commonly involve DPIA review facilitated through the representative.

Entangled Risk Domains

Article 27 non-compliance does not exist in isolation — it creates cascading exposure across multiple interconnected risk domains that privacy practitioners must assess holistically.

Each risk domain represents a distinct exposure pathway. Mature privacy programmes map these domains to specific controls, owners, and monitoring mechanisms within their enterprise risk management frameworks.

Extended Risk Domains

Cybersecurity Risk

External compromise, ransomware, and credential theft can expose personal data processed by non-EU organisations, triggering Article 27 representative engagement with supervisory authorities.

Identity & Access Management Risk

Unauthorised access to personal data systems creates both security and privacy exposure requiring representative-facilitated regulatory response.

Data Lifecycle Risk

Excessive retention and improper disposal of personal data create ongoing compliance exposure that the representative must be equipped to address.

Transparency Risk

Inadequate privacy notices and insufficient disclosures are frequently surfaced through the representative channel by data subjects and supervisory authorities.

Artificial Intelligence Risk

Profiling and automated decision-making activities create heightened scrutiny, with the representative serving as the primary regulatory interface for AI-related inquiries.

Records Risk

Records Management

Missing Article 30 records of processing activities represent a direct compliance failure that supervisory authorities may identify through the representative.

Incident Risk

Incident Management

Delayed breach notifications routed through an unprepared representative create compounded regulatory exposure under Articles 33 and 34.

Strategic Risk

Reputational & Strategic

Loss of trust after compliance failures and market access restrictions within the EU represent the ultimate strategic consequence of Article 27 non-compliance.

Twenty Cross-Cutting Technical Controls: Governance & Documentation

Supporting Article 27 compliance requires a structured control architecture spanning governance, documentation, technical, and operational domains. The first ten controls address foundational governance and documentation requirements.

Governance Controls
1

Applicability Assessment Methodology

Formal Article 27 applicability assessment methodology to determine representative obligation triggers.

2

Representative Appointment Policy

Documented policy governing the selection, appointment, and management of Article 27 representatives.

3

Board-Level Accountability Framework

Board-level GDPR accountability framework ensuring senior ownership of Article 27 obligations.

4

Controller/Processor Classification

Documented controller/processor classification process to determine the nature of the representative obligation.

5

Regulatory Engagement Procedure

Formal procedure governing how the organisation engages with EU supervisory authorities through the representative.

Documentation Controls
1

Article 27 Designation Register

Centralised register recording the designation of representatives across all relevant jurisdictions.

2

Representative Mandate Management

Process for creating, maintaining, and updating written representative mandates in accordance with Article 27(3).

3

Article 30 Record Management

System for maintaining records of processing activities accessible through the representative channel.

4

Regulatory Correspondence Repository

Secure repository for all regulatory correspondence received and sent through the representative.

5

Evidence Preservation Framework

Framework for preserving compliance evidence in anticipation of supervisory authority investigations.

Twenty Cross-Cutting Technical Controls: Data Governance, Technical & Operational

Data Governance Controls

  • Enterprise data inventory
  • Data mapping architecture
  • Data flow documentation
  • Data classification scheme
  • Data retention management programme

Technical Controls

  • Identity and access management
  • Centralised audit logging
  • SIEM monitoring
  • Data loss prevention technologies
  • Encryption at rest and in transit
  • Privacy request workflow automation

Operational Controls

  • Regulatory inquiry response playbooks
  • Supervisory authority communication workflow
  • Incident escalation procedures
  • Breach notification workflow
  • Representative escalation matrix

Twenty Cross-Cutting Technical Controls: Privacy Engineering & Assurance

Privacy Engineering Controls

Privacy by Design Review Gates

Embedded review checkpoints ensuring privacy considerations are addressed at each stage of system and product development.

DPIA Workflow Integration

Integrated Data Protection Impact Assessment workflows for high-risk processing activities, accessible through the representative.

Automated Retention Enforcement

Technical enforcement of data retention schedules to prevent excessive retention violations.

Consent Management Systems

Platforms for capturing, recording, and managing consent evidence in support of lawful basis documentation.

Cross-Border Transfer Monitoring

Continuous monitoring of international data transfers to ensure ongoing compliance with Articles 44–49.

Assurance Controls

Internal Compliance Audits

Regular internal audits assessing the effectiveness of Article 27 compliance arrangements and representative performance.

Representative Effectiveness Reviews

Periodic reviews of the representative's capacity, responsiveness, and mandate adherence.

Independent GDPR Assessments

Third-party assessments providing objective assurance over the organisation's GDPR compliance posture.

Control Testing Programmes

Structured testing of key controls supporting Article 27 obligations to verify design and operating effectiveness.

Management Review Process

Senior management review of compliance metrics, incidents, and representative performance on a regular cycle.

Scope Analysis: What Is In and Out of Scope for Article 27

Advanced Practitioner Teaching Points

Expert Guidance

What Article 27 Is Not

Article 27 is not a privacy notice requirement, not a security control, not a transfer mechanism, not a lawful basis, and not equivalent to appointing a DPO. These are the most common practitioner misconceptions.

What Article 27 Is

Article 27 is fundamentally an accountability, accessibility, and enforceability mechanism. The representative is a visible manifestation of compliance accountability — not the compliance programme itself.

The Governance Node Model

Mature organisations treat Article 27 as a governance node connecting territorial scope analysis, accountability obligations, regulatory engagement, data subject rights management, records management, breach response, international transfer governance, privacy engineering, and security assurance.

Integration into Advanced Privacy Operating Models

Enterprise Governance Frameworks

Three-Lines-of-Defence Models

GRC Platforms

Data Governance Programmes

Third-Party Risk Management

Security Operations

Viewed holistically, Article 27 is the operational bridge that allows the GDPR's extraterritorial reach under Article 3 to be translated into practical supervision, accountability, and enforcement across global data ecosystems.

United Kingdom and the EU

Understanding the post-Brexit landscape and what it means for EU GDPR compliance — a critical distinction for every UK organisation.

Post-BrexitEU GDPRArticle 27

The Short Answer

No. The United Kingdom left the European Union on 31 January 2020 following Brexit.

Transition Period

The Brexit transition period ended on 31 December 2020. Since 1 January 2021, the UK is considered a "third country" under EU GDPR.

Third Country Status

UK organisations are now treated similarly to those in the United States, Canada, Australia, Singapore, India, or other non-EU jurisdictions.

Does GDPR Still Apply to UK Companies?

Yes — often. Brexit did not remove GDPR obligations from UK companies that interact with EU individuals. A UK company may simultaneously be subject to multiple regimes.

1

UK GDPR Only

Purely domestic operations with no EU-facing activities

2

EU GDPR Only

Non-UK entity targeting UK individuals exclusively

3

Both Regimes

UK company with EU-facing goods, services, or monitoring activities

The applicable regime depends entirely on the company's activities. Determining which regime applies is the essential first step before any Article 27 analysis.

The Key Trigger: GDPR Article 3

A UK company falls under EU GDPR when it offers goods or services to individuals in the EU, or monitors the behaviour of individuals located in the EU. Both triggers are assessed independently — satisfying either one is sufficient to engage EU GDPR obligations.

Example: UK Company Not Subject to EU GDPR

Scenario

A London accounting firm serves only UK businesses.

  • No EU clients
  • No EU marketing
  • No EU employees
  • No EU website targeting

Outcome

UK GDPR

Applies — domestic operations are fully within scope.

EU GDPR

Does not apply — no EU-facing activities identified.

Article 27

Does not apply — EU GDPR is not engaged.

Example: UK Company Subject to EU GDPR

Scenario

A Manchester software company sells subscriptions to customers in Germany and France.

  • Website available in German
  • Prices displayed in Euros
  • Active EU marketing campaigns

Outcome

EU GDPR Applies

Triggered under Article 3(2)(a) — offering services to EU individuals.

UK GDPR Also Applies

Dual regime compliance is required simultaneously.

Article 27 Required

An EU representative must be appointed.

Example: UK Company Monitoring EU Individuals

Scenario

A UK-based advertising technology company tracks online behaviour of users in Spain, Italy, and the Netherlands using cookies for profiling and targeted advertising.

Outcome

EU GDPR Applies

Triggered under Article 3(2)(b) — monitoring behaviour of EU individuals.

Article 27 Required

An EU representative must be appointed without exception.

Article 27 Analysis for UK Organisations

After Brexit, a UK company must work through a structured assessment to determine whether an EU representative is required.

Are we established in the EU?

If yes, Article 27 generally does not apply. If no, continue the assessment.

Are we offering goods or services to EU individuals?

Indicators include: shipping products into the EU, marketing to EU residents, accepting Euro payments, or providing EU language support.

Are we monitoring EU individuals?

Includes: behavioural advertising, profiling, analytics tracking, location tracking, and device fingerprinting.

Does the Article 27 exemption apply?

Processing must be occasional, low risk, not large-scale special category, and not large-scale criminal offence processing. Most commercial businesses fail this exemption.

UK Representative vs EU Representative

EU GDPR Article 27 Representative

Purpose

Represents non-EU organisations before EU supervisory authorities and acts as the primary point of contact for data subjects and regulators.

Location Requirement

Must be located in an EU Member State — a UK-based entity cannot fulfil this role post-Brexit.

Triggered By

EU GDPR Article 3(2) — the extraterritorial reach provision covering non-EU established organisations.

Practical Example

A UK company targeting French consumers must appoint an EU representative located within an EU Member State.

UK GDPR Representative

Purpose

Represents non-UK organisations before the UK regulator (the ICO) and acts as the contact point for UK data subjects and enforcement.

Location Requirement

Must be located in the United Kingdom — an EU-based entity cannot fulfil this role.

Triggered By

UK GDPR extraterritorial provisions — mirroring the structure of EU GDPR Article 3(2) but applied to the UK jurisdiction.

Practical Example

A US company targeting UK consumers must appoint a UK representative located within the United Kingdom.

Dual Representation Scenario

Many multinational organisations require both a UK representative and an EU representative simultaneously. This is one of the most practically significant post-Brexit compliance challenges.

Example: UK Ecommerce Company

Sells to UK customers, German customers, and French customers across a single platform.

Potential Requirements

UK GDPR Compliance

Required for UK customer data processing.

EU GDPR Compliance

Required for German and French customer data processing.

UK Representative

May not be needed — company is already established in the UK.

EU Representative

Likely required — company is not established in the EU.

When a UK Company May Not Need an EU Representative

EU Establishment Example

A UK parent company with a subsidiary in Ireland may satisfy establishment requirements, depending on the operational structure. The Irish establishment may mean Article 27 does not apply.

Important Caveat

Mere incorporation is not enough. Regulators examine actual operational establishment. Relevant factors include:

  • Employees based in the EU
  • Decision-making authority exercised in the EU
  • Business activities conducted in the EU
  • Stable and effective arrangements in the EU

High-Risk Areas for UK Companies

UK organisations frequently underestimate their Article 27 exposure. These sectors often engage in continuous EU-facing processing, making the Article 27 exemption unavailable.

SaaS & Cloud

Platforms and cloud services with EU subscribers

FinTech & InsurTech

Financial and insurance technology serving EU customers

AdTech & MarTech

Advertising and marketing technology tracking EU users

Ecommerce

Online retail platforms selling into EU markets

Online Education

EdTech platforms with EU student enrolments

AI Services

AI and machine learning services processing EU personal data

Healthcare Technology

Health tech platforms handling EU patient or user data

Recruitment & HR

Platforms processing EU candidate or employee data

Relationship Between Article 27 and Data Privacy

For UK companies, Article 27 creates a governance bridge between UK operations and the EU data protection framework.

The representative becomes the operational contact point for data subject access requests, erasure requests, regulatory investigations, compliance inquiries, record-of-processing requests, and breach-related communications.

Advanced Practitioner Conclusion

Post-Brexit Compliance Sequence

Determine EU GDPR Applicability

Assess whether EU GDPR applies under Article 3 based on the organisation's activities.

Assess EU Establishment

Determine whether the organisation has a genuine, operational EU establishment that would preclude Article 27.

Assess the Article 27 Exemption

Evaluate whether the narrow exemption applies — most commercial businesses will not qualify.

Appoint an EU Representative

If required, appoint a representative located in an EU Member State and document the appointment.

Maintain Article 30 Records

Keep records of processing activities aligned with Article 30 obligations.

Align Broader Governance

Align Article 27 governance with Articles 5, 24, 25, 30, 32, 33, 35, and 44–49.

Independently Assess UK GDPR

Compliance with one regime does not automatically satisfy the other. Both must be assessed independently.

The most important takeaway for advanced practitioners is that Brexit did not eliminate EU GDPR obligations for UK companies. It transformed the UK into a third country, making Article 27 significantly more relevant to many UK organisations than it was before 2021.

Datari Home