GDPR Representative Under Article 27: Who Needs One, Who’s Exempt, and How to Appoint

The short answer: if your company has no establishment in the EU but offers products or services to people in the EU — or monitors their behaviour (analytics counts) — Article 27 of the GDPR requires you to appoint an EU representative: a named contact point in an EU member state, listed in your privacy notice. Most non-EU SaaS and AI startups with EU users are in scope. Skipping it carries fines of up to €10 million or 2% of global turnover — and, more practically, it’s a question that now appears in almost every enterprise procurement review.

What an EU representative actually is

The representative is your company’s official point of contact in the EU for two audiences: data protection authorities and data subjects (your users). The representative:

  • is named, with an EU address, in your privacy notice;
  • receives and forwards regulator correspondence and user requests;
  • keeps a copy of your Article 30 record of processing activities;
  • must be established in one of the member states where your users are.

What the representative is not: a DPO (different role, different article — you may need both, and they shouldn’t be the same person for conflict-of-interest reasons), a shield from liability (authorities can still enforce against you directly), or an EU subsidiary (no entity needed — that’s the point).

Do you need one? The three-question test

1. Do you have an establishment in the EU? A real one — an entity, branch, or stable arrangement. If yes, Article 27 doesn’t apply to you (Article 3(1) applies instead). A Delaware C-corp with no EU entity: keep reading.

2. Does GDPR apply to you extraterritorially (Article 3(2))? Two triggers:

  • Offering goods or services to people in the EU — even free ones. Signals: EU users can sign up, you price in EUR, you ship to the EU, your marketing reaches EU audiences.
  • Monitoring behaviour of people in the EU — tracking cookies, session recording, personalisation, behavioural analytics, training models on user interactions. This is the trigger startups miss. The regulators’ reading: “monitoring” means tracking people with a purpose — behavioural analysis, profiling, personalisation — and a typical product-analytics stack pointed at EU users does exactly that.

3. Do you qualify for the exemption? Article 27(2) exempts processing that meets all three of the following, cumulatively: it is occasional; it does not include large-scale processing of special-category data (Article 9) or criminal-offence data (Article 10); and it is unlikely to result in a risk to the rights and freedoms of individuals. In practice this is a narrow door: a SaaS with ongoing EU users processes continuously, not occasionally. If you’re checking whether you fit the exemption, you usually don’t.

Verdict for a typical AI/SaaS startup with EU users and no EU entity: you need a representative.

The AI-startup angle: why your risk profile is higher

Two things make Article 27 more pointed for AI companies:

  • Training data and special categories. If user content flows into model training, the odds that Article 9 data (health, biometrics, political opinions…) passes through your systems rise sharply — which both kills the exemption and raises the “risk to individuals” factor.
  • The AI Act parallel. From the AI Act side, non-EU providers of high-risk AI systems must appoint an authorised representative in the EU as well (a separate role under Article 22 of the AI Act, with the deadline effectively aligned to the high-risk obligations — now December 2, 2027 after the Omnibus). And note: the 2026 Digital Omnibus on AI moved AI Act dates only — it changed nothing in the GDPR, so Article 27 applies today, unchanged. Getting your GDPR representation right now builds the same muscle you’ll need there. See our EU AI Act timeline.

What happens if you ignore it

  • The fine: up to €10M or 2% of worldwide annual turnover (Article 83(4)). Standalone Article 27 fines are rare — but authorities increasingly cite a missing representative as an aggravating factor in broader enforcement, and the Dutch DPA has fined a non-EU company specifically for it (LocateFamily.com — €525,000 for operating without an EU representative).
  • The commercial reality (arrives first): enterprise buyers’ DPAs and security questionnaires ask for your EU representative’s name and address. “We don’t have one” reads as “we haven’t done GDPR at all.” Deals stall on this.
  • The user-facing gap: your privacy notice is formally deficient without the representative’s details — visible to anyone who checks, including competitors and complainants.

How to appoint one (a 1-week process)

  1. Choose the member state. It must be one where your affected users are. If you work with a law firm, their jurisdiction usually decides — Luxembourg, Ireland, and the Netherlands are common picks for English-speaking startups.
  2. Sign a written mandate. A service agreement authorising the representative to act under Article 27.
  3. Update your privacy notice. Name, EU address, contact details of the representative (Articles 13/14 require it).
  4. Wire the workflow. Forwarding rules for authority letters and data-subject requests, and a current copy of your Article 30 records with the representative.

Cost benchmark: professional representative services run from a few hundred to a couple of thousand euros per year — one of the cheapest compliance line items you’ll ever buy relative to the risk it retires.

FAQ

Do I need a GDPR representative if I have no EU office?

That’s exactly when you need one: Article 27 applies to controllers and processors without an EU establishment whose processing falls under Article 3(2) — offering goods/services to, or monitoring, people in the EU.

Is a GDPR representative the same as a DPO?

No. The DPO (Articles 37–39) is an internal oversight role; the representative (Article 27) is your EU-based contact point. You may need both, and best practice is that they’re different people.

We only have a few EU users. Are we exempt?

Only if your processing is genuinely occasional, involves no large-scale special-category or criminal-offence data, and is low-risk — all three at once. Ongoing product usage by EU customers is not occasional. Few operating startups qualify.

Does the UK need a separate representative?

Yes — post-Brexit, UK GDPR has its own Article 27. If you serve both markets without establishments in either, you need an EU representative and a UK representative.

What’s the penalty for not appointing one?

Up to €10 million or 2% of global annual turnover, whichever is higher — plus the aggravating-factor effect in any wider GDPR enforcement.

Can our law firm be our representative?

Yes, if it’s established in a relevant member state and takes the mandate in writing. Bundling representation with your broader EU compliance (privacy notice, Article 30 records, DPAs) is usually the efficient setup.

Appoint your EU representative this week

Montaire & Co. provides GDPR Article 27 representation from Luxembourg as a fixed-fee service: mandate, privacy-notice language, request-handling workflow — live in days, bundled with our EU market-entry stack if you need more.

30 minutes · senior advisor · no charge, no obligation

General information, not legal advice. Status as of July 16, 2026.