EUREP

Your EU and UK GDPR Representative

If you offer goods or services to people in the EU or the UK, or track them online, without an establishment there, the EU and UK GDPR usually require a representative. We act as your contact point for authorities and individuals within the agreed mandate; you remain the controller.

Key in the lock of a white office storage cabinet

Your customers are in Europe, you are not

Your shop, app or newsletter reaches people in the EU or the UK, but your company has no office there. If Article 27 applies to you, your privacy notice must name your representative.

What applies to you

The EU GDPR and the UK GDPR each have their own Article 27.

  • The GDPR reaches beyond the EU

    It applies to companies outside the EU that offer goods or services to people in the EU or monitor their behavior there.

  • A representative, designated in writing

    You designate a representative in the EU in writing, unless processing is occasional, unlikely to result in a risk and without large-scale sensitive data.

  • Established where your customers are

    The EU representative must be established in an EU country where the people you offer goods or services to or monitor are.

  • A separate representative for the UK

    The UK GDPR has its own Article 27. If it applies to you, you also need a representative in the UK.

What we do within the agreed scope

We act as your representative under a written mandate, while you remain the controller, responsible for your processing and for answering data protection requests.

Talk to our team
  • Your EU representative

    Named in your privacy notice. We are established in Germany, which fits whenever people in Germany are among those you sell to or monitor.

  • Your UK representative

    We provide your UK GDPR representative, established in the UK as the law requires.

  • Contact for authorities and individuals

    Supervisory authorities and data subjects can contact us; we forward their requests to you and coordinate your reply.

  • Your record, ready on request

    We keep a copy of your record of processing activities and make it available to the supervisory authority on request.

  • Cooperation with authorities

    We cooperate with supervisory authorities on request and provide information they order from us as your representative.

What we need from you

  • Company details and a privacy contact person
  • Countries where your customers and users are
  • Record of processing activities
  • Current privacy notice
  • Overview of your shop, apps and tracking tools

How it works

  1. 01

    Check your setup

    We look at your sales, apps and tracking with you and check where you need representation: EU, UK or both.

  2. 02

    Mandate and records

    You sign the written mandate and send us your record of processing activities.

  3. 03

    Update your privacy notice

    You add your representative's name and contact details to your privacy notice and wherever you collect data.

  4. 04

    Ongoing contact

    We receive inquiries, forward them to you and keep your record available for authorities.

Not sure what your product needs?

Stefan HülsiggensenFounder and Managing Director

Talk to our team

Questions about the GDPR Representative

Do I need a GDPR representative?

Yes, if you have no establishment in the EU and the GDPR applies to you under Article 3(2), because you offer goods or services to people in the EU or monitor their behavior there. The only exemption for businesses is Article 27(2)(a): occasional processing, unlikely to result in a risk, without large-scale sensitive data.

Does a small company need a GDPR representative?

Article 27 sets no threshold for size or turnover. Only the exemption in Article 27(2) counts, and all its conditions must be met. For the European Data Protection Board, processing is occasional only if it is not regular and falls outside the normal course of business.

Is a GDPR representative the same as a data protection officer?

No. The representative acts on your mandate as a contact point for authorities and individuals (Article 27(4)). A data protection officer advises and monitors independently. The European Data Protection Board considers an external data protection officer unable to act as your representative at the same time.

Does my EU representative also cover the UK?

No. The UK GDPR has its own Article 27 and requires a representative in the United Kingdom, to be addressed by the UK regulator and by individuals in the UK. Since 30 September 2026, the regulator is the Information Commission, still known as the ICO, which replaced the Information Commissioner.

Does the representative take on my liability?

No. Designating a representative does not affect your own responsibility and liability, and legal action against you remains possible (Article 27(5), Recital 80). Recital 80 also provides that the representative should be subject to enforcement proceedings if the controller does not comply.

Insights on this topic

Set up your GDPR representation

Tell us where your customers are, and we set up your representation in the EU, the UK or both.

Get in touch with our team of experts

Tell us what you manufacture and where you want to sell. We identify the requirements for EU and UK market access and come back to you with the next steps.

Target market *

* Required