EUREP

GDPR representative: do you need one in the EU?

10 min readRepresenta GmbH

GDPR representative under Article 27: when a company outside the EU selling online to EU customers needs one, which exemptions apply and what it does.

Handshake between a person in a light grey blazer and a person in a dark blue shirt, with blurred office lights in the background

You make kitchen appliances in Canada and sell them through your own web shop to customers in Germany, France and Austria, with a newsletter and advertising cookies. The EU's General Data Protection Regulation (GDPR) then applies to you, and you most likely need a GDPR representative in the EU. Here is how to check, where the representative must be established and what it does.

What a GDPR representative is

The GDPR protects personal data such as names, delivery addresses, email addresses or cookie IDs (Article 4(1) of Regulation (EU) 2016/679). Your company is the controller when it decides why and how these data are processed (Article 4(7)).

A controller outside the EU that falls under the GDPR must designate in writing a representative in the Union (Article 27(1)): a person or company established in the EU that represents it with regard to its GDPR obligations (Article 4(17)). The same applies to processors, which handle data on behalf of others.

When the GDPR applies to a company outside the EU

Under Article 3(2), the GDPR covers controllers outside the EU that process data of people who are in the EU, where the processing relates to:

  • offering goods or services to them, paid or free (Article 3(2)(a)), or
  • monitoring their behavior as far as it takes place in the EU (Article 3(2)(b)).

Nationality does not matter; what counts is that the person is in the EU at the time of the offer or the tracking. That is the view of the European Data Protection Board (EDPB), the joint body of the EU's data protection authorities, in its Guidelines 3/2018 (section 2). The test runs per processing activity.

A website that people in the EU can merely reach is not enough (Recital 23); your intention to sell to them must be apparent. The EDPB lists signs that count, especially in combination:

  • an EU country named in your offer
  • a member state's language or currency, with ordering possible in it
  • delivery to EU member states
  • a domain such as .de or .eu
  • ads aimed at an audience in an EU country
  • mentions of customers in the EU

Monitoring means tracking people online, including profiling (Recital 24). The EDPB names behavioral advertising, tracking cookies and geolocation for marketing; not every data collection counts, the purpose decides. So retargeting ads aimed at EU visitors can bring even a company without a shop under the GDPR.

If you have a branch or subsidiary in the EU and the shop's processing is inextricably linked to its activities, Article 3(1) applies instead, and Article 27 does not (EDPB, section 1).

The Article 27 exemptions, and why a web shop rarely meets them

Article 27(2) knows only two exemptions. The first requires all three conditions at once:

  • the processing is occasional,
  • it includes no large-scale processing of special categories such as health data (Article 9(1)) or of criminal offence data (Article 10), and
  • it is unlikely to result in a risk to the rights and freedoms of natural persons.

The second covers public authorities. For the EDPB, processing is occasional only if it is not regular and falls outside the normal course of business (section 4(b)). A shop with daily orders, customer accounts and a newsletter fails that test. And the exemption requires that no risk is likely at all, not just no high risk.

Where your GDPR representative must be established

The representative must be established in a member state where the people are whose data you process when offering them goods or monitoring them (Article 27(3)). If you deliver only to France and Belgium, a representative in Germany does not qualify.

If a large share of your customers is in one member state, the EDPB recommends establishing the representative there, while it stays easily reachable for the others (section 4(c)). Server locations play no role, and one representative covers all your processing.

Without an EU establishment, you get no one-stop shop with a single lead authority (EDPB, section 2). Any supervisory authority may address your representative (Recital 80).

What the representative does, and what stays with you

Your representative is mandated to be addressed in addition to or instead of you, in particular by supervisory authorities and data subjects, on all processing issues (Article 27(4)). It acts under your mandate (Recital 80).

Duties of the representative and of the controller under the GDPR
DutyRepresentativeYou as controller
Contact for authorities and data subjectsReceives all inquiries (Art. 27(4))Answer and decide
Record of processing activitiesKeeps it too and provides it on request (Art. 30(1), (4))Supply and update the content (EDPB)
Cooperation with the authorityOn request (Art. 31); information when ordered (Art. 58(1)(a))Same duties
Requests for access or erasureFacilitates contact with you (EDPB)Respond within one month (Art. 12(3))
Privacy noticeNamed with contact detailsInclude it (Art. 13(1)(a), 14(1)(a))
Liability for your processingNone in your place (EDPB)Stays with you (Art. 27(5))
Duties of the representative and of the controller under the GDPR

Enforcement can still run through the representative: authorities may address corrective measures and fines imposed on you to it (Articles 58(2) and 83), and it is directly liable for its own duties under Articles 30 and 58(1)(a) (EDPB, section 4(d)).

Not a data protection officer, not a product representative

Three roles are often mixed up:

  • Data protection officer (DPO): required in the cases of Article 37(1), for example where your core activities require regular and systematic monitoring on a large scale. A DPO takes no instructions on its tasks (Article 38(3)); your representative does. The EDPB therefore considers an external DPO in the EU incompatible with the representative role, and sees a conflict if your processor takes it on.
  • EU Authorized Representative: a product law role under a written mandate (Article 3(12) of Regulation (EU) 2019/1020, Article 3(9) of the General Product Safety Regulation (EU) 2023/988). More in EU Authorized Representative or importer and who can be your GPSR Responsible Person.
  • UK representative: the UK GDPR has its own Article 27 requiring a representative in the United Kingdom. An EU representative does not cover UK customers; a separate article will follow.

One company can hold the GDPR role and a product role, but each needs its own written basis, and neither replaces the other.

How to designate your GDPR representative in six steps

  1. Map your EU-facing processing: orders, customer accounts, newsletter, cookies, warranty registrations, customer service. Check each against Article 3(2).
  2. Test the exemption: occasional, no large-scale special categories, no likely risk. If one condition fails, you need a representative (Article 27(2)(a)).
  3. Choose the member state where your customers are, ideally the one with most of them (Article 27(3)).
  4. Sign a written mandate covering all processing issues (Article 27(1), (4)). Agree how fast inquiries are forwarded, since requests must be answered within one month (Article 12(3)).
  5. Hand over your record of processing activities and keep it updated (Article 30(1)).
  6. Update your privacy notice and every point of collection with the representative's name and contact details (Articles 13(1)(a) and 14(1)(a)).

Practical example: a Canadian appliance maker with its own shop

A Canadian maker of coffee grinders sells through its own shop in English, French and German, in euros, with delivery to Germany, France and Austria. Most orders go to Germany. The shop uses retargeting cookies and a newsletter.

How the appliance maker checks whether it needs a GDPR representative
CheckFindingBasis
Offer aimed at the EU?Yes: EU languages, prices in euros, delivery to three member statesArt. 3(2)(a), Recital 23
Monitoring?Yes: retargeting cookies track visitors from the EUArt. 3(2)(b), Recital 24
Exemption?No: orders and newsletter run every dayArt. 27(2)(a), EDPB
Where?Germany, France or Austria; Germany recommendedArt. 27(3), EDPB
How the appliance maker checks whether it needs a GDPR representative

Product law applies separately: as CE-marked electrical equipment, the grinders need an EU economic operator under Article 4 of Regulation (EU) 2019/1020, such as an EU Authorized Representative. If the maker later ships to the UK, it will as a rule need a representative there too.

Common mistakes with the GDPR representative

  • “We are too small.” Article 27 has no size threshold; only the exemption in Article 27(2) counts.
  • The wrong country. The representative must be where your customers or tracked visitors are (Article 27(3)), not wherever your warehouse happens to be.
  • Your external DPO or processor as representative. The EDPB sees a conflict in both combinations.
  • No name in the privacy notice. Even with a representative designated, this breaches Articles 13 and 14.
  • The representative as a shield. You remain liable (Article 27(5)). Failing to designate one can itself be fined up to 10 million euros or, for an undertaking, 2% of worldwide annual turnover, whichever is higher (Article 83(4)(a)).

Conclusion: check your shop, then choose the country

If your shop targets people in the EU or you track their behavior, you very likely need a GDPR representative. Choose one where your customers are, designate it in writing and name it in your privacy notice. It makes you reachable; your duties as controller stay with you.

At Representa, the EU GDPR representative under Article 27 is part of Representation. We are established in Germany, which meets Article 27(3) whenever people in Germany are among those you offer goods to or monitor. We act within the agreed scope and mandate; you remain the controller. For the product side of your launch, see our EU and UK market entry checklist and our compliance consulting.

Frequently asked questions

Does a small company need a GDPR representative?

Yes, if the GDPR applies to it under Article 3(2) and no exemption fits. Article 27(2) has no threshold for size or turnover; the exemption requires occasional processing, no large-scale sensitive data and no likely risk, all at the same time.

Is a GDPR representative the same as a data protection officer?

No. The representative is a contact point acting on your instructions (Article 27(4)); a data protection officer advises and monitors without instructions (Articles 38(3) and 39). The EDPB considers an external data protection officer in the EU unable to act as your representative at the same time.

Is the representative liable for my GDPR violations?

Not in your place. Designating a representative does not affect your own responsibility and liability (Article 27(5), Recital 80). Authorities can, however, address measures and fines imposed on you to the representative, and it answers for its own duties under Articles 30 and 58(1)(a) (EDPB Guidelines 3/2018).

Does my EU representative also cover the UK?

No. The UK GDPR requires its own representative in the United Kingdom (Article 27(1) UK GDPR). If you sell to both markets, you will as a rule need one representative in the EU and one in the UK.

Will the EU simplification packages remove the representative duty?

Not according to the proposals. COM(2025) 501 would change the record-keeping exemption in Article 30(5) GDPR, and the Digital Omnibus COM(2025) 837 would amend other GDPR articles. Neither proposal changes Article 3 or Article 27.

More insights

Apply this to your product

Talk to our team: we identify which of these requirements apply to you.