GDPR Article 27: Representative for non-EU controllers or processors
GDPR Article 27 Explained
Any controller or processor who:
- Is not established in the EU, but
- Offers goods or services to individuals in the EU, or monitors their behaviour,
must appoint in writing a representative in a Member State where the data subjects are located.
This representative acts as a point of contact for supervisory authorities (e.g., the French supervisory authority) and for data subjects.
Why is this article important for your GDPR compliance?
It ensures that European authorities can enforce GDPR, even with regard to actors established outside the EU. This is an essential legal obligation for international companies operating in the European market.
Examples of GDPR Article 27 Application
- An American e-commerce company sells in France: it appoints a GDPR representative based in Paris.
- A Canadian mobile application tracks the behaviour of German users: it designates a representative in Berlin.
- A Chinese online services platform, active in Spain, engages a Spanish GDPR firm as its representative.
Related Resources
Accelerate your compliance in a few clicks
Thanks to our all-in-one solution, you can accelerate and ensure your compliance easily:
- Automate your compliance with our GDPR software
- Supported or outsourced by our DPO experts
- Raise awareness among your teams with our GDPR training e-learning
How to comply with Article 27 of the GDPR?