EU GDPR REPRESENTATIVE

EU GDPR Representative
for Non-EU Organisations

Article 27 representation for controllers and processors subject to the GDPR under Article 3(2) without an establishment in the European Union.

OSTRAI acts as EU GDPR Representative for international organisations requiring a representative in the Union.

Our service combines Article 27 assessment, formal appointment, a dedicated European contact point, Article 30 arrangements, regulatory communications and continuing representation, backed by substantive regulatory expertise.

Not sure whether Article 27 applies? Start with the scope assessment.

ARTICLE 27 DECISION ARCHITECTURE

The route to
representation.

A processing-specific assessment.

Not established in the Union

Does Article 3(2) apply to the relevant processing?

Offering goods or services

to data subjects in the Union

OR

Monitoring behaviour

where behaviour takes place in the Union

If neither applies: no Article 27 appointment required for that processing.

IF ARTICLE 3(2) APPLIESDoes an Article 27(2) exemption apply?

If no

EU Representative
required

If yes

No Article 27
appointment required

for the relevant processing

TERRITORIAL SCOPE

When does Article 27 GDPR apply?

For a controller or processor not established in the Union, Article 3(2) covers processing relating to offering goods or services to data subjects in the Union, irrespective of payment, or monitoring their behaviour within the Union.

If Article 3(2) applies, Article 27 generally requires designation of a representative in the Union unless an Article 27(2) exemption applies.

The analysis is processing-specific. Mere accessibility of a website from the EU is not, by itself, the Article 3(2) test.

EXEMPTIONS

The exemption is narrow and fact-specific.

Organisation size alone does not determine whether the exemption applies.

Article 27(2)(a): all three conditions together

  1. Processing is occasional;

  2. does not include, on a large scale, processing of special categories of personal data under Article 9(1) or personal data relating to criminal convictions and offences under Article 10;

  3. is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account the nature, context, scope and purposes of the processing.

Public authorities or bodies are exempt under Article 27(2)(b).

Not sure how Article 3(2) applies to your organisation?

Request an Article 27 scope assessment

ESTABLISHMENT

The representative must be established in an appropriate Member State.

Article 27(3) requires the representative to be established in one of the Member States where the relevant data subjects are located in connection with the offering of goods or services or monitoring covered by Article 3(2).

OSTRAI Limited is established in Cyprus, within the European Union.

Whether Cyprus is an appropriate Member State for a particular Article 27 appointment is assessed against the organisation's relevant European processing footprint.

Where a significant proportion of relevant data subjects are located in a particular Member State, the EDPB recommends taking that concentration into account when choosing the representative's location.

More than
an EU address.

Article 27 requires an accessible representative in the Union. Effective representation also depends on what happens when a data subject, supervisory authority or regulatory issue reaches that representative.

OSTRAI combines the formal mandate with defined communication and escalation arrangements, Article 30 processes, regulatory experience and access to substantive privacy expertise where required.

YOUR REPRESENTATION SERVICE

A functioning regulatory interface.

  1. Dedicated representative email

    A dedicated client-specific OSTRAI representative email address for the organisation, providing a clear representative contact for publication in applicable privacy information and for communications relating to the mandate.

  2. Designated lead contact

    A defined OSTRAI contact coordinates the representative mandate, communications and material escalations. This reflects the EDPB recommendation to assign a lead contact for each represented organisation.

  3. Formal written mandate

    Article 27 appointment documentation defining the representative relationship, responsibilities and operational contacts.

  4. Privacy notice support

    Representative identity and contact wording for inclusion in applicable Articles 13 and 14 transparency information.

  5. Article 30 arrangements

    A process for maintaining and making available the applicable Article 30 record on the basis of accurate and updated information supplied by the represented organisation.

  6. Data-subject communications

    Receipt, logging and escalation of communications addressed to the representative.

  7. Supervisory authority interface

    Receipt and coordination of communications from relevant supervisory authorities.

  8. Escalation procedure

    Defined contacts and procedures for urgent, material or time-sensitive regulatory matters.

  9. Ongoing mandate review

    Periodic review of relevant entity details, contacts, EU activities and material changes affecting the representation mandate.

Need to appoint an EU GDPR Representative?

Discuss the mandate with OSTRAI

THE REPRESENTATIVE FUNCTION

A clear point of connection.

Data subjects

Supervisory authorities

OSTRAI

EU GDPR Representative

  • Dedicated contact
  • Article 30 interface
  • Communications
  • Escalation
  • Regulatory cooperation

Represented organisation

Controller or processor

Under Article 27(4), the representative may be addressed, in addition to or instead of the controller or processor, by supervisory authorities and data subjects on issues related to the relevant processing, for the purposes of ensuring GDPR compliance.

REGULATORY INTERFACE

What happens when OSTRAI
receives a communication?

  1. Receive

    Communication reaches the organisation's dedicated representative channel.

  2. Log

    The matter is recorded and linked to the representation mandate.

  3. Assess

    OSTRAI identifies the nature of the communication, relevant deadline and regulatory significance.

  4. Escalate

    The appropriate client contacts are notified under the agreed escalation procedure.

  5. Coordinate

    Relevant information, documentation and response responsibilities are coordinated.

  6. Respond / facilitate

    OSTRAI facilitates the required communication with the data subject or supervisory authority in accordance with the mandate.

  7. Record

    The matter and relevant follow-up are retained within the representation process.

Where a matter requires substantive advisory work outside the representative mandate, that work can be separately scoped.

ACCESSIBILITY

The representative must be genuinely accessible.

The representative must be in a position to communicate efficiently with relevant data subjects and cooperate with supervisory authorities concerned.

The EDPB states that communications should in principle take place in the language or languages used by the relevant supervisory authorities and data subjects. Where this would involve disproportionate effort, other means and techniques should ensure effective communication.

Language requirements are considered during onboarding and appropriate communication arrangements are established for the relevant mandate.

LEGAL & REGULATORY PRACTICE

Representation backed by substantive regulatory experience.

OSTRAI's representative service sits within a specialist regulatory practice with substantive legal and privacy expertise, rather than operating as a standalone administrative forwarding service.

Our work in privacy and data protection includes regulatory analysis, governance, data-subject rights, cross-border processing, supervisory-authority engagement and implementation.

Our wider technology-regulation work places representation issues in the context of cybersecurity, artificial intelligence, digital regulation and technology products where relevant.

Explore Privacy & Data

CONTROLLED ACCEPTANCE

We determine the regulatory position before accepting the mandate.

OSTRAI does not treat Article 27 appointment as an automated registration exercise.

Before accepting a mandate, we consider the organisation's establishment, relevant processing activities, Article 3(2) territorial scope, Article 27 exemptions, European processing footprint and the operational arrangements required for effective representation.

The regulatory position determines the engagement.

Discuss whether representation is required

ONBOARDING

Representation Readiness Review

As part of onboarding, OSTRAI establishes the operational basis of the mandate.

Article 3(2)
Basis for territorial application
Article 27
Representative requirement and exemption analysis
Represented entity
Correct controller or processor entity
EU footprint
Relevant markets and data-subject locations
Privacy information
Representative disclosures under Articles 13 and 14
Article 30
Record availability and maintenance process
Communications
Data-subject and authority contact routes
Escalation
Named operational contacts and response arrangements
Regulatory history
Relevant open complaints, authority correspondence or material matters where applicable

APPOINTMENT

From territorial scope
to continuing representation.

  1. Scope

    Article 3(2) and Article 27 analysis

  2. Readiness

    Processing profile, markets, documentation and communication arrangements

  3. Mandate

    Written appointment and operating contacts

  4. Activation

    Dedicated representative contact, privacy-notice information and Article 30 process

  5. Representation

    Continuing communications, regulatory interface and mandate maintenance

Discuss your Article 27 appointment

RESPONSIBILITY

Representation does not
transfer GDPR responsibility.

Controller / processor

Underlying GDPR responsibility

EU GDPR Representative

Article 27 interface in the Union

Separate role

DPO

Independent data-protection governance role where required

The written representative mandate does not transfer the controller's or processor's underlying responsibility or liability under the GDPR. The designation is also without prejudice to legal action against the controller or processor.

The EDPB does not consider the EU Representative function compatible with acting as the same organisation's external DPO because the representative acts under mandate and instructions whereas the DPO must perform its role independently.

Article 30: a maintained regulatory record

The EDPB considers maintenance of the applicable Article 30 record a joint operational responsibility: the represented controller or processor must provide accurate and updated information, while the representative must be in a position to maintain and make the relevant record available as required.

TERRITORIAL FRAMEWORKS

EU and UK representation are separate appointments.

EU GDPR Representative and UK GDPR Representative requirements arise under separate legal frameworks. An EU Article 27 appointment does not, by itself, satisfy a UK representative requirement.

OSTRAI treats EU Regulatory Representation and UK Regulatory Representation as distinct services. UK GDPR Representative services are provided through PRIVACY MINDERS (UK) LIMITED, a UK-established company.

Explore EU Regulatory Representation

WHY OSTRAI

Why organisations appoint
OSTRAI as EU Representative

OSTRAI combines representative infrastructure with substantive regulatory judgement and direct access to the team handling the mandate.

Scope before appointment
We first determine whether Article 27 representation is actually required.
Dedicated contact
Each mandate has a dedicated client-specific OSTRAI representative email address.
Designated lead
A defined OSTRAI contact coordinates the representative relationship.
Regulatory experience
Representation is backed by substantive experience in privacy, regulatory engagement, cross-border compliance and implementation.
Defined escalation
Clear procedures govern data-subject, supervisory-authority and material regulatory communications.
Cross-regulatory view
Privacy issues can be assessed in the context of wider European technology regulation where relevant.

OSTRAI works with internationally operating organisations on privacy, regulatory representation, supervisory matters, governance and wider European technology-regulation issues.

QUESTIONS & ANSWERS

EU GDPR Representative:
the key questions.

Who needs an EU GDPR Representative?

Controllers or processors not established in the Union whose relevant processing falls within Article 3(2) must designate a representative in writing, unless an Article 27(2) exemption applies.

Do all non-EU companies need a GDPR representative?

No. Article 3(2) is processing-specific. Website accessibility alone is insufficient; the offering or monitoring criteria and Article 27 exemptions must be assessed.

Do UK companies need an EU GDPR Representative after Brexit?

A UK organisation without an EU establishment may require representation where Article 3(2) applies to its relevant processing and no Article 27(2) exemption applies.

Where must an EU GDPR Representative be established?

In a Member State where the relevant data subjects are located in connection with the offering or monitoring covered by Article 3(2), as required by Article 27(3).

Can one EU Representative cover multiple EU Member States?

Yes. Separate representatives are not required merely because processing concerns several Member States. The representative must satisfy Article 27(3) and remain effectively accessible to relevant data subjects and supervisory authorities.

Can the EU GDPR Representative also be the DPO?

The EDPB considers representation incompatible with acting as the same organisation's external DPO: the representative acts under instructions, while the DPO must act independently.

Does appointing an EU Representative create an EU establishment?

No. According to the EDPB, an Article 27 appointment does not, by itself, constitute an establishment of the controller or processor for GDPR Article 3(1).

What happens if an organisation fails to appoint an EU GDPR Representative when required?

This is a GDPR infringement within Article 83(4). Supervisory authorities have Article 58 corrective powers; enforcement and any fine depend on the circumstances and Article 83 assessment.

Still unsure whether Article 27 applies?

Discuss your position with OSTRAI

APPLICABLE FRAMEWORK

GDPR Articles 3, 27 and 30 · Recital 80 · EDPB Guidelines 3/2018 on territorial scope

EU GDPR REPRESENTATIVE

Establish the right
European representation structure.

OSTRAI supports international controllers and processors from territorial-scope analysis and Article 27 assessment through appointment, operational setup and continuing EU representation.