EU GDPR REPRESENTATIVE
EU GDPR Representative
for Non-EU Organisations
Article 27 representation for controllers and processors subject to the GDPR under Article 3(2) without an establishment in the European Union.
OSTRAI acts as EU GDPR Representative for international organisations requiring a representative in the Union.
Our service combines Article 27 assessment, formal appointment, a dedicated European contact point, Article 30 arrangements, regulatory communications and continuing representation, backed by substantive regulatory expertise.
Not sure whether Article 27 applies? Start with the scope assessment.
ARTICLE 27 DECISION ARCHITECTURE
The route to
representation.
A processing-specific assessment.
Not established in the Union
Does Article 3(2) apply to the relevant processing?
Offering goods or services
to data subjects in the Union
Monitoring behaviour
where behaviour takes place in the Union
If neither applies: no Article 27 appointment required for that processing.
IF ARTICLE 3(2) APPLIESDoes an Article 27(2) exemption apply?
If no
EU Representative
required
If yes
No Article 27
appointment required
for the relevant processing
TERRITORIAL SCOPE
When does Article 27 GDPR apply?
For a controller or processor not established in the Union, Article 3(2) covers processing relating to offering goods or services to data subjects in the Union, irrespective of payment, or monitoring their behaviour within the Union.
If Article 3(2) applies, Article 27 generally requires designation of a representative in the Union unless an Article 27(2) exemption applies.
The analysis is processing-specific. Mere accessibility of a website from the EU is not, by itself, the Article 3(2) test.
EXEMPTIONS
The exemption is narrow and fact-specific.
Organisation size alone does not determine whether the exemption applies.
Article 27(2)(a): all three conditions together
Processing is occasional;
does not include, on a large scale, processing of special categories of personal data under Article 9(1) or personal data relating to criminal convictions and offences under Article 10;
is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account the nature, context, scope and purposes of the processing.
Public authorities or bodies are exempt under Article 27(2)(b).
Not sure how Article 3(2) applies to your organisation?
Request an Article 27 scope assessmentESTABLISHMENT
The representative must be established in an appropriate Member State.
Article 27(3) requires the representative to be established in one of the Member States where the relevant data subjects are located in connection with the offering of goods or services or monitoring covered by Article 3(2).
OSTRAI Limited is established in Cyprus, within the European Union.
Whether Cyprus is an appropriate Member State for a particular Article 27 appointment is assessed against the organisation's relevant European processing footprint.
Where a significant proportion of relevant data subjects are located in a particular Member State, the EDPB recommends taking that concentration into account when choosing the representative's location.
More than
an EU address.
Article 27 requires an accessible representative in the Union. Effective representation also depends on what happens when a data subject, supervisory authority or regulatory issue reaches that representative.
OSTRAI combines the formal mandate with defined communication and escalation arrangements, Article 30 processes, regulatory experience and access to substantive privacy expertise where required.
YOUR REPRESENTATION SERVICE
A functioning regulatory interface.
Dedicated representative email
A dedicated client-specific OSTRAI representative email address for the organisation, providing a clear representative contact for publication in applicable privacy information and for communications relating to the mandate.
Designated lead contact
A defined OSTRAI contact coordinates the representative mandate, communications and material escalations. This reflects the EDPB recommendation to assign a lead contact for each represented organisation.
Formal written mandate
Article 27 appointment documentation defining the representative relationship, responsibilities and operational contacts.
Privacy notice support
Representative identity and contact wording for inclusion in applicable Articles 13 and 14 transparency information.
Article 30 arrangements
A process for maintaining and making available the applicable Article 30 record on the basis of accurate and updated information supplied by the represented organisation.
Data-subject communications
Receipt, logging and escalation of communications addressed to the representative.
Supervisory authority interface
Receipt and coordination of communications from relevant supervisory authorities.
Escalation procedure
Defined contacts and procedures for urgent, material or time-sensitive regulatory matters.
Ongoing mandate review
Periodic review of relevant entity details, contacts, EU activities and material changes affecting the representation mandate.
Need to appoint an EU GDPR Representative?
Discuss the mandate with OSTRAITHE REPRESENTATIVE FUNCTION
A clear point of connection.
Data subjects
Supervisory authorities
OSTRAI
EU GDPR Representative
- Dedicated contact
- Article 30 interface
- Communications
- Escalation
- Regulatory cooperation
Represented organisation
Controller or processor
Under Article 27(4), the representative may be addressed, in addition to or instead of the controller or processor, by supervisory authorities and data subjects on issues related to the relevant processing, for the purposes of ensuring GDPR compliance.
REGULATORY INTERFACE
What happens when OSTRAI
receives a communication?
Receive
Communication reaches the organisation's dedicated representative channel.
Log
The matter is recorded and linked to the representation mandate.
Assess
OSTRAI identifies the nature of the communication, relevant deadline and regulatory significance.
Escalate
The appropriate client contacts are notified under the agreed escalation procedure.
Coordinate
Relevant information, documentation and response responsibilities are coordinated.
Respond / facilitate
OSTRAI facilitates the required communication with the data subject or supervisory authority in accordance with the mandate.
Record
The matter and relevant follow-up are retained within the representation process.
Where a matter requires substantive advisory work outside the representative mandate, that work can be separately scoped.
ACCESSIBILITY
The representative must be genuinely accessible.
The representative must be in a position to communicate efficiently with relevant data subjects and cooperate with supervisory authorities concerned.
The EDPB states that communications should in principle take place in the language or languages used by the relevant supervisory authorities and data subjects. Where this would involve disproportionate effort, other means and techniques should ensure effective communication.
Language requirements are considered during onboarding and appropriate communication arrangements are established for the relevant mandate.
LEGAL & REGULATORY PRACTICE
Representation backed by substantive regulatory experience.
OSTRAI's representative service sits within a specialist regulatory practice with substantive legal and privacy expertise, rather than operating as a standalone administrative forwarding service.
Our work in privacy and data protection includes regulatory analysis, governance, data-subject rights, cross-border processing, supervisory-authority engagement and implementation.
Our wider technology-regulation work places representation issues in the context of cybersecurity, artificial intelligence, digital regulation and technology products where relevant.
Explore Privacy & DataCONTROLLED ACCEPTANCE
We determine the regulatory position before accepting the mandate.
OSTRAI does not treat Article 27 appointment as an automated registration exercise.
Before accepting a mandate, we consider the organisation's establishment, relevant processing activities, Article 3(2) territorial scope, Article 27 exemptions, European processing footprint and the operational arrangements required for effective representation.
The regulatory position determines the engagement.
Discuss whether representation is requiredONBOARDING
Representation Readiness Review
As part of onboarding, OSTRAI establishes the operational basis of the mandate.
- Article 3(2)
- Basis for territorial application
- Article 27
- Representative requirement and exemption analysis
- Represented entity
- Correct controller or processor entity
- EU footprint
- Relevant markets and data-subject locations
- Privacy information
- Representative disclosures under Articles 13 and 14
- Article 30
- Record availability and maintenance process
- Communications
- Data-subject and authority contact routes
- Escalation
- Named operational contacts and response arrangements
- Regulatory history
- Relevant open complaints, authority correspondence or material matters where applicable
APPOINTMENT
From territorial scope
to continuing representation.
Scope
Article 3(2) and Article 27 analysis
Readiness
Processing profile, markets, documentation and communication arrangements
Mandate
Written appointment and operating contacts
Activation
Dedicated representative contact, privacy-notice information and Article 30 process
Representation
Continuing communications, regulatory interface and mandate maintenance
RESPONSIBILITY
Representation does not
transfer GDPR responsibility.
Controller / processor
Underlying GDPR responsibility
EU GDPR Representative
Article 27 interface in the Union
Separate role
DPO
Independent data-protection governance role where required
The written representative mandate does not transfer the controller's or processor's underlying responsibility or liability under the GDPR. The designation is also without prejudice to legal action against the controller or processor.
The EDPB does not consider the EU Representative function compatible with acting as the same organisation's external DPO because the representative acts under mandate and instructions whereas the DPO must perform its role independently.
Article 30: a maintained regulatory record
The EDPB considers maintenance of the applicable Article 30 record a joint operational responsibility: the represented controller or processor must provide accurate and updated information, while the representative must be in a position to maintain and make the relevant record available as required.
TERRITORIAL FRAMEWORKS
EU and UK representation are separate appointments.
EU GDPR Representative and UK GDPR Representative requirements arise under separate legal frameworks. An EU Article 27 appointment does not, by itself, satisfy a UK representative requirement.
OSTRAI treats EU Regulatory Representation and UK Regulatory Representation as distinct services. UK GDPR Representative services are provided through PRIVACY MINDERS (UK) LIMITED, a UK-established company.
Explore EU Regulatory RepresentationWHY OSTRAI
Why organisations appoint
OSTRAI as EU Representative
OSTRAI combines representative infrastructure with substantive regulatory judgement and direct access to the team handling the mandate.
- Scope before appointment
- We first determine whether Article 27 representation is actually required.
- Dedicated contact
- Each mandate has a dedicated client-specific OSTRAI representative email address.
- Designated lead
- A defined OSTRAI contact coordinates the representative relationship.
- Regulatory experience
- Representation is backed by substantive experience in privacy, regulatory engagement, cross-border compliance and implementation.
- Defined escalation
- Clear procedures govern data-subject, supervisory-authority and material regulatory communications.
- Cross-regulatory view
- Privacy issues can be assessed in the context of wider European technology regulation where relevant.
OSTRAI works with internationally operating organisations on privacy, regulatory representation, supervisory matters, governance and wider European technology-regulation issues.
QUESTIONS & ANSWERS
EU GDPR Representative:
the key questions.
Who needs an EU GDPR Representative?
Controllers or processors not established in the Union whose relevant processing falls within Article 3(2) must designate a representative in writing, unless an Article 27(2) exemption applies.
Do all non-EU companies need a GDPR representative?
No. Article 3(2) is processing-specific. Website accessibility alone is insufficient; the offering or monitoring criteria and Article 27 exemptions must be assessed.
Do UK companies need an EU GDPR Representative after Brexit?
A UK organisation without an EU establishment may require representation where Article 3(2) applies to its relevant processing and no Article 27(2) exemption applies.
Where must an EU GDPR Representative be established?
In a Member State where the relevant data subjects are located in connection with the offering or monitoring covered by Article 3(2), as required by Article 27(3).
Can one EU Representative cover multiple EU Member States?
Yes. Separate representatives are not required merely because processing concerns several Member States. The representative must satisfy Article 27(3) and remain effectively accessible to relevant data subjects and supervisory authorities.
Can the EU GDPR Representative also be the DPO?
The EDPB considers representation incompatible with acting as the same organisation's external DPO: the representative acts under instructions, while the DPO must act independently.
Does appointing an EU Representative create an EU establishment?
No. According to the EDPB, an Article 27 appointment does not, by itself, constitute an establishment of the controller or processor for GDPR Article 3(1).
What happens if an organisation fails to appoint an EU GDPR Representative when required?
This is a GDPR infringement within Article 83(4). Supervisory authorities have Article 58 corrective powers; enforcement and any fine depend on the circumstances and Article 83 assessment.
Still unsure whether Article 27 applies?
Discuss your position with OSTRAIAPPLICABLE FRAMEWORK
GDPR Articles 3, 27 and 30 · Recital 80 · EDPB Guidelines 3/2018 on territorial scope
EU GDPR REPRESENTATIVE
Establish the right
European representation structure.
OSTRAI supports international controllers and processors from territorial-scope analysis and Article 27 assessment through appointment, operational setup and continuing EU representation.
