Article 27 of the GDPR gives organisations caught by the Regulation’s extraterritorial scope a local representative within the European Union.
Following Brexit, the UK GDPR created a parallel requirement for organisations outside the United Kingdom whose processing falls within its own extraterritorial scope.
The representative performs an important function.
It provides a local point through which data subjects and supervisory authorities can communicate with a controller or processor that may have no establishment in the relevant jurisdiction.
But the wording of the GDPR created a difficult question from the outset.
Recital 80 states that the designated representative should be subject to enforcement proceedings in the event of non-compliance by the controller or processor.
Does that mean the representative becomes liable for the controller’s or processor’s GDPR infringements?
The EDPB’s final Guidelines 3/2018 and the UK High Court judgment in Sansó Rondón v LexisNexis Risk Solutions UK Ltd provide the most important guidance on that question.
Both point away from a model of substitutive liability.
The representative has a meaningful legal and operational role, but Article 27 does not simply place the representative in the shoes of the controller or processor for all GDPR liabilities.
What is an Article 27 representative?
Article 3(2) GDPR extends the Regulation to certain controllers and processors that are not established in the European Union.
The provision applies where processing relates to:
- offering goods or services to data subjects in the Union; or
- monitoring their behaviour where that behaviour takes place in the Union.
Where Article 3(2) applies, Article 27 generally requires the controller or processor to designate a representative in the Union unless one of the limited exemptions applies.
The representative must be designated in writing.
Article 27(4) requires the representative to be mandated so that supervisory authorities and data subjects can address it, in addition to or instead of the controller or processor, on issues relating to processing for the purposes of GDPR compliance.
The representative therefore provides local accessibility and regulatory cooperation for an organisation located outside the Union.
Following Brexit, the UK GDPR contains a corresponding Article 27 requirement for organisations outside the UK falling within the UK GDPR’s extraterritorial scope.
Why did Article 27 create uncertainty about liability?
The uncertainty arose principally from the interaction between Article 27 and Recital 80.
Recital 80 provides that the designation of a representative does not affect the responsibility or liability of the controller or processor.
However, its final sentence states that the designated representative should be subject to enforcement proceedings in the event of non-compliance by the controller or processor.
That wording generated concern among organisations providing representative services.
If the representative could be subjected to enforcement because of the controller’s conduct, did Article 27 create a form of joint, vicarious or representative liability?
The operative provisions of Article 27 do not expressly create such a liability regime.
This tension became particularly significant during the development of the EDPB’s guidance on the territorial scope of the GDPR.
The EDPB’s draft Guidelines suggested a broader enforcement role
The first version of EDPB Guidelines 3/2018 contained broader language regarding enforcement against representatives.
That draft suggested that supervisory authorities should be able to initiate enforcement action against the representative in the same way as against controllers or processors, including the possibility of administrative fines and penalties.
For providers of representative services, that language created substantial concern.
It appeared capable of being read as extending the representative’s exposure beyond its own Article 27 functions and into the controller’s or processor’s wider GDPR compliance.
The position did not remain unchanged.
The EDPB’s final Guidelines rejected substitutive liability
The final Guidelines 3/2018, adopted on 12 November 2019 following public consultation, materially refined the earlier position.
The EDPB states that:
“The GDPR does not establish a substitutive liability of the representative in place of the controller or processor it represents in the Union.”
That distinction is central to understanding Article 27.
The representative can provide the local interface through which supervisory authorities communicate with the non-EU controller or processor.
The representative also has specific responsibilities associated with its own role.
But the final EDPB position does not treat the representative as becoming the controller or processor for liability purposes.
The represented organisation remains responsible for its own GDPR compliance.
Sansó Rondón v LexisNexis
The liability question was later considered directly by the High Court of England and Wales in:
Sansó Rondón v LexisNexis Risk Solutions UK Ltd [2021] EWHC 1427 (QB).
World Compliance Inc, a US company, operated a database used for anti-money-laundering and counter-terrorist-financing compliance.
LexisNexis Risk Solutions UK Ltd had been formally designated as World Compliance’s Article 27 representative.
Mr Sansó Rondón objected to the processing of information about him contained in the database.
Instead of suing the controller, he brought proceedings against LexisNexis in its capacity as Article 27 representative.
The claim therefore required the Court to decide whether the representative could be held liable for alleged GDPR infringements committed by the controller.
Two competing interpretations of Article 27
The parties advanced fundamentally different interpretations of the representative role.
LexisNexis argued that the wording “to be addressed” in Article 27(4) describes a local contact and facilitation function.
On that interpretation, the representative enables data subjects and supervisory authorities to communicate effectively with the controller, but does not assume the controller’s substantive obligations.
The claimant relied heavily on the broader language of Recital 80.
He argued that Article 27 intended the representative to stand in the controller’s shoes for enforcement and remedial purposes, with liability existing in addition to the controller’s own liability.
The dispute therefore required the Court to determine whether Article 27 created a liability regime that was not stated expressly in the operative text of the Regulation.
The High Court rejected representative liability for the controller’s infringements
The High Court rejected the claimant’s interpretation.
The Court accepted that the representative has what it described as a considerably fuller role than a mere post-box.
Nevertheless, it concluded that the GDPR does not confer on the representative the controller’s full substantive obligations.
The Court considered the structure of Article 27, the role assigned to the representative elsewhere in the GDPR, the EDPB’s final Guidelines and the practical consequences of the claimant’s interpretation.
For example, if the representative truly stood in the controller’s shoes, it would need powers enabling it to provide remedies such as access, rectification or erasure of personal data.
The GDPR does not give representatives such operational control over the controller’s data or systems.
The Court therefore concluded that if the GDPR had intended to create this form of representative liability, it would have needed to say so clearly in the operative provisions of the Regulation.
The wording of Recital 80 was not sufficient to create that broader liability regime.
Rejecting substitutive liability does not reduce the role to a mailbox
The Court’s rejection of representative liability should not be misunderstood.
The Article 27 representative still performs a genuine regulatory function.
It exists to ensure that a non-EU organisation subject to the GDPR remains accessible within the Union.
Its role includes facilitating:
- communications from data subjects;
- communications from supervisory authorities;
- procedural exchanges with regulators;
- access to relevant records; and
- cooperation concerning the represented organisation’s GDPR compliance.
The representative therefore sits within the GDPR accountability structure even though it does not assume the controller’s or processor’s entire package of obligations.
Representatives remain responsible for their own Article 27 functions
The absence of substitutive liability does not mean the representative is legally irrelevant.
The GDPR assigns representatives certain responsibilities in their own capacity.
Article 30 is one important example.
Where Article 30 applies, the controller or processor and its representative must maintain the relevant records of processing activities or categories of processing.
Those records must be available to the supervisory authority on request.
The representative must also be available to communicate and cooperate with supervisory authorities and data subjects within the scope of its mandate.
A representative can therefore face issues arising from the way it performs its own functions.
That is different from imposing liability on the representative for substantive processing decisions made by the controller or processor.
The representative facilitates data-subject rights, but does not become the controller
Article 27 enables data subjects to contact the representative about processing carried out by the represented organisation.
That does not transfer the controller’s obligations under the data-subject-rights provisions to the representative.
If an access, erasure or objection request is sent to the representative, the representative can provide the communication channel through which the request reaches the controller.
The controller remains responsible for:
- assessing the request;
- locating the relevant personal data;
- determining the appropriate response;
- taking any required operational action; and
- complying with the applicable statutory deadline.
This distinction reinforces the broader Article 27 structure.
The representative facilitates the exercise of rights.
It does not replace the controller in performing them.
The judgment is important, but it is not EU-wide binding precedent
Sansó Rondón is a judgment of the High Court of England and Wales.
It is not a judgment of the Court of Justice of the European Union.
It should therefore not be described as binding EU-wide authority on the interpretation of Article 27.
Its reasoning is nevertheless significant.
The Court examined the same Article 27 wording, Recital 80 and EDPB Guidelines that underpin the EU GDPR representative framework.
Its conclusion also aligns closely with the EDPB’s final position that the GDPR does not establish substitutive liability of the representative.
For EU GDPR purposes, the EDPB Guidelines remain particularly important interpretative material.
For the UK GDPR, the High Court judgment has additional relevance because the UK framework retains the Article 27 representative structure.
The same core distinction continues under the UK GDPR
The UK GDPR continues to require certain controllers and processors outside the United Kingdom to appoint a UK representative where their processing falls within the extraterritorial scope of Article 3(2) and no exemption applies.
Current ICO guidance continues to emphasise the distinction between appointment of the representative and responsibility of the controller or processor.
The ICO states that appointing a representative does not affect the organisation’s own responsibility or liability under the UK GDPR.
The representative acts as the local interface through which individuals and the ICO can engage with the organisation.
Organisations operating across the EU and UK may therefore need two separate representative arrangements:
- an EU representative for EU GDPR purposes; and
- a UK representative for UK GDPR purposes.
The liability question should nevertheless be analysed within each legal framework rather than assuming that the representative replaces the organisation that appointed it.
Why the representative agreement still matters
The rejection of substitutive liability does not make the representative agreement unimportant.
A representative cannot perform its functions effectively unless the represented organisation provides timely and accurate information.
The mandate should therefore define practical matters such as:
- the entities and processing activities covered;
- the information the representative must receive;
- the Article 30 records to be maintained;
- escalation of data-subject requests;
- supervisory-authority communications;
- internal regulatory contacts;
- changes affecting territorial scope;
- updates to privacy-notice information;
- cooperation procedures; and
- termination or replacement of the representative.
The objective is not to transfer the controller’s substantive GDPR obligations by contract.
It is to ensure that the representative can actually perform the local regulatory role Article 27 assigns to it.
EU and UK representation in practice
For organisations subject to the extraterritorial reach of the EU GDPR or UK GDPR, representative compliance can be approached through a simple sequence.
01 · ASSESS TERRITORIAL SCOPE
Determine whether the organisation falls within Article 3(2) of the relevant GDPR regime.
02 · CHECK THE ARTICLE 27 EXEMPTION
Assess whether the processing qualifies for the limited exemption from the representative requirement.
03 · IDENTIFY THE REQUIRED REPRESENTATION
Determine whether the organisation needs:
- an EU representative;
- a UK representative; or
- both.
04 · DEFINE THE MANDATE
Document the entities, processing activities, records, communication processes and cooperation obligations covered by the appointment.
05 · PUBLISH THE REPRESENTATIVE DETAILS
Ensure that data subjects and supervisory authorities can identify and contact the representative through the appropriate public information.
06 · MAINTAIN THE RELATIONSHIP
Keep the mandate, records, contact details and territorial-scope assessment under review as the organisation’s processing changes.
Representative liability depends on the legislation creating the role
The Article 27 analysis should not be generalised across every regulatory representative regime.
Different EU legislation can assign materially different functions and liability consequences to representatives.
The GDPR does not contain an operative provision stating that the Article 27 representative assumes liability for the controller’s or processor’s non-compliance.
The EDPB’s final Guidelines expressly reject substitutive liability.
Other regulatory regimes use different language.
For example, Article 13 of the Digital Services Act expressly provides that it must be possible for the designated legal representative to be held liable for non-compliance with obligations under the DSA, without prejudice to liability and legal actions against the service provider itself.
The distinction demonstrates why the term “representative” should never be assumed to carry one universal EU-law liability model.
The mandate and exposure must be analysed under the specific legislation creating the role.
Compare DSA Article 13 representation →
Where does Article 27 representative liability stand today?
The central conclusion of the original 2022 article remains persuasive.
The EDPB’s final Guidelines do not support substitutive liability of the Article 27 representative for the controller’s or processor’s GDPR infringements.
The High Court reached the same conclusion in Sansó Rondón.
Current UK guidance likewise continues to emphasise that appointment of a representative does not alter the controller’s or processor’s own responsibility or liability.
No later reported judicial decision identified for this update has displaced the central reasoning of Sansó Rondón on this specific representative-liability question.
That does not mean every question concerning Article 27 has been resolved.
Supervisory authorities have continued to enforce the Article 27 appointment requirement itself, and the operational expectations surrounding representation continue to develop.
Those enforcement developments raise a different question from the one addressed here and should be analysed separately.
For the liability issue considered in this Insight, the key distinction remains:
the representative has its own legal and operational responsibilities, but it does not become a substitute controller or processor merely because it has been appointed under Article 27.
A local regulatory interface, not a substitute controller
Article 27 was designed to address a practical consequence of extraterritorial data-protection law.
If an organisation can access European or UK markets without establishing itself locally, data subjects and regulators still need an effective way to communicate with it.
The representative provides that local presence.
That role is meaningful.
It supports transparency, accessibility, record keeping and supervisory cooperation.
But the GDPR does not simply transfer the controller’s or processor’s substantive obligations to the representative.
The EDPB’s final guidance and the Sansó Rondón judgment both support that distinction.
For organisations appointing representatives, and for providers accepting the role, the correct approach is therefore neither to treat the representative as a passive mailbox nor to treat it as a substitute controller.
The representative is a distinct regulatory actor with a defined mandate.
Its responsibilities, and its potential exposure, should be understood by reference to that mandate and to the specific obligations the GDPR places on the representative itself.



