Logo

Article 27 of both the EU GDPR and the UK GDPR is one of the most frequently overlooked pieces of data protection legislation. It requires certain organisations without a local establishment to appoint a representative, yet many businesses assume that having a privacy policy or a DPO is enough. It is not.

Answer first: Do you need an EU or UK representative under Article 27?

If your organisation is based outside the EU or EEA but has EU customers, you may need an EU representative. If you are based outside the UK but process personal data of UK citizens, you may need a UK representative. The obligation applies when you offer goods or services to, or monitor the behaviour of, individuals in those territories.

Run through these quick-test questions:

  • Do you have no office, branch, or other establishment in any EU member states or EEA countries, but regularly sell products or services to people in France, Germany, Spain, Italy, Ireland or any other EEA state?

  • Do you use tracking cookies, analytics, profiling or targeted advertising directed at individuals in Europe?

  • Are you established outside the UK with no UK office, but do you offer goods to UK customers or monitor behaviour of people located in the UK?

  • Does your website accept payment in euros or pounds from EU or UK customers, or does it ship to those countries?

If you answered yes to any of these, Article 27 is likely applicable to your organisation.

Data Privacy Services provides a combined UK and EU Representation Service designed to cover both obligations through a single provider.

What is Article 27 and why does it matter?

Article 27 of the General Data Protection Regulation requires organisations without a local establishment in the EU or the UK to designate, in writing, a representative who can act as a contact point on their behalf for data subjects and supervisory authorities.

  • The EU GDPR applies to processing activities that target data subjects in EU member states and EEA countries. The UK GDPR, established on 1 January 2021, mirrors this requirement for UK data subjects.

  • The Data Protection Act 2018 incorporates the EU GDPR into UK law, and post-Brexit amendments created the standalone UK GDPR framework with near-identical wording to EU law.

  • The policy reason is straightforward: data protection authorities and individuals need a local, accountable contact point to enable enforcement and facilitate communication when a controller or processor sits in a third country.

  • Many organisations focused on GDPR compliance overlook Article 27 because they treat it as optional. Representation is a separate legal obligation from maintaining GDPR documents, appointing a DPO, or publishing a privacy notice.

It is worth noting that “Article 27” appears across many areas of international legislation. Under the UN Charter, Article 27 sets the voting and veto rules for the Security Council. Article 27 of the Universal Declaration of Human Rights protects cultural, artistic, and scientific rights, while Article 27 of the ICCPR protects minority rights to culture, religion, and language. Article 27 of the UNCRC concerns the right to an adequate standard of living for children. In this article, we focus exclusively on Article 27 as it applies to data protection laws under the EU GDPR and UK GDPR.

When does Article 27 EU GDPR require an EU representative?

This section concerns non-EU and non-EEA organisations that process data of individuals in the European Union.

  • Trigger one: you offer goods or services, whether or not payment is required, to people in the EU. For example, a US SaaS provider with subscribers in Ireland and Germany, or a UK e-commerce store shipping to France and Spain.

  • Trigger two: you monitor the behaviour of individuals in the EU through tracking, profiling, or online advertising. A Singapore app developer using analytics on users in Italy and the Netherlands would fall squarely within scope.

  • Article 27 applies where the organisation has no establishment in any EU or EEA member state but is caught by the extraterritorial scope of the EU GDPR. Non-EU businesses must appoint an EU representative under GDPR, and that representative must be based in an EEA country.

  • UK businesses need an EU representative if they are processing EU citizens’ data without having an EU establishment. Since the UK became a third country under EU GDPR on 1 January 2021, this is now a live issue for any British business selling into Europe.

  • Limited exemptions exist for occasional processing that does not include large scale processing of special categories of personal data or criminal data and is unlikely to result in risk to individuals. A public authority may also be exempt. In practice, most active online businesses will not qualify for these exemptions.

When does Article 27 UK GDPR require a UK representative?

After Brexit, the UK GDPR introduced a mirror Article 27 obligation for non-UK organisations processing personal data of UK data subjects. UK businesses must comply with the UK GDPR for UK citizens’ data, and organisations outside the UK targeting those individuals face a parallel requirement.

  • You must appoint a UK representative if you are established outside the UK, have no UK office or branch, but you offer goods or services to people in the UK or monitor the behaviour of people located in the UK.

  • Examples: a German online retailer regularly selling to UK customers since 2021; a US marketing platform tracking behaviour of UK users; an Australian university recruiting and profiling prospective students in England and Scotland.

  • The UK has EU adequacy decisions for data transfers. These adequacy decisions, renewed on 19 December 2025, allow personal information to flow freely from the EEA to the UK and last until 27 December 2031. The UK provides adequate protection for personal information under GDPR. However, an adequacy decision affects data transfers, not the Article 27 representative obligation. An EU-based organisation benefiting from the adequacy decision for transfers must still appoint a UK representative if it targets UK individuals.

  • The UK ICO explicitly requires a written mandate authorising the representative, comparable in scope and formality to the EU requirement.

What does an EU/UK representative actually do under Article 27?

The representative acts as a local point of contact for data subjects and supervisory authorities, without replacing the controller or processor’s own responsibility.

  • Receiving and forwarding data subject access requests, complaints, and other communication on behalf of the organisation.

  • Liaising with data protection authorities in different member states or with the ICO in the UK, enabling cooperation during investigations.

  • The representative maintains records of processing activities and must keep an up-to-date copy of the ROPA available for inspection.

  • Supporting incident response communication during data breaches affecting EU or UK data subjects, in coordination with data breach management processes.

  • Details of the representative, including name, address, and contact email or phone, must be accessible to data subjects and included in privacy notices.

  • For EU representation, the representative must be established in one of the EU or EEA countries where the relevant data subjects are located. For UK representation, the representative must be established in the UK.

  • The EU representative acts on behalf of the non-EU business, but the underlying organisation remains primarily liable under data protection law. The representative can face enforcement for its own failures, such as not cooperating with supervisory authorities or not maintaining records.

How Article 27 fits with other GDPR and UK GDPR obligations

Appointing an EU or UK representative does not, by itself, make an organisation GDPR compliant. It complements wider compliance measures including lawful basis for processing, additional safeguards, DPIAs, and security measures.

  • A Data Protection Officer is required under GDPR in specific circumstances. DPOs must ensure compliance with data protection laws, act as a point of contact for data subjects, must be independent and adequately resourced, and are responsible for training staff on data protection. An Article 27 representative is a fundamentally different role: an external contact point, not an internal oversight function. Learn more about the distinction between a DPO and a representative.

  • Cross-border data transfer rules and adequacy decisions sit within the broader international transfers framework. An organisation might rely on an adequacy decision for transfers but still need a representative because it targets individuals in the EU or UK.

  • Article 27 applies equally to controllers and processors. For example, a cloud provider hosting EU customer data for UK clients may need both an EU representative and a UK representative depending on its establishment and the scope of its processing activities.

  • Under the Vienna Convention, Article 27 prohibits states from using domestic law to excuse treaty breaches. The principle of pacta sunt servanda means treaties in force must be performed in good faith. While these are broader principles of international law, they underline the influence of international obligations on national data protection frameworks.

Practical steps to assess your Article 27 obligations

Use this checklist to determine whether your organisation must appoint a representative.

  • Map where your data subjects are located: UK, EU, EEA countries, or rest of world. Take account of website traffic, customer databases, and marketing reach.

  • Identify whether you offer goods or services to those individuals or monitor their behaviour through cookies, analytics, profiling, or targeted advertising.

  • Confirm whether you have an establishment in those jurisdictions. Having a representative does not count as having an establishment.

  • If you are a UK business with EU customers post-Brexit, or an EU business handling UK personal data, you may need both an EU representative and a UK representative.

  • Review existing privacy notices, cookie banners, contracts with processors, and marketing strategies to check how targeting and monitoring are described.

  • Document the outcome of this assessment as part of your GDPR compliance records. If a data protection authority or the European Commission asks, your organisation must show how it considered Article 27.

How Data Privacy Services can act as your EU and UK representative

Data Privacy Services (trading name of Data Privacy and Data Security Services Limited) provides a combined UK and EU Representation Service for organisations that fall under Article 27 of the EU GDPR and UK GDPR.

  • Acting as your appointed representative in the EU and UK, with contact details listed in your privacy notices and made accessible to data subjects and regulators.

  • Handling communication with data subjects and data protection authorities across member states, as well as with the ICO.

  • Maintaining necessary records of processing activities in line with data protection laws.

  • Data Privacy Services is a UK-based consultancy specialising in GDPR auditing, data protection, and information security, with ISO 27001 certified experts offering DPO as a Service, CISO-as-a-Service, security audits, and training.

  • A single provider covering both EU and UK representation means fewer contracts, consistent support, and integration with broader GDPR compliance and risk assessments.

Contact the team to request a free initial GDPR audit or discuss your representation needs at dataprivacyservices.co.uk.

Frequently asked questions about Article 27 representatives

Do we still need an EU representative if the UK has an adequacy decision? Yes. UK adequacy decisions allow data flow from EEA to UK without additional safeguards, but adequacy decisions concern data transfers, not the Article 27 obligation. If your organisation targets EU data subjects, you still need an EU representative regardless of the UK’s adequacy status.

Can our external law firm or consultant be our representative? Yes. The representative can be a natural or legal person, including a law firm or specialist consultancy, provided the mandate is in writing and clearly defines authority, scope, and contact details.

Do we need a representative if we only occasionally sell to EU customers? Possibly not, but the exemption is narrow. Processing must be genuinely occasional, must not involve large scale special category data, and must be unlikely to result in risk to individuals. Most businesses with a functioning website and regular EU or UK customers will not qualify.

Where must the representative be located? For EU representation, in an EEA state where the relevant data subjects are. For UK representation, in the UK.

Does appointing a representative make us liable in all member states? No. The representative provides a local contact point, but your organisation remains primarily liable. The representative may face enforcement for its own failures, such as not cooperating or not maintaining records.

How long should the mandate last? Mandates are typically structured as annual renewable agreements. Data Privacy Services offers flexible terms that can be adjusted as your processing activities or geographic scope change. You can end or change representatives by updating the written mandate and notifying the applicable supervisory authorities.

Leave a Reply

Your email address will not be published. Required fields are marked *

Thank you for contacting us

We will respond shortly

Note – if you do not receive an email from us please check your spam folder as we normally respond within 2 hours.