The short answer
The requirement is short enough to quote in full:
"Where Article 3(2) applies, the controller or the processor shall designate in writing a representative in the Union."
So it hangs entirely on Article 3(2) — the targeting route that catches companies with no EU establishment. If you have not worked out whether that applies to you, start with does GDPR apply to my US company and come back.
If Article 3(2) does apply, there is one way out, and it is narrow.
Required, or exempt?
Article 27(2)(a) provides the only exemption most businesses could plausibly claim. The critical detail is that its conditions are cumulative — you need all of them to be true.
- Article 3(2) applies to you — you offer goods or services to people in the EU, or monitor their behaviour there
- and you have no establishment in the Union
- and you fail any single one of the exemption conditions opposite
- the processing is "occasional"
- it does not include, on a large scale, special category data (Article 9(1)) or criminal conviction data (Article 10)
- it is "unlikely to result in a risk to the rights and freedoms of natural persons"
Worth noticing how this differs from the 250-employee rule. Under Article 30(5), hitting any one of three conditions cancels your exemption. Here it is the reverse: you need every condition to hold to keep the exemption. Same shape of sentence, opposite logic — which is why people who have read about one often get the other backwards.
"Occasional" is where most software companies come unstuck. If EU customers use your product on an ordinary working basis, the processing is continuous by design — that is what the product is. A newsletter you send twice a year might be occasional. A SaaS application is not.
What a representative actually does
Five things, and the last two are the ones most explanations leave out.
Not wherever is cheapest or most convenient. It has to be a Member State where the people whose data you handle are located.
Article 27(3) "established in one of the Member States where the data subjects… are"
Regulators and individuals can deal with them rather than with you. That is the whole point of the role — someone reachable inside the Union instead of an address across an ocean.
Article 27(4) "addressed in addition to or instead of the controller or the processor… on all issues related to processing"
Their name and contact details go in your privacy notice, so an individual or a regulator can reach them without going through you first. A representative nobody can locate is not doing the job.
They are not just a mailbox. If you fail to comply, the representative can face enforcement action themselves — which is why this is a paid service, and why providers ask questions before they accept you.
Recital 80 "should be subject to enforcement proceedings in the event of non-compliance by the controller or processor"
Appointing one adds someone who can be pursued. It does not remove you. You are exactly as reachable as you were before.
Article 27(5) "without prejudice to legal actions which could be initiated against the controller or the processor themselves"
Three things it is not
1"It puts a legal buffer between us and the regulator"
It does the opposite. It adds a party who can be pursued, without removing you as one.
Article 27(5) is explicit that legal action against you is unaffected, and Recital 80 makes the representative separately exposed. The role exists to make you easier to reach, not harder.
What this means for you: appointing a representative is a box you tick to be compliant, not a liability structure. If someone is selling it to you as protection, they are selling you something else.
2"Our EU representative covers the UK as well"
It does not. Since Brexit, UK GDPR carries its own parallel Article 27, and the two are separate appointments.
The UK requirement is triggered the same way — offering goods or services to people in the UK, or monitoring their behaviour — with a similarly narrow exemption for occasional, low-risk processing. A representative appointed in an EU Member State satisfies the EU obligation only.
What this means for you: if you are deliberately selling into the EU and not the UK, you likely need one appointment and not two. But the moment UK customers become something you actively pursue rather than something that occasionally happens, the second question becomes live — and it is worth asking a lawyer before it does, not after.
3"It is basically the same as a Data Protection Officer"
Different role, different trigger, and having one does not satisfy the other.
A representative is a contact point in the Union for a company that has no presence there. A DPO is an advisory and oversight function, triggered by the nature of what you process rather than by where you are based. A company can need both, either, or neither.
What this means for you: do not let a provider bundle the two and imply one purchase covers both obligations. They are answers to different questions.
What it costs, and how appointing one works
It is a paid service billed annually, provided by firms that specialise in it. The commercial part is straightforward — you sign a written mandate, they give you an address and contact details in a Member State, and you publish those details in your privacy notice.
We went through this ourselves in July 2026, so this is a step we have taken rather than one we are describing from outside. Two things we would flag from doing it:
- The mandate has to be in writing — Article 27(1) says "designate in writing," and that is the appointment, not the invoice.
- Updating your privacy notice is part of the job, not an afterthought. An appointment that never reaches your published notice leaves the obligation half-done, and it is the half a regulator can see from outside.
Why this matters to you: the most common version of getting this wrong is not skipping the appointment — it is appointing someone and never publishing them. The contract exists, the invoice is paid, and the privacy notice still says nothing. From the outside that is indistinguishable from having no representative at all, because the entire point of the role is being findable without asking you.
Working out whether this applies to you
The chain is short: does GDPR reach you at all, and if so, does it reach you through Article 3(2) rather than through an EU establishment? If the answer to both is yes, and your product is used continuously rather than occasionally, you are almost certainly in Article 27 territory.
Our free scope checker answers the first half of that in about seven plain-language questions — whether GDPR, NIS2 and the EU AI Act reach your business, and which route they arrive by. It runs entirely in your browser, needs no account, and will tell you when a regulation does not apply.
What it will not do is decide the Article 27 question for you. Whether your processing is "occasional," and whether it is "unlikely to result in a risk," are judgement calls that no seven-question tool should claim to settle — and this page is honest about that in the same way the checker is.
Sources cited on this page
- GDPR Article 27(1)–(5) — representatives of controllers or processors not established in the Union
- GDPR Recital 80 — designation of a representative, and their exposure to enforcement
- GDPR Article 3(2) — territorial scope, the targeting route
- GDPR Article 30(5) — records exemption, for the comparison drawn above
- UK GDPR Article 27 — the parallel UK representative requirement