An EU representative under Article 27 GDPR is a mandated contact point inside the Union for a controller or processor with no EU establishment. A data protection officer under Article 37 GDPR is an independent expert who advises and monitors compliance. A company may need one, both, or neither.
The two roles sit in the same regulation and answer unrelated questions. The representative answers a jurisdictional one; the officer a governance one.
What is an EU representative under Article 27 GDPR?
An EU representative is a natural or legal person established in the Union whom a controller or processor outside the EU designates in writing under Article 27(1) GDPR. The representative is mandated to be addressed by, in particular, supervisory authorities and data subjects on all processing issues. The duty has applied since 25 May 2018.
The trigger is Article 3(2) GDPR: offering goods or services to people in the Union, or monitoring their behavior there. Processors are caught as well as controllers. The exemption in Article 27(2)(a) is cumulative — occasional processing, no large-scale Article 9 or Article 10 data, no likely risk; Article 27(2)(b) exempts public authorities and bodies.
There is no free choice of Member State: Article 27(3) requires establishment where the data subjects are. The mandate has no statutory content list; Article 27(1) requires it in writing, and Recital 80 adds that it cover the company’s obligations under the Regulation.
What is a data protection officer under Articles 37 to 39 GDPR?
A data protection officer is an expert designated under Article 37 GDPR to inform, advise and monitor compliance inside an organization. Designation is mandatory in three cases: public authorities, except courts acting judicially; core activities requiring regular and systematic monitoring of data subjects on a large scale; and core activities involving large-scale Article 9 or Article 10 data.
The officer is chosen for expert knowledge and may be internal or external (Article 37(5), (6)). Article 37(4) lets Union or national law add cases: in Germany, section 38 of the Federal Data Protection Act (BDSG) sets a 20-person threshold.
The defining feature is independence: under Article 38(3) the officer takes no instructions on the tasks and reports to the highest management level.
Do you need a representative, a DPO, both or neither?
The two duties are triggered independently. A US company with EU users and low-risk processing typically needs a representative only. A German employer with 20 or more people in automated processing needs a DPO under section 38 BDSG and no representative. A non-EU platform doing large-scale behavioral tracking needs both. Neither applies without an EU market or qualifying processing.
| Feature | EU representative (Art. 27 GDPR) | Data protection officer (Arts. 37–39 GDPR) |
|---|---|---|
| Trigger | Art. 3(2) applies, no EU establishment; exemption in Art. 27(2) | One of the three cases in Art. 37(1) |
| Where it sits | A Member State where the data subjects are (Art. 27(3)) | No express location rule; EDPB-endorsed WP29 guidance recommends the Union, but does not rule out a DPO outside it where the company has no EU establishment |
| Function | Addressed “in addition to or instead of” the company (Art. 27(4)) | Informs, advises, monitors, contact point (Art. 39(1)) |
| Independence | None — acts under written mandate | No instructions on the tasks (Art. 38(3)) |
| Visibility | Privacy notice (Art. 13(1)(a), 14(1)(a)); no notification duty | Published and notified to the authority (Art. 37(7)) |
| Own duties | Record of processing (Art. 30(1), (2)) | Art. 39(1) tasks; secrecy (Art. 38(5)) |
| Liability | No substitutive liability for the company’s breaches; corrective measures and fines on the company may be addressed to the representative (Arts. 58(2), 83); own direct liability only under Arts. 30 and 58(1)(a) (EDPB Guidelines 3/2018) | Not personally responsible for the company’s compliance (Art. 24(1)) |
| Fines | Art. 83(4)(a): up to EUR 10 million or 2% of worldwide turnover, whichever is higher — imposed on the company, never on the DPO | |
First which EU representative duty applies to your business, then how to appoint an EU representative.
Can the same person be your EU representative and your DPO?
The GDPR contains no express prohibition. The European Data Protection Board, however, does not consider the representative function compatible with the role of an external data protection officer established in the Union. That is an interpretation by the Board, not a statutory ban.
“The EDPB does not consider the function of representative in the Union as compatible with the role of an external data protection officer (‘DPO’) which would be established in the Union.”
EDPB, Guidelines 3/2018 on the territorial scope of the GDPR (Article 3), Version 2.1, 7 January 2020, section 4(a), p. 24
The reasoning is structural: the officer takes no instructions (Article 38(3)), while the representative acts “under its direct instruction”. The same section flags a second incompatibility: representative and processor for one controller.
Calling it prohibited overstates the law; treating it as unproblematic understates the risk. Article 38(6) obliges the controller to rule out conflicts of interest — keep the two functions in different hands.
Does an EU representative have to be a lawyer?
No. Article 27 GDPR sets no professional requirement. The EDPB confirms that the function can be exercised under a service contract by a wide range of entities, including law firms, consultancies and private companies, provided they are established in the Union. One representative may act for several non-EU companies.
The role requires capacity: reachability for authorities and data subjects, their languages, and the Article 30 record. Where duties cumulate, Article 13(2) DSA requires “necessary powers and sufficient resources”, and under Article 13(3) DSA the representative can be liable in its own right.
Do the DSA, the AI Act, NIS2 and the Data Act have a DPO equivalent?
No. None of the four creates a data protection officer of the GDPR type. The DSA comes closest: Article 41 requires an independent compliance function — but only for very large online platforms and search engines. Each of the four instead creates a representative duty that runs in parallel to Article 27 GDPR.
| Regime | Provision | Applies |
|---|---|---|
| DSA | Art. 13 — legal representative, no size threshold | since 17 February 2024 |
| AI Act (GPAI) | Art. 54 — authorised (US: authorized) representative; exemption in Art. 54(6) | since 2 August 2025 |
| Data Act | Art. 37(11) — legal representative | since 12 September 2025 |
| NIS2 | Art. 26(3); in Germany § 60(3) BSIG | since 18 October 2024 (Directive); in Germany BSIG in force 6 December 2025 |
| AI Act (high-risk) | Art. 22 — authorised representative | from 2 December 2027 (Annex III) and 2 August 2028 (Annex I), Regulation (EU) 2026/1744 |
The mandates differ: a closed catalog of tasks in the AI Act (Article 54(3) today, Article 22(3) from 2027/2028), resourcing and own liability in the DSA. The DSA and the AI Act expressly require writing; under NIS2 and the Data Act it is advisable, not prescribed. Regime by regime in our comparison of the EU representative duties; the record in fines for a missing EU representative.
Appoint a representative, or have the borderline case assessed
Appoint a representative through Regingada UG →Appointment itself is handled by Regingada UG (haftungsbeschränkt), a legally separate company owned by the attorney; legal assessment is a separate mandate with the law firm.
Unsure which applies? Discuss a borderline case with the attorney.
Replies within one business day · CET/CEST (UTC+1/+2)
Frequently asked
Is an EU representative the same as a DPO?
No. The representative is an external contact point for a company without an EU establishment and acts under mandate; the DPO is an independent adviser and monitor inside or for the organization and takes no instructions on the tasks. The triggers are separate, and so are the appointments.
We already have a data protection officer in the United States. Does that satisfy Article 27?
No. Article 27(1) requires a representative in the Union, and Article 27(3) requires it to be established in a Member State where the data subjects concerned are. A DPO outside the Union does not meet either requirement, however well qualified.
Can our European law firm act as our Article 27 representative?
Yes. The EDPB states expressly that the function can be exercised on the basis of a service contract and assumed by law firms, consultancies or private companies established in the Union. Combining it with the role of the same company’s external DPO is what the Board advises against. Here, the representative function sits with Regingada UG, not with the law firm — see its representative setup for companies based in the United States.
Do we have to notify a supervisory authority that we appointed a representative?
Article 27 contains no notification duty. The designation becomes visible through the privacy notice under Articles 13(1)(a) and 14(1)(a). A DPO is different: Article 37(7) requires the contact details to be published and communicated to the supervisory authority.
Can one representative act for several non-EU companies?
Yes. The EDPB confirms that one representative can act on behalf of several non-EU controllers and processors, and that a separate representative is not needed for each processing operation falling under Article 3(2).
Does appointing a representative make us established in the EU?
Under the DSA the answer is in the text: Article 13(5) states that designating a legal representative does not constitute an establishment in the Union. For the GDPR the EDPB takes the same view — the presence of the representative does not constitute an establishment by virtue of Article 3(1). The DSA wording is set out in the legal representative under Article 13 DSA.
- Regulation (EU) 2016/679 (GDPR), Articles 3, 9, 10, 13, 14, 24, 27, 30, 37–39, 58, 83, Recital 80 — data.europa.eu/eli/reg/2016/679/oj
- Bundesdatenschutzgesetz (BDSG), § 38(1) — gesetze-im-internet.de/bdsg_2018
- EDPB, Guidelines 3/2018 on the territorial scope of the GDPR (Article 3), Version 2.1, 7 January 2020, sections 4(a) and 4(d), pp. 23–28 — edpb.europa.eu
- Article 29 Working Party, Guidelines on Data Protection Officers (WP 243 rev.01, adopted 13 December 2016, as last revised and adopted 5 April 2017), section 1 (p. 4), sections 2.1.5 and 2.4, and Annex, question 12 — endorsed by the EDPB on 25 May 2018 — ec.europa.eu (PDF)
- Regulation (EU) 2022/2065 (Digital Services Act), Articles 13, 41 — data.europa.eu/eli/reg/2022/2065/oj
- Regulation (EU) 2024/1689 (AI Act), Articles 22, 54 — data.europa.eu/eli/reg/2024/1689/oj
- Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689 (OJ of 24 July 2026, in force 27 July 2026) — data.europa.eu/eli/reg/2026/1744/oj
- Regulation (EU) 2023/2854 (Data Act), Article 37(11)–(13) — data.europa.eu/eli/reg/2023/2854/oj
- Directive (EU) 2022/2555 (NIS2), Article 26(3) — data.europa.eu/eli/dir/2022/2555/oj
- BSI-Gesetz (BSIG 2025), § 60(3) — gesetze-im-internet.de/bsig_2025