Legal Analysis · GDPR Roles

EU Representative vs. Data Protection Officer: What Is the Difference?

Article 27 GDPR and Articles 37 to 39 GDPR create two different roles. One is an addressable point of presence in the Union for a company that has none. The other is an independent adviser inside or for the organization. They are not interchangeable: the trigger, the location rule and the liability differ.

Published 12 September 2026
Last reviewed 12 September 2026
Scope Art. 27 GDPR · Arts. 37–39 GDPR
Short answer

An EU representative under Article 27 GDPR is a mandated contact point inside the Union for a controller or processor with no EU establishment. A data protection officer under Article 37 GDPR is an independent expert who advises and monitors compliance. A company may need one, both, or neither.

The two roles sit in the same regulation and answer unrelated questions. The representative answers a jurisdictional one; the officer a governance one.

What is an EU representative under Article 27 GDPR?

Direct answer

An EU representative is a natural or legal person established in the Union whom a controller or processor outside the EU designates in writing under Article 27(1) GDPR. The representative is mandated to be addressed by, in particular, supervisory authorities and data subjects on all processing issues. The duty has applied since 25 May 2018.

The trigger is Article 3(2) GDPR: offering goods or services to people in the Union, or monitoring their behavior there. Processors are caught as well as controllers. The exemption in Article 27(2)(a) is cumulative — occasional processing, no large-scale Article 9 or Article 10 data, no likely risk; Article 27(2)(b) exempts public authorities and bodies.

There is no free choice of Member State: Article 27(3) requires establishment where the data subjects are. The mandate has no statutory content list; Article 27(1) requires it in writing, and Recital 80 adds that it cover the company’s obligations under the Regulation.

What is a data protection officer under Articles 37 to 39 GDPR?

Direct answer

A data protection officer is an expert designated under Article 37 GDPR to inform, advise and monitor compliance inside an organization. Designation is mandatory in three cases: public authorities, except courts acting judicially; core activities requiring regular and systematic monitoring of data subjects on a large scale; and core activities involving large-scale Article 9 or Article 10 data.

The officer is chosen for expert knowledge and may be internal or external (Article 37(5), (6)). Article 37(4) lets Union or national law add cases: in Germany, section 38 of the Federal Data Protection Act (BDSG) sets a 20-person threshold.

The defining feature is independence: under Article 38(3) the officer takes no instructions on the tasks and reports to the highest management level.

Do you need a representative, a DPO, both or neither?

Direct answer

The two duties are triggered independently. A US company with EU users and low-risk processing typically needs a representative only. A German employer with 20 or more people in automated processing needs a DPO under section 38 BDSG and no representative. A non-EU platform doing large-scale behavioral tracking needs both. Neither applies without an EU market or qualifying processing.

Art. 27 representative and Art. 37 DPO · as at 12 September 2026
FeatureEU representative (Art. 27 GDPR)Data protection officer (Arts. 37–39 GDPR)
TriggerArt. 3(2) applies, no EU establishment; exemption in Art. 27(2)One of the three cases in Art. 37(1)
Where it sitsA Member State where the data subjects are (Art. 27(3))No express location rule; EDPB-endorsed WP29 guidance recommends the Union, but does not rule out a DPO outside it where the company has no EU establishment
FunctionAddressed “in addition to or instead of” the company (Art. 27(4))Informs, advises, monitors, contact point (Art. 39(1))
IndependenceNone — acts under written mandateNo instructions on the tasks (Art. 38(3))
VisibilityPrivacy notice (Art. 13(1)(a), 14(1)(a)); no notification dutyPublished and notified to the authority (Art. 37(7))
Own dutiesRecord of processing (Art. 30(1), (2))Art. 39(1) tasks; secrecy (Art. 38(5))
LiabilityNo substitutive liability for the company’s breaches; corrective measures and fines on the company may be addressed to the representative (Arts. 58(2), 83); own direct liability only under Arts. 30 and 58(1)(a) (EDPB Guidelines 3/2018)Not personally responsible for the company’s compliance (Art. 24(1))
FinesArt. 83(4)(a): up to EUR 10 million or 2% of worldwide turnover, whichever is higher — imposed on the company, never on the DPO

First which EU representative duty applies to your business, then how to appoint an EU representative.

Can the same person be your EU representative and your DPO?

Direct answer

The GDPR contains no express prohibition. The European Data Protection Board, however, does not consider the representative function compatible with the role of an external data protection officer established in the Union. That is an interpretation by the Board, not a statutory ban.

“The EDPB does not consider the function of representative in the Union as compatible with the role of an external data protection officer (‘DPO’) which would be established in the Union.”

EDPB, Guidelines 3/2018 on the territorial scope of the GDPR (Article 3), Version 2.1, 7 January 2020, section 4(a), p. 24

The reasoning is structural: the officer takes no instructions (Article 38(3)), while the representative acts “under its direct instruction”. The same section flags a second incompatibility: representative and processor for one controller.

Calling it prohibited overstates the law; treating it as unproblematic understates the risk. Article 38(6) obliges the controller to rule out conflicts of interest — keep the two functions in different hands.

Does an EU representative have to be a lawyer?

Direct answer

No. Article 27 GDPR sets no professional requirement. The EDPB confirms that the function can be exercised under a service contract by a wide range of entities, including law firms, consultancies and private companies, provided they are established in the Union. One representative may act for several non-EU companies.

The role requires capacity: reachability for authorities and data subjects, their languages, and the Article 30 record. Where duties cumulate, Article 13(2) DSA requires “necessary powers and sufficient resources”, and under Article 13(3) DSA the representative can be liable in its own right.

Do the DSA, the AI Act, NIS2 and the Data Act have a DPO equivalent?

Direct answer

No. None of the four creates a data protection officer of the GDPR type. The DSA comes closest: Article 41 requires an independent compliance function — but only for very large online platforms and search engines. Each of the four instead creates a representative duty that runs in parallel to Article 27 GDPR.

Representative duties outside the GDPR · as at 12 September 2026
RegimeProvisionApplies
DSAArt. 13 — legal representative, no size thresholdsince 17 February 2024
AI Act (GPAI)Art. 54 — authorised (US: authorized) representative; exemption in Art. 54(6)since 2 August 2025
Data ActArt. 37(11) — legal representativesince 12 September 2025
NIS2Art. 26(3); in Germany § 60(3) BSIGsince 18 October 2024 (Directive); in Germany BSIG in force 6 December 2025
AI Act (high-risk)Art. 22 — authorised representativefrom 2 December 2027 (Annex III) and 2 August 2028 (Annex I), Regulation (EU) 2026/1744

The mandates differ: a closed catalog of tasks in the AI Act (Article 54(3) today, Article 22(3) from 2027/2028), resourcing and own liability in the DSA. The DSA and the AI Act expressly require writing; under NIS2 and the Data Act it is advisable, not prescribed. Regime by regime in our comparison of the EU representative duties; the record in fines for a missing EU representative.

Appoint a representative, or have the borderline case assessed

Appoint a representative through Regingada UG →

Appointment itself is handled by Regingada UG (haftungsbeschränkt), a legally separate company owned by the attorney; legal assessment is a separate mandate with the law firm.

Unsure which applies? Discuss a borderline case with the attorney.

Replies within one business day · CET/CEST (UTC+1/+2)

Frequently asked

Is an EU representative the same as a DPO?

No. The representative is an external contact point for a company without an EU establishment and acts under mandate; the DPO is an independent adviser and monitor inside or for the organization and takes no instructions on the tasks. The triggers are separate, and so are the appointments.

We already have a data protection officer in the United States. Does that satisfy Article 27?

No. Article 27(1) requires a representative in the Union, and Article 27(3) requires it to be established in a Member State where the data subjects concerned are. A DPO outside the Union does not meet either requirement, however well qualified.

Can our European law firm act as our Article 27 representative?

Yes. The EDPB states expressly that the function can be exercised on the basis of a service contract and assumed by law firms, consultancies or private companies established in the Union. Combining it with the role of the same company’s external DPO is what the Board advises against. Here, the representative function sits with Regingada UG, not with the law firm — see its representative setup for companies based in the United States.

Do we have to notify a supervisory authority that we appointed a representative?

Article 27 contains no notification duty. The designation becomes visible through the privacy notice under Articles 13(1)(a) and 14(1)(a). A DPO is different: Article 37(7) requires the contact details to be published and communicated to the supervisory authority.

Can one representative act for several non-EU companies?

Yes. The EDPB confirms that one representative can act on behalf of several non-EU controllers and processors, and that a separate representative is not needed for each processing operation falling under Article 3(2).

Does appointing a representative make us established in the EU?

Under the DSA the answer is in the text: Article 13(5) states that designating a legal representative does not constitute an establishment in the Union. For the GDPR the EDPB takes the same view — the presence of the representative does not constitute an establishment by virtue of Article 3(1). The DSA wording is set out in the legal representative under Article 13 DSA.

Sources