🇪🇺 GDPR & GPSR EU Representation — €490/yr flat · 30-day money-back · Setup in 15 min




📖 Complete Guide · Updated 2026

GDPR Article 27:
The Complete Guide for Non-EU Businesses

Everything you need to know about the EU Representative requirement — who needs it, how to appoint one, what it costs, and what happens if you don’t.

20 min read · Written by EU Shield compliance team

Start Reading ↓

Key Takeaways

  • Any non-EU business processing personal data of EU residents must appoint an EU Representative under GDPR Article 27
  • Failure to comply risks fines up to €20 million or 4% of global annual turnover
  • An EU Representative can be an individual or a service provider — does not need to be a lawyer
  • Cost ranges from €390–€2,000/year depending on provider — EU Shield offers it from €490/year
  • Setup takes 15 minutes and includes representation, correspondence forwarding, and record keeping

1. What is GDPR Article 27?

Article 27 of the EU General Data Protection Regulation (GDPR) requires organizations established outside the European Union to designate a representative in the EU if they process personal data of individuals located in the EU.

EU Shield services: GDPR Article 27 EU Representative · GPSR Responsible Person for product sellers — each €490/year flat, all 27 EU states.

This representative acts as a local point of contact for both:

  • Data subjects (EU residents whose data you process) — they can contact your representative with questions or complaints
  • Supervisory authorities (EU data protection regulators) — they can contact your representative instead of trying to reach you abroad

The representative doesn’t need to be a lawyer or compliance expert. They can be an individual or a specialized service. The key requirement is they are physically located in an EU member state where at least some of your data subjects are.

⚠️ Common misconception: Many non-EU businesses believe GDPR doesn’t apply to them because they don’t have an office in Europe. Under Article 3(2) of the GDPR, any company processing EU residents’ data falls under GDPR jurisdiction — and Article 27 requires them to have a local representative.

The full text of Article 27 states (paraphrased):

“Where Article 3(2) applies, the controller or processor shall designate in writing a representative in the EU. The representative shall be established in one of the member states where the data subjects whose personal data are processed in relation to the offering of goods or services, or whose behavior is monitored, are located.”

The representative mandate applies to both controllers and processors. Whether you own the data or process it for someone else — if you’re non-EU and handle EU personal data, you need a representative.

2. Who Needs an EU Representative?

You need an EU Representative under Article 27 if:

  • You are established outside the European Union
  • AND you process personal data of individuals located in the EU
  • AND your processing relates to either:
    • Offering goods or services to EU residents (even if free), OR
    • Monitoring their behavior (e.g., tracking, analytics, profiling)

This includes:

🌐 SaaS Companies

If your software has EU users — even one — you likely process their data. GDPR applies regardless of company size.

→ Guide for SaaS →

🛒 E-commerce Stores

Selling to EU customers on Shopify, Amazon, Etsy, or your own store? You process their data for order fulfillment.

→ Guide for E-commerce →

🏭 Manufacturers

Exporting physical goods to Europe? Your customer data, shipping data, and warranty data are all covered.

→ Guide for Manufacturers →

💼 Consultants & Coaches

Online courses, coaching clients, consulting projects with EU residents — all trigger the requirement.

📱 App Developers

Your mobile app has EU users? Their analytics data, account data, even device IDs count as personal data.

🛠️ Freelancers

Even as a solo founder or freelancer, if you work with EU clients or users, Article 27 applies.

3. Who is Exempt?

The only exemption from Article 27 is under Article 27(2)(a):

“This obligation shall not apply to processing which is occasional, does not include large scale processing of special categories of data or personal data relating to criminal convictions and offenses, and is unlikely to result in a risk to the rights and freedoms of natural persons.”

In practice, very few businesses qualify for this exemption. The three conditions must all be met simultaneously:

  1. Occasional processing — not regular or systematic
  2. No large-scale special data — no health data, biometrics, criminal records, etc.
  3. Low risk — unlikely to harm data subjects’ rights
🚨 Reality check: If you’re running a business with EU customers, your data processing is NOT occasional. It’s systematic and ongoing. Most commercial businesses do NOT qualify for the Article 27 exemption. Relying on this exemption without proper legal basis is a common and dangerous mistake.

Even the European Data Protection Board (EDPB) has stated that the exemption should be interpreted narrowly. If in doubt, you likely need a representative.

4. What Are the Representative’s Obligations?

Your EU Representative must be:

  • Designated in writing — a formal written agreement appointing them
  • Named in your privacy policy — data subjects must know who to contact
  • Physially established in the EU — they need an EU address
  • Available and responsive — they must handle communications from data subjects and regulators
  • Maintaining records — they hold copies of your processing records under Article 30

What your EU Representative actually does:

Responsibility Details
Forward communications Receive and forward data subject requests (access, deletion, rectification, etc.) to you within regulatory deadlines
Regulator contact Act as first point of contact for EU supervisory authorities; forward regulatory inquiries to you
Record keeping Hold and maintain a copy of your Article 30 processing records, available on request by regulators
Privacy policy listing Your privacy policy must include the representative’s name, address, email, and phone
Legal representation In some jurisdictions, the representative can be addressed in legal proceedings regarding data protection

Important: The representative is NOT liable for your GDPR compliance. Liability stays with you (the controller or processor). However, they must be reachable — an unresponsive representative defeats the purpose and could worsen your regulatory risk.

5. What Are the Fines for Non-Compliance?

GDPR fines are structured in two tiers:

  • Tier 1: Up to €10 million or 2% of global annual turnover — for violations including lack of Article 27 representative
  • Tier 2: Up to €20 million or 4% of global annual turnover (whichever is higher) — for core data processing violations
💶 Real fines in 2025-2026:
• Meta: €1.2 billion (2023) — Schrems II violations
• Amazon: €746 million (2021) — advertising data processing
• TikTok: €345 million (2023) — children’s data violations
• Clearview AI: €20 million (multiple fines) — biometric data

While these are extreme cases, regulators are increasingly targeting non-EU companies. Your risk is real — and growing every year as EU enforcement becomes more aggressive.

But the REAL risk isn’t just the fine. The practical consequences of non-compliance include:

  • Regulatory investigation — which costs time, legal fees, and management attention
  • Reputational damage — being publicly named as non-compliant by an EU regulator
  • Data processing bans — regulators can order you to stop processing EU residents’ data entirely
  • Loss of EU business — EU partners and customers increasingly check for GDPR compliance before doing business

Having an EU Representative is the single cheapest and easiest way to demonstrate good faith compliance. It doesn’t solve all GDPR obligations, but it’s the minimum viable requirement every non-EU business must meet.

→ Read our full GDPR fines analysis (2025-2026) →

6. How Much Does an EU Representative Cost?

The cost of an EU Representative varies significantly by provider and complexity:

🇪🇺 EU Shield

€490/yr

All-inclusive: representation, correspondence forwarding, record keeping, privacy policy support, 30-day guarantee

⚖️ Specialist Services

€800–€2,000/yr

Niche compliance providers, often include legal review or DPO services alongside representation

🏛️ Law Firms

€1,500–€5,000/yr

Premium legal support — overkill for simple Article 27 compliance but suitable for complex cases

🛠️ DIY / Individual

€200–€500/yr

Find a trusted EU-based individual. Risky — what happens when they’re unavailable or move? No SLA, no backup.

What affects the price:

  • Complexity of your data processing
  • Number of EU member states where your data subjects are located
  • Volume of data subject requests you typically receive
  • Whether you need additional services (DPO, legal review, breach notification)

For most non-EU SaaS companies, e-commerce stores, and small manufacturers, €490/year covers everything you need.

→ Detailed cost breakdown with all service comparisons →

7. How to Appoint an EU Representative

Appointing an EU Representative is straightforward. Here’s the step-by-step process:

  1. Choose a provider — select an EU-based service like EU Shield that specializes in Article 27 representation
  2. Sign the designation agreement — a formal written contract appointing them as your representative (required by law)
  3. Provide processing details — share your Article 30 records so the representative can hold them as required
  4. Update your privacy policy — add your representative’s name, address, email, and phone under a dedicated “EU Representative” section
  5. Notify your EU stakeholders — if relevant, inform EU partners or customers of your compliance status
  6. Keep it current — update your representative if your processing changes or if the provider changes
💡 With EU Shield: The entire process takes 15 minutes. Fill out the form, sign digitally, and your representation is active by the next business day. We handle regulator correspondence, data subject requests, and record keeping from our EU office.

What to include in your privacy policy:

Under Article 27, your privacy policy must include a section like this:

EU Representative
Pursuant to Article 27 of the GDPR, [Company Name] has appointed an EU Representative:

EU Shield
[Address]
Email: compliance@eushield.eu
Phone: [phone number]

EU residents may contact our representative regarding data protection matters.

→ Step-by-step guide with templates →

8. EU Representative vs DPO vs Law Firm

Many businesses confuse the EU Representative with other roles. Here’s the difference:

Role Required By Purpose Cost
EU Representative (Art. 27) All non-EU controllers/processors Point of contact for data subjects and regulators €490–€2,000/yr
DPO (Art. 37-39) Public authorities + specific large-scale processing Internal compliance advisor, monitoring and advising €3,000–€15,000/yr
Law Firm Voluntary (when needed) Legal advice, representation in disputes €200–€500/hr

Key distinction: An EU Representative is a mandatory compliance role. A DPO is an advisory role. A law firm provides legal services. You might need all three — but most non-EU businesses only need the Representative.

→ Full comparison: EU Representative vs DPO →
→ EU Representative vs Law Firm: what you actually need →

9. Country-Specific Requirements

While Article 27 is EU-wide, some countries have additional nuances:

🇺🇸 US Companies

Most common non-EU nationality needing a representative. US businesses selling to EU must comply — no exceptions based on size or revenue.

→ US Companies Guide →

🇬🇧 UK Companies

Post-Brexit: UK is third country. UK companies selling into the EU need an EU Representative. High urgency — many UK companies don’t realize this.

→ UK Companies Guide →

🇨🇦 Canadian Companies

Canada has PIPEDA, but PIPEDA ≠ GDPR. Canadian businesses selling into Europe still need an EU Representative.

→ Canadian Companies Guide →

🇦🇺 Australian Companies

Australia has its own Privacy Act — but it doesn’t cover EU requirements. Article 27 applies independently.

→ Australian Companies Guide →

🇮🇳 Indian Companies

India has DPDP Act (2023) — similar framework, but no reciprocity with GDPR. EU Representative still mandatory.

→ Indian Companies Guide →

🇧🇷 Brazilian Companies

LGPD (Brazil’s GDPR equivalent) helps with internal compliance culture, but doesn’t satisfy EU Article 27.

Where should your Representative be located? Choose an EU member state where a significant number of your data subjects are. Ireland, Netherlands, and Germany are popular choices due to their cost-effective compliance ecosystems. EU Shield operates from our EU office covering all member states.

10. Frequently Asked Questions

Do I need an EU Representative if I’m a solo founder with no EU office?
Yes. If you offer goods or services to EU residents, or monitor their behavior, you need an EU Representative regardless of your company size or whether you have an EU office. The GDPR applies to “any size” business — there is no small business exemption.
Can my EU Representative be a friend or business partner in Europe?
Technically yes, but it’s risky. If they’re unavailable, move, change jobs, or don’t respond in time, you face regulatory consequences. Professional services have SLAs, backup staff, and compliant processes. We’ve seen businesses get into trouble because their “friend” went on vacation during a regulator inquiry.
How quickly do I need to respond to data subject requests?
GDPR requires response within one month, extendable to two months for complex requests. Your EU Representative should forward requests to you immediately — ideally within 24 hours — so you don’t miss deadlines. With EU Shield, you get same-day forwarding.
Is an EU Representative the same as a DPO?
No. An EU Representative (Article 27) is a mandatory point of contact for non-EU businesses. A DPO (Articles 37-39) is an internal compliance advisor required for public authorities and specific large-scale processing. Different roles, different legal bases. Some businesses need both.
What if I already have a registered office in the EU?
If you have an actual establishment in the EU (office, subsidiary, branch), you don’t need a separate Article 27 representative — your EU establishment serves that function. However, you must still comply with all other GDPR requirements. This is a common source of confusion.
What happens if I ignore Article 27 entirely?
You risk Tier 1 fines (up to €10M or 2% of global turnover), regulatory investigation, reputational damage, and potential data processing bans. EU regulators are increasingly active against non-EU companies. The risk grows every year as enforcement becomes more systematic. The cost of a representative (€490/year) is negligible compared to these risks.
Do UK companies still need an EU Representative after Brexit?
Yes. The UK is a third country under GDPR. UK companies selling into the EU, or processing EU residents’ data, need an EU Representative. Additionally, UK companies may need a UK Representative under the UK GDPR (post-Brexit equivalent).
Does GDPR apply if I only have a few EU customers?
Yes. There is no minimum threshold. Even one EU customer or user triggers GDPR obligations if you process their personal data. The only exception is the narrow Article 27(2)(a) exemption for occasional, low-risk processing — which rarely applies to commercial businesses.

Ready to Get Compliant?

Appointing an EU Representative is the single most important compliance step for non-EU businesses selling into Europe. It’s affordable, straightforward, and protects you from escalating regulatory risk.

With EU Shield, you get:

  • ✅ EU Representative designation — active by next business day
  • ✅ 24-hour correspondence forwarding from data subjects and regulators
  • ✅ Article 30 record keeping at our EU office
  • ✅ Privacy policy support and template updates
  • ✅ Annual compliance check-in
  • ✅ 30-day money-back guarantee
  • ✅ €490/year — flat fee, no hidden costs
Get Your EU Representative →

Setup in 15 minutes · No lawyers needed · 30-day money-back

Disclaimer: This guide provides general information about GDPR Article 27 requirements. It does not constitute legal advice. For specific legal questions, consult a qualified data protection attorney. EU Shield provides EU Representative services, not legal representation.

Ready to get compliant?

Get your GDPR Article 27 EU Representative set up in 15 minutes. Flat €490/year, 30-day money-back guarantee.

Get Your EU Representative →