# Representatives of controllers or processors not established in the Union — GDPR — context bundle

> Focused context for a single provision, curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/laws/gdpr/art-27
> Every item cites its source. Verify against the official text (EUR-Lex / wetten.overheid.nl) before relying on it.

## Provision

### Representatives of controllers or processors not established in the Union — Representatives of controllers or processors not established in the Union

*GDPR, gdpr-art-27-en — https://overview.legal/laws/gdpr/art-27*

1. Where Article 3(2) applies, the controller or the processor shall designate in writing a representative in the Union.

2. The obligation laid down in paragraph 1 of this Article shall not apply to:
   a) processing which is occasional, does not include, on a large scale, processing of special categories of data as referred to in Article 9(1) or processing of personal data relating to criminal convictions and offences referred to in Article 10, and is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account the nature, context, scope and purposes of the processing; or
   b) a public authority or body.

3. The representative shall be established in one of the Member States where the data subjects, whose personal data are processed in relation to the offering of goods or services to them, or whose behaviour is monitored, are.

4. The representative shall be mandated by the controller or processor to be addressed in addition to or instead of the controller or the processor by, in particular, supervisory authorities and data subjects, on all issues related to processing, for the purposes of ensuring compliance with this Regulation.

5. The designation of a representative by the controller or processor shall be without prejudice to legal actions which could be initiated against the controller or the processor themselves.

## Enforcement

19 decision(s) on record cite Article 27, totalling approximately €2,904,185 in fines (median €3,343).

Top fines:
- **Alpha Exploration: Non-compliance with general data processing principles** (ITALY, €2,000,000) — https://overview.legal/posts/47626
- **Locatefamily.com: Non-compliance with general data processing principles** (THE NETHERLANDS, €525,000) — https://overview.legal/posts/46793
- **Italian DPA finds GDPR applies to US-based Character.AI service** (Italy, €158,000) — https://overview.legal/posts/108999
- **TIGER MEDIA INC.: Insufficient legal basis for data processing** (Spain, €72,000) — https://overview.legal/posts/53641
- **AEPD sanctions Tiger Media Inc. for installing advertising cookies without user consent** (Spain, €72,000) — https://overview.legal/posts/158452

## Guidance

### Opinion 13/2026 on the draft decision of the Office of the Data Protection Ombudsman (FI SA) regarding the approval of the requirement for accreditation of a certification body pursuant to Article 43(3) GDPR

*EDPB — https://overview.legal/posts/125674*

Opinion 13 /2026 on the draft decision of the Office of the Data Protection Ombudsman (FI SA) regarding the approval of the requirement for accreditation of a certification body pursuant to Article 43(3) GDPR Adopted on 15 April 2026 1 | Adopted 2 | Adopted The European Data Protection Board has adopted the following statement: Having regard to Article 43(3), 63, Article 64 (1)(c) and Article 64(3) - (8) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016…

### Opinion 14/2026 on the Europrivacy certification criteria regarding their approval by the Board as European Data Protection Seal pursuant to Article 42.5 GDPR

*EDPB — https://overview.legal/posts/125682*

Opinion 14 / 2026 on the Europrivacy certification criteria regarding their approval by the Board as European Data Protection Seal pursuant to Article 42.5 GDPR Adopted on 15 April 2026 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64 (2) and Article 42 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free…

### Opinion 34/2025 on the draft decision of the Greek Supervisory Authority regarding C.E.C.L certification criteria

*EDPB — https://overview.legal/posts/51416*

Adopted Opinion 34/ 2025 on the draft decision of the Greek Supervisory Authority regarding C.E.C.L certification criteria Adopted on 02 December 2025 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)(c) and Article 42 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and…

### Guidelines 02/2024 on Article 48 GDPR

*EDPB — https://overview.legal/posts/38045*

Article  48  GDPR  provides  that:  ' Any  judgment  of  a  court  or  tribunal  and  any  decision  of  an administrative authority of a third country requiring a controller or processor to transfer or disclose personal data  may  only  be  recognised  or  enforceable  in  any  manner  if  based  on  an  international agreement, such as a mutual legal assistance treaty, in force between the requesting third country and the Union or a Member State, without prejudice to other grounds for transfer...

### Guidelines 02/2024 on Article 48 GDPR

*EDPB — https://overview.legal/posts/50894*

Adopted Guidelines 02/2024 on Article 48 GDPR Version 2.1 Adopted on 4 June 2025 Adopted 2 Version history Version 1.0 2 December 2024 Adoption of the Guidelines for public consultation Version 2.0 4 June 2025 Adoption of the Guidelines after public consultation Version 2.1 20 June 2025 Improved resolution of Annex Adopted 3 EXECUTIVE SUMMARY Article 48 GDPR provides that: “ Any judgment of a court or tribunal and any decision of an administrative authority of a third country requiring a…

## Related topics

- **Territorial scope (GDPR)** — https://overview.legal/topics/territorial-scope
  ## Legal Framework

---
Generated by overview.legal · https://overview.legal/laws/gdpr/art-27 · 2026-08-22
