Skip to content
GDPR Art. 27 EN
LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this article. Contains: the article text, related recitals, cases citing it, enforcement stats and top fines, guidance, and related topics. Everything links back to its source on overview.legal — legal information, not advice.

Representatives of controllers or processors not established in the Union

In force — consolidated2016-05-04 · CELEX 02016R0679-20160504 · ELI ↗
Version history 2
  • 2016-05-04in force CELEX 02016R0679-20160504
  • 2016-04-27 CELEX 32016R0679
  1. 1.

    Where Article 3(2) applies, the controller or the processor shall designate in writing a representative in the Union.

  2. 2.

    The obligation laid down in paragraph 1 of this Article shall not apply to:

    1. a)
      processing which is occasional, does not include, on a large scale, processing of special categories of data as referred to in Article 9(1) or processing of personal data relating to criminal convictions and offences referred to in Article 10, and is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account the nature, context, scope and purposes of the processing; or
    2. b)
      a public authority or body.
  3. 3.

    The representative shall be established in one of the Member States where the data subjects, whose personal data are processed in relation to the offering of goods or services to them, or whose behaviour is monitored, are.

  4. 4.

    The representative shall be mandated by the controller or processor to be addressed in addition to or instead of the controller or the processor by, in particular, supervisory authorities and data subjects, on all issues related to processing, for the purposes of ensuring compliance with this Regulation.

  5. 5.

    The designation of a representative by the controller or processor shall be without prejudice to legal actions which could be initiated against the controller or the processor themselves.

Enforcement

Cited in 20 fines totalling €3.1M

Top authority: 🇪🇺Croatian Data Protection Authority (azop) (12) · median fine €3,500 · see all enforcement for Art. 27 →

Connections by provision

27(1) 87 Case Law 15 Enforcement 12 Guidance .md
27(2) 10 Enforcement 16 Guidance .md
27(2)(a) 2 Guidance .md
27(3) 4 Guidance .md
27(4) 2 Case Law 2 Enforcement 2 Guidance 1 Literature .md
27(5) 4 Guidance 1 Literature .md

Related across sources

C-507/17 Google LLC v CNIL C-507/17 (Google Territorial Scope) CJEU Sep 24, 2019 Territorial scope (GDPR) Right to be Forgotten Direct Marketing
Guidelines 3/2018 territorial scope of the GDPR (Article 3) Guidelines on the territorial scope of the GDPR Guidelines ·EDPB Nov 12, 2019 Territorial scope (GDPR) IP Address Processors
C-306/21 Komisia za zashtita na lichnite danni and Tsentralna izbiratelna komisia v Koalitsia „Demokratichna Bulgaria - Obedinenie“ In this preliminary ruling, the Court of Justice of the European Union addressed whether the GDPR applies to the processing of personal data during national and European elections… CJEU ·Eighth Chamber Oct 20, 2022 Material scope (GDPR) Supervision Personal Data
451423 French Supreme Court reviews CNIL €35M cookie consent fine against Amazon The French DPA had received a complaint on 28 May 2018 regarding the lawfulness of processing by Amazon Europe Core ('Provider' or 'The company'). The French DPA had forwarded… Supreme Administrative Court Jun 27, 2022 Consent Cookies Supervision
Guidelines 02/2024 Article 48 GDPR Article 48 GDPR provides that: ' Any judgment of a court or tribunal and any decision of an administrative authority of a third country requiring a controller or processor to… Guidelines ·EDPB Jun 5, 2025 Controllers Privacy Shield International Transfer