Representatives
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Representatives of controllers not established in the EU
Overview
26 sources · Sep 25, 2026Legal Framework
The designation of an EU representative is governed primarily by Article 27 GDPR, which triggers when the extraterritorial scope rule in Article 3(2) applies. A controller or processor not established in the Union must appoint a natural or legal person established in an EU Member State to act on its behalf. The definition in Article 4(17) confirms that a representative is one who "represents the controller or processor with regard to their respective obligations" under the Regulation.
The core obligation is mandatory and formal:
"Where Article 3(2) applies, the controller or the processor shall designate in writing a representative in the Union."
— GDPR Art. 27(1)
Two exemptions apply: occasional processing that does not involve large-scale special categories of data and is unlikely to result in risk to data subjects' rights (Article 27(2)(a)), and processing by public authorities (Article 27(2)(b)). The representative must be established in a Member State where the affected data subjects are located (Article 27(3)). Critically, the designation creates a point of contact but does not shield the controller or processor from direct legal action:
"The designation of a representative by the controller or processor shall be without prejudice to legal actions which could be initiated against the controller or the processor themselves."
— GDPR Art. 27(5)
Representatives also feature in the record-keeping regime under Article 30, which requires that records of processing activities include the representative's name and contact details. Transparency obligations under Article 13(1)(a) and Article 14(1)(a) require controllers to inform data subjects of the representative's identity and contact details at the time of data collection.
Key Developments
The CJEU has confirmed the representative's role within the broader compliance architecture. In UZ v Bundesrepublik Deutschland, the Court referenced Article 30's requirement that the representative maintain records of processing activities, underscoring that the representative bears operational record-keeping duties — not merely a letterbox function. In X v Russmedia Digital SRL and Inform Media Press SRL, the Court reinforced that information obligations extend to identifying the representative to data subjects:
"the identity and the contact details of the controller and, where applicable, of the controller's representative"
— X v Russmedia Digital SRL, ¶18
The EDPB has emphasized that representatives must facilitate communication between data subjects and the controller, particularly regarding the exercise of data subject rights:
"the identity and contact details of the representative must be provided to data subjects in accordance with articles 13 and 14"
— EDPB Guidelines 3/2018, §79
The Belgian DPA has actively enforced these transparency requirements, finding controllers deficient where privacy policies failed to explicitly identify the representative by name and contact details.
Status of the Debate
The representative requirement itself is well-established, but its boundaries remain contested in litigation. Courts have diverged on the scope of the "establishment" concept under Article 3 — and thus on when the Article 27 obligation triggers — as seen in the divergent applications of the Google Spain and Amazon EU Sàrl lines of reasoning. The EDPB Guidelines 3/2018 provide the most detailed interpretive framework, but open questions remain about the representative's personal liability, the sufficiency of written mandates, and the interaction between the representative's obligations and the controller's primary responsibility. A CJEU ruling directly addressing the scope of a representative's operational duties under Article 27(4) would resolve the principal open question.
Practical Guidance
- Execute a written mandate. Article 27(1) requires written designation. The mandate should expressly enumerate the representative's authority to receive communications from supervisory authorities and data subjects, consistent with Article 27(4).
- Establish the representative in the correct Member State. Under Article 27(3), the representative must be established in a Member State where the data subjects whose data are processed are located. Where processing targets data subjects across multiple Member States, consider appointing representatives in each relevant jurisdiction or designating a single representative in the state of the main establishment.
- Disclose the representative's identity in all privacy notices. Article 13(1)(a) and Article 14(1)(a) require controllers to provide the representative's name and contact details. The Belgian DPA enforcement confirms that vague references are insufficient — the representative must be explicitly identified.
- Maintain records through the representative. Article 30 obliges the representative to maintain records of processing activities and make them available to supervisory authorities on request. Ensure the representative has access to the controller's processing inventory.
- Do not treat the representative as a liability shield. Article 27(5) preserves direct legal action against the controller or processor. The representative facilitates compliance but does not absorb liability.
why this is here
in line with Article 27 of the GDPR, the HDPA ruled that Clearview AI was obliged to designate a representative established within the EEA
The document discusses the Article 27 GDPR obligation for non-EU controllers to appoint a representative, directly covering this topic.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
Het orgaan, de organisatie of de vereniging moet binnen de personele werkingssfeer van artikel 80, lid 2 van de AVG vallen. Een consumentenbeschermingsvereniging zoals in deze zaak valt binnen die werkingssfeer.
The document discusses which bodies can act as representatives under GDPR, a related but distinct concept from representatives of non-EU controllers under Article 27.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
Nothing of this type on this topic.
This is the top of each pile — all 57 Case Law · all 24 Guidance · all 69 Enforcement · all 27 Literature · all 25 News