Representatives
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Representatives of controllers not established in the EU
Overview
24 sources · Jul 23, 2026Legal Framework
The representative regime under the GDPR operates as a bridge between the Regulation's extraterritorial reach and its enforcement machinery. Article 3(2) extends the GDPR to controllers and processors not established in the Union when they offer goods or services to data subjects in the Union or monitor their behaviour there. Article 3(3) likewise applies the Regulation to controllers not established in the Union but in a place where Member State law applies by virtue of public international law. Article 27 GDPR (referenced in the enforcement guidance below) then requires such controllers and processors to designate a representative in the Union, unless an exemption applies.
The transparency obligations reinforce this mechanism. Article 13(1)(a) requires controllers collecting data directly from data subjects to provide:
"the identity and the contact details of the controller and, where applicable, of the controller's representative"
— GDPR Art. 13(1)(a)
A parallel obligation exists in Article 14(1)(a) for data not obtained from the data subject. The representative thus functions both as an enforcement contact point for supervisory authorities and as a transparency anchor for data subjects.
Key Developments
The EDPB has confirmed the interplay between territorial scope and the representative requirement. In its Guidelines 9/2022 on personal data breach notification, the Board stated:
"Article 27 GDPR requires a controller (and a processor) to designate a representative in the EU where Article 3(2) GDPR applies."
— EDPB Guidelines 9/2022 §72
This means a non-EU controller caught by Article 3(2) that experiences a breach remains bound by Articles 33 and 34 notification obligations — and the representative serves as the local interface for that compliance.
The CJEU in Fashion ID addressed the information duty in the context of joint controllers, holding:
"the controller or his representative must provide, as a minimum, the information referred to in that provision to the subject whose data are being collected"
— Fashion ID ¶104
While Fashion ID concerned joint-controller liability under Article 26, the Court's confirmation that the information obligation attaches to "the controller or his representative" underscores that the representative's role is not merely formal — it is a channel through which statutory information duties are discharged.
Status of the Debate
The core obligation to designate a representative under Article 27 when Article 3(2) applies is settled in the guidance. What remains contested is the boundary of Article 3(2) itself — particularly the meaning of "offering goods or services" and "monitoring behaviour" — which determines whether the representative requirement is triggered at all. The EDPB's Guidelines 3/2018 provide the prevailing interpretive framework, but courts have not yet produced a definitive ruling on the precise thresholds for Article 3(2)(a) and (b) in novel factual settings. A CJEU reference on the scope of "offering goods or services" to data subjects in the Union would resolve the principal open question.
Practical Guidance
- Determine establishment status first. Assess whether your organisation has an "establishment" in the Union under Article 3(1). If not, evaluate whether Article 3(2)(a) or (b) applies — only then does the Article 27 representative obligation arise.
- Designate a representative in every relevant Member State. Article 27 requires designation in a Member State where the data subjects are located, unless processing is occasional, non-likely-to-result-in-risk, and not involving special-category data.
- Include representative contact details in all privacy notices. Both Article 13(1)(a) and Article 14(1)(a) require disclosure of the representative's contact details where applicable — omitting this is a standalone transparency violation.
- Ensure the representative can act as a breach-notification contact. Per the EDPB's Guidelines 9/2022 §72, non-EU controllers subject to Article 3(2) must comply with Articles 33 and 34; the representative should be positioned to facilitate timely notification to the competent supervisory authority.
- Document the Article 3(2) analysis. Maintain a written territorial-scope assessment demonstrating why the representative is or is not required, so that the decision can be defended if challenged by a supervisory authority.