Skip to content
Topic Contested in court

Representatives

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Representatives of controllers not established in the EU

215 linked items 13 Laws57 Case Law24 Guidance69 Enforcement25 News

Overview

26 sources · Sep 25, 2026

Legal Framework

The designation of an EU representative is governed primarily by Article 27 GDPR, which triggers when the extraterritorial scope rule in Article 3(2) applies. A controller or processor not established in the Union must appoint a natural or legal person established in an EU Member State to act on its behalf. The definition in Article 4(17) confirms that a representative is one who "represents the controller or processor with regard to their respective obligations" under the Regulation.

The core obligation is mandatory and formal:

"Where Article 3(2) applies, the controller or the processor shall designate in writing a representative in the Union."
— GDPR Art. 27(1)

Two exemptions apply: occasional processing that does not involve large-scale special categories of data and is unlikely to result in risk to data subjects' rights (Article 27(2)(a)), and processing by public authorities (Article 27(2)(b)). The representative must be established in a Member State where the affected data subjects are located (Article 27(3)). Critically, the designation creates a point of contact but does not shield the controller or processor from direct legal action:

"The designation of a representative by the controller or processor shall be without prejudice to legal actions which could be initiated against the controller or the processor themselves."
— GDPR Art. 27(5)

Representatives also feature in the record-keeping regime under Article 30, which requires that records of processing activities include the representative's name and contact details. Transparency obligations under Article 13(1)(a) and Article 14(1)(a) require controllers to inform data subjects of the representative's identity and contact details at the time of data collection.

Key Developments

The CJEU has confirmed the representative's role within the broader compliance architecture. In UZ v Bundesrepublik Deutschland, the Court referenced Article 30's requirement that the representative maintain records of processing activities, underscoring that the representative bears operational record-keeping duties — not merely a letterbox function. In X v Russmedia Digital SRL and Inform Media Press SRL, the Court reinforced that information obligations extend to identifying the representative to data subjects:

"the identity and the contact details of the controller and, where applicable, of the controller's representative"
— X v Russmedia Digital SRL, ¶18

The EDPB has emphasized that representatives must facilitate communication between data subjects and the controller, particularly regarding the exercise of data subject rights:

"the identity and contact details of the representative must be provided to data subjects in accordance with articles 13 and 14"
— EDPB Guidelines 3/2018, §79

The Belgian DPA has actively enforced these transparency requirements, finding controllers deficient where privacy policies failed to explicitly identify the representative by name and contact details.

Status of the Debate

The representative requirement itself is well-established, but its boundaries remain contested in litigation. Courts have diverged on the scope of the "establishment" concept under Article 3 — and thus on when the Article 27 obligation triggers — as seen in the divergent applications of the Google Spain and Amazon EU Sàrl lines of reasoning. The EDPB Guidelines 3/2018 provide the most detailed interpretive framework, but open questions remain about the representative's personal liability, the sufficiency of written mandates, and the interaction between the representative's obligations and the controller's primary responsibility. A CJEU ruling directly addressing the scope of a representative's operational duties under Article 27(4) would resolve the principal open question.

Practical Guidance

  • Execute a written mandate. Article 27(1) requires written designation. The mandate should expressly enumerate the representative's authority to receive communications from supervisory authorities and data subjects, consistent with Article 27(4).
  • Establish the representative in the correct Member State. Under Article 27(3), the representative must be established in a Member State where the data subjects whose data are processed are located. Where processing targets data subjects across multiple Member States, consider appointing representatives in each relevant jurisdiction or designating a single representative in the state of the main establishment.
  • Disclose the representative's identity in all privacy notices. Article 13(1)(a) and Article 14(1)(a) require controllers to provide the representative's name and contact details. The Belgian DPA enforcement confirms that vague references are insufficient — the representative must be explicitly identified.
  • Maintain records through the representative. Article 30 obliges the representative to maintain records of processing activities and make them available to supervisory authorities on request. Ensure the representative has access to the controller's processing inventory.
  • Do not treat the representative as a liability shield. Article 27(5) preserves direct legal action against the controller or processor. The representative facilitates compliance but does not absorb liability.
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
Greek SA fines Clearview AI for EUR 20M A rundown of the fine on IAPP: https://iapp.org/news/a/a-rundown-of-the-greek-dpas-clearview-ai-fine-findings News IAPP Oct 2022 Obligation to designate EEA representative
why this is here
in line with Article 27 of the GDPR, the HDPA ruled that Clearview AI was obliged to designate a representative established within the EEA

The document discusses the Article 27 GDPR obligation for non-EU controllers to appoint a representative, directly covering this topic.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

EU Court: Consumer Protection Associations May File Representative Actions Against Violations of Personal Data Protection ⇄ An association representing consumer interests may bring a representative action against the alleged perpetrator of a personal data breach. A specific breach of a data subject's… News NL EU Court Expert Apr 2022 consumer associations as representatives
why this is here
Het orgaan, de organisatie of de vereniging moet binnen de personele werkingssfeer van artikel 80, lid 2 van de AVG vallen. Een consumentenbeschermingsvereniging zoals in deze zaak valt binnen die werkingssfeer.

The document discusses which bodies can act as representatives under GDPR, a related but distinct concept from representatives of non-EU controllers under Article 27.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

This is the top of each pile — all 57 Case Law · all 24 Guidance · all 69 Enforcement · all 27 Literature · all 25 News