← GDPR · Controller obligations
Art.27 — EU representative for non-EU organisations
Requirement
A controller or processor not established in the EU that offers goods or services to, or monitors the behaviour of, people in the EU (Article 3(2)) must designate in writing a representative in a Member State where those people are, unless processing is occasional, not large-scale special-category or criminal data, and unlikely to result in a risk.
UK GDPR: Non-UK organisations targeting people in the UK need a UK representative under Article 27 UK GDPR; an EU representative does not cover the UK, and vice versa.
What the engine looks for
Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.
Equivalent controls elsewhere
Matched on shared topics. Satisfying this control usually moves these too.
| Framework | Control | Title | Shared topics |
|---|---|---|---|
| SOC 2 | CC1.3 | Organisational structure and reporting lines | roles-responsibilities |
| SOC 2 | CC1.5 | Accountability for control responsibilities | roles-responsibilities |
| ISO 27001 | A.5.2 | Information security roles and responsibilities | roles-responsibilities |
| HIPAA | 164.308(a)(2) | Assigned security responsibility (R) | roles-responsibilities |
| GLBA | 314.4(a) | Qualified Individual oversees the information security program | roles-responsibilities |
| NIST CSF 2.0 | GV.RR-02 | Roles, responsibilities and authorities are established | roles-responsibilities |
| NDPA 2023 | s.32 | Designation of a Data Protection Officer | roles-responsibilities |
| NDPA 2023 | s.41-43 | Cross-border transfer of personal data | cross-border-transfer |