← GDPR · Controller obligations

Art.27 — EU representative for non-EU organisations

high roles-responsibilitiescross-border-transfer

Requirement

A controller or processor not established in the EU that offers goods or services to, or monitors the behaviour of, people in the EU (Article 3(2)) must designate in writing a representative in a Member State where those people are, unless processing is occasional, not large-scale special-category or criminal data, and unlikely to result in a risk.

UK GDPR: Non-UK organisations targeting people in the UK need a UK representative under Article 27 UK GDPR; an EU representative does not cover the UK, and vice versa.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
eu representativerepresentative in the eurepresentative in the unionarticle 27 representativegdpr representativeuk representativeestablished in the eunot established in the euestablished in the union
Required element 2 — any one of
designat…appointappointedcontactwritten mandatenot requiredexemptoccasional
Supporting terms — specificity signals
article 27article 3(2)mandateprivacy noticemember state

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
SOC 2 CC1.3 Organisational structure and reporting lines roles-responsibilities
SOC 2 CC1.5 Accountability for control responsibilities roles-responsibilities
ISO 27001 A.5.2 Information security roles and responsibilities roles-responsibilities
HIPAA 164.308(a)(2) Assigned security responsibility (R) roles-responsibilities
GLBA 314.4(a) Qualified Individual oversees the information security program roles-responsibilities
NIST CSF 2.0 GV.RR-02 Roles, responsibilities and authorities are established roles-responsibilities
NDPA 2023 s.32 Designation of a Data Protection Officer roles-responsibilities
NDPA 2023 s.41-43 Cross-border transfer of personal data cross-border-transfer