A UK company offering goods or services to people in the Union, or monitoring them, needs an Article 27 representative. The exemption is narrow.
The question comes up in an enterprise customer's security questionnaire, in an app store review, or in a data processing agreement sent for signature: who is your Article 27 representative in the Union? For a company in London the instinct is that Brexit ended all of this. It did the opposite.
Why leaving the Union created the obligation
The GDPR reaches beyond the Union through Article 3(2). It applies to a controller or processor with no establishment in the Union where the processing relates to offering goods or services to people in the Union, or to monitoring their behaviour within it. While the United Kingdom was a Member State, a UK company was established in the Union and Article 27 did not apply to it. From the end of the transition period the United Kingdom is a third country, so a UK company with no EU establishment is in exactly the position of a company in New York or Tel Aviv.
Article 27 then requires the controller or processor to designate a representative in the Union, in writing.
Nothing about the company changed. The border moved, and the obligation followed.
The exemption is narrower than it looks
Article 27(2) is where most self-assessments go wrong, because it reads like a small-business exemption and is not one. It applies only where the processing is occasional, does not include on a large scale special category data under Article 9 or criminal conviction data under Article 10, and is unlikely to result in a risk to the rights and freedoms of individuals. The three limbs are cumulative.
A shop that ships to customers in the Union all year, a SaaS product with European users logging in daily, an app whose analytics profile European visitors: none of these is occasional processing. Occasional means what it says.
What the representative is, and what it is not
The representative is the company's point of contact in the Union. It is named in the privacy notice, supervisory authorities and data subjects may address it on all issues related to the processing, and it holds the record of processing activities under Article 30 so that the record can be produced to an authority on request.
It is not a Data Protection Officer. The DPO under Article 37 is an oversight role with independence requirements, and a company can need both. It is also not a liability shield: the obligations remain the controller's.
Article 27(3) requires the representative to be established in one of the Member States where the people whose data is processed are. Where a company serves the whole Union, any Member State qualifies, which makes the choice a practical one about language, responsiveness and who is actually behind the address.
The mirror obligation
The traffic runs both ways. The UK GDPR requires a company established in the Union with no UK establishment, which offers goods or services to people in the United Kingdom or monitors them, to appoint a UK representative. An EU company selling into Britain has the same problem in reverse, and one appointment does not satisfy the other.
If you sell into the EU from the UK and are unsure whether Article 27 applies, write to us at office@kleanthousplatis.com, or the enquiry form. We reply within one business day.
What this means in practice
- If the company has no office, branch or subsidiary in the Union and it sells to people there, assume Article 27 applies and test the exemption properly rather than assuming it fits.
- The appointment must be in writing, and the representative has to be named where people can find it: the privacy notice is the usual place, and it is the first thing a supervisory authority looks at.
- Keep the Article 30 record with the representative, not only on a drive at head office, because the point of the appointment is that something can be produced from inside the Union.
- Check whether the mirror UK appointment is also needed. Companies frequently discover the second obligation only when a customer asks.
We act as EU representative from Nicosia, at a published fixed annual fee, and the scope and the limits are set out on EU GDPR representative. Where the same company also needs an agent for service of process and an address in the Union, the three are taken together in the Cyprus presence pack.
Questions we are asked
Does a UK company still need an EU representative after Brexit?
Leaving the Union created the obligation rather than ending it. Article 3(2) of the GDPR reaches a controller or processor with no establishment in the Union where the processing relates to offering goods or services to people in the Union or to monitoring their behaviour in it, and Article 27 then requires a representative to be designated in writing. While the United Kingdom was a Member State its companies were established in the Union and Article 27 did not apply; from the end of the transition period a UK company with no EU establishment stands where a company in New York or Tel Aviv stands.
Our processing is small. Does the Article 27(2) exemption cover us?
It is not a small business exemption, and this is where most self-assessments go wrong. The exemption applies only where the processing is occasional, does not include on a large scale special category data under Article 9 or criminal conviction data under Article 10, and is unlikely to result in a risk to the rights and freedoms of individuals. The three limbs are cumulative. A shop shipping to Union customers all year, a product with European users logging in daily and an app profiling European visitors are none of them occasional.
Is the representative the same thing as a Data Protection Officer?
No. The Data Protection Officer under Article 37 is an oversight role with its own independence requirements, and a company can need both. The representative is the company's point of contact in the Union, named in the privacy notice, addressable by supervisory authorities and by individuals on all issues related to the processing, and it holds the Article 30 record so that the record can be produced to an authority on request. It is not a liability shield either: the obligations remain the controller's.
Which Member State should the representative be in?
Article 27(3) requires the representative to be established in one of the Member States where the people whose data is processed are. Where a company serves the whole Union any Member State qualifies, which turns the choice into a practical question of language, responsiveness and who is actually behind the address.
We are an EU company selling into Britain. Does this work in reverse?
It does. The UK GDPR requires a company established in the Union with no UK establishment, which offers goods or services to people in the United Kingdom or monitors them, to appoint a UK representative. One appointment does not satisfy the other, and companies commonly discover the second obligation only when a customer asks.
Sources
This article is provided for general information purposes only and does not constitute legal advice.
Related Reading

Klitos Platis
Advocate, Partner
Kleanthous & Platis LLC, Nicosia · Published 18 August 2026
Need advice on your own matter?
Briefly describe your situation, the people involved and any deadline.
We reply within one business day. We will ask for documents once we confirm we can act.
Receive legal updates by email
When Cyprus law changes, hear it from us
One short email when something changes that matters: new legislation, a decision worth knowing, a deadline. Written by the partners, no marketing, unsubscribe with one click.
You are on the list. The next update on Cyprus law will reach your inbox.
That did not go through. Please write to office@kleanthousplatis.com and we will add you.
Your address is used for these updates and nothing else. Privacy notice.