Eleven questions people ask us before they buy an EU representative


 Most of the questions that reach us are not about the law. They are about what happens afterwards: who answers, how fast, what it costs when something actually occurs. These are the eleven that come up most, answered as plainly as I can — including the two where the honest answer costs us the sale.


1. Do we actually need this?


Article 3(2) of the GDPR catches a company established outside the Union when it offers goods or services to people in the EU, or monitors their behaviour. There is no turnover threshold and no minimum number of customers. Offering something free still counts, because the trigger is the processing of personal data rather than the payment. Selling business to business changes nothing, since the buyers on the other side are natural persons.


The exemption in Article 27(2)(a) exists but is narrow: occasional processing, low risk, no special categories. It rarely fits a commercial business.


2. Our DPO handles this, doesn't he?


No, and this is the most expensive misunderstanding in the field. A data protection officer works under Articles 37 to 39, advises internally, and may sit anywhere in the world. The representative works under Article 27, receives rather than advises, and must be established inside the Union. Under EDPB guidance one entity cannot hold both roles for the same company, because they can conflict.


3. Can our EU distributor or our law firm do it?


Only if that entity is established in the Union and formally accepts the role in writing. A distributor who has never signed a designation is not your representative, and a law firm acting as your counsel is not one either. What Article 27 requires is a named entity, published in your privacy notice, that authorities and individuals can address.


4. What do we actually receive?


Four things. A signed designation letter under Article 27(1), executed with an electronic signature that satisfies Regulation (EU) No 910/2014 — not a scanned image. A certificate with a QR and a verification code that resolves against a live public register. The exact Article 13 and 14 wording for your privacy notice, generated in each language your site publishes. And a dedicated address, inbox and web form where requests arrive.


5. What happens the day a regulator writes?


Hour zero, the message lands in your dedicated address, is stamped, given a reference and stored in the register. Within two business days it reaches your nominated contact with the original attached and the deadline stated. Day thirty, the clock on a data subject request runs out, and the desk shows it to both sides so nobody discovers it late.


What we never do is answer on the merits, negotiate or speak for you. Article 27 makes us a contact point, not a defence lawyer, and the contract says so.


6. Why does the certificate have a code instead of just being a PDF?


Because a PDF proves what was true on the day it was signed. It says nothing about today, and it can be edited by anyone with a text editor.


Our badge is one line of HTML that reads the designation register in real time: green while the designation is active, red the moment it lapses. Nobody can display a status they no longer hold — including us. That constraint is the point. A seal that cannot stop lying is worth nothing.


7. What does it cost, really?


290 euro a year for the Union, covering up to ten forwarded requests. 490 euro with unlimited forwarded requests, custody of your Article 30 records for authorities, and the desk in eight languages with the thirty-day clock visible to both sides. 890 euro adds the responsible person under Article 16 GPSR, the authorised representative under Regulation (EU) 2019/1020, and a mailbox dedicated to you alone. From the second year renewals drop to 240, 390 and 690 euro.


Prices exclude VAT, billing is annual in advance and cancellation before renewal is free. Regulated and higher-risk activities — health data, biometrics, credit, dating, minors, data brokerage — are quoted separately.


The number that matters more than any of those: nothing is charged per request, at any tier. In this market fifty to two hundred euro per contact is normal, and it surfaces in month eleven when you have no leverage to argue.


8. Does this cover the United Kingdom?


No. Since Brexit the UK GDPR is a separate regime with its own regulator. A representative established in a member state has no standing before the ICO, so a company reaching both markets needs two designations. We issue both under one order, from 390 euro a year, with two certificates, two codes and two lines of privacy notice wording — because a single line naming one entity would be wrong in front of the other authority.


9. Does appointing you make us liable in Europe for everything?


No. It does not create an establishment, move your tax residence, or extend the GDPR to processing that was already outside its scope. It gives European authorities and individuals a reachable address.


And Article 27(5) is explicit that proceedings can still be brought directly against you. Any provider implying the designation is a shield is selling something the regulation does not contain.


10. We are one person, not a company. Can we still do this?


Yes, and this changed recently because the market assumption no longer holds. A large share of goods reaching European buyers comes from individuals and sole traders selling through marketplaces with no website of their own.


The onboarding accepts individuals: a tax or national ID number instead of a registration number, your own name instead of a company name, a sales channel instead of a website. The company field is not requested at all.


11. How do we know you are real?


Check us the way we tell clients to check anyone. Europe Services SE is IČO 03571785 in the Czech commercial register; REP27 LTD is 17385889 at Companies House. Both are public. Our client register is public too, so you can see which companies we actually represent rather than take our word for it. And the specimen certificate on the site carries a working code that resolves on the same public page yours will.


The two answers that cost us money


Some companies do not need us, and we say so before they pay. If you are already established in a member state, Article 27 does not apply to you at all. If you sell cosmetics, the responsible person you need is the one under Regulation 1223/2009, with the Product Information File and CPNP notification — a different role with a different provider. If your packaging falls under the PPWR, that requires an authorised representative in every member state your packaging reaches, not one for Europe.


We do not cover the last two, and telling someone that is much easier when nobody has paid yet. Which is also why the first seven days are free with no card: representation is active immediately, payment begins only after the seventh day, and nothing is stored to charge you if you walk away.


A question back


The thing I keep turning over is broader than this obligation. Nearly all compliance evidence is self-reported, which makes supplier due diligence an exercise in reading how carefully someone documented themselves. Article 27 is one of the few places where a third party can verify the claim without asking.


So: what proportion of your own supplier due diligence could be checked without asking the supplier? Tell me in the comments — my honest answer is lower than I would like.

Comments

Popular posts from this blog

Who really needs a GDPR representative — and why some companies choose to be named publicly for it