[{"data":1,"prerenderedAt":14},["ShallowReactive",2],{"article:en:the-gdpr-representative-of-article-27-for-a-software-company-outside-the-eu-who-must-appoint-one-the-three-conditions-of-the-exemption-and-where-the-name-goes":3},{"locale":4,"slug":5,"title":6,"description":7,"published":8,"answer":9,"body":13},"en","the-gdpr-representative-of-article-27-for-a-software-company-outside-the-eu-who-must-appoint-one-the-three-conditions-of-the-exemption-and-where-the-name-goes","The GDPR representative of Article 27 for a software company outside the EU: who must appoint one, the three conditions of the exemption, and where the name goes","A software company with no establishment in the Union whose product is used by people in it is under the Regulation by Article 3(2) and must designate a representative in the Union in writing (Article 27(1)), established in a member state where its users are (27(3)), mandated to be addressed by supervisory authorities and data subjects (27(4)), and no shield against action on the company itself (27(5)). The exemption of Article 27(2)(a) has three conditions that must all hold, and a product in use fails the first. Where the representative's name goes: the privacy notice (Article 13(1)(a)), the record of processing (Article 30(1)(a)), and the record the representative keeps itself. The fine tier is Article 83(4). A free page decides it from two questions.","2026-09-12",{"who":10,"when":11,"do":12},"A software company with no establishment in the Union, a US, UK, Swiss, Indian or other company, whose product is offered to people in the Union or monitors their behaviour there; and the EU customers that ask it, in the processor terms, who its representative is.","From the first day the product is offered to people in the Union: Article 3(2) attaches the Regulation to the processing, Article 27(1) attaches the representative to the company, and the duty is not phased, tiered by size or delayed; the exemption of Article 27(2)(a) is read at the same moment.","Designate a representative in writing, established in a member state where your users are, mandated to answer authorities and data subjects; put its name and contact details in the privacy notice and the record of processing, and hand the record to it; the free determination says whether Article 27(2)(a) exempts you, from two questions.","\nA software company with no office, subsidiary or staff in the Union is not outside the Regulation. Article 3(2) applies it to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing relates to offering them goods or services, whether or not they pay, or to monitoring their behaviour as far as it takes place in the Union. A SaaS product sold to European companies, a free tier used by European individuals, an analytics script that tracks European visitors: each is one of the two. And where Article 3(2) applies, Article 27(1) follows in one sentence: the controller or the processor shall designate in writing a representative in the Union. This article reads Article 27 clause by clause against the [catalogue](\u002Fgdpr\u002Fduties) StandardOS keeps of the Regulation, for the company that has to appoint one and for the European customer that will ask who it is.\n\n## Who the duty reaches: the two limbs of Article 3(2)\n\nThe first limb is the offering of goods or services to data subjects in the Union, irrespective of whether a payment is required, so a free product counts. Recital 23 reads the offering from intent: the language or currency used, the mention of customers in the Union, delivery there; mere accessibility of a website is not enough. The second limb is monitoring behaviour within the Union, which recital 24 reads as tracking individuals on the internet, profiling included. A product with a European pricing page, European customers in its case studies, and a session-recording script on its marketing site is in both. The representative duty then falls on the company in the role it holds: the controller of its own customer and visitor data, and the processor of the data its customers put into the product, since Article 27(1) names both. The company that is under the Regulation only because it processes for a European controller, with no offering or monitoring of its own, is in a narrower place the Board's guidelines on territorial scope discuss, and the safe reading for a product company is that its own offering already puts it in the first limb.\n\n## The exemption: three conditions, all at once\n\nArticle 27(2)(a) lifts the duty where the processing is occasional, does not include, on a large scale, special categories of data under Article 9(1) or data on criminal convictions under Article 10, and is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account its nature, context, scope and purposes. The three are joined by \"and\": all must hold. A product in use by customers is not occasional processing; it is the company's business, every day, and the first condition fails before the other two are reached. That is the same reading the record-of-processing threshold uses in Article 30(5), where \"occasional\" is the word that keeps the 250-person exemption from ever applying to a software company, and the [free determination](\u002Fgdpr\u002Fduties) asks the same two questions here, whether the processing is occasional and whether it includes special categories on a large scale, and answers the representative from them. Article 27(2)(b) exempts a public authority or body; a company is not one.\n\n## Where and how: Articles 27(3) to 27(5)\n\nThe representative shall be established in one of the member states where the data subjects are whose data are processed in relation to the offering or the monitoring (Article 27(3)); with customers in six states, any of the six will do, and the state chosen does not create a lead supervisory authority, since the one-stop-shop of Article 56 needs a main establishment and a representative is not one. The representative shall be mandated by the controller or processor to be addressed, in addition to or instead of the company, by supervisory authorities and data subjects on all issues related to the processing (27(4)); recital 80 calls that a written mandate and has the representative cooperate with the authorities on any action taken to ensure compliance, and Article 58(1)(a) gives every supervisory authority the power to order the representative to provide any information it requires. The designation is without prejudice to legal actions against the controller or processor themselves (27(5)): the representative is an address, not a shield, and recital 80 says the designation does not affect the company's own responsibility or liability. The Board's guidelines on territorial scope add one practical line: the role of representative is not compatible with that of an external data protection officer, so the same firm cannot be both.\n\n## Where the name goes\n\nOnce designated, the representative appears in three places the Regulation names. The privacy notice: Article 13(1)(a) and Article 14(1)(a) have the controller give the identity and contact details of the controller and, where applicable, of its representative, so the name goes into the notice at the point of collection. The record of processing: Article 30(1)(a) puts the representative's name and contact details in the controller's record, Article 30(2)(a) in the processor's, and both paragraphs open the same way, each controller or processor \"and, where applicable, the controller's representative\" or the processor's maintaining a record, so the representative keeps a copy of the [record](\u002Fgdpr\u002Frecord-of-processing) itself and produces it to an authority on request under Article 30(4). The processor terms: a European customer's addendum will ask for the representative alongside the [Article 28(3) terms](\u002Fgdpr\u002Fprocessor-terms), because its own record has to carry it. Infringements of Article 27 fall under Article 83(4)(a), the tier of 10 000 000 EUR or 2 % of worldwide annual turnover, whichever is higher.\n\n## What to do with it\n\nAnswer the [determination](\u002Fgdpr\u002Fduties): no establishment in the Union, offering or monitoring, not occasional, and the representative is required with Article 27(1) and Article 3(2) as the basis. Appoint one in writing in a state where your users are, with the mandate of Article 27(4) spelled out; put its name and contact details in the privacy notice and in the record, and give the representative the record. Then read the [breach clock](\u002Fgdpr\u002Fbreach-clock) with the representative in mind: a company with no establishment in the Union has no lead authority, and its Article 33 notification goes to the authority of each state whose residents are affected, which is the authority the representative will be answering.\n",1789383984723]