For the EU, Article 27 links representative appointment to Article 3(2): relevant processing by an organisation outside the Union that offers goods or services to people there, or monitors behaviour there. For the UK, ICO guidance describes a separate test for organisations without a UK establishment. Check the exception before buying the service. Serving both markets requires separate assessments.
Evidence retrieved 2026-10-07. Source versions and topic-specific limits are listed below.
Criteria from the actual provisions
Check these differences before appointing a provider
Decision
EU assessment
UK assessment
What triggers the assessment?
Processing related to offering goods/services to people in the Union, or monitoring behaviour there, by a controller or processor not established in the Union. Payment is not necessary.
Based outside the UK, without a UK branch/office/other establishment, while offering goods/services to people in the UK or monitoring their behaviour there. [1][2][4][5]
Public authority or body?
Article 27(2)(b) separately exempts a public authority or body. Confirm that status for the organisation and covered processing.
ICO lists a separate public-authority exception. Confirm the organisation’s status under the UK criteria. [2][6]
Can occasional processing be exempt?
All parts of Article 27(2)(a) must be met: occasional processing; no large-scale special-category or criminal-offence processing; and unlikely risk to rights/freedoms, considering its nature, context, scope and purpose.
ICO describes the combined exception as occasional, low-risk processing without large-scale special-category or criminal-offence data. A public-authority exception is separate. [2][6][7]
Where can the representative be based?
In a Member State where affected people whose data are processed for the offering/monitoring are located. Choose against your actual processing geography.
The representative must be established in the UK. A location in an EU country does not itself satisfy this UK location criterion. [2][8]
What are you appointing them to do?
Designate in writing and mandate the representative as a contact for authorities and affected people on processing-related compliance matters.
Appoint in writing and define the relationship; ICO guidance describes representation regarding UK GDPR obligations. Your own responsibility/liability remains. [2][9][10]
Small business size is not one of the Article 27(2)(a) exception conditions. Occasional processing alone also does not satisfy the combined test. [2]
Two distinctions that change the answer
A website visit is not the whole targeting test
EDPB guidance says mere website accessibility does not by itself establish an intention to offer goods or services in the Union. Review actual ordering, marketing and customer-location facts; behaviour monitoring is a separate trigger. [1][11]
Representative appointment and DPO designation are separate
EU Article 37 has its own DPO criteria, including certain public-authority processing and core activities involving large-scale monitoring or sensitive/criminal-offence processing. Appointing an Article 27 representative does not decide the DPO assessment. [2][3]
Illustrative scenarios · assumed facts
What changes between these situations?
Overseas shop with recurring EU customers
Assumed facts: Assume the business has no EU establishment, intentionally sells to people in France, and routinely processes their customer data.
What the criteria imply: Assess Article 3(2) offering-related processing. Recurring processing cannot be treated as occasional merely because the business is small; review appointment and the exact scope. [1][2]
Overseas site with incidental EU visitors
Assumed facts: Assume only website accessibility is known; targeted offering and behavioural monitoring have not been established.
What the criteria imply: That fact alone does not settle Article 3(2). Establish targeting or monitoring facts before concluding an appointment is required or unnecessary. [1][11]
One-off processing with an exception claim
Assumed facts: Assume Article 3(2) applies, but the business says the processing is occasional.
What the criteria imply: Check the other exception conditions as well: large-scale special/criminal data and risk to people. Record the facts supporting every part of the exception instead of selecting “occasional” alone. [2]
Your applicability worksheet
Assess EU and UK separately
Choose what you know about the covered processing. Not sure preserves an unresolved question. Results apply only to your supplied facts and need specialist confirmation.
Turn the answer into a scoped appointment
Use this checklist to gather your business or product details before speaking with a specialist. The items below explain what to record and suggest useful supporting documents. You can add your own answers in the editable project brief.
First: document the applicability conclusion
For each relevant market and processing activity, record establishment, offering/monitoring and the exception result. Give the representative the conclusion and unresolved questions rather than asking for an unexplained blanket “GDPR package”.
Useful evidence: A one-page processing/territorial-scope assessment with links to the criteria above.
Then: agree the contact and escalation service
Specify the covered entity, affected locations, representative location and written mandate. Ask who receives enquiries, how they reach your business and what response handling the contract includes.
Useful evidence: Appointment/mandate, contact details and a responsibility/escalation matrix.
Separate any additional privacy work
Ask the provider to quote appointment separately from additional privacy documentation, transfer advice or DPO work. Confirm which deciding facts justify each extra package.
Useful evidence: A deliverables-and-exclusions schedule, with a separate applicability decision for each additional service.
Work packages and dependencies
Conditional: EU/UK representative applicability and appointment — Assess each market and processing activity against the sourced criteria; where appointment applies, agree the location, written mandate, covered entity and contact/escalation service.
Questions for providers
In which country will our EU representative be established, and why does that location fit our affected people?
Does the quote cover an EU appointment, a UK appointment, or both, with the respective location and written mandate?
Which contact-handling tasks, escalation responsibilities and exclusions are included? Which additional privacy services are separately scoped?
Sources and data dates
Read the official document in context. The audit details identify the precise locators and preserved versions used for this page.