Can the EU representative also be your external DPO?
The EDPB considers the EU representative role incompatible with an external DPO role because a representative acts under the mandate while a DPO needs independence. Ask a bundled provider to explain the proposed roles and governance. Assess whether DPO designation is required separately; purchasing representation does not settle that question.
Evidence retrieved 2026-10-07. Source versions and topic-specific limits are listed below.
Sourced criteria · EU · GDPR
What changes the service scope?
Decision or task
What the source describes
What to prepare
Two different roles
The EDPB contrasts representative instructions under a mandate with the autonomy and independence of an external DPO. [1]
Compare the stated example/criterion with the evidence tasks below; retain any factual differences.
The DPO designation test
Article 37 has its own criteria. Do not label DPO services mandatory solely because representative appointment may apply. [3]
Compare the stated example/criterion with the evidence tasks below; retain any factual differences.
DPO independence and conflicts
Article 38 sets independence and conflict-related requirements for DPO tasks. A provider’s combined package needs a role and governance explanation, not only a shared contact address. [4]
Compare the stated example/criterion with the evidence tasks below; retain any factual differences.
The EDPB document is Guidelines 3/2018, version 2.1, adopted 12 November 2019. Its worked examples are guidance and dated assumptions, not a new law or a conclusion about your organisation. EU scope is assessed here; UK and Swiss rules require separate evidence. Novel or disputed scope/role interpretations need specialist legal review.
Prepare the evidence and engagement scope
Use this checklist to gather your business or product details before speaking with a specialist. The items below explain what to record and suggest useful supporting documents. You can add your own answers in the editable project brief.
Request a separate DPO assessment
Record which Article 37 criterion is said to apply and the facts supporting it; keep uncertainty explicit.
Useful evidence: A DPO designation assessment separate from Article 27.
Map the proposed people and roles
Ask who performs each role, who instructs them and how independence and conflicts are handled under the proposed arrangement.
Useful evidence: A provider role/governance matrix and conflict assessment.
Separate contracts and deliverables
Have the specialist review appointment, DPO and advice scopes separately against the EDPB position and actual governance.
Useful evidence: Separate service schedules, escalation routes and unresolved compatibility questions.
Work packages and dependencies
Conditional: EU representative scope and engagement — Review the specific evidence task and unresolved territorial/role facts. Where appointment applies, agree the mandate, communication and handoff; justify additional privacy services separately.
Questions for providers
Which differences between our actual facts and the cited example change your scope conclusion?
Which processing activity and legal entity does your conclusion cover, and which facts remain unresolved?
Which appointment and evidence-handoff deliverables are included, and which additional services are separately justified?
Sources and data dates
Read the official document in context. The audit details identify the precise locators and preserved versions used for this page.