One EU representative for several processing activities: prepare the written mandate
The EDPB does not expect a separate representative for each covered Article 3(2) processing activity of the same controller or processor. Its guidance recommends identifying a lead contact when an organisation provides the service. Define the represented entity, activities and escalation responsibilities; multiple legal entities must not be assumed to share one appointment automatically.
Evidence retrieved 2026-10-07. Source versions and topic-specific limits are listed below.
Sourced criteria · EU · GDPR
What changes the service scope?
Decision or task
What the source describes
What to prepare
Covered entity and activities
The guidance distinguishes one controller/processor with several covered processing activities from a representative acting for several organisations. Specify whom this mandate actually represents. [1]
Compare the stated example/criterion with the evidence tasks below; retain any factual differences.
Lead contact is a recommendation
The EDPB recommends a single person in charge for each represented controller/processor when the representative is an organisation; keep that recommendation distinct from binding law. [1]
Compare the stated example/criterion with the evidence tasks below; retain any factual differences.
Communication and retained responsibility
The representative facilitates communications with people and authorities under the mandate. Appointment does not transfer the controller’s or processor’s own responsibility. [2][4]
Compare the stated example/criterion with the evidence tasks below; retain any factual differences.
The EDPB document is Guidelines 3/2018, version 2.1, adopted 12 November 2019. Its worked examples are guidance and dated assumptions, not a new law or a conclusion about your organisation. EU scope is assessed here; UK and Swiss rules require separate evidence. Novel or disputed scope/role interpretations need specialist legal review.
Prepare the evidence and engagement scope
Use this checklist to gather your business or product details before speaking with a specialist. The items below explain what to record and suggest useful supporting documents. You can add your own answers in the editable project brief.
Define each represented entity
List the actual legal entity and its covered processing activities; identify related group entities requiring a separate conclusion.
Useful evidence: A mandate/entity/activity schedule.
Agree the operational lead and escalation
Identify the lead contact, backup, authority/data-subject handling and the route to your decision-makers.
Useful evidence: A contact, escalation and responsibility matrix.
Specify deliverables and exclusions
Separate appointment and enquiry facilitation from advice, document preparation or other services; retain your internal owners.
Useful evidence: A written mandate and deliverables/exclusions schedule.
Work packages and dependencies
Conditional: EU representative scope and engagement — Review the specific evidence task and unresolved territorial/role facts. Where appointment applies, agree the mandate, communication and handoff; justify additional privacy services separately.
Questions for providers
Which differences between our actual facts and the cited example change your scope conclusion?
Which processing activity and legal entity does your conclusion cover, and which facts remain unresolved?
Which appointment and evidence-handoff deliverables are included, and which additional services are separately justified?
Sources and data dates
Read the official document in context. The audit details identify the precise locators and preserved versions used for this page.