In GDPR compliance practice, the EU Representative requirement under Article 27 is one of the most frequently overlooked obligations for Chinese companies expanding overseas. Many businesses assume that appointing a DPO fulfills the primary organizational requirements of the GDPR, unaware that the Article 27 Representative is a completely separate legal obligation that exists alongside the DPO system. More critically, the European Data Protection Board (EDPB) has explicitly stated that these two roles cannot be held by the same individual or entity. This article will provide an in-depth analysis of the applicability conditions of Article 27, the fundamental differences between an EU Representative and a DPO, and compliance strategies for Chinese companies expanding overseas.
Article 27 Applicability: Who Must Appoint an EU Representative?
GDPR Article 27(1) stipulates that data controllers or processors not established within the EU but subject to GDPR jurisdiction under Article 3(2) must appoint a representative within the EU in writing. The extraterritorial application rules of Article 3(2) cover two scenarios: offering goods or services to data subjects in the EU (whether paid or free) or monitoring the behavior of data subjects within the EU. This means that the vast majority of Chinese companies targeting the European market—including cross-border e-commerce platforms, SaaS providers, game developers, and ad-tech companies—fall within the scope of Article 27.
Exemptions under Article 27
- ›Occasional data processing: The processing is occasional, does not involve large-scale processing of special categories of data under Article 9(1) or criminal record data under Article 10, and, considering the nature, context, scope, and purpose of the processing, is unlikely to pose a risk to the rights and freedoms of natural persons. However, it should be noted that the EDPB has indicated that the threshold for "occasional" is extremely high, and most ongoing commercial activities are unlikely to qualify for this exemption.
- ›Public authorities or public bodies: Public authorities or international organizations are not subject to this requirement.
The Essential Difference Between EU Representatives and DPOs
Although both the EU Representative and the DPO are roles stipulated by the GDPR, there are fundamental differences in their legal positioning, functional authority, and independence. The EU Representative essentially serves as the "local point of contact" for enterprises within the EU, whose role is to represent the enterprise in receiving communications from data subjects and supervisory authorities and to relay relevant matters to the enterprise. The EU Representative acts on the instructions of the enterprise and lacks independence. In contrast, the DPO serves as the "independent compliance advisor" for the enterprise. According to Article 38(3), the enterprise must not issue instructions regarding how the DPO performs their duties, and the DPO enjoys full professional autonomy.
Key Differences Between the Two Roles
- ›Legal Basis: EU Representative is based on Article 27, while DPO is based on Articles 37-39. These are two entirely separate statutory systems. ---ITEM--- Role Definition: The EU Representative serves as the contact point and service agent for the company in the EU; the DPO is an independent data protection expert and advisor within the company. ---ITEM--- Independence: The EU Representative follows company instructions and lacks independence; the DPO does not accept instructions regarding the performance of their duties and enjoys statutory guarantees of independence. ---ITEM--- Scope of Responsibilities: The EU Representative’s duties mainly include receiving communications from supervisory authorities and data subjects, and maintaining records of processing activities (Article 30); the DPO’s responsibilities cover a wide range of areas, including compliance oversight, DPIA consultation, employee training, and liaison with supervisory authorities. ---ITEM--- Dismissal Protection: The EU Representative has no special dismissal protection; the DPO enjoys dismissal protection under Article 38(3)—they cannot be dismissed or penalized for performing their duties. ---ITEM--- Qualification Requirements: The EU Representative has no special qualification requirements; the DPO must possess the expert knowledge required by Article 37(5)—expertise in data protection laws and practices.
Why can't the two roles be merged?
The European Data Protection Board (EDPB) clearly states in its Guidelines 3/2018 on the territorial scope of the GDPR that the roles of the Article 27 representative and the Data Protection Officer (DPO) should not be held simultaneously by the same natural or legal person. This is due to an inherent conflict of interest: the EU representative acts in the interests of the enterprise and follows its instructions, while the DPO must maintain independence and is not bound by the enterprise's directives. If the same individual holds both roles, it would be impossible to simultaneously fulfill the "following instructions" nature of the EU representative and the "not following instructions" nature of the DPO. Chinese enterprises expanding overseas must appoint different individuals or entities for these two roles.
Legal Consequences of Not Appointing an EU Representative
Companies that fail to appoint an EU representative as required by Article 27 may face administrative fines of up to €10 million or 2% of the company’s global annual turnover from the previous financial year, whichever is higher, under GDPR Article 83(4)(a). Although this penalty cap is lower than the maximum fine for violating fundamental data processing principles (€20 million or 4% of global turnover), it still represents a significant compliance risk exposure for most Chinese companies expanding overseas. More importantly, the absence of an EU representative makes it difficult for regulatory authorities to establish effective communication with the company, which could lead to escalated regulatory investigations or intensified enforcement actions.
Fee Reference and Practical Recommendations
- ›EU Representative Service Fees: Market prices typically range from €2,000 to €10,000 per year, depending on the scale and complexity of the company's data processing activities and the number of member states that need to be covered. This cost is highly reasonable compared to the potential risks of fines. ---ITEM--- Selection of Representative Location: Article 27(3) requires the representative to be established in a member state where the data subjects are located. If a company's European users are spread across multiple member states, the representative should be established in the member state with the primary user base. Ireland, the Netherlands, and Germany are commonly chosen as representative locations by Chinese companies expanding overseas. ---ITEM--- Public Disclosure Obligations of the Representative: Article 27(4) requires companies to inform data subjects of the identity and contact details of the EU representative, typically by including this information in the privacy policy. ---ITEM--- Collaboration Between the Representative and the DPO: Although the two roles cannot be combined, it is advisable to establish a clear collaboration mechanism—inquiries received by the EU representative from regulatory authorities should be promptly forwarded to the DPO for handling, and compliance recommendations from the DPO should be communicated to the regulatory authorities through the EU representative.
Conclusion
Article 27 EU Representative is an indispensable piece in the GDPR compliance puzzle. While appointing a DPO, Chinese companies expanding overseas must simultaneously assess and fulfill the designated obligations of an Article 27 Representative. These two roles have distinct responsibilities and are not interchangeable; together, they form the organizational safeguards for enterprises within the EU data protection compliance framework. DataAigis offers one-stop EU Representative and DPO services, helping Chinese companies expanding overseas meet GDPR's dual organizational requirements at optimal cost.



