EU Representation & GDPR
Your legal representative in Europe
If you process the personal data of Europeans but do not have an establishment in the EU, GDPR requires you to appoint a representative who is established in Europe. We take on that role, with name and address, and ensure that there is substance behind it.
No European branch
A questionnaire on your desk
An audit is coming up
Data you can no longer oversee
Our expertise
01.
EU Representation (Article 27)
02.
Request from stakeholders
03.
Data streams in focus
04.
Transfer outside Europe
05.
Data breaches & incidents
06.
European infrastructure
Privacy is not just a document issue. We are moving your site and your data to European LiteSpeed Servers with hourly external backups, setting up your tracking via your own servers instead of third parties, and running AI models on your own infrastructure when you don't want to send sensitive data to an external model. This way, not only your policies are correct, but also your wiring.
Step-by-step plan
Week 1 · one hour-long conversation
We'll start with one conversation and a brief scan. Do you process personal data of people in the EU, and if so: which data, for what purpose, and through which systems? We will review your website, your sales channels, and your main tools, and check this against Article 3 of the GDPR — the article that determines whether the law applies to you at all.
At the end of this phase, you will know three things: whether Article 27 requires you to appoint a representative, whether you also need a Data Protection Officer, and where your greatest exposure lies. Sometimes the answer is “less than you thought.” In that case, that's what we'll tell you, and then we'll be done.
Week 2 to 3 · we at work, with two short interim calls
Now we're drawing out what's really happening. Which system contains which data, where is it physically located, who can access it, how long do you keep it, and on what legal basis do you process it. Not the organizational chart – the actual flows, including your helpdesk, your analytics, your marketing platform, and that one shared drive that no one looks at anymore.
For this, we will interview your IT manager, someone from marketing, and someone from sales or support. The three of them together usually know everything; individually, no one has the complete picture.
Two things almost always come up here: at least one transfer outside of Europe that no one had on their radar, and at least one processing that relies on “consent” when a better legal basis exists. You get a processing register and a data flow map that can show you.
Week 3 to 4
The paperwork, done right the first time. We draft the written mandate appointing us as your representative in the Union, and provide the text and contact details to include in your privacy statement — because an appointment that isn't publicly listed doesn't count.
In addition, we will arrange what is needed around it: your privacy statement rewritten to the legal grounds from phase 2, processor agreements with your suppliers, and, where necessary, standard contractual clauses with a transfer impact assessment for transfers outside the EU.
If you work with a lawyer, we'll provide the file in such a way that they only need to review it instead of building it. This usually saves you many times our fee.
Week 5 to 6
Documents that no one knows are no protection. Therefore, we conclude with the part that makes the difference in practice.
We are implementing the technical measures that came out of Phase 2 — retention periods, access rights, European hosting, or first-party tracking where necessary. We are writing the incident playbook for data breaches, with the 72-hour clock, the contact routes to the appropriate supervisory authority, and who does what. And we will provide your team with a half-day training: what is a data breach, how to recognize a data subject request, and what to do with an email in which someone requests their data.
The training is consciously practical. No legal texts — situations that people actually encounter.
Continuous
From here, the role takes care of itself. We are the point of contact in your privacy statement, we handle data subject requests and monitor deadlines, we keep the processing register up-to-date, and we are the number you call when something goes wrong.
Once a year, we sit down together again: what tools have been added, what markets, what data. Privacy doesn't expire, but your company does change — and most of the problems we see arise in the two years after a successful compliance project.
How much does it cost?
Representation is not a project with an end date. As long as you process European data, the role must be filled. Therefore, we work with an annual subscription.
EU Representation — Basic — €1,850 per year
Appointment on paper, Belgian address in your privacy statement, contact person for data subjects and supervisory authorities, register of processing activities, and up to 10 data subject requests per year.
EU Representation — Extended — €4,500 per year
Europe scan — €1,950 one-time
Not yet needing representation, but want to know where you stand? Three sessions over three weeks: where you stand today, what the gaps are costing you, and a 90-day plan with a compliance summary you can immediately send to a European buyer. If you opt for a subscription within 30 days, we will credit this amount.
All prices exclude VAT in euros (€). Annually cancellable. VAT exemption for non-European companies. Prices apply per legal entity.
Want to start a project with us?
Whether you want to be sure if Article 27 applies to you, or you need a representative right away: we'll take a look without obligation. Preferably on location, from Europe to the USA to Asia.
