EU Representation & GDPR

Your legal representative in Europe

If you process the personal data of Europeans but do not have an establishment in the EU, GDPR requires you to appoint a representative who is established in Europe. We take on that role, with name and address, and ensure that there is substance behind it.

No European branch

You sell to European customers or track European visitors on your website, but you do not have an office, a branch, or an entity within the EU. Article 27 of the GDPR then obliges you to appoint a representative in the Union in writing.

A questionnaire on your desk

A European buyer or distributor sent a supplier questionnaire with questions about your data streams, your sub-processors, and your EU representative. You have two weeks to respond and don't know where to begin.

An audit is coming up

There's an acquisition, an investment round, or a certification process coming up, and privacy is on the checklist. You need documents that are correct, not a policy that was once pulled off the internet.

Data you can no longer oversee

You no longer know exactly which tool stores which data, where it is located, or who can access it. Each new SaaS tool adds a pipe to a system that no one has fully mapped out yet.

Our expertise

01.

EU Representation (Article 27)

We act as your appointed representative in the European Union. With a Belgian address to include in your privacy statement, a written mandate, and a contact person accessible to data subjects and supervisory authorities. We maintain the record of processing activities that you must be able to present in this capacity, and we handle incoming correspondence.
02.

Request from stakeholders

Access, rectification, erasure, restriction, objection, and portability. We capture those requests, verify identity, monitor deadlines, and ensure a compliant response is sent. You provide the data; we do the rest.
03.

Data streams in focus

We map out which system contains which data, where it is physically located, who can access it, and on what legal basis you process it. Not the organizational chart: the actual flows, including the help desk, the analytics, and that one shared drive. Nine times out of ten, at least one transfer emerges that no one had on their radar.
04.

Transfer outside Europe

Personal data can be transferred outside the EU, but not just like that. We arrange the standard contractual clauses, conduct the transfer impact assessment, and document why the arrangement is sustainable. This also applies when your data moves in both directions and two regimes apply simultaneously.
05.

Data breaches & incidents

The GDPR gives you 72 hours to report a data breach to the supervisory authority. That's shorter than it sounds when it starts on a Friday night. We write the playbook, set up the contact channels, and are the number you call when things go wrong.
06.

European infrastructure

Privacy is not just a document issue. We are moving your site and your data to European LiteSpeed Servers with hourly external backups, setting up your tracking via your own servers instead of third parties, and running AI models on your own infrastructure when you don't want to send sensitive data to an external model. This way, not only your policies are correct, but also your wiring.

Step-by-step plan

In 5 phases, we'll take you from “we're not sure” to a dossier that you can present to a European buyer or regulator:

Week 1 · one hour-long conversation

We'll start with one conversation and a brief scan. Do you process personal data of people in the EU, and if so: which data, for what purpose, and through which systems? We will review your website, your sales channels, and your main tools, and check this against Article 3 of the GDPR — the article that determines whether the law applies to you at all.

At the end of this phase, you will know three things: whether Article 27 requires you to appoint a representative, whether you also need a Data Protection Officer, and where your greatest exposure lies. Sometimes the answer is “less than you thought.” In that case, that's what we'll tell you, and then we'll be done.

Week 2 to 3 · we at work, with two short interim calls

Now we're drawing out what's really happening. Which system contains which data, where is it physically located, who can access it, how long do you keep it, and on what legal basis do you process it. Not the organizational chart – the actual flows, including your helpdesk, your analytics, your marketing platform, and that one shared drive that no one looks at anymore.

For this, we will interview your IT manager, someone from marketing, and someone from sales or support. The three of them together usually know everything; individually, no one has the complete picture.

Two things almost always come up here: at least one transfer outside of Europe that no one had on their radar, and at least one processing that relies on “consent” when a better legal basis exists. You get a processing register and a data flow map that can show you.

Week 3 to 4

The paperwork, done right the first time. We draft the written mandate appointing us as your representative in the Union, and provide the text and contact details to include in your privacy statement — because an appointment that isn't publicly listed doesn't count.

In addition, we will arrange what is needed around it: your privacy statement rewritten to the legal grounds from phase 2, processor agreements with your suppliers, and, where necessary, standard contractual clauses with a transfer impact assessment for transfers outside the EU.

If you work with a lawyer, we'll provide the file in such a way that they only need to review it instead of building it. This usually saves you many times our fee.

Week 5 to 6

Documents that no one knows are no protection. Therefore, we conclude with the part that makes the difference in practice.

We are implementing the technical measures that came out of Phase 2 — retention periods, access rights, European hosting, or first-party tracking where necessary. We are writing the incident playbook for data breaches, with the 72-hour clock, the contact routes to the appropriate supervisory authority, and who does what. And we will provide your team with a half-day training: what is a data breach, how to recognize a data subject request, and what to do with an email in which someone requests their data.

The training is consciously practical. No legal texts — situations that people actually encounter.

Continuous

From here, the role takes care of itself. We are the point of contact in your privacy statement, we handle data subject requests and monitor deadlines, we keep the processing register up-to-date, and we are the number you call when something goes wrong.

Once a year, we sit down together again: what tools have been added, what markets, what data. Privacy doesn't expire, but your company does change — and most of the problems we see arise in the two years after a successful compliance project.

How much does it cost?

Representation is not a project with an end date. As long as you process European data, the role must be filled. Therefore, we work with an annual subscription.

EU Representation — Basic — €1,850 per year

Appointment on paper, Belgian address in your privacy statement, contact person for data subjects and supervisory authorities, register of processing activities, and up to 10 data subject requests per year.

EU Representation — Extended — €4,500 per year

Everything from Basic, plus an annual audit of your data streams, support with DPIAs, onward transfer documentation with transfer impact assessments, an incident playbook, and unlimited data subject requests.

Europe scan — €1,950 one-time

Not yet needing representation, but want to know where you stand? Three sessions over three weeks: where you stand today, what the gaps are costing you, and a 90-day plan with a compliance summary you can immediately send to a European buyer. If you opt for a subscription within 30 days, we will credit this amount.

All prices exclude VAT in euros (€). Annually cancellable. VAT exemption for non-European companies. Prices apply per legal entity.

Want to start a project with us?

Whether you want to be sure if Article 27 applies to you, or you need a representative right away: we'll take a look without obligation. Preferably on location, from Europe to the USA to Asia.

Frequently asked questions

Article 27 of the GDPR obliges organizations outside the European Union that offer goods or services to people in the EU — or monitor their behavior — to appoint a representative in writing who is established in an EU Member State. This representative will be the point of contact for data subjects and supervisory authorities, and will maintain the record of processing activities.
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.
No, and you may need both. The representative is your point of contact within the Union because you are not established there yourself. The Data Protection Officer (DPO) is an internal or external supervisory role mandated by Article 37, based on your core activities and the scale of your processing. The assessments are separate.
Not usually. GDPR has extraterritorial reach: it follows the data subject, not the border. For example, Vietnam's PDPL (effective January 1, 2026) is based on GDPR but not identical, and Mexico also revised its LFPDPPP in March 2025 without it covering European requirements. Being compliant with one law does not mean being compliant with another.
Then there is a reporting period of 72 hours to the supervisor. We write the runbook in advance, are on the contact line, and handle the reporting. This is included in the comprehensive subscription.
The appointment itself is a matter of days. The underlying scan—data streams, legal grounds, transfers—usually takes three weeks.
Scroll to Top