Lucrezia Berto, departamento de IP-IT y nuevas tecnologías.
The General Data Protection Regulation 679/2019 (“GDPR”, or the “Regulation”) sets forth duties and obligations that are binding not only on European entities, but also on non-European entities that, due to the provisions of art. 3 GDPR, become subject to the Regulation.
In this post, we focus on the obligation to designate a representative in the European Union for the purposes of data protection and will answer several important questions in this regard.
What does the Regulation say?
Entities not established in the European Union that, nonetheless, are subject to the GDPR as per its article 3(2) (i.e., generally speaking, non-EU entities that process EU citizen data related to the offering goods or services to those citizens, or monitoring their behaviour), are under the obligation to designate a representative established in the Union, in accordance with the provisions of art. 27 GDPR. This applies to both data controller and processors that, as per the Regulation, must inform data subjects of the identity and contact data of the representative.
Failing to designate a representative in the Union, therefore, implies a breach of the Regulation, punishable with an administrative fine up to 10 000 000 EUR, as per art. 83(4) GDPR.
How can a non-EU entity appoint a representative? Who can be a representative?
The representative must be explicitly designated by written mandate of the non-European entity, to act on its behalf with regard to its obligations under the Regulation. Nonetheless, this designation does not affect the responsibility or liability of the data controller or processor not established in the EU under the GDPR. The function of representative in the Union can be exercised by an individual or an organization based on a service contract signed with the data controller/processor, and can therefore be assumed by a wide range of commercial and non-commercial entities (such as law firms, consultancy firms, private companies, etc…) established in the European Union.
What’s the role of the representative?
The representative must perform its tasks according to the mandate received from the non-EU controller or processor, including cooperating with the competent supervisory authorities with regard to any action to take to ensure compliance with the GDPR. For instance, the representative has to notify to the competent data protection supervisory authority of the occurrence of a personal data breach affecting the non-European entity whose processing is subject to the Regulation, when the GDPR imposes such a notification.
Is there any exception to this obligation?
Article 27(2) GDPR sets out some exceptions to the duty to designate of a representative in the Union, when:
- The processing subject to the GDPR is occasional and does not include, on a large scale, processing of special categories of data, and such processing is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account the nature, context, scope and purposes of the processing; or
- The processing is carried out by a “public authority or body”.
In what member state should the representative be established?
If a non-EU entity has to appoint a representative in the EU, it must be established in one of the Member States where the data subjects, whose personal data are processed in relation to the offering of goods or services to them, are. In cases where a significant proportion of data subjects whose personal data are processed are located in one particular Member State, the representative shall be established in that same Member State.
In conclusion, each case is different, and whether an entity is subject to the Regulation or not, and whether an exemption to the duty to appoint a representative applies, must be carefully analysed on a case-by-case basis.




