Companies outside the EU regularly ask us whether their EU representative under Art. 27 GDPR can also serve as their Data Protection Officer (DPO) under Art. 37 GDPR, or whether one role makes the other unnecessary. The short answer: these are two different functions with different purposes, and the GDPR does not allow them to be merged into one person. Whether you need one, both or neither depends on what your company does.
The EU representative (Art. 27 GDPR)
The EU representative is a contact point inside the European Union for a company that has no establishment there. The representative is mandated in writing (Art. 27(1) GDPR) and must be addressed by supervisory authorities and data subjects “in addition to or instead of” the company on all issues related to processing (Art. 27(4) GDPR). The representative does not decide anything for the company and does not check whether the company complies with the GDPR. The obligation is triggered by Art. 3(2) GDPR: offering goods or services to people in the EU, or monitoring their behaviour. Who exactly is affected is explained on our page What is the legal situation?.
The Data Protection Officer (Art. 37 GDPR)
The DPO is an internal (or externally appointed) compliance function. Under Art. 39 GDPR the DPO informs and advises the company, monitors compliance with the GDPR, advises on data protection impact assessments and cooperates with the supervisory authority. The DPO must be able to act independently (Art. 38(3) GDPR) and reports directly to the highest management level. A DPO is mandatory for private companies only in the cases of Art. 37(1)(b) and (c) GDPR: where the core activities consist of regular and systematic monitoring of data subjects on a large scale, or of large-scale processing of special categories of data under Art. 9 GDPR or data relating to criminal convictions under Art. 10 GDPR. Member State law may add further cases; in Germany, for example, Section 38 of the Federal Data Protection Act (BDSG) requires a DPO where at least 20 persons are regularly involved in automated processing of personal data.
Why the two roles cannot be combined
The representative acts on behalf of the company and may be subject to enforcement proceedings in the event of non-compliance by the company (Recital 80 GDPR). The DPO, on the other hand, must be independent and must not be penalised for performing his or her tasks (Art. 38(3) GDPR). The European Data Protection Board states in its Guidelines 3/2018 on the territorial scope of the GDPR that the role of representative is not compatible with the role of DPO, because the required independence of the DPO cannot be reconciled with acting under the instructions of the company. We therefore do not offer a combined mandate. If you need both, we can act as your EU representative, and your DPO can be an internal employee or a separate external provider, which may be located outside the EU.
Side-by-side comparison
| EU representative (Art. 27 GDPR) | Data Protection Officer (Art. 37 GDPR) | |
|---|---|---|
| Who needs it | Companies without an EU establishment that offer goods or services to, or monitor, people in the EU (Art. 3(2) GDPR) | Companies whose core activities involve large-scale monitoring or large-scale processing of sensitive data, plus national rules |
| Location | Must be established in an EU Member State where affected data subjects are (Art. 27(3) GDPR) | Anywhere, inside or outside the EU |
| Function | Point of contact and letterbox for authorities and data subjects | Internal advisor and compliance monitor |
| Independence | Acts under the company’s mandate | Must be independent (Art. 38(3) GDPR) |
| Liability | May be addressed in enforcement proceedings; company remains responsible | Not personally liable for the company’s compliance |
| Publication | Contact details in the privacy policy (Art. 13(1)(a), 14(1)(a) GDPR) | Contact details published and notified to the supervisory authority (Art. 37(7) GDPR) |
| Combination | Not permitted in one person (EDPB Guidelines 3/2018) | |
Typical situations
A US software company with 30 employees selling subscriptions to customers in Germany and France: needs an EU representative, because it offers services to people in the EU. A DPO is normally not required, because the core activity is software, not the monitoring of people. A Canadian ad-tech company tracking millions of EU users for targeted advertising: needs both, an EU representative and a DPO, because large-scale monitoring is the core activity. A Swiss hotel group with an online booking site in German: needs an EU representative. The DPO question depends on scale and on the special categories of data processed (for example health information in guest records). A Swiss or UK group with a subsidiary in Germany: no EU representative is required, because the group has an establishment in the EU; the German subsidiary must be named as the point of contact instead, and the DPO question is assessed for the group as a whole.
Our EU representative service costs 350 EUR per year, as described on the page What does it cost?. If you are unsure which of the two roles applies to your company, describe your business in the inquiry form and we will tell you.
