Skip to content
    August 21, 2026| Top Floor Team| 12 min read

    EU Representative vs DPO: Which Does a US Company Need?

    These are two different appointments with two different triggers, and most US companies caught by the GDPR owe the cheaper one. An Article 27 EU representative is required of almost any controller or processor in GDPR scope with no establishment in the Union, and published appointment prices start at EUR 100 a year (DataRep's stated minimum) and run to GBP 1,500 a year (GRC Solutions, for organisations of 11 to 500 employees). An Article 37 Data Protection Officer is required only where your core activities involve regular and systematic monitoring of data subjects on a large scale, or large-scale processing of special-category or criminal-offence data, and published benchmarks put that service in the thousands of euros a month. EDPB Guidelines 3/2018 state that the two roles are incompatible, so one firm cannot hold both.

    This article walks the two triggers, the price gap, the incompatibility rule that trips up bundled offers, and the case where you owe neither appointment.

    Key takeaways

    • Article 27 (EU representative) is triggered by GDPR scope plus no EU establishment. Article 37 (DPO) is triggered by what your core activities do with data. They are unrelated tests.
    • Published EU representative pricing starts around EUR 100 a year and reaches GBP 1,500 a year for a mid-sized organisation; the appointment is a mailbox and a legal contact point, not an advisory service.
    • The Article 27(2) exemption exists but is narrow: occasional processing, no large-scale special-category or criminal-offence data, and unlikely to result in a risk to individuals. All three must hold.
    • EDPB Guidelines 3/2018 treat representative and DPO as incompatible roles, so a bundled "we will be both" offer is a red flag.
    • If GDPR does not reach you at all, you owe neither, and establishing that in writing is cheaper than either appointment.

    What Article 27 actually requires

    Article 27 says that where Article 3(2) applies, meaning you offer goods or services to people in the Union or monitor their behaviour there, and you have no establishment in the Union, you must designate in writing a representative in one of the Member States where the affected individuals are.

    Three things about what that representative is for. It is a point of contact for supervisory authorities and for data subjects, named in your privacy notice, on matters relating to processing. It must be mandated to be addressed in addition to or instead of you. And under EDPB Guidelines 3/2018 it must maintain the record of processing activities required by Article 30, which means the representative holds a copy of documentation you have to produce anyway.

    What it is not: an adviser, a decision maker, or a compliance function. The representative does not tell you whether your lawful basis is sound. It receives correspondence and holds records. This is why the appointment can honestly cost EUR 100 a year and why paying thousands for one should prompt a question about what else is in the bundle.

    The obligation binds processors too, not only controllers, which is the limb US infrastructure and analytics vendors most often miss.

    The Article 27(2) exemption, and why it is narrower than you want

    Article 27(2) exempts processing that is occasional, does not include large-scale processing of special categories of data under Article 9 or of criminal-conviction data under Article 10, and is unlikely to result in a risk to the rights and freedoms of natural persons. It also exempts public authorities and bodies.

    Every limb has to hold at once. The one that fails in practice is "occasional". A website that runs continuously and takes signups from Union residents every week is not processing occasionally, whatever its volume. EDPB Guidelines 3/2018 read the exemption narrowly and treat processing carried out as part of the regular course of business as failing it.

    So the honest reading for a typical US company with a live product and European users is that the exemption does not apply. It is not impossible to fall inside it, and a genuinely one-off processing operation can. But if your answer to "is this occasional" requires an argument, you have already lost it, and the appointment costs less than the argument.

    What Article 37 actually requires

    Article 37(1) makes a DPO mandatory in three cases: a public authority or body; core activities consisting of processing operations that by their nature, scope or purposes require regular and systematic monitoring of data subjects on a large scale; or core activities consisting of large-scale processing of Article 9 special categories or Article 10 criminal-conviction data.

    The qualifiers do all the work here as well. "Core activities" means the operations essential to what you do, not supporting functions like your own HR and payroll. "Large scale" is not defined numerically; the Article 29 Working Party DPO guidelines (WP243, endorsed by the EDPB) point to the number of individuals, the volume and range of data, the duration, and the geographic reach. "Regular and systematic" means ongoing and organised rather than incidental.

    An adtech company, a behavioural analytics vendor, a consumer health app or a large HR platform will usually be caught. A B2B workflow tool whose product is not about tracking people usually is not, even when it holds a great deal of personal data on behalf of its customers.

    Why the two roles are incompatible

    This is the part that gets bundled offers wrong. EDPB Guidelines 3/2018 state that the function of representative in the Union is not compatible with the role of an external DPO established in the Union, and the reason they give is independence, not liability. The representative is subject to a mandate, acts on the controller's or processor's behalf and therefore under its direct instruction, while Article 38(3) requires that the DPO receive no instructions regarding the exercise of their tasks and Recital 97 says the DPO should be able to perform their duties in an independent manner.

    You cannot be independent of a party whose instructions you take. So if you owe both appointments, you need two providers, and a provider offering both in one contract has either not read the guidance or is hoping you have not.

    Liability is a separate point, and it cuts the other way. The guidelines are explicit that designating a representative does not shift the controller's or processor's own responsibility, and that the GDPR does not establish a substitutive liability of the representative. What it does allow is for supervisory authorities to address corrective measures or fines to the representative under Articles 58(2) and 83, with the representative's own direct liability limited to its obligations under Article 30 and Article 58(1)(a).

    There is a practical corollary on the DPO side. If you appoint a DPO voluntarily when Article 37 does not require it, WP243 rev.01 says the same Articles 37 to 39 requirements apply as if the designation had been mandatory. Voluntary does not mean lightweight.

    The price gap is not marginal

    As of August 2026, published list prices for Article 27 representative appointments look like this. DataRep states a minimum annual appointment fee of EUR 100. GRC Solutions publishes an annual fee of GBP 950 excluding VAT for micro organisations of one to ten employees and GBP 1,500 excluding VAT for small and medium organisations of 11 to 500. Engage Compliance advertises a standalone appointment from EUR 59 a month billed annually. All three of those firms sell the service they are pricing, so these are asking prices rather than a market survey, and they are still useful because they bracket the range and they are public.

    Against that, published benchmark data puts outsourced DPO services in the low thousands of euros per month, which is covered with its sourcing in How much does an outsourced DPO cost. We are not restating that figure here, because a second page on this site quoting a different number for the same service is exactly the failure that a consistent set of published prices exists to prevent.

    The gap between the two appointments is roughly two orders of magnitude annually. That is why getting the trigger analysis right is worth an afternoon.

    The decision, in four questions

    Answer these in order and write the answers down.

    Does GDPR reach you at all? Article 3(2) requires that you offer goods or services to people in the Union or monitor their behaviour there. Recital 23 makes clear that mere accessibility of your website from the Union is not enough; there has to be an apparent intention to offer. Accepting euros, shipping to Union addresses, marketing in a Union language, or running behavioural analytics on Union visitors all point toward scope. If nothing does, stop here.

    Do you have an establishment in the Union? Not an office lease specifically; an establishment implies effective and real exercise of activity through stable arrangements. If you have one, Article 27 does not apply to you and you have a lead supervisory authority question instead.

    Do your core activities require regular and systematic large-scale monitoring, or large-scale special-category processing? If yes, you owe a DPO in addition to the representative. If no, you do not.

    Does the Article 27(2) exemption apply? Only if all its limbs hold: occasional, no large-scale Article 9 or Article 10 data, and unlikely to result in a risk. For a running commercial product, this is almost always no.

    Most US companies that work through this honestly land on: GDPR applies, no Union establishment, no DPO trigger, exemption unavailable. One appointment, at published prices in the hundreds.

    When you owe neither, and should buy neither

    The case that gets undersold: you are out of scope. If you sell exclusively to US customers, price in dollars only, market only in English to a US audience, ship only to US addresses, and do not deliberately track visitors from the Union, Article 3(2) is not obviously met. Some EU residents visiting your site does not by itself put you in scope, and Recital 23 says so.

    The right spend in that situation is a scoping memo, not an appointment. Document the factors, name who decided, date it, and revisit it when you start marketing into Europe or take your first euro-denominated contract. That memo is what you hand a regulator or an enterprise buyer who asks. Two appointments you did not need is worse than no appointment plus a defensible file, because the appointments create public representations you then have to live up to.

    The second case: you are a processor whose only Union exposure comes through a customer who is itself established in the Union and has its own compliance posture. You may still owe Article 27, because the obligation binds processors independently, but the DPO analysis will almost always come back negative, and a customer telling you to appoint a DPO in a data processing agreement is a commercial demand rather than a legal one. Negotiate it as such.

    Where Top Floor fits

    We do not sell Article 27 representative appointments. That market has specialists with entities in the right Member States and published prices, and buying it from a consultancy at a markup would be a worse deal for you.

    What we do is the analysis that comes first and the programme that comes after: GDPR scoping under Article 3, the Article 30 records your representative will be expected to hold, and the notices that have to name the appointment once it exists. Where a company is dealing with the EU and the US state laws at the same time, global privacy handles them as one programme rather than two, and where several regimes stack up at once, international compliance is the framing we use. If you want to see how the same discipline applies to picking a consultant at all, questions to ask a compliance consultant is the companion piece.

    How to decide this week

    Write the Article 3(2) memo first. One page: what you sell, to whom, in what currency, in what languages, with what tracking, and the conclusion. This is the document everything else hangs off, and it takes an afternoon.

    If the memo says you are in scope with no Union establishment, get three published quotes for an Article 27 appointment and check what each includes: the Member State of appointment, whether they hold your Article 30 records, response time commitments, and what happens if a supervisory authority writes to them.

    Run the Article 37 test separately, in writing, and do not let a provider run it for you if that provider sells DPO services. If it comes back positive, buy the DPO from a different firm than your representative, for the reason in the incompatibility section above.

    Finally, update your privacy notice in the same sprint. An appointment nobody can find is an appointment you paid for and cannot rely on.

    Frequently asked questions

    What is the difference between an EU representative and a DPO?

    An Article 27 EU representative is a contact point in the Union for companies in GDPR scope that have no establishment there; it receives correspondence from supervisory authorities and data subjects and, per EDPB Guidelines 3/2018, maintains the Article 30 record of processing activities. An Article 37 Data Protection Officer is an independent internal or contracted role that advises on and monitors compliance, and is mandatory only where core activities involve regular and systematic large-scale monitoring or large-scale special-category processing. The triggers are unrelated: one turns on where you are established, the other on what your business does with data.

    Does my US company need an EU representative?

    If GDPR reaches you under Article 3(2), because you offer goods or services to people in the Union or monitor their behaviour there, and you have no establishment in the Union, then yes, unless the narrow Article 27(2) exemption applies. That exemption requires the processing to be occasional, to exclude large-scale Article 9 or Article 10 data, and to be unlikely to result in a risk to individuals, and all three limbs must hold at once. A continuously running commercial product taking Union signups is not occasional processing, so most US companies in scope owe the appointment.

    How much does a GDPR Article 27 representative cost?

    Published list prices as of August 2026 run from a stated minimum of EUR 100 a year at DataRep, through Engage Compliance's standalone appointment from EUR 59 a month billed annually, up to GBP 950 a year at GRC Solutions for one to ten employees and GBP 1,500 for 11 to 500. These are the providers' own asking prices rather than an independent survey, so treat them as a bracket on the market rather than a benchmark. The appointment is a legal contact point and a records holder, not an advisory retainer, which is why the prices are in the hundreds rather than the thousands.

    Can one company be both our EU representative and our DPO?

    No. EDPB Guidelines 3/2018 state that the function of representative in the Union is not compatible with the role of an external DPO established in the Union. The reason is independence: the representative is subject to a mandate and acts under the direct instruction of the controller or processor, while GDPR Article 38(3) requires that the DPO receive no instructions regarding the exercise of their tasks. If you owe both appointments, use two separate providers, and treat a bundled offer as a signal about how carefully that provider reads the guidance.

    Share Share on LinkedIn

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.