Art. 27 GDPR · EU representative

EU Representative (Art. 27 GDPR) for Swiss Companies

Selling into the EEA from Switzerland, the USA, the UK or Singapore? Then you need a designated EU point of contact. SIDD takes on the mandate through its Munich entity, a fixed CHF 600/year, appointed within 48 h. Note: we are not your sales representative and not a member of the European Parliament, we are your legal representative under Art. 27 GDPR.

CHF 600 / year Appointed within 48 h Active since 2017
EU representative under Art. 27 GDPR for third-country companies
Mandate under Art. 321 SCC Professional secrecy

Working for regulated industries and SMEs

CIPP/E · CIPM IAPP certified
ISO 27001 Lead Auditor (BSI)
Aligned with the FDPIC Revised FADP · Art. 10
HQ Baar, ZG Swiss brand
CH · EU · UK · US Mandates worldwide
Dr. Dominic Staiger

Responsible for this mandate

Dr. Dominic Staiger

LL.M., Dr. iur., CIPP/E · Attorney at Law (New York) · Solicitor (UK)

Has for years represented third-country companies as an Art. 27 representative before European supervisory authorities. Direct point of contact for authority enquiries.

LinkedIn profile

What is an EU representative under Art. 27 GDPR?

Brief definition

An EU representative (Art. 27 GDPR) is a natural or legal person established in the EU who represents a third-country company vis-à-vis European supervisory authorities and data subjects. They serve as the point of contact for authority enquiries, keep the records of processing activities (ROPA) available locally, and enable data subjects to exercise their GDPR rights, they are neither a sales representative nor a member of the European Parliament.

The European legislator requires a representative in the EU so that data protection authorities have an accessible point of contact within their jurisdiction and data subjects can effectively exercise their rights. The representative is subject to EU law and cannot evade official proceedings.

Do you need an EU representative? The 5-point trigger check

Answer the following five questions. If you answer one of them with "Yes", you are obliged under Art. 27 GDPR to designate an EU representative.

1

Does your company have no establishment in the EU?

2

Do you offer goods or services to persons in the EEA (including via a website, an online shop or an app)?

3

Do you monitor the behaviour of persons in the EEA (e.g. tracking, analytics, profiling)?

4

Is the processing not merely occasional or does it involve special categories (Art. 9) or criminal data (Art. 10)?

5

Are you not a public authority or public body?

A "Yes" answer to 1 plus at least one of 2 or 3 (and 4 + 5) triggers the obligation to designate a representative. In the event of a breach, fines of up to EUR 20 million or 4% of worldwide annual turnover may apply.

What tasks does SIDD perform as EU representative?

We carry out the mandate through our Munich-based company, as a legal person, not via a private registered address.

  • Designation in your privacy notice with our Munich business address
  • Receipt and forwarding of enquiries from the EEA (supervisory authorities, data subjects)
  • Keeping the records of processing activities (ROPA) available locally
  • Initial assessment of authority enquiries and coordination with your team
  • Optional: advice on specific enquiries at an hourly rate

Note: maintaining and drawing up the records of processing activities remains the responsibility of the controller (your company outside the EU). We recommend combining this with our Data Protection Advisor (Switzerland) oder Data Protection Officer (EU).

What liability does the EU representative bear?

Under Art. 27(5) GDPR, the designation of a representative does not affect the liability of the controller or processor themselves, both remain primarily responsible. However, the representative can be addressed directly by supervisory authorities and is the addressee for enforcement measures. Recital 80 makes clear that the representative is subject to enforcement measures in the same way as the controller. In recent years, supervisory authorities (in particular the Bavarian LfD and the HmbBfDI) have repeatedly imposed fines on representatives where the mandate existed only formally.

Consequence: you should choose a representative with documented processes, a duty of confidentiality and legal competence, not just a letterbox address.

EU representative vs. UK representative, what you need to know

If you sell into both the EEA and the United Kingdom, you need both. The mandates are separate.

  • Legal basis, EU: Art. 27 GDPR. UK: Art. 27 UK GDPR (independent since Brexit).
  • Address, EU: establishment in an EU member state (us: Munich). UK: address in the United Kingdom (us: London).
  • Supervisory authority, EU: national supervisory authorities (e.g. BayLDA, CNIL, AEPD). UK: ICO.
  • Price at SIDD, EU: 600 CHF/year. UK: GBP 1'200/year.
  • Fine framework, EU: up to EUR 20 million / 4%. UK: up to GBP 17.5 million / 4%.

More details on our UK representative page. On request, we handle both mandates from a single source.

EU representative package

Fixed annual price, no hidden costs. Reduced group rates available for corporate groups on request.

Group rate

On request

For group structures with several subsidiaries outside the EU.

  • Reduced per-unit costs
  • Group reporting
  • Advisory hour quota can be integrated

Tip: If you provide your own email address in your privacy notices, the majority of data-subject requests will reach you directly, we remain the escalation point and contact for authorities.

What happens after the engagement is awarded?

Four steps to an established EU representation. Typical duration: 48 hours until live designation.

Contract

Digital service agreement with a clear scope of services as Art. 27 representative.

ROPA takeover

You provide your records of processing activities (or commission a Data protection workshop).

Privacy Notice

You name our Munich company as your EU representative in your privacy notices.

Ongoing support

Incoming requests are communicated to you promptly and coordinated jointly.

Why SIDD?

An Art. 27 mandate is a liability and authority-facing function, not a mailbox: these six points show why third-country companies entrust it to SIDD.

Our own Munich company

In your privacy notices we name our own company in Munich as a legal entity with a business address, no third-party mailbox address and no private registered address. This is the robust point of contact that supervisory authorities expect under Art. 27 GDPR .

Mandate managed by a lawyer

The mandate is managed by Dr. Dominic Staiger as a lawyer and is subject to professional secrecy under Art. 321 SCC. Authority requests and data-subject information passing through us are therefore especially protected.

A lawyer instead of a mere contact point

Authority requests are given an initial assessment by a doctorate-level data-protection lawyer (Dr. iur., LL.M., CIPP/E), not merely forwarded. This way you avoid the formal sham mandate against which the LfD Bayern and HmbBfDI have already imposed fines.

Commissioned within 48 hours

Digital contract, fixed annual flat fee from CHF 600, no setup fee: within 48 hours our Munich business details are available for your privacy notices. A dedicated contact person, with an initial response within 24 hours.

EU and UK from a single source

We operate our own companies in Munich and London and handle mandates in CH, EU, UK and US. If you sell into the EEA and the United Kingdom, we take on both separate representations, the EU one under Art. 27 GDPR and the UK one under Art. 27 UK GDPR, coordinated through a single point of contact.

Documented escalation

Incoming requests from the EEA are received, documented and escalated to you in a traceable manner. In the event of enforcement by an authority under Recital 80, this verifiability is what distinguishes a representative from a mere address.

Our tool: LexCommand

Why we work with LexCommand, our own Swiss legal AI

LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.

Sovereign in Switzerland

The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.

No citation, no claim

Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.

From effort to judgement

LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.

Three disciplines, one picture

We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.

For the Art. 27 mandate, concretely: when a supervisory authority enquiry arrives from the EEA, LexCommand grounds our first assessment in the governing norm, every reference to Art. 27 GDPR or recital 80 carries a retrievable source, kept cleanly separate from the UK GDPR.

Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.

Frequently asked questions before engaging us

What does an EU representative cost at SIDD?

A fixed 600 CHF per year and per represented company. Reduced group rates apply for corporate groups. No setup fee, no hidden costs.

Who is liable if I breach the GDPR?

Your company remains responsible as the controller or processor. However, the EU representative is also an addressee for enforcement measures (Art. 27(5) GDPR, Recital 80). We reduce the risk through documented processes and an initial review of requests.

Can I designate a private individual as my EU representative?

In theory yes, in practice not advisable. Their private registered address would then have to appear in your privacy notice. We designate our Munich company as a legal entity with a business address.

How quickly is the mandate set up?

Contract signing and provision of the business details for your privacy notice take place within 48 hours of receiving your engagement.

Do I also need a Data Protection Officer (DPO)?

Possibly yes, it depends on your processing activities. The EU representative does not replace a DPO under Art. 37 GDPR. We are happy to handle the dual mandate from a single source, see Data Protection Officer (EU).

What happens in the event of a request from an authority?

We receive the request, document it, conduct an initial review and agree the response with you. For complex requests, we recommend extending the engagement with a data-protection advisor mandate or hourly-rate consulting.

EU representative in 48 hours, a fixed 600 CHF/year.

Order online now. You receive the contract digitally, our Munich business details for your privacy notice and a dedicated point of contact.