DPO vs EU Representative
Last reviewed: · By Victor Humenhuk (CIPP/E certified)
A data protection officer is an independent adviser required by Article 37 when an organisation is a public authority or body, or when its core activities involve regular and systematic monitoring of data subjects on a large scale, or large-scale processing of special category or criminal conviction data. An Article 27 representative is a different role entirely: a person or firm established in the EU that a non-EU organisation caught by Article 3(2) must appoint in writing as its local point of contact for data subjects and supervisory authorities. The DPO must be free from instructions about how to perform the role and cannot be dismissed or penalised for performing it; the representative acts on the organisation's written mandate and can itself be the subject of enforcement proceedings. The EDPB's territorial scope guidelines treat the representative role as incompatible with that of an external DPO, so the same person should not hold both.
DPO vs EU representative side by side
| Feature | Data protection officer | EU representative |
|---|---|---|
| Legal basis | Articles 37-39 | Article 27 |
| Trigger | Public authority; large-scale regular and systematic monitoring; large-scale special category or Article 10 data | Caught by Article 3(2) - offering goods or services to, or monitoring the behaviour of, people in the EU without an EU establishment |
| Who appoints | Controllers and processors alike | Non-EU controllers and processors |
| Where based | Not fixed by the article, provided the DPO is easily accessible from each establishment | In a member state where the relevant data subjects are (Art 27(3)) |
| Core function | Inform, advise, monitor compliance, train, advise on DPIAs, cooperate with the authority | Be addressed by authorities and data subjects; maintain the Article 30 record |
| Independence | No instructions on performing tasks; reports to the highest management level; no conflicting duties | Acts on the organisation's written mandate - not independent |
| Exposure | Cannot be dismissed or penalised for performing the role (Art 38(3)) | May be subject to enforcement proceedings in the event of the organisation's non-compliance |
| Publication | Contact details published and communicated to the supervisory authority (Art 37(7)) | Identity and contact details given in the privacy notice under Arts 13(1)(a) and 14(1)(a) |
| Can it be outsourced | Yes - Article 37(6) allows a service contract | Yes - commonly a law firm or specialist provider |
When must you appoint a DPO?
Article 37(1) sets three mandatory triggers, and they apply to processors as well as controllers.
- The processing is carried out by a public authority or body, except for courts acting in their judicial capacity.
- The core activities consist of processing operations which by their nature, scope or purposes require regular and systematic monitoring of data subjects on a large scale.
- The core activities consist of large-scale processing of special categories of data or of personal data relating to criminal convictions and offences.
The WP29 guidelines on data protection officers unpack the loaded phrases. 'Core activities' means the key operations needed to achieve the organisation's objectives, not ancillary support functions such as payroll or IT security for its own staff. 'Regular and systematic monitoring' includes all forms of online tracking and profiling, not only continuous surveillance. 'Large scale' is assessed against the number of data subjects, the volume and range of data, the duration and the geographical extent.
Article 37(4) allows Union or member state law to require a DPO in further cases, so the national layer matters. A group may appoint a single DPO under Article 37(2) provided the DPO is easily accessible from each establishment. Article 38 protects the position: proper and timely involvement, resources, no instructions on how to carry out the tasks, and no conflict of interest - the CJEU confirmed in X-FAB (C-453/21) that a conflict arises where the DPO also holds duties that involve determining the purposes and means of the organisation's processing.
When must you appoint an Article 27 representative?
The trigger is Article 3(2): a controller or processor with no establishment in the Union that either offers goods or services to data subjects in the Union, whether or not payment is required, or monitors their behaviour as far as that behaviour takes place in the Union. If Article 3(2) applies, a written mandate must appoint a representative established in a member state where the affected data subjects are.
Article 27(2) carves out two situations. There is no obligation where the processing is occasional, does not include large-scale processing of special category or Article 10 data, and is unlikely to result in a risk to rights and freedoms; and there is none for public authorities or bodies. The EDPB's Guidelines 3/2018 on territorial scope also make clear that appointing a representative does not itself create an establishment in the Union, so it does not pull the organisation into Article 3(1).
Post-Brexit this bites twice: a UK-based business targeting the EU may need an EU representative under the GDPR, while a non-UK business targeting the UK may need a UK representative under the UK GDPR. See territorial scope for the underlying tests.
Can the same person be both DPO and representative?
No, and this is a favourite exam point. The EDPB's Guidelines 3/2018 state that the function of representative in the Union is not compatible with the role of an external data protection officer.
The reasoning is structural rather than technical. The representative is mandated by, and acts for, the organisation, and may face enforcement action in the organisation's place. The DPO must be able to act independently, must not receive instructions on how to perform the role, must not be penalised for performing it, and must be in a position to challenge the organisation's decisions. A person who is simultaneously the target of enforcement and the independent monitor of compliance cannot credibly do both.
Practically, an organisation caught by Article 3(2) whose activities also meet an Article 37 trigger needs two separate appointments, and both must be disclosed in the privacy notice.
Related study notes
- The data protection officer (DPO)
- Module 10 · The EU representative (Article 27)
- Module 10 · The data protection officer (DPO, Articles 37-39)
- Article 3(2): the targeting and monitoring tests
- Public international law, EU representatives and Brexit
Frequently asked questions
Does appointing an EU representative make my company established in the EU?
No. Article 27 creates a contact point, not an establishment, and the EDPB has confirmed that appointing a representative does not trigger Article 3(1). Your obligations still flow from Article 3(2).
Can a DPO be an external consultant?
Yes. Article 37(6) allows the DPO to be a staff member or to fulfil the tasks on the basis of a service contract. The external DPO still needs the Article 38 protections, adequate resources and enough access to the business to monitor compliance meaningfully.
Is the representative liable for the organisation's breaches?
Recital 80 says the representative should be subject to enforcement proceedings in the event of non-compliance by the controller or processor, which is why the mandate and indemnities matter commercially. Responsibility for compliance itself remains with the controller or processor.
Do we need a representative in every member state where we have users?
No. One representative is required, established in a member state where data subjects whose data is processed in connection with the offering or monitoring are located. The EDPB suggests choosing a state where a significant share of those data subjects are, and the contact details must be easily accessible to individuals in all affected states.
Test yourself
Try the free CIPP/E practice questions, or read the full CIPP/E study guide - free.