Data Protection

EU Representative Service

Official EU Representative according to Art. 27 GDPR — for companies without a branch in the EU.

Official EU Representative for all EU member states
Art. 27 GDPR compliant — mandatory where required
Never miss a GDPR inquiry — fast, reliable forwarding
Flat annual fee — from CHF 400/year
First legal classification of every inquiry included
Trusted by 1000+ clients
Trusted by 1'500+ tech companies & investors
Thomas Kuster
"Companies without an EU branch that offer services to EU residents or monitor their behaviour typically need an EU representative under Art. 27 GDPR — book a call with me and my team to find out if that applies to you."

Thomas Kuster · Partner @ LEXR  ·  Book your free call →

How we solve your challenges

From official appointment to forwarding every inquiry — the full EU representative mandate, in one team.

We act as your official EU representative for all EU member states, covering your obligations under Art. 27 GDPR in a single engagement — no need to appoint representatives country by country.

We receive all GDPR-related inquiries from supervisory authorities and data subjects across the EU, forward them to you via your preferred communication channel, and provide an initial legal classification so you can respond efficiently.

We provide your records of processing activities to supervisory authorities upon request — a core duty of the EU representative under Art. 27 GDPR — and can assist in creating or updating those records as an add-on service.

Beyond the representative mandate, our data protection experts can handle inquiries substantively, advise on any data protection issues arising from EU regulatory requests, and support you with broader GDPR compliance work.

What's included in our EU Representative service

A complete Art. 27 GDPR mandate — official appointment, inquiry handling, and records of processing activities, all in one annual flat fee.

Official EU representative (all member states)GDPR Art. 27 complianceForwarding of authority & data-subject inquiriesInitial legal classification of inquiriesRecords of processing activities on requestAnnual flat-fee modelAdd-on: substantive inquiry handling

Why LEXR

01

Legal expertise you can rely on

Our data protection experts have in-depth knowledge of GDPR and can classify inquiries professionally — the EU representative is the first point of contact for authorities and data subjects, so competence matters.

02

Transparent, predictable annual fee

From CHF 400 per year. Know your costs up front with a flat annual fee — no billable-hour surprises when an inquiry lands.

03

Fast response times, nothing falls through

We collect all GDPR-related inquiries reliably and forward them quickly with an initial assessment, so you can act before deadlines become a problem.

EU Representative FAQ

The questions we hear most from companies that need an EU representative under Art. 27 GDPR.

If there is no branch in the EU, but goods or services are offered to persons within the EU or the behaviour of persons within the EU is monitored (e.g. tracking and profiling), an EU representative according to Art. 27 GDPR is usually required.

Failure to designate an EU representative may result in fines of up to €10 million or up to 2% of the annual worldwide turnover for the previous fiscal year.

The tasks of the EU representative are defined in Art. 27 GDPR. The representative serves as a contact point for supervisory authorities and data subjects from the EU, assists in receiving and forwarding data subject inquiries, and provides the records of processing activities upon request of the supervisory authority. The representative performs a representative function within the EU and supports compliance with the requirements of the GDPR.

Data subjects must be informed about the EU representative, meaning the representative's contact details must be included in the privacy policy. In addition, the EU representative must be named in the records of processing activities.

The EU representative's function is essentially to be available as an external point of contact for supervisory authorities and data subjects in the EU — it does not affect the liability of the controller. A data protection officer has a much broader scope: they are both an internal and external point of contact for all data protection issues, and perform legally defined tasks such as monitoring compliance with data protection regulations and informing and advising employees and management.

Let's get started

Book your free call and find out whether your company needs an EU representative — and how we can help.

Dive deeper into data protection

Data ProtectionAI Features in Your SaaS? What the EU AI Act Means for YouTeam LEXR · Mar 2026Read more →Data ProtectionYou Need to Fix These 5 Points in Your SaaS Agreements Now!Nadine Saalbach · Sep 2025Read more →Data ProtectionNavigating the EU AI Act: A Comprehensive Analysis and Compliance GuideTeam LEXR · May 2024Read more →Data ProtectionNew EU Regulations: A Blueprint for Growth in the Digital SectorTeam LEXR · May 2024Read more →Data ProtectionCybersecurity and data protection: keeping your company's data safeTeam LEXR · Apr 2024Read more →Data ProtectionFrom concept to compliance: Legal Bases for AI training explainedTeam LEXR · Mar 2024Read more →Data ProtectionData Processing Agreements: Navigating the Essentials for Data Protection Compliance (Part 2)Team LEXR · Feb 2024Read more →Data ProtectionData Processing Agreements: Navigating the Essentials for Data Protection Compliance (Part 1)Team LEXR · Jan 2024Read more →Data ProtectionPseudonymisation versus anonymisation: a practical privacy guideTeam LEXR · Dec 2023Read more →Data ProtectionHow to handle data breaches – a privacy best practice guideTeam LEXR · Sep 2023Read more →Data ProtectionNavigating AI tools and data protection: A guide for compliant company practicesTeam LEXR · Jul 2023Read more →Data ProtectionThe new Swiss Data Protection Act comes into force: What tech companies need to do nowTeam LEXR · Jun 2023Read more →Data ProtectionNavigating Privacy Rules for App Developers: App Store Compliance and Privacy RequirementsTeam LEXR · Apr 2023Read more →Data ProtectionKYC for FinTech companies: Data protection guide part 3 - Manage the dataTeam LEXR · Mar 2023Read more →Data ProtectionKYC for FinTech companies: Data protection guide part 2 - Follow the dataTeam LEXR · Feb 2023Read more →Data ProtectionKYC for FinTech companies - Guide to a data protection compliant implementationTeam LEXR · Feb 2023Read more →Data ProtectionChecklist: How to write a privacy policy for the new FADP and GDPR?Team LEXR · Jun 2021Read more →Data ProtectionData Processing Agreement I: Determine whether you are a Controller or a ProcessorTeam LEXR · Apr 2021Read more →Data ProtectionSchrems II impact on privacy shield & SCCsTeam LEXR · Jul 2020Read more →Data ProtectionGDPR impact on AdTech and Real-Time Bidding (RTB)Team LEXR · May 2020Read more →Data ProtectionConfidential Computing and GDPRTeam LEXR · Mar 2020Read more →Data ProtectionThe License to Kill and the right to be forgotten - Gaming in the Age of GDPRTeam LEXR · Mar 2020Read more →Data ProtectionEmployee awareness as the key to security and data privacyTeam LEXR · Feb 2020Read more →Data ProtectionThe Internet of Things in the GDPR eraTeam LEXR · Jan 2020Read more →Data ProtectionGDPR in Switzerland - What it means for businessesTeam LEXR · Dec 2018Read more →