Newsletter Anmeldung

Bleiben Sie mit dem Newsletter immer up to date.

Request
arrow-to-top
HomeMandatesRepresentative positionsEU Representative under the GDPR
Dimitri Korostylev
Head of Legal & Data Privacy Consulting
request

The external representative under the GDPR

For data protection-compliant processing in EU/EEA markets – even without an established presence in the EU/EEA

Under Article 27 of the European General Data Protection Regulation (GDPR), companies based outside an EU/EEA country must appoint an official representative in the EU or the EEA if they are nevertheless subject to the GDPR.

This is particularly the case if a company:

  • offers goods or services to individuals in EU/EEA countries, regardless of whether for payment or free of charge; or
  • monitors the behaviour of individuals in EU/EEA countries, e.g. through online tracking, profiling or other analytical tools;
  • and does not have its own establishment in the EU/EEA.

The EU representative is designated by law as the point of contact for supervisory authorities and data subjects. They must be authorised to be contacted regarding all of the company’s GDPR obligations.

Our role as your external EU representative under the GDPR

Our subsidiary, Swiss Infosec (Deutschland) GmbH, based in Berlin, Germany, acts as your external representative under Article 27 of the GDPR. Our data protection specialists ensure that enquiries from the EU are handled professionally, in a timely manner and in your best interests.

Among other things, we offer you:

  • Acting as the official point of contact in the EU/EEA for data protection supervisory authorities and data subjects
  • Receiving, coordinating and responding to requests for information and other enquiries from data subjects (rights to access, erasure, objection, etc.)
  • Coordination of communication with supervisory authorities, e.g. in the event of complaints, audits or enquiries regarding data processing
  • Support with the preparation and updating of the necessary documentation, in particular the record of processing activities and, where required, further evidence of GDPR compliance
  • Pragmatic recommendations for action based on data protection best practice – tailored to your business model and risk profile
  • A reliable point of contact who understands your business and your data flows and, where necessary, acts as a liaison between specialist departments, management and the authorities

This allows you to focus on your core business in the EU/EEA market. We take care of data protection-compliant representation and professional communication within the framework of the GDPR.

Why choose Swiss Infosec AG as your EU representative under the GDPR?

  • Specialised data protection expertise with many years of experience in the GDPR, UK GDPR and Swiss data protection law
  • Practical, risk-based advice rather than purely theoretical guidelines, with a focus on business-ready, implementable solutions
  • Experience with international companies without an EU branch, including SaaS providers, e-commerce, industry, finance and service companies
  • Understanding of the interplay between the GDPR, the Swiss Data Protection Act (FADP) and the UK GDPR, particularly in relation to cross-border data flows
  • Clear lines of responsibility and short communication channels for queries, audits or incidents – a single point of contact for all matters relating to Article 27 of the GDPR

Our goal: to design GDPR compliance in such a way that you are legally compliant – without unnecessarily slowing down your business.

Next steps

Contact us for a no-obligation quote. Together, we will clarify:

  • Whether your company falls within the territorial scope of the GDPR (Article 3 GDPR) and is therefore obliged to appoint an EU representative, and
  • how we can efficiently integrate the role of the EU representative under Article 27 of the GDPR into your existing data protection and compliance structures.

Let us take care of your EU representation under the GDPR, so that you can operate in EU/EEA markets securely, trustworthily and in compliance with data protection regulations.

Dimitri Korostylev
Head of Legal & Data Privacy Consulting
request

Non-binding enquiry

© Swiss Infosec AG 2026