All 27 EU member states · live coverage
Article 27 explained Backed by Cloudkasten GmbH · Erftstadt, DE
Industry & Country Coverage

GDPR Article 27 EU Representative — Industry & Country Coverage

GDPR Article 27 requires non-EU companies offering goods or services to EU residents — or monitoring their behaviour — to designate an EU representative. rep4eu provides that designation through Cloudkasten GmbH, a registered German company, with licensed German attorneys (Rechtsanwälte) involved in running the service, across all 27 EU member states, with industry- and country-specific coverage notes below.

For the full statutory framework, see our Article 27 regulations guide, or how the service runs day to day in our Article 27 EU representative services overview.

By Industry

Article 27 triggers the moment your product processes personal data of EU residents — regardless of industry. These industry-specific pages cover the typical data flows, common compliance gaps, and the procurement-review impact in each vertical.

SaaS

Software-as-a-Service companies host user accounts, run product analytics, and process support data — all activities that pull EU users into…

EU representation for SaaS →

E-commerce

Online retailers that ship to or market to EU consumers process names, shipping addresses, payment metadata, and behavioural data from EU re…

EU representation for E-commerce →

Fintech

Fintech operators sit at the intersection of GDPR, PSD2, AMLD, and national financial supervisory law. Article 27 is a baseline you cannot a…

EU representation for Fintech →

HealthTech

Health, wellness, and clinical platforms collect data that falls under GDPR Article 9 special categories. The regulatory floor is higher — a…

EU representation for HealthTech →

EdTech

EdTech platforms serving EU schools, universities, and learners process minors' data and engage with publicly-funded buyers — both of which …

EU representation for EdTech →

Marketing Agency

Agencies act as processors for many clients but also collect data on EU prospects through their own funnels. Both roles can trigger Article …

EU representation for Marketing agencies →

HR Software

Applicant tracking, payroll, and people-ops platforms hold the most sensitive employment data in any organisation — and increasingly serve E…

EU representation for HR software →

Legal Tech

Legal-tech platforms process some of the most sensitive third-party data on the market. EU law firms are conservative buyers and expect thei…

EU representation for Legal tech →

PropTech

From short-term rentals to commercial leasing analytics, PropTech platforms touch tenant, buyer, and visitor data across EU markets with ver…

EU representation for PropTech →

InsurTech

InsurTech operators handle health, financial, and behavioural data on EU policyholders — and operate in a sector under heavy regulatory scru…

EU representation for InsurTech →

AdTech

AdTech is the single highest-risk vertical under GDPR. Real-time bidding, fingerprinting, and cross-site tracking are exactly what EU regula…

EU representation for AdTech →

Gaming

Game studios and platforms process player identity, payment, voice-chat, and behavioural data from millions of EU users — often including mi…

EU representation for Gaming →

Mobile Apps

Mobile apps published in EU app stores hand over identifiers, location, and device data from the first install. SDK chains amplify the data …

EU representation for Mobile apps →

AI/ML

AI and ML providers face dual pressure: GDPR Article 27 today, and EU AI Act Article 25 / 54 representative obligations coming online for hi…

EU representation for AI and ML companies →

Cybersecurity

Security tooling sees deep, sensitive telemetry across customer environments. Even defensive products process personal data, often in specia…

EU representation for Cybersecurity vendors →

Logistics

Logistics platforms route names, addresses, recipient phone numbers, and signature data across EU borders constantly — and the cross-border …

EU representation for Logistics and supply-chain →

Travel

Travel platforms process passport-grade identity data, payment data, and detailed itinerary information for EU travellers — the kind of data…

EU representation for Travel and hospitality →

Food Delivery

Food delivery platforms gather location, payment, and dietary preference data from EU consumers, plus gig-worker data from couriers — both a…

EU representation for Food delivery platforms →

Media/Publishing

Publishers, streaming services, and news platforms profile EU readers, run ad tech, and increasingly handle subscription identities — all in…

EU representation for Media and publishing →

Recruitment

Sourcing platforms, ATS vendors, and headhunting tools handle EU candidate data — usually without the candidates ever signing up directly. T…

EU representation for Recruitment platforms →

By Country

Article 27 applies to any non-EU controller or processor in scope. These country-specific pages cover the typical EU market entry profile, business types most affected, and how rep4eu receives and forwards authority correspondence for operators based outside the EU.

United States

US companies selling to EU customers, running EU marketing, or simply allowing EU traffic to their website fall within GDPR's territorial sc…

EU representation for US companies →

Canada

PIPEDA has been deemed adequate for some EU transfers, but it does not exempt Canadian companies from GDPR Article 27 when they actively off…

EU representation for Canadian companies →

Australia

Australian companies serving EU users are squarely within GDPR's reach. The Australian Privacy Act covers Australian operations but does not…

EU representation for Australian companies →

United Kingdom

Post-Brexit, UK companies are third-country controllers from the EU's perspective. UK GDPR alone is not enough — Article 27 requires a repre…

EU representation for UK companies →

India

Indian SaaS, IT services, and e-commerce companies have grown rapidly into EU markets. The DPDPA covers domestic processing but does nothing…

EU representation for Indian companies →

Singapore

Singapore's PDPA gives a strong domestic baseline but is not a substitute for GDPR Article 27 representation when a Singaporean company proc…

EU representation for Singaporean companies →

Japan

Japan benefits from the EU's adequacy decision, but adequacy does not exempt Japanese controllers from Article 27 when they target EU reside…

EU representation for Japanese companies →

Brazil

Brazil's LGPD is a clear domestic framework, but it does not satisfy GDPR Article 27 when a Brazilian company offers goods or services to EU…

EU representation for Brazilian companies →

Israel

Israel has an adequacy decision for transfers, but adequacy does not solve Article 27. Israeli companies serving EU users still need an EU r…

EU representation for Israeli companies →

South Korea

South Korea has adequacy, but Korean companies offering goods or services in the EU still fall under Article 27. PIPA covers domestic obliga…

EU representation for South Korean companies →

Appoint your EU representative

One registered German GmbH as your EU representative, covering all 27 EU member states. Self-serve checkout, signed designation letter in 24–48 hours.

Ready to Close Your Article 27 Risk Gap?

GDPR Article 27 representation, backed by Cloudkasten GmbH. Fixed annual pricing, published online. Get covered in under 48 hours.

Have a question first? Get in touch →

No credit card required. Results in 2 minutes.

Backed by Cloudkasten GmbH
HRB 92697 · Amtsgericht Köln
24–48h Verification target (business days)