GDPR
Chapter IV - Controller and Processor

GDPR GDPR-Art.27: Representatives of controllers or processors not established in the Union

Where the Regulation applies under Article 3(2) to a controller or processor not established in the Union, designate a representative in the Union in writing, established in one of the Member States where the data subjects whose data is processed in relation to the offering of goods or services, or whose behaviour is monitored, are located. Mandate the representative to be addressed, in addition to or instead of the controller or processor, by supervisory authorities and data subjects on all issues related to processing. The obligation does not apply to processing which is occasional, does not include large scale processing of special category or criminal offence data and is unlikely to result in a risk to the rights and freedoms of natural persons, nor to a public authority or body. Designating a representative is without prejudice to legal actions against the controller or processor themselves.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 4 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

EU AI Act · 2 controls

  • EUAI-Art.22 Authorised representatives of providers of high-risk AI systems
  • EUAI-Art.54 Authorised representatives of providers of general-purpose AI models
  • PIPL-Art53 Domestic Representative for Overseas Handlers

NIS2 Directive · 1 control

  • Art.26 Establish which Member State has jurisdiction, and designate a Union representative if not established in the Union

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Chapter IV - Controller and Processor

You are reading one control. How much of GDPR have you already done?

GDPR GDPR-Art.27 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 41 GDPR controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.

Query this from an agent

The graph holds this control, the 4 it maps to, and the evidence behind each claim, over MCP and REST.