Service Overview

EU GDPR Representative (Article 27)

The EU GDPR requires most controllers and processors not established in the European Union to designate a representative in the Union if they offer goods or services to individuals in the EU or monitor their behaviour. The representative acts as a contact point for supervisory authorities and data subjects in relation to the organisation's GDPR obligations. Article 30 also requires certain organisations to maintain records of processing activities, which must be made available to supervisory authorities upon request.

Service Detail

What this service covers

Our focus

Established in Ireland for genuine EU-facing representation

Lionheart provides Article 27 EU GDPR representation through its Ireland-based establishment, giving non-EU organisations a real compliance foothold within the European Union. We provide a structured, named point of contact for supervisory authorities and data subjects, year-round inbox monitoring, and documented escalation procedures — not a nominal address service.

Senior-led support for complex cross-border privacy operations

Your EU GDPR mandate is handled by experienced privacy and technology professionals who understand both the legal framework and the operational realities of global services, SaaS, adtech, AI, media and online platforms. We work as an extension of your privacy function, helping ensure that regulatory correspondence is received, logged, escalated and actioned correctly.

Coordinated with your wider European footprint

Many organisations needing an EU GDPR representative also require a UK GDPR representative, Swiss FADP representative, or support under adjacent digital regulations. Lionheart coordinates these mandates under a single relationship — consistent procedures, aligned records and a unified escalation path across jurisdictions.

Our services include

Custom email address

A dedicated @LionheartSquared.eu address published in your privacy notice and records of processing activities, monitored year-round.

EU physical address

Lionheart's Dublin address is available for inclusion in your privacy documentation and regulatory filings, satisfying the Article 27 EU GDPR establishment requirement.

Data Protection Authority

Acting as the formal contact point for EU Data Protection Authorities on your behalf — receiving, logging and forwarding all correspondence without delay.

Unlimited data subject enquiries

Receiving and forwarding access, erasure, rectification, restriction and objection requests from individuals in the EU to your privacy team for handling.

Escalation procedures

Defined escalation paths and service levels for time-sensitive regulatory communications, including data breach notifications. Activity reporting available on request.

ROPA record-keeping

Lionheart holds a copy of your Records of Processing Activities (ROPA) as required under Article 30 EU GDPR; it will be made available to EU data protection authorities upon request.

Legal basis: Article 27, EU General Data Protection Regulation (EU) 2016/679

Get started

Not sure if you are in scope?

Use the guided self-check tool to map which representative obligations may apply.