When you need a representative
Art. 27 GDPR (Regulation 2016/679) applies to controllers and processors that are:
- Not established in the EU, AND
- Processing personal data of data subjects who are in the EU, where the processing relates to offering goods/services to those subjects (Art. 3(2)(a)) or monitoring their behaviour in the EU (Art. 3(2)(b))
What the representative actually does
- Acts as the contact point for the Romanian Data Protection Authority (ANSPDCP) and for data subjects
- Receives complaints, requests for access/rectification/erasure and forwards them to the controller within agreed SLAs
- Maintains the record of processing activities (Art. 30) available for inspection
- Coordinates breach notification under Art. 33 within the 72-hour window
- Receives administrative acts and ANSPDCP enforcement notices on your behalf
Practical considerations
Designating a representative does NOT shift liability away from the controller. The controller remains primarily liable under Art. 24, but enforcement actions in Romania may be served on the representative — and ignored notices have led to fines.
We publish the representative's contact details in your privacy notice and provide a Romanian-language complaint channel as required by ANSPDCP guidance.
Frequently asked questions
Related resources
Talk to a Romanian lawyer in English
since 2008 advising foreign companies on Romanian law. Confidential, fixed-fee quotes.