

Service Overview
EU GDPR Representative (Article 27)
The EU GDPR requires most controllers and processors not established in the European Union to designate a representative in the Union if they offer goods or services to individuals in the EU or monitor their behaviour. The representative acts as a contact point for supervisory authorities and data subjects in relation to the organisation's GDPR obligations. Article 30 also requires certain organisations to maintain records of processing activities, which must be made available to supervisory authorities upon request.
Service Detail
What this service covers
Our focus
Established in Ireland for genuine EU-facing representation
Lionheart provides Article 27 EU GDPR representation through its Ireland-based establishment, giving non-EU organisations a real compliance foothold within the European Union. We provide a structured, named point of contact for supervisory authorities and data subjects, year-round inbox monitoring, and documented escalation procedures — not a nominal address service.
Senior-led support for complex cross-border privacy operations
Your EU GDPR mandate is handled by experienced privacy and technology professionals who understand both the legal framework and the operational realities of global services, SaaS, adtech, AI, media and online platforms. We work as an extension of your privacy function, helping ensure that regulatory correspondence is received, logged, escalated and actioned correctly.
Coordinated with your wider European footprint
Many organisations needing an EU GDPR representative also require a UK GDPR representative, Swiss FADP representative, or support under adjacent digital regulations. Lionheart coordinates these mandates under a single relationship — consistent procedures, aligned records and a unified escalation path across jurisdictions.
Our services include
Custom email address
A dedicated @LionheartSquared.eu address published in your privacy notice and records of processing activities, monitored year-round.
EU physical address
Lionheart's Dublin address is available for inclusion in your privacy documentation and regulatory filings, satisfying the Article 27 EU GDPR establishment requirement.
Data Protection Authority
Acting as the formal contact point for EU Data Protection Authorities on your behalf — receiving, logging and forwarding all correspondence without delay.
Unlimited data subject enquiries
Receiving and forwarding access, erasure, rectification, restriction and objection requests from individuals in the EU to your privacy team for handling.
Escalation procedures
Defined escalation paths and service levels for time-sensitive regulatory communications, including data breach notifications. Activity reporting available on request.
ROPA record-keeping
Lionheart holds a copy of your Records of Processing Activities (ROPA) as required under Article 30 EU GDPR; it will be made available to EU data protection authorities upon request.
Legal basis: Article 27, EU General Data Protection Regulation (EU) 2016/679
Get started
Not sure if you are in scope?
Use the guided self-check tool to map which representative obligations may apply.
