Under Article 27 of the GDPR, controllers or processors that are not established in the EU but nevertheless process EU citizens’ personal data for the purposes of offering goods or services or monitoring their behaviour must “designate in writing a representative in the Union”, subject to limited exceptions.
The designated representative must be based in an EU country “where the data subjects, whose personal data are processed in relation to the offering of goods or services to them, or whose behaviour is monitored, are”. Tasks of the designated representative include liaising with data subjects and regulators. The obligation to appoint a representative does not apply to public sector bodies.
Earlier this week, the AP announced that it had fined Locatefamily.com €525,000 because the company did not comply with its Article 27 obligation to designate an EU representative in writing.
Locatefamily.com is a platform that allows users to search for the contact details of people they have lost track of. The AP’s attention was drawn to the company after a series of complaints about the company were raised with its office.
Locatefamily.com told the AP that it had “no business relationships in the European Union”, is not “situated in any country of the European Union” and that it “also do[es] not offer goods or services to the European Union”. However, an AP investigation determined that the company’s processing of personal data was subject to the GDPR and that the company ought to have designated an EU-based representative. The company was given 12 weeks to remedy its breach. If it does not designate an EU data rep in that time, it faces a further fine of €20,000 each fortnight that then passes without action, up to a total of €120,000.
Wouter Seinen of Pinsent Masons said the AP’s enforcement action is a warning to potentially thousands of UK-based companies whose activities are within the scope of the EU GDPR post-Brexit. Those businesses are already subject to the UK GDPR, but Seinen said it is likely that many continue to be subject to the EU GDPR too, and that a large proportion of those companies are probably unaware that they require to designate an EU-based representative to comply with that legislation.
“Due to the binary nature of the data rep requirement, it is quite easy for a regulator to establish that an organisation is in breach, whilst it is almost impossible to find an excuse for not having met this requirement,” Seinen said. “This is why this topic should be higher on the risk radar of non-European businesses – in particular operators of apps and websites.”
Sylvan Martha, managing partner of First European Data Rep, said his company has seen a “steep incline” in the number of non-EU companies designating an EU data rep since Brexit.
Separately, the AP also announced that it had imposed a €7,500 fine on a Dutch political party, PVV Overijssel, over its failure to report a data breach that happened in January 2019. The breach concerned an email sent by an employee of the party to 101 recipients who were described in the email as ‘friends of the PVV’. The email invited those recipients to a meeting. All email addresses were visible to all recipients and as a result the political views of the addressees were shared.