Skill v1.0.1
currentAutomated scan100/1005 files
version: "1.0.1" name: gdpr-eu-representative description: >- Guides appointment of GDPR Article 27 EU representative for non-EU controllers or processors. Covers criteria, responsibilities, and documentation. Activate when a non-EU entity processes EU data. Keywords: EU representative, Article 27, non-EU controller, territorial scope. license: Apache-2.0 metadata: author: mukul975 version: "1.0" domain: privacy subdomain: gdpr-compliance tags: "gdpr, eu-representative, article-27, non-eu-controller, territorial-scope, appointment"
Appointing EU Representative
Overview
Article 27 requires controllers or processors not established in the Union but subject to GDPR under Art. 3(2) to designate a representative in a Member State where affected data subjects are located.
Implementation Approach
Phase 1: Assessment
- Review current state against applicable GDPR articles.
- Identify gaps between current practices and requirements.
- Classify gaps by severity and regulatory risk.
- Document the assessment with evidence references.
Phase 2: Design
- Design measures to address identified gaps.
- Align measures with organisational capacity and risk appetite.
- Obtain DPO and stakeholder review of proposed measures.
- Create implementation timeline with milestones.
Phase 3: Implementation
- Execute the implementation plan according to priority.
- Document all measures implemented with evidence.
- Train relevant staff on new procedures and requirements.
- Validate implementation through testing or review.
Phase 4: Maintenance
- Schedule periodic reviews (minimum annual).
- Monitor for regulatory changes affecting the scope.
- Update measures in response to audit findings or incidents.
- Report on compliance status to the governance structure.