top of page
Five myths about the EU Data Rep role that puts US companies at risk
June 2026 'We're too small', 'we don't charge EU users', 'our vendor handles it': why these assumptions fail Intro Article 27 GDPR requires organisations without an EU establishment that offer goods or services to individuals in the EU, or monitor their behaviour, to appoint an EU Data Representative ('EU Data Rep.'). In our work with US companies, the obligation is rarely ignored deliberately. More often, it is missed because of a handful of persistent myths. Here are the fi

Rock Consultancy
Jun 292 min read
A reminder of the importance of vendor due diligence
2 October 2025 Yet another reminder from a supervisory authority of the importance of vendor due diligence. The Polish Supervisory Authority has fined both the data controller McDonald's and its processor 24/7 Communication for multiple GDPR infringements arising from a data breach of employee data. Of particular note: Obligations from legislation cannot be excluded by the Data Processing Agreement (DPA) The controller did not exercise proper supervision over the personal dat

Elaine Morrissey
Oct 2, 20251 min read
bottom of page