top of page
Five myths about the EU Data Rep role that puts US companies at risk
June 2026 'We're too small', 'we don't charge EU users', 'our vendor handles it': why these assumptions fail Intro Article 27 GDPR requires organisations without an EU establishment that offer goods or services to individuals in the EU, or monitor their behaviour, to appoint an EU Data Representative ('EU Data Rep.'). In our work with US companies, the obligation is rarely ignored deliberately. More often, it is missed because of a handful of persistent myths. Here are the fi

Rock Consultancy
Jun 292 min read
Greek Supervisory Authority imposes fines on controller and processor arising from same incident
11 September 2025 Noteworthy decision from the Greek Supervisory authority who fined both the data controller and data processor arising from the same incident. The controller was found to have infringed its obligations to select a suitable data processor and supervise them effectively. This case highlights the need for a robust vendor managements programme from onboarding assessments to contracts and DPAs and ongoing due diligence. See EDPB for further details: https://www.e

Elaine Morrissey
Sep 11, 20251 min read
bottom of page