Skip to content
Placeholder image

IhrintelligenterGDPR-VertreterfürdieEU 

Zielen Sie auf den EU-Markt ab, geschützt durch die Dienstleistungen des EU-GDPR-Vertreters von Prighter. Art 27 Vertretungsdienst. Wir sind Ihre Datenschutzunterstützung der Stufe 1, die die Einhaltung von Artikel 27 der EU-DSGVO sicherstellt, Risiken mindert und Geschäftswert durch gestärktes Kundenvertrauen schafft. Betreiben Sie Ihr EU-Geschäft mit Vertrauen und Gelassenheit.

Von Kunden auf der ganzen Welt vertraut.

Benötigen Sie einen EU-GDPR-Vertreter? 

Machen Sie unseren fünfminütigen Selbsttest und finden Sie es heraus.Please provide the text that you would like me to translate into German. Wenn die DSGVO auf Ihr Unternehmen anwendbar ist. 

Was ist die Datenschutz-Grundverordnung der EU?

Die EU-Datenschutz-Grundverordnung (DSGVO) is one of the most comprehensive data protection laws in the world. wurde verabschiedettrat in Kraft Im Jahr 2018 eingeführt und ist seitdem zum weltweiten Goldstandard für den Datenschutz geworden. Sure, here is the text for translation: "Hello, how are you today? I hope you are doing well." inspiring Data protection Regulations around the world. 

 

Die GDPR hat eine extraterritoriale Reichweite, was bedeutet, dass sie auch für Organisationen außerhalb Europas gilt. Wenn ein Unternehmen keine Niederlassung in Europa hat, aber den EU-Markt anspricht oder EU-Datensubjekte überwacht.Sure, here is the text for translation: "Hello, how are you doing today? I hope you are having a great day so far." Es fällt in den Anwendungsbereich der DSGVO. Neben allen anderen Verpflichtungen gemäß der DSGVO sind solche Organisationen verpflichtet, einen Vertreter zu benennen, der in ihrem Namen als Empfänger für Behörden und betroffene Personen fungiert. 

 

Eines der Kernziele der DSGVO ist es, Einzelpersonen mehr Kontrolle darüber zu geben, wie ihre personenbezogenen Daten verarbeitet werden. Dies spiegelt sich in einer Vielzahl von Rechten der betroffenen Person wider, einschließlich des Rechts auf Zugang, Berichtigung, Löschung (das "Recht auf Vergessenwerden"), Einschränkung der Verarbeitung, Datenübertragbarkeit und Widerspruch. Organisationen müssen transparente Informationen zur Datenverarbeitung bereitstellen und auf diese Rechte prompt reagieren, in der Regel innerhalb eines Monats. 

 

Die DSGVO legt auch strenge Verpflichtungen für Organisationen fest, um sicherzustellen, dass Daten rechtmäßig, fair und sicher verarbeitet werden. Verantwortliche und Auftragsverarbeiter müssen geeignete technische und organisatorische Maßnahmen umsetzen, detaillierte Aufzeichnungen über Verarbeitungstätigkeiten führen und Datenschutz-Folgenabschätzungen (DPIAs) für risikoreiche Verarbeitungen durchführen. Die Bestellung eines Datenschutzbeauftragten (DSB) ist in bestimmten Fällen erforderlich, um die fortlaufende Einhaltung und Überwachung sicherzustellen. 

 

Ein wichtiger Aspekt der DSGVO-Konformität ist die Meldepflicht bei Datenschutzverletzungen. Organisationen müssen die zuständige Aufsichtsbehörde innerhalb von 72 Stunden nach Bekanntwerden einer Verletzung benachrichtigen, es sei denn, es ist unwahrscheinlich, dass dies ein Risiko für die Rechte und Freiheiten der betroffenen Personen darstellt. Wenn die Verletzung voraussichtlich ein hohes Risiko darstellt, müssen auch die betroffenen Personen informiert werden. Diese Verpflichtungen verdeutlichen den Fokus der DSGVO auf Rechenschaftspflicht, Transparenz und den Schutz der individuellen Privatsphäre. 

Mehr lesen

Compliance im Mittelpunkt

Erfüllen Sie Artikel 27, indem Sie Prighter als Ihren EU-GDPR-Vertreter ernennen. Die Ernennung ist ein sichtbarer Teil Ihrer Bemühungen zum Datenschutz und signalisiert Ihre GDPR-Bereitschaft gegenüber Kunden, Partnern und Regulierungsbehörden gleichermaßen. Vermeiden Sie Bußgelder und beseitigen Sie Zweifel hinsichtlich Ihrer GDPR-Konformität.

Featured image

Ihr zuverlässiger EU-Datenschutzbeauftragter

Wir nehmen die Verantwortung als Ihr EU-DSGVO-Vertreter ernst und stellen sicher, dass wir alle gesetzlichen und qualitativen Anforderungen durch einen hochwertigen Service erfüllen. Wählen Sie Prighter für eine zuverlässige und konforme EU-DSGVO-Vertretung.

Mehrere Standorte mit EU-weiter Abdeckung

Wir operieren in mehreren EU-Mitgliedstaaten und bieten Ihnen die Flexibilität, zu wählen, wo Sie Prighter als Ihren EU-GDPR-Vertreter ernennen möchten. Unser Team - zusammen mit unserem einzigartigen Netzwerk von Partnern - erstreckt sich auf alle wichtigen EU-Mitgliedstaaten und stellt sicher, dass immer ein Büro in der Nähe ist. Das bedeutet auch, dass Sie in allen wichtigen europäischen Sprachen kommunizieren können.

Einfache Einrichtung der Konformität

Compliance muss nicht kompliziert sein. Erhalten Sie alles, was Sie brauchen und noch viel mehr in Ihrem Prighter-Konto - von der Formulierung für Ihre Datenschutzrichtlinie bis hin zu Vorlagen für Verarbeitungstätigkeiten.

Beauftragte Kontaktperson

Unsere Rolle als Vertreter besteht darin, Ihr erster Ansprechpartner für alle mit der DSGVO zusammenhängenden Angelegenheiten zu sein. Wir sind Ihr Gesicht für alle Interessengruppen in der EU und interagieren in Ihrem Auftrag mit Datenschutzbehörden, betroffenen Personen und B2B-Kunden.

Featured image

Autoritätskommunikation und Fallmanagement

Wir sind Ihr vertrauenswürdiger Ansprechpartner für Datenschutzbehörden der EU, der sichere Kommunikationskanäle und Arbeitsbeziehungen aufrechterhält. Verlassen Sie sich auf unser Team von Fachleuten - unterstützt durch unser innovatives Fallmanagement-System - um mit den wichtigsten Situationen wie Untersuchungen oder Benachrichtigungen über Datenschutzverletzungen umzugehen.

Adressat für betroffene Personen

Prighter ist Ihr zuverlässiger Ansprechpartner für betroffene Personen und unterstützt alle wichtigen europäischen Sprachen. Für die Bearbeitung von Anfragen betroffener Personen stellen wir Ihnen unseren eigenen Privacy Rights Manager zur Verfügung, eine SaaS-Lösung zur Kanalisierung, Filterung, Strukturierung und Verwaltung von Anfragen. Verantwortlichkeit und Effizienz kombiniert.

Automatisierte Interaktionen

Wir nutzen unsere rechtliche Expertise, um intelligente Software zu entwickeln, die Ihnen hilft, Interaktionen mit Stakeholdern in der EU effizient und konform zu verwalten. Nutzen Sie unser Authority Case Management für regulatorische Angelegenheiten und den Privacy Rights Manager, um Datenschutzanfragen von Betroffenen zu vereinfachen - effizient, wirksam und vollständig konform.

Mehrwert durch Einhaltung schaffen

Die Bereitschaft zur DSGVO-Konformität kann sich positiv auf Ihren Stand im Markt auswirken. Präsentieren Sie sich als vertrauenswürdige Organisation, die sich mit der DSGVO auseinandersetzt, um Ihren Markenruf zu verbessern und das Vertrauen der Stakeholder zu stärken.

Featured image

Stärken Sie das Vertrauen in Ihre Marke.

Wir sind Ihr vertrauenswürdiger Ansprechpartner für Datenschutzbehörden der EU, der sichere Kommunikationskanäle und Arbeitsbeziehungen aufrechterhält. Verlassen Sie sich auf unser Team von Fachleuten - unterstützt durch unser innovatives Fallmanagement-System - um mit den wichtigsten Situationen wie Untersuchungen oder Benachrichtigungen bei Datenverletzungen umzugehen.

Das Trust Center - Ihr Schaufenster für Compliance

Zeigen Sie Ihre Einhaltung mit dem Trust Center und erhalten Sie Anerkennung von allen Beteiligten. Machen Sie das Trust Center zu Ihrem Schaufenster, indem Sie es anpassen und brandmarken. Wir überprüfen unsere Termine in Echtzeit und machen das Trust Center zum Zugangspunkt für jede Anfrage.

Steigern Sie die Effizienz.

Steigern Sie Ihre Effizienz mit einer leistungsstarken Compliance-SaaS-Lösung, die Workflows automatisiert, manuellen Aufwand reduziert und sicherstellt, dass Sie mit Vorschriften konform bleiben. Vom Umgang mit Datenanfragen betroffener Personen bis hin zur Bearbeitung von Behördeninteraktionen optimieren Sie jeden Schritt mit intelligenten, skalierbaren Tools - damit Sie sich auf das Wesentliche konzentrieren können.

Warten Sie, es gibt mehr.

Die DSGVO-Konformität ist keine Checkliste, sondern eine fortlaufende Anstrengung. Wir stellen Ihnen alles zur Verfügung, was Sie benötigen, um auf dem neuesten Stand zu bleiben und Ihr Datenschutz-Compliance-Projekt proaktiv zu verwalten.

Featured image

Maßgeschneiderte Dienstleistungen

Unsere Vertretungsdienstleistungen und SaaS-Lösungen werden von einem Team führender Branchenexperten unterstützt. Zusammen mit unseren Partnern stehen wir Ihnen während des gesamten Lebenszyklus Ihres Datenschutzprogramms zur Seite. Ein One-Stop-Shop für all Ihre Bedürfnisse.

Open-Source-Expertise

Wir sind bestrebt, unser Wissen mit Ihnen zu teilen und Sie über gesetzliche Änderungen, Rechtsprechung und behördliche Richtlinien auf dem Laufenden zu halten. Unsere Überwachungsbemühungen gehen über die DSGVO hinaus, um Sie auch mit Updates im Zusammenhang mit KI und Digital Governance zu versorgen.

Team von Experten

Unser Team von Experten vereint tiefgreifendes juristisches Wissen mit praktischer Erfahrung im Bereich Datenschutz und Compliance. Von erfahrenen Anwälten bis hin zu technikaffinen Compliance-Spezialisten bringen wir die richtigen Fähigkeiten zusammen, um Sie sicher durch komplexe Vorschriften zu führen. Verlassen Sie sich auf uns für praktische, zuverlässige Unterstützung, die auf die Bedürfnisse und Ambitionen Ihres Unternehmens zugeschnitten ist.

EU GDPR Representation icon

EU GDPR Representation

Kombinieren Sie zusätzliche Vertretungsdienste, um Rabatte von bis zu 40 % zu erhalten

Wählen Sie Ihre Größe:

Ergänzende Produkte hinzufügen:

Privacy Representation

3 products

Digital Governance

3 products

Privacy Software

2 products

€170/Monat
Jährlich abgerechnet €2,040
Sparen Sie €228 /Jahr

Preisaufschlüsselung:

EU GDPR Representation€170/Monat

Core Features

Representative for all EU Member States
Choose from Offices in multiple EU Member States
Qualified local team
Privacy Policy Wording on the Representation
Assisting and Maintaining the Records of Processing Activities(basic)
Translating from European Languages into English(automated)

Marketing Features

Compliance Batch for your website
Dedicated Trust Center
Compliance certificate

Authority Features

Point of contact for EU data protection authorities
Unlimited Authority Requests
Authority Case Manager(basic)
Data Breach Notification(basic)

Data Subject Features

Addressee for EU data subjects
Unlimited Data Subject Requests
Privacy Rights Manager (PRM)(EU PRM)

Processor Features

Addressee for EU B2B clients (relevant for processors)
Data Processing Agreement(basic)
Standard Contractual Clauses (SCC) and International Data Transfer(basic)

Knowledge

Knowledgehub Access
Regulatory Monitoring
GDPR Training

Subscription

Entities and Brands Covered(5)
Digital Governance management suite(5 seats)
Support Level(basic)

How It works

Was unsere Kunden sagen

Wir arbeiten mit Organisationen auf der ganzen Welt zusammen, um eine robuste Einhaltung sicherzustellen. Hier ist, was einige unserer geschätzten Kunden über ihre Erfahrungen mit Prighter zu sagen haben.

Joannah Bodden Small

Prighter has provided the answer we were looking for in terms of EU and UK GDPR representation. Their team has given excellent assistance on a range of issues, not to mention being incredibly responsive and understanding of our needs as a start-up developing a mobile app. Their commitment to continual evolution is commendable in this complex market and their industry updates and webinars are always engaging and useful. Prighter gives us peace of mind and saves us time and we couldn’t be happier with this reliable partnership.

Joannah Bodden Small
Founder and CEO at Caraleya

Resource Center

Our Resource Centre is designed to help businesses around the world to understand and navigate international privacy, AI, and digital governance compliance. Whether you're new to compliance, or you're an experienced privacy professional, you'll find helpful tips, fresh insights, and practical resources to help you level-up your approach to compliance.

Visit the full Resource Center

Showing articles for: EU GDPR

Showing 1-15 of 80 results

Frequently Asked Questions on PrighterGDPR-Rep

Does our company need an Art. 27 GDPR representative in the EU?

Which companies need an EU representative?

Companies established outside the EU are required to appoint an EU representative according to Art. 27 of GDPR if they:

  • offer goods and services to individuals in the EU (e.g. providing a website in an EU language, offering payments in EUR) or
  • monitor their behaviour (e.g. cookie profiling).

According to the Guideline 3/2018 of the European Data Protection Board (EDPB) on the territorial scope of GDPR, this applies to both controllers and processors. For processors not established in the European Union the applicability of GDPR depends on what the “processing activities” are related to. If the data processing conducted for the controller is related to the offering of goods and services or to the monitoring of behaviour, GDPR applies to the processor in addition to the controller.

Case 1: Online Gaming: You are an online gaming company located outside the EU and offer your games to data subjects in the EU free of charge. When using your games you analyse the data subjects' geolocation data, web-browser data and history and show ads based on this data. As you target the EU market by offering your games and monitoring the users' behaviour you are legally required to appoint a GDPR Representative physically established in an EU member state to remain compliant. Violations of the EU GDPR can lead to substantial fines by authorities and exclusion from business activities in the EU.

Case 2: B2B SaaS: You develop CRM software and offer it as a SaaS product to companies, which are either targeting the EU without an establishment or which are located in the EU. Because your business clients are targeting EU data subjects and your CRM software product is processing and storing their data, you are also required to appoint a GDPR Representative physically established in an EU member state. It is likely that your business clients in the EU will also require you to appoint a representative and enter into a data processing agreement. You can establish trust by already being GDPR compliant during the negotiation phase with your business clients.

Are there any exemptions from the obligation to appoint an EU representative?

According to Art. 27 GDPR, controllers or processors are exempted from the regulation if ALL of the following criteria are met:

  • personal data is only processed occasionally, which is only from time to time and non-systematic; AND
  • data processing does not include large-scale processing of special categories of personal data or personal data relating to criminal convictions and offences; AND
  • data processing is unlikely to result in a risk to the rights and freedoms of data subjects. It is hard to meet ALL of these criteria, in particular the criterion of processing data only occasionally proves to be a big hurdle for most businesses.

Does my company offer goods and services to individuals in the EU?

Your company's intention to establish commercial relations with EU customers needs to have manifested in a business activity. The mere accessibility of a website in the EU, a mention on the website of an e-mail or geographical address, or of a telephone number without an international code, does not, of itself, provide sufficient evidence to demonstrate the intention to offer goods or services to EU customers. The European Data Protection Board listed the factors to be taken into account when assessing if goods and services are offered in its Guideline 3/2018 on the territorial scope of GDPR. Some of those factors are:

  • using languages of EU Member States, or offering payments in a currency of an EU Member State;
  • using Google or Facebook ads to address the EU market, or any other marketing activity directed towards EU customers;
  • mentioning EU references or testimonials;
  • the activity at hand being of an international nature, such as certain tourist activities;
  • mentioning dedicated addresses or phone numbers to be reached from an EU country;
  • use of EU top-level domains;
  • description of travel instructions from one or more other EU Member States to the place
where the service is provided;
  • offering the delivery of goods to EU Member States;

In a nutshell, if your company has any outbound activity in the EU or if your company enables or guides EU customers to find your company's product, GDPR is likely to apply.

Case 1: A website, based and managed in Turkey, offers services for creating, editing, printing, and shipping personalised family photo albums. The website is available in English, French, Dutch, and German, and payments can be made in euros or sterling. The website indicates that photo albums can only be delivered by mail in the UK, France, Benelux, and Germany.

Case 2: A Swiss University offers summer courses in international relations and specifically advertises this offer in German and Austrian universities in order to maximise the courses’ attendance. In this case, there is a clear intention from the Swiss University to offer such services to data subjects who are in the European Union, and GDPR will apply to the related processing activities.

Does my company monitor the behaviour of EU data subjects?

Not all online collection or analysis of personal data of individuals in the EU counts automatically as “monitoring”. Monitoring the behaviour of EU data subjects implies an intention to collect data for a specific purpose. Therefore, any kind of tracking of natural persons on the Internet, including the potential subsequent use of profiling techniques qualifies as 'monitoring'. Again, the EDPB gives some more guidance in the Guidelines 03/2018. According to the EDPB, monitoring may not only take place on the Internet but also through wearables and other smart devices. Monitoring activities include:

  • Behavioural advertisement
  • Geo-localisation activities, in particular for marketing purposes
  • Online tracking using cookies or other tracking techniques such as fingerprinting
  • Personalised diet and health analytics services online
  • CCTV
  • Market surveys and other behavioural studies based on individual profiles
  • Monitoring or regular reporting on an individual’s health status

Case 1: A marketing company established in the US provides advice on retail layout to a shopping centre in France, based on an analysis of customers’ movements throughout the centre collected through Wi-Fi tracking.

Case 2: An app developer is established in Canada with no establishment in the EU. I uses a processor established in the US for optimisation and maintenance of the app, however it also monitors the behaviour of data subjects in the EU. The developer is therefore subject to GDPR, as per Art. 3(2)b.

What fine may be imposed for non-compliance?

The GDPR extends its 'territorial scope' to controllers and processors that have their registered office in a country outside of the EU. As a result, high penalties of up to €10 million or 2% of the worldwide annual turnover can apply if a processor or a controller does not comply with the obligation of appointing an EU representative. The penalties may be enforced by individual claims or by authorities. Furthermore, your partners in the EU may be obliged to stop transferring data to your company.

What should I look for in an Art 27 representative? And what is Prighter’s approach?

What are the responsibilities of the representative?

The representative shall act as an addressee for authorities and data subjects to facilitate the communication with processors and controllers outside the EU. The representative needs to be mandated in writing by the controller or processor to evidence the appointment. In addition, the representative shall, maintain Art 30 records of processing activities and shall make the record available to the supervisory authority on request.

How has Prighter's business model been designed to meet these requirements?

  • To facilitate communication, Prighter established a network of offices all over Europe and developed high-end tech solutions for communication with both authorities and data subjects;
  • A written appointment is part of the onboarding flow. Clients can sign a Power of Attorney directly online in an end-to-end digital process; and
  • We assist clients in the drafting of records of processing activities by providing pre-filled templates along with extensive support and guidance.

Where should a representative be located?

First of all, the EDPB clarifies in its Guideline 03/2018 on territorial scope that only one representative needs to be appointed in an EU Member State, which can then serve for all other Member States. In the event that a significant proportion of the customer base is in one particular Member State it is best practice that the representative is established in this Member State. In any case, the representative will be easily accessible for data subjects in all Member States no matter where the representative is located.

How does Prighter approach these requirements?

  • Prighter has offices and partner offices in all major EU Member States, this keeps you compliant and provides you with a local and easily accessible representative for all your customers, no matter where they are located; and
  • Prighter is not a PO box, we have real privacy professionals in every location.

What is Prighter's approach to EU GDPR representation?

Our goal is to enable non-European companies to comply with GDPR through a combination of legal expertise and technology solutions. We put the practical insights we gain as a law firm (due to our role as the appointed Data Protection Officer for major banks, financial service providers, tech companies) into the development of our tools which easily handle Data Subject Requests (DSR) and data breaches, and into the management of records of processing activities. We support you in all privacy related matters, but above all we support you in growing your business by enabling you to improve customer trust by handling privacy matters in an efficient, compliant and professional way.

What do I get by appointing Prighter as my EU GDPR Representative?

The core of our service is representation according to Art. 27 GDPR. Around this requirement we have built features, services and tools which enable you to leverage your compliance in order to increase efficiency and gain the trust of your customers and partners. For more information on the services offered visit “GDPR-Rep Services”:

  • GDPR Representation:

By subscribing to the EU GDPR Representation Program, you appoint Prighter as your EU GDPR Representative. Our qualified team of lawyers and privacy professionals is your first line of defence to deal with requests from data subjects and data protection supervisory authorities (SA).

  • Gain Trust:

We provide you with a Compliance Landing Page that you can customise for your brand, display your privacy and security related certificates, and your privacy and cookie policies. This is your window into the world of privacy-related matters which helps you increase customer trust and confidence by demonstrating your privacy regulations compliance. The Compliance Landing Page also serves as an access point for privacy related requests which you can then easily manage with your GDPR Privacy Software tools.

  • GDPR Privacy Software Tools:

We have built a unique, specialised tool to manage the lifecycle of any data subject requests (DSRs) from existing or potential clients. This saves you time, internal resources, and money, and reduces your compliance risk substantially. When it comes to supervising authorities, we cover all of their standard requests (e.g. requests to submit records of processing activities). Additionally, we offer you a data breach tool that gives you access to our services in any critical situation which involves your data being compromised.

How does Prighter handle requests from data subjects and data protection authorities?

This is where our innovation comes into play. We built the Data Subject Request (DSR) management tool to channel, structure and filter all incoming privacy requests from clients and authorities. You can handle requests from millions of data subjects in one tool with the help of our proprietary AI technology. We cover and support all aspects of the formal handling of DSRs including communication with data subjects. What actually needs to be done in your database (e.g. delete a data subject), is always your own decision. The DSR tool is designed to manage the lifecycle of a data subject request to get all formal aspects right and offer you a framework of advice. Find more information on this tool here: Visit PrighterDSR 

What is the difference between a DPO and an EU GDPR representative?

When do I need a DPO and when do I need a representative?

You are obliged to appoint a data protection officer (DPO) if your company meets one of the following three criteria:

  • the processing is carried out by a public authority or body (except for courts acting in their judicial capacity);
  • the core activities of your company consist of processing operations which, by virtue of their nature, their scope and/or their purpose, require regular and systematic monitoring of data subjects on a large scale; or
  • the core activities of your company consist of processing on a large scale of special categories of data pursuant to Art. 9 and personal data relating to criminal convictions and offences referred to in Art. 10.

More information regarding how the criteria are interpreted is outlined in the Guideline of the Art. 29 Working Party on Data Protection Officers. In comparison to the requirements for appointing a DPO, a GDPR representative is needed in case of offering goods and services or monitoring EU data subjects. In a nutshell, the criteria for the requirement of a DPO reflect a higher risk involved with certain processing activities, whereas the requirements for an EU GDPR representative are triggered when your company’s processing of personal data of individuals located in the EU is noticeable.

What is the position of a DPO compared to an EU GDPR representative?

A Data Protection Officer (DPO) shall be involved in all issues related to the protection of personal data in a company. The role of a DPO is also to monitor the company’s compliance with GDPR, assist in data protection impact assessments, and to advise the management on privacy by design and privacy by default as well as all other privacy related matters. Hence, a DPO needs to be close to the company and needs to be involved in the day-to-day business. Whenever possible, the DPO shall be located in the region of the company’s headquarters. In comparison, the EU GDPR Representative is by nature operating at a distance when representing the company due to the lack of an establishment in the EU. The representative is therefore a substitution for a subsidiary, branch, or other establishment.

Can a DPO also be an EU GDPR representative or vice versa?

No, there is a conflict of interest between the roles of DPO and GDPR representative. The EDPB states in its Guidelines 03/2018 on the territorial scope that there is a possible conflict of obligation and interests in cases of enforcement proceedings. The EDPB does not consider the function of a representative in the EU to be compatible with the role of data processor for the same company, in particular when it comes to compliance with the respective responsibilities and compliance of a DPO and a representative.

How can our company appoint Prighter as our EU GDPR representative?

What is the process of appointing Prighter as our EU GDPR representative?

The onboarding process is simple and can be completed in a couple of minutes.

  1. We grant your company a free 14-day trial to keep the appointment completely risk-free.
  2. Choose a plan. The available plans depend on your company's size. The size of the company is defined according to the Eurostat categories which measure it by the number of people employed. 'Employees' in this definition includes part-time workers and freelancers.
  3. Enter your company's details.
  4. After registering, download the Power of Attorney (PoA). A signed PoA is required as evidence of the appointment of Prighter as your representative in case of requests from supervisory authorities. We kindly ask you to sign and upload your PoA.
  5. Our team will check and verify the provided information about your company and the PoA. This is usually done within a couple of hours.
  6. After the PoA has been approved, your company has successfully appointed Prighter as your Art. 27 GDPR representative for the whole EU. You can log in to your client area where you can find templates and information on what can be included in your homepage and privacy policy.
  7. Your risk-free 14-day trial period starts now.

Are we required to notify a data protection authority of our appointment of Prighter?

Contrary to the appointment of a DPO, you don't need to notify a data protection authority of the representation. If a data protection authority has an inquiry about a company, they take the necessary information from the company's privacy policy. However, please note that you will need to notify the relevant authority that you have appointed Prighter as your NIS representative.

We are a group of companies. Do you offer special options for groups?

Every separate entity requires representation according to Art. 27 GDPR. Nevertheless, Prighter offers your group the option to sign up for a group package to manage the representation of your affiliates through one main account, with sub-accounts for every affiliate. You will be required to internally select a centralised point of data protection management for the group to handle both the main account and the sub-accounts with one centralised login. The number of affiliates covered depends on the package you sign up for. The "small enterprise" package includes two affiliates, the "medium enterprise" package includes up to five affiliates, and the "large enterprise' package includes an unlimited number of affiliates. All included group entities must operate in the same industry, offer the same range of products, and have the same or a linked brand.

What does the service cost and what are the payment options?

Subscription pricing is based on your company size according to official Eurostat categories and the number of entities to be covered, starting from €39 per month. We offer a 14-day trial period on all subscriptions so that you can get to know our service before subscribing. Our pricing is transparent and there are no hidden costs as we do not charge per request from data subjects. You can choose between monthly, quarterly, or yearly payments. Your company gets a discount for quarterly payments and an even higher discount for the yearly payments option. Furthermore, you can choose between paying with credit card or via bank transfer. We accept almost all credit cards. Bank transfers are accepted in EUR, USD and GBP for annual payments. Please contact our support team should you have any further questions.