Every privacy obligation, one desk.

One intake for every data-subject request, one register of what you process and who you share it with, and a named Article 27 representative on record for the authorities. Built for companies that owe Europe something and have no entity there.

What Privacy is

Three jobs that usually sit in three places.

01

The requests

A hosted intake on your own privacy page, identity verification, routing to the systems that hold the data, and a clock on every request from the day it lands.

02

The register

What you process and why, who you share it with, and the assessments behind the risky parts — the Article 30 record a supervisory authority asks for first.

03

The representative

A named Article 27 representative at an EU address, on your privacy notice and on record with every authority. The part of this you cannot do yourself from outside the EU.

Data-subject requests

A request arrives. The clock starts.

  1. It lands in one place

    From your privacy page, an email address, or the embedded SDK. Whichever regime it comes under, it arrives in the same inbox with the deadline that regime sets.

  2. The person is verified

    Identity checks before anything is disclosed, because handing someone else's data to an impostor is itself a breach.

  3. The systems are asked

    The request is routed to the systems that actually hold the data, each with its own task and its own record of what came back. On Pro that routing runs itself.

  4. It closes with a record

    An approval step before anything goes out, then a closed request with the full trail — what was asked, what was found, what was sent, and when.

What the register shows on a closed request
// Access request · GDPR Art. 15

Received    14 Mar · via privacy page
Verified    14 Mar · email + account match
Due         13 Apr (one month, Art. 12(3))

Systems     6 queried · 6 returned
            crm · billing · support
            product · analytics · backups

Approved    21 Mar · Elena Hoffmann
Sent        21 Mar · encrypted bundle
Closed      7 days before deadline
Every step timestamped. When an authority asks how you handled a request, the answer is a record rather than a reconstruction.
Beyond the GDPR

The same intake, whatever the regime.

A European request and a Californian one differ in what they are called, what they oblige and how long you have. They do not need two inboxes, two processes and two sets of evidence.

GDPR UK GDPR CCPA / CPRA VCDPA CPA CTDPA UCPA PIPEDA Law 25 LGPD APPI PDPA PIPL APP POPIA

Each regime brings its own request types and its own deadline. The intake applies the right one and the clock counts down accordingly. All fifteen are included in the fee — there is no per-regime charge.

The register

What a regulator asks for, already written.

Article 30

Records of processing

Every processing activity with its purpose, its lawful basis, the categories of people and data, who receives it and how long you keep it. The first document requested in almost every investigation.

Article 35

Impact assessments

DPIAs for the processing that needs one, kept against the activity they assess rather than in a folder nobody opens, so the assessment and the activity cannot drift apart.

Article 28

Sub-processors

The register of who else touches the data, with the agreement behind each one and a public list on your privacy page that updates when the register does.

Articles 44 to 49

Transfers and the data map

Where personal data physically goes and under which mechanism — adequacy, standard clauses, binding corporate rules or a derogation — drawn from the systems you have connected.

Article 27

The part you cannot do from outside.

Included in Privacy

A named EU representative, on record.

If you process the personal data of people in the EU and have no establishment there, Article 27 requires you to appoint a representative inside the Union. We become yours: a named entity at an EU address, published in your privacy notice, reachable by any supervisory authority and by any person whose data you hold.

Authority correspondence is handled for you and is never metered — a letter from a regulator is not a volume event.

Learn more about the Article 27 mandate →
MandateArticle 27 GDPR · signed
RepresentativeWorld Presence j.d.o.o.
AddressUlica Brune Bušića 42, 10000 Zagreb
PublishedYour privacy notice, Art. 13(1)(a)
CoversAll 27 member states
LettersHandled · never metered
Pricing

One monthly fee. All 27 member states.

The mandate, the intake and the register together, with 25 data-subject requests a month included. Open Usage to set your own volume and see what sits above it.

Privacy

GDPR representative under Article 27. Authority letters are always included, never metered.

$127/mo

Service fee

Start now

In the fee

  • Named Art. 27 representative on record
  • Coverage in all 27 EU member states
  • 25 data-subject requests a month included
  • Supervisory-authority letters, never metered
  • Request intake on your privacy page
  • All 15 privacy regimes, no per-regime charge
  • Records of processing for Article 30
  • DPIAs, sub-processors and the data map
  • DPA correspondence in 24 EU languages

This is on top of your platform plan, which starts at $0. See every price →

Common questions

What teams ask us first.

Is this the same thing as the GDPR representative?

The representative is part of it. Privacy is the product: the request intake, the register, the data map and the Article 27 mandate together. If all you need is the mandate itself, that is the piece described on the GDPR Representative page — but it is bought as Privacy either way.

What counts as a data-subject request?

One request from one person, whatever they ask for — access, erasure, correction, portability, objection. Twenty-five a month are included; above that each one is priced at its own tier. Correspondence with a supervisory authority is not a request and is never metered.

Do you need access to our systems?

Not to start. You can run requests by hand against the systems you list, and the record is the same. Connecting systems is what lets a request be routed and answered without someone chasing six teams, and it is what the Pro plan automates.

We already have a privacy tool. Can we keep it?

Yes, though the overlap is usually the point. What a privacy tool cannot do is be your representative: Article 27 requires an entity established in the Union, which is why companies outside it end up with a tool and a separate mandate. This is both.

Do we also need a Data Protection Officer?

Different role, different article. The representative is your point of contact inside the EU under Article 27; a DPO under Articles 37 to 39 is an independent officer who advises and monitors, and is required only for certain kinds of processing. Many companies need both, and Article 38(6) is why the same person should not be both.

What happens if we stop?

The mandate ends on 30 days' notice, and we tell the authorities it has. Until it does, you stay covered: an Article 27 representative cannot lapse quietly without leaving you in breach.

One desk for the whole obligation.

Thirty minutes to map what you process and where it sits. A named representative on record the moment you sign.