CHAPTER IV — CONTROLLER AND PROCESSOR
Article 27 — Representatives of controllers or processors not established in the Union
Official text
(1)Where Article 3 (2) applies, the controller or the processor shall designate in writing a representative in the Union.
(2)The obligation laid down in paragraph 1 of this Article shall not apply to:
(a)processing which is occasional, does not include, on a large scale, processing of special categories of data as referred to in Article 9 (1) or processing of personal data relating to criminal convictions and offences referred to in Article 10, and is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account the nature, context, scope and purposes of the processing; or
(b)a public authority or body.
(3)The representative shall be established in one of the Member States where the data subjects, whose personal data are processed in relation to the offering of goods or services to them, or whose behaviour is monitored, are.
(4)The representative shall be mandated by the controller or processor to be addressed in addition to or instead of the controller or the processor by, in particular, supervisory authorities and data subjects, on all issues related to processing, for the purposes of ensuring compliance with this Regulation.
(5)The designation of a representative by the controller or processor shall be without prejudice to legal actions which could be initiated against the controller or the processor themselves.
Commentary
1. The purpose of Article 27
Article 27 addresses one of the most practical difficulties created by the GDPR's extraterritorial application.
The GDPR can apply to organisations that have no establishment in the European Union. Article 3(2), for example, can bring a company established in India, the United States, Singapore, Australia or another third country within the GDPR where it offers goods or services to individuals in the Union or monitors their behaviour in the Union.
This creates an obvious enforcement problem.
Suppose an online platform based in India has millions of European users but no European office, employees or subsidiary. A French data subject wants to exercise a GDPR right. A German supervisory authority wants information about the company's processing. The European regulator should not have to rely entirely on an address thousands of kilometres away and an organisation with no physical presence in Europe.
Article 27 addresses this problem by requiring many non-EU organisations caught by Article 3(2) to appoint a representative in the Union.
The representative is therefore best understood as a local point of contact and regulatory bridge.
It does not bring the foreign organisation physically into Europe. It does not become the controller. It does not take over all of the controller's GDPR responsibilities. Instead, it makes the organisation accessible within the Union for matters concerning GDPR compliance.
The underlying policy is simple:
If the GDPR applies to a non-EU organisation because that organisation reaches into the European market or monitors individuals in Europe, the organisation should ordinarily have a meaningful point of contact within Europe.
Article 27 therefore connects two ideas:
extraterritorial application + practical accessibility.
2. Article 27 operates only when Article 3(2) applies
The first mistake in understanding Article 27 is to treat it as a general requirement for every company outside the EU.
It is not.
The starting point is Article 3(2).
Article 27 becomes relevant where a controller or processor that is not established in the Union is nevertheless subject to the GDPR because its processing falls within Article 3(2).
Article 3(2) broadly covers two situations:
-
offering goods or services to individuals in the Union; or
-
monitoring their behaviour where that behaviour takes place within the Union.
Therefore, the analysis should proceed in stages.
First ask:
Does the GDPR apply to this non-EU organisation under Article 3(2)?
Only after answering that question should one ask:
Does Article 27 require the organisation to appoint a representative?
This distinction is important because Article 27 is not itself the source of the GDPR's extraterritorial jurisdiction.
Article 3 establishes the territorial connection.
Article 27 deals with the consequences of that connection.
3. Article 27 is not triggered merely because European data are involved
Another important distinction is that the mere presence of EU personal data does not automatically trigger Article 27.
Consider an Indian company that processes the personal data of an Indian customer. The customer's data may later be stored on a server in Germany.
That fact alone does not mean that Article 27 applies.
Similarly, a non-EU company may process data belonging to a European citizen while that person is outside the Union. The nationality of the individual is not, by itself, the decisive factor.
Article 3(2) focuses on the relevant territorial connection, particularly the offering of goods or services to individuals in the Union or monitoring behaviour taking place in the Union.
This is why Article 27 should always be analysed together with Article 3.
A useful formula is:
==Non-EU establishment + Article 3(2) applicability + no Article 27 exemption = representative required.==
4. The representative is a bridge, not a substitute
The most useful way to understand the role is to think of the representative as a bridge between the foreign organisation and the European regulatory environment.
Imagine a US company with no European office.
Without Article 27:
EU data subject → US company
With Article 27:
EU data subject → EU representative → US company
The same applies to supervisory authorities.
EU supervisory authority → EU representative → foreign controller/processor
This makes communication considerably more practical.
However, the bridge metaphor should not be misunderstood.
The representative does not become the foreign company's substitute.
The foreign company remains the entity responsible for its own GDPR obligations.
If the controller violates Article 32 by failing to implement appropriate security measures, it cannot simply say:
"Our representative was responsible for GDPR compliance."
That is incorrect.
The representative exists to facilitate compliance and communication, not to absorb the controller's substantive obligations.
5. Why the obligation is particularly important for online businesses
Article 27 has become especially important because modern digital businesses can operate throughout Europe without establishing a physical office in Europe.
A company can be:
-
incorporated in India;
-
headquartered in Bengaluru;
-
hosted on infrastructure in Singapore;
-
have employees entirely outside Europe;
-
and nevertheless provide services to thousands of Europeans.
The traditional concept of territorial regulation based upon physical presence is therefore inadequate for digital markets.
Article 27 is part of the GDPR's response to that reality.
Example
Consider an Indian health and fitness application. It has no European subsidiary but:
- offers its application in Germany;
- accepts subscriptions from German residents;
- tracks users' activity;
- analyses exercise patterns;
- creates behavioural profiles.
The organisation may fall within Article 3(2).
Because the processing is continuous and potentially involves health-related information, relying on the Article 27 exemption would be difficult.
A representative may therefore be required.
The representative gives European users and regulators a recognisable point of contact even though the company itself has no establishment in Europe.
6. The written mandate is important
Article 27 requires the representative to be designated in writing.
This requirement is more than a procedural formality.
The written mandate establishes:
-
who the representative is;
-
who appointed it;
-
which organisation it represents;
-
what processing activities fall within the representation;
-
what authority the representative has;
-
what communications it is expected to handle.
The arrangement should therefore be capable of being demonstrated to a supervisory authority.
A vague commercial arrangement saying that a consultancy "provides GDPR support" is not necessarily enough.
There should be a clear legal mandate showing that the organisation has formally appointed the entity as its Article 27 representative.
This is particularly important during regulatory investigations.
A supervisory authority should be able to determine immediately:
Who is the representative?
Which organisation does it represent?
What is the scope of its mandate?
Can it receive regulatory communications?
Can it facilitate communication with the controller?
A properly documented mandate answers these questions.
7. Who can act as the representative?
The GDPR does not prescribe one particular professional category.
A representative could, depending on the circumstances, be:
-
a specialist privacy consultancy;
-
a law firm;
-
another professional services organisation;
-
a specialised compliance provider;
-
an appropriate individual or legal entity established in the Union.
The important issue is capability, not title.
Calling an organisation an "EU representative" does not make it an effective representative.
The representative should have sufficient organisational capacity to:
-
receive communications;
-
communicate with the controller or processor;
-
respond appropriately to data subjects;
-
interact with supervisory authorities;
-
access relevant compliance information;
-
facilitate regulatory cooperation.
A representative that simply receives mail and forwards it weeks later would undermine the purpose of Article 27.
8. Representative and DPO are fundamentally different
One of the most common conceptual errors is to treat the Article 27 representative as a DPO.
They are different legal functions.
The DPO is a specialised GDPR compliance role governed primarily by Articles 37 to 39.
The DPO advises, monitors compliance, raises awareness, provides advice regarding DPIAs and cooperates with supervisory authorities.
The Article 27 representative performs a different function.
Its primary role is to provide a European point of contact for the non-EU controller or processor and facilitate communications relating to GDPR compliance.
The distinction can be illustrated as follows:
| DPO | Article 27 Representative |
|---|---|
| Compliance and advisory function | Representation and contact function |
| Subject to specific independence requirements | Acts according to mandate |
| Advises the organisation | Represents the organisation externally |
| Monitors GDPR compliance | Facilitates communication and cooperation |
| Governed by Articles 37-39 | Governed principally by Article 27 |
This distinction matters because combining the two roles may create conflicts of interest.
The DPO is expected to operate independently in performing the DPO's statutory functions. The Article 27 representative, by contrast, acts under a mandate from the controller or processor.
They therefore serve different institutional purposes.
9. The representative must actually be capable of representing the organisation
The word "representative" should not be interpreted as merely meaning "contact person".
The representative must be capable of acting on behalf of the controller or processor in relation to GDPR obligations falling within the mandate.
Example
suppose a supervisory authority asks for information concerning:
-
categories of processing;
-
categories of data subjects;
-
retention periods;
-
recipients;
-
security measures;
-
processing locations.
The representative should be able to facilitate the provision of the relevant information.
This requires an effective communication structure between the representative and the foreign organisation.
The foreign controller cannot appoint a representative and then provide it with no information about its processing operations.
10. Article 27(2) contains important exemptions
The representative requirement is not absolute.
The GDPR recognises that imposing a permanent European representative on every small, occasional and low-risk processing activity would be disproportionate.
Article 27 therefore creates two exemptions.
The first relates to certain occasional, low-risk processing.
The second concerns public authorities or bodies.
The first exemption is particularly important because it is based on a combination of factors.
The processing must essentially be:
-
occasional;
-
not involve large-scale processing of special-category or criminal-offence data; and
-
unlikely to create a risk to individuals.
These requirements must be analysed together.
11. "Occasional" does not mean "small"
This distinction is extremely important.
A processing activity is not necessarily occasional merely because it involves a small number of individuals.
"Occasional" concerns the regularity and nature of the processing.
Suppose an American company receives five enquiries from Europeans over the course of a year.
That may potentially be occasional.
Now consider a company that has 500 European users and processes their data every day.
Although 500 may not be a huge number, the processing is systematic and forms part of the company's ordinary business.
It is therefore much harder to characterise it as occasional.
The correct question is not:
"How many people are involved?"
It is:
"Is this processing a regular and systematic part of the organisation's activities?"
12. Large-scale processing of sensitive data
The exemption also becomes unavailable where the relevant processing involves large-scale processing of Article 9 special-category data or Article 10 criminal-offence data.
Article 9 includes particularly sensitive information such as:
-
health data;
-
biometric data in relevant circumstances;
-
genetic data;
-
political opinions;
-
religious or philosophical beliefs;
-
trade-union membership;
-
information concerning sex life or sexual orientation.
The GDPR deliberately treats such information as presenting greater risks.
Example
Compare two businesses.
Business A
A foreign retailer occasionally receives the name and email address of a European customer.
Business B
A foreign healthcare platform continuously processes the medical information of hundreds of thousands of European users.
The second situation presents a very different regulatory risk.
The fact that the healthcare platform may have no European office does not make the underlying risks disappear.
Article 27 is designed precisely to ensure accessibility where such significant processing is brought within the GDPR.
13. The risk test is equally important
Even if processing is occasional and does not involve large-scale sensitive data, the exemption may still fail if the processing is likely to create risks to individuals.
This reflects the GDPR's broader risk-based philosophy.
Relevant risks may include:
-
identity theft;
-
fraud;
-
financial loss;
-
discrimination;
-
reputational damage;
-
loss of confidentiality;
-
unauthorised re-identification;
-
significant social or economic disadvantage.
Example
Suppose a foreign company conducts a one-time processing exercise involving 200 European individuals. The processing is genuinely occasional. But suppose the data contain detailed financial information and a security failure could expose individuals to serious fraud. The organisation should not automatically conclude that the Article 27 representative requirement is unnecessary merely because the processing occurs once. Thenature, context, scope and purposes of the processing matter.
14. Risk is not limited to cybersecurity
"Risk to rights and freedoms" is broader than the risk of hacking.
This is a very important conceptual point.
Risk could arise from:
-
discriminatory profiling;
-
intrusive behavioural monitoring;
-
unfair automated decision-making;
-
financial exploitation;
-
exposure of confidential information;
-
reputational harm;
-
identity theft.
Example
a company may have excellent cybersecurity but still engage in highly intrusive behavioural profiling.
The processing may therefore create risks even though there has never been a data breach.
Article 27's risk assessment must therefore be connected to the broader fundamental-rights orientation of the GDPR.
15. The exemptions should be assessed across the organisation's relevant processing
A company should not artificially divide its activities to avoid Article 27.
Suppose a foreign company conducts ten different processing activities involving European individuals.
Nine are low-risk.
One involves systematic monitoring of thousands of individuals and does not qualify for the exemption.
The company should not reason:
"Nine activities are exempt, so we do not need a representative."
The organisation must analyse the Article 3(2) processing activities as a whole and determine whether the representative requirement applies.
This prevents organisations from structuring their processing operations artificially to avoid the requirement.
16. Public authorities have a separate exemption
Article 27 also excludes public authorities or bodies from the representative requirement.
This reflects the special problems associated with exercising jurisdiction over foreign governmental institutions.
The GDPR is European legislation, but a foreign state's governmental authority occupies a different position from an ordinary commercial company.
Example
a foreign ministry, government department or other governmental body may fall within this exemption.
The exemption should not, however, be understood to mean that every organisation that performs some public function is automatically exempt.
The character of the organisation and the nature of the processing must be considered.
17. Where should the representative be established?
The representative must be established in a Member State where the relevant data subjects are located.
This requirement prevents a company from choosing an arbitrary location completely disconnected from its European processing activities.
Suppose a non-EU company processes personal data of individuals in:
-
Germany;
-
France;
-
Spain;
-
Italy.
The company may establish its representative in an appropriate Member State where the relevant data subjects are located.
Where a significant proportion of the affected individuals are concentrated in one Member State, locating the representative there is particularly sensible.
The practical objective is accessibility.
A representative should be reasonably accessible to the individuals and authorities who may need to contact it.
18. Accessibility matters more than merely having an EU address
This is an important practical lesson.
An organisation should not approach Article 27 as a box-ticking exercise:
"We have rented an address in Europe, therefore Article 27 is satisfied."
The representative must be genuinely capable of performing its role.
Consider a company that lists a representative's address in Brussels but:
-
provides no functioning contact mechanism;
-
does not forward data subject requests;
-
does not respond to regulators;
-
has no access to relevant information;
-
cannot communicate with the foreign controller.
Formally naming an entity is very different from creating an effective representation arrangement.
The GDPR is concerned with meaningful accessibility.
19. The representative can be contacted by data subjects
One of the most practical consequences of Article 27 is that European individuals can contact the representative concerning processing activities.
Suppose a Spanish user wants to know:
-
what data are held about them;
-
why their information is being processed;
-
how to exercise their rights;
-
where to send a GDPR request.
The representative can serve as a point through which the request is facilitated.
This is particularly valuable when the foreign controller is difficult for an individual to reach.
The representative therefore improves the practical accessibility of data subject rights.
But there is an important distinction:
Facilitating a right is not necessarily the same as being substantively responsible for deciding the request.
The underlying controller or processor remains responsible for complying with its GDPR obligations.
20. The representative can be contacted by supervisory authorities
The representative also provides a regulatory gateway.
A supervisory authority can contact the representative concerning the foreign organisation's processing.
The representative should be able to facilitate:
-
requests for information;
-
regulatory correspondence;
-
production of relevant documentation;
-
communication with the foreign organisation;
-
cooperation in compliance proceedings.
This is particularly important because GDPR enforcement cannot function effectively if foreign organisations remain practically inaccessible.
Article 27 therefore contributes directly to the GDPR's enforcement architecture.
21. The representative's mandate can be broader than merely receiving letters
Article 27 requires the representative to be mandated concerning "all issues related to processing" for the purpose of ensuring GDPR compliance.
This is deliberately broad.
The representative may therefore need to facilitate matters involving:
-
data subject requests;
-
privacy notices;
-
records of processing;
-
supervisory authority enquiries;
-
compliance documentation;
-
investigations;
-
communications concerning GDPR obligations.
The exact operational responsibilities should be clearly established in the mandate.
A strong contractual arrangement should therefore specify procedures for:
-
escalation;
-
regulatory correspondence;
-
data subject requests;
-
document preservation;
-
response timelines;
-
communication channels;
-
authority requests.
22. Article 27 and Article 30 records
Article 30 requires certain controllers and processors to maintain records of processing activities.
For a non-EU organisation using an Article 27 representative, those records become practically important.
The representative needs sufficient information to respond intelligently to regulatory communications.
Imagine a regulator asks:
"What categories of personal data does the company process concerning European users?"
If the representative has no access to the organisation's processing records, the entire purpose of Article 27 is undermined.
The controller or processor therefore needs an effective information-sharing system with its representative.
The representative is not necessarily the entity that determines or creates every piece of information in the records, but it should have access to what it needs to perform its mandated function.
23. Article 27 does not create an EU establishment
Another important distinction is between a representative and anestablishment.
Appointing an EU representative does not necessarily mean that the foreign company itself becomes established in the Union for purposes of Article 3(1).
The representative is a separate legal mechanism.
This distinction matters enormously.
A company cannot automatically conclude:
"Because we appointed a representative in France, we now have an establishment in France."
The representative requirement is designed precisely for organisations that remain established outside the Union.
Thus:
EU establishment andArticle 27 representation are conceptually different.
24. Article 27 does not transfer controller status
Likewise, appointing a representative does not automatically make the representative a controller.
Suppose an Indian company determines:
-
why personal data are collected;
-
what data are collected;
-
how they are used;
-
how long they are retained.
It remains the controller.
Its German representative does not become controller merely because it communicates with European individuals.
The legal role depends upon the actual functions and decision-making structure, not merely the label attached to the entity.
25. Article 27 and processors
The same principle applies to processors.
Suppose an American software company processes personal data for a non-EU controller and independently falls within Article 3(2).
It may itself need an Article 27 representative.
The analysis should not simply be:
"The controller has appointed a representative, so the processor does not need one."
The controller and processor must assess their own GDPR position.
If the processor independently falls within Article 3(2), Article 27 may apply to it as well.
This is particularly relevant in modern cloud, analytics, advertising and AI ecosystems where several organisations may participate in processing.
26. The representative should not be the same party where conflicts arise
The representative's role can create significant conflicts if the same organisation also performs another GDPR function for the controller or processor.
Example
combining representation with processor functions can create tension because the representative may have to facilitate regulatory scrutiny of the very processing for which it is itself acting as processor.
Similarly, combining the role with the DPO role can raise independence concerns.
The broader lesson is:
The structure of the representative arrangement must permit the representative to perform its obligations objectively and effectively.
The GDPR is not satisfied merely by assigning multiple labels to the same entity.
27. Article 27(5): The controller cannot hide behind the representative
This is perhaps the most important provision in the Article.
The appointment of a representative does not affect the controller's or processor's responsibility or liability.
Suppose:
Company X, based in Singapore, unlawfully processes European users' personal data.
It appoints:
Company Y, based in Germany, as its representative.
Company X cannot argue:
"The German representative is now legally responsible for everything."
No.
Company X remains responsible for its own GDPR compliance.
The representative is not a liability shield.
This principle ensures that Article 27 does not create an incentive for companies to outsource their GDPR obligations merely by appointing an EU intermediary.
28. Can enforcement nevertheless involve the representative?
Yes.
The representative can itself become involved in regulatory proceedings in connection with its own obligations and role.
This is why the representative must take the appointment seriously.
If the representative is required to cooperate with a supervisory authority and simply refuses to engage, its own conduct may become relevant to enforcement.
The possibility of enforcement against the representative reinforces the fact that Article 27 representation must be genuine.
It is not merely a name placed in a privacy policy.
29. The representative should have an effective operating model
For organisations subject to Article 27, good compliance practice should include a defined operating model.
For example:
Data subject request received
- Representative records request
- Identity/request information communicated appropriately
- Controller receives request
- Controller determines substantive response
- Representative facilitates communication where necessary
- Response provided within GDPR requirements
A similar model should exist for regulatory requests.
The foreign controller should therefore establish clear internal procedures before appointing a representative.
30. Example: Indian SaaS company
Consider an Indian SaaS company providing an employee-management platform to European businesses.
It has no EU office.
Its software processes:
-
employee names;
-
contact information;
-
employment information;
-
attendance information;
-
performance information.
The company actively markets the platform to European customers and processes the personal data of individuals in the EU.
If Article 3(2) applies to the company's activities, Article 27 must be considered.
The company cannot simply say:
"Our customers are European companies, but we are Indian, so GDPR does not apply."
Nor can it say:
"We have an EU customer, therefore Article 27 automatically applies."
Both statements are too simplistic.
The correct approach is to analyse the territorial scope first and then determine whether the representative requirement applies.
If Article 27 applies, the company should appoint an EU representative, establish a written mandate, disclose the representative appropriately and create an operational process for data subject and regulatory communications.
31. Example: foreign online marketplace
Consider a US online marketplace that sells products to individuals throughout Europe.
It:
-
accepts euro payments;
-
ships products to European consumers;
-
maintains customer accounts;
-
tracks purchasing behaviour;
-
conducts targeted advertising.
This is a classic situation in which Article 27 becomes highly relevant.
The organisation has a sustained commercial relationship with European individuals.
Its processing is not merely occasional.
A representative can provide an accessible European point of contact for customers and regulators.
But the US company remains responsible for its substantive GDPR compliance.
32. Example: one-off European enquiry
Now consider a small Australian business that has no European market and occasionally receives an enquiry from a person in Spain.
The business processes the individual's contact information solely to respond to that enquiry.
Depending on the circumstances, Article 3(2) may not even apply.
If Article 3(2) does apply, the organisation would then consider whether Article 27(2)(a) provides an exemption.
This illustrates why organisations should not jump directly from:
"European personal data"
to:
"We need an EU representative."
The territorial analysis comes first.
33. Article 27 is ultimately about accountability
The deeper principle behind Article 27 is accountability.
A regulatory framework is less effective if a regulated organisation can be reached only through a distant foreign office.
Article 27 therefore creates a practical accountability mechanism.
It says, in substance:
If your activities bring you within the GDPR even though you are established outside Europe, you may need to maintain a meaningful point of contact within Europe.
This strengthens:
-
transparency;
-
accessibility;
-
regulatory cooperation;
-
enforcement;
-
practical exercise of data subject rights.
34. The provision should not be treated as a mere formal requirement
One of the most important compliance lessons is that Article 27 should not be reduced to:
"Put the representative's name and address in the privacy policy."
That is only the visible part of the arrangement.
A functioning Article 27 programme requires:
-
a genuine written mandate;
-
a competent representative;
-
current processing information;
-
effective communication procedures;
-
procedures for data subject requests;
-
procedures for regulatory requests;
-
appropriate escalation mechanisms;
-
clear allocation of responsibilities;
-
adequate accessibility.
The difference is between nominal representation andeffective representation.
The former satisfies paperwork.
The latter serves the purpose of the GDPR.
35. A useful way to remember Article 27
Article 27 can be reduced to five questions.
Question 1: Does Article 3(2) apply?
If no, Article 27 generally does not arise.
Question 2: Does an exemption apply?
Consider occasional, low-risk processing and the public-authority exemption.
Question 3: Where should the representative be?
In an EU Member State where relevant data subjects are located.
Question 4: What does the representative do?
It provides an accessible point of contact for data subjects and supervisory authorities and facilitates GDPR compliance.
Question 5: Who remains responsible?
The controller or processor.
This produces the core formula:
Article 3(2) creates the territorial connection. Article 27 creates the European point of contact. Article 27(5) preserves the controller's or processor's responsibility.
36. Final assessment
Article 27 is best understood as an enforcement and accessibility mechanism attached to the GDPR's extraterritorial reach.
It recognises a basic reality of the digital economy: a company can serve European individuals without ever opening a European office.
The GDPR therefore cannot rely solely on physical establishment as the basis for accountability.
Article 27 responds by requiring qualifying non-EU controllers and processors to maintain an EU representative, subject to carefully defined exemptions.
But the representative should not be misunderstood.
It is not:
-
the new controller;
-
a substitute processor;
-
automatically the DPO;
-
a liability shield;
-
a mechanism for transferring GDPR responsibility.
It is principally a local representative and point of contact capable of facilitating communication between the foreign organisation, European data subjects and supervisory authorities.
The most important conceptual distinction is therefore:
The representative makes the foreign organisation accessible in the Union. It does not make the representative responsible for everything the foreign organisation does.
For compliance purposes, the strongest approach is to treat Article 27 as an operational obligation rather than a contractual formality. A foreign organisation should appoint a representative only after properly analysing Article 3(2), document the appointment, provide the representative with sufficient information and authority to perform its role, disclose the representative's details where required, and maintain a functioning process for handling data subject and supervisory authority communications.
In that sense, Article 27 performs a very specific function within the GDPR:
Article 3 asks whether the GDPR reaches the foreign organisation.
Article 27 asks how that organisation will remain practically reachable within Europe.
Article 27(5) makes clear that being reachable through a representative does not allow the organisation itself to escape responsibility.
That is the essential architecture of Article 27.