Last updated: August 2026
Case Study: AEPD Fines Tiger Media Over a GDPR Article 27 EU Representative Gap
In 2025, the Spanish Data Protection Agency (AEPD) confirmed sanctions against Tiger Media Inc. following an investigation into advertising-related data processing and the company’s compliance with the GDPR Article 27 EU representative requirement. This AEPD fine is a concrete reminder of a point many non-EU businesses underestimate: appointing an EU representative is not a formality buried in a privacy policy. It is an enforceable obligation, and Spanish data protection enforcement is prepared to act on it.
This article treats the decision as a 2025 enforcement example (not breaking news) and explains what went wrong, why the AEPD rejected Tiger Media’s representative arrangement, and what the EU representative requirement means in practice for other non-EU organisations.
What Happened in the Tiger Media Case
The AEPD investigated Tiger Media Inc., the operator of an advertising platform used by publishers and advertisers, after identifying potential data protection issues connected with personal data processed through advertising technologies. In its final resolution (AEPD proceeding PS/00480/2025), the AEPD confirmed two separate sanctions: €70,000 for an Article 6 GDPR issue and €50,000 for an Article 27 GDPR issue, bringing the total to €120,000 before reductions. Tiger Media applied the available reductions for recognition of responsibility and voluntary payment, bringing the final amount paid to €72,000.
The Article 6 element concerned the lawful basis for processing carried out through the advertising platform. The Article 27 element is the key lesson for privacy teams supporting non-EU organisations because it turns on governance rather than processing details: did the company actually have a representative in the EU, properly appointed?
Why the AEPD Considered the Representative Invalid
According to the AEPD’s findings, Tiger Media had identified a representative located in Northern Ireland and stated that it was in the process of appointing a replacement representative in an EU Member State. The AEPD concluded that, as a result, Tiger Media did not currently have a valid EU representative for GDPR purposes.
The distinction matters. A representative “in process” is not the same as a representative properly appointed in writing, established in the correct territory, and available to act as the EU-facing point of contact. The AEPD’s resolution also noted that Tiger Media offered adult advertising services on at least three Spanish websites, connecting the processing to individuals in Spain and supporting the territorial-scope analysis under Article 3(2) GDPR.
The company’s stated intention to appoint an EU-based representative did not prevent the finding. From a regulator’s perspective, that outcome is predictable: the Article 27 obligation applies once the processing falls within scope, not only once an investigation is underway.
The Article 27 EU Representative Requirement Is More Than a Contact Address
GDPR Article 27 applies, broadly, where a controller or processor has no establishment in the EU but is nonetheless subject to GDPR under Article 3(2) — typically because it offers goods or services to people in the EU or monitors their behaviour there. In those circumstances, the controller or processor must designate, in writing, a representative in the Union, unless a narrow exception applies.
The AEPD was explicit that a representative for a non-EU controller or processor is not simply a contact point. The role includes cooperation with supervisory authorities and support for accountability operations, and the AEPD noted that the absence of a properly appointed representative can affect the GDPR compliance system as a whole.
For a fuller explanation of the obligation, see GDPR Article 27 EU representative. For broader background, see EU data protection representative.
How the Advertising and Cookie Context Surfaced the Gap
Although the Article 27 finding is the central lesson, the wider investigation began with advertising-related processing. The AEPD reviewed the platform’s role in delivering and measuring advertisements and recorded categories of data including device details, operating system, browser information, IP address, website and referral URLs, clicks, impressions, IP-derived location, and cookie identifiers. The AEPD also identified cookies being installed without consent on websites using the platform.
This pattern is common in AEPD enforcement: an authority opens a review focused on cookies, consent, or lawful basis, and the review then expands into governance obligations — including whether the organisation has a valid EU representative in place.
Who Should Reassess Their EU Representative Position
Non-EU organisations should reassess their Article 27 position if they have no EU establishment but intentionally interact with people in the EU through websites, apps, subscriptions, SaaS platforms, marketplaces, advertising, analytics, or tracking technologies. The relevant question is not whether the company is “European” in branding terms, but whether its processing falls within GDPR’s territorial scope.
A review is particularly worthwhile if any of the following apply:
- Your website, app, or platform is available to users in Spain or other EU Member States and is not merely passively accessible.
- You target EU users through language, currency, marketing campaigns, shipping options, local domains, EU-focused onboarding, or sales activity.
- You monitor behaviour in the EU through cookies, pixels, device identifiers, analytics, advertising measurement, fraud detection, frequency capping, or similar technologies.
- You process EU personal data as a processor for clients, publishers, advertisers, or partners.
- Your privacy notice names a UK, Swiss, U.S., or other non-EU contact as if it were an EU Article 27 representative.
- Your organisation appointed a representative before Brexit or before a corporate restructure, and the appointment has not been checked since.
- You rely on the “occasional processing” exception without having documented why it genuinely applies.
The exception point deserves particular care. Article 27 does not apply in every case — there are exemptions, including for certain occasional processing that is unlikely to risk individuals’ rights and freedoms and does not involve large-scale special-category or criminal-offence data. But that exception should be applied deliberately and documented, not assumed by default.
A Practical Compliance Checklist After the Tiger Media Decision
The right response to this AEPD fine is not urgency for its own sake, but a focused compliance check. Article 27 gaps are usually straightforward to fix — and because representative details appear in public privacy notices, they can be spotted quickly by regulators, users, partners, or complainants.
- Map EU-facing processing activities. Identify where your organisation offers services to people in the EU or monitors behaviour in the EU.
- Confirm whether you have an EU establishment. If not, assess whether Article 3(2) brings the processing within GDPR’s territorial scope.
- Test any exemption carefully. If you believe Article 27 does not apply, record the reasoning and revisit it as the business model changes.
- Check the representative’s location. The representative must be established in the EU.
- Make the appointment in writing. Define scope, cooperation duties, and response workflows explicitly.
- Update public notices. Privacy notices should list accurate, current contact details and avoid outdated references.
- Align internal workflows. Support, legal, security, and privacy teams should know how to route EU data-subject or regulator communications.
- Keep records current. Records of processing, cookie documentation, lawful-basis assessments, and vendor files should match what the privacy notice states.
- Review after major changes. Recheck the appointment after Brexit-related changes, mergers, new product launches, market expansion, or new tracking technologies.
Not sure your current appointment would hold up under this analysis? DilicheckRep reviews EU representative arrangements against Article 27, checks the representative’s location and mandate, and flags gaps before a regulator does.
Get an Article 27 representation review from DilicheckRep →
What This AEPD Fine Signals About Regulator Expectations in Spain
The Tiger Media decision confirms that data protection enforcement in Spain covers both substantive processing issues and governance obligations. The AEPD did not treat the EU representative requirement as a minor technicality: it set the Article 27 sanction at €50,000 and ordered corrective measures, including that Tiger Media put a valid EU representative in place.
The resolution also makes clear that payment and recognition of responsibility do not remove the underlying obligation to fix the problem. The AEPD ordered Tiger Media to notify the agency, within three months of the resolution becoming firm and enforceable, of the adoption of the corrective measures described in the decision.
The Key Takeaway for Non-EU Businesses
The Tiger Media decision reframes Article 27 as a practical governance question: if your company is outside the EU but reaches or monitors people in the EU, who is your valid EU representative today — not who you plan to appoint, not who was listed years ago, and not a contact located outside the Union, but the representative properly appointed and able to act now.
Frequently Asked Questions
What is the GDPR Article 27 EU representative requirement? GDPR Article 27 requires controllers and processors with no establishment in the EU, but who are subject to GDPR under Article 3(2), to designate in writing a representative in the Union, unless a narrow exception applies.
How much was Tiger Media fined by the AEPD? The AEPD confirmed sanctions totaling €120,000 before reductions: €70,000 for an Article 6 GDPR issue and €50,000 for an Article 27 GDPR issue. After reductions for recognition of responsibility and voluntary payment, Tiger Media paid €72,000.
Why did the AEPD find Tiger Media’s EU representative invalid? Tiger Media’s listed representative was located in Northern Ireland, and the company stated it was in the process of appointing a representative in an EU Member State. The AEPD concluded this meant no valid EU representative was currently in place.
Which non-EU companies need to appoint an EU representative under GDPR? Non-EU companies that offer goods or services to people in the EU, or monitor their behaviour there, generally fall within GDPR’s territorial scope under Article 3(2) and must appoint an EU representative unless a documented exception applies.
DilicheckRep provides formal EU and UK regulatory representation — including GDPR Article 27, EU AI Act, Digital Services Act, Data Act, and NIS2 contact-point services — with mandate documentation and structured handling of authority and data subject communications.
Review your EU representation scope with DilicheckRep
Disclaimer: This guide is provided for general information purposes only and does not constitute legal advice. The application of EU data protection and other regulatory requirements depends on the specific circumstances of each organisation. You should obtain appropriate legal advice where necessary before relying on this information or making compliance decisions.
AI notice: This article was prepared by an expert with AI assistance.