FAQ
No. Representation includes a documented handling procedure, named responsibles, and response commitments — the standard the EDPB expects, not a letterbox.
Non-EU controllers and processors caught by GDPR Art 3(2), non-EU online platforms under the DSA, and non-EU AI providers/deployers under the EU AI Act — unless an exemption applies.
No — you’re always in control. We log, keep you informed to your chosen SLA, and only respond as you direct, with escalation on anything urgent.
Yes. Kits and representation are independent products. Many buy kits first, appoint representation later.
Sometimes. When your situation needs more detail to make the documentation credible for you, we send a short questionnaire. It keeps the result specific instead of generic — most clients complete it in a few minutes.
No. We are a designated point of contact with a documented procedure: registered correspondence with regulators and data subjects, maintained records of processing (Art 30 GDPR), and active cooperation with supervisory authorities (Art 31 GDPR) — on your chosen response SLA, with escalation for anything urgent. The address is where Europe finds you; the procedure behind it is what makes it work.
A DPO is your internal, independent compliance advisor who helps your organisation live up to the GDPR. An EU representative is the external point that EU regulators and data subjects can address on behalf of a non-EU company — a foreign company’s foot in the EU, not its compliance department. Under EDPB guidelines the two roles cannot be combined; we keep them strictly separate.
No more than the law already provides. A representative is liable for its own direct obligations — records of processing and cooperation with supervisory authorities. Appointing a representative does not transfer your liability as controller or processor to us, and it does not shield you from it. We maintain documented procedures, professional indemnity insurance appropriate to the service is required under our service agreement (certificate of cover available on request), and our liability is transparently limited in the service agreement.
Sometimes the GDPR requires one, and sometimes it simply rewards one. You need one if you’re a public authority or body (except courts acting in their judicial capacity), or if your core activities are large-scale regular and systematic monitoring of people, or large-scale processing of sensitive or criminal data (Art 37(1)) — unless an exemption applies. We screen this with you honestly at onboarding; we won’t sell you a DPO you don’t need.
Yes — the GDPR explicitly allows engaging the DPO through a service contract with an outside body (Art 37(6)). The role carries the same statutory weight as an internal one, and at Zeno Kition it’s a named person, not a mailbox.
No. You remain responsible for your own compliance (Art 24(1)); the DPO advises, monitors and reports — it neither transfers nor assumes your obligations, and it is not personally answerable for your non-compliance. We are liable for our own failures in performing the service, capped at the fees you’ve actually paid, as set out in our agreement.