‘The GDPR does not establish a substitutive liability of the representative in place of the controller or processor it represents in the Union’ and ‘The possibility to hold a representative directly liable is however limited to its direct obligations referred to in articles 30 and 58.1 of the GDPR’
‘The designated representative should be subject to enforcement proceedings in the event of noncompliance by the controller or processor.’
‘The designation of a representative by the controller or processor shall be without prejudice to legal actions which could be initiated against the controller or the processor themselves.’