It's not a consent problem. Even if you have consent, or some other legal justification for what you are doing with user data, users need to contact you if they want to exercise some of their GDPR rights such as the right to have their data deleted.
Article 27 is about requiring that you at least support one specific method of contact: a representative in the Union. It applies if your site is covered by GDPR and is not in the Union.
There's an exception for sites whose processing of personal data is occasional, does not include certain particularly sensitive kinds of data (e.g., genetic data, health data, criminal conviction records), and is unlikely to pose a risk to the rights and freedoms of natural persons.
There's some commentary here [1] about Article 27. It says that
> The aim of Article 27 GDPR is to ensure that the level of protection afforded to EU-based data subjects is not reduced where non-EU based controllers or processors process their data. It aims to both provide a contact point for data subjects and ensure that there is legal accountability for processing activities by mandating the appointment of a representative.
I see that page also has something to say about what "occasional" mean:
> The term "occasional" has been interpreted by the WP29 to mean processing that is not carried out regularly and that falls outside of the scope of the regular activities of the controller or processor. Similarly, Millard and Kamarinou have interpreted the term "occasional" to mean "non-systematic" processing, or in other words, processing that happens on an ad hoc and infrequent basis and not in a regular way
It sounds like automatically logging all visits to your web server in the Apache logs would not be "occasional".
Article 27 is about requiring that you at least support one specific method of contact: a representative in the Union. It applies if your site is covered by GDPR and is not in the Union.
There's an exception for sites whose processing of personal data is occasional, does not include certain particularly sensitive kinds of data (e.g., genetic data, health data, criminal conviction records), and is unlikely to pose a risk to the rights and freedoms of natural persons.
There's some commentary here [1] about Article 27. It says that
> The aim of Article 27 GDPR is to ensure that the level of protection afforded to EU-based data subjects is not reduced where non-EU based controllers or processors process their data. It aims to both provide a contact point for data subjects and ensure that there is legal accountability for processing activities by mandating the appointment of a representative.
I see that page also has something to say about what "occasional" mean:
> The term "occasional" has been interpreted by the WP29 to mean processing that is not carried out regularly and that falls outside of the scope of the regular activities of the controller or processor. Similarly, Millard and Kamarinou have interpreted the term "occasional" to mean "non-systematic" processing, or in other words, processing that happens on an ad hoc and infrequent basis and not in a regular way
It sounds like automatically logging all visits to your web server in the Apache logs would not be "occasional".
[1] https://gdprhub.eu/Article_27_GDPR