Back to Blog
GDPREU RepresentativeGlobal Privacy

Do Non-EU Companies Need a GDPR Representative?

By Robert Healey · June 9, 2026

Do non-EU companies need a GDPR representative

If your business is based in the US, UK, APAC or elsewhere outside the EU, the question is rarely theoretical: do non-EU companies need a GDPR representative, and if so, when does that obligation actually start? For many organisations, the trigger is not having a branch, staff office, or legal entity in Europe. It is whether their processing activities bring them within the territorial reach of the GDPR.

That distinction matters because Article 27 is often missed until procurement, due diligence, or a regulator asks for it. By that stage, the issue is no longer about reading the law. It is about closing an operational gap that can affect contracts, market entry, and overall compliance posture.

When do non-EU companies need a GDPR representative?

A non-EU company generally needs a GDPR representative when it is subject to the GDPR under Article 3(2) and does not have an establishment in the EU. In practical terms, that usually means the organisation is either offering goods or services to individuals in the EU, or monitoring the behaviour of individuals in the EU.

The first limb, offering goods or services, is broader than many teams expect. It is not limited to charging in euros or shipping physical products. A software provider onboarding EU-based users, a life sciences business recruiting EU participants into a programme, or a B2B platform clearly targeting EU markets may all be caught. The key issue is whether the business is directing its activities towards people in the EU, not whether it intended to create a formal EU presence.

The second limb, monitoring behaviour, often applies where businesses track users in a way that supports profiling, analytics, behavioural advertising, fraud prevention, geolocation analysis, or other forms of observation tied to individuals in the EU. This is especially relevant for technology businesses and organisations deploying AI systems that ingest behavioural or usage data from EU users.

If either of those limbs applies, and there is no EU establishment, the Article 27 representative requirement should be assessed immediately.

What Article 27 actually requires

An EU representative is not the same as a Data Protection Officer, and it is not a substitute for internal compliance ownership. The representative acts as a point of contact in the EU for supervisory authorities and data subjects on matters related to processing under the GDPR.

That sounds simple, but it carries operational consequences. The representative must be designated in writing. They need to be located in one of the EU Member States where the relevant data subjects are based. They must be in a position to receive regulatory correspondence and support communication linked to your GDPR obligations.

For enterprise organisations, this is less about a name on paper and more about control. If a regulator makes contact, if a customer requests evidence of compliance, or if a procurement team asks how your cross-border privacy obligations are managed, Article 27 representation needs to be backed by a workable process.

The main exemptions - and where businesses misread them

Not every non-EU organisation needs a representative. The GDPR provides a limited exemption where processing is occasional, does not include large-scale processing of special category or criminal offence data, and is unlikely to result in a risk to the rights and freedoms of natural persons.

That exemption is narrow. Many businesses rely on it too quickly.

The word occasional causes most of the confusion. If your organisation routinely collects employee data, customer data, user analytics, marketing data, support records, or vendor contact details involving people in the EU, the processing may be recurring rather than occasional. A SaaS company with ongoing EU user activity, a manufacturer with regular EU distributor contacts, or a global HR platform supporting EU staff data will often struggle to rely on the exemption.

Special category data raises the stakes further. Health data, biometric data, trade union membership data and similar categories can move an organisation out of the exemption analysis quickly, particularly in life sciences, health technology, insurance, and employment contexts.

Risk also needs a realistic reading. If the processing involves profiling, automated decision-making, large datasets, international transfers, or AI-supported analysis, it becomes harder to argue that there is no likely risk to individuals' rights and freedoms.

Do non-EU companies need a GDPR representative if they only sell B2B?

Sometimes yes. A pure B2B label does not automatically remove GDPR exposure.

The GDPR protects personal data relating to identified or identifiable individuals. In a B2B environment, that can include named contacts at client organisations, employee login details, business email addresses, usage data tied to individual users, and support records. If a non-EU company targets EU businesses and processes personal data about individuals within those client accounts, the territorial scope analysis still applies.

This is one of the most common boardroom misunderstandings. Senior teams assume that because they do not sell to consumers, the Article 27 requirement falls away. In many operating models, it does not.

How to tell whether your business is targeting the EU

This is where careful assessment matters. Accessibility alone is not usually enough. A website being visible in France or Germany does not, by itself, mean the business is offering goods or services there.

What regulators tend to look for is evidence of intention. That might include EU language and market targeting, pricing or contracting designed for EU customers, references to EU users, active sales outreach into EU territories, localised marketing, or support arrangements clearly aimed at EU-based individuals or organisations.

For larger organisations, the right question is not whether one isolated indicator exists. It is whether the commercial model, taken as a whole, is reaching into the EU market. Legal, privacy, sales, and operational teams often hold different parts of that picture. Bringing them together is usually the difference between a credible assessment and a weak assumption.

Representation is not the whole compliance answer

Appointing an EU representative does not solve the underlying GDPR obligations. If your organisation is caught by Article 3(2), you may also need to address transparency, lawful basis, contracts, international transfers, retention, security, data subject rights handling, records of processing, and impact assessments where required.

That is why representative services work best when they sit inside a broader operating model. A purely legal reading may identify the obligation, but it will not by itself create the workflows needed to support it. Equally, a tool without governance will not answer regulator queries or maintain accountability.

This is where execution matters. The most effective programmes combine legal interpretation, privacy governance, and technical operations. That three-team model is often what turns Article 27 from a reactive filing exercise into a controllable compliance function.

Common scenarios where Article 27 is triggered

A US software company selling subscriptions to EU-based teams, an APAC analytics provider tracking behaviour on EU websites, a UK business without an EU establishment marketing services into the EU, or a global AI vendor processing EU user prompts for model improvement may all need an EU representative.

The AI point deserves particular attention. As organisations scale AI-enabled products, they often expand data flows before updating privacy governance. If an AI service is used by individuals in the EU, or if EU personal data is ingested to train, test, monitor, or improve systems, GDPR territorial scope and representative requirements should be reviewed early. This is especially important where AI governance and privacy compliance need to operate together rather than in separate workstreams.

What a good Article 27 assessment looks like

A credible assessment is evidence-based and operational. It reviews where data subjects are located, what products or services are being offered, whether behaviour is being monitored, whether an EU establishment exists, what categories of personal data are involved, and whether any exemption could realistically apply.

It should also consider how the business would respond if challenged. Can it show why Article 27 does or does not apply? Can it identify who owns the decision internally? Can it demonstrate that representation, if required, is formally designated and supported by internal processes?

For growing organisations, this should not sit in a forgotten memo. It belongs within a broader privacy governance framework that can stand up to client diligence, regulator scrutiny, and international expansion.

The commercial reason to address it early

Many organisations first discover the representative requirement during a sales process, investor review, or compliance remediation project. That creates avoidable friction.

Addressing Article 27 early helps remove blockers later. It supports procurement confidence, strengthens market readiness, and reduces the risk of fragmented compliance decisions across legal, security, product, and commercial teams. For businesses operating across multiple jurisdictions, it also helps create a more disciplined structure for handling equivalent representation obligations elsewhere.

For that reason, mature organisations treat the question less as a narrow legal checkbox and more as part of cross-border operating control. Providers such as Formiti Data International are often engaged where businesses need not only a representative mandate, but also the surrounding implementation discipline across legal, privacy, and technical operations.

The practical test is simple: if your organisation is outside the EU but actively reaches EU individuals or monitors their behaviour, do not assume Article 27 is someone else's issue. Check the facts, document the position, and put the right structure in place before the market forces the question for you.

Related Services

Need help with AI governance or data privacy compliance?

Privacy-first website: We do not use tracking cookies, advertising pixels, or third-party analytics on this site. Read our Privacy Notice.