EU GDPR Compliance

GDPR Representative for US Companies: Do You Need One?

By The Data Protection Officers
Reading Time: 6 min
US SaaS company assessing an EU representative route with a privacy evidence map

Possibly. A United States SaaS company may need an EU Article 27 representative when it is not established in the Union, its processing falls within the GDPR's Article 3(2) territorial scope, and no Article 27(2) exception applies. The answer depends on the company's actual offering, targeting, monitoring, processing context, risk, and establishment facts. An Article 27 representative is also a different legal role from a Data Protection Officer under Article 37.

This guide was reviewed on 14 August 2026. It is general information, not legal advice. Read the official GDPR text and the EDPB territorial-scope guidance for the primary framework.

Applicable EU Law

The rules governing this requirement are found directly in the General Data Protection Regulation and related guidelines.

  • General Data Protection Regulation Article 3, Paragraph 2, Territorial Scope.
  • General Data Protection Regulation Article 27, Representatives of controllers or processors not established in the Union.
  • General Data Protection Regulation Article 83, General conditions for imposing administrative fines.
  • General Data Protection Regulation Recital 80, Designation of a representative.
  • European Data Protection Board Guidelines 3/2018 on the territorial scope of the regulation.

Under Article 3(2), the GDPR can apply to an organisation outside the Union when its processing is connected with offering goods or services to people in the Union or monitoring their behaviour. Whether a particular SaaS business is targeting people in the Union is fact-specific; a website being technically accessible from Europe is not, by itself, the complete analysis.

When Article 3(2) applies, Article 27 generally requires a controller or processor without a Union establishment to designate a representative in writing, unless an Article 27(2) exception applies. The representative is a local contact for supervisory authorities and data subjects. It is not a Data Protection Officer, does not replace one, and should not be described as an automatic requirement for every non-EU SaaS company.

The Occasional Processing Exemption Trap

Article 27(2) excludes processing that is occasional, does not include large-scale processing of special-category or criminal-conviction data, and is unlikely to create a risk to the rights and freedoms of individuals, taking the relevant context into account. Each condition and the underlying Article 3(2) scope should be documented rather than assumed.

Recurring accounts, regular customer support, ongoing analytics, or continuous service delivery may make an occasional-processing exception less likely, but none of those facts should be treated as an automatic legal conclusion in isolation. Review the nature, context, scope, purposes, data categories, regularity, and likely risks of the actual processing.

The Controller vs Processor Dynamic in Software Services

Article 27 can apply to both controllers and processors that are not established in the Union. The processor relationship therefore needs to be included in the assessment, but a customer contract or B2B model does not automatically decide whether the Article 3(2) and Article 27 conditions are met.

If you provide cloud infrastructure, customer-management, or human-resources software to European customers, you may process personal data on their behalf and may also act as a controller for your own business operations. Map both roles, the establishments involved, the people targeted or monitored, and the exceptions before deciding whether a representative is required. A European customer should not simply be assumed to be your Article 27 representative.

Furthermore, software companies may also act as controllers for their own direct marketing, website analytics, and internal business operations. Those activities should be assessed separately under Article 3 and Article 27; they do not automatically create a representative obligation merely because the company is a controller. Map each processing activity, its targeting or monitoring context, regularity, risk, and the Article 27(2) exceptions before drawing a conclusion.

Member State Considerations

The regulation requires the representative to be established in a Member State where the relevant data subjects are located. If people in several Member States are affected, assess where the representative can be established and remain accessible for the relevant supervisory and data-subject contacts. Do not choose a country solely because it is commercially convenient or because it has the highest website traffic.

Language, accessibility, legal-system familiarity, and operational capacity can inform the appointment, but they do not replace the location and scope requirements. The mandate, privacy notices, contact arrangements, and escalation process should all identify the representative clearly where Article 27 applies.

Risks of Non Compliance

Failing to meet an applicable Article 27 obligation can create regulatory, commercial, and operational risk. The consequences depend on the facts, the infringement, and the authority involved.

  • Regulatory exposure: GDPR Article 83 provides different administrative-fine bands for different infringements. The applicable category and amount depend on the facts and the authority's assessment.
  • Commercial friction: Customers and procurement teams may ask for a clear representative, privacy notice wording, mandate, and evidence that the relevant territorial-scope analysis has been completed.
  • Operational gaps: Without a named contact and documented process, regulator or data-subject enquiries may be delayed or routed inconsistently.

Practical Recommendations for Compliance

The Data Protection Officers recommend the following actionable steps for United States software companies expanding into the European market.

  1. Assess the Scope: Document establishments, offering and targeting evidence, monitoring activities, processing roles, data categories, regularity, risks, and the Article 27(2) exceptions.
  2. Appoint a Qualified Professional: Select a specialized privacy firm or legal entity located in the appropriate Member State. Do not use a simple mail forwarding service or a virtual office. The representative must understand the European legal framework, speak the local language, and be capable of communicating effectively with regulatory authorities.
  3. Draft a Written Mandate: Create a formal legal contract authorizing the representative to act on your behalf regarding data protection matters. This mandate must be available upon request by regulators.
  4. Update Privacy Documentation: Where Article 27 applies, list the representative's legal name and contact details in the relevant privacy information and keep the mandate and internal records aligned.
  5. Inform European Clients: Update your standard Data Processing Agreements. Including the details of your representative in your vendor compliance packets will smooth the procurement process and build trust with European security teams.

Notes and Frequently Asked Questions

What is the difference between an EU Representative and a Data Protection Officer?

An EU Article 27 representative is a local contact for certain controllers or processors not established in the Union when the GDPR territorial-scope rules apply, subject to the Article 27(2) exceptions. A Data Protection Officer is a separate independent oversight role assessed under Article 37. They serve different legal functions, and an organisation may need one, both, or neither.

Does business to business software trigger the requirement?

B2B status alone does not decide the question. Business contact details, employee accounts, communication logs, and individual user analytics can be personal data, but the representative obligation still requires an Article 3(2) and Article 27 applicability assessment.

What if we only use standard web analytics on our marketing site?

Analytics may be relevant to the Article 3(2) monitoring analysis, but it does not automatically trigger an Article 27 appointment. Review the purpose, targeting, regularity, data categories, risk, and Article 27(2) exceptions before deciding.

Can our existing United States legal counsel act as the representative?

A representative must be established in an EU Member State where the relevant data subjects are located. US counsel without an EU establishment cannot perform that representative role solely from the United States.

How do we choose the right Member State for the appointment?

Assess where the relevant data subjects are located and whether the proposed representative can remain accessible for the relevant supervisory and data-subject contacts. A single representative may be possible where the legal conditions are met; the country with the most website traffic is not an automatic answer.

What happens if we process data from both the European Union and the United Kingdom?

The EU GDPR and UK GDPR are separate regimes. If the representative rules apply in both jurisdictions, separate EU and UK arrangements may be needed. Assess each regime's territorial scope, exceptions, establishments, and contact requirements.

Are there any size thresholds for this rule?

There is no general revenue threshold that decides the Article 27 question. Applicability depends on territorial scope, the processing context, and the statutory exceptions, not company size alone.

Important Disclaimer: This is legal information, not formal legal advice. Local counsel should be consulted for jurisdiction-specific decisions.

To help you assess your specific operational status, The Data Protection Officers have provided an interactive compliance evaluation tool below.

Choose the Right Data Protection Service

Compare the role and scope that fit the jurisdictions and processing activities that matter to your business.

Find the Right Data Protection Service in Minutes

Select your jurisdictions, compare annual pricing, and continue with the service that fits your scope.

View Data Protection Services