US SaaS · Appointment playbook

Appointing an EU Representative for a US SaaS Company

A US SaaS company should assess its EU establishment, territorial scope, and Article 27 exceptions before appointing a representative. Once the requirement is established, the work is to put a written mandate and a functioning EU contact route in place.

By The Data Protection OfficersReading time: 10 min
A cross-border contact route between a US software business and the European Union

Start with the company and the processing

Identify which legal entity contracts with customers and which entity determines each processing purpose. A SaaS provider can act as a processor for customer-hosted content and as a controller for billing, account administration, or its own marketing. Assess the relevant activities rather than assigning one label to everything the product does.

Then check establishment and territorial scope. An EU customer or EU hosting region does not by itself mean the US provider has an EU establishment. Conversely, an overseas corporate address does not settle whether stable arrangements in the Union amount to an establishment. Record the facts that support the analysis before moving to Article 27.

What evidence of an EU offering should you review?

Article 3(2) concerns relevant processing connected with offering goods or services to people in the Union or monitoring their behaviour there. Technical availability of a website is different from evidence of an intended EU offering. Free services can also be relevant; charging a subscription is not a prerequisite.

For a SaaS launch, review country-specific campaigns, the sign-up experience, sales materials, supported markets, customer terms, and the actual user journey. Treat analytics and profiling as a separate workstream: document what is observed, why, and how the resulting information is used. These facts are more useful than a simple question about whether the website can be opened from Europe.

Four SaaS scenarios to work through

These examples illustrate the questions to ask; they are not automatic legal conclusions or reports of customer engagements. The territorial assessment should use the full processing context, including the provider's role and the people affected.

Illustrative scenarioEvidence to examineAppointment question
A US platform actively launches subscriptions in France and GermanyCampaign targeting, supported countries, user terms, recurring account processingDoes Article 3(2) apply, and can any Article 27(2) exception actually be supported?
A US-only service receives an isolated unsolicited sign-up from EuropeSales geography, marketing intent, monitoring, and the actual processing contextTechnical access alone is insufficient; what other facts affect territorial scope?
A B2B platform hosts an EU customer's employee recordsController/processor roles, the relevant processing activities, contractual instructions, and targeting or monitoringAssess the provider's own territorial position; the customer's EU address does not settle it.
An existing EU business line expands into the UKUK-facing offer, UK establishment, processing, and applicable exceptionsDoes a separate UK representative assessment lead to a UK appointment?

Document the exception instead of assuming it

For the processing exception in Article 27(2)(a), the conditions must be considered together: the processing is occasional, does not include large-scale processing of the specified sensitive or criminal-offence data, and is unlikely to create a risk to individuals' rights and freedoms in the circumstances. There is also a separate exception for public authorities or bodies.

A small headcount, low revenue, or a business-to-business label is not a standalone Article 27 exemption. For a subscription product, document the recurrence of the processing rather than treating a small number of accounts as proof that it is occasional. Keep the reasoning and a trigger for reviewing it when the product, audience, or scale changes.

Choose a location connected to the affected users

Article 27 links the representative's establishment to a Member State where the relevant people are located. Prepare a country breakdown of the affected users and the processing that falls within the assessment. Explain why the chosen location fits those facts and how people elsewhere in the Union will use the contact route.

Do not treat the appointment as the creation of an EU establishment or automatic access to the GDPR one-stop-shop mechanism. The provider should explain the mandate, accessibility, and authority correspondence arrangements without suggesting that a postal address settles every cross-border regulatory question.

Put the written mandate and contact route in place

Confirm the appointing entity, representative identity, start arrangements, processing scope, and communication channels in writing. Agree who receives a request, how it reaches the US team, who tracks deadlines, and which person is authorised to approve a response. Check time-zone coverage and absence cover before relying on a single mailbox.

Keep formal representation separate from implementation work and from an external DPO appointment. A representative does not become the controller or take over all GDPR obligations. The EDPB considers the representative function incompatible with acting as external DPO for the same organisation, so any need for both must be addressed through distinct arrangements.

Prepare the appointment pack

Supply a concise record that another person can use without reconstructing your company from sales material. Link each document to the legal entity and service it describes. Use secure access and minimise personal information in the pack; a representative generally needs a description of processing rather than unrestricted access to all customer content.

  • Legal entity details and the written territorial-scope and exception assessment.
  • Description of the product, affected people, relevant countries, and controller/processor activities.
  • Current privacy notices and the proposed representative contact wording.
  • Processing records and a route for keeping relevant records available and current.
  • Named US decision owners, escalation contacts, and request-tracking procedures.
  • Relevant open correspondence or deadlines that must be handed over at the start.

What should happen after appointment?

Publish the representative information where the relevant privacy information is provided and keep it consistent across the applicable product notices. Tell support, legal, security, and management how the contact route works. An address that nobody inside the company recognises is not an effective operational handover.

Review the appointment when the legal entity, processing, countries served, or contact people change. Track correspondence through to a recorded outcome, rather than treating forwarding a message as the end of the process. The company's responsibilities for decisions and responses remain in place throughout the engagement.

Frequently asked questions

Does every US SaaS company need an EU representative?

No. Assess EU establishment, the relevant Article 3(2) processing, and Article 27(2) exceptions. The answer depends on the company's activities and facts.

Are B2B SaaS companies automatically exempt?

No. B2B is not a standalone exemption. Examine the processing of personal data and the provider's territorial position, including its controller and processor activities.

Is EU cloud hosting an EU representative?

No. Hosting location, establishment, and a written Article 27 representative appointment are separate questions.

Can the EU representative cover a UK appointment?

An EU appointment does not itself provide a UK representative. Assess UK scope and exceptions separately and establish the required UK arrangement where applicable.

Do we need to give the representative access to every customer record?

Do not assume unrestricted access is necessary. Agree the records, factual descriptions, contact route, and secure access required for the representative's duties, using appropriate data minimisation.

Keep researching

A practical next step

Make the next privacy decision clearer

Bring your organisation, processing, jurisdictions, current documents, internal owners, and deadline. We can help identify the right scope before an appointment or wider workstream begins.

This guide provides general information, not legal advice or a conclusion that a particular organisation is required to appoint a role. Final scope, responsibilities, capacity, and deliverables should be confirmed against the organisation's facts.

Sources: EUR-Lex: General Data Protection Regulation, EDPB: Guidelines 3/2018 on territorial scope

Choose the Right Data Protection Service

Compare the role and scope that fit the jurisdictions and processing activities that matter to your business.

Find the Right Data Protection Service in Minutes

Select your jurisdictions, compare annual pricing, and continue with the service that fits your scope.

View Data Protection Services