Do I need an EU representative?
Reviewed by our CNIL-designated DPO · 4 min read · Updated June 2026
If your company is based outside the EU and you have anything to do with people in Europe, GDPR Article 27 may require you to appoint a local representative. Here's how to know — in plain English.
The short answer
If you (1) are not established in the EU, and (2) offer goods or services to people in the EU or monitor their behaviour, you almost certainly need an EU representative. Company size doesn't matter.
What counts as targeting the EU?
- 📦 Selling or shipping to customers in the EU
- 🌐 A website or app used by people in the EU
- 📊 Tracking EU visitors with analytics, ads or cookies
- ☁️ Offering a SaaS or online service accessible from the EU
The (narrow) exemption
Article 27 exempts processing that is occasional, does not include large-scale special-category data, and is unlikely to risk people's rights. In practice this exemption rarely applies to companies with ongoing EU users.
What to do next
Run our free 2-question check, then get an instant, itemized quote. We act as your representative — overseen by a Data Protection Officer designated with the CNIL.
FAQ
Does my company size matter?
No. Article 27 applies regardless of headcount or revenue — it's about whether you target or monitor people in the EU.
Is a representative the same as a DPO?
No — different roles. A representative is your local contact point in the EU; a DPO oversees your compliance programme. We can provide both.
What happens if I don't appoint one?
You're in breach of the GDPR and exposed to enforcement and fines; authorities have already acted against non-EU companies operating without a representative.
Work with a real DPO
Appoint an EU representative backed by genuine, verifiable expertise.
Take the free 2-question test →