GDPR Article 27 for SaaS startups: a founder guide
Reviewed by our CNIL-designated DPO · 9 min read · Updated June 2026
If your SaaS product has even one EU user, GDPR Article 27 probably applies to you, no matter where your company is incorporated. Founders often assume this is a later-stage problem, something for when revenue arrives or the team grows. It is not. The obligation to appoint an EU representative is triggered by who your users are and what data you process, not by your headcount, your funding stage, or whether you have charged anyone yet. The good news: for an early SaaS startup this is a small, fixed, predictable task that you can fold into your compliance stack in an afternoon. This guide explains when the rule bites, why it is genuinely easy to handle early, and the few mistakes that turn an easy obligation into an expensive one.
When Article 27 actually applies to a SaaS startup
Article 27 requires any controller or processor not established in the EU to appoint an EU representative when its processing falls under GDPR's territorial scope. For SaaS, that scope is reached when you either offer your service to people in the EU or monitor their behaviour. Both are easy to trigger without noticing.
- Sign-ups, trials and waitlists from EU users, even free ones.
- Analytics, cookies, session recording or A/B testing on EU visitors, which counts as monitoring.
- A pricing page in euros or EU-targeted marketing.
- Processing on behalf of an EU customer, which can make you a processor in scope.
There is a narrow derogation for processing that is genuinely occasional, low-risk and free of large-scale special-category data. The EDPB reads occasional strictly, so a live SaaS product with recurring EU users almost never qualifies.
Why headcount is irrelevant and how to keep it cheap
A common founder misconception is that small companies are exempt. They are not. The 250-employee threshold in GDPR relates to the Article 30 records-of-processing exception, not to Article 27. The representative obligation is about your EU data subjects and the nature of your processing, so a two-person, pre-revenue startup with EU trial users is as much in scope as a 5,000-person enterprise.
This is also why the smart way to buy the service is to let pricing scale with EU data-subject volume, not with your team size or your global revenue. A seed-stage tool with a few hundred EU users should pay seed-stage prices.
- Match the plan to your actual EU footprint, then upgrade as it grows.
- Avoid contracts priced on headcount or company turnover.
- Insist on a real EU address, point of contact and registry handling, not just a mailbox.
Fitting it into your compliance stack and what to avoid
Treat the EU representative as one early, low-effort line item alongside the rest of your privacy basics. Appoint it once, publish the details, and it quietly does its job: receiving inquiries from EU users and supervisory authorities, and helping you keep your Article 30 records in order.
| Do early | Avoid |
| Appoint an EU representative once EU users appear | Waiting for revenue or a funding round |
| Name and address in your privacy policy | Appointing but hiding the details |
| Keep a simple processing record | Assuming the small-business exemption applies |
| Pick volume-based pricing | Confusing the representative with a DPO |
The representative is distinct from a Data Protection Officer and from any UK representative you may also need. Get the EU piece right first, and it scales cleanly as you grow toward NIS2 and AI Act obligations later.
FAQ
Do we need an EU representative before we make any money?
Yes, potentially. Article 27 is triggered by processing EU residents' personal data, not by revenue. If pre-revenue trial users, waitlist sign-ups or analytics involve people in the EU, the obligation can already apply. Being free or pre-launch does not exempt you.
We are a tiny team. Doesn't the small-business exemption cover us?
No. There is no headcount-based exemption from Article 27. The 250-employee figure people remember relates to record-keeping under Article 30, not to the representative requirement. A two-founder startup with EU users is in scope just like a large enterprise.
Is an EU representative the same as a DPO?
No. A DPO advises on and monitors your compliance internally and is required only in specific cases. An EU representative is a contact point in the EU for users and regulators when your company is established outside the EU. You may need one, both or neither depending on your situation.
Work with a real DPO
Appoint an EU representative backed by genuine, verifiable expertise.
Get my quote →