An Australian company with no EU establishment that offers goods or services to people in the EU, or monitors their behavior, is caught by GDPR Article 3(2) and has to appoint an EU representative under Article 27. Engage Compliance acts as that EU representative, established in the EU and named in your privacy notice. Australia’s own Privacy Act reaches foreign conduct in a very different way, straight through to the organization with no appointed local stand-in, so it is easy to assume Australian law has this covered when it does not touch the EU obligation at all.
Key takeaways
- GDPR Article 27 applies to Australian companies with no EU establishment that offer goods or services to, or monitor the behavior of, people in the EU. The exemption is narrow and a store or app that runs on EU users rarely qualifies.
- The Privacy Act 1988 uses pure extraterritorial reach through the section 5B Australian link. It binds overseas organizations directly and appoints no local representative, the opposite design to Article 27.
- The section 6D small-business exemption can put a smaller Australian company outside its own Privacy Act, but it has no effect on the EU obligation, which carries no turnover threshold.
- Most Australian companies caught by the EU obligation are also caught by the separate UK one, and the two are appointed independently.
- We act as your EU representative directly from Amsterdam, and where you also need a DPO we keep the two roles with separate entities on the European Data Protection Board’s own reasoning.
How does an Australian company get caught by GDPR?
GDPR reaches beyond the EU through Article 3(2). A company with no EU establishment is inside the Regulation when its processing relates to either offering goods or services to people who are in the EU, whether or not payment is required, or monitoring their behavior as far as that behavior happens in the EU.
An Australian online retailer or exporter shipping to EU customers, a travel or tourism operator taking bookings from people in the EU, or a SaaS and app business running analytics on EU users all fit the test. These are the ordinary shape of an Australian business that has grown into the EU market without opening an EU office, and each one triggers Article 27.
Does Australian privacy law require an EU representative?
No, and the reason is worth spelling out because Australia’s design is the reverse of the EU’s. The Privacy Act 1988 (Cth) and its 13 Australian Privacy Principles bind “APP entities”. Section 5B, the “Australian link” provision, extends the Act to acts done outside Australia by an organization with an Australian link, such as being incorporated or formed in Australia, or carrying on business in Australia. Since the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 came into force on 13 December 2022, carrying on business in Australia is enough on its own to create that link. The effect is that a foreign organization with an Australian link is bound directly, wherever it is located. There is no Article 27 equivalent and no appointed local representative in the mechanism at all.
Section 6D adds a small-business exemption: organizations with annual turnover of AUD 3,000,000 or less are generally outside the Australian Privacy Principles even where they have an Australian link. So the Privacy Act can reach a large overseas business directly and leave a small one out entirely, and in neither case does it create the kind of appointed EU contact point that GDPR Article 27 requires, because that appointment is an EU obligation and sits outside the reach of any Australian statute.
Who regulates this?
In the EU, the supervisory authority in the member state where your representative sits, and the wider network of authorities coordinated through the European Data Protection Board. In Australia, the Office of the Australian Information Commissioner regulates the Privacy Act and the Australian Privacy Principles. The OAIC does not administer Article 27, which is the point: your Australian regulator does not stand in for an EU representative.
Do Australian companies also need a UK representative?
In most cases, yes. The UK runs its own UK GDPR with its own Article 27, enforced by the Information Commissioner’s Office, and an Australian company selling online into the EU is usually reaching the UK as well. The two obligations are separate appointments in separate territories, and an EU representative does not cover the UK. We can take both, as two mandates.
What does Engage do?
Engage Compliance acts as your EU representative under Article 27, established in the EU, named in your privacy notice, and reachable by supervisory authorities and by people in the EU on your behalf. This is a service we deliver directly from Amsterdam, with the same senior expert on your account rather than a junior handoff. There is no separate Australian representative obligation to satisfy, so nothing here runs through a local partner in Australia.
Where you also need a named DPO, we cannot be both for the same company. The European Data Protection Board is clear the roles can conflict, so we take one and arrange the other through a partner entity, and we say in writing which is which.
Experience across 100+ startups and enterprises including Amazon, Coinbase, and Robinhood sits behind the work.
What to do next
If you are an Australian company selling to or tracking people in the EU and you have not appointed an EU representative, that is an open GDPR Article 27 obligation. Read do I need an EU representative to check whether the narrow exemption could apply to you, see how the EU representative service works, or contact us and we will tell you plainly whether you are caught and what the appointment involves.
Sources and references
- GDPR Article 3, territorial scope, Regulation (EU) 2016/679, EUR-Lex
- GDPR Article 27, representatives of controllers or processors not established in the Union, Regulation (EU) 2016/679, EUR-Lex
- EDPB Guidelines 3/2018 on the territorial scope of the GDPR (Article 3), European Data Protection Board
- Privacy Act 1988, Commonwealth of Australia, Federal Register of Legislation
- The Privacy Act, Office of the Australian Information Commissioner
Representative mandates
These mandates stack rather than replace each other. One company selling into Europe can be caught by several at once, each is a separate appointment with its own published contact point, and an EU representative does not cover the UK. Engage Compliance holds them together so you have one point of contact across the set.
- EU GDPR Article 27 representative
- UK GDPR Article 27 representative
- Swiss FADP Article 14 representative
- DSA Article 13 legal representative
- EU AI Act GPAI authorised representative
- EU AI Act high-risk authorised representative
- NIS2 representative
- Data Act legal representative
- Data Governance Act representative
- e-Evidence legal representative
- Terrorist Content Online representative
- GPSR responsible person
- CE-marking authorised representative
- Non-EU regimes (Swiss, China, Korea, Turkey)