A Canadian company with no EU establishment that offers goods or services to people in the EU, or monitors their behavior, is caught by GDPR Article 3(2) and has to appoint an EU representative under Article 27. Engage Compliance takes that role from its EU establishment and is listed as your Article 27 contact point. Canada has a layered privacy regime of its own, PIPEDA federally and Quebec’s Law 25 on top, and neither of those layers appoints anyone in the EU for you, so this is the obligation Canadian companies most often miss.

Key takeaways

  • GDPR Article 27 applies to Canadian companies with no EU establishment that offer goods or services to, or monitor the behavior of, people in the EU. The exemption is narrow and a store or app that runs on EU users rarely qualifies.
  • Canada’s own laws do not remove this. PIPEDA and Quebec Law 25 impose internal accountability roles that can sit anywhere, not an EU representative.
  • The Law 25 privacy officer is easy to mistake for a local representative. It is an internal role with no locality requirement, and it is not the Article 27 appointment.
  • Most Canadian companies caught by the EU obligation are also caught by the separate UK one, and the two are appointed independently.
  • We act as your EU representative directly from Amsterdam, and where you also need a DPO we keep the two roles with separate entities on the European Data Protection Board’s own reasoning.

How does a Canadian company get caught by GDPR?

GDPR reaches beyond the EU through Article 3(2). A company with no EU establishment is inside the Regulation when its processing relates to either offering goods or services to people who are in the EU, whether or not payment is required, or monitoring their behavior as far as that behavior happens in the EU.

A Canadian ecommerce or direct-to-consumer retailer that ships to and prices for customers in Germany or France is offering goods to people in the EU. A Canadian SaaS or mobile-app business that runs analytics, advertising pixels or session recording on EU visitors is monitoring behavior. Both are the ordinary shape of a Canadian business that has grown into the EU market without opening an EU office, and both trigger Article 27.

Does Canadian privacy law require an EU representative?

No. Canada runs a two-tier regime, and none of the tiers creates a local representative for a foreign company. Federally, PIPEDA (the Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5) applies to organizations handling personal information in the course of commercial activities. Its accountability rule, Schedule 1, Principle 4.1, asks an organization to designate an individual accountable for compliance, and that person can be located anywhere, with no residency requirement. Quebec adds Law 25 (the Act respecting the protection of personal information in the private sector, CQLR c. P-39.1), whose section 3.1 requires a person in charge of the protection of personal information. That role defaults to the person with the highest authority in the enterprise and can be delegated in writing to any person, again with no locality requirement. British Columbia and Alberta run their own PIPA statutes on the same pattern. All of these are internal accountability roles, not a GDPR Article 27 style representative established abroad.

Two Quebec rules get read as a foreign-company representative and are not. Section 70’s “personal information agent” is a registration rule aimed at credit bureaus and information brokers, not a representative you appoint because you are outside Canada. Section 17 is a rule about assessing personal information before it is transferred outside Quebec, which is a transfer-assessment duty, not a local contact point. Neither PIPEDA nor Law 25 puts a representative in place for the EU, because that is an EU obligation and sits outside the reach of any Canadian statute.

Who regulates this?

In the EU, the supervisory authority in the member state where your representative sits, and the wider network of authorities coordinated through the European Data Protection Board. In Canada, privacy is split: federally, the Office of the Privacy Commissioner of Canada oversees PIPEDA, and in Quebec the Commission d’acces a l’information oversees Law 25, with British Columbia and Alberta running their own commissioners. None of them administers Article 27, which is the point: your Canadian regulators do not stand in for an EU representative.

Do Canadian companies also need a UK representative?

In most cases, yes. The UK runs its own UK GDPR with its own Article 27, enforced by the Information Commissioner’s Office, and a Canadian company selling online into the EU is usually reaching the UK as well. The two obligations are separate appointments in separate territories, and an EU representative does not cover the UK. We can take both, as two mandates.

What does Engage do?

Engage Compliance acts as your EU representative under Article 27, established in the EU, named in your privacy notice, and reachable by supervisory authorities and by people in the EU on your behalf. This is a service we deliver directly from Amsterdam, with the same senior expert on your account rather than a junior handoff. There is no separate Canadian representative obligation to satisfy, so nothing here runs through a local partner in Canada.

Where you also need a named DPO, we cannot be both for the same company. The European Data Protection Board is clear the roles can conflict, so we take one and arrange the other through a partner entity, and we say in writing which is which.

Experience across 100+ startups and enterprises including Amazon, Coinbase, and Robinhood sits behind the work.

What to do next

If you are a Canadian company selling to or tracking people in the EU and you have not appointed an EU representative, that is an open GDPR Article 27 obligation. Read do I need an EU representative to check whether the narrow exemption could apply to you, see how the EU representative service works, or contact us and we will tell you plainly whether you are caught and what the appointment involves.

Sources and references

Representative mandates

These mandates stack rather than replace each other. One company selling into Europe can be caught by several at once, each is a separate appointment with its own published contact point, and an EU representative does not cover the UK. Engage Compliance holds them together so you have one point of contact across the set.

FAQ

Frequently asked questions

Does a Canadian company need an EU representative?

If your company is based in Canada, has no establishment in the EU, and either offers goods or services to people in the EU or monitors their behavior, then GDPR Article 27 requires you to appoint a representative established in an EU member state. The narrow exemption in Article 27(2) is for occasional, low-risk processing that does not involve large-scale special category or criminal data, and a store that ships to the EU or an app that tracks EU users rarely qualifies for it.

Doesn't PIPEDA or Quebec Law 25 cover this?

No. PIPEDA and Quebec's Law 25 govern how you handle personal information in Canada. Neither one creates a GDPR Article 27 style representative for a foreign market. PIPEDA's accountability principle asks you to designate an individual responsible for compliance, with no residency requirement, and Law 25 asks for a person in charge of the protection of personal information who can sit anywhere. Both are internal accountability roles under Canadian law, not an EU contact point, because the EU appointment is a requirement of EU law and sits outside what any Canadian statute reaches.

Is the Quebec Law 25 privacy officer the same as an EU representative?

No, and the two are easy to confuse. Law 25 section 3.1 requires a person in charge of the protection of personal information, a role that defaults to the highest authority in the enterprise and can be delegated in writing to any person, with no locality requirement. That is an internal governance role inside your own organization. The EU representative under Article 27 is a separate party established in the EU, named in your privacy notice, and reachable by EU supervisory authorities on your behalf. One does not do the job of the other.

Do Canadian companies also need a UK representative?

Usually, yes. The UK runs its own UK GDPR with its own Article 27, and a Canadian company selling online into the EU is in most cases also reaching people in the UK. The two obligations are separate appointments in separate territories, so meeting the EU requirement does nothing for the UK one. A company reaching both markets appoints a representative in each.

Can the same provider be our EU representative and our DPO?

No. The European Data Protection Board is clear that one provider should not hold both roles for the same company, because the representative can be addressed by the regulator on the company's behalf while the DPO has to monitor that same company independently. Where you need both, we take one and arrange the other through a partner entity, and we say in writing which is which.