A company established in China that offers goods or services to people in the EU, or monitors their behavior, is caught by GDPR Article 3(2) and has to appoint an EU representative under Article 27. Engage Compliance provides that representative directly from Amsterdam, named in your privacy notice and reachable by the supervisory authorities. Chinese companies often already know PIPL requires an in-China representative, and assume that settles it. It does not: the EU obligation is separate, and the two representatives sit in different places and answer to different regulators.

Key takeaways

  • GDPR Article 27 applies to Chinese companies with no EU establishment that offer goods or services to, or monitor the behavior of, people in the EU. The exemption is narrow.
  • This is a different appointment from the PIPL Article 53 representative inside China. One sits in the EU under EU law, the other sits in China under Chinese law.
  • Most Chinese companies caught by the EU obligation are also caught by the separate UK one, and each is appointed independently.
  • We act as your EU representative directly. The PIPL Article 53 representative has to be inside China, so we arrange that through a local partner rather than claiming to perform it ourselves.

How does a Chinese company get caught by GDPR?

GDPR reaches beyond the EU through Article 3(2): a company with no EU establishment is inside the Regulation when its processing relates to offering goods or services to people in the EU, whether or not payment is required, or monitoring their behavior as far as that behavior happens in the EU.

A Chinese cross-border ecommerce seller or consumer-hardware brand shipping to and marketing at EU customers is offering goods to people in the EU. A Chinese mobile-app or adtech company that profiles or tracks EU users is monitoring behavior. Both are ordinary shapes of a Chinese business that has grown into the EU market without an EU entity, and both trigger Article 27.

How is this different from the PIPL Article 53 representative?

China has its own extraterritorial data protection law, and it imposes its own in-country representative duty, which is easy to confuse with the EU one.

The Personal Information Protection Law, in force since 1 November 2021, applies under its Article 3 to handling of personal information outside China where the purpose is to provide products or services to people inside China or to analyze their activities. Where that applies, Article 53 requires the handler to establish a dedicated entity or appoint a representative inside China, and to report that entity or representative’s name and contact details to the authorities, regardless of processing volume.

That representative is inside China, reports to Chinese regulators, and does nothing for your EU position. The GDPR Article 27 representative is inside the EU, is named in your EU privacy notice, and is reachable by EU supervisory authorities and by people in the EU. A Chinese company that both sells into the EU and processes data of people in China can need both, and neither substitutes for the other.

Who regulates this?

In the EU, the supervisory authority in the member state where your representative sits, coordinated through the European Data Protection Board. In China, the Cyberspace Administration of China oversees PIPL, including the Article 53 obligation. They are separate regimes.

Do Chinese companies also need a UK representative?

Usually, where the company also offers goods or services to, or monitors, people in the UK. The UK runs its own UK GDPR with its own Article 27, enforced by the Information Commissioner’s Office, and an EU representative does not cover the UK. The two are separate appointments in separate territories, and we can take both as separate mandates.

What does Engage do?

Engage Compliance acts as your EU representative under Article 27, established in the EU, named in your privacy notice, and reachable by supervisory authorities and by people in the EU on your behalf. This is a service we deliver directly from Amsterdam, with the same senior expert on your account.

The PIPL Article 53 representative is different: it has to sit inside China, so where you need it we arrange it through a local partner and say so in writing, rather than presenting a partner-delivered role as something we perform ourselves. Where you also need a named DPO, we cannot be both for the same company on the European Data Protection Board’s reasoning, so we take one role and arrange the other through a partner entity.

Experience across 100+ startups and enterprises including Amazon, Coinbase, and Robinhood sits behind the work.

What to do next

If you are a Chinese company selling to or tracking people in the EU and you have not appointed an EU representative, that is an open GDPR Article 27 obligation, separate from anything you have done for PIPL. Read do I need an EU representative, see how the EU representative service works, or contact us and we will tell you plainly what applies and what the appointment involves.

Sources and references

Representative mandates

These mandates stack rather than replace each other. One company selling into Europe can be caught by several at once, each is a separate appointment with its own published contact point, and an EU representative does not cover the UK. Engage Compliance holds them together so you have one point of contact across the set.

FAQ

Frequently asked questions

Does a Chinese company need an EU representative?

If your company is based in China, has no establishment in the EU, and either offers goods or services to people in the EU or monitors their behavior, then GDPR Article 27 requires you to appoint a representative established in an EU member state. This is EU law reaching a company outside the EU, and it is separate from anything Chinese law requires. The narrow exemption in Article 27(2) is for occasional, low-risk processing and most products that run on EU users do not qualify.

Isn't the PIPL Article 53 representative the same thing?

No. PIPL Article 53 requires a personal information handler outside China that is caught by PIPL's own extraterritorial scope to establish a dedicated entity or appoint a representative inside China, and to report its name and contact details to the authorities. That representative sits in China and answers to Chinese regulators. The GDPR Article 27 representative sits in the EU and answers to EU supervisory authorities and to people in the EU. They are two different appointments in two different jurisdictions, and holding one does nothing for the other.

Who regulates each side?

In the EU, the supervisory authority in the member state where your representative sits, coordinated through the European Data Protection Board. In China, the Cyberspace Administration of China oversees PIPL, including the Article 53 obligation. They are separate regimes with separate regulators.

Do Chinese companies also need a UK representative?

Usually, where the company also offers goods or services to, or monitors, people in the UK. The UK has its own separate Article 27 obligation under the UK GDPR, enforced by the Information Commissioner's Office, and an EU representative does not cover it. A company reaching both markets appoints a representative in each.

Can Engage handle the China side as well?

We provide the EU representative role directly. The PIPL Article 53 representative has to sit inside China, so where a client needs that we arrange it through a local partner rather than performing it ourselves. We are clear in writing about which part we deliver directly and which is partner-delivered.