---
title: "EU Representative for Israeli Companies | GDPR 27"
url: "https://www.engagecompliance.co/eu-representative-for-israeli-companies"
type: "service"
date: "2026-08-28"
---

# EU Representative for Israeli Companies under GDPR Article 27

An Israeli company that offers goods or services to people in the EU, or monitors their behavior, is caught by GDPR Article 3(2) and has to appoint an EU representative under Article 27. Engage Compliance takes that role from its EU establishment and is listed as your Article 27 contact point. Because Israel holds an EU adequacy decision, many Israeli companies assume GDPR is handled, or does not reach them at all. It does reach them, and adequacy does not answer the Article 27 question.

## Key takeaways

- GDPR Article 27 applies to Israeli companies with no EU establishment that offer goods or services to, or monitor the behavior of, people in the EU. The exemption is narrow.
- Israel's EU adequacy decision does not remove this. Adequacy is about data flowing into Israel; Article 27 is about the Israeli company's own obligations when it targets the EU. They are different questions.
- Israel's own Protection of Privacy Law is a separate regime, overseen by the Privacy Protection Authority, and on the primary text it does not require foreign companies to appoint a local Israeli representative.
- Most Israeli companies caught by the EU obligation are also caught by the separate UK one, and each is appointed independently.
- We act as your EU representative directly from Amsterdam, with the same senior expert on your account.

## How does an Israeli company get caught by GDPR?

GDPR reaches beyond the EU through Article 3(2): a company with no EU establishment is inside the Regulation when its processing relates to offering goods or services to people in the EU, whether or not payment is required, or monitoring their behavior as far as it happens in the EU.

Israel has an unusually large technology sector, so the common case is an Israeli SaaS, adtech, cybersecurity or mobile-app company whose product serves or tracks EU users. Selling subscriptions to EU customers is offering services; running analytics, profiling or ad targeting on EU users is monitoring behavior. Both trigger Article 27, whatever the company's own privacy standards look like at home.

## Why does adequacy not remove the Article 27 obligation?

This is the point Israeli companies get wrong most often, so it is worth being precise.

Israel holds an EU adequacy decision, Commission Decision 2011/61/EU, which the European Commission reaffirmed in its January 2024 review of the older adequacy decisions. Adequacy sits in Chapter V of the GDPR, the chapter on international transfers, and it answers one question: can an EU business send personal data to a recipient in Israel without extra safeguards such as standard contractual clauses? Because of the adequacy decision, the answer is yes. That is a benefit to the EU data exporter.

Article 27 answers a completely different question, and it lives in a different part of the GDPR. It follows from Article 3(2): if your Israeli company itself targets or monitors people in the EU, GDPR applies to you directly, and you must appoint an EU representative. Adequacy does nothing to switch that off. In plain terms, adequacy answers "can EU data be sent to Israel?" while Article 27 answers "does this Israeli company, because it sells to or tracks EU users, need an EU representative?" The answer to the second is yes, independently of the first. Treating the adequacy decision as an Article 27 exemption is the common and expensive mistake.

## What does Israel's own privacy law require?

Israel's Protection of Privacy Law, 5741-1981, as significantly amended by Amendment 13, came into force on 14 August 2025 and is overseen by the Privacy Protection Authority. Amendment 13 moves the law toward GDPR, with a data protection officer duty, broader definitions and stronger enforcement. On the primary text, it does not impose a GDPR Article 27 style requirement for foreign companies to appoint a local Israeli representative, so this is a separate domestic regime rather than a second representative obligation.

## Who regulates this?

In the EU, the supervisory authority in the member state where your representative sits, coordinated through the European Data Protection Board. In Israel, the Privacy Protection Authority oversees the Protection of Privacy Law. Separate regimes.

## Do Israeli companies also need a UK representative?

Usually, where the company also offers goods or services to, or monitors, people in the UK. The UK GDPR carries its own separate Article 27, enforced by the Information Commissioner's Office, and an EU representative does not cover the UK. The same adequacy point applies on the UK side: an adequacy finding covers data sent to Israel and does not remove an Israeli company's own UK Article 27 duty. We can take both as separate mandates.

## What does Engage do?

Engage Compliance acts as your EU representative under Article 27, established in the EU, named in your privacy notice, and reachable by supervisory authorities and by people in the EU on your behalf. This is a service we deliver directly from Amsterdam, with the same senior expert on your account rather than a junior handoff.

Where you also need a named DPO, we cannot be both for the same company. The European Data Protection Board is clear the roles can conflict, so we take one and arrange the other through a partner entity, and we say in writing which is which.

Experience across 100+ startups and enterprises including Amazon, Coinbase, and Robinhood sits behind the work.

## What to do next

If you are an Israeli company selling to or tracking people in the EU and you have not appointed an EU representative, that is an open GDPR Article 27 obligation, and your adequacy status does not close it. Read [do I need an EU representative](/do-i-need-an-eu-representative), see how the [EU representative service](/eu-representative-service) works, or [contact us](/contact) and we will tell you plainly whether you are caught and what the appointment involves.

## Sources and references

- [GDPR Article 3, territorial scope](https://eur-lex.europa.eu/eli/reg/2016/679/oj), Regulation (EU) 2016/679, EUR-Lex
- [GDPR Article 27, representatives of controllers or processors not established in the Union](https://eur-lex.europa.eu/eli/reg/2016/679/oj), Regulation (EU) 2016/679, EUR-Lex
- [Commission Decision 2011/61/EU on the adequate protection of personal data by the State of Israel](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32011D0061), EUR-Lex
- [EDPB Guidelines 3/2018 on the territorial scope of the GDPR (Article 3)](https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-32018-territorial-scope-gdpr-article-3-version_en), European Data Protection Board

## Frequently asked questions

### Does an Israeli company need an EU representative?

If your company is based in Israel, has no establishment in the EU, and either offers goods or services to people in the EU or monitors their behavior, then GDPR Article 27 requires you to appoint a representative established in an EU member state. Israel's large tech sector means this catches a lot of companies. The narrow exemption in Article 27(2) is for occasional, low-risk processing and most products that run on EU users do not qualify.

### Doesn't Israel's EU adequacy decision mean GDPR does not apply to us?

No, and this is the mistake we correct most often. Adequacy and Article 27 answer different questions. Israel's adequacy decision is about data flowing into Israel: it lets an EU business transfer personal data to an Israeli recipient without extra safeguards, because the Commission judged Israel's protection adequate. Article 27 is about your own company's direct obligations: if you target or monitor people in the EU, GDPR applies to you and you must appoint an EU representative. Adequacy does not switch that off. The two sit in different chapters of the GDPR and do different jobs.

### What does Israel's own privacy law require?

Israel's Protection of Privacy Law, 5741-1981, as significantly amended by Amendment 13, which came into force on 14 August 2025, is overseen by the Privacy Protection Authority. Amendment 13 modernizes the law toward GDPR, including a data protection officer duty and stronger enforcement. It is not the same as the EU representative obligation, and on the primary text it does not impose a GDPR Article 27 style requirement for foreign companies to appoint a local Israeli representative.

### Do Israeli companies also need a UK representative?

Usually, where the company also offers goods or services to, or monitors, people in the UK. The UK GDPR carries its own separate Article 27, enforced by the Information Commissioner's Office. The same adequacy point applies on the UK side: an adequacy finding covers data sent to Israel, and does not remove an Israeli company's own UK Article 27 duty when it is directly caught.

### Can the same provider be our EU representative and our DPO?

No. The European Data Protection Board is clear that one provider should not hold both roles for the same company, because the representative can be addressed by the regulator on the company's behalf while the DPO has to monitor that same company independently. Where you need both, we take one and arrange the other through a partner entity.
