A company established in Saudi Arabia that offers goods or services to people in the EU, or monitors their behavior, is caught by GDPR Article 3(2) and has to appoint an EU representative under Article 27. Engage Compliance takes that role from its EU establishment and is listed as your Article 27 contact point. Saudi companies are increasingly aware of their own PDPL, but that is a Saudi regime run by SDAIA, and it does not answer the EU question. The EU obligation is separate, and it sits in Europe.

Key takeaways

  • GDPR Article 27 applies to Saudi companies with no EU establishment that offer goods or services to, or monitor the behavior of, people in the EU. The exemption is narrow.
  • Saudi Arabia’s own Personal Data Protection Law is a separate regime, overseen by SDAIA. It reaches a Saudi company’s processing of the data of people in the Kingdom, and it does not cover the EU obligation.
  • A common claim that the PDPL already requires foreign companies to appoint a licensed representative inside Saudi Arabia runs ahead of the published law. The EU Article 27 representative is the appointment clearly required now for a company reaching EU users.
  • Most Saudi companies caught by the EU obligation are also caught by the separate UK one, and each is appointed independently.
  • We act as your EU representative directly from Amsterdam. Saudi-side PDPL work is a separate local matter, and any of it we route to a local partner rather than presenting it as something we perform.

How does a Saudi company get caught by GDPR?

GDPR reaches beyond the EU through Article 3(2): a company with no EU establishment is inside the Regulation when its processing relates to offering goods or services to people in the EU, whether or not payment is required, or monitoring their behavior as far as it happens in the EU.

A Saudi ecommerce, online-gaming, fintech or travel business selling to EU consumers is offering goods or services to people in the EU. A Saudi app or adtech company tracking EU users is monitoring behavior. Both are ordinary shapes of a Saudi business reaching the EU market without an EU entity, and both trigger Article 27.

How does this sit with Saudi Arabia’s own PDPL?

Saudi Arabia has its own data protection law, and it works differently from GDPR, so it is worth being clear about what each one does.

The Personal Data Protection Law, issued by Royal Decree No. M/19 and amended by Royal Decree No. M/148, together with its implementing regulations, is overseen by SDAIA, the Saudi Data and Artificial Intelligence Authority. It came into force on 14 September 2023, with a compliance period that ran to 14 September 2024. Its reach is broad: it applies to the processing of the personal data of individuals in the Kingdom, including by parties outside Saudi Arabia. That is a Saudi obligation with a Saudi regulator, and it is a different question from GDPR Article 27.

It is worth correcting one point that circulates widely. A lot of guidance states that the PDPL already requires a foreign company to appoint a licensed representative inside Saudi Arabia, in the way GDPR Article 27 requires an EU one. On the published law, SDAIA’s National Register covers controllers within the Kingdom, and SDAIA has said that separate registration rules for controllers located outside the Kingdom will be issued. So that out-of-Kingdom regime is expected rather than in force, and the “Saudi representative” referred to in the register rules today is a registration contact, not a standing legal agent of the kind Article 27 creates.

The GDPR Article 27 representative, by contrast, is a European appointment that is clearly required now: established in the EU, named in your EU privacy notice, and reachable by EU supervisory authorities and by people in the EU. A Saudi company that both sells into the EU and processes the data of people in Saudi Arabia faces both regimes, and neither covers the other.

Who regulates this?

In the EU, the supervisory authority in the member state where your representative sits, coordinated through the European Data Protection Board. In Saudi Arabia, SDAIA is the competent authority for the PDPL.

Do Saudi companies also need a UK representative?

Usually, where the company also offers goods or services to, or monitors, people in the UK. The UK GDPR carries its own separate Article 27, enforced by the Information Commissioner’s Office, and an EU representative does not cover the UK. We can take both as separate mandates.

What does Engage do?

Engage Compliance acts as your EU representative under Article 27, established in the EU, named in your privacy notice, and reachable by supervisory authorities and by people in the EU on your behalf. This is a service we deliver directly from Amsterdam, with the same senior expert on your account.

Saudi-side PDPL compliance is a separate local matter, and where a client needs support with SDAIA registration or the domestic regime we route that to a local partner rather than presenting it as something we perform. Where you also need a named DPO, we cannot be both for the same company on the European Data Protection Board’s reasoning, so we take one role and arrange the other through a partner entity.

Experience across 100+ startups and enterprises including Amazon, Coinbase, and Robinhood sits behind the work.

What to do next

If you are a Saudi company selling to or tracking people in the EU and you have not appointed an EU representative, that is an open GDPR Article 27 obligation, separate from your PDPL position. Read do I need an EU representative, see how the EU representative service works, or contact us and we will tell you plainly what applies and what the appointment involves.

Sources and references

Representative mandates

These mandates stack rather than replace each other. One company selling into Europe can be caught by several at once, each is a separate appointment with its own published contact point, and an EU representative does not cover the UK. Engage Compliance holds them together so you have one point of contact across the set.

FAQ

Frequently asked questions

Does a Saudi company need an EU representative?

If your company is based in Saudi Arabia, has no establishment in the EU, and either offers goods or services to people in the EU or monitors their behavior, then GDPR Article 27 requires you to appoint a representative established in an EU member state. This is EU law reaching a company outside the EU, and it is separate from the Saudi PDPL. The Article 27(2) exemption is narrow and most products that run on EU users do not qualify.

How does this sit with Saudi Arabia's own PDPL?

The Saudi Personal Data Protection Law is a separate regime. It reaches entities outside the Kingdom that process the personal data of individuals in Saudi Arabia, and it is overseen by SDAIA, the Saudi Data and Artificial Intelligence Authority. That is a Saudi obligation with a Saudi regulator. The GDPR Article 27 representative is a European appointment: established in the EU, named in your EU privacy notice, and reachable by EU supervisory authorities. Meeting one does nothing for the other.

Who regulates each side?

In the EU, the supervisory authority in the member state where your representative sits, coordinated through the European Data Protection Board. In Saudi Arabia, SDAIA is the competent authority for the PDPL. Separate regimes, separate regulators.

Do Saudi companies also need a UK representative?

Usually, where the company also offers goods or services to, or monitors, people in the UK. The UK GDPR carries its own separate Article 27, enforced by the Information Commissioner's Office, and an EU representative does not cover it. A company reaching both markets appoints a representative in each.

Does the Saudi PDPL require a local representative inside the Kingdom?

Not in the GDPR Article 27 sense, on the published law. SDAIA's National Register today covers controllers within the Kingdom, and SDAIA has said separate registration rules for controllers located outside the Kingdom will be issued, so that out-of-Kingdom regime is expected rather than in force. A lot of guidance states otherwise, but it runs ahead of the primary text. The appointment clearly required now for a Saudi company reaching EU users is the EU Article 27 representative.

Can Engage handle any Saudi-side requirement too?

We provide the EU representative role directly. Saudi-side PDPL compliance and any SDAIA registration is a separate local matter, and where a client needs support with it we route that to a local partner rather than performing it ourselves. We are clear in writing about what we deliver directly.