A company established in Saudi Arabia that offers goods or services to people in the EU, or monitors their behavior, is caught by GDPR Article 3(2) and has to appoint an EU representative under Article 27. Engage Compliance takes that role from its EU establishment and is listed as your Article 27 contact point. Saudi companies are increasingly aware of their own PDPL, but that is a Saudi regime run by SDAIA, and it does not answer the EU question. The EU obligation is separate, and it sits in Europe.
Key takeaways
- GDPR Article 27 applies to Saudi companies with no EU establishment that offer goods or services to, or monitor the behavior of, people in the EU. The exemption is narrow.
- Saudi Arabia’s own Personal Data Protection Law is a separate regime, overseen by SDAIA. It reaches a Saudi company’s processing of the data of people in the Kingdom, and it does not cover the EU obligation.
- A common claim that the PDPL already requires foreign companies to appoint a licensed representative inside Saudi Arabia runs ahead of the published law. The EU Article 27 representative is the appointment clearly required now for a company reaching EU users.
- Most Saudi companies caught by the EU obligation are also caught by the separate UK one, and each is appointed independently.
- We act as your EU representative directly from Amsterdam. Saudi-side PDPL work is a separate local matter, and any of it we route to a local partner rather than presenting it as something we perform.
How does a Saudi company get caught by GDPR?
GDPR reaches beyond the EU through Article 3(2): a company with no EU establishment is inside the Regulation when its processing relates to offering goods or services to people in the EU, whether or not payment is required, or monitoring their behavior as far as it happens in the EU.
A Saudi ecommerce, online-gaming, fintech or travel business selling to EU consumers is offering goods or services to people in the EU. A Saudi app or adtech company tracking EU users is monitoring behavior. Both are ordinary shapes of a Saudi business reaching the EU market without an EU entity, and both trigger Article 27.
How does this sit with Saudi Arabia’s own PDPL?
Saudi Arabia has its own data protection law, and it works differently from GDPR, so it is worth being clear about what each one does.
The Personal Data Protection Law, issued by Royal Decree No. M/19 and amended by Royal Decree No. M/148, together with its implementing regulations, is overseen by SDAIA, the Saudi Data and Artificial Intelligence Authority. It came into force on 14 September 2023, with a compliance period that ran to 14 September 2024. Its reach is broad: it applies to the processing of the personal data of individuals in the Kingdom, including by parties outside Saudi Arabia. That is a Saudi obligation with a Saudi regulator, and it is a different question from GDPR Article 27.
It is worth correcting one point that circulates widely. A lot of guidance states that the PDPL already requires a foreign company to appoint a licensed representative inside Saudi Arabia, in the way GDPR Article 27 requires an EU one. On the published law, SDAIA’s National Register covers controllers within the Kingdom, and SDAIA has said that separate registration rules for controllers located outside the Kingdom will be issued. So that out-of-Kingdom regime is expected rather than in force, and the “Saudi representative” referred to in the register rules today is a registration contact, not a standing legal agent of the kind Article 27 creates.
The GDPR Article 27 representative, by contrast, is a European appointment that is clearly required now: established in the EU, named in your EU privacy notice, and reachable by EU supervisory authorities and by people in the EU. A Saudi company that both sells into the EU and processes the data of people in Saudi Arabia faces both regimes, and neither covers the other.
Who regulates this?
In the EU, the supervisory authority in the member state where your representative sits, coordinated through the European Data Protection Board. In Saudi Arabia, SDAIA is the competent authority for the PDPL.
Do Saudi companies also need a UK representative?
Usually, where the company also offers goods or services to, or monitors, people in the UK. The UK GDPR carries its own separate Article 27, enforced by the Information Commissioner’s Office, and an EU representative does not cover the UK. We can take both as separate mandates.
What does Engage do?
Engage Compliance acts as your EU representative under Article 27, established in the EU, named in your privacy notice, and reachable by supervisory authorities and by people in the EU on your behalf. This is a service we deliver directly from Amsterdam, with the same senior expert on your account.
Saudi-side PDPL compliance is a separate local matter, and where a client needs support with SDAIA registration or the domestic regime we route that to a local partner rather than presenting it as something we perform. Where you also need a named DPO, we cannot be both for the same company on the European Data Protection Board’s reasoning, so we take one role and arrange the other through a partner entity.
Experience across 100+ startups and enterprises including Amazon, Coinbase, and Robinhood sits behind the work.
What to do next
If you are a Saudi company selling to or tracking people in the EU and you have not appointed an EU representative, that is an open GDPR Article 27 obligation, separate from your PDPL position. Read do I need an EU representative, see how the EU representative service works, or contact us and we will tell you plainly what applies and what the appointment involves.
Sources and references
- GDPR Article 3, territorial scope, Regulation (EU) 2016/679, EUR-Lex
- GDPR Article 27, representatives of controllers or processors not established in the Union, Regulation (EU) 2016/679, EUR-Lex
- SDAIA, Personal Data Protection, Saudi Data and Artificial Intelligence Authority
- EDPB Guidelines 3/2018 on the territorial scope of the GDPR (Article 3), European Data Protection Board
Representative mandates
These mandates stack rather than replace each other. One company selling into Europe can be caught by several at once, each is a separate appointment with its own published contact point, and an EU representative does not cover the UK. Engage Compliance holds them together so you have one point of contact across the set.
- EU GDPR Article 27 representative
- UK GDPR Article 27 representative
- Swiss FADP Article 14 representative
- DSA Article 13 legal representative
- EU AI Act GPAI authorised representative
- EU AI Act high-risk authorised representative
- NIS2 representative
- Data Act legal representative
- Data Governance Act representative
- e-Evidence legal representative
- Terrorist Content Online representative
- GPSR responsible person
- CE-marking authorised representative
- Non-EU regimes (Swiss, China, Korea, Turkey)