A Singapore company with no EU establishment that offers goods or services to people in the EU, or monitors their behavior, is caught by GDPR Article 3(2) and has to appoint an EU representative under Article 27. Engage Compliance takes that role from its EU establishment and is listed as your Article 27 contact point. The confusion here is specific to Singapore: because the PDPA already forces you to name a Data Protection Officer, a lot of Singapore companies assume that role covers the EU as well. It does not, and the two are worth pulling apart.
Key takeaways
- GDPR Article 27 applies to Singapore companies with no EU establishment that offer goods or services to, or monitor the behavior of, people in the EU. The Article 27(2) exemption is narrow and most products that run on EU users do not qualify.
- The PDPA’s mandatory DPO under section 11(3) is not an EU representative. It is an internal compliance officer with no residency requirement, and the PDPA has no Article 27 style obligation for a foreign company to appoint anyone inside Singapore.
- The EU representative sits in an EU member state, is named in your privacy notice, and is reachable by EU supervisory authorities and by people in the EU. That is a role Singapore law does not create.
- Most Singapore companies caught by the EU obligation are also caught by the separate UK one, and the two are appointed independently.
- We act as your EU representative directly from Amsterdam, and where you also need a DPO we keep the two roles with separate entities on the European Data Protection Board’s own reasoning.
How does a Singapore company get caught by GDPR?
GDPR reaches beyond the EU through Article 3(2). A company with no EU establishment is inside the Regulation when its processing relates to either offering goods or services to people who are in the EU, whether or not payment is required, or monitoring their behavior as far as that behavior happens in the EU.
Singapore is a regional hub for ecommerce, fintech, travel and SaaS, so this catches ordinary business models. A Singapore-headquartered ecommerce or travel-booking platform that sells to and prices for consumers in Germany or France is offering goods and services to people in the EU. A Singapore fintech onboarding EU customers is doing the same. A Singapore app or SaaS company that runs behavioral analytics, advertising pixels or session recording on EU users is monitoring behavior. All of these trigger Article 27, and none of them requires an office in Europe to do so.
Does Singapore’s PDPA require an EU representative?
No. The Personal Data Protection Act 2012 is Singapore’s own law, and it works differently. Section 11(3) requires an organization to designate one or more individuals, a Data Protection Officer, to be responsible for making sure the organization complies with the PDPA. Section 11(5) requires you to make the DPO’s business contact information available, and section 11(6) confirms that designating a DPO does not relieve the organization of its own obligations. This is a real, mandatory duty, enforced by the Personal Data Protection Commission.
What the PDPA does not do is create anything like GDPR Article 27. There is no requirement for a company based outside Singapore to appoint a representative or agent inside Singapore, and nothing in the PDPA appoints an EU contact point for you. The EU obligation is a requirement of EU law and sits outside the reach of any Singapore statute.
Is the PDPA’s mandatory DPO the same as an EU representative?
No, and this is the point most Singapore companies get wrong. The DPO under section 11(3) is an internal compliance officer. There is no residency requirement, so the person does not need to live in Singapore and does not need to be an employee. The role is about overseeing your PDPA compliance from the inside, not about being a local face for a foreign regulator.
The EU representative is the opposite kind of role. It is a person or entity established in an EU member state, named in your privacy notice, that EU supervisory authorities and people in the EU can address on your behalf. A DPO who can be anyone anywhere is not a substitute for a representative who has to be inside the EU. Having named a DPO to satisfy the PDPA does nothing for Article 27.
Who regulates this?
Two different bodies, in two different systems. In Singapore, the Personal Data Protection Commission administers the PDPA, including the DPO duty. In the EU, it is the supervisory authority in the member state where your representative sits, working within the wider network of authorities coordinated through the European Data Protection Board. The PDPC has no role in Article 27, and no EU authority has a role in the PDPA, which is why meeting one says nothing about the other.
Do Singapore companies also need a UK representative?
In most cases, yes. The UK runs its own UK GDPR with its own Article 27, enforced by the Information Commissioner’s Office, and a Singapore company selling online into the EU is usually reaching the UK as well. The two obligations are separate appointments in separate territories, and an EU representative does not cover the UK. We can take both, as two mandates.
What does Engage do?
Engage Compliance acts as your EU representative under Article 27, established in the EU, named in your privacy notice, and reachable by supervisory authorities and by people in the EU on your behalf. This is a service we deliver directly from Amsterdam, and where you also target the UK we take the UK representation directly too. The same senior expert stays on your account rather than handing it to a junior.
Where you also need a named DPO, we cannot be both for the same company. The European Data Protection Board is clear the roles can conflict, so we take one and arrange the other through a partner entity, and we say in writing which is which.
Experience across 100+ startups and enterprises including Amazon, Coinbase, and Robinhood sits behind the work.
What to do next
If you are a Singapore company selling to or tracking people in the EU and you have not appointed an EU representative, that is an open GDPR Article 27 obligation, and your PDPA DPO does not close it. Read do I need an EU representative to check whether the narrow exemption could apply to you, see how the EU representative service works, or contact us and we will tell you plainly whether you are caught and what the appointment involves.
Sources and references
- GDPR Article 3, territorial scope, Regulation (EU) 2016/679, EUR-Lex
- GDPR Article 27, representatives of controllers or processors not established in the Union, Regulation (EU) 2016/679, EUR-Lex
- EDPB Guidelines 3/2018 on the territorial scope of the GDPR (Article 3), European Data Protection Board
- Advisory Guidelines on Key Concepts in the Personal Data Protection Act, Personal Data Protection Commission, Singapore
Representative mandates
These mandates stack rather than replace each other. One company selling into Europe can be caught by several at once, each is a separate appointment with its own published contact point, and an EU representative does not cover the UK. Engage Compliance holds them together so you have one point of contact across the set.
- EU GDPR Article 27 representative
- UK GDPR Article 27 representative
- Swiss FADP Article 14 representative
- DSA Article 13 legal representative
- EU AI Act GPAI authorised representative
- EU AI Act high-risk authorised representative
- NIS2 representative
- Data Act legal representative
- Data Governance Act representative
- e-Evidence legal representative
- Terrorist Content Online representative
- GPSR responsible person
- CE-marking authorised representative
- Non-EU regimes (Swiss, China, Korea, Turkey)