A Singapore company with no EU establishment that offers goods or services to people in the EU, or monitors their behavior, is caught by GDPR Article 3(2) and has to appoint an EU representative under Article 27. Engage Compliance takes that role from its EU establishment and is listed as your Article 27 contact point. The confusion here is specific to Singapore: because the PDPA already forces you to name a Data Protection Officer, a lot of Singapore companies assume that role covers the EU as well. It does not, and the two are worth pulling apart.

Key takeaways

  • GDPR Article 27 applies to Singapore companies with no EU establishment that offer goods or services to, or monitor the behavior of, people in the EU. The Article 27(2) exemption is narrow and most products that run on EU users do not qualify.
  • The PDPA’s mandatory DPO under section 11(3) is not an EU representative. It is an internal compliance officer with no residency requirement, and the PDPA has no Article 27 style obligation for a foreign company to appoint anyone inside Singapore.
  • The EU representative sits in an EU member state, is named in your privacy notice, and is reachable by EU supervisory authorities and by people in the EU. That is a role Singapore law does not create.
  • Most Singapore companies caught by the EU obligation are also caught by the separate UK one, and the two are appointed independently.
  • We act as your EU representative directly from Amsterdam, and where you also need a DPO we keep the two roles with separate entities on the European Data Protection Board’s own reasoning.

How does a Singapore company get caught by GDPR?

GDPR reaches beyond the EU through Article 3(2). A company with no EU establishment is inside the Regulation when its processing relates to either offering goods or services to people who are in the EU, whether or not payment is required, or monitoring their behavior as far as that behavior happens in the EU.

Singapore is a regional hub for ecommerce, fintech, travel and SaaS, so this catches ordinary business models. A Singapore-headquartered ecommerce or travel-booking platform that sells to and prices for consumers in Germany or France is offering goods and services to people in the EU. A Singapore fintech onboarding EU customers is doing the same. A Singapore app or SaaS company that runs behavioral analytics, advertising pixels or session recording on EU users is monitoring behavior. All of these trigger Article 27, and none of them requires an office in Europe to do so.

Does Singapore’s PDPA require an EU representative?

No. The Personal Data Protection Act 2012 is Singapore’s own law, and it works differently. Section 11(3) requires an organization to designate one or more individuals, a Data Protection Officer, to be responsible for making sure the organization complies with the PDPA. Section 11(5) requires you to make the DPO’s business contact information available, and section 11(6) confirms that designating a DPO does not relieve the organization of its own obligations. This is a real, mandatory duty, enforced by the Personal Data Protection Commission.

What the PDPA does not do is create anything like GDPR Article 27. There is no requirement for a company based outside Singapore to appoint a representative or agent inside Singapore, and nothing in the PDPA appoints an EU contact point for you. The EU obligation is a requirement of EU law and sits outside the reach of any Singapore statute.

Is the PDPA’s mandatory DPO the same as an EU representative?

No, and this is the point most Singapore companies get wrong. The DPO under section 11(3) is an internal compliance officer. There is no residency requirement, so the person does not need to live in Singapore and does not need to be an employee. The role is about overseeing your PDPA compliance from the inside, not about being a local face for a foreign regulator.

The EU representative is the opposite kind of role. It is a person or entity established in an EU member state, named in your privacy notice, that EU supervisory authorities and people in the EU can address on your behalf. A DPO who can be anyone anywhere is not a substitute for a representative who has to be inside the EU. Having named a DPO to satisfy the PDPA does nothing for Article 27.

Who regulates this?

Two different bodies, in two different systems. In Singapore, the Personal Data Protection Commission administers the PDPA, including the DPO duty. In the EU, it is the supervisory authority in the member state where your representative sits, working within the wider network of authorities coordinated through the European Data Protection Board. The PDPC has no role in Article 27, and no EU authority has a role in the PDPA, which is why meeting one says nothing about the other.

Do Singapore companies also need a UK representative?

In most cases, yes. The UK runs its own UK GDPR with its own Article 27, enforced by the Information Commissioner’s Office, and a Singapore company selling online into the EU is usually reaching the UK as well. The two obligations are separate appointments in separate territories, and an EU representative does not cover the UK. We can take both, as two mandates.

What does Engage do?

Engage Compliance acts as your EU representative under Article 27, established in the EU, named in your privacy notice, and reachable by supervisory authorities and by people in the EU on your behalf. This is a service we deliver directly from Amsterdam, and where you also target the UK we take the UK representation directly too. The same senior expert stays on your account rather than handing it to a junior.

Where you also need a named DPO, we cannot be both for the same company. The European Data Protection Board is clear the roles can conflict, so we take one and arrange the other through a partner entity, and we say in writing which is which.

Experience across 100+ startups and enterprises including Amazon, Coinbase, and Robinhood sits behind the work.

What to do next

If you are a Singapore company selling to or tracking people in the EU and you have not appointed an EU representative, that is an open GDPR Article 27 obligation, and your PDPA DPO does not close it. Read do I need an EU representative to check whether the narrow exemption could apply to you, see how the EU representative service works, or contact us and we will tell you plainly whether you are caught and what the appointment involves.

Sources and references

Representative mandates

These mandates stack rather than replace each other. One company selling into Europe can be caught by several at once, each is a separate appointment with its own published contact point, and an EU representative does not cover the UK. Engage Compliance holds them together so you have one point of contact across the set.

FAQ

Frequently asked questions

Does a Singapore company need an EU representative?

If your company is based in Singapore, has no establishment in the EU, and either offers goods or services to people in the EU or monitors their behavior, then yes, GDPR Article 27 requires you to appoint a representative established in an EU member state. The exemption in Article 27(2) is narrow, for occasional and low-risk processing that does not involve large-scale special category or criminal data, and a Singapore ecommerce, travel, fintech or SaaS business running on EU users rarely fits it.

Isn't our PDPA Data Protection Officer enough?

No. Section 11(3) of the Personal Data Protection Act makes you designate one or more individuals as your DPO responsible for PDPA compliance, and section 11(5) makes you publish their business contact information. That is a genuine and mandatory duty, but the DPO is an internal role. It has no residency requirement, the person need not live in Singapore or be an employee, and it exists to oversee your PDPA obligations, not to act as a local point of contact for a foreign regulator. The EU representative is a different role in a different territory, and one does not stand in for the other.

Does the PDPA make an overseas company appoint a local representative in Singapore?

No. The PDPA has no equivalent of GDPR Article 27. There is no obligation on a company outside Singapore to appoint a representative or agent inside Singapore. The DPO under section 11(3) is an internal compliance officer that can sit anywhere, which is exactly why it is easy to mistake for a cross-border representative and exactly why it is not one.

Do Singapore companies also need a UK representative?

Usually, yes. The UK runs its own Article 27 obligation under the UK GDPR, enforced by the Information Commissioner's Office, and a Singapore business selling online into the EU is in most cases also reaching the UK. Meeting the EU requirement does nothing for the UK one, so a company that targets both markets appoints a representative in each.

Can the same provider be our EU representative and our DPO?

No. The European Data Protection Board is clear that one provider should not hold both roles for the same company, because the representative can be addressed by the regulator on the company's behalf while the DPO has to monitor that same company independently. Where you need both, we take one and arrange the other through a partner entity.