A South African company with no EU establishment that offers goods or services to people in the EU, or monitors their behavior, is caught by GDPR Article 3(2) and has to appoint an EU representative under Article 27. Engage Compliance acts as that EU representative, established in the EU and named in your privacy notice. The mix-up here is specific to South Africa: POPIA already forces you to have an Information Officer, and that role is notified to a regulator, so it looks like the cross-border contact point the EU is asking for. It is not, and the difference matters.
Key takeaways
- GDPR Article 27 applies to South African companies with no EU establishment that offer goods or services to, or monitor the behavior of, people in the EU. The Article 27(2) exemption is narrow and most products that run on EU users do not qualify.
- POPIA’s Information Officer is not an EU representative. It is a domestic role that defaults to the head of the organization and must be notified to the Information Regulator, and POPIA has no Article 27 style obligation for a foreign company.
- The EU representative sits in an EU member state, is named in your privacy notice, and is reachable by EU supervisory authorities and by people in the EU. That is a role South African law does not create.
- Most South African companies caught by the EU obligation are also caught by the separate UK one, and the two are appointed independently.
- We act as your EU representative directly from Amsterdam, and where you also need a DPO we keep the two roles with separate entities on the European Data Protection Board’s own reasoning.
How does a South African company get caught by GDPR?
GDPR reaches beyond the EU through Article 3(2). A company with no EU establishment is inside the Regulation when its processing relates to either offering goods or services to people who are in the EU, whether or not payment is required, or monitoring their behavior as far as that behavior happens in the EU.
South Africa’s business shape makes this common. The country’s large business-process-outsourcing and contact-center sector serves European clients directly, often acting as a processor for EU controllers, which pulls it into GDPR on the processing side. Beyond that, South African ecommerce stores, inbound-tourism and safari booking sites that sell to EU travelers, and South African fintech and app businesses with EU users are all either offering goods and services to people in the EU or monitoring their behavior. Each of these triggers Article 27, with or without a European office.
Does POPIA require an EU representative?
No. The Protection of Personal Information Act 4 of 2013 is South Africa’s own law, and it is built around a different role. POPIA requires an Information Officer, which by default is the head of the organization under the Promotion of Access to Information Act. Section 55 sets out that officer’s duties, section 55(2) means the officer can only take up the role once the responsible party has notified them to the Information Regulator, and section 56 lets you appoint deputy information officers. POPIA applies where the responsible party is domiciled in South Africa, or is not domiciled there but uses means in South Africa to process, under its section 3 territorial rule.
None of that is GDPR Article 27. POPIA has no obligation for a company outside South Africa to appoint an in-country representative because it is foreign, and nothing in POPIA appoints an EU contact point for you. The EU obligation is a requirement of EU law and sits outside the reach of any South African statute.
Is POPIA’s Information Officer the same as an EU representative?
No, and this is the point most South African companies get wrong. The Information Officer is a domestic compliance role. It defaults to the head of the responsible party, it must be notified to the Information Regulator, and its job is to run your POPIA compliance from the inside. The registration step is exactly what makes it look like a representative, because it puts a named person on a regulator’s record.
The EU representative is a different kind of role in a different territory. It is a person or entity established in an EU member state, named in your privacy notice, that EU supervisory authorities and people in the EU can address on your behalf. An Information Officer who is the head of your own South African company is not a substitute for a representative that has to be inside the EU. Meeting POPIA does nothing for Article 27.
Who regulates this?
Two different bodies, in two different systems. In South Africa, the Information Regulator administers POPIA, including the Information Officer registration. In the EU, it is the supervisory authority in the member state where your representative sits, working within the wider network of authorities coordinated through the European Data Protection Board. The Information Regulator has no role in Article 27, and no EU authority has a role in POPIA, which is why meeting one says nothing about the other.
Do South African companies also need a UK representative?
In most cases, yes. The UK runs its own UK GDPR with its own Article 27, enforced by the Information Commissioner’s Office, and a South African company selling online into the EU is usually reaching the UK as well. The two obligations are separate appointments in separate territories, and an EU representative does not cover the UK. We can take both, as two mandates.
What does Engage do?
Engage Compliance acts as your EU representative under Article 27, established in the EU, named in your privacy notice, and reachable by supervisory authorities and by people in the EU on your behalf. This is a service we deliver directly from Amsterdam, and where you also target the UK we take the UK representation directly too. The same senior expert stays on your account rather than handing it to a junior.
Where you also need a named DPO, we cannot be both for the same company. The European Data Protection Board is clear the roles can conflict, so we take one and arrange the other through a partner entity, and we say in writing which is which.
Experience across 100+ startups and enterprises including Amazon, Coinbase, and Robinhood sits behind the work.
What to do next
If you are a South African company selling to or tracking people in the EU and you have not appointed an EU representative, that is an open GDPR Article 27 obligation, and your POPIA Information Officer does not close it. Read do I need an EU representative to check whether the narrow exemption could apply to you, see how the EU representative service works, or contact us and we will tell you plainly whether you are caught and what the appointment involves.
Sources and references
- GDPR Article 3, territorial scope, Regulation (EU) 2016/679, EUR-Lex
- GDPR Article 27, representatives of controllers or processors not established in the Union, Regulation (EU) 2016/679, EUR-Lex
- EDPB Guidelines 3/2018 on the territorial scope of the GDPR (Article 3), European Data Protection Board
- Protection of Personal Information Act and Information Officer guidance, Information Regulator, South Africa
Representative mandates
These mandates stack rather than replace each other. One company selling into Europe can be caught by several at once, each is a separate appointment with its own published contact point, and an EU representative does not cover the UK. Engage Compliance holds them together so you have one point of contact across the set.
- EU GDPR Article 27 representative
- UK GDPR Article 27 representative
- Swiss FADP Article 14 representative
- DSA Article 13 legal representative
- EU AI Act GPAI authorised representative
- EU AI Act high-risk authorised representative
- NIS2 representative
- Data Act legal representative
- Data Governance Act representative
- e-Evidence legal representative
- Terrorist Content Online representative
- GPSR responsible person
- CE-marking authorised representative
- Non-EU regimes (Swiss, China, Korea, Turkey)