---
title: "EU Representative for US Companies | GDPR Art 27"
url: "https://www.engagecompliance.co/eu-representative-for-us-companies"
type: "service"
date: "2026-08-28"
---

# EU Representative for US Companies under GDPR Article 27

A US company with no EU establishment that offers goods or services to people in the EU, or monitors their behavior, is caught by GDPR Article 3(2) and has to appoint an EU representative under Article 27. Engage Compliance acts as that EU representative, established in the EU and named in your privacy notice. It is one of the parts of GDPR that gets missed most often, because it applies only to companies outside the EU, so guidance written from a European point of view tends to skip it.

## Key takeaways

- GDPR Article 27 applies to US companies with no EU establishment that offer goods or services to, or monitor the behavior of, people in the EU. The exemption is narrow and most products that run on EU users do not qualify.
- No US privacy law removes this. The CCPA and the other state laws are threshold-based and impose duties on the business directly. None of them appoints an EU representative for you.
- The EU representative is not your US registered agent for service of process. One is corporate law, the other is GDPR.
- Most US companies caught by the EU obligation are also caught by the separate UK one, and the two are appointed independently.
- We act as your EU representative directly, and where you also need a DPO we keep the two roles with separate entities on the European Data Protection Board's own reasoning.

## How does a US company get caught by GDPR?

GDPR reaches beyond the EU through Article 3(2). A company with no EU establishment is inside the Regulation when its processing relates to either offering goods or services to people who are in the EU, whether or not payment is required, or monitoring their behavior as far as that behavior happens in the EU.

A US direct-to-consumer brand running a Shopify store that ships to and prices for customers in Germany or France is offering goods to people in the EU. A US SaaS or mobile-app company that runs analytics, advertising pixels or session recording on EU visitors is monitoring behavior. Both are the ordinary shape of a US business that has grown into the EU market without opening an EU office, and both trigger Article 27.

## Does US privacy law require an EU representative?

No. The US has no single federal privacy statute. It has a growing patchwork of state laws, and each of them is triggered by doing business with or targeting the residents of that state plus revenue or data-volume thresholds, not by where a company is established, and none of them creates a GDPR Article 27 style local representative.

The California Consumer Privacy Act, as amended by the CPRA, applies above set revenue and data thresholds. Virginia's Consumer Data Protection Act and the Colorado Privacy Act work the same way, and the rest of the 2023 to 2026 wave follows the same model. All of them impose obligations on the business itself. None appoints an EU contact point, because that is a requirement of EU law and sits outside the reach of any US statute.

One point worth clearing up: a company that registers to do business in a US state has to keep a registered agent for service of process under that state's corporations code. That is corporate-law housekeeping and it is not a data protection representative. It does not satisfy Article 27, and Article 27 does not satisfy it.

## Who regulates this?

In the EU, the supervisory authority in the member state where your representative sits, and the wider network of authorities coordinated through the European Data Protection Board. In the US, there is no single privacy regulator: the California Privacy Protection Agency is the one dedicated state body, most states enforce through the state attorney general, and the Federal Trade Commission acts at the federal level under Section 5 of the FTC Act. None of them administers Article 27, which is the point.

## Do US companies also need a UK representative?

In most cases, yes. After Brexit the UK runs its own UK GDPR with its own Article 27, enforced by the Information Commissioner's Office, and a US company selling online into the EU is usually reaching the UK as well. The two obligations are separate appointments in separate territories, and an EU representative does not cover the UK. We can take both, as two mandates.

## What does Engage do?

Engage Compliance acts as your EU representative under Article 27, established in the EU, named in your privacy notice, and reachable by supervisory authorities and by people in the EU on your behalf. This is a service we deliver directly from Amsterdam, with the same senior expert on your account rather than a junior handoff.

Where you also need a named DPO, we cannot be both for the same company. The European Data Protection Board is clear the roles can conflict, so we take one and arrange the other through a partner entity, and we say in writing which is which.

Experience across 100+ startups and enterprises including Amazon, Coinbase, and Robinhood sits behind the work.

## What to do next

If you are a US company selling to or tracking people in the EU and you have not appointed an EU representative, that is an open GDPR Article 27 obligation. Read [do I need an EU representative](/do-i-need-an-eu-representative) to check whether the narrow exemption could apply to you, see how the [EU representative service](/eu-representative-service) works, or [contact us](/contact) and we will tell you plainly whether you are caught and what the appointment involves.

## Sources and references

- [GDPR Article 3, territorial scope](https://eur-lex.europa.eu/eli/reg/2016/679/oj), Regulation (EU) 2016/679, EUR-Lex
- [GDPR Article 27, representatives of controllers or processors not established in the Union](https://eur-lex.europa.eu/eli/reg/2016/679/oj), Regulation (EU) 2016/679, EUR-Lex
- [EDPB Guidelines 3/2018 on the territorial scope of the GDPR (Article 3)](https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-32018-territorial-scope-gdpr-article-3-version_en), European Data Protection Board
- [California Consumer Privacy Act, Civil Code section 1798.100 et seq.](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?division=3.&part=4.&lawCode=CIV&title=1.81.5), California Legislative Information

## Frequently asked questions

### Does a US company need an EU representative?

If your company is based in the US, has no establishment in the EU, and either offers goods or services to people in the EU or monitors their behavior, then yes, GDPR Article 27 requires you to appoint a representative established in an EU member state. The narrow exemption in Article 27(2) is for occasional, low-risk processing that does not involve large-scale special category or criminal data, and most products that run on EU users do not qualify for it.

### Doesn't the CCPA or another US law cover this?

No. US privacy law is a state patchwork, and it is triggered by revenue and data-volume thresholds and by targeting a state's residents, not by where your company is established. No US state comprehensive privacy law imposes a GDPR Article 27 style local representative. The CCPA, Virginia's VCDPA, the Colorado Privacy Act and the rest impose duties directly on the business. None of them appoints an EU contact point for you, because that is an EU obligation, not a US one.

### Is an EU representative the same as our registered agent for service of process?

No, and the two are easy to confuse. A registered agent is a corporate-law requirement you meet when you register to do business in a US state. The EU representative is a data protection role under GDPR Article 27, sitting inside the EU, named in your privacy notice, and reachable by EU supervisory authorities and by people in the EU. Neither one substitutes for the other.

### Do US companies also need a UK representative?

Usually, yes. The UK has its own separate Article 27 obligation under the UK GDPR, and a US company selling online into the EU is in most cases also selling into the UK. Meeting the EU requirement does nothing for the UK one, so a company reaching both markets appoints a representative in each.

### Can the same provider be our EU representative and our DPO?

No. The European Data Protection Board is clear that one provider should not hold both roles for the same company, because the representative can be addressed by the regulator on the company's behalf while the DPO has to monitor that same company independently. Where you need both, we take one and arrange the other through a partner entity.
