Some countries outside the EU and UK make a company appoint a local data protection representative, and the representative has to sit inside that country. Engage Compliance coordinates those appointments through vetted local partners and stays your single point of contact.
The short answer: China, Korea, Turkey, and Thailand each require a representative or agent established in-country for foreign companies caught by their rules, while Brazil and Nigeria have no such requirement at all, and Saudi Arabia is not settled. China, Korea, and Turkey each tie the role to local establishment or nationality, so Engage Compliance arranges those through a vetted local partner. Thailand’s own wording only requires the representative to be present in the Kingdom, not Thai-established or Thai-national, so we hold that one directly. Either way, we manage the relationship so you deal with one team.
Key takeaways
- Engage Compliance coordinates non-EU representative and agent appointments, and remains your single point of contact for all of them.
- China’s PIPL and Korea’s PIPA require a representative or agent established in that country; Turkey’s Registry Regulation requires a Turkish legal entity or citizen. All three are partner-delivered rather than run from our EU establishment.
- Thailand’s PDPA requires a representative in the Kingdom of Thailand but does not require Thai establishment or nationality, so Engage Compliance holds this appointment directly.
- Brazil does not require a foreign controller to appoint a representative. The LGPD role people cite, the encarregado, is a data protection officer, not a representative.
- Nigeria does not require a non-resident entity to appoint a local representative. Its Data Protection Compliance Organization license is a service license, not a statutory representative mandate.
- Saudi Arabia is not settled, so we do not assert a requirement. We assess the position case by case and deliver through a local partner where one turns out to be needed.
- Many companies that need one of these also need an EU or UK representative, or a named DPO, and we line those up together.
Which countries actually require a representative
The market is loose with this language, and a few comparison tables list countries as “representative required” when the law says no such thing. Here is the honest split for the regimes buyers ask about most.
Required, representative established or resident in-country: China, Korea, and Turkey. Each of these is partner-delivered.
Required, representative present in-country, no nationality or establishment test in the Act itself: Thailand. Delivered directly.
Not required for a foreign company: Brazil and Nigeria. There is no representative appointment to make in either.
Not settled: Saudi Arabia. We do not claim a requirement exists, and we check the position before advising.
Each is covered below.
China (PIPL Article 53)
Under Article 53 of the Personal Information Protection Law, a personal information handler outside the PRC that falls within the law’s extraterritorial rule must either establish a dedicated institution or designate a representative within the PRC, responsible for personal information protection matters, and must report that body’s name or the representative’s name and contact details to the regulator.
The obligation is disjunctive: you appoint a dedicated body or a representative, not necessarily both. Either way it has to be inside China, so Engage Compliance delivers it through a local partner and coordinates the reporting to the authority.
On penalties, Article 66 (first paragraph) provides for an order to rectify, a warning, confiscation of unlawful gains, and an order to suspend or terminate the offending app. Where a handler refuses to rectify, there is a fine of up to RMB 1 million, and a fine of RMB 10,000 to 100,000 on the directly responsible person.
China’s wider obligations, including the extraterritorial trigger and the broader compliance picture, are set out on our China PIPL compliance services page.
Korea (PIPA domestic agent)
Full mechanics, the Article 31-2 amendment history, and the buyer FAQ are on our dedicated Korea PIPA domestic agent page. What follows here is the short version.
Korea’s Personal Information Protection Act requires a domestic agent, located in Korea, once a foreign company is above certain thresholds. The duty sits at Article 31-2.
We do not publish the exact thresholds or the penalty figure on this page, because those need to be read off the current statute and enforcement decree for your specific numbers rather than quoted from memory. We confirm them as part of scoping. Where the duty applies, Engage Compliance arranges the Korean domestic agent through a local partner.
Turkey (data controller representative and the VERBIS registry)
Full mechanics, who can hold the role, and the buyer FAQ are on our dedicated Turkey KVKK data controller representative page. What follows here is the short version.
A controller not established in Turkey that has to register with VERBIS, the data controllers’ registry, needs a representative that is a legal entity established in Turkey or a Turkish citizen. That comes from the Registry Regulation (Articles 4 and 11), not from Law No. 6698 itself.
The practical consequence is simple: an Amsterdam entity cannot perform this role. The representative has to be Turkish. The appointment is filed with the Authority together with an authenticated copy of the foreign controller’s appointing decision, and the representative handles notifications, requests, and data subject applications on the controller’s behalf.
Because the representative must be Turkish, Engage Compliance coordinates a qualifying local partner and manages the VERBIS registration for you. The Turkish administrative fine for failing to register is revalued each year, so we confirm the current figure at the point of scoping rather than quote a stale band.
Thailand (PDPA section 37(5))
Full mechanics, the section 38 exemption, and the buyer FAQ are on our dedicated Thailand PDPA representative page. What follows here is the short version.
Section 5 paragraph two of Thailand’s Personal Data Protection Act extends the Act to a data controller or processor outside Thailand where it offers goods or services to people in Thailand, or monitors their behavior there. Section 37(5) then requires such a controller to designate in writing a representative who must be in the Kingdom of Thailand. Section 38 extends the same duty to a data processor caught the same way, and carries a narrow exemption for public authorities and for controllers without large-scale or sensitive processing.
Unlike Turkey, the Act does not require the representative to be a Thai national or a Thai-incorporated entity, only present in the Kingdom. Because of that, Engage Compliance holds this appointment directly rather than through a local partner, the same way we deliver the EU, UK, and Swiss mandates.
Where there is no representative mandate: Brazil and Nigeria
Two countries come up often on the assumption that a representative is required, when it is not.
Brazil. The LGPD has broad extraterritorial reach: it applies to processing carried out in Brazil, to the offering of goods or services to people in Brazil, and to data collected in Brazil. Even so, it places no obligation on a controller established abroad to appoint a representative. The role that gets misread as a representative is the encarregado in Article 5(VIII), which is a data protection officer, the channel between the controller, data subjects, and the national authority. That is a DPO, not a foreign-controller representative. Any page listing Brazil as “representative required” is wrong on the statute. We can still help with LGPD compliance and with the encarregado role, there is just no representative appointment to sell.
Nigeria. The Nigeria Data Protection Act 2023 does not require a non-resident entity to appoint a local representative. Section 44 on registration of controllers and processors of major importance carries no such duty, and the 2025 implementation directive extends registration duties to entities outside Nigeria without adding a representative requirement. Nigeria does license Data Protection Compliance Organizations under section 33 of the Act, but that is a license for firms that provide compliance services in Nigeria, not a statutory representative mandate on foreign companies.
Saudi Arabia: assessed case by case
The Saudi position is not settled, so we do not assert that the Kingdom requires a foreign company to appoint a representative. We assess the Saudi position case by case, and where a local representative turns out to be required, we deliver it through a local partner. We would rather tell you the point is open than sell you an appointment the law may not ask for.
How Engage delivers these appointments
China, Korea, and Turkey each tie the representative role to local establishment or nationality, so those are local-entity appointments and we do not imply otherwise. Thailand’s own wording asks only for presence in the Kingdom, so we hold that one directly. Either way, what we provide is coordination and accountability across the whole set:
- We map which of these obligations actually apply to your company, and which do not, so you are not paying for appointments you do not need.
- Where the local rule requires a local entity or person, as China, Korea, and Turkey do, we appoint qualifying local partners and vet them.
- Where the local rule only requires in-country presence, as Thailand’s does, we hold the appointment directly.
- We stay your single point of contact and manage each relationship, so you deal with one team rather than chasing separate firms in separate time zones.
- Where you also need an EU or UK representative, or a named DPO, we line those up alongside the non-EU appointments.
Where you need a DPO as well as a representative, we offer both as separate products and scope them together.
This page is about data protection representation. If what you need is a product-side operator, a GPSR responsible person or an EU authorised representative for CE-marked goods, those are a separate product-safety role under different law, and we cover them from our EU establishment.
What it costs
Pricing for these mandates is scoped to the work, because the cost depends on which countries apply and what each local partner charges. There is no flat rate to quote here. Tell us where your users are and what you process, and we will come back with a quote. Talk to us on the contact page.
Sources and references
- Personal Information Protection Law of the People’s Republic of China, National People’s Congress, npc.gov.cn
- Nigeria Data Protection Commission, ndpc.gov.ng
- Personal Information Protection Act, Republic of Korea, and its Enforcement Decree, Personal Information Protection Commission
- Regulation on the Registry of Data Controllers, Official Gazette 30 December 2017 No. 30286, Personal Data Protection Authority (KVKK Kurumu)
- Personal Data Protection Act, B.E. 2562 (2019), Government Gazette No. 136 Chapter 69 Gor, PDPC Thailand
Representative mandates
These mandates stack rather than replace each other. One company selling into Europe can be caught by several at once, each is a separate appointment with its own published contact point, and an EU representative does not cover the UK. Engage Compliance holds them together so you have one point of contact across the set.
- EU GDPR Article 27 representative
- UK GDPR Article 27 representative
- Swiss FADP Article 14 representative
- DSA Article 13 legal representative
- EU AI Act GPAI authorised representative
- EU AI Act high-risk authorised representative
- NIS2 representative
- Data Act legal representative
- Data Governance Act representative
- e-Evidence legal representative
- Terrorist Content Online representative
- GPSR responsible person
- CE-marking authorised representative
- Non-EU regimes (China, Korea, Turkey, Thailand)