Some countries outside the EU and UK make a company appoint a local data protection representative, and the representative has to sit inside that country. Engage Compliance coordinates those appointments through vetted local partners and stays your single point of contact.

The short answer: China, Korea, and Turkey each require a representative or agent established in-country for foreign companies caught by their rules, while Brazil and Nigeria have no such requirement at all, and Saudi Arabia is not settled. Because these appointments have to be inside the country in question, Engage Compliance arranges each one through a local partner rather than pretending an Amsterdam entity can perform it, and manages the relationship so you deal with one team.

Key takeaways

  • Engage Compliance coordinates non-EU representative and agent appointments through vetted local partners, and remains your single point of contact for all of them.
  • China’s PIPL, Korea’s PIPA, and Turkey’s registry rules each require a representative or agent that is established in that country, which is why these are partner-delivered rather than run from our EU establishment.
  • Brazil does not require a foreign controller to appoint a representative. The LGPD role people cite, the encarregado, is a data protection officer, not a representative.
  • Nigeria does not require a non-resident entity to appoint a local representative. Its Data Protection Compliance Organization license is a service license, not a statutory representative mandate.
  • Saudi Arabia is not settled, so we do not assert a requirement. We assess the position case by case and deliver through a local partner where one turns out to be needed.
  • Many companies that need one of these also need an EU or UK representative, or a named DPO, and we line those up together.

Which countries actually require a representative

The market is loose with this language, and a few comparison tables list countries as “representative required” when the law says no such thing. Here is the honest split for the regimes buyers ask about most.

Required, and the representative must sit in the country: China, Korea, and Turkey. Each of these is partner-delivered.

Not required for a foreign company: Brazil and Nigeria. There is no representative appointment to make in either.

Not settled: Saudi Arabia. We do not claim a requirement exists, and we check the position before advising.

Each is covered below.

China (PIPL Article 53)

Under Article 53 of the Personal Information Protection Law, a personal information handler outside the PRC that falls within the law’s extraterritorial rule must either establish a dedicated institution or designate a representative within the PRC, responsible for personal information protection matters, and must report that body’s name or the representative’s name and contact details to the regulator.

The obligation is disjunctive: you appoint a dedicated body or a representative, not necessarily both. Either way it has to be inside China, so Engage Compliance delivers it through a local partner and coordinates the reporting to the authority.

On penalties, Article 66 (first paragraph) provides for an order to rectify, a warning, confiscation of unlawful gains, and an order to suspend or terminate the offending app. Where a handler refuses to rectify, there is a fine of up to RMB 1 million, and a fine of RMB 10,000 to 100,000 on the directly responsible person.

China’s wider obligations, including the extraterritorial trigger and the broader compliance picture, are set out on our China PIPL compliance services page.

Korea (PIPA domestic agent)

Korea’s Personal Information Protection Act requires a domestic agent, located in Korea, once a foreign company is above certain thresholds. The duty sits at Article 31-2.

We do not publish the exact thresholds or the penalty figure on this page, because those need to be read off the current statute and enforcement decree for your specific numbers rather than quoted from memory. We confirm them as part of scoping. Where the duty applies, Engage Compliance arranges the Korean domestic agent through a local partner.

Turkey (data controller representative and the VERBIS registry)

A controller not established in Turkey that has to register with VERBIS, the data controllers’ registry, needs a representative that is a legal entity established in Turkey or a Turkish citizen. That comes from the Registry Regulation (Articles 4 and 11), not from Law No. 6698 itself.

The practical consequence is simple: an Amsterdam entity cannot perform this role. The representative has to be Turkish. The appointment is filed with the Authority together with an authenticated copy of the foreign controller’s appointing decision, and the representative handles notifications, requests, and data subject applications on the controller’s behalf.

Because the representative must be Turkish, Engage Compliance coordinates a qualifying local partner and manages the VERBIS registration for you. The Turkish administrative fine for failing to register is revalued each year, so we confirm the current figure at the point of scoping rather than quote a stale band.

Where there is no representative mandate: Brazil and Nigeria

Two countries come up often on the assumption that a representative is required, when it is not.

Brazil. The LGPD has broad extraterritorial reach: it applies to processing carried out in Brazil, to the offering of goods or services to people in Brazil, and to data collected in Brazil. Even so, it places no obligation on a controller established abroad to appoint a representative. The role that gets misread as a representative is the encarregado in Article 5(VIII), which is a data protection officer, the channel between the controller, data subjects, and the national authority. That is a DPO, not a foreign-controller representative. Any page listing Brazil as “representative required” is wrong on the statute. We can still help with LGPD compliance and with the encarregado role, there is just no representative appointment to sell.

Nigeria. The Nigeria Data Protection Act 2023 does not require a non-resident entity to appoint a local representative. Section 44 on registration of controllers and processors of major importance carries no such duty, and the 2025 implementation directive extends registration duties to entities outside Nigeria without adding a representative requirement. Nigeria does license Data Protection Compliance Organizations under section 33 of the Act, but that is a license for firms that provide compliance services in Nigeria, not a statutory representative mandate on foreign companies.

Saudi Arabia: assessed case by case

The Saudi position is not settled, so we do not assert that the Kingdom requires a foreign company to appoint a representative. We assess the Saudi position case by case, and where a local representative turns out to be required, we deliver it through a local partner. We would rather tell you the point is open than sell you an appointment the law may not ask for.

How Engage delivers partner-mandated appointments

For every regime that requires establishment in-country, the representative has to be a local entity or person. We do not imply otherwise. What we provide is coordination and accountability across the whole set:

  • We map which of these obligations actually apply to your company, and which do not, so you are not paying for appointments you do not need.
  • We appoint qualifying local partners in each country where a mandate applies, and we vet them.
  • We stay your single point of contact and manage each relationship, so you deal with one team rather than chasing separate firms in separate time zones.
  • Where you also need an EU or UK representative, or a named DPO, we line those up alongside the non-EU appointments.

Where you need a DPO as well as a representative, we keep the two roles with separate entities, on the European Data Protection Board’s reasoning about the conflict between them.

This page is about data protection representation. If what you need is a product-side operator, a GPSR responsible person or an EU authorised representative for CE-marked goods, those are a separate product-safety role under different law, and we cover them from our EU establishment.

What it costs

Pricing for these mandates is scoped to the work, because the cost depends on which countries apply and what each local partner charges. There is no flat rate to quote here. Tell us where your users are and what you process, and we will come back with a quote. Talk to us on the contact page.

Sources and references

  • Personal Information Protection Law of the People’s Republic of China, National People’s Congress, npc.gov.cn
  • Nigeria Data Protection Commission, ndpc.gov.ng

Representative mandates

These mandates stack rather than replace each other. One company selling into Europe can be caught by several at once, each is a separate appointment with its own published contact point, and an EU representative does not cover the UK. Engage Compliance holds them together so you have one point of contact across the set.

  • Same-business-day response
  • Professional indemnity and cyber insurance
  • Named DPO notified to the supervisory authority

FAQ

Frequently asked questions

Do I need a data protection representative outside the EU and UK?

It depends on the country. China's PIPL requires a dedicated body or a representative inside the PRC for handlers caught by its extraterritorial rule, Korea's PIPA requires a domestic agent above certain thresholds, and Turkey requires a Turkish representative for foreign controllers that must register with VERBIS. Brazil and Nigeria do not require a foreign company to appoint a representative at all. Engage Compliance maps which of these apply to you and arranges the ones that do.

Does China's PIPL require a representative in China?

Yes, where you are caught. PIPL Article 53 says a personal information handler outside the PRC that falls within the law's extraterritorial rule must either establish a dedicated institution or designate a representative within the PRC, and report its name and contact details to the regulator. The representative has to be inside China, so Engage Compliance delivers it through a local partner. Our dedicated China PIPL compliance page goes into the wider obligations.

Does Brazil's LGPD require a foreign company to appoint a representative?

No. The LGPD has broad extraterritorial reach, but it contains no obligation on a controller established abroad to appoint a representative in Brazil. The role people sometimes point to, the encarregado in Article 5(VIII), is a data protection officer, not a foreign-controller representative. Any comparison table that lists Brazil as representative required is wrong. We can still help with LGPD compliance, there is just no representative mandate to appoint.

Does Korea require a domestic agent under PIPA?

Above certain thresholds, yes. PIPA Article 31-2 requires a domestic agent located in Korea. We do not publish the exact thresholds or the penalty figure here because they need to be read off the current statute for your numbers, so we confirm those as part of scoping. Where the duty applies, Engage Compliance arranges the Korean agent through a local partner.

Can an EU or Amsterdam entity act as our Turkey representative?

No. Turkey's Registry Regulation requires the data controller representative to be a legal entity established in Turkey or a Turkish citizen, so an Amsterdam entity cannot perform the role. The duty applies to foreign controllers that have to register with VERBIS. Engage Compliance coordinates a qualifying Turkish representative through a local partner and manages the registration for you.

Does Nigeria require a local data protection representative?

No. The Nigeria Data Protection Act 2023 does not require a non-resident entity to appoint a local representative. Nigeria does license Data Protection Compliance Organizations under section 33 of the Act, but that is a service license for firms doing compliance work in Nigeria, not a statutory representative mandate on foreign companies.