Some countries outside the EU and UK make a company appoint a local data protection representative, and the representative has to sit inside that country. Engage Compliance coordinates those appointments through vetted local partners and stays your single point of contact.
The short answer: China, Korea, and Turkey each require a representative or agent established in-country for foreign companies caught by their rules, while Brazil and Nigeria have no such requirement at all, and Saudi Arabia is not settled. Because these appointments have to be inside the country in question, Engage Compliance arranges each one through a local partner rather than pretending an Amsterdam entity can perform it, and manages the relationship so you deal with one team.
Key takeaways
- Engage Compliance coordinates non-EU representative and agent appointments through vetted local partners, and remains your single point of contact for all of them.
- China’s PIPL, Korea’s PIPA, and Turkey’s registry rules each require a representative or agent that is established in that country, which is why these are partner-delivered rather than run from our EU establishment.
- Brazil does not require a foreign controller to appoint a representative. The LGPD role people cite, the encarregado, is a data protection officer, not a representative.
- Nigeria does not require a non-resident entity to appoint a local representative. Its Data Protection Compliance Organization license is a service license, not a statutory representative mandate.
- Saudi Arabia is not settled, so we do not assert a requirement. We assess the position case by case and deliver through a local partner where one turns out to be needed.
- Many companies that need one of these also need an EU or UK representative, or a named DPO, and we line those up together.
Which countries actually require a representative
The market is loose with this language, and a few comparison tables list countries as “representative required” when the law says no such thing. Here is the honest split for the regimes buyers ask about most.
Required, and the representative must sit in the country: China, Korea, and Turkey. Each of these is partner-delivered.
Not required for a foreign company: Brazil and Nigeria. There is no representative appointment to make in either.
Not settled: Saudi Arabia. We do not claim a requirement exists, and we check the position before advising.
Each is covered below.
China (PIPL Article 53)
Under Article 53 of the Personal Information Protection Law, a personal information handler outside the PRC that falls within the law’s extraterritorial rule must either establish a dedicated institution or designate a representative within the PRC, responsible for personal information protection matters, and must report that body’s name or the representative’s name and contact details to the regulator.
The obligation is disjunctive: you appoint a dedicated body or a representative, not necessarily both. Either way it has to be inside China, so Engage Compliance delivers it through a local partner and coordinates the reporting to the authority.
On penalties, Article 66 (first paragraph) provides for an order to rectify, a warning, confiscation of unlawful gains, and an order to suspend or terminate the offending app. Where a handler refuses to rectify, there is a fine of up to RMB 1 million, and a fine of RMB 10,000 to 100,000 on the directly responsible person.
China’s wider obligations, including the extraterritorial trigger and the broader compliance picture, are set out on our China PIPL compliance services page.
Korea (PIPA domestic agent)
Korea’s Personal Information Protection Act requires a domestic agent, located in Korea, once a foreign company is above certain thresholds. The duty sits at Article 31-2.
We do not publish the exact thresholds or the penalty figure on this page, because those need to be read off the current statute and enforcement decree for your specific numbers rather than quoted from memory. We confirm them as part of scoping. Where the duty applies, Engage Compliance arranges the Korean domestic agent through a local partner.
Turkey (data controller representative and the VERBIS registry)
A controller not established in Turkey that has to register with VERBIS, the data controllers’ registry, needs a representative that is a legal entity established in Turkey or a Turkish citizen. That comes from the Registry Regulation (Articles 4 and 11), not from Law No. 6698 itself.
The practical consequence is simple: an Amsterdam entity cannot perform this role. The representative has to be Turkish. The appointment is filed with the Authority together with an authenticated copy of the foreign controller’s appointing decision, and the representative handles notifications, requests, and data subject applications on the controller’s behalf.
Because the representative must be Turkish, Engage Compliance coordinates a qualifying local partner and manages the VERBIS registration for you. The Turkish administrative fine for failing to register is revalued each year, so we confirm the current figure at the point of scoping rather than quote a stale band.
Where there is no representative mandate: Brazil and Nigeria
Two countries come up often on the assumption that a representative is required, when it is not.
Brazil. The LGPD has broad extraterritorial reach: it applies to processing carried out in Brazil, to the offering of goods or services to people in Brazil, and to data collected in Brazil. Even so, it places no obligation on a controller established abroad to appoint a representative. The role that gets misread as a representative is the encarregado in Article 5(VIII), which is a data protection officer, the channel between the controller, data subjects, and the national authority. That is a DPO, not a foreign-controller representative. Any page listing Brazil as “representative required” is wrong on the statute. We can still help with LGPD compliance and with the encarregado role, there is just no representative appointment to sell.
Nigeria. The Nigeria Data Protection Act 2023 does not require a non-resident entity to appoint a local representative. Section 44 on registration of controllers and processors of major importance carries no such duty, and the 2025 implementation directive extends registration duties to entities outside Nigeria without adding a representative requirement. Nigeria does license Data Protection Compliance Organizations under section 33 of the Act, but that is a license for firms that provide compliance services in Nigeria, not a statutory representative mandate on foreign companies.
Saudi Arabia: assessed case by case
The Saudi position is not settled, so we do not assert that the Kingdom requires a foreign company to appoint a representative. We assess the Saudi position case by case, and where a local representative turns out to be required, we deliver it through a local partner. We would rather tell you the point is open than sell you an appointment the law may not ask for.
How Engage delivers partner-mandated appointments
For every regime that requires establishment in-country, the representative has to be a local entity or person. We do not imply otherwise. What we provide is coordination and accountability across the whole set:
- We map which of these obligations actually apply to your company, and which do not, so you are not paying for appointments you do not need.
- We appoint qualifying local partners in each country where a mandate applies, and we vet them.
- We stay your single point of contact and manage each relationship, so you deal with one team rather than chasing separate firms in separate time zones.
- Where you also need an EU or UK representative, or a named DPO, we line those up alongside the non-EU appointments.
Where you need a DPO as well as a representative, we keep the two roles with separate entities, on the European Data Protection Board’s reasoning about the conflict between them.
This page is about data protection representation. If what you need is a product-side operator, a GPSR responsible person or an EU authorised representative for CE-marked goods, those are a separate product-safety role under different law, and we cover them from our EU establishment.
What it costs
Pricing for these mandates is scoped to the work, because the cost depends on which countries apply and what each local partner charges. There is no flat rate to quote here. Tell us where your users are and what you process, and we will come back with a quote. Talk to us on the contact page.
Sources and references
- Personal Information Protection Law of the People’s Republic of China, National People’s Congress, npc.gov.cn
- Nigeria Data Protection Commission, ndpc.gov.ng
Representative mandates
These mandates stack rather than replace each other. One company selling into Europe can be caught by several at once, each is a separate appointment with its own published contact point, and an EU representative does not cover the UK. Engage Compliance holds them together so you have one point of contact across the set.
- EU GDPR Article 27 representative
- UK GDPR Article 27 representative
- Swiss FADP Article 14 representative
- DSA Article 13 legal representative
- EU AI Act GPAI authorised representative
- EU AI Act high-risk authorised representative
- NIS2 representative
- Data Act legal representative
- Data Governance Act representative
- e-Evidence legal representative
- Terrorist Content Online representative
- GPSR responsible person
- CE-marking authorised representative
- Non-EU regimes (Swiss, China, Korea, Turkey)