US companies are the largest group of non-EU businesses that sell to customers in Germany and the rest of the European Union: SaaS and cloud providers, online shops, app developers, online education, media and subscription services. Many of them have no office in Europe. If people in the EU are among your customers or users, Art. 27 GDPR requires you to appoint a representative established in the EU. Kanzlei Matutis provides this service to US companies from Germany for a flat fee of 350 EUR per year.
Does a company from the United States need an EU representative?
Yes, if it has no establishment in the EU and its processing of personal data relates to offering goods or services to people in the EU or to monitoring their behaviour there (Art. 3(2) in conjunction with Art. 27(1) GDPR). Typical indicators are a German- or French-language version of your website, prices shown in euros, shipping options to EU countries, EU-specific marketing campaigns, or app store listings for EU markets (Recital 23 GDPR). Examples from our practice: a Delaware SaaS company with a German sales page and EUR pricing; a Shopify store in Texas shipping to Germany and Austria; a US marketing-automation provider that tracks website visitors in the EU for its clients. A US company that already has a subsidiary, branch or office in an EU Member State does not need a representative; that EU entity is the point of contact. The exceptions of Art. 27(2) GDPR (occasional, low-risk processing without large-scale sensitive data; public authorities) are narrow and rarely apply to a business that actively markets to the EU. The full criteria are explained on the page What is the legal situation?.
US privacy law, the Data Privacy Framework and the GDPR
The United States has no single federal privacy statute; data protection is governed by sector-specific laws (such as HIPAA, COPPA and the GLBA) and by state laws, above all the California Consumer Privacy Act (CCPA) as amended by the CPRA. Compliance with these laws does not satisfy the GDPR, which applies to your EU-related processing by virtue of Art. 3(2) GDPR regardless of US law. The EU-U.S. Data Privacy Framework (Commission adequacy decision of 10 July 2023 under Art. 45 GDPR) concerns a different question: it allows companies in the EU to transfer personal data to US companies that have self-certified under the Framework without standard contractual clauses. It does not exempt a self-certified US company from Art. 27 GDPR. A DPF-certified company that offers services to people in the EU still needs an EU representative.
What we do as EU representative for US companies
Rechtsanwaltskanzlei Matutis is a German law firm in Potsdam, near Berlin, specialised in data protection law. Under a written mandate pursuant to Art. 27(1) GDPR we act as your point of contact in the EU for all supervisory authorities of the Member States and for data subjects. Letters and emails addressed to us are checked, scanned and forwarded to your contact person without undue delay; we point out deadlines, such as the one-month period for data subject requests under Art. 12(3) GDPR. The time difference of six to nine hours between Germany and the US means that mail received in Potsdam in the morning is in your inbox before your working day starts. We communicate in English and German. We do not replace your Data Protection Officer and do not take over your compliance decisions; the difference is explained on the page EU representative vs. Data Protection Officer.
Cost for companies from the United States
The annual flat fee is 350 EUR. Because the service is provided by a German law firm to a business customer outside Germany, German VAT is not charged (reverse charge), so net equals gross. We invoice in EUR. You can pay by international wire transfer or, most simply, by credit card or PayPal through the law firm’s PayPal link. Forwarding of scanned mail by email is included; postal forwarding of originals is charged at 2 EUR per item plus postage. Full details: What does it cost and what is included?
Next step
Send us your company name, website and a short description of your activities in the EU via the inquiry form. We confirm whether a representative is required in your case and send you the contract and written mandate. The complete process is described on the page How to appoint an EU GDPR representative. Other countries: EU representative by country.
