The obligation to appoint an EU representative under Art. 27 GDPR depends on what a company does in the EU, not on where it is based. Every company without an establishment in the European Union that offers goods or services to people in the EU or monitors their behaviour (Art. 3(2) GDPR) is affected, whether it sits in New York, Zurich, Dubai or São Paulo. The pages below explain the position for the countries from which most of our clients come, including the relationship between the local data protection law, EU adequacy decisions and the representative obligation. The service and the price are the same for every country: 350 EUR per year, provided by Rechtsanwaltskanzlei Matutis from Potsdam, Germany.
One misunderstanding that applies to all countries
Companies from countries with an EU adequacy decision (Switzerland, the United Kingdom, Canada, Israel, Japan, South Korea, New Zealand, Argentina, Brazil, and US companies certified under the Data Privacy Framework) regularly assume that the adequacy decision exempts them from the GDPR. It does not. An adequacy decision under Art. 45 GDPR concerns transfers of personal data from the EU to that country. The territorial scope of the GDPR is defined in Art. 3 GDPR, and Art. 3(2) GDPR applies to any company that targets people in the EU, adequacy decision or not. The representative under Art. 27 GDPR is required in both cases.
North America
- United States – state privacy laws, Data Privacy Framework and the EU representative
- Canada – PIPEDA, provincial laws and the 2002 adequacy decision
- Mexico – LFPDPPP and the absence of an adequacy decision
Europe outside the EU
- United Kingdom – third country since 1 January 2021, UK GDPR and adequacy
- Switzerland – revised FADP, the mirror obligation of Art. 14 FADP and adequacy
Middle East
- United Arab Emirates and Dubai – federal PDPL, DIFC and ADGM laws, free-zone companies
- Israel – Protection of Privacy Law, Amendment 13 and adequacy
Asia-Pacific
- India – DPDP Act 2023, IT service providers as processors
- Singapore – PDPA and regional headquarters
- Hong Kong – PDPO and cross-border trade
- Japan – APPI and the mutual adequacy decisions of 2019
- South Korea – PIPA and the 2021 adequacy decision
- Australia – Privacy Act 1988 and the small-business exemption
- New Zealand – Privacy Act 2020 and adequacy
Africa
- South Africa – POPIA and the Information Officer
South America
- Brazil – LGPD and the adequacy decision of January 2026
- Argentina – Ley 25.326 and the 2003 adequacy decision
- Chile – Ley 21.719 and the new supervisory authority
Countries not listed
The same rules apply to companies from any other third country, for example Türkiye, Colombia, Peru, Nigeria, Kenya, Saudi Arabia, Thailand, Vietnam, Indonesia, Malaysia, the Philippines or Taiwan. Companies in Norway, Iceland and Liechtenstein do not need a representative, because the GDPR applies directly in the European Economic Area and an establishment there counts as an establishment “in the Union” for the purposes of Art. 27 GDPR. If your country is not listed, simply send us your details through the inquiry form; the assessment is free of charge.
