Free GDPR Article 27 Calculator for Non-EU Businesses

Do I Need an EU GDPR Representative?

Are you a company from the USA, UK, Canada, India, China, Switzerland, Australia, Singapore, Japan, UAE, or another non-EU country serving customers or users in Europe? Check whether your business may need an EU GDPR Representative under Article 27 and see the recommended Complico solution.

E-commerce Amazon Sellers Shopify Stores AI Companies SaaS Companies Websites Mobile Apps Online Platforms Digital Services
Step 1 of 8 Company Establishment

Where is your business established?

Select the country where your company is legally registered or incorporated.

IMPORTANT DISCLAIMER: This calculator provides general information based on the answers provided and is intended for informational purposes only. It does not constitute legal advice or a definitive determination of GDPR applicability. The requirements of the GDPR, including Article 27, depend on the specific circumstances of each organisation. For a specific assessment, please consult a qualified legal professional or contact Complico Consulting.

Everything You Need to Know About EU GDPR Representation

Clear regulatory guidance for non-EU online sellers, SaaS providers, mobile apps, and artificial intelligence companies.

An EU GDPR Representative is a legal or natural person designated in writing in the European Union by organisations that are not established in the EU but fall within the territorial scope of the General Data Protection Regulation (GDPR).

Under Article 27 of the GDPR, the representative acts as an official liaison and point of contact on behalf of the non-EU company for European Data Protection Authorities (DPAs) and European data subjects (customers and users) on all matters relating to GDPR compliance.

Non-EU businesses that offer goods or services (whether paid or free) to individuals located in the EU/EEA, or that monitor their behaviour within the EU (such as through tracking cookies, analytics, or behavioral advertising), fall within the extraterritorial scope of Article 3(2) of the GDPR.

Where Article 3(2) applies, the organisation is legally required to appoint an EU Representative under Article 27, unless the processing is strictly occasional, does not include large-scale processing of special categories of data, and is unlikely to result in risk to the rights and freedoms of individuals.

Selling through Amazon does not automatically determine whether an EU GDPR Representative is required. If a non-EU seller lists products on European Amazon marketplaces (such as Amazon.de, Amazon.fr, Amazon.it, Amazon.es) or utilizes fulfillment channels that process customer personal data (names, delivery addresses, inquiry records), the seller acts as an independent data controller.

The relevant GDPR territorial-scope criteria under Article 3(2) must be evaluated based on the business activities, customer communication, and data handling practices.

A Shopify store established outside the EU/EEA that offers shipping to European countries, displays prices in Euros, supports European languages, or uses tracking pixels (Meta Pixel, Google Analytics, TikTok Pixel) directly processes personal data of European shoppers.

Under Article 3(2) and Article 27, non-EU Shopify merchants must assess whether designating an Article 27 representative is required to avoid marketplace warnings, merchant gateway freezes, or regulatory enforcement.

Yes. A US company (corporation, LLC, or sole proprietorship) serving customers, subscribers, or users in the EU/EEA is subject to the extraterritorial effect of the GDPR.

Even without physical offices, employees, or subsidiaries in Europe, US businesses targeting European consumers or collecting their personal information must designate an Article 27 representative within an EU member state where their users reside.

Following the United Kingdom's departure from the European Union (Brexit), UK-based companies are considered third-country organisations under EU law.

While UK companies must comply with the UK GDPR locally, any UK business that offers goods or services to EU/EEA individuals or monitors their online behaviour must also comply with EU GDPR and designate an EU Representative under Article 27.

An AI company or AI website established outside the EU/EEA must assess GDPR applicability when it offers services to EU users or processes personal data relating to individuals in the EU/EEA.

Examples include user account information, prompts, uploaded images, audio or documents, IP addresses, analytics telemetry, and other user-generated content. European data authorities actively scrutinize AI platforms for transparent representation and data subject access compliance.

A non-EU SaaS company providing cloud software, subscription platforms, APIs, or digital workflows to users in the EU/EEA is subject to the GDPR.

SaaS architectures that store user credentials, billing information, usage logs, or client customer data must assess whether an Article 27 Representative is mandatory. Having an appointed EU representative is also a common prerequisite for enterprise B2B sales in the European market.

Book a 30-Minutes
Consultation

Speak directly with a compliance specialist. In this one-on-one call