Regulatory Compliance

Does a U.S. SaaS company need an EU GDPR representative?

Many U.S. SaaS companies serving EU users must appoint an EU GDPR representative. When Article 27 applies, the exception that rarely fits, and what to do next.

Published September 3, 2026

Short answer

A U.S. SaaS company generally must appoint a representative in the European Union when GDPR Article 3(2) applies and the company has no EU establishment. A narrow exception exists for processing that is occasional, low risk, and does not involve large-scale sensitive or criminal-offence data. Many subscription SaaS businesses cannot safely assume that exception applies.

A U.S. SaaS company does not need an office or employees in Europe for the EU General Data Protection Regulation to apply. If the company offers goods or services to people in the European Union or monitors their behaviour there, GDPR Article 3(2) may bring it within scope.

This guide explains the legal test, the exception, and the practical steps a U.S. SaaS company should take. It is general information, not legal advice.

The two questions that determine whether Article 27 applies

For most U.S. SaaS companies, the analysis has two stages:

  1. Does the GDPR apply to the company's processing under Article 3(2)?
  2. If so, must the company designate an EU representative under Article 27?

The representative obligation does not arise merely because someone in Europe can open a website. The relevant facts are whether the company is offering goods or services to people in the EU, or monitoring their behaviour in the EU.

The binding text is contained in GDPR Articles 3 and 27 on EUR-Lex. The European Data Protection Board provides further interpretation in its Guidelines 3/2018 on the territorial scope of the GDPR.

When is a U.S. SaaS company “offering goods or services” in the EU?

The GDPR can apply when a U.S. company intentionally targets people in one or more EU member states. Payment is not required; a free service can still qualify.

No single factor decides the question. Relevant indicators can include:

  • Marketing campaigns directed at EU countries
  • EU-specific customer testimonials or case studies
  • Pricing in euros or another EU currency
  • Offering EU country or language options beyond what U.S. customers ordinarily need
  • Shipping, onboarding, sales, or support aimed at EU users
  • Referring expressly to customers or users in the EU
  • Using an EU country-code domain or EU-focused search advertising

Mere accessibility from the EU is generally not enough on its own. The overall evidence must indicate an intention to serve people in the EU.

SaaS examples

ScenarioArticle 3(2) likely?Why
A U.S. project-management tool runs ads in Germany and France and signs EU customers Likely yes The company is intentionally offering a service to people in the EU
A U.S. developer tool is globally accessible but has no EU targeting, users, or campaigns Not necessarily Website accessibility alone does not establish targeting
A free U.S. AI writing tool promotes an EU-language version to EU users Likely yes A free service can still be an offer of services
A U.S. analytics provider profiles how EU visitors use customer websites Potentially yes Behavioural monitoring can independently trigger Article 3(2)

The facts matter. A single euro symbol is not an automatic finding, and the absence of euro pricing does not keep an actively targeted service outside the GDPR.

What counts as monitoring behaviour in the EU?

Monitoring can apply when a company tracks people in the EU and subsequently analyses or predicts aspects of their behaviour.

Depending on the circumstances, examples may include:

  • Cross-site tracking for advertising
  • Behavioural profiles used for recommendations or personalisation
  • Location tracking
  • Fraud or risk scoring tied to identifiable individuals
  • Health, fitness, or activity tracking
  • Repeated analytics designed to evaluate individual behaviour

Not every log entry or anonymous aggregate metric is automatically “monitoring” for Article 3(2). The purpose, identifiability, tracking method, and subsequent analysis all matter.

If the GDPR applies, when is a representative required?

Article 27 states that a controller or processor covered by Article 3(2) must designate a representative in the Union unless an exception applies.

The representative must be established in an EU member state where relevant data subjects are located. The appointment must be in writing, and the representative must be authorised to communicate with supervisory authorities and data subjects on GDPR-related issues.

Quick applicability table

QuestionIf yesIf no
Does the company have an establishment in the EU involved in the relevant processing? Article 27 may not be the applicable route; assess the EU establishment directly Continue
Does the company offer goods or services to people in the EU, or monitor their behaviour there? Continue Article 27 generally does not apply
Is the processing only occasional? Test every part of the exception The exception is unavailable
Does it avoid large-scale sensitive and criminal-offence data? Continue testing the exception The exception is unavailable
Is the processing unlikely to risk people's rights and freedoms? The narrow exception may apply A representative is required

All parts of the exception must be satisfied. It is not enough for processing to be low risk if it is not occasional.

Why many SaaS companies should not rely on the “occasional processing” exception

Article 27(2)(a) creates a limited exception where processing is:

  • Occasional
  • Does not include large-scale processing of special-category data or criminal-conviction and offence data
  • Unlikely to create a risk to individuals' rights and freedoms, taking account of the nature, context, scope, and purposes

A subscription SaaS business commonly processes customer account, device, usage, support, or billing data on a continuing basis. That recurring activity makes an “occasional” characterisation difficult in many cases.

The exception must be assessed against the company's actual processing, not its size or funding stage. There is no blanket startup exemption and no minimum EU revenue threshold in Article 27.

Does appointing a representative make the company established in Europe?

No. Article 27 representation is a regulatory contact function. It does not, by itself, create an EU establishment under the GDPR.

The same general distinction appears expressly in the Digital Services Act: designation of a DSA legal representative does not constitute an EU establishment. Tax, corporate, employment, and sector-specific establishment questions are separate and should be assessed independently.

Is an EU representative the same as a Data Protection Officer?

No. The roles have different legal bases, functions, and independence requirements.

EU representativeData Protection Officer
Required under GDPR Article 27 in qualifying extra-territorial cases Required under GDPR Articles 37–39 in specified processing situations
Acts as the EU contact for regulators and data subjects Advises and monitors the organisation's data-protection compliance
Must be established in the EU Must be accessible but is not defined by the same establishment rule
Acts under a written mandate Must perform duties independently and without instructions on those duties

A company can need one, both, or neither. Appointing a DPO does not automatically satisfy Article 27.

What to do after appointing a representative

The appointment should become part of the company's working compliance system, not only a signed document.

  1. Execute a written designation defining the representative's mandate.
  2. Select an EU member state where relevant data subjects are located.
  3. Publish the representative's identity and contact details in the privacy notice.
  4. Make the contact channel easy for data subjects and authorities to find.
  5. Keep the representative informed about relevant processing and compliance changes.
  6. Maintain an up-to-date Record of Processing Activities where required.
  7. Establish a process for routing regulatory correspondence and data-subject requests.
  8. Review the appointment when the company's EU markets or processing materially change.

The EDPB's territorial-scope guidelines state that the representative's identity should be included in the information provided to data subjects under Articles 13 and 14, and should be easily accessible to supervisory authorities.

Common mistakes

Assuming that no EU office means no GDPR

Article 3(2) was designed specifically to address certain processing by organisations without an EU establishment.

Treating a cookie banner as complete GDPR compliance

A consent banner does not resolve territorial scope, lawful basis, data-subject rights, records, contracts, security, or representation.

Relying on the exception without documenting it

If a company concludes that Article 27's exception applies, it should record the facts and reasoning supporting every element of the exception, and review the conclusion as its EU activity grows.

Naming a mailbox without appointing a representative

A generic email address is not a written Article 27 designation. The representative must be an EU-established natural or legal person with an appropriate mandate.

Confusing an EU representative with a DPO

The roles are not interchangeable. A company should analyse Articles 27 and 37 separately.

A practical test for U.S. SaaS founders

Ask these questions:

  • Do we have paying or free users located in the EU?
  • Do our website, sales, partnerships, languages, currencies, or campaigns show that we target them?
  • Do we track or profile identifiable people in the EU?
  • Do we have an EU establishment involved in this processing?
  • Is EU-related processing truly occasional, rather than part of normal operations?
  • Do we process health, biometric, political, religious, sexual-orientation, or other special-category data?
  • Could the processing create a risk to individuals' rights and freedoms?
  • Have we recorded the analysis and the evidence behind it?

If the first three questions indicate Article 3(2) applies, the company has no relevant EU establishment, and the full exception cannot be supported, appointing an EU representative is the usual next step.

Frequently asked questions

Is there a minimum number of EU users before Article 27 applies?

Article 27 does not set a numeric user or revenue threshold. Scale can affect risk and the exception analysis, but there is no universal “first 100 users are exempt” rule.

Does a free SaaS product count as offering a service?

It can. Article 3(2) expressly covers offering goods or services “irrespective of whether a payment of the data subject is required.”

Can our U.S. registered agent act as our EU GDPR representative?

Not unless that person or entity is established in the European Union and is validly appointed to perform the Article 27 role. A U.S.-only registered-agent address does not satisfy the EU establishment requirement.

Can one EU representative cover all 27 member states?

One properly situated representative can generally serve for the company's Article 27 obligations across the EU. The representative must be established in a member state where relevant data subjects are located.

Do UK companies need both an EU and a UK representative?

Potentially. After Brexit, the EU GDPR and UK GDPR operate as separate regimes. A UK company targeting or monitoring people in the EU may need an EU representative, while a non-UK company targeting or monitoring people in the UK may separately need a UK representative.

Does an EU representative replace the company's own liability?

No. GDPR Article 27(5) states that appointing a representative does not prevent legal action against the controller or processor itself.

How EU Presence helps

EU Presence provides Article 27 representation for non-EU companies operating in the European market. The service provides a named EU point of contact, regulatory and data-subject communication handling, and a structured operational layer around the appointment.

Start with the GDPR Representative Checker if you are uncertain whether Article 27 applies. If the result indicates that representation is likely required, review the EU Presence GDPR Representative service or request a written scope assessment.

Primary sources


General information, not legal advice

This article explains how Article 27 is generally applied. Whether it applies to any particular company depends on the facts of its activities and processing, and should be confirmed with a qualified privacy professional.

Latest

More from the blog.

All articles →

Not sure if Article 27 applies?

Run the free checker for an answer in about a minute, or talk to us about a written scope assessment for your EU processing.