
A US company can have no office, subsidiary, or employee in Europe and still be fully exposed to the GDPR. That is the practical issue behind GDPR coverage versus establishment: the Regulation can apply to your business even when you are not legally established in the EU.
Getting this distinction wrong creates a visible compliance gap. Your privacy notice may name no EU Representative. A customer procurement team may stop a deal. A data subject request may arrive with no owner prepared to respond. If a supervisory authority contacts you, a mailbox provider that merely forwards the message will not solve the underlying problem.
GDPR Coverage Versus Establishment: Two Different Tests
“GDPR coverage” asks whether the GDPR applies to your processing activity. “Establishment” asks whether your company has a real operational presence in the European Union. The concepts overlap, but they are not interchangeable.
Under Article 3, the GDPR reaches companies outside the EU in two main ways.
First, it applies where processing occurs in the context of the activities of an establishment in the EU. This is commonly called the establishment test under Article 3(1). It can apply even if the actual data processing happens on servers in the United States or another country.
Second, it applies to non-EU businesses that offer goods or services to individuals in the EU or monitor their behavior within the EU. This is the Article 3(2) targeting test. It is the provision that catches many US SaaS companies, eCommerce brands, mobile apps, ad-tech vendors, and online platforms with no EU office at all.
The commercial consequence is straightforward: no EU establishment does not mean no GDPR obligations. In many cases, it means Article 27 is directly relevant.
What Counts as an EU Establishment?
An establishment is not limited to a locally incorporated subsidiary. GDPR case law and regulatory guidance focus on whether the company carries out an effective and real exercise of activity through stable arrangements in the EU.
A German GmbH, French branch, or Dutch subsidiary may clearly be an establishment. But the analysis can also be more fact-specific. An EU-based sales operation, a stable local team, or another enduring business presence may matter depending on what it does and how closely its activities connect to the processing at issue.
A registered address alone is not the answer. Nor is a contract with a service provider automatically an establishment. The question is whether there is a genuine, stable business arrangement conducting relevant activity in the EU.
That distinction matters because companies sometimes make two opposite mistakes. One assumes that a remote employee or commercial partner automatically solves its EU compliance structure. Another assumes that having no incorporated EU entity means the GDPR cannot apply. Both assumptions can fail.
An Article 27 representative does not create an establishment
Appointing an EU Representative under Article 27 is a legal compliance measure, not an EU operating presence. Article 27 expressly states that designation of a representative does not affect the responsibility or liability of the controller or processor, and it does not turn the representative into your EU establishment.
That is useful for non-EU companies. You can meet the representation requirement without creating a local subsidiary or building an internal EU legal function. But representation is not a shortcut around substantive compliance. Your company remains responsible for lawful processing, transparency, security, contracts, data subject rights, and incident management.
When GDPR Coverage Triggers Article 27
If your company is subject to the GDPR under Article 3(2) and is not established in the EU, Article 27 generally requires you to appoint an EU Representative in writing.
The representative acts as a local point of contact for supervisory authorities and data subjects on issues related to processing. The representative’s contact details should appear in your privacy notice and, where relevant, in other required GDPR documentation.
For a US business, the trigger often appears in ordinary commercial activity. You may be offering goods or services to people in the EU if you intentionally market to them, accept euros, provide EU shipping options, offer country-specific language or support, or otherwise demonstrate an intention to serve EU customers. No single signal always decides the issue. The full context matters.
Monitoring can be just as significant. Behavioral advertising, profiling, location tracking, analytics designed to follow users across sites or apps, and similar activity can bring an organization within Article 3(2) when directed at individuals in the EU.
The key is not where your company is headquartered. It is whether your processing reaches people in the EU in the ways Article 3 describes.
The Narrow Article 27 Exception
Article 27 includes an exception, but it should not be treated as a general startup exemption. A non-EU controller or processor may avoid appointing a representative only where processing is occasional, does not include large-scale processing of special-category data or criminal-offense data, and is unlikely to result in a risk to the rights and freedoms of natural persons.
Those conditions are cumulative. If your processing is ongoing, central to your product, involves regular user tracking, or could materially affect individuals, relying on the exception becomes difficult to defend.
Consider a US B2B SaaS company with a handful of EU trial users. If it processes basic account data only, has no targeted EU go-to-market activity, and the processing is genuinely occasional and low risk, the exception may warrant a careful legal analysis. Contrast that with a subscription platform that continually serves EU customers, collects usage data, and profiles product behavior. Calling that processing “occasional” would be a weak position.
The risk is not limited to a fine. A missing representative can signal that the company has not taken its GDPR obligations seriously. That becomes relevant in customer diligence, enterprise procurement, regulator correspondence, and the first hours after a complaint or security incident.
A Practical Decision Framework for US Companies
Start with the business facts, not the wording of your privacy policy. Ask whether you have a real, stable EU presence connected to the relevant processing. Then ask whether you intentionally offer goods or services to people in the EU or monitor their behavior.
If the answer to the first question is yes, you may have an EU establishment and need to assess your obligations through that structure. If the answer is no but the answer to the second question is yes, you are likely in the Article 3(2) scenario where Article 27 representation should be addressed.
Four facts deserve immediate review:
- Your customer footprint, including EU users, buyers, and trial accounts
- Your sales and marketing signals, such as EU campaigns, localized pages, currencies, or shipping
- Your product data flows, especially analytics, advertising, profiling, and location data
- Your EU operational footprint, including personnel, affiliates, branches, contractors, and stable local arrangements
Do not stop at a corporate-structure chart. A company can be incorporated only in Delaware and still need a European legal contact point because its product and commercial conduct place it within the GDPR’s territorial scope.
Why the Difference Changes Your Response Plan
An EU establishment may create a deeper and broader operational compliance question. You may need to assess local employment arrangements, controller roles, supervisory authority relationships, and whether any establishment can serve as a main establishment for particular processing activities. That analysis is fact-dependent. Having an EU entity does not automatically produce a simple one-stop-shop outcome.
A non-EU company without an establishment faces a different immediate requirement: credible Article 27 coverage. The representative must be able to receive and manage communications from authorities and data subjects. Passive forwarding is not a response strategy when the issue involves a complaint, a deadline, or a suspected breach.
This is where the quality of the appointment matters. A representative should provide signed designation documentation, maintain an accessible EU contact point, triage requests quickly, and coordinate with the company when legal judgment is required. For businesses handling meaningful EU volume, lawyer-led representation provides a materially stronger position than a generic address service.
rep4eu provides that model through a registered German company with licensed German attorneys on the team, receiving and promptly forwarding regulatory and data subject communications from all 27 EU member states, with legal support available as a separate engagement. The goal is not to manufacture an EU establishment. It is to close the Article 27 gap with a representative prepared to act when contact becomes consequential.
If your revenue team is selling into Europe, your product team is collecting EU usage data, or your privacy notice has no named EU Representative, treat the question as an operational decision with legal consequences. Establishment and GDPR coverage are different tests, but either one can put Europe’s data protection rules squarely on your company’s desk.