
A Delaware SaaS company can have no office, employee, or bank account in Europe and still be directly exposed to EU privacy enforcement. That is the practical reality behind non EU controller obligations. If your business offers products or services to people in the EU, or monitors their behavior, GDPR may apply to you before your first European customer asks a question.
The issue is not whether your company considers itself "European." The issue is whether your processing activities trigger the GDPR's territorial scope. Once they do, Article 27 may require a formal EU Representative, and several other obligations follow. A privacy policy copied from a competitor and a European mailing address are not a compliance program.
When non EU controller obligations apply
A controller decides why and how personal data is processed. A US eCommerce brand deciding how to use customer profiles, an app company setting analytics purposes, and a B2B software provider managing user accounts are all likely controllers for at least part of their processing.
Under GDPR Article 3(2), a company outside the EU can fall within scope when its processing relates to offering goods or services to individuals in the EU or monitoring their behavior within the EU. Payment is not required. A free app, trial account, newsletter, or ad-supported service can qualify.
Offering is assessed from the real commercial signals around the service. Shipping to EU countries, pricing in euros, choosing EU languages for specific markets, running campaigns aimed at EU users, or accepting local payment methods can all matter. One isolated sale to a traveler is different from actively pursuing EU customers. The facts control.
Monitoring commonly arises through behavioral advertising, tracking pixels, device fingerprinting, location-based profiling, usage analytics tied to identifiable users, and similar technology. Not every security log triggers the rule. But a company building profiles or targeting ads based on how EU residents behave online should assume the question will be asked.
Article 27: appoint an EU Representative
For many non-EU controllers, the first visible requirement is an EU Representative under Article 27. The representative must be established in an EU member state where the relevant data subjects are located. If your company targets users across multiple countries, a representative established in one EU state can generally serve as the required contact point across the Union.
The representative is not a ceremonial address. It acts as a contact point for supervisory authorities and data subjects on matters relating to GDPR processing. Its name and contact details belong in your privacy notice. Regulators must be able to reach a real, accountable party in the EU without chasing a foreign company across time zones.
There are narrow exceptions. Article 27 may not apply where processing is occasional, does not include large-scale processing of special category data or criminal-offense data, and is unlikely to create a risk to individuals' rights and freedoms. Public authorities are also excluded.
That exception is frequently misunderstood. "Occasional" is not a convenient label for recurring customer, employee, prospect, or app-user processing. A subscription business serving EU users every day will have a difficult time arguing that its activity is occasional. If EU revenue, marketing, or product usage is ongoing, appointing a representative is usually the safer and more credible position.
A mailbox provider is not the same as representation
A passive provider may give you an address and forward messages. That does not solve the operational problem when a regulator asks for records, a customer makes an access request, or a suspected breach needs a coordinated response.
The representative should be formally appointed in writing and able to receive, assess, route, and help coordinate GDPR communications. The controller remains responsible for compliance and liability. But choosing a representative with legal capability reduces the risk that a time-sensitive inquiry sits unanswered or is mishandled by a generic inbox.
For companies that need an Article 27 appointment, rep4eu provides lawyer-led EU Representative coverage rather than a mailbox service. That distinction matters when the communication is not routine.
Your obligations do not stop at Article 27
An EU Representative is one part of the framework. Non-EU controllers must build the same core GDPR disciplines expected of an EU-based business, scaled to the nature and risk of their processing.
Give people a usable privacy notice
Your notice must explain who the controller is, how to contact the EU Representative where required, which data you collect, why you use it, the legal basis for processing, retention periods, recipients, international transfers, and the rights available to EU individuals. It must be accessible at the point of collection and written clearly enough for the intended audience.
A vague statement that data is used to "improve services" will not carry much weight if your actual practices include profiling, ad measurement, fraud detection, or sharing with vendors. Privacy notices should reflect the real data flow, not a hopeful version of it.
Establish a lawful basis before collecting data
Every processing purpose needs a lawful basis. Contract may support account administration and delivery of a paid service. Legitimate interests may support certain security, fraud-prevention, or limited business operations, provided your interests do not override the individual's rights. Consent may be required for activities such as non-essential cookies or certain direct marketing practices, depending on the applicable rules.
This is where US-first operations often fail. A broad consent checkbox is not a substitute for analyzing each purpose. Nor is a contract clause enough to justify data uses that are unrelated to providing the service.
Make rights requests operational
EU individuals can request access, correction, deletion, restriction, portability, and object to certain processing. Controllers generally must respond within one month. Your team needs a documented method to verify identity, locate relevant data across systems, evaluate exceptions, and provide a response without disclosing someone else's information.
Treating these requests as customer-support tickets is risky. Support may be the intake channel, but privacy, legal, security, and engineering often need to be involved. The EU Representative must also know how requests are routed and who has authority to respond.
Control vendors and international transfers
If processors handle data for you - cloud hosts, CRM platforms, payment providers, analytics vendors, or support tools - Article 28 requires appropriate written processor terms. You also need visibility into subprocessors and the security measures they use.
Data moving from the EU to the United States or another third country needs a valid transfer mechanism. The answer depends on the recipient, the destination, the data involved, and whether a recognized adequacy mechanism applies. For many US companies, this means assessing whether an approved transfer framework applies or using standard contractual clauses with a transfer assessment and supplementary measures where needed.
Do not confuse an Article 27 Representative with a transfer mechanism. One does not replace the other.
Prepare for security incidents
GDPR expects appropriate technical and organizational measures, not a single prescribed security checklist. The right controls depend on your processing, scale, systems, and risk. Access controls, encryption, vendor review, incident playbooks, and tested escalation paths are common baseline measures.
If a personal data breach is likely to create risk to individuals, the controller may need to notify the competent supervisory authority within 72 hours of becoming aware of it. If the risk is high, affected individuals may also need notification. You cannot make that decision intelligently if nobody knows who owns incident triage, what data was affected, or how to reach European legal contacts quickly.
A practical first 30 days
Start by mapping the data you collect from EU individuals, the systems that receive it, the countries where it goes, and the teams or vendors that touch it. Then identify each processing purpose and its proposed lawful basis. This exercise exposes gaps faster than debating compliance in the abstract.
Next, review your public-facing privacy notice, cookie practices, vendor agreements, and rights-request workflow against what actually happens in the product and sales funnel. If Article 27 applies, appoint an EU Representative through a signed designation and publish the representative's details promptly.
Finally, assign named owners for privacy requests and incidents. A written escalation path is more valuable than a policy that no one can operate under pressure. For larger or higher-risk operations, a data protection impact assessment may also be required before processing begins.
The commercial cost of waiting
Regulatory fines attract attention, but they are not the only consequence. Sophisticated EU customers and procurement teams increasingly ask whether a non-EU vendor has an Article 27 Representative, a credible transfer posture, and a workable process for rights requests. An unclear answer can delay a deal, trigger security questionnaires, or send a buyer to a competitor.
Visible noncompliance also creates an avoidable credibility problem. If your privacy notice says you serve EU residents but omits a required representative, the gap is easy for a customer, competitor, or regulator to spot.
The useful next move is not to buy a European address and hope the issue disappears. Establish whether GDPR applies to your actual business model, appoint qualified representation if required, and make sure the people receiving EU requests can do more than forward an email.