
A US ecommerce brand can ship from Texas, use US staff, and never open an office in Europe - yet still face GDPR obligations the moment it actively sells to people in the EU. Outside EU seller obligations are not determined by where your company is incorporated or where your servers sit. They are determined by what you do with individuals in the Union and the personal data that makes those transactions possible.
For companies with EU customers, the risk is not theoretical. A missing EU Representative can become visible in a privacy notice, during enterprise procurement, when a data subject makes a request, or when a supervisory authority asks who it should contact. At that point, a generic support inbox or a rented European mailing address is not a compliance strategy.
When outside EU seller obligations trigger GDPR
The GDPR can apply to a company with no EU establishment when it processes the personal data of people in the EU in connection with either offering goods or services to them, or monitoring their behavior. You do not need to charge in euros, operate a European warehouse, or translate your entire website into French or German for this test to apply.
The facts matter. An online store that ships to EU countries, displays EU delivery options, accepts local payment methods, runs EU-targeted ads, or provides customer support to buyers in the Union is likely offering goods or services to people in the EU. A SaaS company that markets subscriptions to EU teams or allows EU users to create accounts may reach the same result.
Monitoring behavior is broader than many sellers expect. Behavioral advertising, cross-site tracking, profiling for marketing, and analytics that follow individuals' activity can all raise GDPR questions when directed at people in the Union. Basic aggregate website analytics may require a more fact-specific assessment, but businesses should not assume a tracking script is harmless simply because it is installed by a US vendor.
The key distinction is targeting. A website that is merely accessible from Europe is not automatically subject to the GDPR. But once your commercial activity shows an intention to serve the EU market, the analysis changes quickly.
The Article 27 requirement
If the GDPR applies and your company has no establishment in the EU, Article 27 generally requires you to appoint an EU Representative in writing. The representative acts as a contact point for supervisory authorities and data subjects on matters relating to GDPR compliance.
This is not the same role as a data protection officer. A DPO advises and monitors internal privacy compliance where one is required or voluntarily appointed. An EU Representative provides a formal, accessible EU contact for an outside-EU controller or processor. Some organizations need one role, some need both, and some need neither. Treating them as interchangeable creates a gap that sophisticated customers and regulators can spot.
There is a narrow exemption from Article 27 where processing is occasional, unlikely to create a risk to individuals' rights and freedoms, and does not involve large-scale processing of special-category data or criminal-offense data. That is a demanding test, not a shortcut for ordinary digital commerce. Recurring customer accounts, order histories, marketing lists, and persistent tracking usually make the word “occasional” difficult to defend.
What an EU Representative must actually do
A compliant appointment is more than placing a European address in your footer. Your representative should be formally designated in writing and identified in your privacy information. It must be able to receive, assess, and route communications from EU regulators and individuals who exercise their GDPR rights.
That means the arrangement needs operating procedures. If a German authority sends an inquiry on a Friday, who reviews it? If a customer asks for deletion, how does the request reach the right team, get verified, and receive a timely answer? If a complaint raises questions about lawful basis, marketing consent, or international data transfers, does anyone with legal judgment assess the issue before a response goes out?
A mailbox provider can forward an email. It cannot replace the legal and operational response process behind that email. That distinction matters when the communication is time-sensitive, adversarial, or connected to a suspected breach.
A credible EU Representative service should be prepared to:
- Receive and triage supervisory authority correspondence.
- Route and coordinate data subject access, deletion, objection, and related requests.
- Maintain the written designation and required contact details.
- Coordinate communications during a privacy incident or regulatory inquiry.
- Escalate legal questions to qualified professionals rather than improvising a response.
The representative does not take over your GDPR responsibilities. Your company remains responsible for the lawfulness, security, transparency, and governance of its processing. But appointing the right representative gives regulators and customers a real point of contact in the EU, while giving your internal team a controlled path for handling the issue.
The broader obligations outside-EU sellers cannot ignore
Article 27 is one visible requirement, but it sits within a larger GDPR compliance program. Sellers should start with the data they collect throughout the buyer journey: account details, delivery information, payment identifiers, device data, cookies, support records, loyalty programs, and marketing preferences.
For each category, determine why you process it and whether that legal basis is supportable. Processing an address to fulfill an order may be necessary for contract performance. Sending promotional emails may require consent, depending on the facts and applicable rules. Fraud prevention can often involve legitimate interests, but that is not a blank check for unlimited profiling or retention.
Your privacy notice must accurately explain the processing. For an outside-EU business, it should also identify the EU Representative and provide the representative's contact information. A vague policy copied from a competitor does not solve a mismatch between what your site says and what your systems actually do.
Security and vendor management are equally practical concerns. If your checkout, CRM, analytics platform, customer support tool, or advertising network receives personal data, you need to know what each provider does and whether appropriate contractual terms are in place. Where personal data is transferred from the EU to the US or another third country, assess the transfer mechanism and the safeguards your arrangement requires.
Retention deserves attention as well. Ecommerce teams often retain customer information indefinitely because it is useful for support and marketing. GDPR expects a defined retention approach tied to a real purpose. Keeping data “just in case” is difficult to justify when the data no longer serves order fulfillment, legal obligations, dispute management, or a clearly disclosed customer relationship.
Where sellers get caught
The common failure is not always a dramatic breach. More often, an EU prospect's procurement team sees no EU Representative in the privacy notice and pauses the deal. A customer sends an access request to support, but no one recognizes the one-month response clock. A regulator writes to a listed address, and the message is forwarded without analysis until the deadline is already close.
Another costly mistake is assuming that a US privacy program automatically covers Europe. State privacy laws and the GDPR overlap in places, but they differ in scope, legal bases, individual rights, international transfers, and enforcement structure. A strong US program is useful evidence of maturity. It is not a substitute for GDPR-specific implementation.
Noncompliance can create exposure to administrative fines, complaints, corrective orders, and commercial damage. GDPR penalties for certain Article 27 failures can reach up to €10 million or 2% of worldwide annual turnover, whichever is higher, depending on the circumstances. For most growing businesses, the immediate financial pain may instead be a delayed enterprise sale, a stalled marketplace relationship, or expensive reactive legal work. None of those outcomes is a good reason to postpone a basic appointment.
A practical path to compliance
Start by documenting whether you target or monitor people in the EU. Review your sales countries, shipping terms, advertising audiences, language and currency options, account base, cookies, and tracking tools. Then identify whether you act as a controller, a processor, or both in different services.
If Article 27 applies, appoint an EU Representative through a written mandate and update the relevant privacy notices. Build a simple internal escalation process so customer support, security, marketing, and legal teams know where EU requests and regulator communications go. Test it with a mock access request and a mock authority inquiry. If the process depends on one employee recognizing a legal issue in a crowded inbox, it is not ready.
For companies that need substantive coverage rather than message forwarding, rep4eu provides lawyer-led EU Representative services designed for non-EU businesses. The point is not to add another vendor. It is to ensure that the person receiving sensitive EU communications can respond with the legal judgment and coordination the situation demands.
The best time to appoint an EU Representative is before a buyer, customer, or regulator asks why you do not have one. Put the structure in place while the issue is operationally manageable - not when a deadline has already arrived.