Using an EU data processor: does the overseas controller need an EU representative?
An EU processor does not automatically turn its overseas client into an EU-established controller. The EDPB example separates an EU processor’s own processing obligations from an overseas retailer’s scope where the retailer serves only its domestic market. Map the parties and targeting facts, then assess each activity and appointment independently.
Evidence retrieved 2026-10-07. Source versions and topic-specific limits are listed below.
Sourced criteria · EU · GDPR
What changes the service scope?
Decision or task
What the source describes
What to prepare
Controller and processor are assessed separately
The worked example has an overseas retailer serving its domestic customers and using a processor in the EU. The EU processor’s presence does not automatically establish the controller in the Union. [1]
Compare the stated example/criterion with the evidence tasks below; retain any factual differences.
The processor’s own scope
The guidance explains that processing in the context of the EU processor’s establishment has its own GDPR scope. This is not proof that every processing activity of its client is in scope. [1]
Compare the stated example/criterion with the evidence tasks below; retain any factual differences.
The processing contract
Article 28 sets conditions for controller–processor arrangements. Scope the contract and responsibilities separately from any Article 27 representative appointment. [3][4]
Compare the stated example/criterion with the evidence tasks below; retain any factual differences.
The EDPB document is Guidelines 3/2018, version 2.1, adopted 12 November 2019. Its worked examples are guidance and dated assumptions, not a new law or a conclusion about your organisation. EU scope is assessed here; UK and Swiss rules require separate evidence. Novel or disputed scope/role interpretations need specialist legal review.
Prepare the evidence and engagement scope
Use this checklist to gather your business or product details before speaking with a specialist. The items below explain what to record and suggest useful supporting documents. You can add your own answers in the editable project brief.
Map each actual party
Record which legal entity determines purposes/means and which acts on instructions; locate each relevant establishment.
Useful evidence: A controller/processor and establishment matrix.
Trace relevant targeting
Identify whether the overseas controller offers to people in the EU or monitors behaviour there, and which processor activities relate to that purpose.
Useful evidence: A purpose-level data-flow and targeting map.
Separate contract and appointment work
Ask the provider for a scope conclusion for each party, a processing-contract review where relevant and a distinct representative assessment.
Useful evidence: Separate deliverables, responsible entities and unresolved scope questions.
Work packages and dependencies
Conditional: EU representative scope and engagement — Review the specific evidence task and unresolved territorial/role facts. Where appointment applies, agree the mandate, communication and handoff; justify additional privacy services separately.
Questions for providers
Which differences between our actual facts and the cited example change your scope conclusion?
Which processing activity and legal entity does your conclusion cover, and which facts remain unresolved?
Which appointment and evidence-handoff deliverables are included, and which additional services are separately justified?
Sources and data dates
Read the official document in context. The audit details identify the precise locators and preserved versions used for this page.