EU Representative for Australian Companies
Complete GDPR Article 27 compliance guide for Australian businesses. The Privacy Act 1988 is not enough. EU Representative from €490/yr.
Key Takeaways for Australian Businesses
- Australia Privacy Act does NOT satisfy GDPR — separate compliance for EU customers required
- If you have even one EU customer, GDPR Article 27 requires an EU Representative
- No EU office, subsidiary, or lawyer needed — EU Shield provides your EU presence
- Adequacy decision expected but not yet finalized — don’t wait for it
- €490/year flat fee — no hidden costs, setup in 15 minutes
Does GDPR Apply to Australian Companies?
Yes. Under Article 3(2) of the GDPR, any organization outside the EU that offers goods or services to individuals in the EU, or monitors their behavior, must comply with GDPR. This applies to Australian businesses of all sizes — from solo operators on Etsy to publicly traded corporations.
The GDPR does not care about the size of your business. There is no minimum revenue threshold, no employee minimum, and no exemption for “small businesses” (unlike the Australian Privacy Act, which exempts businesses with annual turnover under AUD $3 million). If you process EU personal data, GDPR applies.
EU Shield services: GDPR Article 27 EU Representative · GPSR Responsible Person for product sellers — each €490/year flat, all 27 EU states.
Privacy Act 1988 vs GDPR — The Gap
Australia’s Privacy Act 1988 (as amended) shares some principles with GDPR — both require consent, purpose limitation, and access rights. However, the gaps are significant:
| Requirement | Australian Privacy Act | GDPR |
|---|---|---|
| EU Representative | Not required | Article 27 mandate |
| Data breach notification | 30 days (Notifiable Data Breaches) | 72 hours |
| Maximum fine | AUD $50M (OAIC) | €20M or 4% global turnover |
| Extra-territorial scope | Limited | Full (Article 3) |
| Small business exemption | Yes (turnover < $3M) | No exemption |
Adequacy Decision — Should Australian Businesses Wait?
The European Commission has been in discussions with Australia regarding an adequacy decision — a determination that Australia’s data protection framework provides “adequate” protection equivalent to GDPR. If finalized, this would simplify cross-border data transfers. However:
An adequacy decision does not exempt you from Article 27. Even if the EU recognizes Australian data protection as adequate, non-EU businesses processing EU personal data must still appoint an EU Representative under Article 27. The adequacy decision covers data transfer mechanisms (Chapter V), not the representative requirement (Article 27). Waiting for the decision means assuming regulatory risk in the meantime.
Australian Businesses Most at Risk
- SaaS companies — if your software has EU users, you process EU personal data; analytics, accounts, billing data all trigger GDPR
- E-commerce sellers — Shopify, Amazon EU, eBay AU sellers shipping to Europe: customer names, addresses, payment data = personal data processed
- Tourism & hospitality — Australian travel operators, hotels, and tour companies serving EU tourists: booking data, passport details, dietary preferences
- EdTech & online education — Australian online course providers with EU students: enrollment data, assessment records, communication history
- Mining & resources — Australian resource companies with EU investors, partners, or suppliers: contact data, contract details, due diligence information
What EU Shield Provides for Australian Clients
- EU-established legal address for regulatory correspondence
- 24-hour correspondence forwarding guarantee
- Record keeping of processing activities (Article 30)
- Designation letter compliant with Article 27(3)
- Cross-border data transfer guidance for Australia-EU flows
- AUD-denominated invoicing option for Australian clients
Ready to get compliant?
€490/year. 15-minute setup. Active next business day.