Compliance Guides
Non-EU company selling into the EU: what must you comply with?
Company owners outside Europe are sure EU law does not touch them because they have no EU office, and they are wrong. GDPR, the AI Act, DORA, and the product rules can all apply when you target the EU market. Here is what each one asks.

Photo: John Simmons / Unsplash
New to the topic? Start with What sovereign compliance actually means.
The same point comes up with almost every CEO and company owner I meet from outside Europe: we have no office in the EU, so EU law is not our problem. They say it with real confidence, and it usually lands as relief. Then I have to take the relief away. EU law can reach you with no EU office at all, and what matters is whether you target the EU market, wherever you happen to sit. You target it by offering goods or services to people in the EU, monitoring their behaviour, placing products on the EU market, or supplying EU-regulated firms. Any one of those can pull you into GDPR, the EU AI Act, DORA, or Europe's product-safety and cybersecurity rules. Below I go through the ones you are most likely to meet, and what each one asks of you.
When EU law applies to a non-EU business
The rule underneath all of this is simple. EU regulation follows the activity, wherever the company sits. A company with no EU establishment can still be caught when it does any of these things:
- Offers goods or services to people in the EU: pricing in euro, shipping to member states, or a site in an EU language can each signal that you target the market.
- Monitors the behaviour of people in the EU: tracking, profiling, or analytics aimed at individuals located in the Union.
- Places products on the EU market: selling physical goods, or products with digital elements, to EU buyers.
- Supplies EU-regulated entities: providing services to EU financial firms or other regulated customers, whose own requirements flow down to you.
- Definition
- Extraterritorial scope
- The reach of a law beyond the borders of the territory that made it. Several EU regulations apply to companies with no EU establishment when their activity targets the EU market: for example offering goods or services to people in the EU, monitoring their behaviour, or placing products on the EU market.
It is the same test that decides which EU regulations apply to your company, only seen from outside the Union looking in.
GDPR and the EU representative (Article 27)
GDPR is the one most non-EU companies meet first, usually before they have heard of any of the rest. Article 3(2) pulls in controllers and processors not established in the EU where their processing relates to offering goods or services to people in the EU, or to monitoring the behaviour of people in the EU. Sitting outside the Union does not put you outside the GDPR.
Many companies caught this way also have to designate an EU representative under Article 27. That is a person or body established in the EU who acts as the contact point for supervisory authorities and for the individuals whose data you process. There is a narrow exception for occasional, low-risk processing, but for a business selling into the EU on any regular basis it rarely helps.
- Definition
- EU representative (GDPR Article 27)
- A person or organisation established in the EU that a non-EU controller or processor designates in writing to act as its point of contact for supervisory authorities and data subjects. Required for many organisations caught by GDPR Article 3(2), with narrow exceptions for occasional, low-risk processing.
The EU AI Act
The EU AI Act reaches past the Union as well. It applies to non-EU providers who place AI systems on the EU market, and to providers and deployers whose system output is used in the EU, even when the system itself runs somewhere else. If your product uses AI and serves EU users, assume it is in view, then work out the risk tier that sets what you actually have to do. I walk through the scope test in does the EU AI Act apply to us.
DORA by contract
DORA reaches most non-EU suppliers through their contracts. If you supply ICT services (cloud, software, data, or managed services) to EU financial entities, the Digital Operational Resilience Act reaches you through those relationships. Its third-party requirements land in your customers' contracts, so a provider based outside the EU still has to meet the terms its EU financial clients are obliged to impose. What counts is that you supply a regulated firm, whether or not you sit in the EU. The detail is in does DORA apply to my company.
Product rules: CE marking and the Cyber Resilience Act
If you place a physical product on the EU market, the CE-marking regimes come into play: the conformity-assessment and marking rules that apply to whole categories of goods before they can be sold in the Union. Where a product has digital elements, connected hardware or software, it also falls under the Cyber Resilience Act, which sets cybersecurity requirements across the whole life of the product. A manufacturer outside the EU has to meet these before it can place products on the market, and will usually need an economic operator established in the Union to carry certain responsibilities on its behalf.
How COMPLY.Reg helps
Working out which of these regimes actually apply to a company in your position, then turning each one into concrete controls, is slow and easy to get wrong by hand. This is the job we built COMPLY.Reg to do, and I will be honest that it is a good part of why the company exists. It is a regulatory compliance platform that uses AI to scan your business profile against European regulatory sources, work out which requirements apply to you wherever you are based, and turn them into audit-ready, traceable controls with a person signing off each determination. Your source documents stay on your own systems, and your compliance data is processed in the EU, which for me is not negotiable. It is built for European companies and for companies outside Europe that still have to meet EU requirements to do business here. If you are not sure where to begin, start with which EU regulations apply to your company.
Frequently asked questions
- Does EU law apply if I have no office in the EU?
- Yes, and more often than companies expect. Offering goods or services to people in the EU, monitoring their behaviour, placing products on the EU market, or supplying EU-regulated firms can bring GDPR, the AI Act, DORA, or product rules into scope with no EU establishment at all.
- Do I need an EU representative?
- If GDPR Article 3(2) catches you as a non-EU controller or processor, you usually have to designate an EU representative under Article 27, unless the narrow exception for occasional, low-risk processing applies to you.
- Does the EU AI Act reach non-EU companies?
- Yes. It applies to non-EU providers who place AI systems on the EU market, and to providers and deployers whose system output is used in the EU.