Data Privacy

GDPR for Australian Companies: Does It Apply to You?

When the GDPR reaches an Australian business under Art. 3(2), the two scope tests applied to Australian fact patterns, the Art. 27 EU representative duty, and what non-compliance costs.

Most Australian companies reach this question through a procurement questionnaire or a stalled European deal. The answer turns on two tests in Art. 3(2) GDPR, and on a written designation under Art. 27 that either exists or does not. This page sets out both, applies them to Australian fact patterns, and lists the documents you need to produce in the order a European counterparty will ask for them.

The operative facts: the GDPR applies to you if you offer goods or services to people in the EU or monitor their behaviour, regardless of where your servers, your staff or your ABN sit. Compliance with the Privacy Act 1988 does not discharge it. Australia holds no EU adequacy decision, so European data reaching Australian infrastructure needs a separate transfer basis on top.

Key takeaways

  • Art. 3(2) GDPR catches Australian companies with no EU entity, no EU staff and no EU servers, on either a targeting test or a monitoring test.
  • Exemption from the Privacy Act 1988 as a small business gives no relief under the GDPR. Art. 3 contains no turnover threshold and no volume threshold.
  • Where Art. 3(2) applies and you have no EU establishment, Art. 27 requires a written designation of an EU representative whose details are published in your privacy notice.
  • Health data is Art. 9 special category data. For Australian health-tech, medtech and clinical research companies, scope is the entry point: an Art. 9 condition and a DPIA follow immediately.
  • Australia has no adequacy decision from the European Commission — verified against the Commission’s published list on 30 July 2026 — so EU-to-Australia transfers require Standard Contractual Clauses plus a transfer impact assessment.

The two tests in Art. 3(2)

Art. 3(1) is the straightforward limb: an establishment in the Union — a Dublin sales office, a Berlin subsidiary, on some readings a single employee working from Lisbon — brings processing carried out in the context of that establishment’s activities within the regulation. Most Australian companies reading this have no such establishment. Art. 3(2) catches them anyway. Our general treatment of whether the GDPR applies outside the EU sets out the doctrine; what follows applies it.

Test one: offering goods or services to people in the EU

Recital 23 is explicit that accessibility of a website from Europe is insufficient, as is the isolated European customer. The test is whether you envisage offering to data subjects in the Union. EDPB Guidelines 3/2018 on territorial scope list the indicators supervisory authorities use in practice: pricing or accepting payment in euros, a country-code or .eu domain, EU delivery options, EU-language content, EU customer references, advertising directed at European markets, and international dialling codes.

Two points that trip up the analysis. First, Art. 3(2)(a) says “irrespective of whether a payment is required” — a free tier, a research portal, a gated clinical resource all count. Second, the test concerns offering to data subjects, meaning natural persons, so a B2B contract with a European hospital group still brings the clinicians and administrators whose credentials and correspondence you process into scope.

Test two: monitoring behaviour in the EU

Recital 24 names internet tracking and profiling as the paradigm case, but the wording of Art. 3(2)(b) is broader than cookies. Monitoring covers behavioural analytics, retargeting, device fingerprinting, and — importantly for health companies — remote monitoring of physiological or activity data from users located in the Union. This limb catches companies the first limb misses, and it applies to processors as well as controllers, which matters if you supply analytics or platform services to customers who deploy them against European traffic. Before assuming which side you are on, check the distinction between a controller and a processor.

Worked examples

A Melbourne telehealth platform with EU users. Consultations booked by patients in Ireland and Germany, priced in euros, with clinical notes stored in Sydney. Both limbs of Art. 3(2) engage: services are offered to people in the Union, and the platform’s engagement analytics profile those users. Because the processing concerns health, Art. 9(1) applies and the platform needs a condition under Art. 9(2) — in practice Art. 9(2)(h) for the provision of health care under contract with a health professional bound by professional secrecy, or Art. 9(2)(a) explicit consent — in addition to an Art. 6 basis. Two bases, not one.

A Perth SaMD vendor. Software as a medical device, CE-marked, sold to European hospitals, transmitting device telemetry and patient identifiers back to Australian servers. Scope is established by the offering test. The processing is very likely to require a data protection impact assessment: Art. 35(3)(b) makes a DPIA mandatory for processing on a large scale of Art. 9 data, and every national supervisory authority’s mandatory-DPIA list includes health data processing of this kind.

A Sydney CRO or clinical-trial sponsor. Participant data from European sites flowing to an Australian coordinating centre. This is Art. 9 special category data at volume, transferred to a country with no adequacy decision, usually alongside a separate research-ethics regime. The GDPR analysis is independent of the Clinical Trials Regulation analysis; neither substitutes for the other.

A Brisbane health-app developer. Symptom tracking, cycle tracking, mental-health journaling — an app on the EU app stores, with no EU entity. The offering test is met by distribution and localisation; the monitoring test is met by in-app analytics. Data inferred about health status is Art. 9 data even where the user never enters a diagnosis.

And a non-health case, for contrast. A Melbourne retailer whose checkout offers delivery to Ireland and the Netherlands, quotes landed prices in euros and runs geotargeted advertising at those markets, is offering goods to people in the EU. Order volume is irrelevant to scope. What differs from the health examples is the consequence: ordinary customer data, Art. 6 alone, and a DPIA only if Art. 35 is otherwise triggered.

Why Art. 9 changes the exercise for health companies

Scope tells you the regulation applies. For health data it tells you very little about the work. Three consequences follow immediately and should be documented before anything else:

  1. A second lawful basis. Art. 9(1) prohibits processing health data unless one of the Art. 9(2) conditions is met. That condition is cumulative with the Art. 6 basis, not an alternative to it. Legitimate interest is not available as an Art. 9 condition. Where you rely on explicit consent under Art. 9(2)(a), it must meet the Art. 7 standard and be explicit — a separate, unambiguous statement, not a ticked box in a terms-of-service bundle. Our page on special categories of data sets out the conditions.
  2. A DPIA that is effectively mandatory. Art. 35(3)(b) requires one for large-scale processing of Art. 9 data. Produce it before deployment, not after; if it identifies a residual high risk you cannot mitigate, Art. 36 requires prior consultation with the supervisory authority. See our DPIA methodology.
  3. The heavier end of the enforcement range. Art. 83(5) reaches EUR 20 million or 4% of worldwide turnover, and Art. 83(2)(g) makes the special-category nature of the data an explicit aggravating factor. This is why a health company cannot treat the exercise as paperwork.

What being in scope requires

There is no lighter regime for non-EU entities. Once Art. 3(2) applies to a processing activity, the whole regulation applies to it: an Art. 6 basis for every purpose, transparency notices meeting Art. 13, one-month responses to data subject access requests, erasure and objection rights, Art. 28 contracts with every processor and sub-processor touching the data, an Art. 30 record of processing activities, security measures proportionate to risk under Art. 32, and 72-hour breach notification to a European supervisory authority.

One divergence from Australian practice deserves flagging because it changes incident-response procedure: the GDPR breach clock starts when you become aware of the breach, not when you finish assessing whether it is notifiable. The full mapping of the two regimes is in our comparison of the Privacy Act 1988 against the GDPR.

The Art. 27 EU representative duty

Art. 27(1) requires a controller or processor caught by Art. 3(2), with no establishment in the Union, to designate a representative in the Union in writing. The representative must be established in a member state where the data subjects you process are located, and their identity and contact details must appear in your privacy notice. Either the name is published or it is not; there is no partial credit, and it is the cheapest finding a supervisory authority or a procurement lawyer can make.

The representative is a mandated contact point for authorities and data subjects. It is not a liability shield, and it is not a data protection officer — the roles are incompatible in substance and should not be filled by the same person. Our pages on Art. 27 and non-EU representatives and on selecting an EU representative cover the mechanics and the mandate terms.

The exemption is narrow. Art. 27(2)(a) applies only where processing is occasional, does not include large-scale processing of Art. 9 or Art. 10 data, and is unlikely to result in a risk to rights and freedoms. All three limbs must hold simultaneously. Any recurring commercial relationship fails the “occasional” limb, and any health company fails the second. In practice the exemption is unavailable to the businesses reading this page. Art. 27(2)(b) covers public authorities.

If you already have an MDR Authorised Representative, you are not covered

This catches medical device manufacturers regularly. Art. 11(1) of the Medical Device Regulation (EU) 2017/745 provides that where a manufacturer is not established in a member state, the device may be placed on the Union market only if the manufacturer designates a sole authorised representative; under Art. 11(2) that designation constitutes the representative’s mandate and is valid only when accepted in writing. Australian device manufacturers know this role, budget for it, and name it in their technical documentation.

The GDPR’s Art. 27 representative is a separate obligation with a separate appointee. Different regulation, different subject matter — personal data protection rather than device safety and market surveillance — different statutory tasks, and a different published location. An MDR Authorised Representative does not satisfy Art. 27, and an Art. 27 representative does not satisfy Art. 11 MDR. The same is true in reverse for the equivalent role under the In Vitro Diagnostic Regulation. Some service providers offer both; that is a commercial convenience, not a legal merger of the two mandates, and the two appointments must be documented separately. If your regulatory affairs team has an authorised representative agreement in a drawer, that is evidence you are placing products on the EU market — which is itself an indicator under the Art. 3(2)(a) targeting test.

What non-compliance costs

Failure to designate a representative is an infringement in its own right under Art. 83(4)(a), sanctionable at up to EUR 10 million or 2% of worldwide annual turnover, whichever is higher. Substantive breaches — no lawful basis, transparency failures, ignored data subject rights, unlawful transfers, and any breach of Art. 9 — sit in the upper band of Art. 83 at EUR 20 million or 4%.

For a mid-sized Australian exporter the realistic exposure is commercial before it is regulatory. European buyers — and European hospitals and research institutions in particular — run data protection due diligence as a standing procurement gate. No named EU representative, no record of processing, no DPIA, no transfer paperwork: no contract. The second exposure is the transfer question, addressed in our Australia–EU transfer analysis.

The order of work

  1. Scope memo. List every processing activity involving people in the EU. For each, record the limb of Art. 3(2) relied on, the evidence for it, and whether Art. 9 data is involved. One page. This is the first document European counsel will ask for.
  2. Art. 30 record. Build it next; every subsequent obligation reads off it, and it is the artefact a European counterparty opens first.
  3. Lawful basis register. Art. 6 for every purpose, Art. 9(2) condition where health data is involved, recorded per activity rather than per company.
  4. Art. 27 designation. Written mandate, member state chosen by reference to where your data subjects are, details published in the privacy notice.
  5. DPIA for any large-scale Art. 9 processing, before deployment.
  6. Transfer file. SCC module, transfer impact assessment, and the Australian government access powers that assessment must address.
  7. Processor contracts. Art. 28 terms with hosting, analytics, payment and support vendors, with sub-processor lists.
  8. Tooling. Maintaining this by hand does not survive a growing customer base; see GDPR compliance software for Australian companies.

FAQ

We have only a handful of European customers. Does the GDPR apply?

Yes, if you are targeting them. Art. 3 has no volume or turnover threshold. A small European base affects your risk profile and, in theory, the Art. 27(2) analysis — but the analysis has to be documented rather than assumed, and it fails for any recurring relationship or any health data.

Does complying with the Privacy Act 1988 mean we comply with the GDPR?

No. The regimes overlap on security and breach handling and diverge on lawful bases, consent quality, data subject rights, records and transfers. Australia holds no adequacy decision, which is the European Commission’s formal statement that it does not treat Australian law as delivering an essentially equivalent level of protection.

We are a medical device manufacturer with an EU Authorised Representative. Do we still need an Art. 27 representative?

Yes. Art. 11 MDR and Art. 27 GDPR are separate obligations under separate regulations with separate scopes. Holding one does not satisfy the other, and both appointments must be in writing and separately documented.

Can a European authority actually enforce against an Australian company?

Cross-border enforcement is harder than intra-EU enforcement, but the exposure is real: published decisions, orders to suspend processing that your European customers must then act on, and the loss of European revenue when procurement finds the gap. The Clearview AI case, discussed in our page on GDPR for US companies, shows a supervisory authority fining a non-EU company that declined to engage at all.

Legiscope automates this for you

Stop doing compliance manually. Legiscope's AI handles ROPA creation, DPA audits, and gap analysis — in minutes, not weeks.

Start free trial
TD
Written by
Fondateur de Legiscope et expert RGPD

Docteur en droit de l'Université Panthéon-Assas (Paris II), 23 ans d'expérience en droit du numérique et conformité RGPD. Ancien conseiller de l'administration du Premier ministre sur la mise en œuvre du RGPD. Thiébaut est le fondateur de Legiscope, plateforme de conformité RGPD automatisée par l'IA.

View full author profile →