Since Brexit the UK is a third country for EU GDPR. A UK company with no EU establishment that offers goods or services to people in the EU, or monitors their behavior, is caught by GDPR Article 3(2) and has to appoint an EU representative under Article 27. Engage Compliance provides that representative directly from Amsterdam, named in your privacy notice and reachable by the supervisory authorities. This is the appointment that quietly opened up when the transition period ended, and a lot of UK companies that were compliant before Brexit did nothing about it afterward.

Key takeaways

  • Post-Brexit, a UK company is a non-EU company for GDPR purposes. Selling to or monitoring people in the EU with no EU establishment triggers the Article 27 EU representative obligation.
  • This is not a UK representative. A UK representative is for companies outside the UK. What a UK company needs, when it reaches the EU, is an EU one.
  • The UK’s EU adequacy decision does not close this. Adequacy is about data flowing into the UK; Article 27 is about your own activity in the EU.
  • At home you are governed by the UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025, and regulated by the ICO. That is separate from the EU appointment.
  • We act as your EU representative directly from Amsterdam, with the same senior expert on your account.

How a UK company gets caught by EU GDPR

GDPR reaches beyond the EU through Article 3(2): a company with no EU establishment is inside the Regulation when its processing relates to offering goods or services to people in the EU, whether or not payment is required, or monitoring their behavior as far as it happens in the EU.

A UK SaaS, fintech, ecommerce or media company selling to or running analytics on customers in Ireland, France or Germany, with no office in the EEA, is exactly the shape Article 3(2) catches. Before the transition period ended, the UK was part of the EU regime and this was not a separate obligation. After 2021 it became one, and it is the step most often missed, because nothing about the day-to-day of the business changed even though its legal position did.

Do UK companies need a UK representative or an EU one?

An EU one. This is the point that trips people up, so it is worth stating plainly.

A UK representative, under UK GDPR Article 27, is for companies established outside the UK that target or monitor people in the UK. Your UK company already has UK establishment, so that obligation does not fall on you. The gap that does catch you runs the other way: when you offer goods or services to, or monitor, people in the EU, you are the non-EU company, and Article 27 requires you to appoint a representative established in an EU member state, named in your privacy notice and reachable by EU supervisory authorities and by people in the EU.

Does UK adequacy close the gap?

No, and the two are easy to conflate. The UK holds an EU adequacy decision, renewed in December 2025, which lets personal data flow from the EEA into the UK without additional safeguards such as standard contractual clauses. That is about data coming in. It says nothing about your own obligations when your company reaches out into the EU market. Article 27 follows from your activity under Article 3(2), and adequacy does not switch it off. A UK company can be fully covered by adequacy for inbound data and still owe an EU representative for its own EU-facing processing.

What about your UK regime at home?

At home you are governed by the UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025, and regulated by the Information Commissioner’s Office. That is your domestic compliance and it stands on its own. The EU representative obligation sits on top of it, as an EU requirement that follows from selling into or monitoring the EU market.

What does Engage do?

Engage Compliance acts as your EU representative under Article 27, established in the EU, named in your privacy notice, and reachable by supervisory authorities and by people in the EU on your behalf. This is a service we deliver directly from Amsterdam, with the same senior expert on your account rather than a junior handoff.

Where you also need a named DPO, we cannot be both for the same company. The European Data Protection Board is clear the roles can conflict, so we take one and arrange the other through a partner entity, and we say in writing which is which. Where you also target the UK market and are the non-UK party there, the separate UK representative service covers that appointment.

Experience across 100+ startups and enterprises including Amazon, Coinbase, and Robinhood sits behind the work.

What to do next

If you are a UK company selling to or tracking people in the EU and you have not appointed an EU representative since Brexit, that is an open GDPR Article 27 obligation. Read do I need an EU representative, see how the EU representative service works, or contact us and we will tell you plainly whether you are caught and what the appointment involves.

Sources and references

Representative mandates

These mandates stack rather than replace each other. One company selling into Europe can be caught by several at once, each is a separate appointment with its own published contact point, and an EU representative does not cover the UK. Engage Compliance holds them together so you have one point of contact across the set.

FAQ

Frequently asked questions

Does a UK company need an EU representative?

If your company is established in the UK, has no establishment in the EU or EEA, and either offers goods or services to people in the EU or monitors their behavior, then GDPR Article 27 requires you to appoint a representative established in an EU member state. Before the transition period ended the UK was inside the EU regime, so this was not a separate step. After 2021 it became one, and the narrow Article 27(2) exemption covers only occasional, low-risk processing.

We are in the UK. Don't we need a UK representative, not an EU one?

No. A UK representative under UK GDPR Article 27 is for companies outside the UK that target people in the UK. Your company is established in the UK, so it does not need one. The gap that catches UK companies is the reverse: when you sell to or monitor people in the EU, you are the non-EU company, and it is an EU representative you need.

Doesn't the UK's EU adequacy decision cover this?

No. Adequacy and Article 27 are different things. The UK's adequacy decision, renewed in December 2025, is about data flowing from the EEA into the UK without extra safeguards. Article 27 is about your own company's obligations when it targets the EU. Adequacy does not remove the requirement to appoint an EU representative, and treating it as though it does is a common mistake.

What does the UK's own regime require of us at home?

At home you are governed by the UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025, and regulated by the Information Commissioner's Office. That is your domestic compliance. It is separate from the EU representative obligation, which is an EU requirement that follows from your activity in the EU market.

Can the same provider be our EU representative and our DPO?

No. The European Data Protection Board is clear that one provider should not hold both roles for the same company, because the representative can be addressed by the regulator on the company's behalf while the DPO has to monitor that same company independently. Where you need both, we take one and arrange the other through a partner entity.